Network security state evaluation method, system and terminal based on 5G network
By acquiring and evaluating multiple types of network information, the problems of single evaluation information type and single analysis mode in the prior art are solved, and comprehensive evaluation and protection of the security status of 5G network is achieved, and the reliability of the evaluation results is improved.
Patent Information
- Application Number
- CN202411893300.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-06
AI Technical Summary
The existing network security status evaluation system has a single type of collection and evaluation information and a single analysis mode, which leads to low reliability of network security status evaluation results and cannot meet user needs.
By obtaining network status information, simulated attack information, access network information and network equipment information, network information evaluation, protection evaluation, access evaluation and hardware evaluation are carried out separately, multiple evaluation information are generated, and the network security status evaluation is integrated.
It has achieved comprehensive evaluation and protection of the security status of 5G network, improved the reliability of the evaluation results, and better met the network security needs of users.
Smart Images

Figure CN119946660A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security status assessment method, system, terminal and computer-readable storage medium based on a 5G network. Background Art
[0002] Network status assessment is to evaluate the current status and changing trends of the entire network composed of the operating status of network equipment, network behavior and user behavior. Effective network security assessment is a very important issue currently. Many researchers have designed and implemented a large number of network situation assessment methods. In the process of network status assessment of 5G networks, network security status assessment systems are generally used.
[0003] However, the existing network security status assessment system has the problem of a single type of assessment information collected and a single analysis mode, which leads to low reliability of the final analyzed network security status assessment results and cannot meet user needs.
[0004] Therefore, the prior art still needs to be improved and developed. Summary of the invention
[0005] The main purpose of the present invention is to provide a network security status assessment method, system, terminal and computer-readable storage medium based on 5G network, aiming to solve the problem that the network security status assessment system in the prior art collects a single type of assessment information and a single analysis mode, which leads to low reliability of the final analyzed network security status assessment results and cannot meet user needs.
[0006] To achieve the above object, the present invention provides a method for evaluating the network security status based on a 5G network, and the method for evaluating the network security status based on a 5G network comprises the following steps:
[0007] Acquiring network status information, and calculating a network information evaluation level according to the network status information to obtain first evaluation information;
[0008] Acquire simulated attack information, and calculate a protection assessment level according to the simulated attack information to obtain second assessment information;
[0009] Acquiring access network information, and calculating an access assessment level according to the access network information to obtain third assessment information;
[0010] Acquire network device information, and perform hardware level evaluation calculation according to the network device information to obtain fourth evaluation information;
[0011] A network security status assessment result is obtained according to the first assessment information, the second assessment information, the third assessment information and the fourth assessment information.
[0012] Optionally, in the network security status assessment method based on 5G network, the network status information includes network delay information and network packet loss information;
[0013] The acquiring of network status information and calculating a network information evaluation level according to the network status information to obtain first evaluation information specifically includes:
[0014] Collect network delay information and network packet loss information at preset intervals to obtain multiple network delay information and multiple network packet loss information;
[0015] Performing adjacent network delay information difference calculation and absolute value calculation on the plurality of network delay information to obtain a first evaluation parameter;
[0016] Calculate the average of the plurality of network packet loss information to obtain a second evaluation parameter;
[0017] A first preset formula is used to calculate a comprehensive evaluation parameter according to the first evaluation parameter and the second evaluation parameter, and first evaluation information is obtained according to the comprehensive evaluation parameter.
[0018] Optionally, in the network security status assessment method based on a 5G network, the first assessment information includes first-level assessment information, second-level assessment information and third-level assessment information;
[0019] The obtaining of the first evaluation information according to the comprehensive evaluation parameter specifically includes:
[0020] Determine a first preset value and a second preset value, wherein the first preset value is greater than the second preset value;
[0021] If the comprehensive evaluation parameter is greater than the first preset value, generating the first-level evaluation information;
[0022] If the comprehensive evaluation parameter is greater than the second preset value and less than the first preset value, generating the secondary evaluation information;
[0023] If the comprehensive evaluation parameter is less than the second preset value, the third-level evaluation information is generated.
[0024] Optionally, in the 5G network-based network security status assessment method, the second assessment information includes a first-level protection assessment, a second-level protection assessment, and a third-level protection assessment;
[0025] The acquiring of simulated attack information and calculating the protection evaluation level according to the simulated attack information to obtain second evaluation information specifically includes:
[0026] Determine a preset simulated attack database, and select a preset number of simulated attack modes from the preset simulated attack database;
[0027] Performing a network simulated attack according to each of the simulated attack methods, and obtaining the corresponding attack duration when each simulated attack method is successfully attacked, thereby obtaining multiple attack durations;
[0028] Calculate the average of the multiple break-through times to obtain an average break-through time;
[0029] Determining a third preset value and a fourth preset value, wherein the third preset value is smaller than the fourth preset value;
[0030] If the average attack time is greater than the fourth preset value, a first-level protection assessment is generated;
[0031] If the average breach time is greater than the third preset value and less than the fourth preset value, a level 2 protection assessment is generated;
[0032] If the average attack duration is less than the third preset value, a third-level protection assessment is generated.
[0033] Optionally, in the 5G network-based network security status assessment method, the access network information includes the number of users accessing the network and the historical access times of a single access user;
[0034] The acquiring of access network information, and calculating the access assessment level according to the access network information to obtain third assessment information specifically includes:
[0035] Acquire the number of users accessing the network and the historical access times of a single access user, and determine a first preset number and a second preset number, wherein the first preset number is greater than the second preset number;
[0036] If the historical access times of the single access user are greater than the first preset times, determining that the single access user is a first-class user;
[0037] If the historical access times of the single access user are less than the first preset times and greater than the second preset times, the single access user is determined to be a second-category user;
[0038] If the historical access times of the single access user are less than the second preset times, determining that the single access user is a third type user;
[0039] An access evaluation parameter is calculated according to the number of users accessing the network, the number of users of the first category, the number of users of the second category, and the number of users of the third category using a second preset formula, and third evaluation information is obtained according to the access evaluation parameter.
[0040] Optionally, in the network security status assessment method based on the 5G network, the third assessment information includes a first-level access assessment, a second-level access assessment, and a third-level access assessment;
[0041] The obtaining the third evaluation information according to the access evaluation parameter specifically includes:
[0042] Determining a fifth preset value and a sixth preset value, wherein the fifth preset value is greater than the sixth preset value;
[0043] If the access assessment parameter is greater than the fifth preset value, generating a first-level access assessment;
[0044] If the access assessment parameter is greater than the sixth preset value and less than the fifth preset value, generating a secondary access assessment;
[0045] If the access assessment parameter is less than the sixth preset value, a third level access assessment is generated.
[0046] Optionally, in the network security status assessment method based on 5G network, the network equipment information includes network hardware temperature information and network hardware environment dust concentration; the fourth assessment information includes first-level hardware assessment, second-level hardware assessment and third-level hardware assessment;
[0047] The acquiring of network device information and performing hardware level evaluation calculation according to the network device information to obtain fourth evaluation information specifically includes:
[0048] Acquire the network hardware temperature information and the network hardware environment dust concentration, and determine a seventh preset value;
[0049] If the network hardware temperature information and the network hardware environment dust concentration are both less than the seventh preset value, generating a first-level hardware assessment;
[0050] If the network hardware temperature information or the network hardware environment dust concentration is greater than the seventh preset value, generating a secondary hardware assessment;
[0051] If the network hardware temperature information and the network hardware environment dust concentration are both greater than the seventh preset value, a third-level hardware evaluation is generated.
[0052] In addition, to achieve the above-mentioned purpose, the present invention also provides a network security status assessment system based on a 5G network, wherein the network security status assessment system based on a 5G network includes:
[0053] A first evaluation information generating module, used to obtain network status information, and calculate a network information evaluation level according to the network status information to obtain first evaluation information;
[0054] A second evaluation information generating module is used to obtain simulated attack information, and calculate the protection evaluation level according to the simulated attack information to obtain second evaluation information;
[0055] A third evaluation information generating module, used to obtain access network information, and calculate the access evaluation level according to the access network information to obtain third evaluation information;
[0056] A fourth evaluation information generating module is used to obtain network device information and perform hardware level evaluation calculation according to the network device information to obtain fourth evaluation information;
[0057] An assessment result generating module is used to obtain a network security status assessment result according to the first assessment information, the second assessment information, the third assessment information and the fourth assessment information.
[0058] In addition, to achieve the above-mentioned purpose, the present invention also provides a terminal, wherein the terminal includes: a memory, a processor, and a 5G network-based network security status assessment program stored in the memory and executable on the processor, wherein the 5G network-based network security status assessment program, when executed by the processor, implements the steps of the 5G network-based network security status assessment method as described above.
[0059] In addition, to achieve the above-mentioned purpose, the present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a network security status assessment program based on a 5G network, and when the network security status assessment program based on a 5G network is executed by a processor, the steps of the network security status assessment method based on a 5G network as described above are implemented.
[0060] In the present invention, network status information is obtained, and the network information evaluation level is calculated based on the network status information to obtain first evaluation information; simulated attack information is obtained, and the protection evaluation level is calculated based on the simulated attack information to obtain second evaluation information; access network information is obtained, and the access evaluation level is calculated based on the access network information to obtain third evaluation information; network equipment information is obtained, and the hardware level evaluation calculation is performed based on the network equipment information to obtain fourth evaluation information; network security status evaluation results are obtained based on the first evaluation information, the second evaluation information, the third evaluation information, and the fourth evaluation information. The present invention can achieve comprehensive evaluation and protection of the 5G network security status by obtaining network status information, simulated attack information, access network information, and network equipment information, and performing level evaluation processing on these information, thereby effectively ensuring the network security of the 5G network. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 It is a flowchart of a preferred embodiment of a method for assessing network security status based on a 5G network of the present invention;
[0062] Figure 2 It is a schematic diagram of the overall structure of a preferred embodiment of the network security status assessment method based on 5G network of the present invention;
[0063] Figure 3 It is a structural diagram of a preferred embodiment of the network security status assessment system based on 5G network of the present invention;
[0064] Figure 4 It is a structural diagram of a preferred embodiment of the terminal of the present invention. DETAILED DESCRIPTION
[0065] In order to make the purpose, technical solution and advantages of the present invention clearer and more specific, the present invention is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0066] Network status assessment is to evaluate the current status and changing trends of the entire network composed of the operating status of network equipment, network behavior and user behavior. Effective network security assessment is an issue that people are currently paying close attention to. Many researchers have designed and implemented a large number of network situation assessment methods. In the process of network status assessment of 5G networks, network security status assessment systems are generally used.
[0067] However, the existing network security status assessment system has the problems of single type of collected assessment information and single analysis mode, which leads to low reliability of the final analyzed assessment results, bringing certain impacts to the use of the network security status assessment system.
[0068] To solve the above problems, the present invention proposes a network security status assessment method and system based on 5G network. The present invention generates first assessment information, second assessment information, third assessment information and fourth assessment information by processing network status information, access network information, simulated attack information and network equipment information, thereby realizing comprehensive network security status assessment of 5G network. Among them, through the generated first assessment information, the actual network status of 5G network can be understood, so as to timely find out whether there is abnormal fluctuation or abnormal packet loss rate in the network, thereby ensuring the network security of 5G network; through the generated second assessment information, it can be understood whether the security of 5G network is in place, and the protection weaknesses of 5G network can be understood through simulated attack, so as to update the corresponding network security protection means, and better ensure the network security of 5G network; through the generated third assessment information, the user status of accessing the 5G network can be understood, and the more new users accessing, the more risks the 5G network faces, thereby reminding network management personnel to deploy different network security protection according to the status of access users; through the generated fourth assessment information, the status of hardware equipment of 5G network can be understood, and whether network hardware is overheated or dusty, etc., which causes network fluctuations and affects network security, thereby realizing a more comprehensive evaluation and protection of the installation status of 5G network.
[0069] The network security status assessment method based on 5G network described in the preferred embodiment of the present invention is as follows: Figure 1 As shown, the network security status assessment method based on 5G network includes the following steps:
[0070] Step S10: Obtain network status information, and calculate the network information evaluation level according to the network status information to obtain first evaluation information. The network status information includes network delay information and network packet loss information. The first evaluation information includes first-level evaluation information, second-level evaluation information, and third-level evaluation information.
[0071] like Figure 2 As shown, the present invention is provided with multiple modules such as a network information collection module, a network access collection module, a simulated attack collection module, a network device collection module, a data processing module and an information sending module, wherein the network information collection module is used to collect network status information, the network access collection module is used to collect access network information, the simulated attack collection module is used to collect simulated attack information, and the network device collection module is used to collect network device information; the data processing module is used to process the network status information, access network information, simulated attack information and network device information, and correspondingly generate the first evaluation information, the second evaluation information, the third evaluation information and the fourth evaluation information; the information sending module is used to send the first evaluation information, the second evaluation information, the third evaluation information and the fourth evaluation information.
[0072] Among them, the process of obtaining the first evaluation information is as follows: 1. Extract the collected network status information, the network status information includes network delay information and network packet loss information; 2. Process the network delay information to obtain the first evaluation parameter, process the network packet loss information to obtain the second evaluation parameter, and calculate the first evaluation parameter and the second evaluation parameter to obtain the comprehensive evaluation parameter; 3. When the comprehensive evaluation parameter is greater than the preset value a1 (that is, the first preset value in the present invention), the first-level evaluation information is generated; when the comprehensive evaluation parameter is between the preset value a1 and a2 (that is, the second preset value in the present invention), the second-level evaluation information is generated; when the comprehensive evaluation parameter is less than the preset value a2, the third-level evaluation information is generated.
[0073] Specifically, network delay information and network packet loss information are collected at preset time intervals to obtain multiple network delay information and multiple network packet loss information; adjacent network delay information difference calculation and absolute value calculation are performed on the multiple network delay information to obtain a first evaluation parameter; the mean calculation is performed on the multiple network packet loss information to obtain a second evaluation parameter; and a first preset formula is used to calculate a comprehensive evaluation parameter based on the first evaluation parameter and the second evaluation parameter.
[0074] It can be understood that the specific processing process of the first evaluation parameter is as follows: 1. Collect network delay information once every preset time, collect continuously x times, and obtain x network delay information (that is, multiple network delay information in the present invention); 2. Mark the network delay information as G, and calculate the difference Gg1 between G1 and G2, the difference Gg2 between G2 and G3... the difference Ggx-1 between Gx-1 and Gx in sequence according to the collection time, and obtain x-1 evaluation differences; 3. Calculate the absolute values of x-1 evaluation differences, and extract the number of absolute values of x-1 evaluation differences that are greater than the preset value, that is, obtain the first evaluation parameter (where x≥10).
[0075] It can be understood that the specific processing process of the second evaluation parameter is as follows: collect network packet loss information once every preset time, collect m times in succession, and then calculate the average of the m times of network packet loss information, that is, obtain the second evaluation parameter (where m≥5).
[0076] Determine a first preset value and a second preset value, wherein the first preset value is greater than the second preset value; if the comprehensive evaluation parameter is greater than the first preset value, generate the first-level evaluation information; if the comprehensive evaluation parameter is greater than the second preset value and less than the first preset value, generate the second-level evaluation information; if the comprehensive evaluation parameter is less than the second preset value, generate the third-level evaluation information.
[0077] Among them, the process of obtaining the comprehensive evaluation parameters is as follows: extract the collected first evaluation parameter and the second evaluation parameter, mark them as K1 and K2, assign a correction value Q1 to the first evaluation parameter K1, and assign a correction value Q2 to the second evaluation parameter K2 (need to satisfy Q1>Q2, Q1+Q2=1), and obtain the comprehensive evaluation parameter Kk through the formula K1*Q1+K2*Q2=Kk (that is, the first preset formula in the present invention).
[0078] Among them, the first-level assessment information means that the network status of the 5G network is stable with few abnormal fluctuations; the second-level assessment information means that the 5G network has certain fluctuations and needs regular inspection; the third-level assessment information means that the network status of the 5G network is poor and active network anomaly investigation is needed.
[0079] The present invention achieves the following effects by evaluating network delay information and network packet loss information: 1. Improving network performance: By detecting network delay and packet loss rate, the performance status of the network can be understood, problems existing in the network can be discovered in time, and corresponding measures can be taken to optimize and improve network performance. 2. Improving user experience: Network delay and packet loss rate are important factors affecting user experience. By detecting these indicators, problems in the network can be discovered in time, and corresponding measures can be taken to repair them, thereby improving user experience. 3. Preventing network failures: By continuously monitoring network delay and packet loss rate, potential problems in the network can be discovered in time, network failures can be prevented, and network stability and availability can be guaranteed. 4. Ensuring network security: Abnormalities in network delay and packet loss rate may be caused by network attacks or malicious behaviors. By detecting these indicators, abnormal behaviors can be discovered in time, and corresponding security measures can be taken to ensure network security. 5. Optimizing network resource configuration: By detecting network delay and packet loss rate, the usage of network resources can be understood, thereby optimizing the configuration of network resources according to actual needs and improving the utilization rate of network resources. 6. Assisted network troubleshooting: When a network failure occurs, the detection of network delay and packet loss rate can help troubleshoot the cause of the failure, quickly locate the problem, and improve the efficiency of troubleshooting. Through the above process, the present invention can obtain more accurate first evaluation parameters, second evaluation parameters and comprehensive evaluation parameters, thereby effectively ensuring the accuracy of the generation of the first evaluation information.
[0080] Step S20: Acquire simulated attack information, and calculate the protection evaluation level according to the simulated attack information to obtain second evaluation information, wherein the second evaluation information includes a first-level protection evaluation, a second-level protection evaluation, and a third-level protection evaluation.
[0081] Specifically, a preset simulated attack database is determined, and a preset number of simulated attack methods are selected from the preset simulated attack database; a network simulated attack is performed according to each of the simulated attack methods, and the corresponding breakthrough time when each simulated attack method is successfully broken is obtained, and multiple breakthrough time times are obtained; the average of the multiple breakthrough time times is calculated to obtain an average breakthrough time; a third preset value and a fourth preset value are determined, wherein the third preset value is less than the fourth preset value; if the average breakthrough time is greater than the fourth preset value, a first-level protection evaluation is generated; if the average breakthrough time is greater than the third preset value and less than the fourth preset value, a second-level protection evaluation is generated; if the average breakthrough time is less than the third preset value, a third-level protection evaluation is generated.
[0082] It can be understood that the process of obtaining the simulated attack information in the present invention is as follows: 1. A preset simulated attack database is set, and at least e simulation formula methods (i.e., a preset number of simulated attack methods in the present invention) are selected from the preset simulated attack database to perform network simulated attacks; 2. The attack is continued for at least a preset time t, and then the time required for breaking through the e simulated attack methods is recorded (when the attack is not broken within the preset time t, the breaking time is equal to t), and e breaking time information is obtained (i.e., multiple breaking time in the present invention); 3. The mean of the e breaking time information is calculated, that is, the average breaking time is obtained (wherein, e≥3); 4. When the average breaking time is less than the preset value b1 (i.e., the third preset value in the present invention), a third-level protection evaluation is generated; when the average breaking time is between the preset value b1 and b2 (i.e., the fourth preset value in the present invention), a second-level protection evaluation is generated; when the average breaking time is greater than the preset value b2, a first-level protection evaluation is generated, where b1<b2.
[0083] A level one protection assessment means that the protection effect of the 5G network is good; a level two protection assessment means that the protection effect of the 5G network is average and needs to be optimized regularly; a level three protection assessment means that the protection effect of the 5G network is poor and protection measures need to be optimized immediately.
[0084] Simulating attacks on the network has the following benefits: 1. Discovering security issues: Simulating attacks can set attack scenarios on demand and simulate various common attack methods, so as to better discover security issues in systems and software, which helps to identify and resolve potential security risks without being harmed by actual attacks. 2. Enhance early warning capabilities: Through simulated attacks, real attacks can be identified and intercepted in advance, and the early warning capabilities of network security can be enhanced. This capability helps companies to respond quickly and reduce potential losses when facing real attacks. 3. Improve employee safety awareness: Simulating attacks can help companies improve employees' safety awareness and emergency response capabilities without being harmed by actual attacks. This can not only enhance employees' attention to network security, but also help improve the security prevention level of the entire company. 4. Evaluate defense strategies and security mechanisms: Simulating attacks can help companies evaluate and improve their own defense strategies and security mechanisms to adapt to increasingly complex and diverse forms of network attacks, which helps companies better respond to changing network threats and improve the overall security of the network.
[0085] It should be noted that simulated attacks cannot completely replace the detection effect of actual attacks, because simulated attacks may not be able to fully reproduce all the details and potential impacts of real attacks. Therefore, in terms of network security, the comprehensive use of multiple methods for detection and protection is a more comprehensive and effective strategy.
[0086] Step S30: Obtain access network information, and calculate the access assessment level according to the access network information to obtain third assessment information. The access network information includes the number of users accessing the network and the historical access times of a single access user; the third assessment information includes a first-level access assessment, a second-level access assessment, and a third-level access assessment.
[0087] The access network information includes the number of users accessing the network and the historical access times of a single access user. The present invention identifies the first-category users, the second-category users and the third-category users by processing the historical access times of each access user.
[0088] Specifically, the number of users accessing the network and the historical access times of a single access user are obtained, and a first preset number and a second preset number are determined, wherein the first preset number is greater than the second preset number; if the historical access times of the single access user are greater than the first preset number, the single access user is determined to be a Class I user; if the historical access times of the single access user are less than the first preset number and greater than the second preset number, the single access user is determined to be a Class II user; if the historical access times of the single access user are less than the second preset number, the single access user is determined to be a Class III user; and an access evaluation parameter is calculated according to the number of users accessing the network, the number of Class I users, the number of Class II users, and the number of Class III users using a second preset formula.
[0089] The access network information includes the number of users accessing the network and the historical access times of a single access user. The historical access times of each access user are processed to obtain Class I users, Class II users and Class III users. The specific classification steps are as follows: 1. When the historical access times of a single access user are greater than the preset value times c1 (i.e., the first preset times in the present invention), it is classified as a Class I user; 2. When the historical access times of a single access user are between the preset values times c1 and c2 (i.e., the second preset times in the present invention), it is classified as Class II times; when the historical access times of a single access user are less than the preset value times c2, it is classified as Class III times; 4. The number of Class I users is extracted and marked as H1, the number of Class II users is marked as H2, the number of Class III users is marked as H3, and the number of users accessing the network is marked as F. The access evaluation parameter Hh is obtained by the formula H1 / F-(H2 / F+H3 / F)=Hh (i.e., the second preset formula in the present invention).
[0090] Determine a fifth preset value and a sixth preset value, wherein the fifth preset value is greater than the sixth preset value; if the access assessment parameter is greater than the fifth preset value, generate a first-level access assessment; if the access assessment parameter is greater than the sixth preset value and less than the fifth preset value, generate a second-level access assessment; if the access assessment parameter is less than the sixth preset value, generate a third-level access assessment.
[0091] It can be understood that when the access evaluation parameter is greater than the preset value d1 (i.e., the fifth preset value in the present invention), a first-level access evaluation is generated; when the access evaluation parameter is between the preset value d1 and d2 (i.e., the sixth preset value in the present invention), a second-level access evaluation is generated; when the access evaluation parameter is less than the preset value d2, a third-level access evaluation is generated (where d2 < d1).
[0092] Level 1 access assessment means that access users are stable and the risk is relatively low; level 2 access assessment means that access users are average and there is a certain risk; level 3 access assessment means that access users are unstable and there is a greater risk.
[0093] Step S40, obtaining network device information, and performing hardware level evaluation calculation based on the network device information to obtain fourth evaluation information. The network device information includes network hardware temperature information and network hardware environment dust concentration; the fourth evaluation information includes first-level hardware evaluation, second-level hardware evaluation, and third-level hardware evaluation.
[0094] Specifically, the network hardware temperature information and the dust concentration of the network hardware environment are obtained, and a seventh preset value is determined; if the network hardware temperature information and the dust concentration of the network hardware environment are both less than the seventh preset value, a first-level hardware evaluation is generated; if the network hardware temperature information or the dust concentration of the network hardware environment is greater than the seventh preset value, a second-level hardware evaluation is generated; if the network hardware temperature information and the dust concentration of the network hardware environment are both greater than the seventh preset value, a third-level hardware evaluation is generated.
[0095] When the network hardware temperature information and the network hardware environment dust concentration are both less than the preset value (i.e., the seventh preset value in the present invention), a first-level hardware evaluation is generated; when either the network hardware temperature information or the network hardware environment dust concentration is greater than the preset value (i.e., the seventh preset value in the present invention), a second-level hardware evaluation is generated; when the network hardware temperature information and the network hardware environment dust concentration are both greater than the preset value (i.e., the seventh preset value in the present invention), a third-level hardware evaluation is generated.
[0096] It is understandable that the first-level hardware evaluation means that the environment of the hardware terminal of the 5G network is normal; the second-level hardware evaluation means that the hardware terminal of the 5G network is abnormal and needs regular maintenance; the third-level hardware evaluation means that the environment of the hardware terminal of the 5G network is poor and needs immediate inspection and maintenance. For example, network equipment and servers generate heat during operation. In order to dissipate this heat, active heat dissipation is usually used to dissipate the heat. Due to the small space in the computer room, these devices usually use air cooling to dissipate heat. The heat dissipation holes cooperate with the convection air to bring dust into the equipment. Dust will carry moisture and corrosive substances into the equipment, cover the electronic components, causing the heat dissipation capacity of the electronic components to decrease, and long-term accumulation of a large amount of heat will cause the equipment to work unstably. Because the dust contains moisture and corrosive substances, the insulation resistance between adjacent printed wires decreases, or even short-circuits, affecting the normal operation of the circuit, and even seriously burning the power supply, motherboard and other equipment components. In addition, when too much dry dust enters the equipment, it will play an insulating role, directly leading to poor contact between the connector contacts. At the same time, it will increase the frictional resistance of the equipment's movement, which may accelerate the wear of the equipment at the least, or directly cause the equipment to get stuck and damaged at the worst. Therefore, it is very necessary to regularly maintain the network hardware.
[0097] Step S50: Obtain a network security status assessment result according to the first assessment information, the second assessment information, the third assessment information, and the fourth assessment information.
[0098] After obtaining the first evaluation information, the second evaluation information, the third evaluation information and the fourth evaluation information, the present invention will have a comprehensive understanding of the current network security status and formulate corresponding processing measures based on the evaluation results to maintain and improve the network security status and ensure the normal operation of the 5G network.
[0099] In summary, the present invention realizes a comprehensive network security status evaluation of the 5G network by processing the network status information, access network information, simulated attack information and network equipment information to generate the first evaluation information, the second evaluation information, the third evaluation information and the fourth evaluation information. Among them, through the generated first evaluation information, the actual network status of the 5G network can be understood, so as to timely find out whether there is abnormal fluctuation or abnormal packet loss rate in the network, thereby ensuring the network security of the 5G network; through the generated second evaluation information, it can be understood whether the security of the 5G network is in place, and the protection weaknesses of the 5G network can be understood through simulated attacks, so as to update the corresponding network security protection means, and better ensure the network security of the 5G network; through the generated third evaluation information, the user status of the 5G network can be understood, and the more new users accessed, the more risks the 5G network faces, thereby reminding the network management personnel to deploy different network security protections according to the status of the accessed users; through the generated fourth evaluation information, the status of the hardware equipment of the 5G network can be understood, and whether the network hardware is overheated or dusty, etc., causing network fluctuations to affect network security, thereby realizing a more comprehensive evaluation and protection of the installation status of the 5G network, making the system more worthy of promotion and use.
[0100] Furthermore, if Figure 3 As shown, based on the above-mentioned network security status assessment method based on 5G network, the present invention also provides a network security status assessment system based on 5G network, wherein the network security status assessment system based on 5G network includes:
[0101] A first evaluation information generating module 51 is used to obtain network status information and calculate a network information evaluation level according to the network status information to obtain first evaluation information;
[0102] A second evaluation information generating module 52 is used to obtain simulated attack information, and calculate the protection evaluation level according to the simulated attack information to obtain second evaluation information;
[0103] A third evaluation information generating module 53 is used to obtain access network information and calculate the access evaluation level according to the access network information to obtain third evaluation information;
[0104] The fourth evaluation information generating module 54 is used to obtain network device information and perform hardware level evaluation calculation according to the network device information to obtain fourth evaluation information;
[0105] The evaluation result generating module 55 is used to obtain a network security status evaluation result according to the first evaluation information, the second evaluation information, the third evaluation information and the fourth evaluation information.
[0106] Furthermore, if Figure 4 As shown, based on the above-mentioned 5G network-based network security status assessment method and system, the present invention also provides a terminal accordingly, and the terminal includes a processor 10, a memory 20 and a display 30. Figure 4 Only some components of the terminal are shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.
[0107] In some embodiments, the memory 20 may be an internal storage unit of the terminal, such as a hard disk or memory of the terminal. In other embodiments, the memory 20 may also be an external storage device of the terminal, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (SecureDigital, SD) card, a flash card (Flash Card), etc. equipped on the terminal. Further, the memory 20 may also include both an internal storage unit of the terminal and an external storage device. The memory 20 is used to store application software and various types of data installed on the terminal, such as the program code of the installation terminal. The memory 20 may also be used to temporarily store data that has been output or is to be output. In one embodiment, a network security status assessment program 40 based on a 5G network is stored on the memory 20, and the network security status assessment program 40 based on a 5G network can be executed by the processor 10, thereby realizing the network security status assessment method based on a 5G network in the present application.
[0108] In some embodiments, the processor 10 may be a central processing unit (CPU), a microprocessor or other data processing chip, used to run the program code or process data stored in the memory 20, such as executing the 5G network-based network security status assessment method.
[0109] In some embodiments, the display 30 may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, an OLED (Organic Light-Emitting Diode) touch device, etc. The display 30 is used to display information on the terminal and to display a visual user interface. The terminals communicate with each other via a system bus.
[0110] In one embodiment, when the processor 10 executes the 5G network-based network security status assessment program 40 in the memory 20, the steps of the 5G network-based network security status assessment method as described above are implemented.
[0111] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a network security status assessment program based on a 5G network, and when the network security status assessment program based on a 5G network is executed by a processor, the steps of the network security status assessment method based on a 5G network as described above are implemented.
[0112] In summary, the present invention provides a network security status assessment method, system and terminal based on 5G network, the method comprising: obtaining network status information, and calculating the network information assessment level according to the network status information to obtain first assessment information; obtaining simulated attack information, and calculating the protection assessment level according to the simulated attack information to obtain second assessment information; obtaining access network information, and calculating the access assessment level according to the access network information to obtain third assessment information; obtaining network equipment information, and calculating the hardware level assessment according to the network equipment information to obtain fourth assessment information; obtaining network security status assessment results according to the first assessment information, the second assessment information, the third assessment information and the fourth assessment information. The present invention can achieve comprehensive assessment and protection of the 5G network security status by obtaining network status information, simulated attack information, access network information and network equipment information, and performing level assessment processing on these information, and effectively ensures the network security of the 5G network.
[0113] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or terminal including the element.
[0114] Of course, those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing related hardware (such as a processor, a controller, etc.) through a computer program, and the program can be stored in a computer-readable storage medium that can be read by a computer, and the program can include the processes of the above-mentioned method embodiments when executed. The computer-readable storage medium can be a memory, a disk, an optical disk, etc.
[0115] It should be understood that the application of the present invention is not limited to the above examples. For ordinary technicians in this field, improvements or changes can be made based on the above description. All these improvements and changes should fall within the scope of protection of the claims attached to the present invention.
Claims
1. A network security status assessment method based on 5G network, characterized in that: The 5G network-based network security status assessment method includes: Acquiring network status information, and calculating a network information evaluation level according to the network status information to obtain first evaluation information; Acquire simulated attack information, and calculate a protection assessment level according to the simulated attack information to obtain second assessment information; Acquiring access network information, and calculating an access assessment level according to the access network information to obtain third assessment information; Acquire network device information, and perform hardware level evaluation calculation according to the network device information to obtain fourth evaluation information; A network security status assessment result is obtained according to the first assessment information, the second assessment information, the third assessment information and the fourth assessment information.
2. The method for evaluating network security status based on 5G network according to claim 1, characterized in that: The network status information includes network delay information and network packet loss information; The acquiring of network status information and calculating a network information evaluation level according to the network status information to obtain first evaluation information specifically includes: Collect network delay information and network packet loss information at preset intervals to obtain multiple network delay information and multiple network packet loss information; Performing adjacent network delay information difference calculation and absolute value calculation on the plurality of network delay information to obtain a first evaluation parameter; Calculate the average of the plurality of network packet loss information to obtain a second evaluation parameter; A first preset formula is used to calculate a comprehensive evaluation parameter according to the first evaluation parameter and the second evaluation parameter, and first evaluation information is obtained according to the comprehensive evaluation parameter.
3. The method for evaluating network security status based on 5G network according to claim 2, characterized in that: The first evaluation information includes first-level evaluation information, second-level evaluation information and third-level evaluation information; The obtaining of the first evaluation information according to the comprehensive evaluation parameter specifically includes: Determine a first preset value and a second preset value, wherein the first preset value is greater than the second preset value; If the comprehensive evaluation parameter is greater than the first preset value, generating the first-level evaluation information; If the comprehensive evaluation parameter is greater than the second preset value and less than the first preset value, generating the secondary evaluation information; If the comprehensive evaluation parameter is less than the second preset value, the third-level evaluation information is generated.
4. The method for evaluating network security status based on 5G network according to claim 1, characterized in that: The second assessment information includes a first-level protection assessment, a second-level protection assessment, and a third-level protection assessment; The acquiring of simulated attack information and calculating the protection evaluation level according to the simulated attack information to obtain second evaluation information specifically includes: Determine a preset simulated attack database, and select a preset number of simulated attack modes from the preset simulated attack database; Performing a network simulated attack according to each of the simulated attack methods, and obtaining the corresponding attack duration when each simulated attack method is successfully attacked, thereby obtaining multiple attack durations; Calculate the average of the multiple break-through times to obtain an average break-through time; Determining a third preset value and a fourth preset value, wherein the third preset value is smaller than the fourth preset value; If the average attack time is greater than the fourth preset value, a first-level protection assessment is generated; If the average breach time is greater than the third preset value and less than the fourth preset value, a level 2 protection assessment is generated; If the average attack duration is less than the third preset value, a third-level protection assessment is generated.
5. The method for evaluating network security status based on 5G network according to claim 1, characterized in that: The access network information includes the number of users accessing the network and the historical access times of a single access user; The acquiring of access network information, and calculating the access assessment level according to the access network information to obtain third assessment information specifically includes: Acquire the number of users accessing the network and the historical access times of a single access user, and determine a first preset number and a second preset number, wherein the first preset number is greater than the second preset number; If the historical access times of the single access user are greater than the first preset times, determining that the single access user is a first-class user; If the historical access times of the single access user are less than the first preset times and greater than the second preset times, the single access user is determined to be a second-category user; If the historical access times of the single access user are less than the second preset times, determining that the single access user is a third type user; An access evaluation parameter is calculated according to the number of users accessing the network, the number of users of the first category, the number of users of the second category, and the number of users of the third category using a second preset formula, and third evaluation information is obtained according to the access evaluation parameter.
6. The method for evaluating network security status based on 5G network according to claim 5, characterized in that: The third evaluation information includes a first-level access evaluation, a second-level access evaluation, and a third-level access evaluation; The obtaining the third evaluation information according to the access evaluation parameter specifically includes: Determining a fifth preset value and a sixth preset value, wherein the fifth preset value is greater than the sixth preset value; If the access assessment parameter is greater than the fifth preset value, generating a first-level access assessment; If the access assessment parameter is greater than the sixth preset value and less than the fifth preset value, generating a secondary access assessment; If the access assessment parameter is less than the sixth preset value, a third level access assessment is generated.
7. The method for evaluating network security status based on 5G network according to claim 1, characterized in that: The network equipment information includes network hardware temperature information and network hardware environment dust concentration; the fourth evaluation information includes first-level hardware evaluation, second-level hardware evaluation and third-level hardware evaluation; The acquiring of network device information and performing hardware level evaluation calculation according to the network device information to obtain fourth evaluation information specifically includes: Acquire the network hardware temperature information and the network hardware environment dust concentration, and determine a seventh preset value; If the network hardware temperature information and the network hardware environment dust concentration are both less than the seventh preset value, generating a first-level hardware assessment; If the network hardware temperature information or the network hardware environment dust concentration is greater than the seventh preset value, generating a secondary hardware assessment; If the network hardware temperature information and the network hardware environment dust concentration are both greater than the seventh preset value, a third-level hardware evaluation is generated.
8. A network security status assessment system based on 5G network, characterized in that: The network security status assessment system based on 5G network includes: A first evaluation information generating module, used to obtain network status information, and calculate a network information evaluation level according to the network status information to obtain first evaluation information; A second evaluation information generating module is used to obtain simulated attack information, and calculate the protection evaluation level according to the simulated attack information to obtain second evaluation information; A third evaluation information generating module, used to obtain access network information, and calculate the access evaluation level according to the access network information to obtain third evaluation information; A fourth evaluation information generating module, used to obtain network device information, and perform hardware level evaluation calculation according to the network device information to obtain fourth evaluation information; An assessment result generating module is used to obtain a network security status assessment result according to the first assessment information, the second assessment information, the third assessment information and the fourth assessment information.
9. A terminal, characterized in that: The terminal includes: a memory, a processor, and a 5G network-based network security status assessment program stored in the memory and executable on the processor. When the 5G network-based network security status assessment program is executed by the processor, the steps of the 5G network-based network security status assessment method as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a 5G network-based network security status assessment program, and when the 5G network-based network security status assessment program is executed by a processor, the steps of the 5G network-based network security status assessment method as described in any one of claims 1-7 are implemented.