Data analysis method and system based on communication security situation awareness

By building a vulnerability knowledge base and timing feature matrix, combined with attention mechanism and deep learning model, the problem of difficulty in dynamically perceiving the status of the communication system and comprehensively considering the risk of equipment in the existing technology is solved, and the risk assessment of network equipment and the precise push of vulnerability information is achieved, and the defense efficiency is improved.

CN119996071AActive Publication Date: 2025-05-13NANJING CONTROL COMM TECH CO LTD

Patent Information

Application Number
CN202510436666.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-05-13
Estimated Expiration
2045-04-09

AI Technical Summary

Technical Problem

The prior art is difficult to dynamically perceive the status of the communication system, and lacks comprehensive consideration of the risks faced by the equipment from the spatiotemporal relationship of network devices, resulting in inaccurate vulnerability information.

Method used

By collecting vulnerability features of network devices from the operation and maintenance records of the communication system, building a vulnerability knowledge base, and combining the timing operation characteristics and spatial relationships of network devices, weighted fusion is used using attention mechanisms and deep learning models (such as BERT, LSTM, and Transformer) to generate the risk matrix and threat score of network devices.

Benefits of technology

It realizes the risk assessment of network equipment in the communication system and the accurate push of vulnerability information, dynamically responds to changes in network status, and improves defense efficiency and vulnerability management accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996071A_ABST
    Figure CN119996071A_ABST
Patent Text Reader

Abstract

The invention discloses a data analysis method and system based on communication security situation awareness, and relates to the technical field of network equipment data management. Vulnerability features of network equipment vulnerabilities are collected from operation and maintenance records of a communication system, and a time sequence operation feature sequence of each piece of network equipment in a time range is obtained; the method comprises the following steps: capturing a spatial relationship of network devices in a communication system through an attention mechanism, carrying out weighted fusion on time sequence features and the spatial relationship in the communication system to obtain a risk matrix of all network devices in the communication system, extracting risk feature vectors of the network devices from the risk matrix, and calculating the risk feature vectors of the network devices; the method comprises the following steps: obtaining threat scores of corresponding network devices through dimensionality compression and linear mapping, calculating risk assessment values of various vulnerabilities of all network devices, and providing related vulnerability information of the network devices for managers of a communication system according to a descending order of the risk assessment values.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network equipment data management, and in particular to a data analysis method and system based on communication security situation awareness. Background Art

[0002] With the development of communication network technology, the number and types of network devices connected to the communication system are increasing day by day, and the security supervision of communication networks has become a key issue in related fields.

[0003] In traditional technical solutions, the traffic of communication links and the status of network devices are supervised by establishing network topology, such as network management mechanism. As the number of devices connected to the communication network increases and the location of the interface changes, the network topology needs to be updated frequently, so the status of the communication system cannot be perceived dynamically. At the same time, the judgment of device vulnerability risk is usually based on the current status of the network device itself, and there is a lack of multi-angle consideration of the risks faced by the device from the time and space relationship of the device. Therefore, the vulnerability information pushed by the communication management system to relevant managers is not accurate enough. Summary of the invention

[0004] The purpose of the present invention is to provide a data analysis method and system based on communication security situation awareness to solve the problems raised in the prior art.

[0005] To achieve the above object, the present invention provides the following technical solution: a data analysis method based on communication security situation awareness, the method comprising: Step S100: Collect vulnerability features of network device vulnerabilities from the operation and maintenance records of the communication system, collect the vulnerability features to obtain a vulnerability knowledge base, collect the matching degree between the network device and each vulnerability feature, and obtain a risk feature sequence of the network device; Step S200: obtaining operation records of all network devices in the communication system, collecting the time series operation feature sequences of each network device within a time range, and performing dimension compression on the time series feature sequences to obtain a time series feature matrix of the communication system; Step S300: Capture the spatial relationship of network devices in the communication system through the attention mechanism, perform weighted fusion of the temporal features and spatial relationships in the communication system, and obtain the risk matrix of all network devices in the communication system; Step S400: extracting the risk feature vector of each network device from the risk matrix, and obtaining the threat score of the corresponding network device by means of dimensional compression and linear mapping; Step S500: Obtain the risk feature sequence and threat score of the network device, calculate the risk assessment value of each vulnerability of all network devices, and provide the relevant vulnerability information of the network device to the administrator of the communication system according to the order of risk assessment value from large to small.

[0006] Furthermore, step S100 includes: Step S101: Collecting the processing records of network device vulnerabilities in the communication system from the operation and maintenance records of the communication system, annotating the network device vulnerabilities by name, collecting the names of all network device vulnerabilities in the communication system, collecting word vectors of the names as vulnerability features of the network device vulnerabilities, and collecting the word vectors of all network device vulnerabilities to obtain a vulnerability knowledge base; Step S102: numbering the network devices in the communication system, obtaining semantic features in the operation log of the ith network device in the communication system, corresponding each semantic feature to a semantic feature vector, and collecting all semantic feature vectors generated by the ith network device in a certain unit time period to obtain a semantic feature sequence; Step S103: Calculate the similarity between the word vectors in the vulnerability knowledge base and the semantic feature vectors in the semantic feature sequence one by one, obtain the maximum value of the similarity between each word vector and the semantic feature vector, take the maximum value of the similarity of each word vector as the similarity matching value of the word vector, and collect all the corresponding similarity matching values ​​of the operation log of the i-th network device to obtain the risk feature sequence; Through natural language processing models, such as BERT, feature extraction is performed on the vulnerability description of the device, such as extracting the description text from the CVE database, and feature extraction and encoding of the vulnerability type, impact range, attack method, etc., and feature extraction is performed on the device operation log of the device, and features such as software version, configuration information, and service status are extracted and encoded to obtain the device's fingerprint vector f. The highest match of each vulnerability feature is matched and triggered to obtain the probability of the network device being affected by the vulnerability risk.

[0007] Further, step S200 includes: Step S201: obtaining the operation records of each network device in the communication system, and obtaining the operation characteristics of each network device in a unit time period, wherein the operation characteristics include network traffic characteristics and communication protocol distribution in a unit time period; Step S202: sampling the operation records of the ith network device in a certain unit time period, composing the sampled operation features into an operation record sequence, extracting a feature vector of the operation feature of a network device from the operation record at each sampling moment, arranging the feature vectors in chronological order, and obtaining an operation feature time series; Step S203: extracting the time series forward propagation features and the time series backward propagation features of the running feature time series through the bidirectional LSTM, obtaining the time series forward feature vector and the time series backward feature vector of a certain unit time period, and concatenating the time series forward feature vector and the time series backward feature vector to obtain the time series features of a certain unit time period; Step S204: Gather the time series characteristics of several unit time periods of the ith network device to obtain the time series characteristic sequence of the ith network device, which is recorded as H LSTM i ; Step S205: Gather the time series feature sequences of all devices, and compress the time series feature sequences by the maximum pooling method to obtain the time series feature matrix H of all network devices. LSTM ; In the dynamic feature fusion mechanism, MaxPool is used to compress the temporal features output by the LSTM branch into the spatial dimension to achieve dimension alignment with the Transformer branch so as to facilitate fusion with the Transformer branch in subsequent steps.

[0008] Furthermore, step S300 includes: Step S301: Gather the d-dimensional operation features of all network devices in the communication system in a certain unit time period to form an input tensor X, where each operation feature corresponds to one dimension, and the three-dimensional size of the input tensor is N×τ×d, where N represents the number of network devices in the communication system, and τ represents the length of a certain unit time period. The input tensor is expanded from the device dimension to the sequence dimension to obtain X2, and the three-dimensional size of X2 is τ×N×d; Step S302: Sample a time points from a unit time period, and calculate the coding matrix E of the communication system at the t-th time point in the unit time period. t , E t =X2W e +P, where W e is the feature embedding matrix, the size of the feature embedding matrix is ​​d×d h , d h is an integer multiple of d and an integer power of 2, P is the network device position coding matrix, and the position coding matrix includes the logical relationship coding of the network device at the tth moment; The position code P is used to distinguish the spatial locations of different devices. Even if the physical location of the device is unknown, the model can still learn its logical relationship. This allows the model to not only focus on the physical connection relationship with the network device, but also capture the spatial relationship of network devices in flexible scenarios, providing key spatial relationship features for subsequent threat scoring. Step S303: Get Q t , K t and V t , where Q t =E t W Q , K t =E t W K , V t =Et W V , where W Q , W K and W V is the weight matrix, and calculates the attention at the tth moment t , , where d k =d h / h, h represents the number of attention heads, and d h is an integer multiple of h, and softmax represents the softmax activation function; Step S304: Calculate the attention of all a moments and extract the cross-time pattern H through time dimension convolution trans , , where “;” represents the vector concatenation operator and Conv1D represents a one-dimensional convolutional neural network layer; Step S305: In a certain unit time period, the risk matrix H of all network devices in the communication system fusion , H fusion =G⊙H LSTM +(1-G)H trans , where G represents the weight matrix and ⊙ represents the Hadamard product.

[0009] Furthermore, step S400 includes: Step S401: Obtain the feature vector corresponding to the dimension of the ith row in the risk matrix as the risk feature vector of the ith network device, and record the risk feature vector as H Fusion i ; Step S402: Calculate the threat score threat of the ith network device through the MLP neural network i , , where w s T Represents the linear mapping weight of the threat score, which is the weight vector w s The transpose of s represents the bias term; The weights of the two branches are dynamically adjusted through G and 1-G, and the LSTM and Transformer branches are dynamically integrated to adapt to different threat types while enhancing the robustness of the model. The perception granularity of the LSTM branch is finer and is used to locate the abnormal time point of specific network equipment. The perception granularity of the Transformer branch is coarser and is used to identify the risk pattern of the entire network. The model's perception of the communication network status is improved through multi-level fusion. When the weight of LSTM is large, it reflects that the network device anomaly is mainly caused by changes in timing behavior, such as a sudden increase in traffic. When the weight of Transformer is large, it reflects that the cause of the network device anomaly is greatly affected by the correlation characteristics between devices, such as the diffusion relationship of risks in network devices.

[0010] Furthermore, step S500 includes: Step S501: Obtain the threat score of the ith network device, multiply the threat score by the risk feature sequence to obtain the risk feature value sequence of the ith network device, establish a new dimension according to the device sequence number, and collect the risk feature value sequences of all network devices in order to obtain the risk feature matrix of the communication system; Step S502: sort all matrix elements in the risk feature matrix from large to small to obtain a risk warning sequence, obtain the word vectors corresponding to the sequence number and similarity matching value of the network device according to the order of the risk warning sequence, and obtain the network device vulnerability corresponding to the word vector; Step S503: The network device number and the network device vulnerability are combined into an alarm information group, all the alarm information groups are arranged in the order of the risk alarm sequence, and pushed to the administrator of the communication system.

[0011] In order to better implement the above method, a data analysis system based on communication security situation awareness is also proposed, the system includes: Vulnerability management module, time series feature management module, risk matrix management module, threat score management module and risk warning module, wherein the vulnerability management module is used to obtain the vulnerability features of network devices from the operation and maintenance records of network devices, match the operation features of network devices with the vulnerability features, and manage the risk feature sequence of network devices; the time series feature management module is used to collect the time series features of the operation status of network devices and manage the time series feature matrix of the communication system; the risk matrix management module is used to weightedly fuse the time series features and spatial relationships and manage the risk matrix of all network devices in the communication system; the threat score management module is used to manage the threat scores of network devices; the risk warning module is used to calculate the risk assessment value of each network device and provide risk warnings to relevant managers; Further, the vulnerability management module includes: a vulnerability knowledge base management unit, a semantic vector management unit and a risk feature sequence management unit, wherein the vulnerability knowledge base management unit is used to manage the vulnerability knowledge base of the communication system, the semantic vector management unit is used to manage the word vectors of the vulnerability knowledge base and the semantic feature vectors of the network device operation log, and the risk feature sequence management unit is used to compare the similarity between the word vector and the semantic feature vector to obtain the risk feature sequence of the network device; Furthermore, the timing feature management module includes an operation feature management unit, an operation feature time series management unit, a timing feature extraction unit and a dimension compression unit. The operation feature management unit is used to manage the operation features of the network device, the operation feature time series management unit is used to manage the operation feature time series, the timing feature extraction unit is used to establish a bidirectional LSTM propagation model, extract the timing feature sequence of each network device, and the dimension compression unit is used to perform dimension compression on the timing feature sequence of the device and manage the timing feature matrix of the network device. Furthermore, the risk matrix management module includes: a spatial feature acquisition unit, an attention mechanism calculation unit, a spatial feature management unit and a feature fusion unit. The spatial feature acquisition unit is used to expand the dimension of the operation status of the network device and embed the spatial feature code to manage the spatial relationship of the network device. The attention mechanism calculation unit is used to capture the attention features of the spatial relationship of the network device through the head attention mechanism. The spatial feature management unit is used to obtain the cross-time spatial features of the network device through a one-dimensional convolutional neural network. The feature fusion unit is used to fuse the temporal features and spatial features of the network device to obtain the risk matrix of the network device. Further, the threat score management module includes: a risk feature vector management unit and a threat score management unit, the threat score management unit is used to obtain the threat score of the corresponding network device by means of dimensional compression and linear mapping; Furthermore, the risk warning module includes: a risk characteristic matrix management unit, a risk assessment value sorting unit and an information reminder unit, wherein the risk characteristic matrix management unit is used to sequence the risk characteristic values ​​of the network equipment and manage the risk characteristic matrix of the communication system; the risk assessment value sorting unit is used to sort the elements in the risk characteristic matrix; and the information reminder unit is used to push the network equipment number and network equipment vulnerability to relevant management personnel.

[0012] Compared with the prior art, the beneficial effects of the present invention are: capturing the behavior of network devices themselves through time dimension features, such as the abnormal behavior of a single device after being invaded, and capturing the relationship between network devices through space dimension features, such as the spread of network penetration between devices, ultimately forming a closed loop from risk calculation to repair decision-making, effectively reducing the attack surface.

[0013] The beneficial effects of the present invention also include: 1. Precise positioning: identifying high-risk device-vulnerability pairs; 2. Global optimization: determining repair priorities from the perspective of the entire network; 3. Dynamic response: adapting to changes in network status and improving defense efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 It is a flow chart of a data analysis method based on communication security situation awareness of the present invention; Figure 2It is a structural schematic diagram of the data analysis system based on communication security situation awareness of the present invention. DETAILED DESCRIPTION

[0015] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0016] Example: Figure 1-Figure 2 As shown, the present invention provides a technical solution, a data analysis method and system based on communication security situation awareness: Step S100: Collect vulnerability features of network device vulnerabilities from the operation and maintenance records of the communication system, collect the vulnerability features to obtain a vulnerability knowledge base, collect the matching degree between the network device and each vulnerability feature, and obtain a risk feature sequence of the network device; Wherein, step S100 includes: Step S101: Collecting the processing records of network device vulnerabilities in the communication system from the operation and maintenance records of the communication system, annotating the network device vulnerabilities by name, collecting the names of all network device vulnerabilities in the communication system, collecting word vectors of the names as vulnerability features of the network device vulnerabilities, and collecting the word vectors of all network device vulnerabilities to obtain a vulnerability knowledge base; Step S102: numbering the network devices in the communication system, obtaining semantic features in the operation log of the ith network device in the communication system, corresponding each semantic feature to a semantic feature vector, and collecting all semantic feature vectors generated by the ith network device in a certain unit time period to obtain a semantic feature sequence; Step S103: Calculate the similarity between the word vectors in the vulnerability knowledge base and the semantic feature vectors in the semantic feature sequence one by one, obtain the maximum value of the similarity between each word vector and the semantic feature vector, take the maximum value of the similarity of each word vector as the similarity matching value of the word vector, and collect all the corresponding similarity matching values ​​of the operation log of the i-th network device to obtain the risk feature sequence; In an embodiment, a public database such as a CVE database may be selected to supplement the vulnerability knowledge base; For example, the vulnerability knowledge base includes r word vectors, which are recorded as (v1, v2, v3, ..., vr), where v1, v2, v3, ... and vr are the first, second, third, ... and rth word vectors respectively. Get a total of j semantic feature vectors generated by the ith network device in a certain unit time, calculate the similarity between v1 and the j semantic feature vectors respectively, take the maximum similarity value as the first similarity matching value, traverse the word vectors and semantic feature vectors in the order of the vulnerability knowledge base, generate a total of r similarity matching values, and collect all similarity matching values ​​to obtain the risk feature sequence of the ith network device.

[0017] Step S200: obtaining operation records of all network devices in the communication system, collecting the time series operation feature sequences of each network device within a time range, and performing dimension compression on the time series feature sequences to obtain a time series feature matrix of the communication system; Wherein, step S200 includes: Step S201: obtaining the operation records of each network device in the communication system, and obtaining the operation characteristics of each network device in a unit time period, wherein the operation characteristics include network traffic characteristics and communication protocol distribution in a unit time period; Step S202: sampling the operation records of the ith network device in a certain unit time period, composing the sampled operation features into an operation record sequence, extracting a feature vector of the operation feature of a network device from the operation record at each sampling moment, arranging the feature vectors in chronological order, and obtaining an operation feature time series; Step S203: extracting the time series forward propagation features and the time series backward propagation features of the running feature time series through the bidirectional LSTM, obtaining the time series forward feature vector and the time series backward feature vector of a certain unit time period, and concatenating the time series forward feature vector and the time series backward feature vector to obtain the time series features of a certain unit time period; Step S204: Gather the time series characteristics of several unit time periods of the ith network device to obtain the time series characteristic sequence of the ith network device, which is recorded as H LSTM i ; Step S205: Gather the time series feature sequences of all devices, and compress the time series feature sequences by the maximum pooling method to obtain the time series feature matrix H of all network devices. LSTM ; In the embodiment, the operation feature vector of the ith network device is obtained and arranged in chronological order to obtain Xi, where the operation feature vector at the lth moment is recorded as x l ; Building a bidirectional LSTM: , ; ; where h fwd represents the vector in the forward propagation LSTM branch, hbwd Represents the vector in the backward propagation LSTM branch, and the “;” in the formula represents the vector concatenation operator; In the embodiment, the temporal feature sequence output by the bidirectional LSTM preferably has a column dimension of 2h; The size of the time series feature sequence output by one of the devices is τ×2h, and the total time series feature sequence H of N network devices is collected. LSTM 0, the size of the obtained three-dimensional tensor is N×τ×2h; The method for compressing the size of a three-dimensional tensor is H LSTM [m,d]=max(H LSTM 0[m,c,d]) where c∈{1,2,3,…,a}, H LSTM [m,d] means H LSTM The element in the mth row and dth column of H LSTM 0[m,c,d] represents H LSTM 0, the element with three-dimensional coordinates (m, c, d), max represents the maximum value function, and the final output H LSTM The size is N×2h.

[0018] Step S300: Capture the spatial relationship of network devices in the communication system through the attention mechanism, perform weighted fusion of the temporal features and spatial relationships in the communication system, and obtain the risk matrix of all network devices in the communication system; Wherein, step S300 includes: Step S301: Gather the d-dimensional operation features of all network devices in the communication system in a certain unit time period to form an input tensor X, where each operation feature corresponds to one dimension, and the three-dimensional size of the input tensor is N×τ×d, where N represents the number of network devices in the communication system, and τ represents the length of a certain unit time period. The input tensor is expanded from the device dimension to the sequence dimension to obtain X2, and the three-dimensional size of X2 is τ×N×d; Step S302: Sample a time points from a unit time period, and calculate the coding matrix E of the communication system at the t-th time point in the unit time period. t , E t =X2W e +P, where W e is the feature embedding matrix, the size of the feature embedding matrix is ​​d×d h , d h is an integer multiple of d and an integer power of 2, P is the network device position coding matrix, and the position coding matrix includes the logical relationship coding of the network device at the tth moment; Step S303: Get Q t , K t and V t , where Qt =E t W Q , K t =E t W K , V t =E t W V , where W Q , W K and W V is the weight matrix, and calculates the attention at the tth moment t , , where d k =d h / h, h represents the number of attention heads, and d h is an integer multiple of h, and softmax represents the softmax activation function; Step S304: Calculate the attention of all a moments and extract the cross-time pattern H through time dimension convolution trans , , where “;” represents the vector concatenation operator and Conv1D represents a one-dimensional convolutional neural network layer; Step S305: In a certain unit time period, the risk matrix H of all network devices in the communication system fusion , H fusion =G⊙H LSTM +(1-G)H trans , where G represents the weight matrix and ⊙ represents the Hadamard product; In the embodiment, H LSTM Matrix and H trans The matrix is ​​concatenated to obtain H concat Matrix, H concat =[H LSTM ;H trans ]; G = σ(W g ·H concat +b g ), where σ represents the Sigmoid function, which compresses the elements in the matrix G to the interval [0,1], and W g represents the weight matrix, b g represents the bias term; In the risk matrix calculation process, H fusion The element H in the xth row and yth column fusion (x, y) is calculated as: H fusion (x, y) = G (x, y) H LSTM (x,y)+(1-G(x,y))·H trans(x, y), where G(x, y) represents the element in the xth row and yth column of the matrix G, and H LSTM (x, y) represents the matrix H LSTM The element in the xth row and yth column of H trans (x, y) represents the matrix H trans The xth row and yth column element in .

[0019] Step S400: extracting the risk feature vector of each network device from the risk matrix, and obtaining the threat score of the corresponding network device by means of dimensional compression and linear mapping; Wherein, step S400 includes: Step S401: Obtain the feature vector corresponding to the dimension of the ith row in the risk matrix as the risk feature vector of the ith network device, and record the risk feature vector as H Fusion i ; Step S402: Calculate the threat score threat of the ith network device through the MLP neural network i , , where w s T Represents the linear mapping weight of the threat score, which is the weight vector w s The transpose of s represents the bias term; In the embodiment w s and b s It is automatically learned through training data, for example, by using the Xavier method to train w s Initialize bs by setting a small constant of 0 or close to 0, such as 0.01, and use the back propagation method to initialize w s and b s Perform parameter learning; For example, threat i The probability distribution of is used as a variable to establish the cross entropy loss function, and the gradient descent algorithm such as the Adam algorithm is used to s and b s Update parameters; In the embodiment, several ReLu functions are set to calculate H by using the MLP neural network. Fusion i The column dimension of the model is gradually reduced layer by layer until it reaches 1 dimension, and the output dimension compression result is converted into probability through the Sigmoid function. The output of the threat score is a probability value.

[0020] Step S500: Obtain risk feature sequences and threat scores of network devices, calculate risk assessment values ​​of various vulnerabilities of all network devices, and provide relevant vulnerability information of network devices to managers of the communication system in descending order of risk assessment values; Wherein, step S500 includes: Step S501: Obtain the threat score of the ith network device, multiply the threat score by the risk feature sequence to obtain the risk feature value sequence of the ith network device, establish a new dimension according to the device sequence number, and collect the risk feature value sequences of all network devices in order to obtain the risk feature matrix of the communication system; Step S502: sort all matrix elements in the risk feature matrix from large to small to obtain a risk warning sequence, obtain the word vectors corresponding to the sequence number and similarity matching value of the network device according to the order of the risk warning sequence, and obtain the network device vulnerability corresponding to the word vector; Step S503: The network device number and the network device vulnerability are combined into an alarm information group, all the alarm information groups are arranged in the order of the risk alarm sequence, and pushed to the administrator of the communication system.

[0021] The system includes: vulnerability management module, time series feature management module, risk matrix management module, threat score management module and risk warning module; Among them, the vulnerability management module is used to obtain the vulnerability characteristics of the network device from the operation and maintenance records of the network device, match the operation characteristics of the network device with the vulnerability characteristics, and manage the risk feature sequence of the network device. Among them, the vulnerability management module includes: a vulnerability knowledge base management unit, a semantic vector management unit and a risk feature sequence management unit, wherein the vulnerability knowledge base management unit is used to manage the vulnerability knowledge base of the communication system, the semantic vector management unit is used to manage the word vector of the vulnerability knowledge base and the semantic feature vector of the network device operation log, and the risk feature sequence management unit is used to compare the similarity between the word vector and the semantic feature vector to obtain the risk feature sequence of the network device; Among them, the timing feature management module is used to collect the timing features of the operation status of the network equipment and manage the timing feature matrix of the communication system. Among them, the timing feature management module includes an operation feature management unit, an operation feature time series management unit, a timing feature extraction unit and a dimension compression unit. The operation feature management unit is used to manage the operation features of the network equipment, the operation feature time series management unit is used to manage the operation feature time series, the timing feature extraction unit is used to establish a bidirectional LSTM propagation model, extract the timing feature sequence of each network equipment, and the dimension compression unit is used to compress the dimension of the timing feature sequence of the equipment and manage the timing feature matrix of the network equipment; Among them, the risk matrix management module is used to weightedly fuse the temporal features and spatial relationships to manage the risk matrix of all network devices in the communication system. Among them, the risk matrix management module includes: a spatial feature acquisition unit, an attention mechanism calculation unit, a spatial feature management unit and a feature fusion unit. The spatial feature acquisition unit is used to dimensionally expand the operating status of the network device and embed the spatial feature code to manage the spatial relationship of the network device. The attention mechanism calculation unit is used to capture the attention features of the spatial relationship of the network device through the head attention mechanism. The spatial feature management unit is used to obtain the cross-time spatial features of the network device through a one-dimensional convolutional neural network. The feature fusion unit is used to fuse the temporal features and spatial features of the network device to obtain the risk matrix of the network device; The threat score management module is used to manage the threat score of the network device, wherein the threat score management module includes: a risk feature vector management unit and a threat score management unit, and the threat score management unit is used to obtain the threat score of the corresponding network device by means of dimensional compression and linear mapping; Among them, the risk warning module is used to calculate the risk assessment value of each network device and provide risk warnings to relevant managers. The risk warning module includes: a risk characteristic matrix management unit, a risk assessment value sorting unit and an information reminder unit. Among them, the risk characteristic matrix management unit is used to sequence the risk characteristic values ​​of network devices and manage the risk characteristic matrix of the communication system. The risk assessment value sorting unit is used to sort the elements in the risk characteristic matrix. The information reminder unit is used to push the network device number and network device vulnerability to relevant managers.

[0022] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and range of equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.

Claims

1. A data analysis method based on communication security situation awareness, characterized in that: The method comprises the steps of: Step S100: Collect vulnerability features of network device vulnerabilities from the operation and maintenance records of the communication system, collect the vulnerability features to obtain a vulnerability knowledge base, collect the matching degree between the network device and each vulnerability feature, and obtain a risk feature sequence of the network device; Step S200: obtaining operation records of all network devices in the communication system, collecting the time series operation feature sequences of each network device within a time range, and performing dimension compression on the time series feature sequences to obtain a time series feature matrix of the communication system; Step S300: Capture the spatial relationship of network devices in the communication system through the attention mechanism, perform weighted fusion of the temporal features and spatial relationships in the communication system, and obtain the risk matrix of all network devices in the communication system; Step S400: extracting the risk feature vector of each network device from the risk matrix, and obtaining the threat score of the corresponding network device by means of dimensional compression and linear mapping; Step S500: Obtain the risk feature sequence and threat score of the network device, calculate the risk assessment value of each vulnerability of all network devices, and provide the relevant vulnerability information of the network device to the administrator of the communication system according to the order of risk assessment value from large to small.

2. The data analysis method based on communication security situation awareness according to claim 1 is characterized in that: Step S100 includes: Step S101: Collecting the processing records of network device vulnerabilities in the communication system from the operation and maintenance records of the communication system, annotating the network device vulnerabilities by name, collecting the names of all network device vulnerabilities in the communication system, collecting word vectors of the names as vulnerability features of the network device vulnerabilities, and collecting the word vectors of all network device vulnerabilities to obtain a vulnerability knowledge base; Step S102: numbering the network devices in the communication system, obtaining semantic features in the operation log of the ith network device in the communication system, corresponding each semantic feature to a semantic feature vector, and collecting all semantic feature vectors generated by the ith network device in a certain unit time period to obtain a semantic feature sequence; Step S103: Calculate the similarity between the word vectors in the vulnerability knowledge base and the semantic feature vectors in the semantic feature sequence one by one, obtain the maximum value of the similarity between each word vector and the semantic feature vector, take the maximum value of the similarity of each word vector as the similarity matching value of the word vector, and aggregate all the corresponding similarity matching values ​​of the operation log of the i-th network device to obtain the risk feature sequence.

3. The data analysis method based on communication security situation awareness according to claim 2 is characterized in that: Step S200 includes: Step S201: obtaining operation records of each network device in the communication system, and obtaining operation characteristics of each network device in a unit time period, wherein the operation characteristics include network traffic characteristics and communication protocol distribution in a unit time period; Step S202: sampling the operation records of the ith network device in a certain unit time period, composing the sampled operation features into an operation record sequence, extracting a feature vector of the operation feature of a network device from the operation record at each sampling moment, arranging the feature vectors in chronological order, and obtaining an operation feature time series; Step S203: extracting the time series forward propagation features and the time series backward propagation features of the running feature time series through the bidirectional LSTM, obtaining the time series forward feature vector and the time series backward feature vector of a certain unit time period, and concatenating the time series forward feature vector and the time series backward feature vector to obtain the time series features of a certain unit time period; Step S204: Gather the time series characteristics of several unit time periods of the ith network device to obtain the time series characteristic sequence of the ith network device, which is recorded as H LSTM i ; Step S205: Gather the time series feature sequences of all devices, and compress the time series feature sequences by the maximum pooling method to obtain the time series feature matrix H of all network devices. LSTM .

4. The data analysis method based on communication security situation awareness according to claim 3 is characterized in that: Step S300 includes: Step S301: Gather d-dimensional operation features of all network devices in a communication system in a unit time period to form an input tensor X, where each operation feature corresponds to one dimension, and the three-dimensional size of the input tensor is N×τ×d, where N represents the number of network devices in the communication system, and τ represents the length of a unit time period. The input tensor is expanded from the device dimension to the sequence dimension to obtain X2, and the three-dimensional size of X2 is τ×N×d; Step S302: sampling a time points from the unit time period, and calculating the coding matrix E of the communication system at the t-th time point in the unit time period t , E t =X2W e +P, where W e is a feature embedding matrix, the size of which is d×d h , d h is an integer multiple of d and an integer power of 2, P is a network device position coding matrix, and the position coding matrix includes the logical relationship coding of the network device at the t-th moment; Step S303: Get Q t , K t and V t , where Q t =E t W Q , K t =E t W K , V t =E t W V , where W Q , W K and W V is the weight matrix, and calculates the attention at the tth moment t , , where d k =d h / h, h represents the number of heads of attention, and d h is an integer multiple of h, and softmax represents the softmax activation function; Step S304: Calculate the attention of all a moments and extract the cross-time pattern H through time dimension convolution trans , , where ";" represents the vector concatenation operator and Conv1D represents a one-dimensional convolutional neural network layer; Step S305: In the unit time period, the risk matrix H of all network devices in the communication system fusion , H fusion =G⊙H LSTM +(1-G)H trans , where G represents the weight matrix and ⊙ represents the Hadamard product.

5. The data analysis method based on communication security situation awareness according to claim 4 is characterized in that: Step S400 includes: Step S401: Obtain the feature vector corresponding to the dimension of the ith row in the risk matrix as the risk feature vector of the ith network device, and record the risk feature vector as H Fusion i ; Step S402: Calculate the threat score threat of the ith network device through the MLP neural network i , , where w s T Represents the linear mapping weight of the threat score, which is the weight vector w s The transpose of s Represents the bias term.

6. The data analysis method based on communication security situation awareness according to claim 5 is characterized in that: Step S500 includes: Step S501: Obtain the threat score of the ith network device, multiply the threat score by the risk feature sequence to obtain the risk feature value sequence of the ith network device, establish a new dimension according to the device sequence number, and collect the risk feature value sequences of all network devices in order to obtain the risk feature matrix of the communication system; Step S502: sort all matrix elements in the risk feature matrix from large to small to obtain a risk warning sequence, obtain the word vectors corresponding to the sequence numbers and similarity matching values ​​of the network devices in the order of the risk warning sequence, and obtain the network device vulnerabilities corresponding to the word vectors; Step S503: The network device number and the network device vulnerability are combined into an alarm information group, all the alarm information groups are arranged in the order of the risk alarm sequence, and pushed to the administrator of the communication system.

7. A data analysis system based on communication security situation awareness, used to execute the data analysis method based on communication security situation awareness according to any one of claims 1 to 6, characterized in that: The system includes: Vulnerability management module, timing feature management module, risk matrix management module, threat score management module and risk warning module, among which, the vulnerability management module is used to obtain the vulnerability features of network devices from the operation and maintenance records of network devices, match the operation features of network devices with the vulnerability features, and manage the risk feature sequence of network devices. The timing feature management module is used to collect the timing features of the operating status of network devices and manage the timing feature matrix of the communication system. The risk matrix management module is used to weightedly fuse the timing features and spatial relationships and manage the risk matrix of all network devices in the communication system. The threat score management module is used to manage the threat scores of network devices. The risk warning module is used to calculate the risk assessment value of each network device and provide risk warnings to relevant managers.

8. The data analysis system based on communication security situation awareness according to claim 7 is characterized in that: The vulnerability management module includes: a vulnerability knowledge base management unit, a semantic vector management unit and a risk feature sequence management unit, wherein the vulnerability knowledge base management unit is used to manage the vulnerability knowledge base of the communication system, the semantic vector management unit is used to manage the word vectors of the vulnerability knowledge base and the semantic feature vectors of the network device operation log, and the risk feature sequence management unit is used to compare the similarity between the word vector and the semantic feature vector to obtain the risk feature sequence of the network device.

9. The data analysis system based on communication security situation awareness according to claim 7 is characterized in that: The time series feature management module includes an operation feature management unit, an operation feature time series management unit, a time series feature extraction unit and a dimension compression unit. The operation feature management unit is used to manage the operation features of network devices, the operation feature time series management unit is used to manage the operation feature time series, the time series feature extraction unit is used to establish a bidirectional LSTM propagation model, extract the time series feature sequence of each network device, and the dimension compression unit is used to perform dimension compression on the time series feature sequence of the device and manage the time series feature matrix of the network device. The risk matrix management module includes: a spatial feature acquisition unit, an attention mechanism calculation unit, a spatial feature management unit and a feature fusion unit. The spatial feature acquisition unit is used to expand the dimension of the operating status of the network device and embed the spatial feature code to manage the spatial relationship of the network device. The attention mechanism calculation unit is used to capture the attention features of the spatial relationship of the network device through the head attention mechanism. The spatial feature management unit is used to obtain the cross-time spatial features of the network device through a one-dimensional convolutional neural network. The feature fusion unit is used to fuse the temporal features and spatial features of the network device to obtain the risk matrix of the network device.

10. The data analysis system based on communication security situation awareness according to claim 7 is characterized in that: The threat score management module includes: a risk feature vector management unit and a threat score management unit, and the threat score management unit is used to obtain the threat score of the corresponding network device by means of dimension compression and linear mapping; The risk warning module includes: a risk feature matrix management unit, a risk assessment value sorting unit and an information reminder unit, wherein the risk feature matrix management unit is used for the risk feature value sequence of the network equipment and the risk feature matrix of the management communication system; the risk assessment value sorting unit is used for sorting the elements in the risk feature matrix; and the information reminder unit is used for pushing the network equipment number and network equipment vulnerability to relevant management personnel.

Citation Information

Patent Citations

  • Action recognition method based on double-flow convolution attention

    CN112926396A

  • Vulnerability patch existence detection method based on deep learning

    CN116108446A

  • Safety detection and efficiency verification method for penetration test tool

    CN118764237A

  • Controllable video generation method and system based on multi-modal fusion

    CN119091362A

  • Systems and methods for risk-adaptive security investment optimization

    US20220366332A1

Cited By

  • System vulnerability detection method and device based on penetration test

    CN120658521A

  • System vulnerability detection method and device based on penetration test

    CN120658521B