Data Analysis Method and System Based on Communication Security Situation Awareness

The method and system for communication security situational awareness address the challenge of dynamic network monitoring by integrating vulnerability and spatial relation analysis to enhance threat detection and response efficiency.

CN119996071BActive Publication Date: 2025-07-15NANJING CONTROL COMM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510436666.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-15
Estimated Expiration
2045-04-09

AI Technical Summary

Technical Problem

In the prior art, the increase in the number of communication network equipment leads to frequent updates of network topology, and the inability to dynamically perceive the status of the communication system. The lack of multi-angle considerations in the judgment of device vulnerability risks, resulting in inaccurate vulnerability information.

Method used

Through data analysis methods based on communication security situation awareness, network equipment vulnerability characteristics are collected, vulnerability knowledge base is built, and the attention mechanism and two-way LSTM model are used to calculate the threat score and risk assessment value of network equipment to provide dynamic vulnerability information.

Benefits of technology

It realizes accurate positioning and global optimization of network equipment risks, dynamically responds to changes in network status, and improves defense efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996071B_ABST
    Figure CN119996071B_ABST
Patent Text Reader

Abstract

The present invention discloses a data analysis method and system based on communication security situation awareness, which relates to the technical field of network device data management. It collects the vulnerability characteristics of network device vulnerabilities from the operation and maintenance records of the communication system, obtains the time-series operation characteristic sequences of each network device within a time range, captures the spatial relationship of network devices in the communication system through the attention mechanism, performs weighted fusion on the time-series characteristics and spatial relationship in the communication system to obtain the risk matrix of all network devices in the communication system, extracts the risk feature vectors of each network device from the risk matrix, obtains the threat score of the corresponding network device through dimension compression and linear mapping, calculates the risk assessment values of each vulnerability of all network devices, and provides relevant vulnerability information of network devices to the management personnel of the communication system according to the order from large to small of the risk assessment values.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network device data management, and specifically to a data analysis method and system based on communication security situation awareness. Background Art

[0002] With the development of communication network technology, the number and types of network devices accessing the communication system are increasing day by day, and the security supervision of the communication network has become a key issue in related fields.

[0003] In traditional technical solutions, by establishing a network topology, such as a network management mechanism, the traffic of the communication link and the status of network devices are supervised. With the increase in the number of network devices accessing the communication network and the change of the obtained interface position, the network topology needs to be frequently updated, so the status of the communication system cannot be dynamically perceived. At the same time, the judgment of the device vulnerability risk is usually based on the current status of the network device itself for monitoring, lacking multi-angle consideration of the risks faced by the device from the spatio-temporal relationship of the device. Therefore, the vulnerability information pushed by the communication management system to relevant management personnel is not accurate enough. Summary of the Invention

[0004] The purpose of the present invention is to provide a data analysis method and system based on communication security situation awareness to solve the problems raised in the prior art.

[0005] To achieve the above purpose, the present invention provides the following technical solutions: A data analysis method based on communication security situation awareness, the method includes:

[0006] Step S100: Collect the vulnerability characteristics of network device vulnerabilities from the operation and maintenance records of the communication system, collect the vulnerability characteristics to obtain a vulnerability knowledge base, and collect the matching degrees between the network devices and each vulnerability characteristic to obtain the risk characteristic sequence of the network devices;

[0007] Step S200: Obtain the operation records of all network devices in the communication system, collect the time-series operation characteristic sequences of each network device within a time range, and perform dimension compression on the time-series characteristic sequences to obtain the time-series characteristic matrix of the communication system;

[0008] Step S300: Capture the spatial relationship of network devices in the communication system through an attention mechanism, and perform weighted fusion on the time-series characteristics and spatial relationship in the communication system to obtain the risk matrix of all network devices in the communication system;

[0009] Step S400: Extract the risk characteristic vectors of each network device from the risk matrix, and obtain the threat score of the corresponding network device through dimension compression and linear mapping;

[0010] Step S500: Obtain the risk feature sequence and threat score of the network device, calculate the risk assessment value of each vulnerability of all network devices, and provide the relevant vulnerability information of the network device to the management personnel of the communication system in the order from large to small according to the risk assessment value.

[0011] Further, step S100 includes:

[0012] Step S101: Collect the processing records of network device vulnerabilities from the operation and maintenance records of the communication system, label the names of network device vulnerabilities, gather the names of all network device vulnerabilities in the communication system, collect the word vectors of the names as the vulnerability features of network device vulnerabilities, and gather the word vectors of all network device vulnerabilities to obtain a vulnerability knowledge base;

[0013] Step S102: Number the network devices in the communication system, obtain the semantic features in the operation log of the i-th network device in the communication system, correspond each semantic feature to a semantic feature vector, and gather all the semantic feature vectors generated by the i-th network device in a certain unit time period to obtain a semantic feature sequence;

[0014] Step S103: Calculate the similarity between each word vector in the vulnerability knowledge base and the semantic feature vectors in the semantic feature sequence one by one, obtain the maximum value of the similarity between each word vector and the semantic feature vector, use the maximum value of the similarity of each word vector as the similarity matching value of the word vector, and gather all the corresponding similarity matching values of the operation log of the i-th network device to obtain a risk feature sequence;

[0015] Through a natural language processing model, such as BERT, extract the features of the device's vulnerability description, such as extracting the description text of the CVE database, and perform feature extraction and encoding for the vulnerability type, scope of influence, attack method, etc. Extract features from the device's device operation log, such as software version, configuration information, and service status, etc., and encode to obtain the fingerprint vector f of the device. Trigger the highest match for each vulnerability feature to obtain the probability of the network device being vulnerable to risks.

[0016] Further, step S200 includes:

[0017] Step S201: Obtain the operation records of each network device in the communication system, obtain the operation characteristics of each network device in a unit time period, and the operation characteristics include network traffic characteristics and the communication protocol distribution in the unit time period;

[0018] Step S202: Sample the operation records of the i-th network device in a certain unit time period, form an operation record sequence with the sampled operation characteristics, extract a feature vector of the operation characteristics of a network device for each sampled moment, and arrange the feature vectors in chronological order to obtain an operation feature time series;

[0019] Step S203: Extract the forward propagation feature and backward propagation feature of the operation feature time series through bidirectional LSTM, obtain the forward feature vector and backward feature vector of a certain unit time period, and splice the forward feature vector and backward feature vector to obtain the time series feature of a certain unit time period;

[0020] Step S204: Aggregate the time series features of several unit time periods of the i-th network device to obtain the time series feature sequence of the i-th network device denoted as H LSTM i ;

[0021] Step S205: Aggregate the time series feature sequences of all devices, and compress the dimension of the time series feature sequences through the max pooling method to obtain the time series feature matrix H of all network devices LSTM ;

[0022] In the dynamic feature fusion mechanism, max pooling (MaxPool) is used to compress the time series features output by the LSTM branch to the spatial dimension to achieve dimension alignment with the Transformer branch, so as to be fused with the Transformer branch in subsequent steps.

[0023] Furthermore, step S300 includes:

[0024] Step S301: Aggregate the d-dimensional operation features of all network devices in a certain unit time period in the communication system to form an input tensor X. Among them, each type of operation feature corresponds to one dimension. The three-dimensional size of the input tensor is N×τ×d, where N represents the number of network devices in the communication system, τ represents the time length of a certain unit time period. Expand the input tensor from the device dimension to the sequence dimension to obtain X2, and the three-dimensional size of X2 is τ×N×d;

[0025] Step S302: Sample a moments from a certain unit time period, and calculate the encoding matrix E of the communication system at the t-th moment in a certain unit time period t , E t =X2W e +P, where W e is the feature embedding matrix, and the size of the feature embedding matrix is d×d h , d hIs an integer multiple of d and a power of 2, and P is the network device location encoding matrix. The location encoding matrix includes the logical relationship encoding of the network device at the t-th moment;

[0026] The location encoding P is used to distinguish the spatial positions of different devices. Even if the physical positions of the devices are unknown, the model can still learn their logical relationships, enabling the model to not only focus on the physical connection relationships with the network devices, but also capture the spatial relationships of the network devices in flexible scenarios, providing key spatial relationship features for subsequent threat scoring;

[0027] Step S303: Obtain Q t , K t and V t , where Q t = E t W Q , K t = E t W K , V t = E t W V , where W Q , W K and W V are weight matrices, and calculate the attention Attention t , , where d k = d h / h, h represents the number of attention heads, and d h is an integer multiple of h, and softmax represents the softmax activation function;

[0028] Step S304: Calculate the attention at all a moments, and extract the cross-time pattern H through temporal dimension convolution trans , , where ";" represents the vector concatenation operator, and Conv1D represents the one-dimensional convolutional neural network layer;

[0029] Step S305: In a certain unit time period, the risk matrix H of all network devices in the communication system fusion , H fusion = G⊙H LSTM +(1 - G)H trans , where G represents the weight matrix, and ⊙ represents the Hadamard product.

[0030] Furthermore, step S400 includes:

[0031] Step S401: Take the eigenvector corresponding to the i-th row dimension in the risk matrix as the risk eigenvector of the i-th network device, and denote the risk eigenvector as H Fusioni ;

[0032] Step S402: Calculate the threat score threat of the i-th network device through an MLP neural network i , , where w s T represents the linear mapping weight of the threat score, which is the transpose of the weight vector w s , and b s represents the bias term;

[0033] Dynamically adjust the weights of the two branches through G and 1−G, perform dynamic fusion on the LSTM and Transformer branches, adapt to different threat types while enhancing the robustness of the model. The LSTM branch has a finer perception granularity and is used to determine the abnormal time point of specific network devices. The Transformer branch has a coarser perception granularity and is used to identify the risk patterns of the entire network. Improve the model's perception of the communication network state through a multi-level fusion method;

[0034] When the weight of the LSTM is large, it reflects that the abnormality of the network device is mainly caused by changes in timing behavior, such as sudden traffic increase. When the weight of the Transformer is large, it reflects that the cause of the network device abnormality is greatly affected by the correlation features between devices, such as the diffusion relationship of risks among network devices.

[0035] Further, step S500 includes:

[0036] Step S501: Obtain the threat score of the i-th network device, multiply the threat score by the risk feature sequence to obtain the risk feature value sequence of the i-th network device, establish a new dimension according to the device serial number, and sequentially collect the risk feature value sequences of all network devices to obtain the risk feature matrix of the communication system;

[0037] Step S502: Sort all matrix elements in the risk feature matrix from largest to smallest to obtain a risk warning sequence. Obtain the serial number of the network device and the word vector corresponding to the similarity matching value according to the order of the risk warning sequence, and obtain the network device vulnerability corresponding to the word vector;

[0038] Step S503: Combine the network device number and the network device vulnerability into an alarm information group, arrange all alarm information groups according to the order of the risk warning sequence, and push them to the management personnel of the communication system.

[0039] To better implement the above method, a data analysis system based on communication security situation awareness is also proposed. The system includes:

[0040] A vulnerability management module, a time series feature management module, a risk matrix management module, a threat scoring management module, and a risk warning module. Among them, the vulnerability management module is used to obtain the vulnerability features of network devices from the operation and maintenance records of network devices, match the operation features of network devices with the vulnerability features, and manage the risk feature sequence of network devices. The time series feature management module is used to collect the time series features of the operation status of network devices and manage the time series feature matrix of the communication system. The risk matrix management module is used to perform weighted fusion of time series features and spatial relationships and manage the risk matrix of all network devices in the communication system. The threat scoring management module is used to manage the threat scores of network devices. The risk warning module is used to calculate the risk assessment values of each network device and give risk warnings to relevant management personnel;

[0041] Furthermore, the vulnerability management module includes: a vulnerability knowledge base management unit, a semantic vector management unit, and a risk feature sequence management unit. Among them, the vulnerability knowledge base management unit is used to manage the vulnerability knowledge base of the communication system. The semantic vector management unit is used to manage the word vectors of the vulnerability knowledge base and the semantic feature vectors in the operation logs of network devices. The risk feature sequence management unit is used to compare the similarity between the word vectors and the semantic feature vectors to obtain the risk feature sequence of network devices;

[0042] Furthermore, the time series feature management module includes an operation feature management unit, an operation feature time series management unit, a time series feature extraction unit, and a dimension compression unit. The operation feature management unit is used to manage the operation features of network devices. The operation feature time series management unit is used to manage the operation feature time series. The time series feature extraction unit is used to establish a bidirectional LSTM propagation model to extract the time series feature sequences of each network device. The dimension compression unit is used to perform dimension compression on the time series feature sequences of devices and manage the time series feature matrix of network devices;

[0043] Furthermore, the risk matrix management module includes: a spatial feature acquisition unit, an attention mechanism calculation unit, a spatial feature management unit, and a feature fusion unit. The spatial feature acquisition unit is used to perform dimension expansion on the operation status of network devices and embed spatial feature encoding to manage the spatial relationships of network devices. The attention mechanism calculation unit is used to capture the attention features of the spatial relationships of network devices through the head attention mechanism. The spatial feature management unit is used to obtain the cross-time spatial features of network devices through a one-dimensional convolutional neural network. The feature fusion unit is used to fuse the time series features and spatial features of network devices to obtain the risk matrix of network devices;

[0044] Furthermore, the threat scoring management module includes: a risk feature vector management unit and a threat scoring management unit. The threat scoring management unit is used to obtain the threat scores of corresponding network devices through dimension compression and linear mapping;

[0045] Further, the risk warning module includes: a risk feature matrix management unit, a risk assessment value sorting unit, and an information reminder unit. Among them, the risk feature matrix management unit is used for the risk feature value sequence of network devices to manage the risk feature matrix of the communication system. The risk assessment value sorting unit is used to sort the elements in the risk feature matrix, and the information reminder unit is used to push the numbers of network devices and network device vulnerabilities to relevant management personnel.

[0046] Compared with the prior art, the beneficial effects of the present invention are: capturing the self-behavior of network devices through time dimension features, such as abnormal behavior after a single device is invaded, and capturing the relationship between network devices through space dimension features, such as the spread of network penetration among devices. Finally, a closed loop from risk calculation to repair decision is formed, effectively reducing the attack surface.

[0047] The beneficial effects of the present invention also include: 1. Precise positioning: identifying high-risk device-vulnerability pairs; 2. Global optimization: determining the repair priority from the perspective of the entire network; 3. Dynamic response: adapting to network state changes and improving the defense efficiency. Description of the Drawings

[0048] Figure 1 It is a schematic flowchart of the data analysis method based on communication security situation awareness of the present invention;

[0049] Figure 2 It is a schematic structural diagram of the data analysis system based on communication security situation awareness of the present invention. Detailed Embodiments

[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0051] Embodiment: As Figure 1 - Figure 2 shown, the present invention provides a technical solution, a data analysis method and system based on communication security situation awareness:

[0052] Step S100: Collect the vulnerability features of network device vulnerabilities from the operation and maintenance records of the communication system, gather the vulnerability features to obtain a vulnerability knowledge base, and gather the matching degrees between network devices and each vulnerability feature to obtain a risk feature sequence of network devices;

[0053] Among them, step S100 includes:

[0054] Step S101: Collect the processing records of network device vulnerabilities in the communication system from the operation and maintenance records of the communication system, label the names of the network device vulnerabilities, gather the names of all network device vulnerabilities in the communication system, collect the word vectors of the names as the vulnerability features of the network device vulnerabilities, and gather the word vectors of all network device vulnerabilities to obtain a vulnerability knowledge base;

[0055] Step S102: Number the network devices in the communication system, obtain the semantic features in the operation log of the i-th network device in the communication system, correspond each semantic feature to a semantic feature vector, and gather all the semantic feature vectors generated by the i-th network device in a certain unit time period to obtain a semantic feature sequence;

[0056] Step S103: Calculate the similarity between each word vector in the vulnerability knowledge base and the semantic feature vectors in the semantic feature sequence one by one, obtain the maximum value of the similarity between each word vector and the semantic feature vector, take the maximum value of the similarity of each word vector as the similarity matching value of the word vector, and gather all the similarity matching values corresponding to the operation log of the i-th network device to obtain a risk feature sequence;

[0057] In the embodiment, a public database such as the CVE database can be selected to supplement the vulnerability knowledge base;

[0058] For example, the vulnerability knowledge base includes r word vectors denoted as (v1, v2, v3,..., vr) respectively, where v1, v2, v3,... and vr are the 1st, 2nd, 3rd,... and r-th word vectors respectively,

[0059] Obtain a total of j semantic feature vectors generated by the i-th network device in a certain unit time. Calculate the similarity between v1 and the j semantic feature vectors respectively, take the maximum similarity value as the 1st similarity matching value, traverse the word vectors and semantic feature vectors in the order of the vulnerability knowledge base, and a total of r similarity matching values are generated. Gather all the similarity matching values to obtain the risk feature sequence of the i-th network device.

[0060] Step S200: Obtain the operation records of all network devices in the communication system, gather the time-series operation feature sequences of each network device within the time range, and perform dimensionality compression on the time-series feature sequences to obtain the time-series feature matrix of the communication system;

[0061] Among them, Step S200 includes:

[0062] Step S201: Obtain the operation records of each network device in the communication system, obtain the operation features of each network device in a unit time period, and the operation features include network traffic features and the communication protocol distribution in the unit time period;

[0063] Step S202: Sample the operation records of the i-th network device in a certain unit time period, form the operation feature sequence with the sampled operation features, extract the feature vector of the operation feature of a network device for each sampled time moment, and arrange the feature vectors in chronological order to obtain the operation feature time series;

[0064] Step S203: Extract the forward propagation feature and backward propagation feature of the operation feature time series through the bidirectional LSTM, obtain the forward feature vector and backward feature vector of a certain unit time period, and splice the forward feature vector and backward feature vector to obtain the time series feature of a certain unit time period;

[0065] Step S204: Aggregate the time series features of several unit time periods of the i-th network device to obtain the time series feature sequence of the i-th network device denoted as H LSTM i ;

[0066] Step S205: Aggregate the time series feature sequences of all devices, and compress the dimensions of the time series feature sequences through the max pooling method to obtain the time series feature matrix H of all network devices LSTM ;

[0067] In the embodiment, obtain the operation feature vector of the i-th network device, and arrange it in chronological order to obtain Xi, where the operation feature vector at the l-th moment is denoted as x l ;

[0068] Establish a bidirectional LSTM:

[0069] , ;

[0070] ;

[0071] where h fwd represents the vector in the forward propagation LSTM branch, h bwd represents the vector in the backward propagation LSTM branch, and ";" in the formula represents the vector splicing operator;

[0072] In the embodiment, the column dimension of the time series feature sequence output by the bidirectional LSTM is preferably 2h;

[0073] where the size of the time series feature sequence output by one device is τ×2h, and aggregate the time series feature sequences H LSTM 0 of a total of N network devices to obtain a three-dimensional tensor with a size of N×τ×2h;

[0074] The method for compressing the dimensions of the three-dimensional tensor is H LSTM[m,d]=max(H LSTM 0[m,c,d]) where c ∈ {1, 2, 3, ……, a}, H LSTM [m,d] represents the element in the m-th row and d-th column of H LSTM ; H LSTM 0[m,c,d] represents the element in H LSTM 0 with three-dimensional coordinates (m, c, d), max represents the maximum value function, and the finally output H LSTM has a size of N × 2h.

[0075] Step S300: Capture the spatial relationships of network devices in the communication system through the attention mechanism, and perform weighted fusion on the temporal features and spatial relationships in the communication system to obtain the risk matrix of all network devices in the communication system;

[0076] Among them, Step S300 includes:

[0077] Step S301: Aggregate the d-dimensional operation features of all network devices in the communication system in a certain unit time period to form the input tensor X. Among them, each type of operation feature corresponds to one dimension, and the three-dimensional size of the input tensor is N × τ × d. N represents the number of network devices in the communication system, τ represents the time length of a certain unit time period, and expand the input tensor from the device dimension to the sequence dimension to obtain X2. The three-dimensional size of X2 is τ × N × d;

[0078] Step S302: Sample a moments from a certain unit time period, and calculate the encoding matrix E t of the communication system at the t-th moment in a certain unit time period, E t = X2W e + P, where W e is the feature embedding matrix, and the size of the feature embedding matrix is d × d h , d h is an integer multiple of d and a power of 2, and P is the network device position encoding matrix, and the position encoding matrix includes the logical relationship encoding of the network device at the t-th moment;

[0079] Step S303: Obtain Q t , K t and V t , where Q t = E t W Q , K t = E t W K , V t = E t W V , where W Q , W K and W Vis the weight matrix, calculating the attention at the t-th moment t , , where d k = d h / h, h represents the number of attention heads, and d h is an integer multiple of h, softmax represents the softmax activation function;

[0080] Step S304: Calculate the attention at all a moments, and extract the cross-time pattern H through temporal dimension convolution trans , , where ";" represents the vector concatenation operator, and Conv1D represents the one-dimensional convolutional neural network layer;

[0081] Step S305: In a certain unit time period, the risk matrix H of all network devices in the communication system fusion , H fusion = G ⊙ H LSTM + (1 - G)H trans , where G represents the weight matrix, and ⊙ represents the Hadamard product;

[0082] In the embodiment, the H LSTM matrix and the H trans matrix are concatenated to obtain the H concat matrix, H concat = [H LSTM ; H trans ;

[0083] G = σ(W g · H concat + b g ), where σ represents the Sigmoid function, compressing the elements in the matrix G in the interval [0, 1], W g represents the weight matrix, and b g represents the bias term;

[0084] During the calculation of the risk matrix, the element H fusion at the x-th row and y-th column in H fusion (x, y) is calculated as follows:

[0085] H fusion (x, y) = G(x, y) · H LSTM (x, y) + (1 - G(x, y)) · H trans (x, y), where G(x, y) represents the element at the x-th row and y-th column in the matrix G, and H LSTM (x, y) represents the element at the x-th row and y-th column in the matrix H LSTM , and H trans (x, y) represents the element at the x-th row and y-th column in the matrix H transThe element in the x-th row and y-th column of

[0086] Step S400: Extract the risk feature vectors of each network device from the risk matrix, and obtain the threat score of the corresponding network device through dimension compression and linear mapping;

[0087] Among them, step S400 includes:

[0088] Step S401: Take the feature vector corresponding to the i-th row dimension in the risk matrix as the risk feature vector of the i-th network device, and denote the risk feature vector as H Fusion i ;

[0089] Step S402: Calculate the threat score threat of the i-th network device through the MLP neural network i , , where w s T represents the linear mapping weight of the threat score, which is the transpose of the weight vector w s b s represents the bias term;

[0090] In the embodiment, w s and b s are automatically learned through training data. For example, w s is initialized by the Xavier method, bs is initialized by setting a small constant of 0 or close to 0, such as 0.01, and the parameters of w s and b s are learned through the backpropagation method;

[0091] For example, a cross-entropy loss function is established with the probability distribution of threat i as a variable, and the parameters of w s and b s are updated through a gradient descent algorithm such as the Adam algorithm;

[0092] In the embodiment, several ReLu functions are set in the calculation of the MLP neural network to gradually decrease the column dimension of H Fusion i until it reaches 1 dimension, and then the output dimension compression result is converted into a probability through the Sigmoid function, and the output of the threat score is a probability value.

[0093] Step S500: Obtain the risk feature sequence and threat score of the network device, calculate the risk assessment values of various vulnerabilities of all network devices, and provide the relevant vulnerability information of the network device to the management personnel of the communication system in descending order of the risk assessment values;

[0094] Among them, step S500 includes:

[0095] Step S501: Obtain the threat score of the i-th network device, multiply the threat score by the risk feature sequence to obtain the risk feature value sequence of the i-th network device, establish a new dimension according to the device serial number, and collect the risk feature value sequences of all network devices in order to obtain the risk feature matrix of the communication system;

[0096] Step S502: Sort all matrix elements in the risk feature matrix from largest to smallest to obtain a risk warning sequence, obtain the serial number of the network device and the word vector corresponding to the similarity matching value according to the order of the risk warning sequence, and obtain the network device vulnerability corresponding to the word vector;

[0097] Step S503: Combine the number of the network device and the network device vulnerability into an alarm information group, arrange all alarm information groups according to the order of the risk warning sequence, and push them to the management personnel of the communication system.

[0098] The system includes: a vulnerability management module, a time series feature management module, a risk matrix management module, a threat score management module, and a risk prompt module;

[0099] Among them, the vulnerability management module is used to obtain the vulnerability features of the network device from the operation and maintenance records of the network device, match the operation features of the network device with the vulnerability features, and manage the risk feature sequence of the network device. Among them, the vulnerability management module includes: a vulnerability knowledge base management unit, a semantic vector management unit, and a risk feature sequence management unit. Among them, the vulnerability knowledge base management unit is used to manage the vulnerability knowledge base of the communication system, the semantic vector management unit is used to manage the word vectors of the vulnerability knowledge base and the semantic feature vectors in the network device operation logs, and the risk feature sequence management unit is used to compare the similarity of the word vectors and the semantic feature vectors to obtain the risk feature sequence of the network device;

[0100] Among them, the time series feature management module is used to collect the time series features of the network device operation status and manage the time series feature matrix of the communication system. Among them, the time series feature management module includes an operation feature management unit, an operation feature time series management unit, a time series feature extraction unit, and a dimension compression unit. The operation feature management unit is used to manage the operation features of the network device, the operation feature time series management unit is used to manage the operation feature time series, the time series feature extraction unit is used to establish a bidirectional LSTM propagation model to extract the time series features of each network device, and the dimension compression unit is used to perform dimension compression on the time series features of the device and manage the time series feature matrix of the network device;

[0101] Among them, the risk matrix management module is used to perform weighted fusion on the time series features and spatial relationships, and manage the risk matrices of all network devices in the communication system. Among them, the risk matrix management module includes: a spatial feature acquisition unit, an attention mechanism calculation unit, a spatial feature management unit, and a feature fusion unit. The spatial feature acquisition unit is used to expand the operation state of the network device in dimensions and embed spatial feature encoding to manage the spatial relationships of the network devices. The attention mechanism calculation unit is used to capture the attention features of the spatial relationships of the network devices through the head attention mechanism. The spatial feature management unit is used to obtain the cross-time spatial features of the network devices through a one-dimensional convolutional neural network. The feature fusion unit is used to fuse the time series features and spatial features of the network devices to obtain the risk matrix of the network devices;

[0102] Among them, the threat score management module is used to manage the threat scores of network devices. Among them, the threat score management module includes: a risk feature vector management unit and a threat score management unit. The threat score management unit is used to obtain the threat scores of the corresponding network devices through dimension compression and linear mapping;

[0103] Among them, the risk prompt module is used to calculate the risk assessment values of each network device and give risk prompts to relevant management personnel. Among them, the risk prompt module includes: a risk feature matrix management unit, a risk assessment value sorting unit, and an information reminder unit. Among them, the risk feature matrix management unit is used for the risk feature value sequence of the network device to manage the risk feature matrix of the communication system. The risk assessment value sorting unit is used to sort the elements in the risk feature matrix. The information reminder unit is used to push the numbers of the network devices and the vulnerabilities of the network devices to relevant management personnel.

[0104] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, it is intended to include all changes falling within the meaning and scope of the equivalent elements of the claims in the present invention. Any reference signs in the claims should not be regarded as limiting the claims involved.

Claims

1. A data analysis method based on communication security situation awareness, characterized in that: The method includes the steps of: Step S100: Collect the vulnerability characteristics of network device vulnerabilities from the operation and maintenance records of the communication system, gather the vulnerability characteristics to obtain a vulnerability knowledge base, and gather the matching degrees between the operation logs of network devices and each vulnerability characteristic to obtain the risk characteristic sequence of network devices; Step S200: Obtain the operation records of all network devices in the communication system, gather the time series characteristic sequences of each network device within a time range, and perform dimensionality compression on the time series characteristic sequences to obtain the time series characteristic matrix of the communication system; Step S300: Capture the cross-time patterns of network devices in the communication system through the attention mechanism, and perform weighted fusion on the time series characteristic matrix and the cross-time patterns in the communication system to obtain the risk matrix of all network devices in the communication system; Step S300 includes: Step S301: Gather the d-dimensional operation characteristics of all network devices in the communication system within a certain unit time period to form an input tensor X. Among them, each operation characteristic corresponds to one dimension, and the three-dimensional size of the input tensor is N×τ×d. N represents the number of network devices in the communication system, τ represents the time length of a certain unit time period. Expand the input tensor from the device dimension to the sequence dimension to obtain X2, and the three-dimensional size of X2 is τ×N×d; Step S302: Sample a moments from the certain unit time period, and calculate the encoding matrix E of the communication system at the t-th moment in the certain unit time period t , E t =X2W e +P, where W e is the feature embedding matrix, and the size of the feature embedding matrix is d×d h , d h is an integer multiple of d and a power of 2, and P is the network device position encoding matrix, and the position encoding matrix includes the logical relationship encoding of the network device at the t-th moment; Step S303: Obtain Q t , K t and V t , where Q t = E t W Q , K t = E t W K , V t = E t W V , where W Q , W K and W V are weight matrices, Q t represents the query vector, K t represents the key vector, V t represents the value vector, calculate the attention Attention t , , where d k = d h / h, h represents the number of attention heads, and d h is an integer multiple of h, softmax represents the softmax activation function; Step S304: Calculate the attention at all a moments, and extract the cross-time pattern H through temporal dimension convolution trans , , where ";" represents the vector concatenation operator, and Conv1D represents the one-dimensional convolutional neural network layer; Step S305: In the certain unit time period, the risk matrix H of all network devices in the communication system fusion , H fusion =G⊙H LSTM +(1 - G)H trans , where G represents the weight matrix, ⊙ represents the Hadamard product, and H LSTM represents the time series feature matrix of all network devices in the communication system; Step S400: Extract the risk characteristic vectors of each network device from the risk matrix, and obtain the threat score of the corresponding network device through dimensionality compression and linear mapping; Step S500: Obtain the risk characteristic sequence and threat score of the network device, calculate the risk characteristic matrix of the communication system, generate an alarm message according to the order of the matrix elements in the risk characteristic matrix from large to small, and provide relevant vulnerability information of the network device to the management personnel of the communication system.

2. The data analysis method based on communication security situation awareness according to claim 1, wherein: Step S100 includes: Step S101: Collect the processing records of network device vulnerabilities in the communication system from the operation and maintenance records of the communication system, label the names of network device vulnerabilities, gather the names of all network device vulnerabilities in the communication system, collect the word vectors of the names as the vulnerability characteristics of network device vulnerabilities, and gather the word vectors of all network device vulnerabilities to obtain a vulnerability knowledge base; Step S102: Number the network devices in the communication system, obtain the semantic characteristics in the operation log of the i-th network device in the communication system, correspond each semantic characteristic to a semantic characteristic vector, and gather all the semantic characteristic vectors generated by the i-th network device within a certain unit time period to obtain a semantic characteristic sequence; Step S103: Calculate the similarity between each word vector in the vulnerability knowledge base and the semantic characteristic vectors in the semantic characteristic sequence one by one, obtain the maximum value of the similarity between each word vector and the semantic characteristic vector, use the maximum value of the similarity of each word vector as the similarity matching value of the word vector, and gather the corresponding all similarity matching values of the operation log of the i-th network device to obtain the risk characteristic sequence.

3. The data analysis method based on communication security situation awareness according to claim 2, characterized in that: Step S200 includes: Step S201: Obtain the operation records of each network device in the communication system, and obtain the operation characteristics of each network device within a unit time period. The operation characteristics include network traffic characteristics and the communication protocol distribution within the unit time period; Step S202: Sample the operation records of the \(i\)-th network device in a certain unit time period, form an operation record sequence with the sampled operation characteristics, extract a feature vector of the operation characteristics of a network device for each sampled moment, and arrange the feature vectors in chronological order to obtain an operation feature time series; Step S203: Extract the forward propagation feature and backward propagation feature of the operation feature time series through a bidirectional LSTM, obtain the forward feature vector and backward feature vector of a certain unit time period, and splice the forward feature vector and backward feature vector to obtain the time series feature of a certain unit time period; Step S204: Aggregate the temporal features of several unit time periods of the i-th network device to obtain the temporal feature sequence of the i-th network device, denoted as H LSTM i ; Step S205: Aggregate the time series feature sequences of all devices, and compress the dimensions of the time series feature sequences by the max pooling method to obtain the time series feature matrix H of all network devices LSTM .

4. The data analysis method based on communication security situation awareness according to claim 3, characterized in that: Step S400 includes: Step S401: Take the eigenvector corresponding to the i-th row dimension in the risk matrix as the risk eigenvector of the i-th network device, and denote the risk eigenvector as H Fusion i ; Step S402: Calculate the threat score threat of the i-th network device through the MLP neural network i , , where w s T is the transpose of the linear mapping weight vector w s , and b s represents the bias term.

5. The data analysis method based on communication security situation awareness according to claim 4, characterized in that: Step S500 includes: Step S501: Obtain the threat score of the \(i\)-th network device, multiply the threat score by the risk feature sequence to obtain the risk feature value sequence of the \(i\)-th network device, establish a new dimension in the order of the network device numbers, and gather the risk feature value sequences of all network devices in order to obtain the risk feature matrix of the communication system; Step S502: Sort all the matrix elements in the risk feature matrix from largest to smallest to obtain a risk warning sequence, obtain the word vectors corresponding to the network device numbers and similarity matching values in the order of the risk warning sequence, and obtain the network device vulnerabilities corresponding to the word vectors; Step S503: Combine the network device numbers and network device vulnerabilities into an alarm information group, arrange all the alarm information groups in the order of the risk warning sequence, and push them to the management personnel of the communication system.

6. A data analysis system based on communication security situation awareness, which is used to execute the data analysis method based on communication security situation awareness described in any one of claims 1-5, and is characterized in that: The system includes: A vulnerability management module, a time series feature management module, a risk matrix management module, a threat score management module, and a risk prompt module. Among them, the vulnerability management module is used to obtain the vulnerability characteristics of network devices from the operation and maintenance records of network devices, match the operation logs of network devices with each vulnerability characteristic, and manage the risk feature sequence of network devices. The time series feature management module is used to collect the time series features of the operation status of network devices and manage the time series feature matrix of the communication system. The risk matrix management module is used to perform weighted fusion on the time series feature matrix and the cross-time mode and manage the risk matrix of all network devices in the communication system. The threat score management module is used to manage the threat scores of network devices. The risk prompt module is used to calculate the risk feature matrix of the communication system and give risk prompts to relevant management personnel.

7. The data analysis system based on communication security situation awareness according to claim 6, wherein: The vulnerability management module includes: a vulnerability knowledge base management unit, a semantic vector management unit, and a risk feature sequence management unit. Among them, the vulnerability knowledge base management unit is used to manage the vulnerability knowledge base of the communication system. The semantic vector management unit is used to manage the word vectors of the vulnerability knowledge base and the semantic feature vectors in the operation logs of network devices. The risk feature sequence management unit is used to compare the similarity between the word vectors and the semantic feature vectors to obtain the risk feature sequence of network devices.

8. The data analysis system based on communication security situation awareness according to claim 6, wherein: The timing feature management module includes an operation feature management unit, an operation feature time series management unit, a timing feature extraction unit, and a dimension compression unit. The operation feature management unit is used to manage the operation features of network devices. The operation feature time series management unit is used to manage the operation feature time series. The timing feature extraction unit is used to establish a bidirectional LSTM propagation model to extract the timing feature sequences of each network device. The dimension compression unit is used to perform dimension compression on the timing feature sequences of devices and manage the timing feature matrix of network devices; The risk matrix management module includes a spatial feature acquisition unit, an attention mechanism calculation unit, a spatial feature management unit, and a feature fusion unit. The spatial feature acquisition unit is used to perform dimension expansion on the operation status of network devices, embed logical relationship encoding, and manage the cross-time patterns of network devices. The attention mechanism calculation unit is used to capture the attention features of the cross-time patterns of network devices through the head attention mechanism. The spatial feature management unit is used to obtain the cross-time patterns of network devices through a one-dimensional convolutional neural network. The feature fusion unit is used to fuse the timing feature matrix and the cross-time patterns of the communication system to obtain the risk matrix of network devices.

9. The data analysis system based on communication security situation awareness according to claim 6, wherein: The threat score management module includes a risk feature vector management unit and a threat score management unit. The threat score management unit is used to obtain the threat score of the corresponding network device through dimension compression and linear mapping; The risk prompt module includes a risk feature matrix management unit, a risk assessment value sorting unit, and an information reminder unit. Among them, the risk feature matrix management unit is used for the risk feature value sequence of network devices and manages the risk feature matrix of the communication system. The risk assessment value sorting unit is used to sort the elements in the risk feature matrix. The information reminder unit is used to push the numbers of network devices and network device vulnerabilities to relevant management personnel.

Citation Information

Patent Citations

  • Vulnerability patch existence detection method based on deep learning

    CN116108446A

  • Safety detection and efficiency verification method for penetration test tool

    CN118764237A