Security monitoring alarm device and method for network security vulnerabilities
By building a security knowledge base based on knowledge graph and using the Gray Wolf algorithm for intelligent vulnerability detection, it solves the problem that traditional technology is difficult to detect unknown threats and complex attack behaviors, and realizes efficient security incident analysis and real-time alarm generation, providing valuable decision-making support.
Patent Information
- Application Number
- CN202411887386.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-30
AI Technical Summary
Traditional cybersecurity monitoring and alarm technologies are difficult to detect unknown threats, mine complex attack behaviors, process large-scale heterogeneous security data, and provide valuable decision-making support.
By building a security knowledge base based on knowledge graphs, multi-source heterogeneous security data is collected for preprocessing and entity extraction, intelligent vulnerability detection is used using the Gray Wolf algorithm, and security events and attack chains are analyzed through graph mining and semantic inference, and real-time alarm information is finally generated.
It improves the accuracy and comprehensiveness of detection of network security vulnerabilities, enhances the detection and analysis capabilities of complex attack behaviors, provides rich and structured alarm information, and supports security operators to quickly understand threat situations and take response measures.
Smart Images

Figure CN120074857A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of monitoring and alarming, and in particular to a security monitoring and alarming device and method for network security loopholes. Background Art
[0002] With the increasing complexity of network environments and the continuous upgrading of attack methods, traditional network security monitoring and alarm technologies have been unable to meet actual needs and have many shortcomings. Traditional methods mainly rely on rule matching and feature detection technology. Rule matching is to match network traffic and security events according to a pre-defined set of rules to discover potential security threats. Feature detection is to match and identify network data based on the feature signatures of known threats. These methods have certain effects in discovering known threats, but they also have obvious limitations: first, it is difficult to discover unknown threats in a timely manner, and there is a lack of detection capabilities for new attack methods; second, it is impossible to well mine and associate scattered security events, and there is a lack of comprehensive detection and analysis capabilities for complex multi-step attack behaviors; third, it relies on manual maintenance of rule bases and feature bases, which is labor-intensive and inefficient; fourth, the ability to process large-scale heterogeneous security data is limited, which is prone to missed reports and false positives.
[0003] On the other hand, the existing network security alarm system also has many shortcomings. Most alarm systems only provide alarm information for a single security event, lack analysis of event associations and attack chains, and are unable to fully reflect the full picture of network attacks. The alarm content is also relatively simple, mainly basic information such as the time and location of the event, lacking descriptions of the event type, severity level, and scope of impact, and cannot provide valuable decision-making support for security personnel. In addition, the generation and sending of alarm information is often passive, lacking active monitoring and early warning mechanisms. Summary of the invention
[0004] In view of this, an embodiment of the present invention provides a security monitoring and alarming device and method for network security vulnerabilities, which are used to improve the accuracy of security monitoring and alarming of network security vulnerabilities.
[0005] The present invention provides a security monitoring and alarming device for network security vulnerabilities, comprising: a collection module, configured to collect historical multi-source heterogeneous security data from multiple data sources, and preprocess the historical multi-source heterogeneous security data to obtain an initial security data set, wherein the multi-source heterogeneous security data includes: asset information, network topology, security device logs, and vulnerability scan reports; an extraction module, configured to perform security entity extraction on the initial security data set to obtain a security entity data set, wherein the security entity data set includes: entity names, entity attributes, and entity relationships; a mapping module, configured to perform knowledge graph mapping according to the security entity data set to obtain a target knowledge graph; a detection module, configured to collect real-time network operation data from the multiple data sources, and perform vulnerability detection on the target knowledge graph and the real-time network operation data through a preset grey wolf algorithm to obtain vulnerability detection data; an analysis module, configured to perform security event analysis on the vulnerability detection data to obtain security event data and attack chain data; and a generation module, configured to generate real-time alarm information according to the security event data and the attack chain data, wherein the real-time alarm information includes: alarm objects and alarm content.
[0006] In the present invention, the collection module is specifically configured to: collect data from multiple data sources to obtain historical multi-source heterogeneous security data, wherein the multi-source heterogeneous security data includes: asset information, network topology, security device logs, and vulnerability scan reports; perform data deduplication processing on the historical multi-source heterogeneous security data to obtain deduplicated historical network operation data; perform data cleaning on the deduplicated historical network operation data to obtain cleaned historical network operation data; perform format conversion processing on the cleaned historical network operation data through a regular expression to obtain structured historical network operation data; extract key fields from the structured historical network operation data to obtain key field data; and perform data desensitization processing on the key field data to obtain the initial security data set.
[0007] In the present invention, the extraction module is specifically configured to: perform named entity recognition processing on the initial security data set according to a preset named entity recognition rule to obtain preliminary security entity data; perform entity linking processing on the preliminary security entity data according to a preset entity linking rule to obtain linked security entity data; perform entity attribute recognition on the linked security entity data root according to a preset entity attribute recognition rule to obtain entity attribute data; perform entity relationship extraction processing on the linked security entity data to obtain entity relationship data; perform entity alias mapping processing on the entity attribute data and the entity relationship data to obtain normalized entity attribute data and entity relationship data; perform data fusion processing on the linked security entity data, the normalized entity attribute data, and the entity relationship data to obtain a security entity knowledge base; perform entity classification processing on the security entity knowledge base to obtain a classified security entity data set; perform attribute constraint check processing on the classified security entity data set to obtain an attribute-constrained security entity data set; perform relationship semantic analysis processing on the attribute-constrained security entity data set to obtain a relationship-semantic security entity data set; perform data partitioning on the relationship-semantic security entity data set to obtain the entity name, the entity attributes, and the entity relationships, and merge the entity name, the entity attributes, and the entity relationships into the security entity data set.
[0008] In the present invention, the mapping module is specifically configured to: perform ontology construction processing on the security entity data set to obtain ontology instance data; perform graph database construction processing on the ontology instance data to obtain a target graph database; import the ontology instance data into the target graph database to obtain a graph database instance; perform knowledge fusion processing on the graph database instance to obtain a fused graph database instance; perform knowledge representation learning processing on the fused graph database instance to obtain entity vector representation data and relationship vector representation data; perform graph structure optimization on the fused graph database instance to obtain an optimized graph database instance; perform knowledge reasoning on the optimized graph database instance to obtain an inferred graph database instance; perform knowledge visualization processing on the inferred graph database instance based on the entity vector representation data and the relationship vector representation data to obtain the target knowledge graph.
[0009] In the present invention, the detection module is specifically configured to: map the real-time network operation data to the target knowledge graph to obtain the mapped real-time network operation data; extract features from the mapped real-time network operation data to obtain a real-time network operation data feature set; initialize the detection agent data of the grey wolf algorithm according to the real-time network operation data feature set, and distribute the detection agent data to different regions of the target knowledge graph as a grey wolf population; the grey wolf population performs vulnerability detection in the target knowledge graph according to the preset grey wolf optimization algorithm rules in the grey wolf algorithm; monitor the detection paths of the grey wolf population in real time to obtain vulnerability detection trajectory data; identify the vulnerability points in the target knowledge graph according to the vulnerability detection trajectory data to obtain vulnerability point data; perform clustering analysis on the vulnerability point data to obtain vulnerability cluster data; evaluate the severity of the vulnerability cluster data to obtain a vulnerability severity evaluation result, and generate vulnerability detection data according to the vulnerability severity evaluation result.
[0010] In the present invention, the analysis module is specifically configured to: extract events from the vulnerability detection data to obtain initial security event data; perform event normalization processing on the initial security event data to obtain standardized security event data; map the standardized security event data to the target knowledge graph to obtain mapped security event data; identify relevant vulnerability points, asset points, and threat points in the target knowledge graph according to the mapped security event data to obtain relevant point data; extract a subgraph from the target knowledge graph based on the relevant point data to obtain an event-related subgraph; mine semantic paths from the event-related subgraph to obtain event semantic path data; reconstruct an event attack chain according to the event semantic path data to obtain attack chain data; classify the attack chain data to obtain classified attack chain data; perform risk assessment on the classified attack chain data to obtain a risk assessment report as the security event data; fuse the risk assessment report with the attack chain data to generate a security event analysis report as the attack chain data.
[0011] In the present invention, the generation module is specifically configured to: perform event parsing on the security event data, extract key information such as event type and event severity level to obtain the parsed event data; perform attack path parsing on the attack chain data, extract key information such as attack steps and attack targets to obtain the parsed attack chain data; construct an event-attack chain correspondence relationship according to the parsed event data and the parsed attack chain data; based on the event-attack chain correspondence relationship, perform an asset impact scope analysis on the target knowledge graph to obtain an affected asset set; perform an asset importance assessment on the affected asset set to obtain an important asset subset; determine an alarm object list according to the important asset subset; perform content normalization processing on the parsed event data to generate a standardized event description; perform content normalization processing on the parsed attack chain data to generate a standardized attack path description; perform content fusion on the standardized event description and the standardized attack path description to generate an alarm content template; perform data fusion on the alarm object list and the alarm content template to generate the final real-time alarm information.
[0012] The present invention also provides a security monitoring and alarm method for network security vulnerabilities, including: collecting historical multi-source heterogeneous security data from multiple data sources, and performing preprocessing on the historical multi-source heterogeneous security data to obtain an initial security data set, where the multi-source heterogeneous security data includes: asset information, network topology, security device logs, and vulnerability scan reports; performing security entity extraction on the initial security data set to obtain a security entity data set, where the security entity data set includes: entity name, entity attributes, and entity relationships; performing knowledge graph mapping according to the security entity data set to obtain a target knowledge graph; collecting real-time network operation data from multiple data sources, and performing vulnerability detection on the target knowledge graph and the real-time network operation data through a preset gray wolf algorithm to obtain vulnerability detection data; performing security event analysis on the vulnerability detection data to obtain security event data and attack chain data; generating real-time alarm information according to the security event data and the attack chain data, where the real-time alarm information includes: alarm objects and alarm content.
[0013] In the technical solution provided by the present invention, multi-source heterogeneous security data is intelligently processed and fused to construct a security knowledge base based on a knowledge graph, which can effectively capture and represent complex security semantic information. Through preprocessing, entity extraction, knowledge fusion and other links on heterogeneous data such as asset information, network topology, security device logs and vulnerability scan reports, a unified knowledge model covering security entities, attributes and relationships is formed. Compared with traditional rule bases or pattern bases, the knowledge graph can express concepts, facts and logics in the security field more flexibly and comprehensively, which helps to dig out hidden threat associations and improve the accuracy and comprehensiveness of detection. By introducing intelligent algorithms such as the Grey Wolf Optimization Algorithm, intelligent vulnerability detection based on the knowledge graph is realized. The Grey Wolf Algorithm simulates the behavior pattern of wolf packs. By deploying multiple detection agents in the knowledge graph and performing distributed detection according to optimization rules, potential vulnerability points and vulnerability clusters can be efficiently discovered. Compared with traditional rule matching or pattern matching methods, this algorithm has stronger adaptability and global search ability, can discover complex and multi-step vulnerability propagation paths, and improves the coverage rate and accuracy of vulnerability detection.
[0014] By combining vulnerability detection data with the knowledge graph, intelligent analysis of security events and attack chains is realized through graph mining and semantic reasoning technologies. Using algorithms such as graph neural networks, vector representations of security entities and relationships can be learned to support similarity calculation and semantic reasoning. On this basis, through operations such as subgraph extraction and semantic path mining, a complete attack chain can be reconstructed to reveal the root cause and scope of influence of the event, providing a comprehensive basis for risk assessment and decision-making response. Compared with single-event analysis, hidden event associations can be discovered, improving the detection and analysis capabilities for complex attack behaviors. Finally, by intelligently fusing security event data and attack chain data, real-time alarm information is generated. Through links such as event parsing, attack path parsing, and asset impact analysis, the alarm object and alarm content can be accurately identified, improving the pertinence and operability of the alarm. Compared with traditional alarm methods, it can provide richer and more structured alarm information, including event type, severity level, attack steps, affected assets, etc., which helps security operation personnel quickly understand the threat situation and take targeted response measures. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1Flow chart of a security monitoring and alarm device for network security vulnerabilities in an embodiment of the present invention; Figure 2 Schematic diagram of a security monitoring and alarm system for network security vulnerabilities in an embodiment of the present invention. Specific implementation manners
[0017] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0018] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0019] In addition, the technical features involved in different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0020] For ease of understanding, the specific process of the embodiments of the present invention will be described below. Please refer to Figure 1 , Figure 1 is a flow chart of a security monitoring and alarm device for network security vulnerabilities in an embodiment of the present invention, as shown in Figure 1As shown in the figure, it includes: a collection module 101, which is used to collect historical multi-source heterogeneous security data from multiple data sources, and preprocess the historical multi-source heterogeneous security data to obtain an initial security data set. Among them, the multi-source heterogeneous security data includes: asset information, network topology, security device logs, and vulnerability scan reports; an extraction module 102, which is used to perform security entity extraction on the initial security data set to obtain a security entity data set. Among them, the security entity data set includes: entity names, entity attributes, and entity relationships; a mapping module 103, which is used to perform knowledge graph mapping according to the security entity data set to obtain a target knowledge graph; a detection module 104, which is used to collect real-time network operation data from multiple data sources, and perform vulnerability detection on the target knowledge graph and the real-time network operation data through a preset gray wolf algorithm to obtain vulnerability detection data; an analysis module 105, which is used to perform security event analysis on the vulnerability detection data to obtain security event data and attack chain data; a generation module 106, which is used to generate real-time alarm information according to the security event data and the attack chain data. The real-time alarm information includes: alarm objects and alarm contents.
[0021] It should be noted that the collection module collects historical multi-source heterogeneous security data from multiple data sources, including asset information, network topology, security device logs, and vulnerability scan reports, etc., and preprocesses these heterogeneous data to obtain an initial security data set. This step solves the problem that it is difficult for traditional methods to process large-scale heterogeneous security data. Taking a certain enterprise network as an example, this module can obtain asset information of devices such as servers and routers from the asset management system, obtain network topology information from the network management system, obtain log data from security devices such as firewalls and intrusion detection systems, obtain vulnerability scan reports from vulnerability scanning tools, and perform preprocessing such as data cleaning, format conversion, and field extraction on these data to form a unified initial security data set.
[0022] Secondly, the extraction module performs security entity extraction on the initial security data set to obtain a security entity data set, including entity names, entity attributes, and entity relationships. This step transforms the scattered security data into a structured knowledge form, laying a foundation for subsequent knowledge fusion and semantic analysis. Continuing with the above enterprise network as an example, this module can identify asset entities such as Web servers and database servers from the initial data set, extract their attributes such as IP addresses and operating system versions, and the relationships between entities such as network reachability and service dependencies, and construct a complete security entity data set.
[0023] Next, the mapping module performs knowledge graph mapping based on the security entity dataset to obtain the target knowledge graph. A knowledge graph is a knowledge representation form rich in semantic information that can capture concepts, facts, and logical rules in the security domain. Taking the above enterprise network as an example, the mapping module can build an ontology model containing concepts such as assets, vulnerabilities, threats, and events based on the security entity dataset, map the entity data into the knowledge graph, and enrich and optimize the graph through technologies such as knowledge fusion and representation learning, finally obtaining the target knowledge graph.
[0024] The detection module uses the pre-set gray wolf algorithm to perform vulnerability detection on the target knowledge graph and the network operation data collected in real time, obtaining vulnerability detection data. The gray wolf algorithm is an intelligent optimization algorithm that simulates the behavior pattern of wolf packs and can efficiently discover targets in a complex search space. Taking the above enterprise network as an example, the detection module can map the asset change information, vulnerability scan results, etc. collected in real time into the knowledge graph, deploy multiple detection agents to perform distributed detection in the graph, discover potential vulnerability points and vulnerability clusters according to the optimization rules, and generate vulnerability detection data.
[0025] The analysis module performs security event analysis on the vulnerability detection data to obtain security event data and attack chain data. Based on the knowledge graph, this module can discover hidden event correlations and reconstruct the complete attack chain. Taking the above enterprise network as an example, the analysis module can associate the detected vulnerability points with real-time security events, extract the event-related subgraphs in the knowledge graph, perform semantic path mining and attack chain reconstruction, generate event data and attack chain data, and reveal the root cause, steps, and scope of influence of the events.
[0026] Finally, the generation module generates real-time alarm information based on the security event data and attack chain data, including the alarm object and alarm content. This module can intelligently analyze information such as the severity level of the event and the attack path, determine the important assets affected, and generate targeted alarm objects and content. Taking the above enterprise network as an example, the generation module can parse the event type, attack steps, etc., analyze the scope of influence and asset importance, determine important assets such as web servers and databases as alarm objects, and generate standardized event descriptions and attack path descriptions as alarm content, providing them to security operation personnel for taking response measures.
[0027] Through the collaborative cooperation of the above-mentioned various modules, multi-source heterogeneous security data is intelligently processed and fused to construct a security knowledge base based on a knowledge graph, which can effectively capture and represent complex security semantic information. Through preprocessing, entity extraction, knowledge fusion and other processes on heterogeneous data such as asset information, network topology, security device logs and vulnerability scan reports, a unified knowledge model covering security entities, attributes and relationships is formed;. Compared with traditional rule bases or pattern bases, knowledge graphs can express concepts, facts and logics in the security field more flexibly and comprehensively, which helps to discover hidden threat associations and improve the accuracy and comprehensiveness of detection. By introducing intelligent algorithms such as the Grey Wolf Optimization Algorithm, intelligent vulnerability detection based on the knowledge graph is realized. The Grey Wolf Algorithm simulates the behavior pattern of wolf packs. By deploying multiple detection agents in the knowledge graph and conducting distributed detection according to optimization rules, potential vulnerability points and vulnerability clusters can be efficiently discovered. Compared with traditional rule matching or pattern matching methods, this algorithm has stronger adaptability and global search ability, can discover complex and multi-step vulnerability propagation paths, and improves the coverage rate and accuracy of vulnerability detection.
[0028] By combining vulnerability detection data with the knowledge graph and through graph mining and semantic reasoning technologies, intelligent analysis of security events and attack chains is realized. Using algorithms such as graph neural networks, vector representations of security entities and relationships can be learned to support similarity calculation and semantic reasoning. On this basis, through operations such as subgraph extraction and semantic path mining, a complete attack chain can be reconstructed to reveal the root cause and scope of influence of the event, providing a comprehensive basis for risk assessment and decision-making response. Compared with single-event analysis, hidden event associations can be discovered, improving the detection and analysis capabilities for complex attack behaviors. By finally intelligently fusing security event data and attack chain data, real-time alarm information is generated. Through links such as event parsing, attack path parsing, and asset impact analysis, the alarm object and alarm content can be accurately identified, improving the pertinence and operability of the alarm. Compared with traditional alarm methods, it can provide richer and more structured alarm information, including event type, severity level, attack steps, affected assets, etc., which helps security operation personnel quickly understand the threat situation and take targeted response measures.
[0029] In a specific embodiment, the acquisition module 101 is specifically configured to perform the following steps: (1) Collect data from multiple data sources to obtain historical multi-source heterogeneous security data, where the multi-source heterogeneous security data includes: asset information, network topology, security device logs, and vulnerability scan reports; (2) Perform data deduplication on the historical multi-source heterogeneous security data to obtain deduplicated historical network operation data; (3) Perform data cleaning on the deduplicated historical network operation data to obtain cleaned historical network operation data; (4) Perform format conversion on the cleaned historical network operation data through regular expressions to obtain structured historical network operation data; (5) Extract key fields from the structured historical network operation data to obtain key field data; (6) Perform data desensitization on the key field data to obtain an initial security data set.
[0030] Specifically, the acquisition module needs to collect historical multi-source heterogeneous security data from multiple data sources, including asset information, network topology, security device logs, and vulnerability scan reports, etc. These data are distributed in different systems and tools within the enterprise, with different formats and structures, reflecting different security dimensions in the network environment. Taking a certain enterprise as an example, the asset information may come from the asset management system, describing the detailed information of IT assets such as servers, routers, and firewalls owned by the enterprise; the network topology information may come from the network management system, describing the physical connections and logical relationships between these assets; the security device logs may come from security devices such as firewalls and intrusion detection systems, recording the details of network traffic and security events; the vulnerability scan reports may come from specialized vulnerability scanning tools, listing various vulnerabilities existing in the assets and their severity levels. By collecting data from these heterogeneous data sources, the security status of the enterprise network environment can be comprehensively reflected. The acquisition module needs to perform data deduplication on these historical multi-source heterogeneous security data to obtain deduplicated historical network operation data. Due to the large number of data sources, duplicate data inevitably exists. For example, the asset information of a certain server may be recorded in multiple systems. The deduplication process can calculate the hash value of the data, mark the data with the same hash value as duplicate data and merge or delete them, thereby eliminating redundancy and improving the efficiency of subsequent processing.
[0031] The data collection module needs to clean the deduplicated historical network operation data to obtain the cleaned historical network operation data. There may be problems such as noise, outliers, and missing values in the original data, and data cleaning needs to be performed through methods such as regular expression matching, outlier detection, and missing value filling to ensure the integrity and accuracy of the data. Then, the data collection module needs to perform format conversion processing on the cleaned historical network operation data through regular expressions to obtain structured historical network operation data. Since the original data may exist in an unstructured format, such as log files, report documents, etc., regular expressions need to be used to extract key fields and convert the unstructured data into structured data for subsequent processing and analysis. The data collection module needs to extract key fields from the structured historical network operation data to obtain key field data. Although the data has been structured after the previous format conversion, it may still contain a large number of redundant fields, and key fields related to security, such as IP addresses, port numbers, vulnerability names, event types, etc., need to be extracted according to predefined rules to reduce the data volume and improve processing efficiency.
[0032] Finally, the data collection module needs to perform data desensitization processing on the key field data to obtain the initial security data set. Since the security data may contain sensitive information, such as passwords, personal identity information, etc., these sensitive information needs to be encrypted or anonymized through technologies such as cryptographic hashing and differential privacy to ensure data availability while protecting data privacy, and finally form the initial security data set to provide high-quality data support for subsequent entity extraction and knowledge graph construction.
[0033] In a specific embodiment, the extraction module 101 is specifically configured to perform the following steps: (1) perform named entity recognition processing on the initial security data set according to the preset named entity recognition rules to obtain preliminary security entity data; (2) perform entity linking processing on the preliminary security entity data according to the preset entity linking rules to obtain linked security entity data; (3) perform entity attribute recognition on the root of the linked security entity data according to the preset entity attribute recognition rules to obtain entity attribute data; (4) perform entity relationship extraction processing on the linked security entity data to obtain entity relationship data; (5) perform entity alias mapping processing on the entity attribute data and the entity relationship data to obtain normalized entity attribute data and entity relationship data; (6) perform data fusion processing on the linked security entity data, the normalized entity attribute data and the entity relationship data to obtain a security entity knowledge base; (7) perform entity classification processing on the security entity knowledge base to obtain a classified security entity data set; (8) perform attribute constraint check processing on the classified security entity data set to obtain an attribute-constrained security entity data set; (9) perform relationship semantic analysis processing on the attribute-constrained security entity data set to obtain a relationship-semantic security entity data set; (10) perform data partitioning on the relationship-semantic security entity data set to obtain entity names, entity attributes, and entity relationships, and merge the entity names, entity attributes, and entity relationships into a security entity data set.
[0034] Specifically, the extraction module needs to perform named entity recognition processing on the initial security data set according to the preset named entity recognition rules to obtain preliminary security entity data. Named entity recognition is a basic technology in the field of natural language processing, aiming to identify entity mentions from unstructured text. Taking an enterprise network as an example, the extraction module can use machine learning algorithms such as conditional random fields and recurrent neural networks to identify asset entities such as "Web server", "database", vulnerability entities such as "CVE-2022-1234", threat entities such as "malware", event entities such as "network intrusion", etc. from the initial data set, and construct preliminary security entity data. The extraction module needs to perform entity linking processing on the preliminary security entity data according to the preset entity linking rules to obtain the linked security entity data. Since the same entity may have multiple representations, such as "Web Server" and "WWW Server" actually referring to the same entity, these different representations need to be linked to eliminate entity ambiguity. The extraction module can link different mentions of co-referential entities through methods such as string similarity calculation and knowledge base query to obtain uniquely identified entity data.
[0035] The extraction module needs to identify the entity attributes of the linked security entity data according to the preset entity attribute recognition rules to obtain entity attribute data. Entity attributes describe information such as the type, level, and description of the entity. For example, the attributes of a "Web server" may include "Type: Application server", "Operating system: Linux", etc. The extraction module can use natural language processing technologies such as pattern matching and dependency analysis to identify the attribute information of the entity from the context. Then, the extraction module needs to perform entity relationship extraction processing on the linked security entity data to obtain entity relationship data. Entity relationships reflect the semantic connections between entities. For example, there may be a "dependency" relationship between a "Web server" and a "database". The extraction module can use methods such as statistical models and deep learning models to extract the relationship information between entities from the context.
[0036] Then, the extraction module needs to perform entity alias mapping processing on the entity attribute data and entity relationship data to obtain normalized entity attribute data and entity relationship data. Since the same entity may have multiple aliases, these aliases need to be mapped to a unified standard name to eliminate ambiguity and improve data quality. Next, the extraction module needs to perform data fusion processing on the linked security entity data, normalized entity attribute data, and entity relationship data to obtain a security entity knowledge base, which serves as the basis for the security entity data set. Technologies such as graph databases and knowledge bases can be used to seamlessly integrate these structured data to form a complete security entity knowledge base.
[0037] Then, the extraction module needs to perform entity classification processing on the security entity knowledge base to obtain a classified security entity data set. Entities can be classified into different types such as asset class, vulnerability class, threat class, event class, etc. according to the preset entity type hierarchy, which facilitates subsequent processing and management. The extraction module needs to perform attribute constraint check processing on the classified security entity data set to obtain a security entity data set with attribute constraints. Different types of entities should meet specific attribute constraint conditions. For example, asset entities should include attributes such as IP address and operating system version, and vulnerability entities should include attributes such as vulnerability description and severity level. Through attribute constraint checking, missing or incorrect attribute information can be discovered and supplemented or corrected.
[0038] Then, the extraction module needs to perform relational semantic analysis on the security entity dataset after attribute constraint to obtain a security entity dataset with relational semantics. Different entity relationships may have different semantic types, such as causal relationships, temporal relationships, compositional relationships, etc. Through semantic analysis, the relationships can be classified and annotated, laying a foundation for subsequent knowledge reasoning. Finally, the extraction module needs to partition the security entity dataset with relational semantics to obtain entity names, entity attributes, and entity relationships, and merge them into a security entity dataset to provide the required structured input data for knowledge graph mapping.
[0039] In a specific embodiment, the mapping module 101 is specifically configured to perform the following steps: (1) perform ontology construction on the security entity dataset to obtain ontology instance data; (2) perform graph database construction on the ontology instance data to obtain a target graph database; (3) import the ontology instance data into the target graph database to obtain a graph database instance; (4) perform knowledge fusion on the graph database instance to obtain a fused graph database instance; (5) perform knowledge representation learning on the fused graph database instance to obtain entity vector representation data and relationship vector representation data; (6) optimize the graph structure of the fused graph database instance to obtain an optimized graph database instance; (7) perform knowledge reasoning on the optimized graph database instance to obtain an inference graph database instance; (8) perform knowledge visualization on the inference graph database instance based on the entity vector representation data and the relationship vector representation data to obtain a target knowledge graph.
[0040] Specifically, the mapping module needs to perform ontology construction on the security entity dataset to obtain ontology instance data. Ontology is a formal description of concepts in a certain domain and their mutual relationships, and is the basis for constructing a knowledge graph. Taking an enterprise network as an example, the mapping module can extract core concepts such as assets, vulnerabilities, threats, events, etc. from the security entity dataset according to preset ontology construction rules, define their hierarchical relationships, attribute constraints, etc., and construct an ontology model for the security domain. Then, the specific instance data in the security entity dataset is mapped into the ontology model to obtain ontology instance data. The mapping module needs to perform graph database construction on the ontology instance data to obtain a target graph database. A graph database is a database suitable for representing highly connected data and can efficiently store and query complex entity relationship data. The mapping module can convert the ontology instance data into nodes and edges in the graph database according to a preset graph database schema to construct a logical model of the target graph database.
[0041] Then, the mapping module needs to import the ontology instance data into the target graph database to obtain a graph database instance. That is, the specific instance data in the security entity dataset, such as web servers, vulnerability CVE-2022-1234, malware, etc., and their attribute relationships, are imported into the constructed graph database model to form an actual graph database instance. The mapping module needs to perform knowledge fusion processing on the graph database instance to obtain a fused graph database instance. Since the knowledge sources in the security field are extensive, relying solely on the collected data is insufficient, and external knowledge sources need to be fused. The mapping module can semantically align and fuse structured knowledge such as security knowledge bases, threat intelligence bases, vulnerability databases, etc., and unstructured knowledge such as security literature, reports, etc., with the graph database instance, thereby enriching and improving the knowledge in the graph.
[0042] Then, the mapping module needs to perform knowledge representation learning processing on the fused graph database instance to obtain entity vector representation data and relationship vector representation data. Knowledge representation learning is a technology that maps symbolic knowledge to a low-dimensional continuous vector space, which helps to capture the semantic information of entities and relationships. The mapping module can adopt classical knowledge representation learning algorithms such as TransE, TransR, or algorithms based on graph neural networks such as GCN, GAT, etc., to learn the low-dimensional vector representations of entities and relationships by minimizing the distance between nodes or iteratively aggregating the neighbor information of nodes. The mapping module needs to optimize the graph structure of the fused graph database instance to obtain an optimized graph database instance. Since the original graph database instance may have problems such as redundancy and noise, it is necessary to optimize the topological structure of the graph to improve its quality and efficiency. The mapping module can adopt graph structure optimization strategies based on centrality, homogeneity, etc., to perform operations such as compressing and clustering nodes and edges to obtain a more compact and efficient optimized graph database instance.
[0043] The mapping module needs to perform knowledge reasoning on the optimized graph database instance to obtain the inferred graph database instance. Knowledge reasoning is a process of deriving new implicit knowledge based on existing facts and is crucial for discovering potential security threats. The mapping module can perform link reasoning, constraint reasoning, etc. on the basis of the optimized graph database instance according to preset knowledge reasoning rules, such as induction rules, deduction rules, etc., to derive knowledge such as hidden security vulnerabilities and attack paths, and form an inferred graph database instance. The mapping module needs to perform knowledge visualization processing on the inferred graph database instance based on entity vector representation data and relationship vector representation data to obtain the target knowledge graph. Knowledge visualization can present abstract symbolic knowledge in a graphical way, facilitating human-computer interaction and decision-making analysis. The mapping module can use the vector representations of entities and relationships, combined with visualization techniques such as graph layout and node coloring, to render the inferred graph database instance into an intuitive knowledge graph form, which is used as the final output of the entire solution and provides data support for subsequent processes such as intelligent vulnerability detection, event analysis, and alarm generation.
[0044] In a specific embodiment, the detection module 101 is specifically configured to perform the following steps: (1) Map the real-time network operation data into the target knowledge graph to obtain the mapped real-time network operation data; (2) Extract features from the mapped real-time network operation data to obtain the real-time network operation data feature set; (3) Initialize the detection agent data of the grey wolf algorithm according to the real-time network operation data feature set, and deploy the detection agent data distributively to different regions of the target knowledge graph as the grey wolf population; (4) The grey wolf population performs vulnerability detection in the target knowledge graph according to the preset grey wolf optimization algorithm rules in the grey wolf algorithm; (5) Monitor the detection paths of the grey wolf population in real time to obtain vulnerability detection trajectory data; (6) Identify the vulnerability points in the target knowledge graph according to the vulnerability detection trajectory data to obtain the vulnerability point data; (7) Perform clustering analysis on the vulnerability point data to obtain the vulnerability cluster data; (8) Evaluate the severity of the vulnerability cluster data to obtain the vulnerability severity evaluation result, and generate vulnerability detection data according to the vulnerability severity evaluation result.
[0045] Specifically, the detection module needs to map the real-time collected network operation data into the constructed target knowledge graph to obtain the mapped real-time network operation data. Taking the network of an enterprise as an example, the detection module can map the data such as asset change information, vulnerability scanning results, and security event logs collected in real time to the existing nodes in the knowledge graph for entities such as assets, vulnerabilities, and events according to semantic alignment and entity linking technologies, so as to obtain incremental real-time network operation data. Next, the detection module needs to extract features from the mapped real-time network operation data to obtain a real-time network operation data feature set. Feature extraction is to transform the original data into a numerical vector form that can be processed by algorithms, which is crucial for subsequent vulnerability detection. The detection module can use classical feature extraction algorithms such as TF-IDF and Word2Vec, or algorithms based on attention mechanisms such as Transformer to extract feature vectors reflecting aspects such as asset status, vulnerability hazards, and event impacts from real-time data to form a real-time network operation data feature set. Then, the detection module needs to initialize the detection agent data of the grey wolf algorithm according to the real-time network operation data feature set and distribute the detection agent data to different regions of the target knowledge graph as the grey wolf population. The grey wolf algorithm is an intelligent optimization algorithm that simulates the behavior pattern of wolf packs hunting and can efficiently discover targets in a complex search space. The detection module can initialize the positions and states of multiple detection agents according to the feature set and distribute them to different regions of the knowledge graph to simulate the situation where wolf packs are scattered throughout the search space. Next, the grey wolf population needs to perform vulnerability detection in the target knowledge graph according to the preset grey wolf optimization algorithm rules in the grey wolf algorithm. These rules simulate the behavior strategies when wolf packs hunt, such as dispersing, surrounding, chasing, and feeding. Each detection agent moves in the graph with a certain probability according to its own state and the positions of other agents, gradually approaching potential vulnerability points. At the same time, the detection module needs to monitor the detection paths of the grey wolf population in real time to obtain vulnerability detection trajectory data. The movement trajectories of each detection agent in the graph can be recorded, their aggregation trends can be analyzed, and it can be judged whether they are gradually approaching certain regions, so as to discover potential vulnerability points. Then, the detection module needs to identify the vulnerability points in the target knowledge graph according to the vulnerability detection trajectory data to obtain vulnerability point data. When the detection agents gather at certain nodes or regions, these nodes or regions can be marked as potential vulnerability points as the output of the vulnerability point data. Next, the detection module needs to perform clustering analysis on the vulnerability point data to obtain vulnerability cluster data. Since a single vulnerability point may only be a link in a larger vulnerability, it is necessary to cluster related vulnerability points to discover the complete vulnerability clusters and their attack paths. The detection module can use clustering algorithms based on density, hierarchical, etc. to divide the vulnerability point data into several vulnerability clusters. Then, the detection module needs to evaluate the severity of the vulnerability cluster data to obtain the vulnerability severity evaluation result.Different vulnerability clusters may pose threats to network security to varying degrees and need to be quantitatively evaluated. The detection module can calculate the severity score of each vulnerability cluster through a preset evaluation model based on factors such as the importance of assets involved in the vulnerability cluster, the severity level of the vulnerability, and the attack difficulty. Finally, the detection module needs to generate vulnerability detection data based on the evaluation results of vulnerability severity. The evaluation results can be sorted from high to low according to severity, and a detailed vulnerability detection report can be generated as input data for subsequent event analysis and alarm generation, providing timely and comprehensive vulnerability detection information for security operation personnel.
[0046] In a specific embodiment, the analysis module 101 is specifically configured to perform the following steps: (1) Extract events from the vulnerability detection data to obtain initial security event data; (2) Perform event normalization processing on the initial security event data to obtain standardized security event data; (3) Map the standardized security event data into the target knowledge graph to obtain the mapped security event data; (4) Based on the mapped security event data, identify relevant vulnerability points, asset points, and threat points in the target knowledge graph to obtain relevant point data; (5) Extract subgraphs from the target knowledge graph based on the relevant point data to obtain event-related subgraphs; (6) Mine semantic paths of the event-related subgraphs to obtain event semantic path data; (7) Reconstruct the event attack chain based on the event semantic path data to obtain attack chain data; Classify the attack chain data to obtain classified attack chain data; (8) Perform risk assessment on the classified attack chain data to obtain a risk assessment report as security event data; (9) Integrate the risk assessment report with the attack chain data to generate a security event analysis report as attack chain data.
[0047] Specifically, the analysis module needs to perform event extraction on the vulnerability detection data to obtain the initial security event data. The vulnerability detection data may contain information on security events that have occurred, such as intrusion detection system alerts, firewall blocking records, etc. The analysis module can use a rule-based method or a deep learning-based sequence annotation algorithm to identify and extract these security events from the vulnerability detection data. Next, the analysis module needs to perform event normalization on the initial security event data to obtain normalized security event data. Since the original event data may come from different sources and have inconsistent formats, normalization processing is required. The analysis module can define a unified event template and map the extracted event data into this template to obtain a standardized event description. Then, the analysis module needs to map the normalized security event data into the target knowledge graph to obtain the mapped security event data. Entity linking technology can be used to map entities such as assets, vulnerabilities, and threats mentioned in the event data to existing nodes in the knowledge graph. Next, the analysis module needs to identify relevant vulnerability points, asset points, and threat points in the target knowledge graph based on the mapped security event data to obtain relevant point data. Through graph traversal algorithms, nodes related to the event data can be found in the graph, such as asset nodes with vulnerabilities, attacker nodes that may pose threats, etc. Then, the analysis module needs to perform subgraph extraction on the target knowledge graph based on the relevant point data to obtain an event-related subgraph. Subgraph extraction can strip out the local area related to the current event from the entire knowledge graph, focus on the analysis object, and improve efficiency. Next, the analysis module needs to perform semantic path mining on the event-related subgraph to obtain event semantic path data. The semantic path reflects the potential causal chain of the event, such as "attacker -> vulnerability -> asset". The analysis module can use a rule-based path mining algorithm or an embedding-based path ranking algorithm to discover multiple possible semantic paths from the subgraph. According to the event semantic path data, the analysis module needs to reconstruct the event attack chain to obtain attack chain data. The attack chain is a further interpretation and reconstruction of the semantic path, reflecting the entire process of the attack. The analysis module can combine security domain knowledge and rules to transform the semantic path into specific content such as attack steps and attack targets. Then, the analysis module needs to classify the attack chain data to obtain the classified attack chain data. Different types of attack chains may correspond to different response strategies and need to be classified. The analysis module can classify the attack chain based on features such as attack purpose and attack means using supervised or unsupervised machine learning algorithms. Next, the analysis module needs to perform risk assessment on the classified attack chain data to obtain a risk assessment report as security event data. Risk assessment needs to consider factors such as the harm degree and occurrence probability of the attack chain. The analysis module can build a risk assessment model and output the risk scores and levels of each attack chain.Finally, the analysis module needs to fuse the risk assessment report with the attack chain data to generate a security event analysis report as the output of the attack chain data. This report not only includes the detailed steps of the attack chain but also the risk level and impact scope of each attack chain, providing a comprehensive decision-making basis for subsequent alarm generation. Taking the network of an enterprise as an example, assume that the detection module discovers the risk of vulnerability CVE-2022-1234 in the Web server. The analysis module can extract relevant intrusion events from the vulnerability detection data, map them to the knowledge graph, identify the Web server node, vulnerability node, and attacker node, and extract the event-related subgraph. Then, through semantic path mining, it discovers the attack path of "attacker -> CVE-2022-1234 -> Web server", reconstructs the attack chain of "the attacker exploits the vulnerability to invade the Web server", and conducts a risk assessment based on the vulnerability severity level, the importance of the Web server, etc. Finally, it outputs a security event analysis report containing the details of the attack chain and the risk level.
[0048] In a specific embodiment, the generation module 101 is specifically configured to perform the following steps: (1) perform event parsing on the security event data, extract key information such as event type and event severity level, and obtain the parsed event data; (2) perform attack path parsing on the attack chain data, extract key information such as attack steps and attack targets, and obtain the parsed attack chain data; (3) construct an event-attack chain correspondence relationship based on the parsed event data and the parsed attack chain data; (4) perform an asset impact scope analysis on the target knowledge graph based on the event-attack chain correspondence relationship to obtain the set of affected assets; (5) perform an asset importance assessment on the set of affected assets to obtain a subset of important assets; (6) determine the alarm object list according to the subset of important assets; (7) perform content normalization processing on the parsed event data to generate a standardized event description; (8) perform content normalization processing on the parsed attack chain data to generate a standardized attack path description; (9) fuse the standardized event description and the standardized attack path description to generate an alarm content template; (10) fuse the alarm object list with the alarm content template to generate the final real-time alarm information.
[0049] It should be noted that the generation module needs to perform event parsing on the security event data, extract key information such as event type and event severity level, and obtain the parsed event data. A rule-based method or a deep learning-based event extraction algorithm can be used to identify core information such as event type and scope of impact from the original event description. At the same time, the generation module needs to perform attack path parsing on the attack chain data, extract key information such as attack steps and attack targets, and obtain the parsed attack chain data. Natural language processing techniques can be used to split the attack chain step by step and identify the attack behavior, attack object, etc. in each step. Next, the generation module needs to construct an event-attack chain correspondence based on the parsed event data and the parsed attack chain data. That is, establish a mapping association between a single event and its potential attack chain to facilitate subsequent impact analysis and alarm generation. Then, based on the event-attack chain correspondence, the generation module needs to analyze the asset impact scope of the target knowledge graph to obtain the set of affected assets. Using the semantic link relationship in the knowledge graph, it is possible to trace the asset nodes that may be affected along the path of the attack chain. Next, the generation module needs to evaluate the importance of the set of affected assets to obtain a subset of important assets. Different assets have different degrees of importance to enterprise operations, and it is necessary to quantitatively evaluate their importance as the basis for subsequent alarm decisions. According to the subset of important assets, the generation module can determine the list of alarm objects. The entity corresponding to the important asset is used as the alarm object, and the security event data is subjected to event parsing to extract key information such as event type and event severity level, and obtain the parsed event data. At the same time, the generation module needs to perform attack path parsing on the attack chain data, extract key information such as attack steps and attack targets, and obtain the parsed attack chain data. Then, based on the parsed event data and the parsed attack chain data, the generation module can construct an event-attack chain correspondence. Establish a mapping association between a single event and its potential attack chain. Next, based on the event-attack chain correspondence, the generation module needs to analyze the asset impact scope of the target knowledge graph to obtain the set of affected assets. Using the semantic link relationship in the knowledge graph, it is possible to trace the affected asset entities. By evaluating the importance of the set of affected assets, the generation module can obtain a subset of important assets. Different assets have different degrees of importance to enterprise operations, and it is necessary to quantitatively evaluate their importance. According to the subset of important assets, the generation module can determine the list of alarm objects. The entity corresponding to the important asset is used as the alarm object. Then, the generation module needs to perform content normalization processing on the parsed event data to generate a standardized event description. A preset content template can be used to format the event information. At the same time, the generation module needs to perform content normalization processing on the parsed attack chain data to generate a standardized attack path description. Similarly, a preset content template is used to format the attack chain information.Next, the generation module needs to fuse the standardized event description and the standardized attack path description to generate an alarm content template. Integrate the event information and the attack chain information to form a complete alarm content template. Finally, the generation module needs to fuse the alarm object list with the alarm content template to generate the final real-time alarm information. Combine the alarm object with the alarm content to form high-quality and actionable real-time alarm information, providing a basis for timely response for security operation personnel.
[0050] An embodiment of the present invention also provides a security monitoring and alarm method for network security vulnerabilities, including: S201, collecting historical multi-source heterogeneous security data from multiple data sources, and preprocessing the historical multi-source heterogeneous security data to obtain an initial security data set, where the multi-source heterogeneous security data includes: asset information, network topology, security device logs, and vulnerability scan reports; S202, performing security entity extraction on the initial security data set to obtain a security entity data set, where the security entity data set includes: entity names, entity attributes, and entity relationships; S203, performing knowledge graph mapping according to the security entity data set to obtain a target knowledge graph; S204, collecting real-time network operation data from multiple data sources, and performing vulnerability detection on the target knowledge graph and the real-time network operation data through a preset gray wolf algorithm to obtain vulnerability detection data; S205, performing security event analysis on the vulnerability detection data to obtain security event data and attack chain data; S206, generating real-time alarm information according to the security event data and the attack chain data, and the real-time alarm information includes: alarm objects and alarm content.
[0051] Through the collaborative work of the above-mentioned various modules, the multi-source heterogeneous security data is intelligently processed and fused to construct a security knowledge base based on a knowledge graph, which can effectively capture and represent complex security semantic information. Through preprocessing, entity extraction, knowledge fusion and other links on heterogeneous data such as asset information, network topology, security device logs and vulnerability scan reports, a unified knowledge model covering security entities, attributes and relationships is formed;. Compared with traditional rule bases or pattern bases, knowledge graphs can express concepts, facts and logics in the security field more flexibly and comprehensively, helping to discover hidden threat associations and improving the accuracy and comprehensiveness of detection. By introducing intelligent algorithms such as the gray wolf optimization algorithm, intelligent vulnerability detection based on a knowledge graph is realized. The gray wolf algorithm simulates the behavior pattern of wolf packs. By deploying multiple detection agents in the knowledge graph and performing distributed detection according to optimization rules, potential vulnerability points and vulnerability clusters can be efficiently discovered. Compared with traditional rule matching or pattern matching methods, this algorithm has stronger adaptability and global search ability, can discover complex and multi-step vulnerability propagation paths, and improves the coverage rate and accuracy of vulnerability detection.
[0052] By combining vulnerability detection data with a knowledge graph and leveraging graph mining and semantic reasoning technologies, intelligent analysis of security events and attack chains is achieved. Using algorithms such as graph neural networks, vector representations of security entities and relationships can be learned to support similarity calculations and semantic reasoning. On this basis, through operations such as subgraph extraction and semantic path mining, a complete attack chain can be reconstructed to reveal the root cause and scope of influence of events, providing a comprehensive basis for risk assessment and decision-making responses. Compared with single-event analysis, it can discover hidden event correlations and improve the detection and analysis capabilities for complex attack behaviors. By finally intelligently fusing security event data and attack chain data, real-time alarm information is generated. Through links such as event parsing, attack path parsing, and asset impact analysis, the alarm object and alarm content can be accurately identified, improving the pertinence and operability of the alarm. Compared with traditional alarm methods, it can provide richer and more structured alarm information, including event type, severity level, attack steps, affected assets, etc., which helps security operation personnel quickly understand the threat situation and take targeted response measures.
[0053] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to the embodiments, those of ordinary skill in the art should understand that: modifications or equivalent substitutions can still be made to the specific implementation manners of the present invention, and any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered by the scope of the claims of the present invention.
Claims
1. A security monitoring and alarm device for network security vulnerabilities, characterized in that: include: A collection module is used to collect historical multi-source heterogeneous security data from multiple data sources, and pre-process the historical multi-source heterogeneous security data to obtain an initial security data set, wherein the multi-source heterogeneous security data includes: asset information, network topology, security device logs and vulnerability scanning reports; an extraction module is used to extract security entities from the initial security data set to obtain a security entity data set, wherein the security entity data set includes: entity name, entity attributes and entity relationship; a mapping module is used to perform knowledge graph mapping based on the security entity data set to obtain a target knowledge graph; a detection module is used to collect real-time network operation data from multiple data sources, and perform vulnerability detection on the target knowledge graph and the real-time network operation data through a preset gray wolf algorithm to obtain vulnerability detection data; an analysis module is used to perform security event analysis on the vulnerability detection data to obtain security event data and attack chain data; a generation module is used to generate real-time alarm information based on the security event data and attack chain data, and the real-time alarm information includes: alarm object and alarm content.
2. The security monitoring and alarm device for network security vulnerabilities according to claim 1 is characterized in that: The acquisition module is specifically used to: collect data from multiple data sources to obtain historical multi-source heterogeneous security data, wherein the multi-source heterogeneous security data includes: asset information, network topology, security equipment logs and vulnerability scanning reports; perform data deduplication processing on the historical multi-source heterogeneous security data to obtain deduplicated historical network operation data; perform data cleansing on the deduplicated historical network operation data to obtain cleaned historical network operation data; perform format conversion processing on the cleaned historical network operation data through regular expressions to obtain structured historical network operation data; perform key field extraction on the structured historical network operation data to obtain key field data; perform data desensitization processing on the key field data to obtain the initial security data set.
3. The security monitoring and alarm device for network security vulnerabilities according to claim 1 is characterized in that: The extraction module is specifically used to: perform named entity recognition processing on the initial security data set according to a preset named entity recognition rule to obtain preliminary security entity data; perform entity linking processing on the preliminary security entity data according to a preset entity linking rule to obtain linked security entity data; perform entity attribute recognition on the linked security entity data root according to a preset entity attribute recognition rule to obtain entity attribute data; perform entity relationship extraction processing on the linked security entity data to obtain entity relationship data; perform entity alias mapping processing on the entity attribute data and the entity relationship data to obtain normalized entity attribute data and entity relationship data; Performing data fusion processing on the linked security entity data, the normalized entity attribute data and the entity relationship data to obtain a security entity knowledge base; Performing entity classification processing on the security entity knowledge base to obtain a classified security entity data set; Performing attribute constraint checking on the classified security entity data set to obtain an attribute constraint security entity data set; Performing relational semantic analysis on the attribute-constrained security entity data set to obtain a relational semantic security entity data set; The relational semantic security entity data set is partitioned to obtain the entity name, the entity attribute and the entity relationship, and the entity name, the entity attribute and the entity relationship are merged into the security entity data set.
4. The security monitoring and alarm device for network security vulnerabilities according to claim 1 is characterized in that: The mapping module is specifically used to: perform ontology construction processing on the security entity data set to obtain ontology instance data; perform graph database construction processing on the ontology instance data to obtain a target graph database; import the ontology instance data into the target graph database to obtain a graph database instance; perform knowledge fusion processing on the graph database instance to obtain a fused graph database instance; perform knowledge representation learning processing on the fused graph database instance to obtain entity vector representation data and relationship vector representation data; perform graph structure optimization on the fused graph database instance to obtain an optimized graph database instance; perform knowledge reasoning on the optimized graph database instance to obtain a reasoning graph database instance; perform knowledge visualization processing on the reasoning graph database instance based on the entity vector representation data and the relationship vector representation data to obtain the target knowledge graph.
5. The security monitoring and alarm device for network security vulnerabilities according to claim 1 is characterized in that: The detection module is specifically used to: map the real-time network operation data to the target knowledge graph to obtain the mapped real-time network operation data; perform feature extraction on the mapped real-time network operation data to obtain a feature set of the real-time network operation data; Initialize the detection agent data of the gray wolf algorithm according to the real-time network operation data feature set, and distribute the detection agent data to different areas of the target knowledge graph as a gray wolf population; The gray wolf population performs vulnerability detection in the target knowledge graph according to the gray wolf optimization algorithm rules preset in the gray wolf algorithm; the detection path of the gray wolf population is monitored in real time to obtain vulnerability detection trajectory data; According to the vulnerability detection trajectory data, vulnerability points in the target knowledge graph are identified to obtain vulnerability point data; Performing cluster analysis on the vulnerability point data to obtain vulnerability cluster data; A severity assessment is performed on the vulnerability cluster data to obtain a vulnerability severity assessment result, and vulnerability detection data is generated based on the vulnerability severity assessment result.
6. The security monitoring and alarm device for network security vulnerabilities according to claim 1 is characterized in that: The analysis module is specifically used to: perform event extraction on the vulnerability detection data to obtain initial security event data; perform event normalization processing on the initial security event data to obtain standardized security event data; map the standardized security event data to the target knowledge graph to obtain mapped security event data; identify relevant vulnerability points, asset points and threat points in the target knowledge graph based on the mapped security event data to obtain relevant point data; perform subgraph extraction on the target knowledge graph based on the relevant point data to obtain event-related subgraphs; perform semantic path mining on the event-related subgraphs to obtain event semantic path data; reconstruct event attack chains based on the event semantic path data to obtain attack chain data; perform attack classification on the attack chain data to obtain classified attack chain data; Performing risk assessment on the classified attack chain data to obtain a risk assessment report as the security event data; fusing the risk assessment report with the attack chain data to generate a security event analysis report as the attack chain data.
7. The security monitoring and alarm device for network security vulnerabilities according to claim 6 is characterized in that: The generation module is specifically used to: perform event analysis on the security event data, extract key information such as event type and event severity level, and obtain analyzed event data; perform attack path analysis on the attack chain data, extract key information such as attack steps and attack targets, and obtain analyzed attack chain data; According to the parsed event data and the parsed attack chain data, an event-attack chain correspondence relationship is constructed; based on the event-attack chain correspondence relationship, an asset impact range analysis is performed on the target knowledge graph to obtain an affected asset set; Perform asset importance assessment on the affected asset set to obtain a subset of important assets; determine an alarm object list based on the subset of important assets; perform content normalization processing on the parsed event data to generate a standardized event description; perform content normalization processing on the parsed attack chain data to generate a standardized attack path description; perform content fusion on the standardized event description and the standardized attack path description to generate an alarm content template; perform data fusion on the alarm object list and the alarm content template to generate final real-time alarm information.
8. A security monitoring and alarm method for network security vulnerabilities, comprising: Collect historical multi-source heterogeneous security data from multiple data sources, and pre-process the historical multi-source heterogeneous security data to obtain an initial security data set, wherein the multi-source heterogeneous security data includes: asset information, network topology, security device logs and vulnerability scanning reports; extract security entities from the initial security data set to obtain a security entity data set, wherein the security entity data set includes: entity name, entity attributes and entity relationship; perform knowledge graph mapping based on the security entity data set to obtain a target knowledge graph; collect real-time network operation data from multiple data sources, perform vulnerability detection on the target knowledge graph and the real-time network operation data through a preset gray wolf algorithm to obtain vulnerability detection data; perform security event analysis on the vulnerability detection data to obtain security event data and attack chain data; generate real-time alarm information based on the security event data and attack chain data, and the real-time alarm information includes: alarm object and alarm content.
Citation Information
Cited By
Network security monitoring method and system based on dynamic vulnerability verification
CN120389908A
A network security monitoring method and system based on dynamic vulnerability verification
CN120389908B
Auxiliary decision-making method and system for safety operation center
CN120415879A
Low-delay network security detection method and system
CN120415923A
Computer network alarm system and method
CN120512304A