A method, system, device and medium for network security situation awareness

By generating a security database and using a situational awareness module to analyze attack intent, the problem of incomplete network security awareness has been solved, enabling comprehensive awareness and precise prevention and control of network risks.

CN119945781BActive Publication Date: 2025-10-31CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510104789.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-10-31
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

Existing technologies, under an open capability architecture, lack comprehensive cybersecurity awareness and are unable to effectively prevent and control cyber risks.

Method used

By acquiring unified information standards and basic architectural information of the target network, a security database is generated. The situational awareness module is used to analyze attack intent, perform risk control analysis and spread prediction, determine risk control strategies, and perform visual management of terminals.

Benefits of technology

It enables comprehensive security awareness and precise analysis of target networks, effectively preventing and controlling network risks and enhancing network security capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945781B_ABST
    Figure CN119945781B_ABST
Patent Text Reader

Abstract

This invention provides a network security situation awareness method, system, device, and medium. The method includes: acquiring a unified information standard and basic architecture information of the target network capability open architecture; based on the basic architecture information, mining network security elements based on network security events through network element function decoupling, and generating a security database; supervising and training a situation awareness module based on the security database and the unified information standard; interacting with network data streams to filter out risk data and locate risk data streams; inputting the risk data streams into the situation awareness module, performing risk control analysis and propagation prediction by parsing attack intent, and obtaining situation awareness results; determining corresponding risk control strategies based on the situation awareness results, and performing terminal visualization and network security prevention and control management. This method, system, device, and medium can solve the problem that existing technologies suffer from incomplete network security awareness and are unable to effectively prevent and control network risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a network security situation awareness method, system, device, and medium. Background Technology

[0002] With the rapid development and widespread application of communication technologies, taking 5G networks as an example, while bringing advantages such as high speed, low latency, and large capacity, it also faces increasingly severe security challenges. Under the open capability architecture, the openness and complexity of this network further increase, making network security issues more complex and diverse. On the one hand, the network connects a large number of devices and users, including IoT devices and smart terminals, whose security levels vary, making them vulnerable to network attacks. On the other hand, open capabilities allow different service providers and developers to access the network, increasing the attack surface. Simultaneously, the network integrates various emerging technologies, such as software-defined networking and network function virtualization, and the introduction of these technologies also brings new security risks.

[0003] However, under the open capability architecture, existing technologies suffer from incomplete network security awareness and are unable to effectively prevent and control network risks. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a network security situation awareness method, system, device and medium to solve the problem that the prior art has incomplete network security awareness and cannot effectively prevent and control network risks.

[0005] In a first aspect, the present invention provides a network security situation awareness method, wherein the method...

[0006] The law includes:

[0007] Obtain unified information standards and basic architectural information of the target network capability open architecture;

[0008] Based on the aforementioned basic architecture information, network element functions are decoupled to mine network security elements based on network security events and generate a security database.

[0009] Based on the security database and the unified information standard, supervise the training of the situational awareness module;

[0010] Interact with network data streams to filter out risky data and locate risky data streams;

[0011] The risk data stream is input into the situation awareness module, and the situation awareness results are obtained by analyzing the attack intent and performing risk control analysis and spread prediction.

[0012] Based on the situational awareness results, the corresponding risk control strategy is determined, and terminal visualization and network security prevention and control management are carried out.

[0013] Furthermore, the step of generating a security database by mining network security elements based on network security events through network element function decoupling based on the aforementioned basic architecture information specifically includes:

[0014] Based on the aforementioned architecture information, multiple network element functions of the target network are determined, and each network element function is sequentially designated as the first network element function. For each first network element function, the following steps are performed: determine the first network security event set of the first network element function; according to the preset decoupling and splitting criteria, traverse the first network security event set, analyze each network security event, extract the first network security elements related to the target network security, and integrate the extracted first network security elements to obtain the first security database.

[0015] The final security database is obtained by combining all the first security databases.

[0016] Furthermore, before traversing the first network security event set according to the preset decoupling and splitting criteria, the method further includes:

[0017] The decoupling criteria are determined, wherein the decoupling criteria include primary decoupling based on the configuration of the interconnected system and secondary decoupling based on the entire system link;

[0018] The process of integrating the extracted first network security elements to obtain the first security database specifically includes:

[0019] The extracted primary network security elements are classified, merged, and correlated.

[0020] The element sequence is determined based on the results of the correlation analysis, where each element sequence corresponds to a different stage in the entire security lifecycle;

[0021] Traverse the element sequence, determine the corresponding attack intent and attack penetration level and establish a mapping, to obtain the mapping relationship between the attack intent and attack penetration level of each element sequence.

[0022] The first security database is obtained by integrating all the element sequences and the mapping relationship between the attack intent of each element sequence and the attack penetration level.

[0023] Furthermore, the step of supervising the training of the situational awareness module based on the security database and the unified information standard specifically includes:

[0024] Data related to network security is obtained from the security database, and the obtained data is preprocessed according to the unified information standard.

[0025] The preprocessed data is analyzed in terms of attack intent, attack penetration level, and multiple dimensions to obtain a training dataset; wherein the attack penetration level is determined at least based on attack path, attack type, and attack target.

[0026] The situation awareness module is trained under supervision using the training dataset.

[0027] Furthermore, the step of inputting the risk data stream into the situational awareness module, performing risk control analysis and propagation prediction by parsing the attack intent, and obtaining the situational awareness result specifically includes:

[0028] The risk data stream is input into the situation awareness module, and the situation awareness module performs the following steps: determining the target analysis granularity corresponding to the risk data stream, performing attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and performing diffusion prediction, and obtaining the situation awareness result by combining the results of the risk control analysis and diffusion prediction.

[0029] Furthermore, determining the target analysis granularity corresponding to the risk data stream specifically includes:

[0030] Identify the data stream type of the risk data stream;

[0031] The target analysis granularity corresponding to the data stream type is determined based on the pre-defined multi-level analysis granularity.

[0032] Furthermore, the method further includes at least one of the following:

[0033] Deceptive network security data is filtered from the security database, perception conditions are determined based on the deceptive network security data, and branch incremental learning is performed on the situation awareness module based on the perception conditions.

[0034] Acquire security management data for a predetermined time zone, evaluate the perception capability of the situation awareness module based on the security management data, and optimize the situation awareness module based on passive prevention and control data if the perception capability does not meet the threshold standard.

[0035] Based on the security management data, the architectural pattern defects of the capability open architecture are determined, and the architecture of the capability open architecture is solidified based on the architectural pattern defects.

[0036] In a second aspect, the present invention provides a network security situation awareness system, comprising:

[0037] The capability open architecture information acquisition module is used to acquire the unified information standard and basic architecture information of the target network capability open architecture;

[0038] The security database generation module is connected to the capability open architecture information acquisition module. It is used to generate a security database by mining network security elements based on network security events through network element function decoupling based on the basic architecture information.

[0039] A situational awareness training module is connected to the security database generation module and is used to supervise the training of the situational awareness module based on the security database and the unified information standard.

[0040] The risk data stream localization module is connected to the situational awareness training module and is used to interact with the network data stream, filter out risk data, and locate the risk data stream.

[0041] The situational awareness result determination module is connected to the risk data stream location module and is used to input the risk data stream into the situational awareness module, perform risk control analysis and diffusion prediction by parsing the attack intent, and obtain the situational awareness result.

[0042] The prevention and control management module is connected to the situational awareness result determination module and is used to determine the corresponding risk control strategy based on the situational awareness result, and to perform terminal visualization and network security prevention and control management.

[0043] Thirdly, the present invention provides a network security situation awareness device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the network security situation awareness method described in the first aspect above.

[0044] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the network security situation awareness method described in the first aspect.

[0045] This invention provides a network security situation awareness method, system, device, and medium. First, it acquires the unified information standard and basic architectural information of the target network capability open architecture. Based on this basic architectural information, it decouples network element functions to mine network security elements based on network security events, generating a security database. Then, based on the security database and the unified information standard, it supervises and trains a situation awareness module; it interacts with network data streams to filter out risk data and locate risk data streams. The risk data streams are then input into the situation awareness module, where attack intent is analyzed for risk control analysis and propagation prediction, yielding situation awareness results. Finally, based on the situation awareness results, corresponding risk control strategies are determined, and terminal visualization and network security prevention and control management are implemented. This invention achieves situation awareness results by constructing a security database, supervising and training a situation awareness module, and using this module to analyze attack intent in risk data streams for risk control analysis and propagation prediction. Based on these situation awareness results, corresponding risk control strategies are further determined, thereby achieving comprehensive perception of the target network security and achieving precise analysis and effective prevention and control. This solves the problem of incomplete network security perception and ineffective prevention and control of network risks in existing technologies. Attached Figure Description

[0046] Figure 1 This is a flowchart of a network security situation awareness method according to Embodiment 1 of the present invention;

[0047] Figure 2 This is a schematic diagram of the structure of a network security situation awareness system according to Embodiment 2 of the present invention;

[0048] Figure 3 This is a schematic diagram of the structure of a network security situation awareness device according to Embodiment 3 of the present invention. Detailed Implementation

[0049] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0050] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.

[0051] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.

[0052] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.

[0053] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.

[0054] It is understood that the terms "first," "second," etc., in the embodiments of the present invention are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0055] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.

[0056] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.

[0057] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.

[0058] Example 1:

[0059] This embodiment provides a network security situation awareness method, such as Figure 1 As shown, the method includes:

[0060] Step S101: Obtain the unified information standard and basic architecture information of the target network capability open architecture.

[0061] In this embodiment, the target network can be any network with an open capability architecture, including but not limited to 5G networks. Unified information standards can be subdivided into two main categories: intra-domain standards and cross-domain standards. Intra-domain standards refer to standards universally applicable within a specific domain, helping to ensure information consistency and interoperability within that domain. Cross-domain standards, on the other hand, are established to break down information barriers between different domains, promoting information flow and sharing and enabling better collaboration among them. An open capability architecture is essentially a shared platform. Its basic information includes configuration details such as functional blocks, interface types, and components.

[0062] Step S102: Based on the basic architecture information, decouple network element functions, mine network security elements based on network security events, and generate a security database.

[0063] In this embodiment, because target networks are typically heterogeneous and complex, with multiple interconnected systems, the analysis layers are numerous. In such cases, attackers can launch penetration attacks from multiple levels, making it difficult to accurately pinpoint the risk points. To address these challenges, a security database is generated by mining network security elements based on network security events. This database uses the decoupling and decomposition of network element functions as a means to deeply analyze basic architectural information and identify various elements related to network security events. These elements cover multiple aspects and can comprehensively reflect the security status of the target network.

[0064] Optionally, the step of generating a security database by decoupling network element functions based on the basic architecture information and mining network security elements based on network security events specifically includes:

[0065] Based on the aforementioned architecture information, multiple network element functions of the target network are determined, and each network element function is sequentially designated as the first network element function. For each first network element function, the following steps are performed: determine the first network security event set of the first network element function; according to the preset decoupling and splitting criteria, traverse the first network security event set, analyze each network security event, extract the first network security elements related to the target network security, and integrate the extracted first network security elements to obtain the first security database.

[0066] The final security database is obtained by combining all the first security databases.

[0067] In this embodiment, based on the configuration of basic architectural information, multiple network element functions are first determined, and then network risk analysis is performed during architecture operation. Here, the first network element function refers to any one of all network element functions. Network element functions are the basic components of the network, and their related first network security event set contains various event information that affects network security.

[0068] Specifically, for each first network element function, a first network security event set for that first network element function is first determined, serving as the foundation for subsequent security element mining and database establishment. Then, based on a preset decoupling and splitting standard, the first network security event set is traversed, each network security event is analyzed, and elements related to the target network security are extracted, such as network topology, device information, data flow characteristics, and attack patterns. The extracted network security elements are then integrated to determine the first security database. This database contains all mined security elements and their relationships and associations. Finally, the final security database is obtained based on the first security databases for all first network element functions.

[0069] Optionally, before traversing the first network security event set according to a preset decoupling and splitting criterion, the method further includes:

[0070] The decoupling criteria are determined, wherein the decoupling criteria include primary decoupling based on the configuration of the interconnected system and secondary decoupling based on the entire system link;

[0071] The process of integrating the extracted first network security elements to obtain the first security database specifically includes:

[0072] The extracted primary network security elements are classified, merged, and correlated.

[0073] The element sequence is determined based on the results of the correlation analysis, where each element sequence corresponds to a different stage in the entire security lifecycle;

[0074] Traverse the element sequence, determine the corresponding attack intent and attack penetration level and establish a mapping, to obtain the mapping relationship between the attack intent and attack penetration level of each element sequence.

[0075] The first security database is obtained by integrating all the element sequences and the mapping relationship between the attack intent of each element sequence and the attack penetration level.

[0076] In this embodiment, the decoupling criteria are divided into primary decoupling based on the configuration of the interconnected system and secondary decoupling based on the entire system link. Primary decoupling mainly involves a preliminary decomposition of the configuration of the interconnected system, separating tightly coupled systems or functions to a certain extent to better understand and analyze the network's structure and function. Secondary decoupling goes further, conducting a comprehensive analysis and decomposition based on the entire system link to further reveal the complex relationships between systems and potential risk points. The interconnected system includes direct and indirect interconnections, with indirect interconnections determined based on the risk diffusion threat. Through decoupling and decomposition, the network's structure and function can be better understood and analyzed, revealing the complex relationships between systems and potential risk points.

[0077] In this embodiment, the generation of the first security database mainly includes the following steps:

[0078] 1) Obtaining primary cybersecurity elements: These elements come from various channels, such as network monitoring and security incident reports.

[0079] 2) Perform data classification, merging, and correlation analysis: group similar elements into one category to facilitate subsequent processing and analysis; at the same time, identify the relationships between different elements to better understand the cybersecurity situation.

[0080] 3) Determine the element sequence: Each element sequence corresponds to different stages of the entire security lifecycle, such as prevention, detection, response, and recovery.

[0081] 4) Traverse the element sequence to determine the attack intent and attack penetration level and establish a mapping: By analyzing the element sequence, infer the possible attack intent and attack penetration level, and establish a mapping relationship.

[0082] 5) Integrate and determine the first security database: Integrate the information such as the element sequence, attack intent and the mapping relationship between the attack penetration level determined in the previous steps to form a complete security database.

[0083] Step S103: Based on the security database and the unified information standard, supervise the training of the situational awareness module;

[0084] In this embodiment, based on a security database and unified information standards, an attack intent-attack penetration level-multi-dimensional analysis is used as the basic logic to supervise the training of the situational awareness module. The situational awareness module can be trained on any neural network model using sample data until the model converges and the output meets the preset accuracy requirements.

[0085] Optionally, the step of supervising the training of the situation awareness module based on the security database and the unified information standard specifically includes:

[0086] Data related to network security is obtained from the security database, and the obtained data is preprocessed according to the unified information standard.

[0087] The preprocessed data is analyzed in terms of attack intent, attack penetration level, and multiple dimensions to obtain a training dataset; wherein the attack penetration level is determined at least based on attack path, attack type, and attack target.

[0088] The situation awareness module is trained under supervision using the training dataset.

[0089] In this embodiment, the training steps of the situational awareness module include:

[0090] (1) Data acquisition and preprocessing: Data related to network security is acquired from the security database. This data includes information about network security incidents, security elements, etc. At the same time, the data is preprocessed according to the unified information standard to ensure the consistency and standardization of the data.

[0091] (2) Attack Intent Analysis: Starting from the attack intent, we will conduct an in-depth analysis of the attacker's purpose and motivation, providing an important basis for subsequent training.

[0092] (3) Attack penetration level research: By studying the attack penetration level, we can understand the various approaches and methods that attackers may take, as well as the spread and impact of these attacks in the network.

[0093] (4) Multi-dimensional analysis: The data is comprehensively considered from multiple perspectives, including but not limited to time, space, network topology, etc., to improve the perception and analysis capabilities of the situation awareness module.

[0094] (5) Supervised training: Based on the above basic logic, supervised training is conducted on the situation awareness module to improve its ability to perceive and analyze network security situation.

[0095] In this embodiment, the attack penetration level is determined at least based on the attack path, attack type, and attack target. Among these,

[0096] An attack path refers to the way an attacker gains access to a target system or network. This includes methods such as exploiting software vulnerabilities, social engineering attacks, and phishing. For example, attackers may directly intrude into a target system by discovering and exploiting security vulnerabilities in the operating system or applications; or they may gain access to the system by sending seemingly legitimate emails or messages that trick users into clicking malicious links or providing sensitive information.

[0097] Attack types are categorized based on their specific purpose and methods. If the target is assets, this includes physical damage or logical attacks on hardware devices, servers, network infrastructure, etc. For example, attackers might infect servers with malware, rendering them inoperable and impacting business continuity. If the target is data, attack types include data theft, data tampering, and data destruction. For example, attackers might exploit network vulnerabilities to steal users' personal information or companies' trade secrets.

[0098] An attack target clearly defines the specific object that the attacker wants to influence or obtain. The target can be network infrastructure, servers, databases, specific applications, or user data. For example, an attacker might target a company's critical servers to try and obtain trade secrets stored there; or target an individual user's device to steal their bank account information.

[0099] By comprehensively considering attack methods, attack types, and attack targets, a more complete understanding of the penetration level of an attack can be achieved. This helps cybersecurity personnel develop targeted defense strategies, promptly detect and block potential attacks, and protect the security of network systems and user data.

[0100] Step S104: Interact with the network data stream to filter out risky data and locate the risky data stream.

[0101] In this embodiment, anomaly detection algorithms based on machine learning can be used to filter risk control data. Once an abnormal data stream is detected, its source and destination are further analyzed. Advanced algorithms and technologies are used to accurately locate the risky data stream within the network. Based on the location results, corresponding alert information is generated and relevant personnel are notified. Relevant personnel can then take timely measures to process the risky data stream based on the alert information, ensuring the security of the network system.

[0102] Step S105: Input the risk data stream into the situation awareness module, perform risk control analysis and spread prediction by parsing the attack intent, and obtain the situation awareness result.

[0103] In this embodiment, the risk data stream is transmitted to the situational awareness module. By deeply analyzing the attack intent, risk control analysis and diffusion prediction are performed to determine the situational awareness results, providing key decision-making basis for the subsequent determination of risk control strategies.

[0104] Optionally, the step of inputting the risk data stream into the situational awareness module, performing risk control analysis and propagation prediction by parsing the attack intent, and obtaining the situational awareness result specifically includes:

[0105] The risk data stream is input into the situation awareness module, and the situation awareness module performs the following steps: determining the target analysis granularity corresponding to the risk data stream, performing attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and performing diffusion prediction, and obtaining the situation awareness result by combining the results of the risk control analysis and diffusion prediction.

[0106] In this embodiment, the situational awareness module possesses multi-level analysis granularity capabilities, enabling data analysis from different levels and perspectives to provide a more comprehensive understanding of network security. The module first determines the target analysis granularity corresponding to the risky data stream, and then performs network security situational analysis based on this. Specifically, the module analyzes information such as the data packet content, source, destination, and transmission mode in the risky data stream to gain a deeper understanding of the attacker's objectives and strategies. Based on these analysis results, the module performs risk control analysis, assessing the potential threats that the risky data stream may pose to network security, including the existence, severity, and possible scope of impact of the potential threats. In addition to risk control analysis, the module also performs diffusion prediction, i.e., predicting the possible propagation paths and scope of the risky data stream within the network. This prediction helps to take preventative measures in advance, reducing potential security risks. Finally, by combining the results of risk control analysis and diffusion prediction, the module can determine the final situational awareness result.

[0107] Optionally, determining the target analysis granularity corresponding to the risk data stream specifically includes:

[0108] Identify the data stream type of the risk data stream;

[0109] The target analysis granularity corresponding to the data stream type is determined based on the pre-defined multi-level analysis granularity.

[0110] In this embodiment, the multi-level analysis granularity includes multiple levels such as coarse-grained, medium-grained, and fine-grained, with each level corresponding to at least one data type. For example, the coarse-grained analysis level may correspond to overall network traffic data, the medium-grained analysis level may correspond to the data type of a specific application or service, and the fine-grained analysis level may correspond to specific data packet or protocol data types. The situational awareness module first identifies the data flow type of the risky data flow. Then, it traverses the multi-level analysis granularity, matching the data flow type of the risky data flow with the data type applicable to each level of analysis granularity to determine the target analysis granularity. This process ensures that the risky data flow receives the most appropriate analysis, avoiding both over-analysis that wastes resources and under-analysis that leads to the omission of important security risks.

[0111] Optionally, the method further includes at least one of the following:

[0112] Deceptive network security data is filtered from the security database, perception conditions are determined based on the deceptive network security data, and branch incremental learning is performed on the situation awareness module based on the perception conditions.

[0113] Acquire security management data for a predetermined time zone, evaluate the perception capability of the situation awareness module based on the security management data, and optimize the situation awareness module based on passive prevention and control data if the perception capability does not meet the threshold standard.

[0114] Based on the security management data, the architectural pattern defects of the capability open architecture are determined, and the architecture of the capability open architecture is solidified based on the architectural pattern defects.

[0115] In this embodiment, in order to improve the situational awareness module's ability to identify and respond to deceptive data, the security database can be traversed to filter deceptive network security data and deeply explore its dynamic and static characteristics to determine the perception conditions. Based on these perception conditions, the situational awareness module can perform branch incremental learning.

[0116] Specifically, in network security protection, traversing security databases and filtering out deceptive network security data is a crucial step. An anomaly detection-based algorithm can be used for this filtering, with the main steps as follows: First, collect network traffic data and system logs from the security database, preprocess them, and extract key features such as IP addresses and port numbers. Then, use unsupervised learning algorithms to analyze normal data and build a behavioral model. Calculate the deviation of new data sample features from the model; if the deviation exceeds a threshold, the data is considered suspicious. Finally, combine this with manual analysis to confirm the data's authenticity. This anomaly detection-based algorithm can effectively traverse security databases, filter out deceptive network security data, and improve network security protection capabilities.

[0117] Specifically, processing deceptive network security data requires traversing this data. Deceptive data is often covert and cannot be directly identified, thus necessitating in-depth analysis of its dynamic and static characteristics. Static characteristics can be analyzed from multiple perspectives. For example, checking the source and destination addresses of the data to see if there are abnormal IP address combinations. Some deceptive data originates from known malicious IP address ranges, or the destination address points to unusual network locations. Simultaneously, analyzing the structure and content of data packets is crucial to identify potential anomaly patterns. For instance, specific packet formats may not conform to normal network communication, or they may contain suspicious code snippets. Regarding dynamic characteristics, the focus is on abnormal traffic surges and frequent IP address changes. A sudden and significant increase in network traffic could be a sign of a deceptive attack. This could be due to malware propagation or attackers engaging in data theft. Ultimately, by mining and analyzing the dynamic and static characteristics of deceptive network security data, detection conditions are determined. These conditions can serve as early warning indicators for network security systems. When these conditions are met, the system can issue timely alerts to take appropriate protective measures.

[0118] Specifically, decision tree algorithms can be used for incremental branch learning in the situational awareness module. First, a dataset of deceptive cybersecurity data containing various sensing conditions is collected, encompassing information such as traffic characteristics and IP address behavior. Then, an initial decision tree is constructed using this dataset, selecting splitting features based on criteria such as information gain, like abnormal traffic surges. When new sensing conditions or data emerge, the module performs incremental learning. If the data matches the decision tree, it is directly classified and analyzed; otherwise, the decision tree is expanded, such as by adding a branch for IP address change patterns. The decision tree is continuously optimized and adjusted, with regular pruning. Construction criteria and parameters are adjusted according to actual needs to ensure that the situational awareness module can always effectively perform incremental branch learning, improving its ability to identify and respond to deceptive cybersecurity data.

[0119] In this embodiment, to evaluate and optimize the situational awareness module's perception capabilities, security management data from a predetermined time zone can be read to assess the module's capabilities. If the perception capabilities do not meet the threshold standard, the situational awareness module is optimized based on passive control data to enhance its active perception capabilities. The perception capabilities are determined based on the ratio of active perception to passive control.

[0120] Specifically, the first step is to read security management data for a predetermined time zone. This data contains various network security-related information within a specific time period, such as network traffic records, security event logs, and system configuration changes. By reading this data, a comprehensive understanding of the network security status and the operational status of the situational awareness module within that predetermined time zone can be obtained. Next, the situational awareness module's perception capability is evaluated based on the security management data. This perception capability is determined by the ratio of proactive perception to reactive defense. Proactive perception refers to the situational awareness module's ability to proactively detect potential security threats, such as providing early warnings of possible attacks through abnormal traffic monitoring and vulnerability scanning. Reactive defense, on the other hand, involves taking measures to respond to and protect against security incidents after they have occurred, such as firewall blocking and intrusion detection system responses. By analyzing the proactive perception and reactive defense data in the security management data, the ratio between the two can be calculated, thereby evaluating the situational awareness module's perception capability. If the evaluation results show that the perception capability does not meet the threshold standard, it indicates that the situational awareness module is insufficient in proactive perception and needs optimization. In this case, the situational awareness module can be optimized based on reactive defense data. This involves analyzing security events that occur during reactive defense, extracting key features and patterns, and then feeding this information back into the situational awareness module. For example, if a specific type of attack occurs repeatedly and the situational awareness module fails to detect it in advance, the module's monitoring parameters and algorithms can be adjusted to target this type of attack, improving its proactive detection capabilities. Simultaneously, analysis of passive defense data can identify weak points and potential risks in the network, further strengthening the situational awareness module's monitoring and early warning of these areas, thereby enhancing the overall network security level.

[0121] In this embodiment, in order to improve the security and stability of the network architecture, security management data can be identified, architectural pattern defects can be determined, and the capability open architecture can be solidified based on these defects.

[0122] Specifically, architecture solidification is a targeted improvement process. First, a detailed analysis of the defects is conducted to determine the root cause and scope of the problem. Then, corresponding solutions are developed. If the defect is due to insufficient performance of certain components in the architecture, upgrading or replacing these components can be considered. If the defect stems from flawed architectural design, some architectural modules need to be replanned and redesigned. For example, if the network architecture is found to perform poorly in responding to distributed denial-of-service attacks, traffic scrubbing and protection mechanisms need to be strengthened, dedicated anti-DDoS equipment added, or existing protection strategies optimized. During the architecture solidification process, thorough testing and verification are also necessary to ensure that the improved architecture effectively addresses the identified defects without introducing new problems. Simultaneously, continuous monitoring of security management data is crucial to promptly identify new problems and potential risks, continuously optimizing and improving the capability-open architecture to ensure the stability and reliability of network security.

[0123] Step S106: Determine the corresponding risk control strategy based on the situational awareness results, and perform terminal visualization and network security prevention and control management.

[0124] In this embodiment, based on situational awareness results, an in-depth analysis of the current state of network security and potential threats is conducted. These situational awareness results may include key information such as the distribution of risky data flows and the analysis results of attack intentions. Based on these analysis results, targeted risk control strategies are formulated to ensure the secure and stable operation of the network.

[0125] In this embodiment, terminal visualization refers to presenting network security-related information to users in the form of charts and / or reports. For example, risk data flow distribution maps and attack intent analysis results reports can be generated to help users quickly grasp the overall network security situation and potential risks.

[0126] In this embodiment, network security prevention and control management involves taking a series of measures based on risk control strategies to ensure network security. These measures may include configuring and adjusting network devices to optimize network performance and security; providing early warnings and handling of potential security threats to prevent their further spread; and controlling network access to ensure that only legitimate users can access network resources. Furthermore, the module continuously monitors the network's security status, promptly identifying and resolving emerging security issues to ensure stable network operation.

[0127] In one specific embodiment, the network security situation awareness method is applied to a network security situation awareness system, which includes a capability open architecture information acquisition module, a security database generation module, a situation awareness training module, a risk data stream location module, a situation awareness result determination module, and a prevention and control management module. Taking a 5G network as an example, the modules are described as follows:

[0128] 1. Capability Open Architecture Information Acquisition Module

[0129] This module is used to efficiently and accurately obtain unified information standards and basic architectural information of the capability open architecture.

[0130] Unified information standards are divided into two main categories: standards within the same field and standards across different fields.

[0131] Standards within the same field: These standards focus on information specifications within a specific technical area, aiming to ensure consistency and interoperability of information within that field. By adhering to these standards, information exchange between different devices, systems, or services can proceed smoothly, avoiding compatibility issues caused by differences in formats, encoding, etc.

[0132] Cross-domain standards: Given the information barriers that exist between different technological fields, the development of cross-domain standards is particularly important. It aims to break down these barriers and promote the flow and sharing of information across different fields. By implementing cross-domain standards, various fields can collaborate more effectively, jointly driving technological progress and innovative development.

[0133] It should be noted that the capability open architecture is equivalent to a shared platform. The basic information of the architecture includes some configuration information of the platform architecture, such as basic information of functional blocks, interface types, components, etc.

[0134] By acquiring unified information standards and basic architectural information, the capability open architecture information acquisition module provides important basic data support for the entire system, enabling subsequent modules to conduct more accurate and effective analysis and processing based on this information, thereby achieving comprehensive perception and effective prevention and control of 5G network security situation.

[0135] 2. Security Database Generation Module

[0136] This module is used to obtain basic architectural information based on the capability open architecture information acquisition module, and operates by decoupling and splitting network element functions. Specifically, this module includes the following steps:

[0137] (1) Determine the first network security event set for the first network element function: This event set contains various event information that affects network security, serving as the basis for subsequent security element mining and database establishment.

[0138] It should be noted that, based on the configuration of basic architecture information, multiple network element functions are first determined, and then network risk analysis is performed during the architecture's operation. Here, the first network element function refers to any one of all network element functions, that is, the analysis method for any network element function under this architecture is based on this.

[0139] (2) Determining Decoupling Criteria: This criterion is divided into primary decoupling based on the configuration of the interconnected system and secondary decoupling based on the entire system link. Primary decoupling mainly involves a preliminary decomposition of the configuration of the interconnected system, separating tightly coupled systems or functions to a certain extent to better understand and analyze the network's structure and function. Secondary decoupling goes further, conducting a comprehensive analysis and decomposition based on the entire system link to further reveal the complex relationships between systems and potential risk points. The interconnected system includes direct and indirect interconnections, with indirect interconnections determined based on the risk diffusion threat. Through decoupling and decomposition, the network's structure and function can be better understood and analyzed, revealing the complex relationships between systems and potential risk points.

[0140] It's important to clarify that direct interconnection refers to multiple systems collaboratively performing a specific function, with close connections and direct interactions between them. For example, in some cases, multiple network devices work together to achieve high-speed data transmission, which is a manifestation of direct interconnection. Indirect interconnection, on the other hand, is a more complex situation. In this case, while some systems or functions may not directly perform a specific function, if that function malfunctions or a system is attacked, the risk can spread and evolve, affecting other related systems or functions. For instance, if a seemingly unrelated network management system has a security vulnerability, attackers may exploit this vulnerability to further penetrate other critical business systems; this is an example of indirect interconnection. Identifying indirect interconnection is primarily based on the threat of risk propagation. This means assessing and analyzing various potential risks within the system, predicting how the risk might spread and evolve if a system or function malfunctions, and thus determining which systems or functions have indirect interconnection relationships. This approach provides a more comprehensive understanding of the network's security status, offering strong support for subsequent network security protection and management.

[0141] (3) Traverse the first network security event set to mine 5G network security elements: Based on the decoupling and splitting standard, traverse the first network security event set, analyze each network security event, and extract elements related to 5G network security, such as network topology, device information, data flow characteristics, attack mode, etc.

[0142] (4) Determine the first security database: Integrate the mined 5G network security elements to determine the first security database. This database contains all mined security elements and the relationships and associations between them. For example, a sequence of security elements, i.e., a type of security element, may include network topology, device information, data flow characteristics, attack patterns, etc. For instance, the risk may be that a certain topology node has a vulnerability, and an attacker can launch a network attack on it under a certain pattern, and the risk can penetrate to other layers, which is a related feature.

[0143] The security database generation module also includes the following steps:

[0144] 1) Obtaining primary cybersecurity elements: These elements come from various channels, such as network monitoring and security incident reports.

[0145] 2) Perform data classification, merging, and correlation analysis: group similar elements into one category to facilitate subsequent processing and analysis; at the same time, identify the relationships between different elements to better understand the cybersecurity situation.

[0146] 3) Determine the element sequence: Each element sequence corresponds to different stages of the entire security lifecycle, such as prevention, detection, response, and recovery.

[0147] 4) Traverse the element sequence to determine the attack intent and attack penetration level and establish a mapping: By analyzing the element sequence, infer the possible attack intent and attack penetration level, and establish a mapping relationship.

[0148] Specifically, based on the results of the correlation analysis, the element sequence under a security cycle is determined, and then attack and defense analysis is carried out, that is, the attack intent and the attack penetration level are determined, and the security data is determined.

[0149] 5) Integrate and determine the first security database: Integrate the information such as the element sequence, attack intent and the mapping relationship between the attack penetration level determined in the previous steps to form a complete security database.

[0150] It's important to note that the security database includes a sequence of security elements, as well as the mapping relationship between the attack intent and the attack penetration level of each element sequence. For example, within a security cycle, based on the security link sequence, there may be multiple security elements, i.e., sequences. Further attack and defense related analysis is performed to identify and locate the attack and protection parts in the link, and map them as a combination, such as attack location, attack type, and attack intent, and the corresponding protection and response. This allows subsequent automatic security management based on the security database, directly targeting attacks as the monitoring objective and based on protection measures.

[0151] 3. Situational Awareness Training Module

[0152] Based on security databases and unified information standards, this study employs an attack intent-attack penetration level-multi-dimensional analysis as its fundamental logic to supervise the training of the situational awareness module. This includes the following steps:

[0153] (1) Data acquisition and preprocessing: Data related to network security is acquired from the security database. This data includes information about network security incidents, security elements, etc. At the same time, the data is preprocessed according to the unified information standard to ensure the consistency and standardization of the data.

[0154] It should be noted that in the specific implementation process, for example, when a certain task is completed based on the architecture, since the security database is mined based on security events of different network element functions, the corresponding security information, i.e., the network security related data, can be determined based on the network element functions executed by the task. Based on this, the attack and defense monitoring of the task execution process can be carried out.

[0155] (2) Attack Intent Analysis: Starting from the attack intent, we will conduct an in-depth analysis of the attacker's purpose and motivation, providing an important basis for subsequent training.

[0156] (3) Attack penetration level research: By studying the attack penetration level, we can understand the various approaches and methods that attackers may take, as well as the spread and impact of these attacks in the network.

[0157] (4) Multi-dimensional analysis: The data is comprehensively considered from multiple perspectives, including but not limited to time, space, network topology, etc., to improve the perception and analysis capabilities of the situation awareness module.

[0158] (5) Supervised training: Based on the above basic logic, supervised training is conducted on the situation awareness module to improve its ability to perceive and analyze network security situation.

[0159] It should be noted that the situational awareness module can be trained based on any neural network model using sample data until the model converges and the output results meet the preset accuracy requirements.

[0160] The situational awareness training module further includes:

[0161] 1) Determining the Attack Penetration Level: The attack penetration level is determined based on at least the attack path, attack type, and attack target. By comprehensively considering these three aspects, a more complete understanding of the attack penetration level can be achieved, providing strong support for developing targeted defense strategies.

[0162] 2) Processing of deceptive cybersecurity data: The security database is traversed to filter deceptive cybersecurity data, and its dynamic and static characteristics are deeply analyzed to determine the perception conditions. Based on these perception conditions, the situational awareness module undergoes branch incremental learning to improve its ability to identify and respond to deceptive data.

[0163] 3) Assessment and optimization of perception capabilities: Read security management data from a predetermined time zone to assess the perception capabilities of the situational awareness module. If the perception capabilities do not meet the threshold standards, optimize the situational awareness module based on passive control data to improve its active perception capabilities. The perception capabilities are determined based on the ratio of active perception to passive control.

[0164] Among them, security management data refers to the data analyzed and processed by the situational awareness module during application, based on a specific periodic time interval.

[0165] 4) Identification and solidification of architectural pattern defects: Identify security management data, determine architectural pattern defects, and solidify the capability open architecture based on these defects to improve the security and stability of the network architecture.

[0166] 4. Risk Data Stream Location Module

[0167] This module is primarily used for efficient interaction with network data streams, enabling precise filtering of risk control data and accurate location of risk data streams. It should be noted that the network data stream here refers to the full data stream running under the task's architecture, from which the risk component is identified to determine the risk control data.

[0168] Function Description:

[0169] (1) Interactive Network Data Stream: One of the core functions of the risk data stream location module is to interact with the network data stream in real time. It can receive and process massive amounts of data from the network, ensuring the comprehensiveness and real-time nature of the data.

[0170] (2) Risk Control Data Screening: To achieve risk control data screening, the module incorporates a machine learning-based anomaly detection algorithm. This algorithm screens risk control data through the following steps:

[0171] Data collection: First, the module collects key information from the network data stream, including but not limited to the source address, destination address, port number, and protocol type of the data packets.

[0172] Feature extraction: Next, feature extraction is performed on the collected data, including features such as the number, size, and transmission rate of statistical data packets. At the same time, the content and behavior patterns of the data packets are analyzed in depth to form a comprehensive description of the data flow features.

[0173] Model training: Using historical data or known risk data, the machine learning model is trained to learn and recognize patterns and characteristics of normal data flows.

[0174] Real-time anomaly detection: After model training is complete, the module inputs the current data stream features into the trained model to perform real-time anomaly detection. If the model determines that the current data stream deviates significantly from the normal pattern, it is considered potentially risky.

[0175] (3) Risk data flow location: Once an abnormal data flow is detected, the module will further analyze the source and destination of the abnormal data flow, and use advanced algorithms and technologies to accurately locate the specific location of the risk data flow in the network.

[0176] (4) Alarm Generation and Processing: Based on the location results, the module will generate corresponding alarm information and notify relevant personnel. Relevant personnel can take timely measures to process the risky data stream based on the alarm information to ensure the security of the network system.

[0177] 5. Situational Awareness Result Determination Module

[0178] It is mainly used to transmit risk data streams to the situational awareness module, and to perform risk control analysis and spread prediction by deeply analyzing attack intentions, thereby determining the situational awareness results and providing key decision-making basis for the prevention and control management module.

[0179] Module Function Description:

[0180] (1) Risk Data Stream Transmission and Reception: The primary task of the situation awareness result determination module is to transmit the risk data streams selected by the risk data stream location module to the situation awareness module. After successfully receiving these risk data streams, the module will conduct in-depth analysis.

[0181] (2) Attack Intent Analysis and Risk Control: The module analyzes the data packet content, source, destination, and transmission mode in the risky data stream to gain a deeper understanding of the attacker's purpose and strategy. Based on these analysis results, the module performs risk control analysis to assess the potential threats that the risky data stream may pose to network security, including the existence, severity, and possible scope of impact of the potential threats.

[0182] (3) Propagation Prediction: In addition to risk control analysis, the module also performs propagation prediction, that is, predicts the possible propagation path and scope of risky data streams in the network. This prediction helps to take preventive measures in advance and reduce potential security risks.

[0183] (4) Situational Awareness Result Determination: Based on the combined results of risk control analysis and diffusion prediction, the module can determine the final situational awareness result. This result will provide important decision-making basis for the prevention and control management module, helping it to formulate and implement corresponding prevention and control strategies to ensure the safe and stable operation of the network.

[0184] (5) Multi-level analysis granularity setting: In the process of network security situation analysis, the situation awareness result determination module also has the function of setting multi-level analysis granularity. This function aims to analyze data from different levels and perspectives to gain a more comprehensive understanding of the network security situation.

[0185] Multi-level analysis granularity definition: Multi-level analysis granularity includes multiple levels such as coarse-grained, medium-grained, and fine-grained, with each level corresponding to at least one data type. For example, the coarse-grained analysis level may correspond to overall network traffic data, the medium-grained analysis level may correspond to data types of specific applications or services, and the fine-grained analysis level may correspond to specific data packet or protocol data types.

[0186] (6) Data Flow Type Identification and Target Analysis Granularity Matching: In network security situation analysis, the module first identifies the data flow type of the risky data flow. Then, it traverses multiple levels of analysis granularity, matching the data flow type of the risky data flow with the data types applicable to each level of analysis granularity to determine the target analysis granularity. This process ensures that the risky data flow receives the most appropriate analysis, avoiding both over-analysis that wastes resources and under-analysis that leads to the omission of important security risks.

[0187] (7) Network security posture analysis based on target analysis granularity: After determining the target analysis granularity, the module will conduct network security posture analysis based on it (i.e., by understanding the attack intent, and then conducting risk control analysis and diffusion prediction, to determine whether there are security risks and assess the evolution trend of these risks as the current network security posture). The analysis content will also differ depending on the target analysis granularity. For example, at the coarse-grained analysis level, the module will focus on the overall trend and abnormal characteristics of network traffic; at the medium-grained analysis level, it will conduct in-depth analysis of the usage and potential risks of specific applications or services; and at the fine-grained analysis level, it will examine detailed information at the packet level to identify potential malicious packets or protocol vulnerabilities.

[0188] 6. Prevention and Control Management Module

[0189] Based on situational awareness results, risk control strategies are determined, and the system is responsible for endpoint visualization and network security prevention and control management. By deeply analyzing situational awareness results, targeted risk control strategies are formulated, and network security-related information is presented in an intuitive way. At the same time, a series of measures are taken to ensure network security. This invention effectively improves the efficiency and effectiveness of network security management.

[0190] Module Function Description:

[0191] (1) Risk Control Strategy Formulation: The prevention and control management module first conducts an in-depth analysis of the current network security status and potential threats based on the provided situational awareness results. These situational awareness results may include key information such as the distribution of risk data flows and the analysis results of attack intentions. Based on these analysis results, the module will formulate targeted risk control strategies to ensure the safe and stable operation of the network.

[0192] (2) Endpoint Visualization: To enable users to clearly understand the network security status, the prevention and control management module is also responsible for endpoint visualization. This includes presenting network security-related information to users in the form of charts, reports, etc. For example, the module can generate risk data flow distribution diagrams, attack intent analysis results reports, etc., to help users quickly grasp the overall network security situation and potential risks.

[0193] (3) Network Security Prevention and Control Management: After formulating the risk control strategy, the prevention and control management module will take a series of measures to ensure network security. These measures may include configuring and adjusting network devices to optimize network performance and security; providing early warnings and handling of potential security threats to prevent their further spread; and controlling network access to ensure that only legitimate users can access network resources. In addition, the module will continuously monitor the network security status, promptly identify and resolve emerging security issues, and ensure the stable operation of the network.

[0194] (4) Continuous Monitoring and Optimization: The prevention and control management module not only focuses on the current network security status but also emphasizes future security risk management. By continuously monitoring the network security status, the module can promptly identify new security issues or potential threats and adjust and optimize risk control strategies based on the actual situation. This continuous monitoring and optimization mechanism ensures the effectiveness and adaptability of network security management.

[0195] The network security situation awareness method provided in this invention first acquires the unified information standard and basic architecture information of the target network capability open architecture; then, based on the basic architecture information, it mines network security elements based on network security events through network element function decoupling to generate a security database; next, based on the security database and the unified information standard, it supervises and trains a situation awareness module; and interacts with network data streams to filter out risk data and locate risk data streams; then, it inputs the risk data streams into the situation awareness module, performs risk control analysis and propagation prediction by parsing attack intent, and obtains situation awareness results; finally, it determines the corresponding risk control strategy based on the situation awareness results and performs terminal visualization and network security prevention and control management. This invention, by constructing a security database, supervising and training a situation awareness module, and using this module to parse attack intents in risk data streams for risk control analysis and propagation prediction, can obtain situation awareness results. Based on these situation awareness results, it further determines the corresponding risk control strategy, thereby achieving comprehensive perception of the target network security and achieving the technical effect of accurate analysis and effective prevention and control. This solves the problem of incomplete network security perception and ineffective prevention and control of network risks in existing technologies.

[0196] Example 2:

[0197] like Figure 2 As shown, this embodiment provides a network security situation awareness system for executing the above-described network security situation awareness method, including:

[0198] The capability open architecture information acquisition module 11 is used to acquire the unified information standard and basic architecture information of the target network capability open architecture;

[0199] The security database generation module 12 is connected to the capability open architecture information acquisition module 11 and is used to generate a security database by mining network security elements based on network security events through network element function decoupling based on the architecture basic information.

[0200] The situational awareness training module 13 is connected to the security database generation module 12 and is used to supervise the training of the situational awareness module based on the security database and the unified information standard.

[0201] The risk data stream location module 14 is connected to the situational awareness training module 13 and is used to interact with the network data stream, filter out risk data, and locate the risk data stream.

[0202] The situational awareness result determination module 15 is connected to the risk data stream location module 14 and is used to input the risk data stream into the situational awareness module, perform risk control analysis and diffusion prediction by parsing the attack intent, and obtain the situational awareness result.

[0203] The prevention and control management module 16 is connected to the situational awareness result determination module 15 and is used to determine the corresponding risk control strategy based on the situational awareness result, and to perform terminal visualization and network security prevention and control management.

[0204] Optionally, the security database generation module 12 includes:

[0205] The first security database generation unit is used to determine multiple network element functions of the target network based on the basic architecture information, and sequentially take each network element function as the first network element function. For each first network element function, the following steps are performed: determine the first network security event set of the first network element function, traverse the first network security event set according to the preset decoupling and splitting criteria, analyze each network security event, extract the first network security elements related to the target network security, and integrate the extracted first network security elements to obtain the first security database.

[0206] The final security database generation unit is used to obtain the final security database based on all the first security databases.

[0207] Optionally, the security database generation module 12 further includes:

[0208] A decoupling and splitting criterion determination unit is used to determine the decoupling and splitting criterion, wherein the decoupling and splitting criterion includes primary decoupling based on the crosslinking system configuration and secondary decoupling based on the entire system link;

[0209] The first security database generation unit includes:

[0210] The classification, merging, and association unit is used to perform data classification, merging, and association analysis on the extracted first network security elements.

[0211] The element sequence determination unit is used to determine the element sequence based on the results of the correlation analysis, wherein each element sequence corresponds to a different stage in the entire security cycle;

[0212] The mapping relationship determination unit is used to traverse the element sequence, determine the corresponding attack intent and attack penetration level and establish a mapping, so as to obtain the mapping relationship between the attack intent and attack penetration level of each element sequence.

[0213] An integration unit is used to integrate all the element sequences and the mapping relationship between the attack intent of each element sequence and the attack penetration level to obtain the first security database.

[0214] Optionally, the situational awareness training module 13 includes:

[0215] A preprocessing unit is used to obtain network security-related data from the security database and preprocess the obtained data according to the unified information standard.

[0216] The data analysis unit is used to perform attack intent, attack penetration level, and multi-dimensional analysis on the preprocessed data to obtain a training dataset; wherein the attack penetration level is determined at least based on the attack path, attack type, and attack target.

[0217] A supervised training unit is used to supervise the training of the situational awareness module using the training dataset.

[0218] Optionally, the situational awareness result determination module 15 is specifically used for:

[0219] The risk data stream is input into the situation awareness module, and the situation awareness module performs the following steps: determining the target analysis granularity corresponding to the risk data stream, performing attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and performing diffusion prediction, and obtaining the situation awareness result by combining the results of the risk control analysis and diffusion prediction.

[0220] Optionally, the situational awareness result determination module 15 includes:

[0221] A data stream type identification unit is used to identify the data stream type of the risky data stream;

[0222] The target analysis granularity determination unit is used to determine the target analysis granularity corresponding to the data stream type based on a pre-set multi-level analysis granularity.

[0223] Optionally, the situational awareness training module 13 further includes at least one of the following:

[0224] A deceptive network security data processing unit is used to filter out deceptive network security data from the security database, determine perception conditions based on the deceptive network security data, and perform branch incremental learning on the situation awareness module based on the perception conditions.

[0225] The perception capability assessment and optimization unit is used to acquire security management data in a predetermined time zone, assess the perception capability of the situational awareness module based on the security management data, and optimize the situational awareness module based on passive prevention and control data if the perception capability does not meet the threshold standard.

[0226] The architecture pattern defect identification and solidification unit is used to determine the architecture pattern defects of the capability open architecture based on the security management data, and to solidify the architecture open architecture based on the architecture pattern defects.

[0227] Example 3:

[0228] refer to Figure 3 This embodiment provides a network security situation awareness device, including a memory 21 and a processor 22. The memory 21 stores a computer program, and the processor 22 is configured to run the computer program to execute the network security situation awareness method in Embodiment 1.

[0229] The memory 21 is connected to the processor 22. The memory 21 can be a flash memory, a read-only memory or other memory, and the processor 22 can be a central processing unit or a microcontroller.

[0230] Example 4:

[0231] This embodiment provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the network security situation awareness method in Embodiment 1 above.

[0232] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.

[0233] In summary, the network security situation awareness method, system, device, and medium provided in this invention first acquire the unified information standard and basic architectural information of the target network capability open architecture; then, based on the basic architectural information, through network element function decoupling, mine network security elements based on network security events to generate a security database; next, based on the security database and the unified information standard, supervise and train the situation awareness module; and interact with network data streams to filter out risk data and locate risk data streams; then, input the risk data streams into the situation awareness module, perform risk control analysis and propagation prediction by parsing attack intent, and obtain situation awareness results; finally, determine the corresponding risk control strategy based on the situation awareness results, and perform terminal visualization and network security prevention and control management. This invention, by constructing a security database, supervising and training the situation awareness module, and using this module to parse attack intent in risk data streams for risk control analysis and propagation prediction, can obtain situation awareness results. Based on these situation awareness results, further determine the corresponding risk control strategy, thereby achieving comprehensive perception of the target network security and achieving the technical effect of accurate analysis and effective prevention and control. This solves the problem of incomplete network security perception and ineffective prevention and control of network risks in existing technologies.

[0234] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.

Claims

1. A network security situation awareness method, characterized in that, The method includes: Obtain unified information standards and basic architectural information of the target network capability open architecture; Based on the aforementioned basic architecture information, network element functions are decoupled to mine network security elements based on network security events and generate a security database. Based on the security database and the unified information standard, supervise the training of the situational awareness module; Interact with network data streams to filter out risky data and locate risky data streams; The risk data stream is input into the situation awareness module, and the situation awareness results are obtained by analyzing the attack intent and performing risk control analysis and spread prediction. Based on the situational awareness results, the corresponding risk control strategy is determined, and terminal visualization and network security prevention and control management are carried out.

2. The method according to claim 1, characterized in that, Based on the aforementioned basic architecture information, and through network element function decoupling, the process of mining network security elements based on network security events to generate a security database specifically includes: Based on the aforementioned architecture information, multiple network element functions of the target network are determined, and each network element function is sequentially designated as the first network element function. For each first network element function, the following steps are performed: determine the first network security event set of the first network element function; according to the preset decoupling and splitting criteria, traverse the first network security event set, analyze each network security event, extract the first network security elements related to the target network security, and integrate the extracted first network security elements to obtain the first security database. The final security database is obtained by combining all the first security databases.

3. The method according to claim 2, characterized in that, Before traversing the first network security event set according to the preset decoupling and splitting criteria, the method further includes: The decoupling criteria are determined, wherein the decoupling criteria include primary decoupling based on the configuration of the interconnected system and secondary decoupling based on the entire system link; The process of integrating the extracted first network security elements to obtain the first security database specifically includes: The extracted primary network security elements are classified, merged, and correlated. The element sequence is determined based on the results of the correlation analysis, where each element sequence corresponds to a different stage in the entire security lifecycle; Traverse the element sequence, determine the corresponding attack intent and attack penetration level and establish a mapping, to obtain the mapping relationship between the attack intent and attack penetration level of each element sequence. The first security database is obtained by integrating all the element sequences and the mapping relationship between the attack intent of each element sequence and the attack penetration level.

4. The method according to claim 1, characterized in that, The process of supervising and training the situational awareness module based on the security database and the unified information standard specifically includes: Data related to network security is obtained from the security database, and the obtained data is preprocessed according to the unified information standard. The preprocessed data is analyzed in terms of attack intent, attack penetration level, and multiple dimensions to obtain a training dataset; wherein the attack penetration level is determined at least based on attack path, attack type, and attack target. The situation awareness module is trained under supervision using the training dataset.

5. The method according to claim 1, characterized in that, The process of inputting the risk data stream into the situation awareness module, performing risk control analysis and propagation prediction by parsing attack intent, and obtaining situation awareness results specifically includes: The risk data stream is input into the situation awareness module, and the situation awareness module performs the following steps: determining the target analysis granularity corresponding to the risk data stream, performing attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and performing diffusion prediction, and obtaining the situation awareness result by combining the results of the risk control analysis and diffusion prediction.

6. The method according to claim 5, characterized in that, Determining the target analysis granularity corresponding to the risk data stream specifically includes: Identify the data stream type of the risk data stream; The target analysis granularity corresponding to the data stream type is determined based on the pre-defined multi-level analysis granularity.

7. The method according to claim 1, characterized in that, The method further includes at least one of the following: Deceptive network security data is filtered from the security database, perception conditions are determined based on the deceptive network security data, and branch incremental learning is performed on the situation awareness module based on the perception conditions. Acquire security management data for a predetermined time zone, evaluate the perception capability of the situation awareness module based on the security management data, and optimize the situation awareness module based on passive prevention and control data if the perception capability does not meet the threshold standard. Based on the security management data, the architectural pattern defects of the capability open architecture are determined, and the architecture of the capability open architecture is solidified based on the architectural pattern defects.

8. A network security situation awareness system, characterized in that, include: The capability open architecture information acquisition module is used to acquire the unified information standard and basic architecture information of the target network capability open architecture; The security database generation module is connected to the capability open architecture information acquisition module. It is used to generate a security database by mining network security elements based on network security events through network element function decoupling based on the basic architecture information. A situational awareness training module is connected to the security database generation module and is used to supervise the training of the situational awareness module based on the security database and the unified information standard. The risk data stream localization module is connected to the situational awareness training module and is used to interact with the network data stream, filter out risk data, and locate the risk data stream. The situational awareness result determination module is connected to the risk data stream location module and is used to input the risk data stream into the situational awareness module, perform risk control analysis and diffusion prediction by parsing the attack intent, and obtain the situational awareness result. The prevention and control management module is connected to the situational awareness result determination module and is used to determine the corresponding risk control strategy based on the situational awareness result, and to perform terminal visualization and network security prevention and control management.

9. A network security situation awareness device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to implement the network security situational awareness method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the network security situation awareness method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Intention-driven network management system and method

    CN114167760A

  • Dynamic cyberattack mission planning and analysis

    US20250007942A1