Data processing method and device for cyberspace situation analysis

Through a data processing method and device for cyberspace situation analysis, the problem that traditional methods are difficult to capture the complexity, dynamicity and nonlinear relationships of cyberspace is solved, and higher analysis accuracy and efficiency are achieved, providing more solid support for cyberspace security.

CN120050187AInactive Publication Date: 2025-05-27NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510187672.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional cyberspace situation prediction methods based on feature space cannot comprehensively and accurately describe the complexity and dynamics of cyberspace, and are difficult to capture nonlinear relationships in the data, affecting the accuracy of prediction results.

Method used

A data processing method and device for cyberspace situation analysis is proposed, including obtaining the information to be processed, pre-processing and analysis processing, performing feature analysis and judgment through the target situation analysis model, and generating network situation analysis results.

Benefits of technology

It improves the accuracy and efficiency of cyberspace situation analysis and can more accurately evaluate cyberspace situations, thereby providing support for ensuring cyberspace security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050187A_ABST
    Figure CN120050187A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method and device for cyberspace situation analysis. The method comprises the following steps: acquiring cyberspace information to be processed; preprocessing the to-be-processed network space information to obtain target processing network space information; and analyzing and processing the target processing network space information to obtain target network situation analysis result information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technology, and in particular to a data processing method and device for network space situation analysis. Background Art

[0002] In the field of cyberspace security, situation prediction is a crucial technology. Traditional cyberspace situation prediction methods based on feature space have exposed some problems in long-term applications. Traditional cyberspace situation prediction based on feature space often relies on artificial experience to select features, which makes it impossible to fully and accurately describe the complexity and dynamics of cyberspace. Some key features may be ignored, thus affecting the accuracy of the prediction results. Cyberspace situation prediction problems often have nonlinear characteristics, and traditional feature space methods are mostly based on linear assumptions, which makes it difficult to capture nonlinear relationships in data, thus affecting the prediction accuracy. Therefore, a data processing method and device for cyberspace situation analysis are provided to improve the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security. Summary of the invention

[0003] The technical problem to be solved by the present invention is to provide a data processing method and device for cyberspace situation analysis, which is conducive to improving the accuracy and efficiency of cyberspace situation analysis, and further provides support for ensuring cyberspace security.

[0004] In order to solve the above technical problems, the first aspect of the embodiment of the present invention discloses a data processing method for cyberspace situation analysis, the method comprising:

[0005] Obtaining the cyberspace information to be processed;

[0006] Preprocessing the to-be-processed network space information to obtain target processed network space information;

[0007] The target processing network space information is analyzed and processed to obtain target network situation analysis result information.

[0008] A second aspect of an embodiment of the present invention discloses a data processing device for cyberspace situation analysis, the device comprising:

[0009] An acquisition module, used to acquire the network space information to be processed;

[0010] A first processing module is used to pre-process the network space information to be processed to obtain target processing network space information;

[0011] The second processing module is used to analyze and process the target network space information to obtain target network situation analysis result information.

[0012] The third aspect of the present invention discloses another data processing device for cyberspace situation analysis, the device comprising:

[0013] A memory storing executable program code;

[0014] a processor coupled to the memory;

[0015] The processor calls the executable program code stored in the memory to execute part or all of the steps in the data processing method for cyberspace situation analysis disclosed in the first aspect of an embodiment of the present invention.

[0016] The fourth aspect of the present invention discloses a computer-readable storage medium, which stores computer instructions. When the computer instructions are called, they are used to execute part or all of the steps in the data processing method for cyberspace situation analysis disclosed in the first aspect of an embodiment of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0018] Figure 1 It is a schematic diagram of a scenario of a data processing system for cyberspace situation analysis provided by an embodiment of the present invention;

[0019] Figure 2 It is a flow chart of a data processing method for cyberspace situation analysis disclosed in an embodiment of the present invention;

[0020] Figure 3 It is a structural schematic diagram of a data processing device for cyberspace situation analysis disclosed in an embodiment of the present invention;

[0021] Figure 4 It is a structural schematic diagram of another data processing device for cyberspace situation analysis disclosed in an embodiment of the present invention;

[0022] Figure 5 It is a structural schematic diagram of a target situation analysis model disclosed in an embodiment of the present invention;

[0023] Figure 6 It is a structural schematic diagram of a feature processing module disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0025] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, device, product or equipment that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to these processes, methods, products or equipment.

[0026] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0027] In this application, the word "exemplary" is used to mean "used as an example, illustration, or description." Any embodiment described in this application as "exemplary" is not necessarily to be construed as being preferred or advantageous over other embodiments. The following description is given to enable any technician in the field to implement and use the present application. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present application can be implemented without using these specific details. In other instances, well-known structures and processes will not be elaborated in detail to avoid obscuring the description of the present application with unnecessary details. Therefore, the present application is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed in the present application.

[0028] It should be noted that since the method of the embodiment of the present application is executed in a computer device, the processing objects of each computer device exist in the form of data or information. For example, time is actually time information. It can be understood that if size, quantity, position, etc. are mentioned in subsequent embodiments, they are all corresponding data for processing by the computer device. The details will not be repeated here.

[0029] It should be noted that the artificial intelligence related technologies that may be involved in this application are briefly described. Artificial Intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a similar way to human intelligence. Artificial intelligence is to study the design principles and implementation methods of various intelligent machines so that machines have the functions of perception, reasoning and decision-making.

[0030] Artificial intelligence technology is a comprehensive discipline that covers a wide range of fields, including both hardware-level and software-level technologies. The basic technologies of artificial intelligence generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, mechatronics and other technologies. Artificial intelligence software technology mainly includes computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0031] Computer Vision (CV) is a science that studies how to make machines "see". To put it more specifically, it refers to machine vision such as using cameras and computers to replace human eyes to identify and measure targets, and further perform graphic processing so that computer processing becomes an image that is more suitable for human eye observation or transmission to instrument detection. As a scientific discipline, computer vision studies related theories and technologies, and attempts to establish an artificial intelligence system that can obtain information from images or multi-dimensional data. Computer vision technology usually includes image processing, image recognition, image semantic understanding, image retrieval, OCR, video processing, video semantic understanding, video content / behavior recognition, three-dimensional object reconstruction, 3D technology, virtual reality, augmented reality, simultaneous positioning and map construction, and other technologies, as well as common biometric recognition technologies such as face recognition and fingerprint recognition.

[0032] Unimodal information is data of only one type, such as text, image, audio, video, electromagnetic signal, etc. Multimodal information is data that includes at least two types of unimodal information. Furthermore, multimodal information is suitable for complex tasks that require the integration of multiple information sources, such as sentiment analysis, robot interaction, autonomous driving, etc. By integrating information from multiple modalities, higher performance and accuracy can usually be achieved on the task.

[0033] A large model refers to an artificial neural network model with a very large number of parameters. In the field of artificial intelligence, a large model generally refers to a model with hundreds of millions to trillions of parameters. Models usually need to be trained on large-scale data sets and require a large amount of computing resources to be optimized and adjusted. Large models are often used to solve complex tasks such as natural language processing, computer vision, and speech recognition. Generative AI is an AI that can create new content and ideas, including conversations, stories, images, videos, and music. In an embodiment of the present application, the large model may be ChatGPT, BERT, XLNet, Zhipu model, Claude, Moonshot AI model, ChatGLM model, Tongwen Qianyi model, MiniMax model, Spark model, Llama model, 360GPT model, Qwen model, Baichuan model, Skylark model, vivoLM model, and Wenxin Yiyan scale language models, which are not limited in the embodiments of the present application.

[0034] The embodiments of the present application provide a data processing method, apparatus, computer equipment, and computer-readable storage medium for cyberspace situation analysis, which are described in detail below.

[0035] See also Figure 1 , Figure 1 The schematic diagram of a scenario of a data processing system for cyberspace situation analysis provided in an embodiment of the present application is as follows. The data processing system for cyberspace situation analysis may include a computer device 100, in which a data processing device for cyberspace situation analysis is integrated, such as Figure 1 Computer equipment in.

[0036] In the embodiment of the present application, the computer device 100 is mainly used to obtain the network space information to be processed;

[0037] Preprocessing the to-be-processed network space information to obtain target processed network space information;

[0038] The target processing network space information is analyzed and processed to obtain target network situation analysis result information.

[0039] It can improve the accuracy and efficiency of cyberspace situation analysis, and thus provide support for ensuring cyberspace security.

[0040] In the embodiment of the present application, the computer device 100 may be an independent server, or a server network or server cluster composed of servers. For example, the computer device 100 described in the embodiment of the present application includes but is not limited to a computer, a network host, a single network server, a plurality of network server sets or a cloud server composed of a plurality of servers. The cloud server is composed of a large number of computers or network servers based on cloud computing.

[0041] It is understandable that the computer device 100 used in the embodiments of the present application may be a device including both receiving and transmitting hardware, that is, a device having receiving and transmitting hardware capable of performing two-way communication on a two-way communication link. Such a device may include: a cellular or other communication device having a single-line display or a multi-line display or a cellular or other communication device without a multi-line display. The specific computer device 100 may be a desktop terminal or a mobile terminal, and the computer device 100 may also be one of a mobile phone, a tablet computer, a laptop computer, etc.

[0042] Those skilled in the art will understand that Figure 1 The application environment shown in the figure is only one application scenario of the present application solution and does not constitute a limitation on the application scenario of the present application solution. Other application environments may also include Figure 1 More or less computer equipment as shown in Figure 1 Only one computer device is shown. It can be understood that the data processing system for cyberspace situation analysis may also include one or more other services, which are not specifically limited here.

[0043] In addition, if Figure 1 As shown, the data processing system for cyberspace situation analysis may also include a memory 200 for storing data, such as image data, location information, etc.

[0044] It should be noted that Figure 1 The scenario diagram of the data processing system for cyberspace situation analysis shown is merely an example. The data processing system and scenario for cyberspace situation analysis described in the embodiment of the present application are intended to more clearly illustrate the technical solution of the embodiment of the present application, and do not constitute a limitation on the technical solution provided in the embodiment of the present application. A person of ordinary skill in the art can appreciate that with the evolution of the data processing system for cyberspace situation analysis and the emergence of new business scenarios, the technical solution provided in the embodiment of the present application is equally applicable to similar technical problems.

[0045] The present invention discloses a data processing method and device for cyberspace situation analysis, which is beneficial to improving the accuracy and efficiency of cyberspace situation analysis, and further provides support for ensuring cyberspace security. Detailed descriptions are given below.

[0046] Embodiment 1

[0047] See also Figure 2 , Figure 2 The following is a flow chart of a data processing method for cyberspace situation analysis disclosed in an embodiment of the present invention. Figure 2 The data processing method for cyberspace situation analysis described above is applied to a management system, such as a local server or a cloud server for management, and the embodiments of the present invention are not limited thereto. Figure 2 As shown, the data processing method for cyberspace situation analysis may include the following operations:

[0048] 101. Obtain the network space information to be processed.

[0049] 102. Preprocess the network space information to be processed to obtain target processing network space information.

[0050] 103. Analyze and process the target network space information to obtain the target network situation analysis result information.

[0051] It should be noted that the above-mentioned cyberspace information to be processed can be intelligence material sources such as websites, social platforms, scientific research databases, vulnerability libraries, etc. collected through multi-source heterogeneous cross-language security intelligence data collection technology, so as to break through the core technical points such as intelligence collection based on self-learning of subject knowledge, deep intelligence material collection for DeepWeb, and multi-search engine fusion collection, combined with MSNB anti-crawling technology for intelligence sources, to achieve real-time collection of security information such as global cyberspace strategy, industry status, equipment system, research hotspots, threats, etc., to provide data support for breakthroughs and verification of deep mining of network security intelligence, correlation analysis, and network security intelligence trend perception technology, which is not limited in the embodiments of the present invention.

[0052] Furthermore, the cyberspace information to be processed can be intelligence collected based on self-learning of subject knowledge. With the goal of being able to quickly obtain network security intelligence materials with targeted and focused requirements, breakthroughs in the focused intelligence collection technology based on self-learning of subject knowledge are achieved from aspects such as subject representation model and subject knowledge expansion, supporting and realizing comprehensive and high-quality collection of intelligence materials driven by the subject. The embodiment of the present invention is not limited. The implementation process is as follows: (1) Constructing a subject representation model. Before data collection, the user needs to describe the subject he wants to collect, that is, the subject representation model. The described subject is subject knowledge. In order to reduce the complexity of the search and collection subject representation model and improve the ease of use and maintenance for users, the present invention constructs a triple subject representation model. The subject knowledge is described by a triple <I, E, C>, where I is a set of keywords directly related to the subject, E is a set of keywords contrary to the subject, and C is a feature vector composed of keywords indirectly related to the subject. Among them, the feature value of each keyword in C represents the degree of relevance between the keyword and the subject. The I set in the model refers to the keyword set that can fully represent the characteristics of the field. To limit the scope of crawling and collection; the E set is used to filter documents that are not related to the topic, that is, they must not contain any keywords in the E set; the C vector enables the algorithm to quantify the degree of topic relevance of web pages, URLs and keywords in web pages, so that the topic knowledge is expanded according to the quantitative calculation results during the crawling and collection process, and the output web pages and URLs are sorted according to the degree of topic relevance. During initialization, the user only needs to give a small number of representative keywords and weights to construct the C vector, and the topic knowledge expansion algorithm will continuously expand and improve the C vector. In the above topic representation model, the user only needs to set a few keywords at the beginning, which makes it easier to describe the topic. (2) Topic knowledge expansion. The text of the data source contains a large amount of knowledge related to the topic. Making full use of the topic-related keywords contained in the text of the intelligence source and continuously expanding the topic knowledge can better solve the problem of insufficient description of user topic knowledge. In the process of technological breakthrough, the synonyms of the natural language of the topic or its subcategories are fully considered for improvement. The present invention will construct a topic vocabulary relevance evaluation formula to describe the ability of keywords to represent topics, as shown below:

[0053]

[0054] Among them, the function γ k Indicates the topic relevance of keywords x is a noun, df(x) represents the DF value of x, D represents the currently collected web page set, D is the size of the D set, γ k The definition of (x,d) is as follows:

[0055]

[0056] Where d is a web page, φ(x,d) is the set of sentences in the text of d that contain both x and keywords in set I; S(d) is the set of sentences in the text of d; tf(x,u) and tf(x,d) are the TF values ​​of x in the anchor text of u and the text of d; U(d) is the set of all URLs in web page d. The complexity of this calculation method is linear with the number of web pages, and linear with the number of URLs in set I and the web page. The number of nouns and URLs on each web page is generally not too large, and will not grow infinitely over time.

[0057] Furthermore, the cyberspace information to be processed may be intelligence collected by deep mining of DeepWeb. In the network environment, the page that can be directly accessed through the link on the web page and can be accessed by the search engine is an ordinary web page, whose content is briefly summarized and the core information is missing. Most of the effective, core and comprehensive information can only be accessed through the interactive interface in the page filled by the user and the query request is sent to the site server to access the page with detailed intelligence information stored in the database, namely Deep Web. Focusing on the basic requirements of obtaining comprehensive and in-depth intelligence material content driven by security, the present invention adopts the core technical points such as DeepWeb interface detection and result link noise elimination based on DeepWeb data source research to support the acquisition of high-quality intelligence material from intelligence sources with DeepWeb characteristics, thereby improving the quality of intelligence material collection, which is not limited in the embodiments of the present invention. Furthermore, (1) DeepWeb interface detection. To obtain Deep Web data information, it is necessary to first discover the Deep Web data source on the web page, that is, to determine the DeepWeb site page. The query interface page is the only entrance to the Deep Web backend database, and the determination of the Deep Web data source can be transformed into the query interface page detection problem. The present invention uses the HTML structure information of the web page form to perform feature extraction, thereby determining the Deep Web query interface page and interaction mode, and on this basis, performs interface accuracy verification. In addition, in order to improve the matching coverage of the Deep Web query interface of the core intelligence source, a patterned Deep Web query interface configuration library is constructed to adapt to a variety of different coding styles. (2) Noise removal. In the field of topic search and collection, a large amount of noise content such as advertisements and navigation bars will cause topic drift. In order to improve the quality of search and collection, the present invention removes noise through style tree comparison denoising, retains core effective information, and is used to improve the efficiency and quality of WeepWeb deep mining.

[0058] Furthermore, the cyberspace information to be processed can be collected based on the fusion of multiple search engines. For a certain network security intelligence topic, the search results of a single search engine may produce incomplete content to be collected. At the same time, the noise of the search results will cause the subject collection content to be offset. In response to the above-mentioned problem of collecting network security intelligence materials based on search engines, the present invention removes noise from multiple search engines such as Baidu, Google, Zhongsou, Sogou, Qihoo, Bing, iAsk, Yahoo, NetEase, Tieyi, Soso, and Daqi one by one based on the collection theme, generates effective search result information focused on the theme, and weakens the adverse effects of excessive subject deviation. On this basis, the results of multiple search engines that have been noise-removed one by one are collected to provide effective and targeted support for subsequent intelligence material fusion processing, and weaken the impact of incomplete single search result information on the generation of high-quality intelligence. Ultimately, the intelligence material collection is comprehensive and effective, and the embodiments of the present invention are not limited.

[0059] It can be seen that implementing the data processing method for cyberspace situation analysis described in the embodiment of the present invention is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0060] In an optional embodiment, the target processing network space information is analyzed and processed to obtain the target network situation analysis result information, including:

[0061] Using the target situation analysis model to perform feature analysis on the target processing network space information to obtain first network space analysis result information;

[0062] The first network space analysis result information is judged, analyzed and processed to obtain the target network situation analysis result information.

[0063] In this optional embodiment, as an optional implementation manner, the above-mentioned judgment and analysis processing of the first network space analysis result information to obtain the target network situation analysis result information includes:

[0064] Obtain network situation assessment interval information; the network situation assessment interval information includes 5 assessment intervals and the network situation corresponding to the assessment interval;

[0065] Matching the first network space analysis result information with the evaluation interval in the network situation evaluation interval information to obtain a target evaluation interval;

[0066] The network situation corresponding to the target evaluation interval is determined as the target network situation analysis result information.

[0067] It should be noted that the above evaluation interval is 5 adjacent set values ​​divided between 0-1, and the corresponding network situations respectively represent the network being complete, the network being in a low-risk state, the network being in a medium-risk state, the network being in a high-risk state, and the network being in an ultra-high-risk state, which is not limited in the embodiments of the present invention.

[0068] It should be noted that the above-mentioned matching process of the first network space analysis result information with the evaluation interval in the network situation evaluation interval information is to find out the evaluation interval containing the network space analysis result value corresponding to the first network space analysis result information, which is not limited in the embodiment of the present invention.

[0069] It should be noted that the above-mentioned judgment, analysis and processing of the first network space analysis result information to obtain the target network situation analysis result information can accurately realize the quantitative assessment of the network space situation, thereby providing solid data support for network space management, and the embodiments of the present invention are not limited thereto.

[0070] It can be seen that implementing the data processing method for cyberspace situation analysis described in the embodiment of the present invention is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0071] In another optional embodiment, Figure 5 As shown, the target situation analysis model includes a first convolution module, a first pooling module, a first connection module, a first feature extraction network, a second feature extraction network, a first feature extraction module, a second feature extraction module, a feature processing module and a feature classification module; wherein,

[0072] The input end of the first convolution module and the input end of the feature processing module are configured to receive the model input of the target situation analysis model; the output end of the first convolution module is connected to the input end of the first pooling module; the output end of the first pooling module is connected to the input end of the first connection module; the output end of the first connection module is connected to the input end of the feature processing module; the output end of the feature processing module is connected to the input end of the first feature extraction network; the output end of the first feature extraction network is connected to the input end of the second feature extraction network; the output end of the second feature extraction network is connected to the input end of the first feature extraction module; the output end of the first feature extraction module is connected to the output end of the second feature extraction module; the output end of the second feature extraction module is connected to the input end of the feature classification module; the output end of the feature classification module is configured to output the model output of the target situation analysis model.

[0073] It should be noted that the above-mentioned target situation analysis model extracts data feature information of the time dimension and spatial structure dimension in the cyberspace data information, and obtains the classification prediction of the network airborne situation after quantitative classification by multiple different types of activation functions and then weighted fusion, thereby realizing accurate analysis of the cyberspace situation for further accurate situation assessment in the future, which is not limited to the embodiments of the present invention.

[0074] It should be noted that the convolution kernel size of the above-mentioned first convolution module is 1×1, and the step size is 1, which is not limited in the embodiment of the present invention.

[0075] It should be noted that the above-mentioned first pooling module is constructed based on the maximum pooling layer, which is not limited in the embodiment of the present invention.

[0076] It should be noted that the above-mentioned first connection module is constructed based on the fully connected layer, which is not limited in the embodiment of the present invention.

[0077] It should be noted that the above-mentioned first feature extraction network and second feature extraction network are constructed based on graph convolutional networks to extract network space information, and then provide spatial dimension information for subsequent network space state classification analysis to improve the accuracy of classification analysis, which is not limited in the embodiments of the present invention.

[0078] It should be noted that the model architectures of the first feature extraction module and the second feature extraction module are consistent, and the embodiment of the present invention does not limit this.

[0079] It should be noted that the target situation analysis model can be implemented based on PYTHON 3.7 and above, and trained on an NVIDIA GeForce RTX 4090 graphics card. The training samples can be formed by users collecting network security intelligence data for clustering and then labeling (such as using the file analysis platform VirusTotal for analysis and labeling). During training, the sample batch size is not less than 10, the iteration round is not less than 300 times, the optimizer is Adam, and the learning rate is not more than 1×10 -4 The loss function may be a cross entropy loss function, and the trained model may be evaluated using accuracy, precision, and recall, which is not limited in the embodiment of the present invention.

[0080] It can be seen that implementing the data processing method for cyberspace situation analysis described in the embodiment of the present invention is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0081] In another optional embodiment, the first feature extraction module includes a first convolution unit, a second convolution unit, a third convolution unit, a fourth convolution unit, a first normalization unit, a second normalization unit, a first activation unit, a second activation unit, a first regularization unit, a second regularization unit, and a first fusion unit; wherein,

[0082] The input end of the first convolution unit and the input end of the third convolution unit are configured as the input end of the first feature extraction module; the output end of the first convolution unit is connected to the input end of the first normalization unit; the output end of the first normalization unit is connected to the input end of the first activation unit; the output end of the first activation unit is connected to the input end of the first regularization unit; the output end of the first regularization unit is connected to the input end of the second convolution unit; the output end of the second convolution unit is connected to the input end of the second normalization unit; the output end of the second normalization unit is connected to the input end of the second activation unit; the output end of the second activation unit is connected to the input end of the second regularization unit; the output end of the second regularization unit and the output end of the third convolution unit are both connected to the input end of the first fusion unit; the output end of the first fusion unit is connected to the input end of the fourth convolution unit; the output end of the fourth convolution unit is configured as the output end of the first feature extraction module.

[0083] It should be noted that the above-mentioned first feature extraction module extracts features of different scales on the time dimension feature information through two branches, and then uses the fourth convolution unit to filter it, so as to achieve deep and effective extraction of the time dimension feature information, which is more conducive to the subsequent accurate analysis of the cyberspace situation, and the embodiments of the present invention are not limited to this.

[0084] It should be noted that the convolution kernel size of the first convolution unit and the second convolution unit is 3×3, and the step size is 1, which is not limited in the embodiment of the present invention. The convolution kernel of the third convolution unit is 1×1, and the step size is 1, which is not limited in the embodiment of the present invention. The fourth convolution unit is constructed based on the gated linear unit GLU, which is not limited in the embodiment of the present invention.

[0085] It should be noted that the above-mentioned first normalization unit and second normalization unit are constructed based on weight normalization (WeightNormalizatio), which is not limited in the embodiment of the present invention.

[0086] It should be noted that the above-mentioned first activation unit and second activation unit are constructed based on the RELU activation function, which is not limited in the embodiment of the present invention.

[0087] It should be noted that the first regularization unit and the second regularization unit are constructed based on the regularization operation (Dropout), which is not limited in the embodiment of the present invention.

[0088] It should be noted that the above-mentioned first fusion unit is constructed based on an element-by-element addition operation, which is not limited in the embodiment of the present invention.

[0089] It can be seen that implementing the data processing method for cyberspace situation analysis described in the embodiment of the present invention is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0090] In yet another optional embodiment, the feature classification module includes a first connection unit, a third activation unit, a fourth activation unit, and a second fusion unit; wherein,

[0091] The input end of the first connection unit is configured as the input end of the feature classification module; the output end of the first connection unit is respectively connected to the input end of the third activation unit and the input end of the fourth activation unit; the output end of the third activation unit and the output end of the fourth activation unit are both connected to the input end of the second fusion unit; the output end of the second fusion unit is configured as the output end of the target situation analysis model.

[0092] It should be noted that the above-mentioned feature classification module is to classify the features extracted by the previous network modules in the target situation analysis model to provide accurate feature analysis data for further evaluation and analysis of the network airborne situation, which is not limited in the embodiment of the present invention. Further, in the feature classification module, two different types of activation modules are used to map the features to classification values ​​in different ways, and then perform weighted averaging to obtain a more reasonable and reliable classification result, which is not limited in the embodiment of the present invention.

[0093] It should be noted that the above-mentioned first connection unit is constructed based on the fully connected layer, which is not limited in the embodiment of the present invention.

[0094] It should be noted that the third activation unit is constructed based on the sigmoid activation function, which is not limited in the embodiment of the present invention.

[0095] It should be noted that the fourth activation unit is constructed based on the softmax activation function, which is not limited in the embodiment of the present invention.

[0096] It should be noted that the above-mentioned second fusion unit is constructed based on a weighted sum operation, which is not limited in the embodiment of the present invention.

[0097] It can be seen that implementing the data processing method for cyberspace situation analysis described in the embodiment of the present invention is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0098] In an optional embodiment, if Figure 6 As shown, the feature processing module includes a first sampling unit, a second sampling unit, a fifth convolution unit, a sixth convolution unit and a third fusion unit; wherein,

[0099] The input end of the first sampling unit is configured to receive the model input of the target situation analysis model, and the output end of the first sampling unit is connected to the input end of the third fusion unit; the input end of the fifth convolution unit is configured to be connected to the input end of the first connection module, and the output end of the fifth convolution unit is connected to the input end of the third fusion unit; the output end of the third fusion unit is connected to the input end of the sixth convolution unit; the output end of the sixth convolution unit is connected to the input end of the second sampling unit; the output end of the second sampling unit is configured as the output end of the feature processing module.

[0100] It should be noted that the above-mentioned feature processing module is mainly used for further dimensionality reduction and association learning of semantic features of the data to facilitate subsequent in-depth feature extraction, which is not limited in the embodiment of the present invention.

[0101] It should be noted that the first sampling unit and the second sampling unit are constructed based on the upsampling operation, which is not limited in the embodiment of the present invention.

[0102] It should be noted that the convolution kernel size of the fifth convolution unit and the sixth convolution unit is 3×3 and the step size is 1, which is not limited in the embodiment of the present invention.

[0103] It should be noted that the above-mentioned third fusion unit is constructed based on element-by-element addition operation, which is not limited in the embodiment of the present invention.

[0104] It can be seen that implementing the data processing method for cyberspace situation analysis described in the embodiment of the present invention is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0105] In another optional embodiment, preprocessing the network space information to be processed to obtain target processing network space information includes:

[0106] Matrix processing is performed on the network space information to be processed to obtain first processed network space information;

[0107] Normalizing the first processed network space information to obtain second processed network space information;

[0108] Performing dimensionality reduction processing on the second processed network space information to obtain third processed network space information;

[0109] The third network space information is subjected to information redundancy optimization processing to obtain target processing network space information.

[0110] It should be noted that the above-mentioned matrix processing of the processed cyberspace information is to perform standard quantization processing on various types of network data information (such as user comment information, announcement information, etc.) collected from the processed cyberspace information, and then take the vector formed by each type of data information as a separate category to form a multi-dimensional matrix, so as to perform more accurate and effective semantic understanding and feature extraction of the cyberspace information, which is not limited in the embodiments of the present invention.

[0111] It should be noted that the above-mentioned normalization processing of the first processed network space information is to map the elements in the matrix to numerical values ​​between 0 and 1, which is not limited in the embodiment of the present invention.

[0112] It should be noted that the dimensionality reduction processing of the second processed network space information is to convert the matrix into a one-dimensional vector, which can be implemented based on the flatten operation, and the embodiment of the present invention is not limited thereto.

[0113] It should be noted that the above-mentioned information redundancy optimization processing of the third network space information is to remove the redundant information of the third processed network space information, so as to input the redundant information into the target situation analysis model, thereby improving the processing efficiency of the model, which is not limited in the embodiment of the present invention. Further, the above-mentioned information redundancy optimization processing can be a whitening processing of the data, which is not limited in the embodiment of the present invention.

[0114] It can be seen that implementing the data processing method for cyberspace situation analysis described in the embodiment of the present invention is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0115] Embodiment 2

[0116] See also Figure 3 , Figure 3 1 is a schematic diagram of a data processing device for cyberspace situation analysis disclosed in an embodiment of the present invention. Figure 3 The described device can be applied to a management system, such as a local server or a cloud server for management, etc., which is not limited in the embodiments of the present invention. Figure 3 As shown, the device may include:

[0117] An acquisition module 201 is used to acquire network space information to be processed;

[0118] The first processing module 202 is used to pre-process the network space information to be processed to obtain target processing network space information;

[0119] The second processing module 203 is used to analyze and process the target network space information to obtain target network situation analysis result information.

[0120] It can be seen that implementation Figure 3 The described data processing device for cyberspace situation analysis is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0121] In another optional embodiment, Figure 3 As shown, the target network space information is analyzed and processed to obtain the target network situation analysis result information, including:

[0122] Using the target situation analysis model to perform feature analysis on the target processing network space information to obtain first network space analysis result information;

[0123] The first network space analysis result information is judged, analyzed and processed to obtain the target network situation analysis result information.

[0124] It can be seen that implementation Figure 3 The described data processing device for cyberspace situation analysis is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0125] In yet another optional embodiment, Figure 3 As shown, the target situation analysis model includes a first convolution module, a first pooling module, a first connection module, a first feature extraction network, a second feature extraction network, a first feature extraction module, a second feature extraction module, a feature processing module and a feature classification module; wherein,

[0126] The input end of the first convolution module and the input end of the feature processing module are configured to receive the model input of the target situation analysis model; the output end of the first convolution module is connected to the input end of the first pooling module; the output end of the first pooling module is connected to the input end of the first connection module; the output end of the first connection module is connected to the input end of the feature processing module; the output end of the feature processing module is connected to the input end of the first feature extraction network; the output end of the first feature extraction network is connected to the input end of the second feature extraction network; the output end of the second feature extraction network is connected to the input end of the first feature extraction module; the output end of the first feature extraction module is connected to the output end of the second feature extraction module; the output end of the second feature extraction module is connected to the input end of the feature classification module; the output end of the feature classification module is configured to output the model output of the target situation analysis model.

[0127] It can be seen that implementation Figure 3 The described data processing device for cyberspace situation analysis is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0128] In yet another optional embodiment, Figure 3As shown, the first feature extraction module includes a first convolution unit, a second convolution unit, a third convolution unit, a fourth convolution unit, a first normalization unit, a second normalization unit, a first activation unit, a second activation unit, a first regularization unit, a second regularization unit, and a first fusion unit; wherein,

[0129] The input end of the first convolution unit and the input end of the third convolution unit are configured as the input end of the first feature extraction module; the output end of the first convolution unit is connected to the input end of the first normalization unit; the output end of the first normalization unit is connected to the input end of the first activation unit; the output end of the first activation unit is connected to the input end of the first regularization unit; the output end of the first regularization unit is connected to the input end of the second convolution unit; the output end of the second convolution unit is connected to the input end of the second normalization unit; the output end of the second normalization unit is connected to the input end of the second activation unit; the output end of the second activation unit is connected to the input end of the second regularization unit; the output end of the second regularization unit and the output end of the third convolution unit are both connected to the input end of the first fusion unit; the output end of the first fusion unit is connected to the input end of the fourth convolution unit; the output end of the fourth convolution unit is configured as the output end of the first feature extraction module.

[0130] It can be seen that implementation Figure 3 The described data processing device for cyberspace situation analysis is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0131] In yet another optional embodiment, Figure 3 As shown, the feature classification module includes a first connection unit, a third activation unit, a fourth activation unit and a second fusion unit; wherein,

[0132] The input end of the first connection unit is configured as the input end of the feature classification module; the output end of the first connection unit is respectively connected to the input end of the third activation unit and the input end of the fourth activation unit; the output end of the third activation unit and the output end of the fourth activation unit are both connected to the input end of the second fusion unit; the output end of the second fusion unit is configured as the output end of the target situation analysis model.

[0133] It can be seen that implementation Figure 3 The described data processing device for cyberspace situation analysis is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0134] In yet another optional embodiment, Figure 3 As shown, the feature processing module includes a first sampling unit, a second sampling unit, a fifth convolution unit, a sixth convolution unit and a third fusion unit; wherein,

[0135] The input end of the first sampling unit is configured to receive the model input of the target situation analysis model, and the output end of the first sampling unit is connected to the input end of the third fusion unit; the input end of the fifth convolution unit is configured to be connected to the input end of the first connection module, and the output end of the fifth convolution unit is connected to the input end of the third fusion unit; the output end of the third fusion unit is connected to the input end of the sixth convolution unit; the output end of the sixth convolution unit is connected to the input end of the second sampling unit; the output end of the second sampling unit is configured as the output end of the feature processing module.

[0136] It can be seen that implementation Figure 3 The described data processing device for cyberspace situation analysis is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0137] In yet another optional embodiment, Figure 3 As shown, the network space information to be processed is preprocessed to obtain the target processing network space information, including:

[0138] Matrix processing is performed on the network space information to be processed to obtain first processed network space information;

[0139] Normalizing the first processed network space information to obtain second processed network space information;

[0140] Performing dimensionality reduction processing on the second processed network space information to obtain third processed network space information;

[0141] The third network space information is subjected to information redundancy optimization processing to obtain target processing network space information.

[0142] It can be seen that implementation Figure 3 The described data processing device for cyberspace situation analysis is conducive to improving the accuracy and efficiency of cyberspace situation analysis, thereby providing support for ensuring cyberspace security.

[0143] Embodiment 3

[0144] See also Figure 4 , Figure 4 : is a structural diagram of another data processing device for cyberspace situation analysis disclosed in an embodiment of the present invention. Figure 4 The described device can be applied to a management system, such as a local server or a cloud server for management, etc., which is not limited in the embodiments of the present invention. Figure 4 As shown, the device may include:

[0145] A memory 301 storing executable program codes;

[0146] a processor 302 coupled to the memory 301;

[0147] The processor 302 calls the executable program code stored in the memory 301 to execute the steps in the data processing method for cyberspace situation analysis described in the first embodiment.

[0148] Embodiment 4

[0149] An embodiment of the present invention discloses a computer-readable storage medium, which stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute the steps of the data processing method for cyberspace situation analysis described in Embodiment 1.

[0150] Embodiment 5

[0151] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps in the data processing method for cyberspace situation analysis described in Example 1.

[0152] The device embodiments described above are only illustrative, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, i.e., they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Those of ordinary skill in the art may understand and implement it without creative work.

[0153] Through the specific description of the above embodiments, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution can be essentially or partly contributed to the prior art in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, and the storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electronically erasable rewritable read-only memory (EEPROM), a compact disc (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.

[0154] Finally, it should be noted that the data processing method and device for cyberspace situation analysis disclosed in the embodiments of the present invention only disclose the preferred embodiments of the present invention, which are only used to illustrate the technical solution of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments can still be modified, or some of the technical features can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data processing method for cyberspace situation analysis, characterized in that: The method comprises: Obtaining the cyberspace information to be processed; Preprocessing the to-be-processed network space information to obtain target processed network space information; The target processing network space information is analyzed and processed to obtain target network situation analysis result information.

2. The data processing method for cyberspace situation analysis according to claim 1, characterized in that: The analyzing and processing the target processing network space information to obtain target network situation analysis result information includes: Using the target situation analysis model to perform feature analysis on the target processing network space information to obtain first network space analysis result information; The first network space analysis result information is judged and analyzed to obtain the target network situation analysis result information.

3. The data processing method for cyberspace situation analysis according to claim 2 is characterized in that: The target situation analysis model includes a first convolution module, a first pooling module, a first connection module, a first feature extraction network, a second feature extraction network, a first feature extraction module, a second feature extraction module, a feature processing module and a feature classification module; wherein, The input end of the first convolution module and the input end of the feature processing module are configured to receive the model input of the target situation analysis model; the output end of the first convolution module is connected to the input end of the first pooling module; the output end of the first pooling module is connected to the input end of the first connection module; the output end of the first connection module is connected to the input end of the feature processing module; the output end of the feature processing module is connected to the input end of the first feature extraction network; the output end of the first feature extraction network is connected to the input end of the second feature extraction network; the output end of the second feature extraction network is connected to the input end of the first feature extraction module; the output end of the first feature extraction module is connected to the output end of the second feature extraction module; the output end of the second feature extraction module is connected to the input end of the feature classification module; the output end of the feature classification module is configured to output the model output of the target situation analysis model.

4. The data processing method for cyberspace situation analysis according to claim 3 is characterized in that: The first feature extraction module includes a first convolution unit, a second convolution unit, a third convolution unit, a fourth convolution unit, a first normalization unit, a second normalization unit, a first activation unit, a second activation unit, a first regularization unit, a second regularization unit, and a first fusion unit; wherein, The input end of the first convolution unit and the input end of the third convolution unit are configured as the input end of the first feature extraction module; the output end of the first convolution unit is connected to the input end of the first normalization unit; the output end of the first normalization unit is connected to the input end of the first activation unit; the output end of the first activation unit is connected to the input end of the first regularization unit; the output end of the first regularization unit is connected to the input end of the second convolution unit; the output end of the second convolution unit is connected to the input end of the second normalization unit; the output end of the second normalization unit is connected to the input end of the second activation unit; the output end of the second activation unit is connected to the input end of the second regularization unit; the output end of the second regularization unit and the output end of the third convolution unit are both connected to the input end of the first fusion unit; the output end of the first fusion unit is connected to the input end of the fourth convolution unit; the output end of the fourth convolution unit is configured as the output end of the first feature extraction module.

5. The data processing method for cyberspace situation analysis according to claim 3 is characterized in that: The feature classification module includes a first connection unit, a third activation unit, a fourth activation unit and a second fusion unit; wherein, The input end of the first connection unit is configured as the input end of the feature classification module; the output end of the first connection unit is respectively connected to the input end of the third activation unit and the input end of the fourth activation unit; the output end of the third activation unit and the output end of the fourth activation unit are both connected to the input end of the second fusion unit; the output end of the second fusion unit is configured as the output end of the target situation analysis model.

6. The data processing method for cyberspace situation analysis according to claim 3 is characterized in that: The feature processing module includes a first sampling unit, a second sampling unit, a fifth convolution unit, a sixth convolution unit and a third fusion unit; wherein, The input end of the first sampling unit is configured to receive the model input of the target situation analysis model, and the output end of the first sampling unit is connected to the input end of the third fusion unit; the input end of the fifth convolution unit is configured to be connected to the input end of the first connection module, and the output end of the fifth convolution unit is connected to the input end of the third fusion unit; the output end of the third fusion unit is connected to the input end of the sixth convolution unit; the output end of the sixth convolution unit is connected to the input end of the second sampling unit; the output end of the second sampling unit is configured as the output end of the feature processing module.

7. The data processing method for cyberspace situation analysis according to claim 1 is characterized in that: The preprocessing of the to-be-processed network space information to obtain target processed network space information includes: Performing matrix processing on the network space information to be processed to obtain first processed network space information; Normalizing the first processed network space information to obtain second processed network space information; Performing dimensionality reduction processing on the second processed network space information to obtain third processed network space information; The third network space information is subjected to information redundancy optimization processing to obtain target processing network space information.

8. A data processing device for cyberspace situation analysis, characterized in that: The device comprises: An acquisition module, used to acquire the network space information to be processed; A first processing module is used to pre-process the network space information to be processed to obtain target processing network space information; The second processing module is used to analyze and process the target network space information to obtain target network situation analysis result information.

9. A data processing device for cyberspace situation analysis, characterized in that: The device comprises: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the data processing method for cyberspace situation analysis as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, which, when called, are used to execute the data processing method for cyberspace situation analysis as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and device for generating cloud and mist shielding image

    CN118799428A

  • Network security situation assessment method and device, medium and product

    CN119051899A