Network security situation comprehensive prediction system based on flow monitoring

By designing a comprehensive network security situation prediction system based on traffic monitoring, using deep neural networks and long and short-term memory networks to identify attack patterns and predict attack probability, and conduct comprehensive security situation assessments in combination with real-time status of the network environment, the problem of existing technology being difficult to cope with new and complex attack modes is solved, and efficient network security monitoring and early warning is achieved.

CN120050121AInactive Publication Date: 2025-05-27SHENZHEN XINHUANYU NETWORK TECH CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510521255.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing network security monitoring system is difficult to deal with new and complex attack modes, has limited recognition capabilities, and fails to effectively combine the dynamic changes of network traffic data, the timing characteristics of attack modes and the real-time status of the network environment, and lacks comprehensive situational awareness and comprehensive evaluation capabilities.

Method used

A comprehensive prediction system for network security situation based on traffic monitoring is designed, including data acquisition module, data processing module, feature extraction module, analysis and identification module, evaluation and decision-making module and visualization module. The distributed traffic acquisition device obtains network traffic data in real time, performs data preprocessing, extracts traffic time series features, statistical features and connection mode features, uses deep neural networks and long and short-term memory networks to identify attack patterns and predict attack probability, and conducts a comprehensive assessment of security situations in combination with the real-time status of the network environment.

Benefits of technology

It realizes detecting various cyber attacks in a shorter time and predicting the probability of future attacks in real time, improving the early warning capability and response speed of network security incidents, and improving the efficiency of network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050121A_ABST
    Figure CN120050121A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a network security situation comprehensive prediction system based on flow monitoring, which comprises a data acquisition module, a data processing module, a feature extraction module, an analysis and identification module, an evaluation and decision module and a visualization module. The data acquisition module acquires network flow data in real time, the data processing module preprocesses the network flow data, the feature extraction module extracts key features from the preprocessed data, and the analysis and recognition module recognizes an attack mode based on a deep neural network and a long and short-term memory network and predicts the probability of occurrence of future attacks. And the evaluation and decision-making module generates a security situation score and provides decision-making support for management personnel. And the visualization module displays the network traffic, the attack mode recognition result and the security situation assessment result through a graphical interface. According to the method, the network security monitoring, early warning and decision support capability can be effectively improved, and a user is helped to cope with complex and changeable network attack threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a comprehensive network security situation prediction system based on traffic monitoring. Background Art

[0002] With the rapid development of information technology and the wide application of the Internet, network security has become increasingly important. The attack means in modern networks are becoming increasingly complex and diverse, and the occurrence frequency and harmfulness of network attack events are constantly increasing, posing a serious threat to information security. Traditional network security monitoring means and protection mechanisms have gradually become difficult to meet the current network security protection requirements. In order to effectively address these challenges, an intelligent security system based on traffic monitoring and data analysis has emerged.

[0003] Most existing network security monitoring systems focus on the detection of a single type of attack or the determination of security events based on simple rule matching methods. However, these traditional methods have some significant deficiencies: First, many existing systems rely on a pre-set attack feature library and are unable to cope with new and complex attack patterns, resulting in limited recognition capabilities. Second, most existing technologies fail to effectively combine the dynamic changes in network traffic data, the temporal characteristics of attack patterns, and the real-time state of the network environment, lacking comprehensive situation awareness and comprehensive evaluation capabilities, resulting in the inability to detect complex attack behaviors in a timely manner. Summary of the Invention

[0004] The present invention provides a comprehensive network security situation prediction system based on traffic monitoring.

[0005] A comprehensive network security situation prediction system based on traffic monitoring includes a data acquisition module, a data processing module, a feature extraction module, an analysis and recognition module, an evaluation and decision module, and a visualization module, wherein;

[0006] The data acquisition module obtains network traffic data in real time through traffic acquisition devices distributed at various nodes of the network;

[0007] The data processing module preprocesses the collected network traffic data, including data cleaning and denoising processing;

[0008] The feature extraction module extracts important features from the preprocessed network traffic data, and the important features include traffic time series features, traffic statistical features, and network connection mode features;

[0009] The analysis and recognition module constructs an abnormal behavior recognition model based on the extracted important features, identifies potential attack patterns, and predicts the probability of network attack events occurring in a future period of time. The abnormal behavior recognition model includes a deep neural network sub-model and a long short-term memory network sub-model;

[0010] The evaluation and decision-making module combines the output of the analysis and recognition module and the real-time status of the network environment (traffic load and network topology changes), comprehensively evaluates the network security situation, and provides decision-making support to management personnel according to the evaluation results;

[0011] The visualization module displays real-time network traffic data, attack pattern recognition results, and network security situation evaluation results through a visualization interface.

[0012] Optionally, the data acquisition module includes:

[0013] The traffic acquisition device includes a packet capture device, a traffic monitor, and a protocol parser, where;

[0014] The packet capture device is deployed on key nodes (such as routers, switches, gateways, etc.) or terminal devices in the network, and captures and records network packets passing through the node;

[0015] The traffic monitor calculates the throughput, latency, and packet loss rate of each network traffic by monitoring the collected network packet traffic in real time;

[0016] The protocol parser combines with the packet capture device to parse the captured network packets in real time, and extracts key information in each layer protocol. The key information includes the IP header, TCP / UDP header, and application layer data;

[0017] The traffic acquisition device is deployed using a distributed architecture, and each network node is equipped with an independent traffic acquisition device;

[0018] The data acquisition module adopts a real-time data transmission mechanism, and transmits the network traffic data collected by each node to the data processing module through an encrypted transmission channel.

[0019] Optionally, the data processing module includes:

[0020] Data cleaning: Clean the collected network traffic data;

[0021] Denoising processing: Denoise the cleaned network traffic data;

[0022] Data formatting: Format the denoised network traffic data.

[0023] Optionally, the feature extraction module specifically includes:

[0024] Traffic time series feature extraction: Extract traffic time series features from the preprocessed network traffic data.

[0025] Traffic statistical feature extraction: Extract traffic statistical features from the preprocessed network traffic data;

[0026] Network connection pattern feature extraction: Extract network connection pattern features from the preprocessed network traffic data.

[0027] Optionally, the deep neural network sub-model includes:

[0028] Model construction: Based on the extracted important features, construct a deep neural network sub-model for identifying attack patterns in network traffic;

[0029] Model training: Use the training data to train the deep neural network sub-model.

[0030] Attack pattern recognition: Use the trained deep neural network sub-model to identify attack patterns.

[0031] Optionally, the long short-term memory network sub-model includes:

[0032] Model construction: Through the long short-term memory network algorithm, construct a long short-term memory network sub-model to predict the probability of network attack events occurring in the next period of time;

[0033] Model training: Use the training data to train the long short-term memory network sub-model;

[0034] Network attack prediction: After the long short-term memory network sub-model is trained, based on the real-time collected network traffic data, predict potential network attack events.

[0035] Optionally, the evaluation and decision-making module includes:

[0036] Receive attack pattern recognition results: The evaluation and decision-making module receives the output of the analysis and recognition module. The output of the analysis and recognition module includes the identified attack patterns (such as DoS attacks, port scans, malware propagation, etc.) and the predicted network attack probability;

[0037] Receive the real-time state of the network environment: The evaluation and decision-making module further receives the real-time state data of the network environment, including traffic load and network topology changes;

[0038] Comprehensive security situation assessment: The evaluation and decision-making module uses a comprehensive evaluation algorithm to conduct a security situation assessment based on the received output of the analysis and recognition module and the real-time state of the network environment;

[0039] Security situation classification: Classify the network security status according to the security situation assessment results.

[0040] Optionally, the evaluation and decision-making module further includes:

[0041] Provide decision-making support to management personnel: The evaluation and decision-making module generates corresponding security situation reports based on the security situation scores and classification results, and provides decision-making support.

[0042] Real-time warning and alert: When the security situation changes, the evaluation and decision-making module provides real-time warnings to management personnel. If there is a sudden increase in the security score or a change in the classification category, it promptly reminds management personnel to take new protection or emergency response measures.

[0043] Optionally, the visualization module includes:

[0044] Display of real-time network traffic data: The visualization module displays the collected network traffic data in real time through a visualization interface.

[0045] Display of attack pattern recognition results: The visualization module displays the attack pattern recognition results output by the analysis and recognition module through a visualization interface.

[0046] Display of security situation assessment results: The visualization module displays the assessment results generated by the evaluation and decision-making module through a visualization interface.

[0047] User interaction function: The visualization module also includes an interaction function that allows management personnel to filter and view specified data through the interface.

[0048] Advantages of the present invention:

[0049] In the present invention, network traffic data is obtained in real time through distributed traffic collection devices, and effective preprocessing (such as data cleaning and denoising) is performed through a data processing module, ensuring the accuracy and reliability of the collected data. The feature extraction module extracts key features (such as traffic time series features, traffic statistical features, and network connection pattern features) from the cleaned data, enabling the analysis and recognition module to accurately identify potential attack patterns based on deep neural networks and long short-term memory networks and predict the probability of network attacks occurring. Compared with traditional network security monitoring systems, the present invention can detect various network attacks in a shorter time and predict the probability of future attacks in real time, improving the early warning ability and response speed of network security incidents.

[0050] In the present invention, the evaluation and decision-making module combines the output of the analysis and recognition module with the real-time state of the network environment (including traffic load and network topology changes), and uses a weighted scoring mechanism to comprehensively evaluate the security situation of the network and generate a clear security situation score. By dividing the security situation into security, attention, risk, and severe threat levels, management personnel can quickly understand the overall network security situation and make timely and effective decisions based on the evaluation results. This module not only improves the efficiency of network security management but also helps management personnel identify potential risks and take corresponding protection measures. Description of the Drawings

[0051] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only those of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0052] Figure 1 It is a schematic diagram of the system flow of the embodiment of the present invention. Detailed implementation manners

[0053] The following will describe the present invention in detail in combination with the drawings and specific embodiments. At the same time, it should be noted here that in order to make the embodiments more detailed, the following embodiments are the best and preferred embodiments. For some well-known technologies, those skilled in the art can also adopt other alternative methods for implementation; moreover, the drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.

[0054] As Figure 1 shown, a comprehensive network security situation prediction system based on traffic monitoring includes a data acquisition module, a data processing module, a feature extraction module, an analysis and recognition module, an evaluation and decision-making module, and a visualization module, wherein;

[0055] The data acquisition module obtains network traffic data in real time through traffic acquisition devices distributed at various nodes of the network;

[0056] The data processing module preprocesses the acquired network traffic data, including data cleaning and denoising processing;

[0057] The feature extraction module extracts important features from the preprocessed network traffic data. The important features include traffic time series features, traffic statistical features, and network connection mode features;

[0058] The analysis and recognition module constructs an abnormal behavior recognition model based on the extracted important features, identifies potential attack patterns, and predicts the probability of network attack events occurring in the future. The abnormal behavior recognition model includes a deep neural network sub-model and a long short-term memory network sub-model;

[0059] The evaluation and decision-making module combines the output of the analysis and recognition module and the real-time state of the network environment (traffic load and network topology changes) to comprehensively evaluate the network security situation and provide decision support to managers according to the evaluation results;

[0060] The visualization module displays real-time network traffic data, attack pattern recognition results, and network security situation evaluation results through a visualization interface.

[0061] The data acquisition module includes:

[0062] The traffic acquisition device includes a data packet capture device, a traffic monitor, and a protocol parser, where;

[0063] The data packet capture device is deployed on key nodes (such as routers, switches, gateways, etc.) or terminal devices in the network, captures and records network data packets passing through the node. The data packet capture device supports packet capture of different protocols, including IP protocol, TCP protocol, UDP protocol, and HTTP protocol;

[0064] The traffic monitor monitors the traffic of the collected network data packets in real time, calculates the throughput, latency, and packet loss rate of each network traffic. The traffic monitor classifies and tags the collected network data according to the traffic type for subsequent processing and analysis;

[0065] The protocol parser combines with the data packet capture device to parse the captured network data packets in real time and extract the key information in each layer protocol. The key information includes the IP header, TCP / UDP header, and application layer data;

[0066] The traffic acquisition device is deployed using a distributed architecture. Each network node is equipped with an independent traffic acquisition device. The acquisition devices form a traffic data acquisition network through high-speed network connections, realizing the coverage monitoring of the whole network traffic and forming a multi-point and wide-area traffic acquisition system in the system. The distributed deployment scheme ensures the high concurrency and high scalability of traffic acquisition and can meet the data acquisition requirements in a large-scale network environment;

[0067] The data acquisition module adopts a real-time data transmission mechanism and transmits the network traffic data collected by each node to the data processing module through an encrypted transmission channel to ensure the integrity and security of the data during transmission. The data transmission uses standard protocols (such as MQTT, HTTPs, etc.) and can select a low-latency and high-reliability data transmission scheme according to actual requirements;

[0068] The data acquisition module obtains the multi-level and multi-protocol network traffic data of the whole network in real time through the distributedly deployed traffic acquisition devices. This module adopts technologies such as data packet capture, traffic monitoring, and protocol parsing, combines with the distributed architecture and the real-time data transmission mechanism, and provides comprehensive, accurate, and timely raw data support for subsequent data processing, feature extraction, and analysis and identification.

[0069] The data processing module includes:

[0070] Data cleaning: Clean the collected network traffic data, specifically including:

[0071] Missing value handling: The data processing module detects missing values in the collected network traffic data. If there are missing values, interpolation is used to fill them to ensure the integrity of the dataset;

[0072] Duplicate data deletion: Detect possible data duplication during the collection process, especially duplicate data packets caused by network latency or device failures. Through data deduplication algorithms, duplicate data is automatically deleted to avoid interference with subsequent analysis;

[0073] Denoising processing: Denoise the cleaned network traffic data, specifically including:

[0074] In network traffic, there is noise caused by external factors (such as device failures, network attacks, etc.). The data processing module uses a low-pass filter to identify and filter out the noise;

[0075] Data formatting: Perform formatting processing on the denoised network traffic data, specifically including:

[0076] Standardization processing: Use the Z-score standardization method to standardize the network traffic data so that subsequent analysis can be carried out on a unified scale;

[0077] Time series serialization: For time series data, time window partitioning technology is used to divide the data at certain time intervals (such as 1 minute, 10 minutes, etc.) and mark time stamps, providing a data format with time series consistency for further time series analysis and model training;

[0078] Through the preprocessing process of data cleaning, denoising, and formatting, the data processing module effectively guarantees the quality and consistency of the collected network traffic data. By means of missing value filling, noise filtering, etc., data interference caused by errors and noise in the collection process is eliminated; at the same time, through data formatting, traffic data from different sources and of different types is converted into a unified standard format, ensuring that subsequent feature extraction and analysis can be carried out on the basis of high-quality data, thereby improving the system prediction accuracy and analysis reliability.

[0079] The feature extraction module specifically includes:

[0080] Flow time series feature extraction: Extract flow time series features from the preprocessed network traffic data, specifically including:

[0081] Time window partitioning: Divide the network traffic data into multiple time segments according to a fixed time window (such as every second, every minute, etc.). Each time segment corresponds to a set of network traffic features, and the sliding window method is used to capture the change of traffic over time;

[0082] Trend extraction: Apply methods such as moving average and exponentially weighted moving average to smooth the network traffic data, extract the long-term trend of the traffic, and help identify long-term change patterns, such as the growth or decline trend of the traffic.

[0083] Seasonal variation analysis: Use wavelet transform or Fourier transform to perform frequency domain analysis on the network traffic data, extract the periodic features in the traffic, and reveal the seasonal fluctuations of the traffic, such as the traffic differences between weekdays and holidays, or the peak traffic hours per hour.

[0084] Traffic statistical feature extraction: Extract traffic statistical features from the preprocessed network traffic data, specifically including:

[0085] Throughput: Calculate the amount of data transmitted per unit time, usually expressed in bits per second or bytes per second. The fluctuations in throughput can effectively reflect the changes in network load;

[0086] Traffic volatility: Measure the degree of fluctuation of the network traffic by calculating statistical quantities such as the standard deviation and variance of the network traffic data. Larger traffic volatility may indicate abnormal activities or attacks in the network;

[0087] Packet size distribution: Conduct statistical analysis on the packet sizes in the network traffic, extract features such as the average value and standard deviation of the packet lengths. Abnormal packet size distributions may indicate potential attack behaviors (such as abnormal increases in packet sizes in DDoS attacks);

[0088] Packet arrival rate: Calculate the number of packets received per unit time, monitor the changes in the packet arrival rate, and identify potential abnormal traffic or attack patterns, such as brute force cracking or port scanning;

[0089] Network connection pattern feature extraction: Extract network connection pattern features from the preprocessed network traffic data, specifically including:

[0090] Source / destination IP distribution: Analyze the source IP and destination IP distributions in the traffic, and calculate the proportion of traffic for different IP addresses. Abnormal IP distribution patterns (such as a large number of new IPs initiating connections in a short period) may indicate distributed denial of service (DDoS) attacks or scanning activities;

[0091] Connection duration: Statistically analyze the duration of each network connection, and analyze the proportion of short connections and long connections. The generation of a large number of short connections in a short period may be related to port scanning or brute force cracking attacks;

[0092] Port usage: Analyze the traffic conditions of each port and identify abnormal port usage patterns. For example, an abnormal increase in traffic on certain ports may be a sign of unauthorized services or attackers exploiting known vulnerabilities for attacks;

[0093] Through the above feature extraction steps, the system can extract time - series features, statistical features, and connection pattern features in the traffic, providing high - quality input data for subsequent attack recognition and prediction models.

[0094] The deep neural network sub - model includes:

[0095] Model construction: Based on the extracted important features, construct a deep neural network sub - model for identifying attack patterns in network traffic. The steps for constructing the deep neural network sub - model include:

[0096] Input layer design: The input layer receives the important features extracted by the feature extraction module, including traffic time - series features, traffic statistical features, and network connection pattern features. Each feature corresponds to a node in the input layer, and the number of features determines the number of nodes in the input layer;

[0097] Hidden layer configuration: The deep neural network sub - model includes multiple hidden layers. The number of nodes in each layer is optimized according to the input feature dimension, the complexity of the dataset, and the task requirements. Each hidden layer uses the ReLU activation function for non - linear transformation. The role of the activation function is to increase the expressive power of the model and improve the model's learning ability for complex patterns;

[0098] Output layer design: The number of nodes in the output layer is determined by the number of classifications of network attack patterns. The softmax activation function is used to output the probability of each attack type;

[0099] The expression of the deep neural network sub - model is:

[0100] ;

[0101] Among them, is the input feature, is the weight matrix of each layer, is the bias of each layer, is the prediction result of the output layer;

[0102] Model training: Use the training data to train the deep neural network sub - model. The training data contains classification labels of attack behaviors (such as DDoS attacks, port scans, malware propagation, etc.). The training process includes:

[0103] Data preparation: Use the training dataset containing labels. The training dataset includes normal network traffic data and network traffic data of various attack patterns;

[0104] Loss function and optimization algorithm: The cross-entropy loss function is used to optimize the classification task. The goal is to minimize the difference between the predicted class and the actual label. The Adam optimizer is used as the optimization algorithm. This optimizer combines the advantages of the gradient descent method and has an adaptive learning rate, which can accelerate the convergence process;

[0105] Training process: Through multiple iterations, the weights and biases of the model are gradually adjusted to make the classification accuracy of the model on the training data reach the optimal;

[0106] Training result output: After training, the deep neural network sub-model outputs the predicted probabilities of each network attack and generates classification results.

[0107] Attack pattern recognition: Use the trained deep neural network sub-model to identify attack patterns, specifically including:

[0108] Prediction output: Input the real-time collected network traffic data into the trained deep neural network sub-model. The deep neural network sub-model outputs the occurrence probabilities of various attack patterns. If the probability of a certain attack pattern exceeds the set threshold, it is considered that the network has this type of attack;

[0109] Attack pattern classification: According to the prediction results output by the deep neural network sub-model, classify the network traffic into normal or attack types and generate a detailed attack pattern report, which includes the attack type and occurrence probability for network security management personnel to reference.

[0110] The long short-term memory network sub-model includes:

[0111] Model construction: Build a long short-term memory network sub-model through the long short-term memory network algorithm to predict the probability of network attack events occurring in a future period of time. The construction of the long short-term memory network sub-model includes:

[0112] Input layer design: The input layer receives the time series data from the traffic feature extraction module, including traffic time series features, traffic statistical features, and network connection pattern features. The input data needs to be sorted in time order so that the long short-term memory network can capture the evolution and dynamic changes of traffic over time;

[0113] Long short-term memory network cell structure: The long short-term memory network consists of multiple long short-term memory network cells. Each long short-term memory network cell contains three gating mechanisms (input gate, forget gate, and output gate) to control the flow of information and the update of memory. Each long short-term memory network cell can capture the long-term dependencies in the time series data and avoid the problem of gradient vanishing or explosion;

[0114] Output layer design: The output layer is designed as one or more neuron nodes, which are used to predict the probability of network attack events occurring within a future period of time. This node uses the sigmoid activation function to output the predicted attack probability, indicating the risk of an attack that may occur within the predicted time range.

[0115] The model expression is:

[0116] ;

[0117] Among them, is the long short-term memory network, is the hidden state at the th moment, is the input data at the th moment, and are the hidden state and cell state at the previous moment respectively;

[0118] Model training: Use the training data to train the long short-term memory network sub-model. The training data includes historical network traffic data, classification labels of attack behaviors (such as DDoS attacks, port scans, malware propagation, etc.) and corresponding timestamps, specifically including:

[0119] Training process: Train the model through the backpropagation algorithm. During the training process, the optimization goal is to minimize the error between the prediction result and the actual label, and use the cross-entropy loss function as the loss function;

[0120] Time series modeling: Through iterative training, the long short-term memory network sub-model can automatically learn the long-term dependencies in the network traffic and optimize the prediction ability of the time series, especially being able to capture the periodic, trend changes and potential attack patterns in the traffic;

[0121] Network attack prediction: After the long short-term memory network sub-model is trained, based on the real-time collected network traffic data, it predicts potential network attack events;

[0122] Attack prediction: Dynamically predict the network traffic at future moments based on the long short-term memory network sub-model, and output the probability values of different attack patterns occurring within each time step. The prediction result can be used for real-time monitoring and early warning, and generate an alarm according to the predicted attack probability;

[0123] Attack probability report: The model generates a report on the future network attack risk through continuous time step predictions. The report includes the probability and impact degree of an attack occurring within a future period of time;

[0124] Through the prediction ability of the long short-term memory network sub-model, the system can accurately identify potential future threats and improve the timeliness of network security protection.

[0125] The evaluation and decision-making module includes:

[0126] Receiving the attack pattern recognition result: The evaluation and decision-making module receives the output of the analysis and recognition module. The output of the analysis and recognition module includes the recognized attack patterns (such as DoS attack, port scanning, malware propagation, etc.) and the predicted probability of network attack;

[0127] Receiving the real-time status of the network environment: The evaluation and decision-making module further receives the real-time status data of the network environment, including traffic load and network topology changes. Specifically:

[0128] Traffic load: The traffic load situation of the current network, including the traffic consumption of each node and the entire network. A sudden increase or imbalance in traffic load may indicate potential attack activities (such as DDoS attack);

[0129] Network topology changes: Refer to the status and changes of each node, device, and connection in the network. Topology changes may occur due to factors such as network device failures, device offline caused by attacks, or lateral movement of intruders in the network. Monitoring the network topology helps identify potential attack paths;

[0130] Comprehensive security situation assessment: The evaluation and decision-making module uses a comprehensive assessment algorithm to conduct a security situation assessment based on the output of the received analysis and recognition module and the real-time status of the network environment. This algorithm assigns different weights to each evaluation factor (attack pattern, traffic load, topology change), and synthesizes the evaluation results to obtain the overall risk assessment value of network security, expressed as:

[0131] ;

[0132] Wherein, is the comprehensive security situation score of the network, ranging from 0 (completely secure) to 100 (extremely high risk), is the risk score of the attack pattern, calculated based on the probability of the attack occurring and its threat level, is the score of the traffic load, calculated based on traffic sudden increase and traffic imbalance information, is the score of the topology change, scored based on the abnormality of network node changes; are the weighting coefficients, respectively representing the relative importance of the attack pattern, traffic load, and topology change in the comprehensive security situation. The weights are adjusted according to the influence degree of each index;

[0133] Security situation classification: According to the security situation assessment result, classify the network security status. Specifically:

[0134] Secure: In the range of 0 - 30, it indicates that the network is in a normal state and the possibility of an attack is relatively low;

[0135] Attention: In the range of 31 - 50, it indicates that the network is in potential risk and needs to be closely monitored;

[0136] Risk: In the range of 51 - 80, it indicates that there is a relatively high attack risk in the network and defensive measures need to be taken promptly;

[0137] Severe threat: In the range of 81 - 100, it indicates that the network is encountering a severe security threat and may be under attack.

[0138] The evaluation and decision - making module also includes:

[0139] Providing decision - making support to managers: The evaluation and decision - making module generates a corresponding security situation report based on the security situation score and classification results, and provides decision - making support, specifically including:

[0140] Recommended protection measures: According to different security levels, recommend corresponding protection measures to managers. For example, for the "Risk" or "Severe threat" status, it may recommend emergency measures such as traffic monitoring, isolating the attack source, and strengthening firewall policies;

[0141] Resource allocation suggestions: Provide resource scheduling suggestions according to the current security situation score to optimize network protection. For example, if the network is in the "Risk" state, it can be recommended to increase security devices or adjust bandwidth allocation to mitigate potential threats;

[0142] Priority ranking: Rank multiple potential threats to help managers identify the most urgent security issues currently and prioritize high - risk events for handling;

[0143] Real - time warning and alert: When the security situation changes, the evaluation and decision - making module provides real - time warnings to managers. If the security score suddenly increases or the classification category changes, managers are reminded to take new protection or emergency response measures in a timely manner.

[0144] The visualization module includes:

[0145] Display of real - time network traffic data: The visualization module displays the collected network traffic data in real - time through a visualization interface, including:

[0146] Traffic data of each node: Display the traffic conditions of each network node, including indicators such as transmission rate, number of data packets, packet loss rate, and latency;

[0147] Overall traffic trend: Display the traffic trend graph of the entire network, indicating the time points of traffic changes, moments of sudden increase or decrease;

[0148] Attack mode recognition result display: The visualization module displays the attack mode recognition results output by the analysis and recognition module through a visualization interface, specifically including:

[0149] Attack mode type: Displays the currently detected attack types (such as DoS, port scanning, malware propagation, etc.), as well as the time of occurrence, duration, and attack intensity.

[0150] Attack probability: Displays the occurrence probability of various attacks, and uses charts (such as bar charts or pie charts) to vividly show the risk level of each attack mode.

[0151] Security posture assessment result display: The visualization module displays the assessment results generated by the assessment and decision-making module through a visualization interface, specifically including:

[0152] Security posture score: Displays the security posture score of the current network through a chart or dashboard. The score range is from 0 (completely secure) to 100 (extremely high risk), and different security levels are represented by color changes (such as green, blue, yellow, red);

[0153] Security posture classification: According to the assessment results, displays the security posture classification of the network (such as secure, concerned, risky, severe threat), and provides corresponding actionable suggestions for managers through text descriptions.

[0154] User interaction function: The visualization module also includes an interaction function that allows managers to filter and view specified data through the interface, specifically including:

[0155] Filter and view specific data: Managers can choose to view data for a certain node, a certain time period, or a certain attack type.

[0156] Data zoom in and out: The visualization interface supports zoom operations to facilitate viewing detailed data or overall trends.

[0157] Alarm notification setting: The visualization interface provides alarm setting options. Managers can set custom thresholds, and when the traffic, attack probability, or security score exceeds the threshold, the system automatically issues an alarm.

[0158] The present invention covers any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of the present invention. To enable the public to have a thorough understanding of the present invention, specific details are described in detail in the following preferred embodiments of the present invention, and those skilled in the art can fully understand the present invention without these detailed descriptions. Additionally, well-known methods, processes, procedures, components, and circuits, etc. are not described in detail to avoid unnecessary confusion to the essence of the present invention.

[0159] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A network security situation comprehensive prediction system based on traffic monitoring, characterized in that: It includes data acquisition module, data processing module, feature extraction module, analysis and recognition module, evaluation and decision module and visualization module, among which; The data collection module acquires network traffic data in real time through traffic collection devices distributedly deployed at each node of the network; The data processing module pre-processes the collected network traffic data, including data cleaning and denoising; The feature extraction module extracts important features from the preprocessed network traffic data, the important features including traffic time series features, traffic statistics features and network connection mode features; The analysis and identification module constructs an abnormal behavior identification model based on the extracted important features, identifies potential attack patterns, and predicts the probability of network attack events occurring in the future. The abnormal behavior identification model includes a deep neural network sub-model and a long short-term memory network sub-model; The evaluation and decision module combines the output of the analysis and identification module with the real-time status of the network environment to conduct a comprehensive evaluation of the network security situation and provide decision support to managers based on the evaluation results; The visualization module displays real-time network traffic data, attack pattern recognition results, and network security situation assessment results through a visualization interface.

2. According to claim 1, a network security situation comprehensive prediction system based on traffic monitoring is characterized in that: The data acquisition module comprises: The traffic collection device includes a data packet capture device, a traffic monitor and a protocol analyzer, wherein; The data packet capture device is deployed on a key node or terminal device in the network to capture and record network data packets passing through the node; The flow monitor calculates the throughput, delay and packet loss rate of each network flow by monitoring the collected network data packet flow in real time; The protocol analyzer is combined with a data packet capture device to analyze captured network data packets in real time and extract key information from each layer of the protocol, including the IP header, TCP / UDP header and application layer data; The traffic collection equipment is deployed using a distributed architecture, where each network node is equipped with an independent traffic collection equipment; The data collection module adopts a real-time data transmission mechanism to transmit the network flow data collected by each node to the data processing module through an encrypted transmission channel.

3. A network security situation comprehensive prediction system based on traffic monitoring according to claim 2, characterized in that: The data processing module comprises: Data cleaning: Clean the collected network traffic data; Denoising: Denoising the cleaned network traffic data; Data formatting: Format the denoised network traffic data.

4. A network security situation comprehensive prediction system based on traffic monitoring according to claim 3, characterized in that: The feature extraction module specifically includes: Traffic time series feature extraction: Extract traffic time series features from preprocessed network traffic data; Traffic statistics feature extraction: Extract traffic statistics features from pre-processed network traffic data; Network connection pattern feature extraction: Extract network connection pattern features from preprocessed network traffic data.

5. A network security situation comprehensive prediction system based on traffic monitoring according to claim 4, characterized in that: The deep neural network sub-model includes: Model building: Based on the extracted important features, a deep neural network sub-model is built to identify attack patterns in network traffic; Model training: Use training data to train the deep neural network sub-model; Attack pattern recognition: Use the trained deep neural network sub-model to recognize attack patterns.

6. A network security situation comprehensive prediction system based on traffic monitoring according to claim 5, characterized in that: The long short-term memory network sub-model includes: Model construction: Through the long short-term memory network algorithm, a long short-term memory network sub-model is constructed to predict the probability of network attack events in the future; Model training: Use the training data to train the LSTM sub-model; Network attack prediction: After the training of the long short-term memory network sub-model is completed, it predicts potential network attack events based on the real-time collected network traffic data.

7. A network security situation comprehensive prediction system based on traffic monitoring according to claim 6, characterized in that: The evaluation and decision-making module includes: Receiving attack pattern recognition results: The evaluation and decision module receives the output of the analysis and recognition module, and the output of the analysis and recognition module includes the recognized attack pattern and the predicted network attack probability; Receive real-time status of the network environment: The evaluation and decision module receives real-time status data of the network environment, including traffic load and network topology changes; Comprehensive security situation assessment: The assessment and decision module uses a comprehensive assessment algorithm to conduct security situation assessment based on the output of the analysis and identification module and the real-time status of the network environment; Security situation classification: Classify the network security status according to the security situation assessment results.

8. A network security situation comprehensive prediction system based on traffic monitoring according to claim 7, characterized in that: The evaluation and decision-making module also includes: Providing decision support to managers: The assessment and decision module generates corresponding security situation reports based on security situation scores and classification results, and provides decision support; Real-time early warning and alert: When the security situation changes, the assessment and decision-making module provides real-time early warning to managers.

9. A network security situation comprehensive prediction system based on traffic monitoring according to claim 8, characterized in that: The visualization module comprises: Real-time network traffic data display: The visualization module displays the collected network traffic data in real time through a visualization interface; Attack pattern recognition result display: The visualization module displays the attack pattern recognition results output by the analysis and recognition module through a visualization interface; Security situation assessment result display: The visualization module displays the assessment results generated by the assessment and decision modules through a visualization interface; User interaction function: The visualization module also includes interactive functions, allowing managers to filter and view specified data through the interface.

Citation Information

Patent Citations

  • Large-scale network security situation intelligent prediction method

    CN112165485A

  • Intelligent network equipment service host security management system based on deep learning

    CN117424740A

  • Network security evaluation system and method based on dynamic attack and defense game model

    CN119544307A

  • Method and system for network security situation assessment

    US20240179155A1

  • Network security situation adaptive active defense system and method

    WO2023077617A1