Network security situation awareness method based on adaptive algorithm

By collecting and preprocessing the log information and exception alarm records of network equipment, using machine learning models for deep feature extraction and abnormal behavior recognition, and dynamically adjusting model parameters through real-time updated historical data analysis results and adaptive threshold settings, the inefficiency of network security situation awareness methods in the existing technology in dealing with large-scale data and quickly identifying abnormal behaviors is solved, and more efficient threat recognition and response is achieved.

CN119966658APending Publication Date: 2025-05-09SHANGHAI ARTIFICIAL INTELLIGENCE NETWORK SYST ENG TECH RES CENT CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202411924851.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The existing network security situation awareness method based on adaptive algorithms has inefficient problems in handling large-scale network security data and quickly identifying abnormal behaviors, resulting in insufficient threat response speed and insufficient identification accuracy.

Method used

By collecting and preprocessing the log information and abnormal alarm records of network equipment, the machine learning model is used to deeply extract and abnormal behavior recognition of network security data, and dynamically adjust the machine learning model parameters through real-time updated historical data analysis results and adaptive threshold settings to optimize recognition accuracy and response speed.

Benefits of technology

It improves the ability to identify potential cyber threats, reduces the occurrence of false alarms and underreports, enhances the ability to respond to complex attack modes, and significantly improves the defense efficiency of cyber attacks and the timeliness of early warnings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966658A_ABST
    Figure CN119966658A_ABST
Patent Text Reader

Abstract

The invention discloses a network security situation awareness method based on an adaptive algorithm, and the method comprises the steps: S1, collecting and preprocessing original log information and abnormal alarm records from a plurality of network devices to form structured network security data, s2, distinguishing normal behavior patterns and abnormal activities in the structured network security data based on a machine learning model, and performing deep feature extraction to identify potential security threats and attack behaviors, s3, dynamically adjusting machine learning model parameters and optimizing recognition accuracy based on a real-time updated historical data analysis result and self-adaptive adjustment threshold setting; according to the network security situation awareness method based on the adaptive algorithm, the overall network security situation awareness capability is improved, the defense efficiency of network attacks and the timeliness of early warning are remarkably improved, and the problems of how to improve the accuracy of abnormal behavior recognition and accelerate the threat response speed are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field, and in particular to a network security situation awareness method based on an adaptive algorithm. Background Art

[0002] As the complexity and frequency of cyber attacks continue to increase, traditional network security protection methods have gradually exposed their shortcomings and are unable to cope with rapidly changing attack patterns and emerging threats. In order to improve network protection capabilities, a network security situation awareness method based on adaptive algorithms has emerged. This method uses machine learning or artificial intelligence technology to dynamically adjust model parameters to enhance the system's adaptability in detecting and preventing network attacks. Specifically, the system collects various types of behavioral data in the network, processes and analyzes the data in real time based on adaptive algorithms to identify abnormal behaviors, detect potential threats, and quickly adjust defense strategies when new attacks are discovered, thereby effectively improving network security situation awareness capabilities.

[0003] However, in practical applications, the network security situation awareness method based on adaptive algorithms also faces some challenges. First, how to efficiently process and analyze large-scale network security data, especially the need to process a large amount of complex network behavior data in real time, which places high demands on the computing power of the system. Secondly, there are still certain limitations in the automatic classification and identification of abnormal behaviors, which may lead to the identification of potential threats not being timely or accurate enough, and prolonging the response time of early warning and defense measures. Since the effectiveness of early warning and the implementation of defense strategies may lag behind the actual changes in attacks, the overall effect and response efficiency of network security situation awareness may be affected in some cases. Therefore, how to improve the accuracy of abnormal behavior identification and speed up threat response has become an urgent problem to be solved. Summary of the invention

[0004] The purpose of the present invention is to provide a network security situation awareness method based on an adaptive algorithm to solve the problem of how to improve the accuracy of abnormal behavior identification and speed up threat response.

[0005] To achieve the above object, the present invention provides the following technical solution: a network security situation awareness method based on an adaptive algorithm, the method comprising:

[0006] S1: Collect and pre-process raw log information and abnormal alarm records from multiple network devices to form structured network security data;

[0007] S2: distinguishing normal behavior patterns and abnormal activities in the structured network security data based on a machine learning model and performing deep feature extraction to identify potential security threats and attack behaviors;

[0008] S3: Dynamically adjust machine learning model parameters and optimize recognition accuracy based on real-time updated historical data analysis results and adaptive threshold settings;

[0009] S4: Build an interactive visualization platform to display the real-time status of network threats and generate intelligent defense strategy recommendations based on analysis results, as well as provide early warning services for advanced persistent threats to enhance security decision-making support mechanisms.

[0010] Preferably, in the step of dynamically adjusting the machine learning model parameters and optimizing the recognition accuracy based on the real-time updated historical data analysis results and the adaptively adjusted threshold settings, the anomaly score calculation formula is: [the current data point anomaly score is the absolute value of the difference between the current data and the historical average divided by the standard deviation], where the current data is the observation value in the most recent time window.

[0011] Preferably, the distinguishing normal behavior patterns and abnormal activities in the structured network security data based on the machine learning model and performing deep feature extraction to identify potential security threats and attack behaviors includes:

[0012] Collect unstructured network security data and structured network security data and perform pre-processing;

[0013] Extract the features of pre-processed unstructured network security data and structured network security data, and use machine learning algorithms to train threat detection models to make a primary judgment (differentiation) between normal behavior and abnormal activities;

[0014] Perform incremental feature extraction on unstructured network security data after a judgment (differentiation);

[0015] Input the incrementally extracted features, train the threat detection model, and make secondary judgments (differentiation) on the original data;

[0016] The differences between the first and second judgments are counted and analyzed for setting adaptive thresholds and dynamically adjusting machine learning model parameters to accurately identify potential security threats and attack behaviors.

[0017] Preferably, the dynamically adjusting the machine learning model parameters based on the real-time updated historical data analysis results and the adaptively adjusted threshold settings includes:

[0018] Collect information on the results of historical data analysis;

[0019] Set adaptive thresholds for dynamic adjustment;

[0020] Adjust the machine learning model based on the information and the set parameters;

[0021] If the current error is less than the preset value P, the model remains stable.

[0022] Preferably, in the step of setting an adaptive threshold for dynamic adjustment:

[0023] Initialize the threshold;

[0024] Increase or decrease a small value △V according to the change trend of the data;

[0025] Apply the new threshold to the data adjustment process;

[0026] If the system response speed R exceeds the predetermined speed standard S, reduce the adjustment increment.

[0027] Preferably, the applying the new threshold to the data adjustment process specifically refers to:

[0028] Use the new threshold T to adjust the machine learning model parameter w;

[0029] Calculate the score Q of the model performance after applying the new threshold;

[0030] Compare whether the score Q is greater than or equal to the reference score B;

[0031] When the score meets the condition Q≥B, confirm the threshold adjustment effect.

[0032] Preferably, when the score after calculating the new model parameter does not meet the condition, i.e., Q<B:

[0033] Call the fallback program to restore to the previous parameter setting P;

[0034] Continue to process the new security event data X using the restored parameters;

[0035] Evaluate the feedback value F based on the actual effect after processing;

[0036] If F reaches the ideal effect standard L, confirm the effectiveness of this step.

[0037] From the above technical solutions, it can be seen that the present invention has the following beneficial effects:

[0038] The network security situation awareness method based on the adaptive algorithm collects and preprocesses raw log information and abnormal alarm records from multiple network devices to form structured network security data, distinguishes normal behavior patterns and abnormal activities in the structured network security data based on a machine learning model and performs deep feature extraction to identify potential security threats and attack behaviors, dynamically adjusts machine learning model parameters and optimizes recognition accuracy based on real-time updated historical data analysis results and adaptively adjusted threshold settings, builds an interactive visualization platform to display the real-time status of network threats and generate intelligent defense strategy recommendations based on analysis results, and provides early warning services for advanced persistent threats to enhance the security decision-making support mechanism, improves the ability to identify potential network threats, reduces the occurrence of false alarms and missed alarms, improves the ability to respond to complex attack patterns, improves the overall network security situation awareness capability, significantly improves the defense efficiency of network attacks and the timeliness of early warnings, and solves the problem of how to improve the accuracy of abnormal behavior identification and speed up threat response. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0040] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0041] like Figure 1 As shown, a network security situation awareness method based on an adaptive algorithm comprises:

[0042] S1: Collect and pre-process raw log information and abnormal alarm records from multiple network devices to form structured network security data;

[0043] S2: distinguishing normal behavior patterns and abnormal activities in the structured network security data based on a machine learning model and performing deep feature extraction to identify potential security threats and attack behaviors;

[0044] S3: Dynamically adjust machine learning model parameters and optimize recognition accuracy based on real-time updated historical data analysis results and adaptive threshold settings;

[0045] S4: Build an interactive visualization platform to display the real-time status of network threats and generate intelligent defense strategy recommendations based on analysis results, as well as provide early warning services for advanced persistent threats to enhance security decision-making support mechanisms.

[0046] First, log files from multiple network devices including firewalls, IDS systems, and various router switches, as well as existing network anomaly alarm records, are collected and preprocessed. After a series of operations such as cleaning, denoising, and unified formatting, these initial data are formed into a structured network security data set that can be used to directly carry out further work. At this stage, invalid or unclear information will be excluded to reduce the burden of subsequent work.

[0047] Then, based on the machine learning method, the collected data is studied in depth to find out the state characteristics of the system operation under normal conditions. By setting corresponding rules, those behaviors that are significantly different from the general rules are regarded as abnormalities, so as to locate the operation actions that may have security risks. This part is the core. By introducing the machine self-learning concept in artificial intelligence, a variety of parameter bases that can effectively help distinguish between legitimate traffic and attacker behavior are extracted in the mining of massive historical information. These factors can more accurately distinguish which behaviors in daily operations need to be paid attention to, and this process is still in the process of continuous improvement because after each execution of this step, the system will autonomously analyze the results to improve the judgment level, paving the way for providing better quality warning work in the future. For example, for a typical DDoS attack scenario, the present invention can use the above process to quickly identify the differences between a large number of illegal access attempts and normal user access, and optimize the classification effect by continuously learning new DDoS features to ensure that even variant methods can be intercepted in the first time.

[0048] Then, based on the knowledge gained from the previous round of detection and the trend analysis updated in real time, the relevant machine learning parameters are adjusted to more efficiently track the development of malicious events while ensuring that the basic judgment is correct. The corresponding thresholds are flexibly changed according to these changes, so that even in the face of constantly changing new situations, corresponding modifications can be made in time to avoid missing important intelligence. Through this step, the solution ensures that threats can be closely tracked on the one hand, and overreactions can be prevented on the other hand, resulting in unnecessary warning floods, while also allowing the system to better adapt to today's complex and rapidly changing online environment.

[0049] In the final stage, a set of interactive graphic display interfaces is built. This tool can present the network security situation in the form of charts or numbers on the screen, allowing managers to intuitively understand the current situation in the entire network domain and make targeted improvement suggestions to users after combining the specific intelligence information obtained previously. For example, for a long-standing and highly hidden hacker team infiltration attempt currently discovered, it can remind relevant departments to deploy more enhanced protection software in a timely manner to prevent it from causing more serious damage. At the same time, it can also predict other means that the other party may use next based on the information collected, so as to build a good defense line in advance to achieve twice the result with half the effort. Ultimately, through this process, the ability of relevant personnel to face various crises can be greatly enhanced to achieve the security function of the entire chain and be able to respond to changes quickly.

[0050] In this way, this network security situational awareness technology can not only meet actual needs but also continue to evolve and adapt to more complex and dangerous forms in the future.

[0051] The method of distinguishing normal behavior patterns and abnormal activities in the structured network security data based on a machine learning model and performing deep feature extraction to identify potential security threats and attack behaviors includes:

[0052] Collect unstructured network security data and structured network security data and perform pre-processing;

[0053] Extract the features of pre-processed unstructured network security data and structured network security data, and use machine learning algorithms to train threat detection models to make a primary judgment (differentiation) between normal behavior and abnormal activities;

[0054] Perform incremental feature extraction on unstructured network security data after a judgment (differentiation);

[0055] Input the incrementally extracted features, train the threat detection model, and make secondary judgments (differentiation) on the original data;

[0056] Count and analyze the differences between the first and second judgments for setting adaptive thresholds and dynamically adjusting machine learning model parameters to accurately identify potential security threats and attack behaviors

[0057] Next, the specific steps of dynamically adjusting the machine learning model parameters and optimizing the recognition accuracy based on the real-time updated historical data analysis results and the adaptively adjusted threshold settings are described, using the anomaly score calculation formula: [The current data point anomaly score is the absolute value of the difference between the current data and the historical average divided by the standard deviation], where the current data is the observation value in the most recent time window, and its value range is 0 to 100, and the optimal value range is 0 to 10; the historical average is calculated based on the data of the past week, and the value range is the same as the current data; the standard deviation is calculated based on the historical data of the same period, and the minimum non-zero positive number is usually the optimal value of 0.1 or more. In this process, an appropriate time window length is first determined, such as selecting the past hour or day, to ensure that the data can reflect the changes in real time and quickly; all network activity-related data collected during this time period are used as the current data point. Next, by analyzing the numerical range of the data obtained during this time, ensure that it is between 0 and 100, and the best case is to keep it within a smaller value such as 0 to 10.

[0058] Secondly, the average of similar network activity observations collected in the past week will be calculated, which is defined as the historical average. Its value is also between 0 and 100, and is used to provide a long-term reference point to evaluate whether the current observations have changed significantly relative to this long time series; the standard deviation is the value calculated based on all collected network activity data points in the same week in the past. This value is the smallest positive real number greater than zero to avoid possible division by zero errors in subsequent operations.

[0059] After this stage, the above-mentioned anomaly score calculation formula is used to quantify the degree of anomaly in the data point. Specifically, the difference is obtained by subtracting the previously defined historical average from the current real-time network data (the positive value of the difference is proportional to the trend change of the data), and then the absolute value of the difference is divided by the previously calculated historical standard deviation. This operation is done in order to obtain a dimensionless way to compare whether the current behavior pattern is significantly different from the long-term trend, and the result is the anomaly score of the data point in a given period of time.

[0060] To illustrate this process with an example, we assume that the current data value is 70, observed within one hour, and the historical average value of the historical one-week data set is 10, and the historical standard deviation is calculated to be approximately 3 (here it has been simplified to an integer for easy understanding). Then the result obtained according to this calculation formula is 60 (equal to 70-10) absolute value, which is 60, and the result of further division by 3 is approximately 20 points. This means that if this anomaly score is adopted by the final model, the model will be adjusted according to such a score to make more accurate behavior recognition in the future. Such a score setting helps to adaptively and dynamically optimize parameter adjustments in machine learning models and helps to improve recognition accuracy.

[0061] Next, the specific steps of distinguishing normal behavior patterns and abnormal activities in the structured network security data based on the machine learning model and performing deep feature extraction to identify potential security threats and attack behaviors are described. First, collecting structured network security data means collecting various types of network traffic information of the enterprise and formatting them into structured data, such as obtaining information on switch port usage through the Simple Network Management Protocol or reading specific formatted security events from server logs; this step involves data format conversion and normalization, such as unifying timestamps to UTC format. A specific example is to record all inbound traffic packets through network probes installed on routers and store them in a relational database for subsequent data processing.

[0062] Secondly, use the pre-processed historical data to train the machine learning algorithm through supervised learning methods (such as decision tree classifiers, random forests, or support vector machines) to distinguish which network behaviors belong to normal daily business operations and which are considered potential abnormal activities. This step may require defining a normal state data set and some known attack patterns as the basis for model learning, which usually involves indicators such as accuracy, precision, and recall to optimize the effect of machine learning. Precision is used to measure the probability of correct warnings. The goal is to reduce the number of false alarms while not ignoring real security incidents. Ideally, we should strive to achieve an ideal ratio close to 1; but in reality, we need to make compromises and adjust the training threshold according to actual application needs.

[0063] Next, we use deep learning architectures such as neural networks to dig deeper into the abnormal phenomena initially identified by machine learning, try to capture more subtle, high-level related clues and automatically extract key patterns that are helpful for further classification and judgment (for example, a sudden increase in IP access frequency or an unknown request type). This process usually includes pre-training network layers to abstract feature representations and then tuning or adding custom modules (such as convolutional units, which are particularly important in time series features) to improve performance; taking deep neural networks as an example, large-scale models with multiple hidden layers and a large number of parameters can be used at this stage. These parameters will be iteratively adjusted during training until the loss function reaches the lowest point, which means that the model output should be as close to the true label value as possible. The parameters represent the connection weights and bias terms, and the function E is the error evaluation rule, with the minimum square loss L(x,y)=sum(yf(x)) 2 .

[0064] Finally, based on the knowledge gained in the above two stages, we can identify specific forms of network attacks or other high-risk hidden dangers (such as SQL injection attempts, DDoS flooding, abuse of internal privileged accounts, etc.), and formulate targeted countermeasures by building dynamic strategies or rule sets in combination with actual scenarios. In this case, we can use the behavioral baseline generated in the previous stage to discover any deviations from the norm and map it to the threat category database to find a match. If the monitoring system detects that a host sends a large number of ICMP requests to the outside, it may be determined that this wave meets the characteristics of a distributed denial of service attack based on the feature analysis results, and then take actions to limit the flow and block the host. The entire process also needs to consider details such as the robustness of the algorithm, update frequency, and compatibility and integration with the existing architecture.

[0065] Next, the specific steps for dynamically adjusting the parameters of the machine learning model based on the real-time updated historical data analysis results and the adaptively adjusted threshold settings are described. First, it is necessary to collect information on the historical data analysis results, which refers to the aggregation and processing of previous network behaviors, abnormal activities, and related logs into a form that can be used for analysis; this process involves the preliminary screening and formatting of large amounts of data in order to further mine useful features. Secondly, an adaptive threshold that changes dynamically under initial conditions is set. In this field, this value is customized according to different network environments, data characteristics, etc. It defines a standard to measure when to revise the learning model.

[0066] Then, based on the above two inputs, the parameter values ​​in the original machine learning framework are adjusted and optimized according to the real-time updated data flow and the set variability limits, that is, online learning methods such as small batch stochastic gradient descent (SGD) are used to make the new model more accurately reflect the latest changes in network security situation. If the number of misclassifications or loss function values ​​detected in a certain situation is at a low level (less than a certain pre-defined good or bad indicator P), the system will consider the current model to be satisfactory and will not make changes to ensure the relative stability and coherent operation of the system, without having to trigger unnecessary algorithm readjustment or retraining every time the data is updated.

[0067] Taking the DDoS attack detection system as an example, assume that the latest attack report and normal traffic data are received every five minutes as the accumulation of historical information; then, according to the past false alarm rate or the detection frequency of true positives (for example, 90% to 95% is taken as the target TPR), the dynamic response level is set (equivalent to the adaptive adjustment threshold mentioned above), and finally, a self-adaptive learning technology such as support vector machine (SVM) is used to re-estimate the attack pattern characteristics and modify the original SVM weight distribution according to the latest information. If a new parameter combination is found that can improve the recognition performance while maintaining the number of false alarms at an acceptable level, then they will be adopted.

[0068] When adjusting, we can select from a series of possible candidates those that make the target loss function E for the current observation data H t The position where the value is minimized; the determination of the loss function should take into account the quantitative form of the prediction error and the specific needs of the business. Such an update rule is chosen because it is hoped that the machine-learned model can make a more rapid and accurate response mechanism design for unknown challenges.

[0069] Next, the steps of setting the adaptive threshold for dynamic adjustment of the present invention are described as follows: initializing the threshold; increasing or decreasing a small value △V according to the change trend of the data; applying the new threshold to the data adjustment process; if the system response speed R exceeds the predetermined speed standard S, then reducing the specific steps of the adjustment increment. The first step is to initialize the threshold, which is a process of setting the initial value, which is crucial in the adaptive algorithm. The initial value can be determined based on the empirical value or estimated based on the previous time data. For example, when the system is first deployed, the threshold may be set to an average value of the historical network activity level or a standard for the frequency of abnormal data. The second step is to dynamically determine the change of the threshold based on the trend of the data, such as the network data volume or access log information. When an increase in traffic or other indicators is detected, the decimal increment △V is increased to relax the detection rules so that more behaviors are considered compliant; on the contrary, if these change indicators decrease, the rules are tightened by subtracting small increments; this step is performed by monitoring the real-time or regularly collected data and analyzing the trend. The new threshold will then be applied to the actual data management to implement the corresponding rule update. Finally, the overall performance of the system will be measured and recorded regularly. If the system processes the newly introduced information much faster than the preset indicators, then the increment will be adjusted, that is, the amplitude of each change will be halved or narrowed according to other strategies. This is to allow the system to adapt to changes and respond to changes neither too quickly nor too slowly.

[0070] Let's take an example to illustrate this process. In the initial stage, the network security system may set a threshold for abnormal traffic, such as one thousand requests per second. If the monitoring data later shows that the website's traffic per second during the holiday period is close to five thousand, the detection threshold may be set higher to reduce the number of false alarms. The meaning of △V in this scenario is the adjustment range each time, which may be a percentage or an absolute value. If the system can quickly identify that the traffic is normal and the processing time is short after changing the rules, in order not to miss possible attacks, it is necessary to slow down the threshold change rate again to maintain the accuracy at the balance point. This process allows security policies to automatically change with actual conditions, improves the ability of network security to respond to emergencies and maintains a reasonable response rate without relying on manual intervention. The △V and threshold adjustment strategies and speed presets here should all be flexibly defined to match various network conditions, but it should be noted that they should be fine-grained enough to avoid overreaction or delayed reaction, and avoid frequent unnecessary adjustments that lead to unnecessary expenses and burdens. Because this involves multiple variables and complex environmental factors, the best strategy needs to be tested and optimized according to specific situations, usually completed in a test environment and improved through continuous iteration.

[0071] Next, the specific meaning of applying the new threshold to the data adjustment process is described as follows: using the new threshold T to adjust the machine learning model parameter w; calculating the score Q of the model performance after applying the new threshold; comparing whether the score Q is greater than or equal to the benchmark score B; when the score meets the condition Q≥B, the specific steps to confirm the threshold adjustment effect are as follows. First, when a new threshold T is given, adjusting the parameter w in the machine learning model means that during the training phase, when encountering a certain decision point, adjusting the decision-making mechanism parameters related to this decision point according to T, that is, the weights and biases of the model, etc. These internal parameters of the model determine the decoding output and prediction results. Second, calculate the model performance score Q of the entire system after applying the new threshold. Here, the performance score can be a comprehensive indicator, including but not limited to accuracy, precision, recall, or F1 score. This step is to evaluate the ability of the machine learning model to handle specific tasks when using the new threshold configuration. Then, the third key step is to determine whether the new score Q is higher than or equal to the set standard or benchmark score B; if the new threshold brings a performance score Q that is at least not lower than the original level B, the adjustment is considered effective and helps to stabilize or even optimize the system performance; otherwise, more effective optimization methods need to be found. Suppose there is a neural network model for intrusion detection in an existing system, and its classification accuracy is 87%. We call this accuracy the baseline B of the model. When using a certain threshold such as 0.5 to determine the output label of a binary classification problem, the new score Q obtained by the model is 89%. Obviously, Q≥B = 87% holds, which proves that the new threshold T is an improvement scheme for the model, making the identification of intrusion events more accurate. However, for a specific application scenario, T needs to be dynamically adjusted according to specific evaluation indicators and business requirements to keep it within an appropriate range to ensure the effect of security situation awareness and the robustness of the system.

[0072] Next, when the score after calculating the new model parameters does not meet the condition, that is, Q<B, the specific steps of the present invention are as follows: calling a fallback program to restore to the previous parameter setting P; continuing to use the restored parameters to process the new security event data X; evaluating the feedback value F based on the actual effect after processing; if F reaches the ideal effect standard L, then confirm the effectiveness of this step: First, after the score of the newly trained model parameter Q is found not to reach the predetermined score benchmark B (here B can be a set of numerical values or score sets预先设定的一组衡量模型效能的数值或分数集合)预先设定的一组衡量模型效能的数值或分数集合). The system immediately takes action to activate the pre-designed fallback mechanism, so that the currently used security model is restored to the previous best configuration state, that is, setting P. The existence of this fallback mechanism is mainly to avoid possible adverse changes during the training or updating of the model and ensure that the security status of the network is not affected.

[0073] Afterwards, when the system returns to its previous stable state, this set of parameters is used to conduct security monitoring and processing analysis on the newly collected data X. In this way, the actual performance of the system operation after the model adjustment is obtained.

[0074] Next, based on the performance after processing this set of parameters, we will have an evaluation process to determine whether it meets the pre-set standard indicator F. The feedback value F is used to evaluate the comprehensive performance of the processed network data in terms of recognition accuracy (the ability to accurately identify network intrusion behavior), response time (the average delay from detecting threat signals to responding), the number of false alarms, and other key performance indicators directly related to network protection functions. The standard setting of F is usually based on past data accumulation and experience summary, and is flexibly changed over time and actual conditions to be closest to the actual network threat scenario. If the value of F fails to meet the expected standard, it means that further debugging or improvement of the existing settings is needed to achieve the optimization goal. If it exceeds the standard level, it is considered to have reached the ideal performance level L, which proves that the adjustment process at this stage has been successful, and subsequent work can continue to be performed with this configuration.

[0075] To make the understanding more intuitive, the following is a hypothetical scenario: In a certain network defense system, suppose the newly calculated risk assessment model Q score is lower than the expected standard value B (which may be a certain threshold such as 0.6 points or other dynamic thresholds calculated based on past statistics); at this time, the network monitoring system is developed and prepared before it is launched and tested to verify that it is safe and effective. The rollback plan restores Q to the original good performance P; then a batch of new network activity logs are processed through such parameters; then, according to the detection accuracy and false alarm ratio brought by this parameter combination, an evaluation number F is formed by comprehensive evaluation; if F exceeds the set ideal threshold value, it means that the fallback solution is feasible in the current scenario. In this process, the specific Q value may include multiple parameters such as the recognition accuracy index A (the ideal value should be around 0.9) and the response speed index B (the expected average response time is no more than 2 seconds), which together reflect the system's real-time monitoring capabilities for network risks.

[0076] The invention discloses a network security situation awareness method based on an adaptive algorithm, comprising: first, collecting relevant original log information and abnormal alarm records from multiple network devices, and then pre-processing them to convert them into structured network security data that can be further analyzed; then, using machine learning methods and techniques, according to normal behavior patterns and abnormal activities that may pose a threat in these data, detailed feature extraction is performed to identify existing security threats and suspicious behaviors; in addition, in this process, according to the update of historical analysis conditions and the boundary parameters automatically adjusted by the algorithm, the applied model parameters are dynamically changed and fine-tuned, so that the method can make a rapid and accurate response according to the actual situation changes and improve the accuracy of identifying potential risk factors; at the same time, an interactive visualization display environment is established to reflect the current state of the threat and provide prevention suggestions based on the obtained results, which is particularly suitable for early warning work of advanced persistent threats, thereby enhancing the user's decision-making ability in formulating security measures and realizing a more comprehensive enhancement of the overall awareness level of security situation in the network area, so that the challenges of real-time analysis and visualization of network security data can be effectively responded to, and threat warnings can be issued in a timely manner while providing intelligent protection plan suggestions, so as to achieve the effect of comprehensively improving the system's grasp of the entire network security situation.

[0077] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A network security situation awareness method based on an adaptive algorithm, characterized in that: The method includes: S1: Collect and preprocess the original log information and exception alarm records from multiple network devices to form structured network security data; S2: Based on a machine learning model, distinguish the normal behavior patterns and abnormal activities in the structured network security data and perform in-depth feature extraction to identify potential security threats and attack behaviors; S3: Dynamically adjust the machine learning model parameters and optimize the recognition accuracy based on the results of real-time updated historical data analysis and adaptively adjusted threshold settings; S4: Build an interactive visualization platform to display the real-time status of network threats, generate intelligent defense strategy suggestions based on the analysis results, and provide early warning services for advanced persistent threats to enhance the security decision-making support mechanism.

2. The method for network security situation awareness based on an adaptive algorithm according to claim 1, characterized in that: In the step of dynamically adjusting the machine learning model parameters and optimizing the recognition accuracy based on the results of real-time updated historical data analysis and adaptively adjusted threshold settings, the abnormal score calculation formula: [The abnormal score of the current data point is the absolute value of the difference between the current data and the historical average divided by the standard deviation], where the current data is the observed value within the most recent time window.

3. The network security situation awareness method based on an adaptive algorithm according to claim 1 is characterized in that: The step of distinguishing the normal behavior patterns and abnormal activities in the structured network security data and performing in-depth feature extraction to identify potential security threats and attack behaviors based on a machine learning model includes: Collect unstructured network security data and structured network security data, and perform preprocessing; Extract the features of the preprocessed unstructured network security data and structured network security data, and use machine learning algorithms to train a threat detection model to make a primary judgment (distinction) of normal behaviors and abnormal activities; Perform incremental feature extraction on the unstructured network security data after the primary judgment (distinction); Input the incrementally extracted features, train the threat detection model, and make a secondary judgment (distinction) of the original data; Statistically analyze the difference items between the primary judgment and the secondary judgment, which are used for the setting of the adaptive threshold and the dynamic adjustment of the machine learning model parameters to accurately identify potential security threats and attack behaviors.

4. The method for network security situation awareness based on an adaptive algorithm according to claim 1, characterized in that: The step of dynamically adjusting the machine learning model parameters based on the results of real-time updated historical data analysis and adaptively adjusted threshold settings includes: Collect the result information of historical data analysis; Set an adaptive threshold for dynamic adjustment; Adjust the machine learning model based on the information and the set parameters; If the current error is less than the preset value P, keep the model stable.

5. The method for network security situation awareness based on an adaptive algorithm according to claim 4 is characterized in that: In the step of setting an adaptive threshold for dynamic adjustment: Initialize the threshold; Increase or decrease a small value △V according to the change trend of the data; Apply the new threshold to the data adjustment process; If the system response speed R exceeds the predetermined speed standard S, reduce the adjustment increment.

6. The method for network security situation awareness based on an adaptive algorithm according to claim 5 is characterized in that: The specific meaning of applying the new threshold to the data adjustment process is: Adopt the new threshold T to adjust the machine learning model parameter w; Calculate the score Q of the model performance after applying the new threshold; Compare whether the score Q is greater than or equal to the benchmark score B; When the score meets the condition Q≥B, confirm the threshold adjustment effect.

7. A network security situation awareness method based on an adaptive algorithm according to claim 6, characterized in that: When the score after calculating the new model parameters does not meet the condition, that is, Q<B: Call the rollback program to restore to the previous parameter setting P; Continue to process new security event data X using the recovery parameter; Evaluate the feedback value F based on the actual effect after processing; If F reaches the ideal effect standard L, the effectiveness of this step is confirmed.

Citation Information

Cited By

  • Situation awareness method based on RAG and decision tree algorithm

    CN120528715A

  • Network security situation prediction method based on big data

    CN120729655A

  • Security identification method and system based on intelligent AI

    CN120811728A