Risk assessment method and system based on network security situation awareness

Through a risk assessment method based on network security situation awareness, the network data binary classification model is used to process network activity information and security event records, and the problem of insufficient real-time and accurate risk assessment in the existing technology is solved, achieving more efficient and accurate network security risk monitoring and early warning.

CN120068089AInactive Publication Date: 2025-05-30DALIAN VOCATIONAL & TECHNICAL COLLEGE (DALIAN OPEN UNIVERSITY)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510148597.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing network security risk assessment methods lack real-time and accuracy, making it difficult to effectively handle huge and complex network activity information and security event records, and lack adaptive optimization mechanisms.

Method used

A risk assessment method based on network security situation awareness is adopted. By obtaining network activity information and security event records, a binary classification model of network data is established, data extraction and classification is carried out, network activity information of potential risks is selected, risk prediction values ​​are calculated, risk reports are generated, and optimization mechanism is triggered when the accuracy test fails.

Benefits of technology

It realizes more accurate risk screening and early warning, reduces false alarms and underreports, can dynamically evaluate and update network risk status, improves the accuracy and efficiency of risk assessment, and reduces the burden on network managers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068089A_ABST
    Figure CN120068089A_ABST
Patent Text Reader

Abstract

The invention discloses a risk assessment method and system based on network security situation awareness, and relates to the technical field of network risk assessment, and the method comprises the steps: obtaining network activity information and security event records in a network; obtaining a network data dichotomy model according to the security event record; classifying the network activity information through a network data dichotomy model, and screening out one type of network activity information; through analysis of one type of network activity information, a risk prediction value of each network activity in the network is obtained, a security risk event existing in the network is identified, then the comprehensive risk state of the network is evaluated, and a network security situation awareness risk report is output. And carrying out accuracy check on the network security situation awareness risk report, and triggering a network security situation awareness risk assessment optimization mechanism when an accuracy check result is unqualified. Automatic and intelligent risk assessment based on situation awareness is realized, so that the efficiency and accuracy of network security protection are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network risk assessment, and specifically to a risk assessment method and system based on network security situation awareness. Background Art

[0002] With the rapid development of network technology and the increasing severity of network security threats, the research on network security situation awareness technology has received more and more attention. Network security situation awareness aims to collect, analyze, and evaluate various types of information in the network, grasp the security status of the network in real time, predict and warn potential security risks, and help decision-makers make scientific and reasonable countermeasures.

[0003] However, many current network security risk assessment methods face the following challenges: the data volume is huge and complex, the data volume of network activity information and security event records is extremely large, and traditional assessment methods are difficult to process this data in real time; the assessment accuracy is insufficient, traditional rule-based assessment methods often cannot adapt to the complex and changeable network environment, resulting in low accuracy and reliability of the assessment results; there is a lack of an adaptive optimization mechanism, and existing methods usually require manual adjustment and optimization and cannot automatically adjust algorithms and strategies according to the assessment accuracy.

[0004] Therefore, in view of the above problems, there is an urgent need for a risk assessment method and system based on network security situation awareness. Summary of the Invention

[0005] Aiming at the deficiencies of the prior art, the present invention provides a risk assessment method and system based on network security situation awareness, which solves the problems of lack of real-time performance and accuracy in network security risk assessment, and the extremely large data volume of network activity information and security event records.

[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: A risk assessment method based on network security situation awareness includes the following steps: obtaining network activity information and security event records in the network based on network devices and monitoring tools; extracting data from the security event records to obtain security event record data, and then using the security event record data as input to obtain a network data binary classification model; classifying the network activity information according to the network data binary classification model, and screening out a category of network activity information; analyzing the category of network activity information to obtain the risk prediction value of each network activity in the network, and then marking the security risk events existing in the network; evaluating the comprehensive risk status of the network based on the risk prediction values of each marked security risk event in the network, and then outputting a network security situation awareness risk report; performing an accuracy test on the network security situation awareness risk report, and when the accuracy test result is unqualified, triggering a network security situation awareness risk assessment optimization mechanism.

[0007] Furthermore, data extraction is performed on the security event records to obtain security event record data. Then, using the security event record data as input, the specific analysis of the network data binary classification model is as follows: Obtain the security event records, perform data extraction on the security event records to obtain security event record data, where the security event record data includes the exact security risk event data and the misjudged security risk event data recorded; the exact security risk event data recorded specifically includes the sampling rate of the exact security risk event data, the missing value ratio of the exact security risk event data, the accuracy of the exact security risk event data, and the correlation of the exact security risk event data; the misjudged security risk event data recorded specifically includes the sampling rate of the misjudged security risk event data, the missing value ratio of the misjudged security risk event data, the accuracy of the misjudged security risk event data, and the correlation of the misjudged security risk event data; Use Logistic regression as the model basis of the network data binary classification model. Then, respectively use the exact security risk event data and the misjudged security risk event data recorded as the input of the network data binary classification model to obtain the output results of the network data binary classification model for the exact security risk event data and the misjudged security risk event data recorded. Set the classification threshold of the network data binary classification model based on the output results of the network data binary classification model for the exact security risk event data and the misjudged security risk event data recorded.

[0008] Furthermore, the specific analysis of setting the classification threshold of the network data binary classification model based on the output results of the network data binary classification model for the exact security risk event data and the misjudged security risk event data recorded is as follows: Combine the output results of the network data binary classification model for the exact security risk event data and the misjudged security risk event data recorded into an output probability sample; Randomly generate data within the range of 0 to 1 as the traversal threshold, and compare the output probability sample respectively according to different traversal thresholds. Then, output the comparison results and combine the comparison results into a confusion matrix; Based on the different confusion matrices obtained by comparing with different traversal thresholds, respectively obtain the accuracy and recall rate corresponding to different traversal thresholds, and obtain the harmonic mean of the accuracy and recall rate; Compare the sizes of the harmonic means of the accuracy and recall rate corresponding to different traversal thresholds, and mark the traversal threshold corresponding to the maximum harmonic mean of the accuracy and recall rate as the classification threshold of the network data binary classification model.

[0009] Further, the network activity information is classified according to the network data binary classification model. The specific analysis of screening out a certain type of network activity information is as follows: obtaining the quality evaluation parameters of the network activity information, where the quality evaluation parameters of the network activity information specifically include the sampling rate of the network activity information, the proportion of missing values of the network activity information, the accuracy of the network activity information, and the relevance of the network activity information; using the quality evaluation parameters of the network activity information as the input of the network data binary classification model, and outputting the output result of the network data binary classification model for the network activity information, where the output result of the network data binary classification model for the network activity information is specifically the quality reliability probability of the network activity information; comparing the output result of the network data binary classification model for the network activity information with the classification threshold of the network data binary classification model, screening out the network activity information whose output result of the network data binary classification model is less than or equal to the classification threshold of the network data binary classification model, retaining the network activity information whose output result of the network data binary classification model is greater than the classification threshold of the network data binary classification model, and marking it as a certain type of network activity information.

[0010] Further, through the analysis of a certain type of network activity information, the risk prediction value of each network activity in the network is obtained, and then the specific analysis of marking the security risk events existing in the network is as follows: extracting a certain type of network activity characteristics based on the certain type of network activity information; obtaining the certain type of network activity characteristics within the preset time window, and then respectively obtaining the mean value and standard deviation of each certain type of network activity characteristic; comprehensively calculating each certain type of network activity characteristic and the mean value and standard deviation of the corresponding characteristic to obtain the risk prediction value of each network activity; respectively comparing the risk prediction value of each network activity with the preset risk threshold, and when the risk prediction value exceeds the preset risk threshold, marking the network activity as a security risk event, that is, there is a security risk in the network.

[0011] Further, based on the risk prediction values of each marked security risk event in the network, the comprehensive risk status of the network is evaluated, and then the specific analysis of outputting the network security situation awareness risk report is as follows: identifying each marked security risk event and obtaining the risk prediction value corresponding to each security risk event, and then marking the mean value of the risk prediction values corresponding to each security risk event as the network comprehensive risk assessment value, where the network comprehensive risk assessment value is used to quantify the comprehensive risk degree of the network; recording each marked security risk event in the network and the network comprehensive risk assessment value in the network security situation awareness risk report, and then transmitting the network security situation awareness risk report to the network security officer for risk warning.

[0012] Furthermore, for the accuracy test of the network security situation awareness risk report, when the accuracy test result is unqualified, the specific analysis for triggering the network security situation awareness risk assessment optimization mechanism is as follows: obtain the actual test records in real time after the network security officer receives the network security situation awareness risk report. The actual test records are specifically the actual test results of each security risk event marked in the network. The actual test results include that the event is actually tested as a security risk event and the event is actually tested not to be a security risk event. When there is a test result in the actual test records that the event is actually tested not to be a security risk event, trigger the network security situation awareness risk assessment optimization mechanism. The specific optimization method of the network security situation awareness risk assessment optimization mechanism is: update the network activity information and security event records in the network, and update the network data binary classification model and the classification threshold of the network data binary classification model based on the updated network activity information and security event records.

[0013] A risk assessment system based on network security situation awareness, which applies the above-mentioned risk assessment method based on network security situation awareness, includes: a data acquisition module for acquiring network activity information and security event records in the network based on network devices and monitoring tools; a network data binary classification model construction module for extracting data from the security event records to obtain security event record data, and then using the security event record data as input to obtain a network data binary classification model; a data screening module for classifying the network activity information according to the network data binary classification model and screening out a category of network activity information; a security risk identification module for analyzing through a category of network activity information to obtain the risk prediction value of each network activity in the network, and then marking the security risk events existing in the network; a comprehensive risk assessment module for evaluating the comprehensive risk status of the network based on the risk prediction values of each threat in the network, and then outputting a network security situation awareness risk report; an optimization and update module for performing an accuracy test on the network security situation awareness risk report, and triggering the network security situation awareness risk assessment optimization mechanism when the accuracy test result is unqualified.

[0014] The present invention has the following beneficial effects:

[0015] The risk assessment method and system based on network security situation awareness can, through classification analysis based on a network data binary classification model, more accurately screen out network activity information with potential risks, provide targeted early warnings for network security incidents, and reduce the possibility of false alarms and missed reports; through comprehensive risk assessment of network activities, it can comprehensively understand the security status of the network, timely discover potential security threats, and help network managers take effective countermeasures; based on the network activity information collected in real time in the network, it can dynamically evaluate and update the risk status of the network to ensure that network security risks can be monitored and evaluated at any time; when the accuracy of risk assessment is insufficient, an optimization mechanism is automatically triggered to further improve the accuracy and effectiveness of risk assessment; the automated risk assessment process reduces the need for manual intervention and improves efficiency. Especially in the face of a large-scale complex network environment, it can greatly reduce the burden on network managers. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a flowchart of a risk assessment method based on network security situation awareness according to the present invention.

[0017] Figure 2 It is a structural diagram of a risk assessment system based on network security situation awareness according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] In the embodiments of the present application, through a risk assessment method and system based on network security situation awareness, automated and intelligent risk assessment based on situation awareness is realized, thereby greatly improving the efficiency and accuracy of network security protection.

[0019] The general idea of the embodiments of the present application is as follows:

[0020] By combining network security situation awareness with risk assessment methods, based on the network activity information and security event records collected by network devices and monitoring tools, a data model is established to analyze and classify security risks in the network.

[0021] Please refer to Figure 1, an embodiment of the present invention provides a technical solution: a risk assessment method based on network security situation awareness, including the following steps: obtaining network activity information and security event records in the network based on network devices and monitoring tools; extracting data from the security event records to obtain security event record data, and then using the security event record data as input to obtain a network data binary classification model; classifying the network activity information according to the network data binary classification model, and screening out a class of network activity information; analyzing the class of network activity information to obtain the risk prediction value of each network activity in the network, and then marking the security risk events existing in the network; evaluating the comprehensive risk status of the network based on the risk prediction values of the marked security risk events in the network, and then outputting a network security situation awareness risk report; performing an accuracy test on the network security situation awareness risk report, and triggering a network security situation awareness risk assessment optimization mechanism when the accuracy test result is unqualified.

[0022] Specifically, the specific analysis of extracting data from the security event records to obtain security event record data and then using the security event record data as input to obtain a network data binary classification model is as follows: obtaining the security event records, extracting data from the security event records to obtain security event record data, and the security event record data includes the exact security risk event data recorded and the misjudged security risk event data recorded; the exact security risk event data recorded specifically includes the sampling rate of the exact security risk event data, the missing value ratio of the exact security risk event data, the accuracy of the exact security risk event data, and the relevance of the exact security risk event data; the misjudged security risk event data recorded specifically includes the sampling rate of the misjudged security risk event data, the missing value ratio of the misjudged security risk event data, the accuracy of the misjudged security risk event data, and the relevance of the misjudged security risk event data; using Logistic regression as the model basis of the network data binary classification model, and then respectively using the exact security risk event data recorded and the misjudged security risk event data recorded as the input of the network data binary classification model to obtain the output results of the network data binary classification model for the exact security risk event data recorded and the misjudged security risk event data recorded, and setting the classification threshold of the network data binary classification model according to the output results of the network data binary classification model for the exact security risk event data recorded and the misjudged security risk event data recorded. A specific example of the network data binary classification model expression is:

[0023] In the formula, P(y = 1) represents the probability that the network activity information is reliable data, b 1 represents the sampling rate, b 2 represents the missing value ratio, b 3 represents the accuracy, b 4 represents the relevance, β 0 、β1 , β 2 , β 3 , β 4 represent the regression coefficients respectively, which are obtained through model training using the training set data, and the maximum likelihood estimation (MLE) or other optimization algorithms (such as gradient descent) are used to estimate the most appropriate regression coefficients.

[0024] In this implementation plan, the sampling rate represents the proportion of samples extracted from the overall data, which is determined by the sampling mechanism in the data collection process; the missing value proportion represents the proportion of the missing part in the data to the overall data, which is obtained through statistical methods in the data cleaning process; the precision represents the accuracy of the data, which is calculated by comparing the true labels and predicted labels of the data; the correlation represents the mutual relationship between events, which is calculated through correlation analysis (such as Pearson correlation coefficient).

[0025] The specific analysis of setting the classification threshold of the network data binary classification model based on the output results of the network data binary classification model for the recorded exact security risk event data and the recorded misjudged security risk event data is as follows: combine the output results of the network data binary classification model for the recorded exact security risk event data and the recorded misjudged security risk event data into an output probability sample; randomly generate data with a value range between 0 and 1 as the traversal threshold, and compare the output probability sample according to different traversal thresholds respectively, and then output the comparison results, and combine the comparison results into a confusion matrix; according to the different confusion matrices obtained by comparing different traversal thresholds, obtain the precision and recall corresponding to different traversal thresholds respectively, and obtain the harmonic mean of the precision and recall; compare the sizes of the harmonic means of the precision and recall corresponding to different traversal thresholds, and mark the traversal threshold corresponding to the maximum harmonic mean of the precision and recall as the classification threshold of the network data binary classification model.

[0026] The classification threshold is a key parameter that determines the output category of the model, and is used to divide the probability value output by the model into different categories. For example, when the output probability P(y = 1) is greater than a certain threshold, the network activity information is determined as "reliable data", otherwise it is "unreliable data". The confusion matrix specifically represents a matrix used to evaluate the classification performance of the model, recording the comparison between the true label and the predicted label, including: true positive (TP), the number of samples that record the exact security risk event data and are determined as reliable data according to the comparison with the candidate threshold; false negative (FN), the number of samples that record the exact security risk event data and are determined as unreliable data according to the comparison with the candidate threshold; false positive (FP), the number of samples that record the misjudged security risk event data and are determined as reliable data according to the comparison with the candidate threshold; true negative (TN), the number of samples that record the misjudged security risk event data and are determined as unreliable data according to the comparison with the candidate threshold. Compare the prediction results of all samples according to different thresholds to generate a confusion matrix.

[0027] Precision is used to measure the accuracy of the model when predicting reliable data, which is calculated from true positives and false positives in the confusion matrix. The calculation formula is: P recision represents precision.

[0028] Recall is used to measure the model's ability to identify reliable data, which is calculated from true positives and false negatives in the confusion matrix. The calculation formula is: R ecall represents recall.

[0029] The harmonic mean (F1-Score) is used to comprehensively evaluate the classification effect of the model, which is obtained by calculating the harmonic mean of precision and recall. The calculation formula is: F1 represents the harmonic mean.

[0030] Based on the network data binary classification model, the network activity information is classified. The specific analysis of screening out a certain type of network activity information is as follows: Obtain the quality evaluation parameters of the network activity information. The quality evaluation parameters of the network activity information specifically include the sampling rate of the network activity information, the proportion of missing values of the network activity information, the precision of the network activity information, and the relevance of the network activity information; Use the quality evaluation parameters of the network activity information as the input of the network data binary classification model, and the output result of the network data binary classification model for the network activity information is obtained. The output result of the network data binary classification model for the network activity information is specifically the quality reliability probability of the network activity information; Compare the output result of the network data binary classification model for the network activity information with the classification threshold of the network data binary classification model, screen out the network activity information whose output result of the network data binary classification model is less than or equal to the classification threshold of the network data binary classification model, retain the network activity information whose output result of the network data binary classification model is greater than the classification threshold of the network data binary classification model, and mark it as a certain type of network activity information.

[0031] Through the binary classification model processing of security event records and network activity information, the real security risk events and misjudgment events can be effectively distinguished, thereby improving the ability to identify potential network security threats, helping to reduce false alarms and missed reports, and enhancing the overall efficiency of the protection system; Using the classification threshold to adjust the precision and recall of the model can find a balance point in actual applications, so as to improve the accuracy and enhance the sensitivity to potential threats when classifying network activity information; By evaluating the quality of network activity information, low-quality data can be filtered out to ensure that the data input into the model has high quality, further improving the classification effect; Using Logistic regression as the basis of the binary classification model is a widely used statistical learning model with strong interpretability, which is convenient for understanding and optimization.

[0032] Specifically, through the analysis of a type of network activity information, the risk prediction values of each network activity in the network are obtained, and the specific analysis of marking the security risk events existing in the network is as follows: extracting a type of network activity characteristics based on a type of network activity information; obtaining the type of network activity characteristics within a preset time window, and then respectively obtaining the mean and standard deviation of each type of network activity characteristic; calculating by integrating each type of network activity characteristic and the mean and standard deviation of the corresponding characteristic to obtain the risk prediction value of each network activity; respectively comparing the risk prediction value of each network activity with a preset risk threshold, and when the risk prediction value exceeds the preset risk threshold, marking the network activity as a security risk event, that is, there is a security risk in the network.

[0033] In this implementation plan, the network activity characteristics are numerical characteristics used to describe the attributes of network activities, such as network traffic, request frequency, duration, packet size, communication protocol, etc., which are extracted from network traffic data, such as capturing packets through traffic analysis tools (such as Wireshark, NetFlow) and calculating relevant characteristics; the mean represents the average value of a certain characteristic of this type of network activity within a preset time window, and is used to describe the common value of this characteristic; the standard deviation represents the degree of dispersion of a certain characteristic of this type of network activity, measuring the degree of deviation of the data from the mean. The larger the standard deviation, the greater the volatility of this characteristic and the higher the risk possibility; the specific risk prediction value is used to predict whether there is a security risk in this activity, and the specific formula is: In this formula, Risk represents the risk prediction value, i represents the network activity characteristic number, N represents the total number of network activity characteristics, and the network activity characteristics include but are not limited to network traffic, request frequency, duration, packet size, κ i represents the weight value of the i-th network activity characteristic, X i represents the value of the i-th network activity characteristic, μ i represents the mean within the time window of the i-th network activity characteristic, σ i represents the standard deviation within the time window of the i-th network activity characteristic. The setting method of the weight values of each network activity characteristic is as follows: judging which characteristics are more important according to the experience of network security domain experts and giving higher weight values, or evaluating the importance of characteristics through statistical learning methods (such as decision trees, random forests, gradient boosting trees, etc.), and the weight can also be determined by analyzing the correlation between each characteristic and the risk prediction value. Characteristics with stronger correlation can be given higher weights, and through the training of historical data, it is also possible to optimize the characteristic weights through algorithms such as weighted least squares method and ridge regression.

[0034] The following aspects need to be considered when presetting the time window: Time characteristics of network activities: If real-time monitoring of network traffic and events is required, a shorter time window (e.g., from a few minutes to a few hours) can be selected to promptly detect potential risks. If historical data analysis is performed, a longer time window (e.g., a few days or weeks) can be set to capture the long-term trend of network activity changes; Frequency of event occurrence: If risk events in network activities occur relatively frequently, a shorter time window may be more effective. If risk events are relatively rare, a longer time window can be considered to capture more behavior patterns; Trend analysis of past data: By analyzing past network activity data and observing the patterns of event occurrence (e.g., some network activities may be periodic or regular), a time window that conforms to these patterns can be selected. For example, if network attack events usually occur within a specific time period, a window related to the attack time can be chosen. In practical applications, dynamic adjustment of the time window can also be considered. For instance, according to the changes in network activities, the size of the time window can be adjusted in real time. If network activities are extremely intense, the window length can be appropriately shortened to increase the detection sensitivity; if network activities are relatively stable, the time window can be appropriately extended.

[0035] The risk threshold is the boundary used to distinguish between safe activities and potentially risky activities. When the risk prediction value of network activities exceeds this threshold, it indicates that the activity has potential security risks. The setting of the risk threshold is based on historical data analysis or empirical rules. The specific setting methods are as follows: Set a fixed threshold based on historical data or the experience of domain experts. For example, it is considered that there is a security risk when the risk prediction value exceeds 10; or set a certain percentile as the threshold according to the historical data distribution of network activities. For example, select the upper 90% of the prediction values as the threshold; it is also possible to dynamically adjust the risk threshold based on the real-time monitoring of network activities, and automatically adjust the threshold according to different network environments through learning algorithms (such as machine learning models).

[0036] By calculating the risk prediction value of network activities and comparing it with the preset threshold, possible security risk events can be automatically marked, reducing the workload of manual monitoring and analysis and improving efficiency; By analyzing the mean and standard deviation of network activity characteristics, designs can be made to capture abnormal changes in network behavior and evaluate risks through statistical models, making risk prediction more accurate; Adjust the analysis strategy based on different time windows and the specific characteristics of network activities to cope with the dynamic changes in network activity patterns; By comparing the risk prediction value with the threshold, potential security risks can be promptly warned, which helps to take preventive measures in advance and reduce the occurrence probability of potential security events.

[0037] Specifically, the specific analysis of evaluating the comprehensive risk status of the network based on the risk prediction values of each marked security risk event in the network and then outputting the network security situation awareness risk report is as follows: identify each marked security risk event and obtain the corresponding risk prediction value for each security risk event. Then, mark the mean value of the risk prediction values corresponding to each security risk event as the network comprehensive risk assessment value, and the network comprehensive risk assessment value is used to quantify the comprehensive risk degree of the network; record each marked security risk event in the network and the network comprehensive risk assessment value in the network security situation awareness risk report, and then transmit the network security situation awareness risk report to the network security officer for risk warning. The network security situation awareness risk report is specifically a report generated based on means such as network traffic analysis and log monitoring, used to present possible network security risk events, automatically generated by a network security monitoring tool or system, based on real-time network activity information and security events.

[0038] In this implementation plan, by identifying each marked security risk event and obtaining the corresponding risk prediction value, various possible security risks in the network can be systematically identified; the calculation of the risk prediction value can help quantify the severity of each risk event, making the evaluation of network security more scientific and accurate; the network comprehensive risk assessment value quantifies the security risk degree of the entire network by calculating the mean value of each risk event, providing a clear assessment of the overall security situation; by clarifying the network comprehensive risk assessment value, managers can more clearly understand the current security state of the network; the quantified risk assessment result can provide valuable decision-making support for security personnel, helping them take protective measures in a timely manner, optimize resource allocation, and avoid or mitigate potential security threats; recording and transmitting each security event and its risk prediction value to the network security officer can issue a warning to the security officer in advance, prompting them to take corresponding preventive measures before the problem occurs; timely risk warning can reduce potential security vulnerabilities and the probability of the network being attacked, thereby enhancing the overall network protection ability; through the automated situation awareness report, the security officer can quickly obtain the security status of the network, avoiding manual analysis and cumbersome processing procedures, and enhancing the response speed; the regularly updated risk report can also help security personnel understand the change trend of the network security state and further optimize the network protection strategy.

[0039] Specifically, for the accuracy verification of the network security situation awareness risk report, when the accuracy verification result is unqualified, the specific analysis for triggering the network security situation awareness risk assessment optimization mechanism is as follows: Obtain the actual verification records in real time after the network security officer receives the network security situation awareness risk report. The actual verification records are specifically the actual verification results of each security risk event marked in the network. The actual verification results include that the event is actually verified as a security risk event and the event is actually verified not to be a security risk event. When there is a verification result in the actual verification records that the event is actually verified not to be a security risk event, the network security situation awareness risk assessment optimization mechanism is triggered. The specific optimization method of the network security situation awareness risk assessment optimization mechanism is: Update the network activity information and security event records in the network, and update the network data binary classification model and the classification threshold of the network data binary classification model based on the updated network activity information and security event records.

[0040] In this implementation plan, the actual verification record refers to the actual verification record made by the network security officer for the security risk events marked in the network security situation awareness report, indicating which events are confirmed as security risks and which events are confirmed not to be. It is judged and recorded by the network security officer according to the actual situation, based on the actual detection results and the risk verification process. The actual verification results include the verification results of "security risk events" and "non-security risk events", and are analyzed by security experts according to the actual network activities or log data to judge whether an event belongs to a security risk.

[0041] By verifying the accuracy of the network security situation awareness risk report, it can ensure that the network security detection system can more accurately identify and judge potential security risk events, reduce false alarms and missed reports, and enhance the network defense ability. When it is found that some detection results are inaccurate, the optimization mechanism can adjust the model in real time to enhance the system's adaptability to emerging threats. As network activities and security events are constantly changing, the old network security assessment models may not be able to effectively cope with new threats. By introducing an optimization mechanism based on actual verification records, the network security situation awareness system can be continuously updated and optimized to maintain a high detection accuracy and be able to cope with changing security threats. By updating the real-time verification records and security events, it helps to more accurately predict and classify network risks through big data analysis and machine learning, dynamically update the network data binary classification model and its classification threshold, so that the model can adapt to different security environments and threat situations, thereby improving the ability to identify new types of attacks.

[0042] Please refer to Figure 2, A risk assessment system based on network security situation awareness, which applies the above-mentioned risk assessment method based on network security situation awareness, includes: a data acquisition module, which is used to obtain network activity information and security event records in the network based on network devices and monitoring tools; a network data binary classification model construction module, which is used to extract data from security event records to obtain security event record data, and then use the security event record data as input to obtain a network data binary classification model; a data screening module, which is used to classify network activity information according to the network data binary classification model and screen out a certain type of network activity information; a security risk identification module, which is used to analyze through a certain type of network activity information to obtain the risk prediction value of each network activity in the network, and then mark the security risk events existing in the network; a comprehensive risk assessment module, which is used to evaluate the comprehensive risk status of the network based on the risk prediction values of various threats in the network, and then output a network security situation awareness risk report; an optimization and update module, which is used to conduct accuracy tests on the network security situation awareness risk report, and when the accuracy test result is unqualified, trigger the network security situation awareness risk assessment optimization mechanism.

[0043] In summary, the present application has at least the following effects:

[0044] By obtaining network activity information and security event records through real-time monitoring of network devices and tools, the network status can be perceived in real time, and potential security threats can be discovered in time. By using data extraction and network data binary classification models to classify network activity information, a certain type of network activity information, that is, those activities that may be related to security risks, can be identified more accurately. Based on the risk prediction values of each marked security risk event in the network, the comprehensive risk status of the network can be comprehensively evaluated, which helps network administrators or security teams understand the security situation of the entire network, so as to make more reasonable security decisions. It realizes automation to a large extent, reduces the need for manual intervention, improves work efficiency, and can be continuously optimized with the accumulation of data, improving the accuracy and intelligence level of risk assessment.

[0045] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods and systems. Therefore, the present invention can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0046] The present invention is described with reference to the flowcharts and block diagrams of methods and systems according to embodiments of the present invention. It should be understood that each combination of operations and modules in the flowcharts and block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one operation Figure 1 one operation or multiple operations and block diagrams Figure 1 or multiple modules.

[0047] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one operation Figure 1 one operation or multiple operations and block diagrams Figure 1 or multiple modules.

[0048] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one operation Figure 1 one operation or multiple operations and block diagrams Figure 1 or multiple modules.

[0049] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0050] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A risk assessment method based on network security situation awareness, characterized in that: The following steps are involved: Obtain network activity information and security event records in the network based on network devices and monitoring tools; Extract data from security event records to obtain security event record data, and then use the security event record data as input to obtain a network data binary classification model; Classify the network activity information according to the network data binary classification model and select a category of network activity information; By analyzing a type of network activity information, we can obtain the risk prediction value of each network activity in the network, and then mark the security risk events existing in the network; Evaluate the comprehensive risk status of the network based on the risk prediction values ​​of each security risk event marked in the network, and then output a network security situation awareness risk report; The network security situation awareness risk report is checked for accuracy. When the accuracy check result fails, the network security situation awareness risk assessment optimization mechanism is triggered.

2. According to the risk assessment method based on network security situation awareness according to claim 1, it is characterized in that: The security event records are extracted to obtain security event record data, and then the security event record data is used as input to obtain the specific analysis of the network data binary classification model: Acquire security event records, extract data from the security event records, and obtain security event record data, wherein the security event record data includes recorded accurate security risk event data and recorded misjudged security risk event data; The recorded exact security risk event data specifically includes the sampling rate of the exact security risk event data, the missing value ratio of the exact security risk event data, the accuracy of the exact security risk event data, and the relevance of the exact security risk event data; The recorded misjudged security risk event data specifically includes the sampling rate of the misjudged security risk event data, the missing value ratio of the misjudged security risk event data, the accuracy of the misjudged security risk event data, and the relevance of the misjudged security risk event data; Logistic regression is used as the model basis of the network data binary classification model, and the recorded exact security risk event data and the recorded misjudged security risk event data are used as the input of the network data binary classification model respectively to obtain the output results of the network data binary classification model of the recorded exact security risk event data and the recorded misjudged security risk event data. The classification threshold of the network data binary classification model is set according to the output results of the network data binary classification model of the recorded exact security risk event data and the recorded misjudged security risk event data.

3. A risk assessment method based on network security situation awareness according to claim 2, characterized in that: The specific analysis of setting the classification threshold of the network data binary classification model based on the output results of the network data binary classification model of the recorded accurate security risk event data and the recorded misjudged security risk event data is as follows: The output results of the network data binary classification model of the recorded accurate security risk event data and the recorded misjudged security risk event data are combined into an output probability sample; Randomly generate data with a value range of 0 to 1 as the traversal threshold, compare the output probability samples according to different traversal thresholds, and then output the comparison results, and combine the comparison results into a confusion matrix; According to the different confusion matrices obtained by comparing different traversal thresholds, the precision and recall rates corresponding to different traversal thresholds are obtained respectively, and the harmonic mean of the precision and recall rates is obtained; The harmonic means of precision and recall corresponding to different ergodic thresholds are compared, and the ergodic threshold corresponding to the maximum harmonic mean of precision and recall is marked as the classification threshold of the network data binary classification model.

4. A risk assessment method based on network security situation awareness according to claim 2, characterized in that: According to the network data binary classification model, network activity information is classified and a specific analysis of a category of network activity information is screened out as follows: Obtaining quality assessment parameters of the network activity information, wherein the quality assessment parameters of the network activity information specifically include a sampling rate of the network activity information, a missing value ratio of the network activity information, an accuracy of the network activity information, and a correlation of the network activity information; Using the quality assessment parameter of the network activity information as the input of the network data binary classification model, and outputting an output result of the network data binary classification model of the network activity information, wherein the output result of the network data binary classification model of the network activity information is specifically the quality reliability probability of the network activity information; The output results of the network data binary classification model of the network activity information are compared with the classification threshold of the network data binary classification model, and the network activity information whose output results of the network data binary classification model are less than or equal to the classification threshold of the network data binary classification model is screened out, and the network activity information whose output results of the network data binary classification model are greater than the classification threshold of the network data binary classification model is retained and marked as Class I network activity information.

5. The risk assessment method based on network security situation awareness according to claim 1 is characterized in that: Through the analysis of a type of network activity information, the risk prediction value of each network activity in the network is obtained, and then the specific analysis of the security risk events existing in the network is marked as follows: A type of network activity feature is obtained based on a type of network activity information extraction; Obtaining a class of network activity features within a preset time window, and then obtaining the mean and standard deviation of each class of network activity features; The risk prediction value of each network activity is obtained by comprehensively calculating the mean and standard deviation of each type of network activity characteristics and corresponding characteristics; The risk prediction value of each network activity is compared with the preset risk threshold. When the risk prediction value exceeds the preset risk threshold, the network activity is marked as a security risk event, that is, there is a security risk in the network.

6. The risk assessment method based on network security situation awareness according to claim 1 is characterized in that: The comprehensive risk status of the network is evaluated based on the risk prediction values ​​of each security risk event marked in the network, and the specific analysis of the network security situation awareness risk report is output as follows: Identify each marked security risk event and obtain the risk prediction value corresponding to each security risk event, and then mark the average of the risk prediction values ​​corresponding to each security risk event as the network comprehensive risk assessment value, which is used to quantify the comprehensive risk level of the network; Each security risk event marked in the network and the comprehensive risk assessment value of the network are recorded in the network security situation awareness risk report, and then the network security situation awareness risk report is transmitted to the network security personnel for risk warning.

7. A risk assessment method based on network security situation awareness according to claim 6, characterized in that: The network security situation awareness risk report is checked for accuracy. When the accuracy test result fails, the specific analysis of triggering the network security situation awareness risk assessment optimization mechanism is as follows: Obtaining in real time the actual inspection records of network security personnel after receiving the network security situation awareness risk report, wherein the actual inspection records are specifically the actual inspection results of each security risk event marked in the network, and the actual inspection results include the actual inspection being a security risk event and the actual inspection not being a security risk event; When the actual inspection record contains an inspection result that is not a security risk event, the network security situation awareness risk assessment optimization mechanism is triggered. The specific optimization method of the network security situation awareness risk assessment optimization mechanism is: updating the network activity information and security event records in the network, and updating the network data binary classification model and the classification threshold of the network data binary classification model based on the updated network activity information and security event records.

8. A risk assessment system based on network security situation awareness, applying a risk assessment method based on network security situation awareness according to any one of claims 1 to 7, characterized in that: include: A data acquisition module is used to obtain network activity information and security event records in the network based on network devices and monitoring tools; A network data binary classification model building module is used to extract data from security event records to obtain security event record data, and then use the security event record data as input to obtain a network data binary classification model; A data screening module is used to classify network activity information according to a network data binary classification model and screen out a category of network activity information; The security risk identification module is used to obtain the risk prediction value of each network activity in the network through a type of network activity information analysis, and then mark the security risk events existing in the network; Comprehensive risk assessment module, which is used to evaluate the comprehensive risk status of the network based on the risk prediction values ​​of each threat in the network, and then output a network security situation awareness risk report; The optimization and update module is used to verify the accuracy of the network security situation awareness risk report. When the accuracy test result fails, the network security situation awareness risk assessment optimization mechanism is triggered.