Network security dynamic early warning method and device and electronic equipment

By building a network knowledge graph and using the fruit fly optimization algorithm to optimize the graph query algorithm, the existing network security early warning technology is solved, and efficient and accurate network security threat detection and early warning are achieved.

CN120050123AActive Publication Date: 2025-05-27江西省科技基础条件平台中心(江西省计算中心)

Patent Information

Application Number
CN202510525991.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-05-27
Estimated Expiration
2045-04-25

AI Technical Summary

Technical Problem

Existing network security early warning technologies are difficult to adapt to the dynamic changes in the network environment and the continuous evolution of attack methods, and there are information island problems between different security devices, resulting in inefficient early warning.

Method used

By building a network knowledge graph, the entities and entity relationships in network data are stored in the form of graph structures, and using the fruit fly optimization algorithm to map threat features into three-dimensional odor concentration fields, the graph query algorithm is optimized to identify potential attacks and find potential attack paths.

Benefits of technology

It realizes more efficient and accurate network security threat detection, can trigger early warnings in a timely manner, and improve network operation security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050123A_ABST
    Figure CN120050123A_ABST
Patent Text Reader

Abstract

The invention provides a network security dynamic early warning method and device and electronic equipment. The method comprises the following steps: constructing a network knowledge graph; defining a query target, including identifying a potential attack and searching a potential attack path; the threat features are mapped into a three-dimensional odor concentration field through a fruit fly optimization algorithm, a graph query algorithm is optimized, and the three-dimensional odor concentration field comprises threat types, emergency degrees and propagation speeds; and on the basis of a query target, searching in the network knowledge graph through the optimized graph query algorithm, searching for potential attacks and attack paths, and triggering early warning in time. According to the method, the threat features are mapped into the three-dimensional odor concentration field through the fruit fly optimization algorithm, and the graph query algorithm is optimized, so that the optimized graph query algorithm can fully consider the node concentration field and preferentially pay attention to and locate nodes with relatively high threat degrees in network knowledge graph search, and the search efficiency is greatly improved; potential attacks and attack paths can be found in the network knowledge graph more accurately and efficiently.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a network security dynamic early warning method, device and electronic device. Background Art

[0002] With the rapid development of the Internet, network security issues have become increasingly prominent. In order to effectively address these network security challenges, the industry has been continuously researching various network security protection and early warning technologies.

[0003] Traditional network security early warning technologies often have the following many defects and are difficult to meet the current complex and changing network security requirements: They usually defend based on static rules and features, and it is difficult to adapt to the dynamic changes of the network environment and the continuous evolution of attack methods; there are often information island problems between different security devices, and threat intelligence cannot be effectively shared and integrated, resulting in low early warning efficiency; in the face of large-scale and complex network attacks, the response speed is often slow, and effective defense measures cannot be taken in time. Summary of the Invention

[0004] Based on this, the purpose of the present invention is to propose a network security dynamic early warning method, device and electronic device to solve the above-mentioned problems.

[0005] According to the network security dynamic early warning method proposed by the present invention, the method includes:

[0006] Storing entities and entity relationships in network data in the form of a graph structure to form a network knowledge graph;

[0007] Defining a query target according to the requirements of network security early warning, where the query target includes identifying potential attacks and finding potential attack paths;

[0008] Mapping threat features to a three-dimensional odor concentration field through the fruit fly optimization algorithm to optimize the graph query algorithm, where the three-dimensional odor concentration field includes the threat type, urgency and propagation speed of network security;

[0009] Based on the query target, searching in the network knowledge graph through the optimized graph query algorithm to find potential attacks and attack paths, and triggering an early warning in a timely manner.

[0010] Furthermore, the mapping of threat features to a three-dimensional odor concentration field through the fruit fly optimization algorithm to optimize the graph query algorithm includes:

[0011] Randomly selecting N starting nodes in the network knowledge graph as the initial positions of the fruit fly population, and each fruit fly individual carries a three-dimensional position vector, including node ID, relationship type and confidence;

[0012] Define a fitness function according to the threat type, urgency, and propagation speed of network security to quantify and calculate the odor concentration of nodes. Among them, the higher the concentration value, the more critical the corresponding node is on the attack path. The formula is:

[0013]

[0014] Among them, ω 1 、ω 2 、ω 3 are weight coefficients, ω 1 +ω 2 +ω 3 = 1, is the threat type quantization value of node i, is the threat urgency quantization value of node i, is the threat propagation speed quantization value of node i;

[0015] For each node at the current position of the fruit fly, calculate its odor concentration value according to the fitness function, and update the position of the fruit fly according to the concentration gradient to make it move towards the high-concentration node;

[0016] Repeat the execution of odor concentration calculation and position update until the termination condition is met, determine the final position distribution of the fruit fly population, and the optimized node concentration field, including the odor concentration value of each node, as the initial threat quantization value.

[0017] Furthermore, based on the query target, search in the network knowledge graph through the optimized graph query algorithm to find potential attacks and attack paths, including:

[0018] According to the final position distribution of the fruit fly population, extract high-concentration nodes as candidate key nodes, and construct a candidate set of attack paths sorted by concentration values;

[0019] Deploy multiple search agents to start traversing and querying the high-concentration nodes in the candidate set of attack paths to find potential attacks and attack paths;

[0020] Activate the attack pattern memory bank to sparsely auto-encode and store the discovered new attack patterns;

[0021] Regularly synchronize the external threat intelligence library to update the node threat quantization values and relationship weights in the network knowledge graph.

[0022] Furthermore, the deployment of multiple search agents includes:

[0023] For the high-concentration nodes in the candidate set of attack paths, calculate the traversal priority by combining the node odor concentration value, the number of neighbor nodes, and the average odor concentration of neighbor nodes. The formula is:

[0024] ,

[0025] Among them, S i is the odor concentration value of node i, that is, the initial threat quantification value of node i, and N i is the number of neighbor nodes, is the average concentration of neighbor nodes, and α + β + γ = 1;

[0026] According to the traversal priority, each high-concentration node is assigned to multiple search agents, where each search agent is responsible for a subgraph area.

[0027] Furthermore, starting a traversal query for the high-concentration nodes in the attack path candidate set to find potential attacks and attack paths includes:

[0028] For each sub-region responsible by a search agent, pre-load the initial concentration field data and adjacency matrix of the sub-region it is responsible for;

[0029] Starting from the node with the highest concentration value in the sub-region, visit in descending order of the current threat quantification value of neighbor nodes;

[0030] Judge whether the traversal path deviates from the normal mode, including frequently visiting low-concentration nodes, the threat type of the path being too single, and the threat value fluctuating violently;

[0031] If the traversal path deviates from the normal mode, extract the current path feature vector and calculate the similarity with the known attack patterns stored in the attack pattern memory bank. The path feature vector includes the statistical distribution of the threat quantification values of path nodes, the threat type sequence, and path entropy;

[0032] If the similarity exceeds the similarity threshold, mark it as a potential attack and trigger an alarm. The alarm content includes the list of path nodes and threat types;

[0033] When the traversal covers all high-concentration nodes and their direct neighbors in the attack path candidate set, terminate the traversal and generate an attack path graph and output a risk score report.

[0034] Furthermore, after starting from the node with the highest concentration value in the sub-region and visiting in descending order of the current threat quantification value of neighbor nodes, it also includes:

[0035] During the visit, if it is found that three consecutive nodes all belong to high-concentration nodes and the threat types of the nodes belong to the same attack chain, trigger a depth search and continue to explore along the direction of the gradient descent of the threat quantification value;

[0036] When the growth rate of the cumulative threat value of the path is less than the backtracking threshold for two consecutive steps, trigger backtracking and terminate the depth search.

[0037] Further, updating the node threat quantification values and relationship weights in the network knowledge graph includes:

[0038] During the traversal process, obtain the real-time threat data stream;

[0039] For the nodes on the traversal path, dynamically update their real-time threat quantification values. The update formula is:

[0040] ,

[0041] where, is the real-time threat quantification value of node i on the path, is the initial threat quantification value of node i, δ is the attenuation coefficient, Δt is the time window, is the real-time threat increment of node i;

[0042] Define the node sequence containing multiple high-concentration nodes and with related threat types as a high-threat path, and strengthen the weight of the high-threat path. The formula is:

[0043] ,

[0044] ,

[0045] ,

[0046] ,

[0047] TypeCorrelation = number of consecutive matching stages / total number of attack chain stages,

[0048] where, is the strengthened weight from node i to node j, is the original weight from node i to node j, λ is the strengthening coefficient, PathThreat is the path threat score, TypeCorrelation is the path threat type correlation degree, θ is the correlation strength coefficient, is the entropy weight coefficient of node i, used to reflect the threat type diversity, is the threat type entropy value of node i, is the occurrence probability of the e-th threat type of node i, m is the total number of threat types faced by node i, and n is the number of nodes on the path.

[0049] Further, for the nodes on the traversal path, dynamically updating their real-time threat quantification values further includes:

[0050] During the traversal process, if the number of nodes visited by the search agent exceeds the node number threshold, then randomly select k low-concentration nodes and temporarily increase their threat quantification values.

[0051] The present invention also provides a network security dynamic early warning device for implementing the above-mentioned network security dynamic early warning method. The device includes:

[0052] A knowledge graph module: used to store entities and entity relationships in network data in the form of a graph structure to form a network knowledge graph;

[0053] A query target module: used to define a query target according to the requirements of network security early warning. The query target includes identifying potential attacks and finding potential attack paths;

[0054] An optimization module: used to map threat features to a three-dimensional odor concentration field through the fruit fly optimization algorithm to optimize the graph query algorithm. The three-dimensional odor concentration field includes the threat type, urgency, and propagation speed of network security;

[0055] A threat detection module: used to search in the network knowledge graph based on the query target through the optimized graph query algorithm to find potential attacks and attack paths and trigger early warnings in a timely manner.

[0056] The present invention also provides a network security dynamic early warning device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the above-mentioned network security dynamic early warning method is implemented.

[0057] In summary, the network security dynamic early warning method of the present invention can better mine the potential relationships between data and support complex query operations by constructing a network knowledge graph and using the network knowledge graph as the data basis, so as to quickly locate information related to specific entities or relationships; according to the requirements of network security early warning, identify potential attacks and find potential attack paths as query targets, providing a clear direction and pertinence for the search of the graph query algorithm; through the fruit fly optimization algorithm, map threat features to a three-dimensional odor concentration field and optimize the graph query algorithm, so that the optimized graph query algorithm can fully consider the node concentration field, that is, the odor concentration value of each node. Since these concentration values comprehensively reflect the characteristics of nodes in terms of threat type, urgency, and propagation speed, the graph query algorithm can give priority attention and locate those nodes with higher threat levels during the search process in the network knowledge graph, reducing unnecessary searches, greatly improving the search efficiency, and thus more accurately and efficiently finding potential attacks and attack paths in the network knowledge graph and triggering early warnings in a timely manner to ensure the security of network operation.

[0058] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be understood through the embodiments of the present invention. Description of the Drawings

[0059] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the following description of embodiments in conjunction with the accompanying drawings, in which:

[0060] Figure 1 is a flowchart of the network security dynamic early warning method according to the first embodiment of the present invention;

[0061] Figure 2 is a system block diagram of the network security dynamic early warning device according to the second embodiment of the present invention;

[0062] Figure 3 is a structural schematic diagram of the network security dynamic early warning device according to the third embodiment of the present invention. Detailed Embodiments

[0063] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. Several embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided so that the disclosure of the present invention is thorough and comprehensive.

[0064] It should be noted that when an element is referred to as being "fixedly provided on" another element, it can be directly on the other element or there can also be an intermediate element. When an element is considered to be "connected" to another element, it can be directly connected to the other element or there may be an intermediate element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are only for the purpose of illustration.

[0065] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used herein in the description of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0066] Embodiment 1

[0067] Please refer to Figure 1 , the present invention provides a network security dynamic early warning method, which includes steps S101 to S104:

[0068] S101, storing the entities and entity relationships in the network data in the form of a graph structure to form a network knowledge graph.

[0069] It should be noted that network data is collected in real time, such as data from various sources including network traffic logs, system logs, security event reports, vulnerability databases, etc. And the network data is cleaned and preprocessed, including missing value handling, outlier handling, data standardization, etc.

[0070] The entities and entity relationships in the network are presented in the form of a graph structure to construct a network knowledge graph. The entities and relationships in the graph are interrelated, forming a complex and orderly network structure, which can facilitate the discovery of potential threat paths and attack patterns in the network.

[0071] Entity types can include IP addresses, domain names, malware names, attacker identities, etc. Entity relationship types can include attack relationships, dependency relationships, etc. Among them, the attack relationship represents the attack behavior between the attacker and the attacked, such as DDoS attacks, malware infections, etc.; the dependency relationship represents the dependency relationship between network entities, such as service dependencies, data dependencies, etc.

[0072] Specifically, a graph database suitable for storing and processing complex network data, such as Neo4j, JanusGraph, etc., can be selected. The identified entities and entity relationships are stored in the graph database in the form of nodes and edges, and attributes such as entity type, relationship type, timestamp, etc. are set for the nodes and edges. The network data from different sources is fused into the same graph to form a comprehensive network information database, and the graph is continuously updated and expanded according to new network data and threat intelligence to maintain its timeliness.

[0073] S102, according to the requirements of network security warnings, define the query target, and the query target includes identifying potential attacks and finding potential attack paths.

[0074] When the network is running normally, various network devices and systems will generate data with certain rules and characteristics. For example, the daily access volume of a server will fluctuate within a relatively stable range under normal circumstances, and the distribution of the IP addresses of the access sources will also have certain rules. When abnormal behavior occurs, there may be a sudden sharp increase or decrease in the access volume, or the IP addresses of the access sources are concentrated in some uncommon regions, etc. For example, if a certain IP address initiates a large number of connection requests to different ports within a short period of time, which does not conform to the historical normal connection pattern, it can be marked as a potential attack.

[0075] An attack path refers to a series of nodes and connections that an attacker may pass through to achieve an attack goal. In a network knowledge graph, these nodes can be IP addresses, servers, applications, etc., and the connections represent the communication relationships between them. For example, an attacker may first intrude into an external server and then use this server as a springboard to further attack critical systems in the internal network. By finding possible attack paths, weak links on the path can be strengthened in advance, such as patching system vulnerabilities and enhancing access control, thereby reducing the probability of a successful attack.

[0076] Specifically, graph query algorithms can be used to search for possible attack paths in the network knowledge graph. The algorithm, based on the attack relationships, dependency relationships, etc. between nodes, combined with the initial threat quantification value obtained through the fruit fly optimization algorithm, finds the paths that are most likely to be exploited by attackers. For example, starting from the attacker identity node, along the attack relationship edges, search for paths that can reach the critical target node, and evaluate the danger level of the path according to the threat quantification values of the nodes on the path.

[0077] S103, through the fruit fly optimization algorithm, map threat features to a three-dimensional odor concentration field to optimize the graph query algorithm, where the three-dimensional odor concentration field includes the threat type, urgency, and propagation speed of network security.

[0078] Through the fruit fly optimization algorithm, map threat features to a three-dimensional odor concentration field, and then optimize the graph query algorithm. That is, utilize the characteristics of the fruit fly optimization algorithm, combined with specific dimensions of network security threats, to quantitatively evaluate the nodes in the network knowledge graph, so as to improve the efficiency and accuracy of the graph query algorithm when searching for potential threat paths.

[0079] Specifically, threat features can be mapped to a three-dimensional odor concentration field, where the three dimensions respectively represent the threat type, urgency, and propagation speed of network security. By calculating the quantification values of each node in these three dimensions and obtaining the odor concentration value of the node according to the fitness function, a node concentration field of the entire network knowledge graph is constructed. The node concentration field can not only more comprehensively and accurately evaluate the importance of nodes in potential attack paths, but also provide a clear search direction for the graph query algorithm, enabling the query process to preferentially explore nodes with high concentration values according to the concentration gradient of the nodes, thereby greatly improving the search efficiency and finding potential threat paths faster.

[0080] Further optionally, the step of optimizing the graph query algorithm by mapping threat features to a three-dimensional odor concentration field through the fruit fly optimization algorithm includes:

[0081] Randomly select N starting nodes in the network knowledge graph as the initial positions of the fruit fly population, and make each fruit fly individual carry a three-dimensional position vector, including node ID, relationship type, and confidence level;

[0082] Define a fitness function according to the threat type, urgency, and propagation speed of network security to quantify and calculate the odor concentration of nodes. Among them, the higher the concentration value, the more critical the corresponding node is on the attack path. The formula is:

[0083] ,

[0084] where ω 1 , ω 2 , ω 3 are weight coefficients, ω 1 +ω 2 +ω 3 = 1, is the threat type quantization value of node i, is the threat urgency quantization value of node i, is the threat propagation speed quantization value of node i;

[0085] For each node at the current position of the fruit fly, calculate its odor concentration value according to the fitness function, and update the position of the fruit fly according to the concentration gradient, so that it moves towards the node with a high concentration;

[0086] Repeat the calculation of the odor concentration and the update of the position until the termination condition is met, determine the final position distribution of the fruit fly population, and the optimized node concentration field, including the odor concentration value of each node, as the initial threat quantization value.

[0087] It can be understood that in the specific application of this embodiment, first, randomly select N starting nodes in the network knowledge graph as the initial positions of the fruit fly population, such as N being 50 - 200. Each fruit fly individual carries a three-dimensional position vector, including the node ID, relationship type, and confidence level, which is used to represent the position information of the current node in the network.

[0088] And map the threat features to a three-dimensional odor concentration field. The three dimensions respectively represent the threat type, urgency, and propagation speed of network security. By calculating the quantization values of each node in these three dimensions and obtaining the odor concentration value of the node according to the fitness function, the node concentration field of the entire network knowledge graph is constructed. The higher the concentration value, the more critical the corresponding node is on the attack path.

[0089] For each node at the current position of the fruit fly, calculate its odor concentration value according to the fitness function, and update the position of the fruit fly according to the concentration gradient, so that it moves towards the node with a high concentration. This process simulates the behavior of fruit flies looking for food sources according to the odor concentration. Through continuous iteration and update, the fruit fly population gradually gathers towards the nodes with a higher threat level.

[0090] Repeat the calculation of odor concentration and position update until the termination condition is met. The termination condition can be reaching the maximum number of iterations, convergence of the concentration value, etc. When the termination condition is met, determine the final position distribution of the fruit fly population and the optimized node concentration field, including the odor concentration value of each node, as the initial threat quantification value. These initial threat quantification values will provide a more accurate basis for node evaluation in the subsequent graph query algorithm.

[0091] This is further illustrated by the following example:

[0092] Suppose there are multiple nodes in a network knowledge graph, representing different servers, network devices, etc. After mapping the threat features to a three-dimensional odor concentration field through the fruit fly optimization algorithm: Node A represents an external server with a high-risk vulnerability exploitation threat type, high urgency, and fast propagation speed. After calculation by the fitness function, its odor concentration value is relatively high. Node B represents an ordinary printer inside the network, with a low-risk configuration error threat type, low urgency, and slow propagation speed. After calculation by the fitness function, its odor concentration value is relatively low.

[0093] During the optimization process of the graph query algorithm, the fruit fly population will gradually gather towards Node A because the concentration value of Node A is high, indicating that it is more important in the potential attack path. In this way, the subsequent search process can preferentially explore Node A and its related paths, thus greatly improving the efficiency and accuracy of searching for potential attack paths.

[0094] S104, Based on the query target, search in the network knowledge graph through the optimized graph query algorithm to find potential attacks and attack paths, and trigger an early warning in a timely manner.

[0095] The optimized graph query algorithm fully considers the node concentration field, that is, the odor concentration value (initial threat quantification value) of each node. These concentration values comprehensively reflect the characteristics of nodes in terms of threat type, urgency, and propagation speed, enabling the algorithm to give priority to those nodes with higher threat levels during the search process, thereby improving the search efficiency, accurately and efficiently identifying the security threats existing in the network, triggering an early warning in a timely manner, and ensuring the security of network operation.

[0096] Further optionally, the searching in the network knowledge graph through the optimized graph query algorithm based on the query target to find potential attacks and attack paths includes:

[0097] According to the final position distribution of the fruit fly population, extract the high-concentration nodes as candidate key nodes, and construct a candidate set of attack paths by sorting according to the concentration values;

[0098] Deploy multiple search agents to start traversing and querying the high-concentration nodes in the candidate set of attack paths to find potential attacks and attack paths;

[0099] Activate the attack pattern memory bank and sparsely auto-encode and compressively store the newly discovered attack patterns.

[0100] Regularly synchronize the external threat intelligence library and update the threat quantification values and relationship weights of the nodes in the network knowledge graph.

[0101] It is understandable that the fruit fly optimization algorithm maps nodes to a three-dimensional odor concentration field according to threat characteristics, and the final position distribution of the fruit fly population reflects the importance of nodes in threat assessment. Extract high-concentration nodes from these position distributions to construct a candidate set of attack paths. Specifically, by setting a concentration threshold, such as 1.5 times the global average concentration, nodes with a threat level significantly higher than the average level can be screened out. Or the top D% (such as Top20%) of the nodes can be selected to construct a candidate set of attack paths to focus on the nodes with the highest threat level.

[0102] High-concentration nodes represent nodes with a higher threat level in the network and are key points in the attack path. Attackers often use these nodes as breakthrough points or transfer stations. Therefore, preferentially exploring these nodes and their neighbors can more accurately and efficiently discover potential threats.

[0103] Deploy multiple search agents to traverse and query high-concentration nodes in parallel to improve the search speed. Start the traversal query from high-concentration nodes and expand the search to their neighbor nodes centered on these nodes. In this way, other nodes and relationships connected to high-concentration nodes can be gradually discovered, thereby constructing potential attack paths.

[0104] For the newly discovered attack patterns, use sparse auto-encoding feature compression to store them in the attack pattern memory bank to reduce storage overhead and support fast pattern matching. The attack pattern memory bank is used to store known attack patterns (such as DDoS attacks, malware infections, SQL injection attacks, brute-force cracking attacks, etc.) and newly discovered attack patterns for fast pattern matching in the search to identify the current attack pattern and issue early warnings in a timely manner.

[0105] According to the information in the external threat intelligence library, update the threat quantification values and relationship weights of the nodes in the network knowledge graph. Thereby improving the accuracy and effectiveness of the graph query algorithm and better discovering potential attacks and paths.

[0106] Further optionally, the deployment of multiple search agents includes:

[0107] For the high-concentration nodes in the candidate set of attack paths, calculate the traversal priority by combining the node odor concentration value, the number of neighbor nodes, and the average odor concentration of neighbor nodes. The formula is:

[0108] ,

[0109] Among them, S i is the odor concentration value of node i, that is, the initial threat quantification value of node i, N i is the number of neighbor nodes, is the average concentration of neighbor nodes, and α + β + γ = 1;

[0110] According to the traversal priority, each high-concentration node is assigned to multiple search agents, where each search agent is responsible for a subgraph area.

[0111] It can be understood that when deploying search agents, the deployment can be specifically carried out according to the traversal priority calculated by combining the odor concentration value of the node, the number of neighbor nodes, and the average odor concentration of neighbor nodes.

[0112] Among them, S i is the concentration value of node i, that is, the initial threat quantification value, which reflects the threat level of the node itself. The higher the concentration value, the greater the importance of the node in the potential attack path. Therefore, a higher weight should be assigned when calculating the traversal priority.

[0113] N i is the number of neighbor nodes, representing the connection range of node i. The more neighbor nodes, the wider the influence range of the node in the network, and it may form potential attack paths with more other nodes.

[0114] is the average concentration of neighbor nodes, which reflects the threat level of the environment around node i. If the average concentration of neighbor nodes is relatively high, it means that the overall threat of the area where the node is located is relatively large, and then the node is more likely to be part of an attack path.

[0115] α, β, and γ are weight coefficients used to balance the influence of different parameters on the traversal priority. According to the actual network security requirements and node characteristics, the values of the coefficients can be adjusted. For example, if it is considered that the threat level of the node itself is more important, the value of α can be appropriately increased.

[0116] According to the calculated traversal priority, each high-concentration node is assigned to multiple search agents, and each agent is responsible for a subgraph area to ensure that the number of nodes and the total concentration value responsible for each agent are balanced, thus avoiding the situation where some search agents are overloaded while others are idle, and improving the search efficiency. At the same time, making the threat levels of the areas responsible for each agent relatively balanced helps to comprehensively and deeply explore potential threats in the network.

[0117] For example, for the top 5% of the highest-concentration nodes, since their threat levels are extremely high and they are key nodes in the attack path, assigning 2 - 3 agents to explore in parallel can speed up the search and increase the probability of discovering potential attacks and paths.

[0118] Further optionally, starting a traversal query for the high-concentration nodes in the candidate attack path set to find potential attacks and attack paths, including:

[0119] For each sub-region responsible by a search agent, pre-load the initial concentration field data and adjacency matrix of its responsible sub-region;

[0120] Starting from the node with the highest concentration value in the sub-region, visit in descending order of the current threat quantification value of neighbor nodes;

[0121] Determine whether the traversal path deviates from the normal mode, including frequent visits to low-concentration nodes, overly single threat type of the path, and drastic fluctuations in threat values;

[0122] If the traversal path deviates from the normal mode, extract the current path feature vector and calculate the similarity with the known attack modes stored in the attack mode memory bank. The path feature vector includes the statistical distribution of threat quantification values of path nodes, the threat type sequence, and path entropy;

[0123] If the similarity exceeds the similarity threshold, mark it as a potential attack and trigger an alarm. The alarm content includes the list of path nodes and threat types;

[0124] When the traversal covers all high-concentration nodes and their direct neighbors in the candidate attack path set, terminate the traversal, and generate an attack path map and output a risk score report.

[0125] It is understandable that when starting a traversal query for high-concentration nodes, for each sub-region responsible by a search agent, first pre-load the initial concentration field data (including node ID + initial concentration value S i ), and the adjacency matrix (stored in sparse matrix format, used to describe the connection relationship between nodes).

[0126] Starting from the node with the highest concentration value in the sub-region, visit in descending order of the current threat quantification value of neighbor nodes. The node with the highest concentration value represents the node with the highest threat level. Starting from these nodes can find the core part of the potential attack path faster. And the current threat quantification value of neighbor nodes reflects their threat level in the current network environment. Visiting in descending order can preferentially select neighbor nodes with higher threat levels, further focusing on the potential attack path. For every 10 nodes visited, a local attack mode detection can be performed to timely discover abnormal modes in the traversal path and avoid missing potential attacks.

[0127] Record the node sequence of the access path, the cumulative threat value, and the path entropy. Among them, recording the node sequence can construct the traversal path; the cumulative threat value reflects the overall threat level of the nodes on the path and can be an important indicator for judging whether the path is a potential attack path; the path entropy is calculated based on the distribution of path threat types and reflects the diversity of threat types on the path. The lower the path entropy, the more single the threat type, and there may be an anomaly.

[0128] Judge whether the traversal path deviates from the normal mode, such as frequently accessing low-concentration nodes, the path threat type being too single, and the threat value fluctuating violently, etc. The judgment criteria can be as follows: If the number of low-concentration nodes accessed within the window / the total number of accessed nodes is greater than 0.6, it is judged as frequently accessing low-concentration nodes. Because under normal circumstances, the traversal path should preferentially access high-concentration nodes. If low-concentration nodes are frequently accessed, it may indicate that the path deviates from the normal mode and there is a possibility of potential attack.

[0129] If the current path entropy is less than 0.7 times the historical average path entropy, it is determined that the path threat type is too single. Because normal attack paths usually involve multiple threat types. If the path threat type is too single, it may be an abnormal attack mode.

[0130] When the standard deviation / mean of the path cumulative threat value is greater than 0.3, it is determined that the threat value fluctuates violently. The violent fluctuation of the threat value may mean that there are abnormal threat changes on the path, which may be caused by attack behaviors.

[0131] If the traversal path deviates from the normal mode, extract the current path feature vector and calculate the similarity with the known attack modes stored in the attack mode memory library to determine whether the current path is similar to the known attack modes, so as to determine whether it is a potential attack. The path feature vector includes the statistical distribution of the threat quantization values of path nodes, the threat type sequence, and the path entropy. If the similarity exceeds the similarity threshold (such as > 85%), it is marked as a potential attack and an alarm is triggered. The alarm content includes the list of path nodes and the threat type.

[0132] When the traversal covers all high-concentration nodes and their direct neighbors in the attack path candidate set, the traversal is terminated, and an attack path graph and an output risk score report are generated. The attack path graph includes key nodes (i.e., high-concentration nodes), path weights, and threat type distributions to visually display potential attack paths. The content of the risk score report includes threat types and emergency level classifications, providing detailed risk assessment information for security management personnel.

[0133] Further optionally, after starting from the node with the highest concentration value in the sub-region and accessing in descending order of the current threat quantization value of neighbor nodes, it further includes:

[0134] During the access process, if it is found that three consecutive nodes all belong to high-concentration nodes and the threat types of the nodes belong to the same attack chain, then depth search is triggered and exploration continues along the direction of the gradient descent of the threat quantization value;

[0135] When the growth rate of the cumulative threat value of the path is less than the backtracking threshold for two consecutive steps, then backtracking is triggered and the depth search is terminated.

[0136] It can be understood that high-concentration nodes represent nodes with a relatively high degree of threat in network threat assessment. If three high-concentration nodes appear consecutively, it indicates that the current access path may be in an area with a high concentration of threats and is very likely to hide important potential attack paths.

[0137] When the threat types of the nodes belong to the same attack chain, it indicates that the current path may be developing along a real attack path. For example, an attacker may first obtain a network entry through an initial access, then elevate privileges to gain more control, and finally perform lateral movement to expand the attack scope. In this case, depth search can help discover the complete attack path.

[0138] When the above two conditions are both met, that is, three consecutive nodes belong to both high-concentration nodes and the same attack chain, it indicates that this path is very likely to be a potential attack path with a high threat. Triggering depth exploration can more accurately screen out truly valuable paths. Specifically, exploration can continue along the direction of the gradient descent of the threat quantization value, that is, extending from high-threat nodes to relatively lower-threat nodes. Because in an attack scenario, an attacker often uses nodes with gradually decreasing threat levels to advance the attack to reduce the risk of being discovered. For example, an attacker may first attack a high-threat core server and then further penetrate the network by controlling some terminal devices with lower threat levels.

[0139] This choice of search direction conforms to the behavior pattern of an attacker in an actual attack and can more effectively discover the subsequent links of the attack path. It avoids blind search, concentrates search resources in areas where there is a higher likelihood of an attack path, thereby further improving the search efficiency.

[0140] When the growth rate is less than the backtracking threshold for two consecutive steps, it indicates that the threat level of the current path is growing slowly, may have deviated from the main attack path, or has entered a low-threat area. Then backtracking is triggered and the depth search is terminated to avoid wasting search resources.

[0141] Further optionally, the updating of the threat quantization value and relationship weight of the nodes in the network knowledge graph includes:

[0142] During the traversal process, for the nodes on the traversed path, their real-time threat quantization values are dynamically updated, and the update formula is:

[0143] ,

[0144] Among them, is the real-time threat quantification value of node i on the path, is the initial threat quantification value of node i, δ is the attenuation coefficient, Δt is the time window, is the real-time threat increment of node i;

[0145] A node sequence that contains multiple high-concentration nodes and whose threat types are related is defined as a high-threat path, and weight reinforcement is performed on the high-threat path. The formula is:

[0146] ,

[0147] ,

[0148] ,

[0149] ,

[0150] TypeCorrelation = number of consecutive matching stages / total number of attack chain stages,

[0151] Among them, is the weight after reinforcement from node i to node j, is the original weight from node i to node j, λ is the reinforcement coefficient, PathThreat is the path threat score, TypeCorrelation is the path threat type correlation degree, θ is the correlation strength coefficient, is the entropy weight coefficient of node i, used to reflect the threat type diversity, is the threat type entropy value of node i, is the occurrence probability of the e-th threat type of node i, m is the total number of threat types faced by node i, and n is the number of nodes on the path.

[0152] It can be understood that for the nodes on the traversed path, their real-time threat quantification values are dynamically updated to more accurately evaluate the threat level of the nodes in the current network environment.

[0153] At the same time, the relationship weights between nodes in the network knowledge graph are dynamically updated. Specifically, weight reinforcement can be performed on high-threat paths to make these paths more prominent in the network knowledge graph, so as to more easily discover potential serious threats. A node sequence that contains multiple high-concentration nodes and whose threat types are related can be defined as a high-threat path. High-concentration nodes mean that these nodes have a higher threat level, and threat type correlation indicates that these nodes may belong to the same attack chain or have similar threat characteristics.

[0154] Further optionally, dynamically updating the real-time threat quantification value of the nodes on the traversal path further includes:

[0155] During the traversal process, when the number of nodes visited by the search agent exceeds the node number threshold, randomly select k low-concentration nodes and temporarily increase their threat quantification values.

[0156] It can be understood that during the traversal of the network knowledge graph, high-concentration nodes are usually more easily noticed, but low-concentration nodes may also hide potential threats. If only high-concentration nodes are focused on, the search process may get stuck in local high-threat areas and ignore other potentially threatening paths.

[0157] When the number of nodes visited by the search agent exceeds the node number threshold, the local optimal situation can be broken by temporarily increasing the threat quantification values of low-concentration nodes, making the search more comprehensive. Thus, guiding the search agent to explore those areas that may be overlooked and discovering potential security risks. For example, in some cases, attackers may use low-threat nodes as springboards to gradually penetrate into the core area of the network.

[0158] It can be set that the number of nodes visited in a single traversal being greater than 100 is used as the trigger condition. If the network scale is large, the threshold can be appropriately increased; if the security requirements are high and a more comprehensive exploration is desired earlier, the threshold can be decreased.

[0159] The threat quantification values can be increased for exploration by randomly selecting 5 to 10 low-concentration nodes. The selection within this range should ensure exploration diversity while avoiding excessive node increases that may cause the search to be too scattered.

[0160] The threat quantification values of low-concentration nodes can be increased to 2 to 5 times the original values. Too small an increase may not effectively guide the search, while too large an increase may cause the search to be overly concentrated on these temporarily increased nodes.

[0161] In summary, the network security dynamic early warning method of the present invention constructs a network knowledge graph and uses it as the data basis, which can better mine the potential relationships between data and support complex query operations to quickly locate information related to specific entities or relationships. According to the requirements of network security early warning, identifying potential attacks and finding potential attack paths are defined as query targets, providing a clear direction and pertinence for the search of graph query algorithms. Through the fruit fly optimization algorithm, threat features are mapped into a three-dimensional odor concentration field, and the graph query algorithm is optimized, so that the optimized graph query algorithm can fully consider the node concentration field, that is, the odor concentration value of each node. Since these concentration values comprehensively reflect the characteristics of nodes in terms of threat type, urgency, and propagation speed, the graph query algorithm can give priority attention and locate those nodes with higher threat levels during the search process of the network knowledge graph, reducing unnecessary searches, greatly improving the search efficiency, and thus more accurately and efficiently finding potential attacks and attack paths in the network knowledge graph, triggering early warnings in a timely manner, and ensuring the security of network operation.

[0162] Embodiment 2

[0163] Please refer to Figure 2 , the network security dynamic early warning device proposed by the present invention, which includes:

[0164] Knowledge graph module: used to store entities and entity relationships in network data in the form of a graph structure to form a network knowledge graph;

[0165] Query target module: used to define query targets according to the requirements of network security early warning, and the query targets include identifying potential attacks and finding potential attack paths;

[0166] Optimization module: used to map threat features into a three-dimensional odor concentration field through the fruit fly optimization algorithm to optimize the graph query algorithm, where the three-dimensional odor concentration field includes the threat type, urgency, and propagation speed of network security;

[0167] Threat detection module: used to search in the network knowledge graph based on the query target through the optimized graph query algorithm to find potential attacks and attack paths and trigger early warnings in a timely manner.

[0168] Further optionally, the optimization module is further used for:

[0169] Randomly select N starting nodes in the network knowledge graph as the initial positions of the fruit fly population, and each fruit fly individual carries a three-dimensional position vector, including node ID, relationship type, and confidence;

[0170] Define a fitness function according to the threat type, urgency, and propagation speed of network security to quantify and calculate the odor concentration of nodes. Among them, the higher the concentration value, the more critical the corresponding node is on the attack path. The formula is:

[0171] ,

[0172] Among them, ω 1 , ω 2 , ω 3 are weight coefficients, ω 1 +ω 2 +ω 3 = 1, is the threat type quantization value of node i, is the threat urgency quantization value of node i, is the threat propagation speed quantization value of node i;

[0173] For each node at the current position of the fruit fly, calculate its odor concentration value according to the fitness function, and update the position of the fruit fly according to the concentration gradient to make it move towards the high-concentration node;

[0174] Repeat the execution of odor concentration calculation and position update until the termination condition is met, determine the final position distribution of the fruit fly population, and the optimized node concentration field, including the odor concentration value of each node, as the initial threat quantization value.

[0175] Further optionally, the threat detection module is further used for:

[0176] Extract high-concentration nodes as candidate key nodes according to the final position distribution of the fruit fly population, and construct a candidate set of attack paths by sorting according to the concentration value;

[0177] Deploy multiple search agents to start traversing and querying the high-concentration nodes in the candidate set of attack paths to find potential attacks and attack paths;

[0178] Activate the attack pattern memory bank to sparsely auto-encode and store the discovered new attack patterns;

[0179] Regularly synchronize the external threat intelligence library to update the node threat quantization value and relationship weight in the network knowledge graph.

[0180] Further optionally, the threat detection module is further used for:

[0181] For the high-concentration nodes in the candidate set of attack paths, calculate the traversal priority by combining the node odor concentration value, the number of neighbor nodes, and the average odor concentration of neighbor nodes. The formula is:

[0182] ,

[0183] Among them, S i is the odor concentration value of node i, that is, the initial threat quantification value of node i, and N i is the number of neighbor nodes, is the average concentration of neighbor nodes, where α + β + γ = 1;

[0184] According to the traversal priority, each high-concentration node is assigned to multiple search agents, where each search agent is responsible for a subgraph area.

[0185] Further optionally, the threat detection module is further configured to:

[0186] For each sub-region responsible by a search agent, pre-load the initial concentration field data and adjacency matrix of the sub-region it is responsible for;

[0187] Starting from the node with the highest concentration value in the sub-region, visit in descending order of the current threat quantification value of neighbor nodes;

[0188] Determine whether the traversal path deviates from the normal mode, including frequently visiting low-concentration nodes, the threat type of the path being too single, and the threat value fluctuating violently;

[0189] If the traversal path deviates from the normal mode, extract the current path feature vector and calculate the similarity with the known attack patterns stored in the attack pattern memory library. The path feature vector includes the statistical distribution of the threat quantification values of path nodes, the threat type sequence, and the path entropy;

[0190] If the similarity exceeds the similarity threshold, mark it as a potential attack and trigger an alarm. The alarm content includes the list of path nodes and the threat type;

[0191] When the traversal covers all high-concentration nodes and their direct neighbors in the attack path candidate set, terminate the traversal, and generate an attack path map and output a risk score report.

[0192] Further optionally, the threat detection module is further configured to:

[0193] During the access process, if it is found that three consecutive nodes all belong to high-concentration nodes and the threat types of the nodes belong to the same attack chain, trigger a depth search and continue to explore along the direction of the gradient descent of the threat quantification value;

[0194] When the growth rate of the cumulative threat value of the path is less than the backtracking threshold for two consecutive steps, trigger backtracking and terminate the depth search.

[0195] Further optionally, the threat detection module is further configured to:

[0196] During the traversal process, obtain the real-time threat data stream;

[0197] For the nodes on the traversal path, their real-time threat quantification values are dynamically updated, and the update formula is:

[0198] ,

[0199] where, is the real-time threat quantification value of node i on the path, is the initial threat quantification value of node i, δ is the attenuation coefficient, Δt is the time window, is the real-time threat increment of node i;

[0200] A node sequence that contains multiple high-concentration nodes and whose threat types are associated is defined as a high-threat path, and weight reinforcement is performed on the high-threat path. The formula is:

[0201] ,

[0202] ,

[0203] ,

[0204] ,

[0205] TypeCorrelation = number of consecutive matching stages / total number of attack chain stages,

[0206] where, is the weight after reinforcement from node i to node j, is the original weight from node i to node j, λ is the reinforcement coefficient, PathThreat is the path threat score, TypeCorrelation is the path threat type correlation degree, θ is the correlation strength coefficient, is the entropy weight coefficient of node i, used to reflect the threat type diversity, is the threat type entropy value of node i, is the occurrence probability of the e-th threat type of node i, m is the total number of threat types faced by node i, and n is the number of nodes on the path.

[0207] Further optionally, the threat detection module is further used for:

[0208] During the traversal process, if the number of nodes visited by the search agent exceeds the node number threshold, then randomly select k low-concentration nodes and temporarily increase their threat quantification values.

[0209] Embodiment III

[0210] Please refer to Figure 3, the present invention also provides a network security dynamic warning device, which is shown as the network security dynamic warning device in the third embodiment of the present invention. It includes a memory 20, a processor 10, and a computer program 30 stored in the memory and executable on the processor. When the processor 10 executes the computer program 30, it implements the network security dynamic warning method as described above.

[0211] Among them, the network security dynamic warning device can specifically be a computer, a server, a host computer, etc. In some embodiments, the processor 10 can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips, and is used to run the program code stored in the memory 20 or process data, such as executing an access restriction program, etc.

[0212] Among them, the memory 20 includes at least one type of readable storage medium. The readable storage medium includes flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 20 can be an internal storage unit of the network security dynamic warning device, such as the hard disk of the network security dynamic warning device. In some other embodiments, the memory 20 can also be an external storage device of the network security dynamic warning device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the network security dynamic warning device. Further, the memory 20 can also include both the internal storage unit and the external storage device of the network security dynamic warning device. The memory 20 can not only be used to store the application software and various types of data installed in the network security dynamic warning device, but also be used to temporarily store the data that has been output or will be output.

[0213] The above embodiments only represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention should be subject to the appended claims.

Claims

1. A network security dynamic early warning method, characterized in that: The method comprises: Store entities and entity relationships in network data in the form of a graph structure to form a network knowledge graph; According to the requirements of network security early warning, the query objectives are defined, and the query objectives include identifying potential attacks and finding potential attack paths; Through the fruit fly optimization algorithm, the threat characteristics are mapped into a three-dimensional odor concentration field to optimize the graph query algorithm. The three-dimensional odor concentration field includes the threat type, urgency and propagation speed of network security. Based on the query target, the optimized graph query algorithm is used to search in the network knowledge graph to find potential attacks and attack paths, and trigger early warnings in a timely manner.

2. The network security dynamic early warning method according to claim 1 is characterized in that: The threat feature is mapped into a three-dimensional odor concentration field by the fruit fly optimization algorithm, and the graph query algorithm is optimized, including: Randomly selecting N starting nodes in the network knowledge graph as the initial position of the fruit fly population, so that each fruit fly individual carries a three-dimensional position vector including a node ID, a relationship type, and a confidence level; The fitness function is defined according to the threat type, urgency and propagation speed of network security, which is used to quantify the odor concentration of the computing node. The higher the concentration value, the more critical the corresponding node is on the attack path. The formula is: , Among them, ω1, ω2, ω3 are weight coefficients, ω1+ω2+ω3=1, is the quantified value of the threat type of node i, is the quantitative value of the threat urgency of node i, is the quantitative value of the threat propagation speed of node i; For each fruit fly's current position node, calculate its odor concentration value according to the fitness function, and update the fruit fly's position according to the concentration gradient to make it move to the high-concentration node; Repeat the odor concentration calculation and position update until the termination condition is met to determine the final position distribution of the fruit fly population and the optimized node concentration field, including the odor concentration value of each node, as the initial threat quantification value.

3. The network security dynamic early warning method according to claim 2 is characterized in that: Based on the query target, searching in the network knowledge graph by using an optimized graph query algorithm to find potential attacks and attack paths includes: According to the final position distribution of the fruit fly population, high-concentration nodes are extracted as candidate key nodes, and the candidate set of attack paths is constructed by sorting by concentration value; Deploy multiple search agents to initiate traversal queries on high-concentration nodes in the attack path candidate set to find potential attacks and attack paths; Activate the attack pattern memory bank and compress and store the discovered new attack patterns using sparse autoencoding features; Regularly synchronize external threat intelligence libraries and update the node threat quantification values ​​and relationship weights in the network knowledge graph.

4. The network security dynamic early warning method according to claim 3 is characterized in that: The deployment of multiple search agents includes: For the high-concentration nodes in the attack path candidate set, the traversal priority is calculated by combining the node odor concentration value, the number of neighboring nodes, and the average odor concentration of neighboring nodes. The formula is: , Among them, S i is the odor concentration value of node i, that is, the initial threat quantization value of node i, N i is the number of neighbor nodes, is the average concentration of neighbor nodes, α+β+γ=1; Each high-density node is allocated to a plurality of search agents according to the traversal priority, wherein each search agent is responsible for a subgraph area.

5. The network security dynamic early warning method according to claim 3 is characterized in that: The initiating a traversal query on high-concentration nodes in the attack path candidate set to find potential attacks and attack paths includes: For each sub-region that a search agent is responsible for, preload the initial concentration field data and adjacency matrix of the sub-region that the search agent is responsible for; Starting from the node with the highest concentration value in the sub-area, visit the neighboring nodes in descending order of the current threat quantization value; Determine whether the traversal path deviates from the normal pattern, including frequent visits to low-concentration nodes, too single path threat type, and drastic fluctuations in threat value; If the traversal path deviates from the normal mode, the current path feature vector is extracted and the similarity is calculated with the known attack patterns stored in the attack pattern memory. The path feature vector includes the statistical distribution of the threat quantization value of the path node, the threat type sequence and the path entropy. If the similarity exceeds the similarity threshold, it is marked as a potential attack and an alarm is triggered. The alarm content includes the path node list and threat type; When the traversal covers all high-concentration nodes and their direct neighbors in the attack path candidate set, the traversal is terminated, and an attack path graph is generated and a risk score report is output.

6. The network security dynamic early warning method according to claim 5 is characterized in that: After starting from the node with the highest concentration value in the sub-area and visiting neighboring nodes in descending order of the current threat quantization value, the method further includes: During the visit, if three consecutive nodes are found to be high-concentration nodes and the threat types of the nodes belong to the same attack chain, a deep search is triggered and the exploration continues along the gradient descent direction of the threat quantization value; When the growth rate of the cumulative threat value of the path is less than the backtracking threshold for two consecutive steps, backtracking is triggered and the deep search is terminated.

7. The network security dynamic early warning method according to claim 3 is characterized in that: The updating of the node threat quantification value and the relationship weight in the network knowledge graph includes: During the traversal process, obtain real-time threat data streams; For the nodes on the traversal path, the real-time threat quantification value is dynamically updated. The update formula is: , in, is the real-time threat quantification value of node i on the path, is the initial threat quantization value of node i, δ is the attenuation coefficient, Δt is the time window, is the real-time threat increment of node i; A node sequence containing multiple high-concentration nodes and associated threat types is defined as a high-threat path, and the weight of the high-threat path is strengthened. The formula is: , , , , TypeCorrelation = number of consecutive matching stages / total number of attack chain stages, in, is the weight after strengthening from node i to node j, is the original weight from node i to node j, λ is the reinforcement coefficient, PathThreat is the path threat score, TypeCorrelation is the path threat type correlation, θ is the correlation strength coefficient, is the entropy weight coefficient of node i, which is used to reflect the diversity of threat types. is the threat type entropy value of node i, is the occurrence probability of the e-th threat type at node i, m is the total number of threat types faced by node i, and n is the number of nodes on the path.

8. The network security dynamic early warning method according to claim 7 is characterized in that: The dynamically updating the real-time threat quantification value of the nodes on the traversal path also includes: During the traversal process, if the number of nodes visited by the search agent exceeds the node number threshold, k low-concentration nodes are randomly selected to temporarily increase their threat quantification value.

9. A network security dynamic early warning device, used to implement the network security dynamic early warning method according to any one of claims 1 to 8, characterized in that: The device comprises: Knowledge graph module: used to store entities and entity relationships in network data in the form of a graph structure to form a network knowledge graph; Query target module: used to define query targets according to the needs of network security early warning, and the query targets include identifying potential attacks and finding potential attack paths; Optimization module: used to map threat features into a three-dimensional odor concentration field through the fruit fly optimization algorithm to optimize the graph query algorithm, where the three-dimensional odor concentration field includes the threat type, urgency and propagation speed of network security; Threat detection module: used to search in the network knowledge graph based on the query target through the optimized graph query algorithm, find potential attacks and attack paths, and trigger early warning in time.

10. Network security dynamic early warning equipment, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, the network security dynamic early warning method as claimed in any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Network security knowledge graph generation method based on threat intelligence

    CN113282759A

  • Network security protection method and system

    CN117879970A

  • Data retrieval management system and method based on standard knowledge graph

    CN117909516A

  • Key threat information inference method and device based on meta-heuristic algorithm

    CN118101245A

  • Network security threat perception identification response method based on security knowledge graph

    CN119011251A

Cited By

  • Alarm information processing system and method of technological process

    CN120811859A

  • Unmanned aerial vehicle-mounted multi-mode vegetation observation system

    CN120928825A