Network security situation awareness method based on knowledge graph and related equipment

Through a knowledge graph-based method, clustering user node graphs and calculating vulnerability values, the problem of difficult to identify nodes infected by attackers but not exhibiting attack behavior in the prior art is solved, and effective assessment and prediction of the risk of network attacks is achieved.

CN119995921APending Publication Date: 2025-05-13国网思极网安科技(北京)有限公司 +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411882523.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to identify and predict nodes in the network environment that are infected by attackers but do not show attack behavior, resulting in the inability to effectively evaluate the risk of attack on the network.

Method used

Through a knowledge graph-based method, the target network topology graph is determined, the user node graph is clustered, the user group vulnerability value is calculated, and the user group influence is predicted at the next moment to evaluate the network's risk level of attack.

Benefits of technology

The identification and risk assessment of potentially attacked nodes in the network environment is realized, avoiding the risk of attackers continuing to infect other hosts by infecting some nodes, and improving the accuracy of network security situation awareness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995921A_ABST
    Figure CN119995921A_ABST
Patent Text Reader

Abstract

The invention provides a network security situation awareness method based on a knowledge graph and related equipment. The method comprises the following steps: determining a target network topological graph; determining a user node graph according to the target network topological graph, clustering user nodes in the user node graph through a clustering algorithm, and determining a plurality of first user groups; clustering the plurality of first user groups, and determining a plurality of second user groups; calculating vulnerability values of any first user group and any second user group, and determining a plurality of first vulnerability values and a plurality of second vulnerability values; determining the influence of any node according to the plurality of first vulnerability values and the plurality of second vulnerability values; and determining an attacked risk level of the current network at the next moment according to the influence of any node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a network security situation awareness method and related equipment based on a knowledge graph. Background Art

[0002] As network security issues become increasingly serious, the need for accurate quantitative assessment of security risks in network systems is increasing. However, the existing technology generally determines the network attack behaviors that have occurred by setting access times or traffic limits to resist network attacks, so it is impossible to identify a small number of nodes in the network environment that have been infected by the attacker but have not shown any attack behavior. Summary of the invention

[0003] In view of this, the purpose of this application is to propose a network security situation awareness method and related equipment based on knowledge graph.

[0004] Based on the above objectives, this application provides a network security situation awareness method based on knowledge graph, including:

[0005] Determine the target network topology;

[0006] Determine a user node graph according to the target network topology graph, cluster the user nodes in the user node graph by using a clustering algorithm, and determine a plurality of first user groups;

[0007] Clustering the first user groups to determine a second user group;

[0008] Calculating the vulnerability value of any of the first user group and any of the second user group, and determining a plurality of first vulnerability values ​​and a plurality of second vulnerability values;

[0009] Determining the influence of any node according to a plurality of the first vulnerability values ​​and a plurality of the second vulnerability values;

[0010] According to the influence of any node, the attack risk level of the current network at the next moment is determined.

[0011] Optionally, clustering the user nodes in the user node graph by a density-based clustering algorithm to determine a plurality of first user groups; wherein the first user group is a user group at time t;

[0012] A plurality of the first user groups are clustered by a density-based clustering algorithm to determine a plurality of the second user groups; wherein the second user groups are user groups at time t+1.

[0013] Optionally, the calculating the vulnerability value of any of the first user group and any of the second user group to determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values ​​includes:

[0014] The vulnerability values ​​of any of the first user groups and any of the second user groups are calculated by the following formula:

[0015]

[0016] Among them, B k is the total data throughput of the nodes in the current user group in one operation cycle, B all is the total data throughput of all nodes in the current graph in one operation cycle; n k -1 is the number of groups other than the current user group in the clustering result of the current user distribution graph; is the number of edges that the node has in the current group, regardless of direction; is the number of node edges in the k'th group except this group; is the standard deviation of the number of edges of each node in the current group k.

[0017] Optionally, determining the influence of any node according to the plurality of the first vulnerability values ​​and the plurality of the second vulnerability values ​​includes:

[0018] Determining a number of fragility increments according to a number of the first fragility values ​​and a number of the second fragility values;

[0019] According to any of the fragile increments, the influence of any of the nodes at time t+1 is determined.

[0020] Optionally, determining the influence of any node at time t+1 according to any of the vulnerable increments includes:

[0021] The influence of any node at time t+1 is determined according to any of the fragile increments by the following formula:

[0022]

[0023] in, Fragile increment for other user groups that are linked to the current group.

[0024] Optionally, determining the attack risk level of the current network at the next moment according to the influence of any node includes:

[0025]

[0026] in, is the ratio of the mean stability of influence of each user group in the network topology at the current moment to that at the previous moment, max(R k )-min(R k ) is the extreme difference of influence of each group at the current moment, and Sinc function is the Singer function.

[0027] Based on the same inventive concept, the embodiment of the present application also provides a network security situation awareness method and device based on a knowledge graph, including:

[0028] A determination module is configured to determine a target network topology map;

[0029] A first clustering module is configured to determine a user node graph according to the target network topology graph, cluster the user nodes in the user node graph by a clustering algorithm, and determine a plurality of first user groups;

[0030] A second clustering module is configured to cluster the first user groups to determine a plurality of second user groups;

[0031] a vulnerability value calculation module, configured to calculate the vulnerability value of any of the first user groups and any of the second user groups, and determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values;

[0032] An influence calculation module, configured to determine the influence of any node according to a plurality of the first vulnerability values ​​and a plurality of the second vulnerability values;

[0033] The risk assessment module is configured to determine the attack risk level of the current network at the next moment according to the influence of any of the nodes.

[0034] Optionally, the second clustering module is configured to: cluster the user nodes in the user node graph by a density-based clustering algorithm to determine a plurality of the first user groups; wherein the first user group is a user group at time t;

[0035] A plurality of the first user groups are clustered by a density-based clustering algorithm to determine a plurality of the second user groups; wherein the second user groups are user groups at time t+1.

[0036] Optionally, the second clustering module is further configured to:

[0037] The vulnerability values ​​of any of the first user groups and any of the second user groups are calculated by the following formula:

[0038]

[0039] Among them, B k is the total data throughput of the nodes in the current user group in one operation cycle, B all is the total data throughput of all nodes in the current graph in one operation cycle; n k -1 is the number of groups other than the current user group in the clustering result of the current user distribution graph; is the number of edges that the node has in the current group, regardless of direction; is the number of node edges in the k'th group except this group; is the standard deviation of the number of edges of each node in the current group k.

[0040] Optionally, the influence calculation module is further configured to:

[0041] Determining a number of fragility increments according to a number of the first fragility values ​​and a number of the second fragility values;

[0042] According to any of the fragile increments, the influence of any of the nodes at time t+1 is determined.

[0043] Optionally, the influence calculation module is further configured to:

[0044] The influence of any node at time t+1 is determined according to any of the fragile increments by the following formula:

[0045]

[0046] in, is the fragile increment of other user groups linked to the current group, k is the node number, For fragile increments, is the abnormal spillover value of the second user group.

[0047] Optionally, the risk assessment module is further configured to:

[0048]

[0049] in, is the ratio of the mean stability of influence of each user group in the network topology at the current moment to that at the previous moment, max(R k )-min(R k ) is the extreme difference of influence of each group at the current moment, and Sinc function is the Singer function.

[0050] Based on the same inventive concept, an embodiment of the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, a network security situation awareness method based on a knowledge graph as described in any one of the above is implemented.

[0051] Based on the same inventive concept, an embodiment of the present application also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute any of the above-mentioned knowledge graph-based network security situation awareness methods.

[0052] Based on the same inventive concept, an embodiment of the present application also provides a computer program product, including computer program instructions. When the computer program instructions are executed on a computer, the computer executes any of the above-mentioned knowledge graph-based network security situation awareness methods.

[0053] From the above, it can be seen that according to the embodiments of the present application, several first user groups determined by clustering user nodes at the current moment can be clustered again, and several second user groups can be determined according to the results of the re-clustering, and then the difference in vulnerability values ​​between the several first user groups and the several second user groups can be calculated, and the attack risk level of the current network at the next moment can be determined according to the difference in vulnerability values. This avoids the situation where some nodes are attacked but the attacker intends to use this node to continue to infect other hosts in the network until a certain scale of infected nodes is reached before attacking, and the identification ability of nodes infected by the attacker but not showing attack behavior is poor. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] In order to more clearly illustrate the technical solutions in the present application or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0055] Figure 1 A schematic diagram of the process of a network security situation awareness method based on a knowledge graph according to an embodiment of the present application;

[0056] Figure 2 A schematic diagram of the network topology of the target network in an embodiment of the present application;

[0057] Figure 3 A schematic diagram of a user node in an embodiment of the present application;

[0058] Figure 4 A schematic diagram of the mapping of the Sinc function of an embodiment of the present application;

[0059] Figure 5 A schematic diagram of a network security situation awareness device based on a knowledge graph according to an embodiment of the present application;

[0060] Figure 6 A schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0061] In order to make the objectives, technical solutions and advantages of the present application more clearly understood, the present application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0062] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should be the usual meanings understood by people with ordinary skills in the field to which the present application belongs. The "first", "second" and similar words used in the embodiments of the present application do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0063] In order to facilitate understanding of the technical solutions of the present disclosure, some technical terms involved in the present disclosure are introduced below.

[0064] Density-based clustering algorithm is an important clustering analysis method. It assumes that the clustering structure can be determined by the compactness of sample distribution, that is, as long as the sample density in an area is greater than a certain threshold, it will be classified into a cluster similar to it.

[0065] The OPTICS (Ordering points to identify the clustering structure) clustering algorithm is a density-based clustering method, which is an improved version of the DBSCAN algorithm. The OPTICS algorithm constructs a reachability graph and assigns reachability distances and sorting attributes to each sample, allowing clusters of variable density to be extracted in a single data set.

[0066] Network vulnerability refers to security weaknesses in systems, networks or applications that may be exploited by attackers to achieve unauthorized access, data leakage, and disruption of normal system operations. These malicious behaviors may cause problems in the security, reliability, availability, confidentiality, and integrity of network systems. Vulnerabilities are generally caused by software design flaws, configuration errors, insufficient password strength, and failure to patch in a timely manner. The main purpose of network vulnerability assessment is to identify possible security risks and weaknesses in the network system and provide corresponding improvement measures.

[0067] In order to make the technical solution of the present disclosure clearer and easier to understand, the knowledge graph-based network security situation awareness method provided by the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.

[0068] As described in the background technology section, as network security issues become increasingly serious, the demand for accurate quantitative assessment of security risks in network systems is increasing day by day. However, in the prior art, network attacks that have occurred are generally determined by setting access times or traffic limits to resist network attacks. The applicant has found through research that in attacks on the network, some nodes are attacked, but the attacker intends to use this node to continue to infect other hosts in the network until there is a certain scale of infected nodes before attacking. Therefore, the prior art cannot identify a small number of nodes in the network environment that have been infected by the attacker but have not shown attack behavior.

[0069] In view of this, the embodiments of the present application provide a network security situation awareness method, device, electronic device, storage medium and related equipment based on a knowledge graph, including: clustering through a clustering algorithm according to a user node graph at the current moment, determining a number of first user groups, and then clustering the several first user groups again, and predicting a number of second user groups at the next moment according to the clustering results, thereby, according to the vulnerability values ​​of the several first user groups corresponding to the current moment and the predicted vulnerability values ​​of the several second user groups at the next moment, the attack risk level of the current network at the next moment is evaluated, thereby solving the scenario where some nodes are attacked but the attacker intends to use this node to continue to infect other hosts in the network until a certain scale of infected nodes is reached before attacking, and the existing method of setting the number of accesses or traffic limits cannot identify a small number of nodes in the network environment that are infected by the attacker but do not show attack behavior.

[0070] like Figure 1 As shown, the network security situation awareness method based on knowledge graph includes:

[0071] Step S102, determining the target network topology map;

[0072] Step S104: determining a user node graph according to the target network topology graph, clustering user nodes in the user node graph by using a clustering algorithm, and determining a plurality of first user groups;

[0073] Step S106: clustering the first user groups to determine a number of second user groups;

[0074] Step S108: Calculate the vulnerability value of any of the first user groups and any of the second user groups, and determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values;

[0075] Step S110: determining the influence of any node according to a plurality of the first vulnerability values ​​and a plurality of the second vulnerability values;

[0076] Step S112: Determine the attack risk level of the current network at the next moment according to the influence of any node.

[0077] In step S102, a network topology diagram is a graphical representation method used to represent the physical or logical connection relationship between nodes (such as computers, switches, routers, etc.) in a computer network. The network topology diagram can not only help network designers and administrators understand and plan the network structure, but also can be used for fault diagnosis, performance optimization and security analysis.

[0078] In this step, the target network topology is specifically composed of various types of devices in the area to be evaluated for attack risk. Figure 2 The network topology diagram is shown in Figure 1. Figure 2 As shown in the figure, the target network topology is divided into: server area, exit area, core area and access area, etc. Among them, the server area includes MES (Manufacturing Execution System, MES) server, that is, the server of the manufacturing execution system, SCM (Source Code Management) server, that is, the server for user source code management, and database server, etc.; the exit area includes the Internet network; the core area includes core switches, aggregation switches, access switches, firewalls, and AC network controllers, etc.; the access area includes various access terminal devices, such as computers, mobile phones, iPads, access control gates, cameras and other terminal devices.

[0079] In some implementations, connections are made based on the types of devices in the target network topology and the connection relationships between the devices, as well as the directions of the messages sent by the users for communication (directed edges with the sending user as the starting point and the receiving user as the end point), so as to obtain the following: Figure 3 The user node graph shown can represent the connection relationship between users. It should be noted that the security situation of the network is often affected by the access of user terminals, so the user node graph is constructed through the sending direction of communication between access users (directed edges with the sending user as the starting point and the receiving user as the end point).

[0080] Furthermore, for the connections between user nodes in the user node graph, there are some users in the user topology who perform similar behaviors. These users represent a group of users who work together. However, in addition to similar behaviors, the users in the group also perform different network behaviors, which shows that the proximity between these users in the node graph is not high, indicating that non-identical network behaviors will interfere with the evaluation of nodes with similar attributes. Therefore, it is necessary to screen the group distribution of some network users with similar network behaviors, so as to analyze the behavioral deviations between the user group groups and the impact of the new nodes connected on the formed network connections to evaluate the abnormal status.

[0081] In some implementations, the user nodes in the user node graph are clustered using a density-based clustering algorithm (OPTICS clustering algorithm) to obtain n k user clusters, each of which is a first user group. The first user group is the user grouping corresponding to the network topology at the current moment, that is, at moment t. A first user group includes multiple users, and multiple users in the first user group perform similar behaviors.

[0082] In some optional implementations, the user node graph may be replaced by a knowledge graph having the same function as the user node graph, and a plurality of first user groups may be determined by clustering the knowledge graph.

[0083] In some embodiments, the changes in nodes within a user group during different collection cycles have different effects on the vulnerability of users within the group. Therefore, in order to solve the problem in the prior art that when a node is compromised, the attacker does not immediately launch an attack, but uses the compromised node as an infection source to infect more nodes, so that when the attack is launched, the situation of the current node will quickly tend to be extremely abnormal, causing large-scale network paralysis, the following clusters several first user groups, predicts the user group at the next moment, determines several second user groups, and calculates the vulnerability value of any of the first user groups and any of the second user groups, determines several first vulnerability values ​​and several second vulnerability values, and thereby determines the attack risk of the corresponding node according to the first vulnerability value and the second vulnerability value.

[0084] In some implementations, clustering the user nodes in the user node graph by a density-based clustering algorithm is performed to determine a number of first user groups; wherein the first user group is a user group at time t; clustering the first user groups by a density-based clustering algorithm is performed to determine a number of second user groups; wherein the second user group is a user group at time t+1. For example, the current target network includes abcdefghijklmnopqrst, a total of 20 nodes, and the 20 nodes are divided into 4 groups by clustering, then the four groups are all called first user groups, namely, the first user group including abcd with a total of 4 nodes, the first user group including efghijk with a total of 7 nodes, the first user group including lmno with a total of 4 nodes, and the first user group including pqrst with a total of 5 nodes. As for the second user group, the four first user groups are clustered again to determine, wherein the result of the re-clustering may be that one or more of the first user groups have a new user node or a reduction in user nodes, or it may be that none of the multiple first user groups has a new user node or a reduction in user nodes.

[0085] In some implementations, calculating the vulnerability value of any of the first user group and any of the second user group to determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values ​​includes:

[0086] The vulnerability value Z of each first user group is calculated by the following formula: k and the vulnerability value of each second user group

[0087]

[0088] Among them, B k is the total data throughput of the nodes in the current user group in one operation cycle, B all is the total data throughput of all nodes in the current graph in one operation cycle; n k -1 is the number of groups other than the current user group in the clustering result of the current user node graph; The number of edges (regardless of direction) owned by the node in the current group; is the number of node edges in the k'th group except this group; is the standard deviation of the number of edges of each node in the current group k, This indicates that the data throughput in the current user group is significantly higher than that in other groups, and the attack data packets sent by the attacker are more likely to be received by the current group. It is the comprehensiveness of the network communication of the current node to all nodes. The larger the value of this formula is, the more users the current user group is screening with, and it is easier for attackers to break through the nodes in the current group and attack the network.

[0089] It should be noted that when performing the vulnerability value test of the second user group When calculating the above vulnerability value, it is necessary to modify k in the above vulnerability value calculation formula to k t+1 , to be distinguished from k when calculating the vulnerability value of the first user group. Wherein, k = 1, 2, 3, ..., n.

[0090] In some optional implementations, the number of nodes may change in adjacent cycles (e.g., t cycle and t+1 cycle, or t-1 cycle and t cycle), so the centroid of each cluster in the current cycle is used as the clustering starting point of the new acquisition cycle, and clustering is performed to obtain the clusters corresponding to each cluster in the current cycle in the next cycle, which are recorded as the user groups corresponding to the user groups in the current cycle in the next cycle. Remove the users who also exist in the previous cycle from the user group of the next cycle, and the obtained ones are recorded as the newly added users of this cycle. Since the attacked nodes are usually connected to many nodes, it is easier for the attacker to disguise. Therefore, the changes in the vulnerability of the user group nodes that are linked to the current user group are more obvious than other groups, indicating that the user group is more likely to be affected by the attack, resulting in abnormal nodes in the group.

[0091] Therefore, the vulnerability spillover impact of user group k in the current collection cycle is calculated, and the vulnerability spillover impact is judged based on the calculation results:

[0092] (1) Compare the first user group corresponding to period t with the second user group corresponding to period t+1 to determine the second user group with an increase or decrease in nodes compared with the first user group, and the vulnerability value of the second user group

[0093] (2) Calculate the user vulnerability value of the second user group where the node is increased or decreased after removing the increased or decreased node.

[0094] (3) Based on the vulnerability value and weakness value The vulnerability increment is determined by the following calculation formula

[0095]

[0096] in, The vulnerability value of the second user group that is increased or decreased for the node, is the user vulnerability value after removing the added or reduced nodes, max(Z t+1 ) is the maximum value of user vulnerability Z, min(Z t+1) is the minimum value of user vulnerability Z. The higher the vulnerability increment, the more likely the current user group will be attacked in the next cycle, causing the node to be compromised, so that the attacker can use the current node to continue infecting other nodes in the topology.

[0097] Then, further, according to the fragile increment The node influence of any second user group in the next collection period (i.e., period t+1) is calculated by the following formula: and the node influence of any first user group in the current period (i.e., period t)

[0098]

[0099] in, A fragile increment for other user groups that are linked to the current group. It is obtained by subtracting the z calculated at the next time t+1 from the z calculated at the previous time t, where k is the node number. For fragile increments, is the abnormal spillover value of the second user group. The larger the abnormal spillover value, the less abnormal spillover of the current user group itself, which reflects that the current user group's own access situation has deviations and is attacked, resulting in a lower possibility of abnormality. Therefore, the current user group has a higher degree of influence on the network security situation tending to be stable.

[0100] It should be noted that the above formula is used to calculate the node influence of any first user group in the current period (t period) When k in the above formula is t+1 Modified to k t Perform corresponding calculations.

[0101] In some implementations, after determining the node influences of multiple second user groups according to the above method, the risk of network attack in the next cycle is evaluated according to the node influences of the multiple second user groups. It should be noted that the more second user groups with high influence appear, the more the current network can withstand different network environment states, the lower the abnormal situation caused by the attack, and the higher the ability to withstand the risk of attack.

[0102] Therefore, the network attack resistance Q of the next acquisition cycle is calculated by the following method.

[0103] First, put all the node influence R of each group in the next monitoring period (t+1 period) into an empty set and name the set as influence set R t+1 Similarly, there is also an influence set in the current monitoring period, denoted as R t .

[0104] Then, for the influence set Rt+1 and R t The two sets represent the correlation between user groups in the total topology. When the overall fluctuation of the influence of user groups in the two sets is relatively stable, it means that the network security status in the network topology between the two adjacent moments is maintained at a relatively safe level. Therefore, the attack resistance Q of the network topology at the current moment can be evaluated.

[0105]

[0106] in, is the ratio of the mean stability of influence of each user group in the network topology in the next monitoring period to that in the current monitoring period; max(R k )-min(R k ) is the influence difference of each group at the current moment; Sinc function is the Singer function, such as Figure 4 As shown in the figure, when the input approaches 0 (regardless of direction), the output approaches the maximum value 1, and further adjusts the output value range to the range of [0,1] through the absolute value, which serves as the network attack resistance at the current moment.

[0107] In some embodiments, the network resistance Q may be evaluated according to a plurality of pre-set evaluation criteria for resistance ranges, and the evaluation criteria for resistance ranges include:

[0108] (1) When the network resistance Q falls into the range of [0,0.3], it indicates that the network may be attacked at the next moment;

[0109] (2) When the network resistance Q falls into the range of (0.3, 0.6], it indicates that the network has been penetrated at the current moment;

[0110] (3) When the network resistance Q falls into the range of (0.6, 0.8], it indicates that a small number of hosts in the network may be infiltrated by attackers at the current moment;

[0111] (4) When the network resistance Q falls within the range of (0.8,1], it indicates that the current network environment is relatively safe.

[0112] In some optional implementations, the vulnerability of a network node may be multifaceted, including but not limited to the following aspects:

[0113] (1) Software vulnerabilities: Defects or errors that may exist in the design, development, testing, or deployment of software, which may be exploited by attackers to execute malicious code, elevate privileges, or bypass security controls.

[0114] (2) Misconfiguration: Improper configuration of the system or network may lead to security vulnerabilities. For example, failure to set adequate security policies, unreasonable authority allocation, failure to enable necessary security features, etc. may make the system vulnerable to attacks.

[0115] (3) Insufficient password strength: The password set by the user is too simple or the same password is reused to protect multiple accounts, which can be easily guessed by attackers through brute force or dictionary attacks to obtain sensitive information.

[0116] (4) Failure to install patches in a timely manner: Software vendors will release patches to fix security vulnerabilities after discovering them. If the system or application does not install these patches in a timely manner, it may become a target for attackers.

[0117] (5) Protocol flaws: Security vulnerabilities or deficiencies in the network protocol itself may also become exploitable points for attackers. For example, when the TCP / IP protocol was first designed, it focused more on openness and operational efficiency, but not enough on security, so there are many known security vulnerabilities.

[0118] (6) Human factors: Improper user operations, lack of security awareness, or malicious behavior may also lead to system or network vulnerabilities. For example, users may click on unknown links, download malware, or leak sensitive information.

[0119] From the above, it can be seen that the network security situation awareness method based on the knowledge graph performs clustering according to the user node graph at the current moment through a clustering algorithm to determine several first user groups, and then clusters the several first user groups again, and predicts several second user groups at the next moment according to the clustering results. Thus, according to the vulnerability values ​​of the several first user groups corresponding to the current moment and the vulnerability values ​​of the several second user groups at the next moment determined by the prediction, the attack risk level of the current network at the next moment is evaluated, thereby solving the scenario where some nodes are attacked but the attacker intends to use this node to continue to infect other hosts in the network until a certain scale of infected nodes is reached before attacking. The existing method of setting the number of accesses or traffic limits cannot identify the small number of nodes that are infected by the attacker but do not show attack behavior in the network environment.

[0120] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the described method.

[0121] It should be noted that the above describes some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0122] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a network attack risk assessment device.

[0123] refer to Figure 5 , the network attack risk assessment device comprises:

[0124] The determination module 502 is configured to determine a target network topology map;

[0125] A first clustering module 504 is configured to determine a user node graph according to the target network topology graph, cluster the user nodes in the user node graph by a clustering algorithm, and determine a plurality of first user groups;

[0126] A second clustering module 506 is configured to cluster the first user groups to determine a number of second user groups;

[0127] A vulnerability value calculation module 508 is configured to calculate the vulnerability value of any of the first user groups and any of the second user groups, and determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values;

[0128] An influence calculation module 510 is configured to determine the influence of any node according to a plurality of the first vulnerability values ​​and a plurality of the second vulnerability values;

[0129] The risk assessment module 512 is configured to determine the attack risk level of the current network at the next moment according to the influence of any of the nodes.

[0130] As an optional embodiment, the second clustering module 506 is configured to: cluster the user nodes in the user node graph by a density-based clustering algorithm to determine a plurality of first user groups; wherein the first user group is a user group at time t;

[0131] A plurality of the first user groups are clustered by a density-based clustering algorithm to determine a plurality of the second user groups; wherein the second user groups are user groups at time t+1.

[0132] As an optional embodiment, the second clustering module 506 is further configured to:

[0133] The vulnerability values ​​of any of the first user groups and any of the second user groups are calculated by the following formula:

[0134]

[0135] Among them, B k is the total data throughput of the nodes in the current user group in one operation cycle, B all is the total data throughput of all nodes in the current graph in one operation cycle; n k -1 is the number of groups other than the current user group in the clustering result of the current user distribution graph; The number of edges (regardless of direction) owned by the node in the current group; is the number of node edges in the k'th group except this group; is the standard deviation of the number of edges of each node in the current group k.

[0136] As an optional embodiment, the influence calculation module 510 is further configured to:

[0137] Determining a number of fragility increments according to a number of the first fragility values ​​and a number of the second fragility values;

[0138] According to any of the fragile increments, the influence of any of the nodes at time t+1 is determined.

[0139] As an optional embodiment, the influence calculation module 510 is further configured to:

[0140] The influence of any node at time t+1 is determined according to any of the fragile increments by the following formula:

[0141]

[0142] in, is the fragile increment of other user groups linked to the current group, k is the node number, For fragile increments, is the abnormal spillover value of the second user group.

[0143] As an optional embodiment, the risk assessment module 512 is further configured to:

[0144]

[0145] in, is the ratio of the mean stability of influence of each user group in the network topology at the current moment to that at the previous moment, max(R k )-min(R k) is the extreme difference of influence of each group at the current moment, and Sinc function is the Singer function.

[0146] For the convenience of description, the above device is described in terms of functions divided into various modules. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0147] The device of the above-mentioned embodiment is used to implement the corresponding knowledge graph-based network security situation awareness method in any of the above-mentioned embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0148] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the knowledge graph-based network security situation awareness method described in any of the above embodiments is implemented.

[0149] Figure 6 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.

[0150] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0151] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0152] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0153] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0154] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0155] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0156] The electronic device of the above-mentioned embodiment is used to implement the corresponding knowledge graph-based network security situation awareness method in any of the above-mentioned embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0157] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the network security situation awareness method based on the knowledge graph as described in any of the above embodiments.

[0158] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0159] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the network security situation awareness method based on the knowledge graph as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0160] Based on the same inventive concept, corresponding to the network security situation awareness method based on knowledge graph described in any of the above embodiments, the present disclosure also provides a computer program product, which includes computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer so that the computer and / or the processor executes the network security situation awareness method based on knowledge graph. Corresponding to the execution subject corresponding to each step in each embodiment of the network security situation awareness method based on knowledge graph, the processor that executes the corresponding step may belong to the corresponding execution subject.

[0161] The computer program product of the above embodiment is used to enable the computer and / or the processor to execute the network security situation awareness method based on the knowledge graph as described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0162] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0163] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the known power supply / ground connection with the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device can be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform to be implemented in the embodiments of the present application (that is, these details should be fully within the scope of understanding of those skilled in the art). In the case of elaborating specific details (e.g., circuits) to describe exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.

[0164] Although the present application has been described in conjunction with specific embodiments of the present application, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.

[0165] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the present application.

Claims

1. A network security situation awareness method based on knowledge graph, characterized in that: include: Determine the target network topology; Determine a user node graph according to the target network topology graph, cluster the user nodes in the user node graph by using a clustering algorithm, and determine a plurality of first user groups; Clustering the first user groups to determine a second user group; Calculating the vulnerability value of any of the first user group and any of the second user group, and determining a plurality of first vulnerability values ​​and a plurality of second vulnerability values; Determining the influence of any node according to a plurality of the first vulnerability values ​​and a plurality of the second vulnerability values; According to the influence of any node, the attack risk level of the current network at the next moment is determined.

2. The method according to claim 1, characterized in that Clustering the user nodes in the user node graph by a density-based clustering algorithm to determine a plurality of first user groups; wherein the first user group is a user group at time t; A plurality of the first user groups are clustered by a density-based clustering algorithm to determine a plurality of the second user groups; wherein the second user groups are user groups at time t+1.

3. The method according to claim 2, characterized in that The calculating the vulnerability value of any of the first user group and any of the second user group to determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values ​​comprises: The vulnerability values ​​of any of the first user groups and any of the second user groups are calculated by the following formula: Among them, B k is the total data throughput of the nodes in the current user group in one operation cycle, B all is the total data throughput of all nodes in the current graph in one operation cycle; n k -1 is the number of groups other than the current user group in the clustering result of the current user distribution graph; is the number of edges that the node has in the current group, regardless of direction; is the number of node edges in the k'th group except this group; is the standard deviation of the number of edges of each node in the current group k.

4. The method according to claim 1, characterized in that: The determining the influence of any node according to the plurality of the first vulnerability values ​​and the plurality of the second vulnerability values ​​comprises: Determining a number of fragility increments according to a number of the first fragility values ​​and a number of the second fragility values; According to any of the fragile increments, the influence of any of the nodes at time t+1 is determined.

5. The method according to claim 4, characterized in that Determining the influence of any node at time t+1 according to any of the vulnerable increments includes: The influence of any node at time t+1 is determined according to any of the fragile increments by the following formula: in, is the fragile increment of other user groups linked to the current group, k is the node number, For fragile increments, is the abnormal spillover value of the second user group.

6. The method according to claim 1, characterized in that Determining the attack risk level of the current network at the next moment according to the influence of any node includes: in, is the ratio of the mean stability of influence of each user group in the network topology at the current moment to that at the previous moment, max(R k )-min(R k ) is the extreme difference of influence of each group at the current moment, and Sinc function is the Singer function.

7. A network security situation awareness device based on knowledge graph, characterized in that: include: A determination module is configured to determine a target network topology map; A first clustering module is configured to determine a user node graph according to the target network topology graph, cluster the user nodes in the user node graph, and determine a plurality of first user groups; A second clustering module is configured to cluster the first user groups to determine a plurality of second user groups; a vulnerability value calculation module, configured to calculate the vulnerability value of any of the first user groups and any of the second user groups, and determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values; An influence calculation module, configured to determine the influence of any node according to a plurality of the first vulnerability values ​​and a plurality of the second vulnerability values; The risk assessment module is configured to determine the attack risk level of the current network at the next moment according to the influence of any of the nodes.

8. The device according to claim 7, characterized in that Clustering the user nodes in the user node graph by a density-based clustering algorithm to determine a plurality of first user groups; wherein the first user group is a user group at time t; A plurality of the first user groups are clustered by a density-based clustering algorithm to determine a plurality of the second user groups; wherein the second user groups are user groups at time t+1.

9. The device according to claim 8, characterized in that The calculating the vulnerability value of any of the first user group and any of the second user group to determine a plurality of first vulnerability values ​​and a plurality of second vulnerability values ​​comprises: The vulnerability values ​​of any of the first user groups and any of the second user groups are calculated by the following formula: Among them, B k is the total data throughput of the nodes in the current user group in one operation cycle, B all is the total data throughput of all nodes in the current graph in one operation cycle; n k -1 is the number of groups other than the current user group in the clustering result of the current user distribution graph; is the number of edges that the node has in the current group, regardless of direction; is the number of node edges in the k'th group except this group; is the standard deviation of the number of edges of each node in the current group k.

10. The device according to claim 1, characterized in that The determining the influence of any node according to the plurality of the first vulnerability values ​​and the plurality of the second vulnerability values ​​comprises: Determining a number of fragility increments according to a number of the first fragility values ​​and a number of the second fragility values; According to any of the fragile increments, the influence of any of the nodes at time t+1 is determined.

11. The device according to claim 10, characterized in that Determining the influence of any node at time t+1 according to any of the vulnerable increments includes: The influence of any node at time t+1 is determined according to any of the fragile increments by the following formula: in, is the fragile increment of other user groups linked to the current group, k is the node number, For fragile increments, is the abnormal spillover value of the second user group.

12. The device according to claim 7, characterized in that Determining the attack risk level of the current network at the next moment according to the influence of any node includes: in, is the ratio of the mean stability of influence of each user group in the network topology at the current moment to that at the previous moment, max(R k )-min(R k ) is the extreme difference of influence of each group at the current moment, and Sinc function is the Singer function.

13. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method according to any one of claims 1 to 6 when executing the computer program.

14. A non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method according to any one of claims 1 to 6.

15. A computer program product, comprising computer program instructions, which, when executed on a computer, cause the computer to execute the method according to any one of claims 1 to 6.