Network detection system and method based on network security
By constructing a network security feature vector and generating functions that change over time, combining risk prediction and compensation strategies, the problem of traditional network security detection being difficult to identify complex attacks and lacking a global perspective is solved, and overall control and efficient detection of network risks are achieved.
Patent Information
- Application Number
- CN202510243413.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-30
AI Technical Summary
Traditional network security detection methods are difficult to identify complex cyber attacks and new attack methods, and lack a global perspective, so they cannot effectively evaluate the spread range and degree of harm of network security risks.
The network traffic is filtered through the boundary firewall, the system log and user behavior data are collected, and after preprocessing, a network security feature vector and a function of generation of features change over time are constructed, the risk threshold is calculated, the time when the network security risk reaches the threshold is predicted, and a network security check task schedule is generated. At the same time, analyze network performance losses and inter-regional correlations, evaluate compensation capabilities, and formulate network performance compensation strategies.
The overall control of risks in various areas of the network is achieved. Through multi-source data processing, the disadvantages of manually analyzing massive data are avoided, and the accuracy and timeliness of network security detection are improved.
Smart Images

Figure CN120074937A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security detection, and in particular, to a network detection system and method based on network security. Background Art
[0002] With the acceleration of the digitalization process, the application of the network has become more and more in-depth in various fields such as enterprise operation and social life, and the importance of network security has become increasingly prominent. As a key link to ensure the stable operation of the network and information security, the accuracy, timeliness, and comprehensiveness of network security detection directly affect the normal operation of the network, the secure storage and transmission of data, and thus are related to the business continuity of enterprises, the security of user information, and the stable development of society.
[0003] However, traditional network security detection methods often face the following problems when dealing with an increasingly complex network environment, massive network data, and diverse attack methods: First, the detection process lacks intelligent means and it is difficult to detect complex network attacks. Traditional detection methods mainly match based on known attack characteristics and rules, and it is difficult to identify new, variant attack methods and abnormal behaviors hidden in a large amount of normal data. With the continuous evolution of network attack technologies, attack methods are becoming more and more complex and diverse. Attackers are good at using loopholes in network protocols and weaknesses in systems for covert attacks. Traditional methods cannot dig out potential security risks from the complex associations of massive data. When dealing with advanced persistent threats, the effectiveness of traditional detection methods is limited and it is difficult to detect long-term latent attack behaviors in a timely manner. Second, network security detection lacks a global perspective and does not comprehensively consider the correlations between different regions of the network and different business systems and their mutual impacts on network security, and cannot effectively evaluate the spread range and harm degree of network security risks. Summary of the Invention
[0004] The purpose of the present invention is to provide a network detection system and method based on network security to solve the problems raised in the prior art.
[0005] To achieve the above purpose, the present invention provides the following technical solution: A network detection method based on network security, the method includes the following steps:
[0006] Filter network traffic through a border firewall, collect system logs and user behavior data, and preprocess the data;
[0007] Obtain network security-related features from the preprocessed data, construct a network security feature vector according to the obtained features, and generate a function of network security features changing with time;
[0008] Calculate the derivative of the network security feature function, set the risk threshold, predict the moment when the network security risk reaches the threshold, calculate the risk prediction moment according to different regions, and generate a network security inspection task schedule;
[0009] By analyzing the performance metrics and frequency characteristics of the affected regions, calculate the network performance loss function, conduct correlation analysis with the performance frequency components of other regions, use principal component analysis to find potential inter-regional correlations, evaluate the compensation capabilities of each region, and formulate a network performance compensation strategy.
[0010] Deploy a border firewall in the secure area at the network boundary. For the data packets flowing through the firewall, filter them according to the security rules to obtain the filtered network traffic data. Among them, the security rules determine the security of the data packets by checking the source IP address, destination IP address, port number, and protocol type of the data packets. The network traffic data includes the number of data packets flowing through each node of the network, the data transmission rate, the source IP address, the destination IP address, the port number, and the protocol type information;
[0011] Collect system log information and user behavior data related to the network. Among them, the system log data includes login information, operation records, and error information, and the user behavior data includes operation frequency and access permissions. Count the number of logins within a specific time period through the system log interface, and use user behavior monitoring software to record the number of times users access resources with different permissions;
[0012] Preprocess the obtained data, including using the median filtering algorithm to remove random interference in the data, deleting duplicate and incorrect data records through data cleaning operations, and converting the data format into a unified format.
[0013] Obtain the characteristics related to the network traffic data, system log data, and user behavior data. Based on the calculated characteristics, construct a network security feature vector, and generate a function of the network security features changing over time based on this feature vector. The specific steps include:
[0014] For the network traffic data, take the set time window as the period, count the total traffic within this time period, and calculate the traffic proportion of different source IP addresses;
[0015] For the system log data, first filter out the log entries related to security (logs containing keywords such as "attack", "abnormal", "error"), and then count the number of times error information appears in the filtered logs within the time window, and calculate the frequency of error information appearance;
[0016] For the user behavior data, determine the list of the user's permission scope, and by monitoring the user's operation records, count the number of times the user accesses beyond their own permissions within the time window, and calculate the frequency of the user accessing beyond their own permissions;
[0017] Based on the above - mentioned calculation features, construct the network security feature vector S = [P 1 , P 2 ,..., P n , E, O], where P 1 , P 2 ,..., P n represent the traffic proportions of the 1st, 2nd,..., nth source IP addresses within the time window, E represents the frequency of the filtered error messages appearing in the system logs within the time window, and O represents the frequency of users accessing beyond their own permissions within the time window;
[0018] Taking the time interval as the period, generate the function F(t) of the network security features changing with time according to the constructed network security feature vector, where the function F(t) represents integrating the feature values changing with time through weighted summation.
[0019] Calculate the derivative of the network security feature function, set the risk threshold, and calculate the predicted time t risk when the network security risk reaches the threshold based on the current time, the preset risk threshold, the network security risk value at the current time, and the derivative parameter of the network security feature function at the current time. The calculation formula is as follows:
[0020]
[0021] where t risk represents the predicted time when the network security risk reaches the threshold, t 0 represents the current time, R threshold represents the preset risk threshold, R(t 0 ) represents the network security risk value at the current time t 0 , and F’(t 0 ) represents the derivative of the network security feature function at the current time. The risk threshold can be obtained from historical data;
[0022] Calculate the predicted time t risk,i when the risk reaches the threshold for different regions in the network respectively. Take the time when the risk reaches the threshold as the time for network security inspection or taking protection measures. Generate a network security inspection task schedule according to the calculated predicted time and the corresponding region identifier, where i represents the i - th region.
[0023] When it is detected that the network security risk in the \(i\)-th area reaches the threshold, the performance indicators related to the affected area are separated from the overall network performance indicators. Through the analysis of historical data and the combination of real-time monitoring data, the frequency characteristics of the performance indicators related to the affected area in the normal state are obtained. The frequency domain transformation is performed on the overall network performance indicators to separate the frequency components related to the affected area, and then the inverse transformation is performed to obtain the function \(G(t)\) of the network performance loss and time after the security problem appears in this area. Among them, the performance indicators related to the affected area include the traffic of the attacked subnet and the response time of the specific business system. The frequency characteristics of the performance indicators related to the affected area in the normal state include the fluctuation frequency of the normal traffic and the change frequency of the response time;
[0024] Number the other areas except the affected area, and obtain the corresponding frequency components according to the performance indicators during normal operation, denoted as the set \(D = \{f 1 , f 2 , \cdots, f m , \cdots, f z \}, where \(z\) represents the number of the remaining areas, and \(f m \) represents the frequency component corresponding to the area numbered \(m\). Among them, the performance indicators during normal operation include normal traffic and response time;
[0025] Regarding the network performance loss situation of the affected area reflected by the function \(G(t)\), conduct a correlation analysis with the frequency components of each area in the set \(D\). Use principal component analysis to find the potential correlation between the affected area and other areas. Based on the analysis results, consider the remaining network resources, performance elasticity, and performance indicator matching degree of each area, and calculate the comprehensive compensation ability index through weighted calculation. Set the evaluation criteria and thresholds, screen out the key compensation areas, and formulate an overall performance compensation strategy covering traffic scheduling, service load balancing, and resource allocation priority according to the proportion of the comprehensive compensation ability index of each area. When implementing the compensation strategy, real-time monitor the network performance indicators of the affected area and the participating compensation areas, and use the feedback control mechanism to dynamically adjust the compensation task allocation according to the monitoring data.
[0026] A network detection system based on network security, the system includes a data acquisition module, a security feature analysis module, a security task planning module and a compensation module. The data acquisition module is used to filter network traffic through a border firewall, collect system logs and user behavior data, and preprocess the data. The security feature analysis module is used to obtain features related to network security from the preprocessed data, construct a network security feature vector according to the obtained features, and generate a function of network security features changing with time. The security task planning module is used to calculate the derivative of the network security feature function, set a risk threshold, predict the moment when the network security risk reaches the threshold, calculate the risk prediction moment according to different regions, and generate a network security inspection task schedule. The compensation module is used to calculate the network performance loss function by analyzing the performance indicators and frequency characteristics of the affected regions, conduct correlation analysis with the performance frequency components of other regions, evaluate the compensation capabilities of each region, and formulate a network performance compensation strategy.
[0027] The data acquisition module includes a network traffic collection unit, a system log collection unit, a user behavior monitoring unit and a preprocessing unit. The network traffic collection unit is used to deploy a border firewall in the secure area of the network boundary, filter the data packets flowing through the firewall according to security rules, and obtain the filtered network traffic data. The system log collection unit is used to collect system log data related to network security, including login information, operation records and error information. The user behavior monitoring unit is used to record the behavior data of users, including access permissions and operation records. The preprocessing unit is used to preprocess the obtained data, including using a median filtering algorithm to remove random interference in the data, deleting duplicate and incorrect data records through data cleaning operations, and converting the data format into a unified format.
[0028] The security feature analysis module includes a feature extraction unit and a network security risk prediction unit. The feature extraction unit is used to obtain features related to network traffic data, system log data and user behavior data. The network security risk prediction unit is used to comprehensively extract the features, construct a network security feature vector, and integrate the time-varying feature values by weighted summation at a time interval as a cycle to generate a function of network security features changing with time.
[0029] The security task planning module includes a risk calculation unit and a task planning unit. The risk calculation unit is used to predict the moment when the network security risk reaches the threshold according to the network security feature function and its derivative. The task planning unit is used to calculate the predicted moment when the risk reaches the threshold for different regions in the network, take the moment when the risk reaches the threshold as the moment when network security inspection or protective measures need to be taken, and generate a network security inspection task schedule according to the predicted moment and the corresponding region identifier.
[0030] The compensation module includes a performance analysis unit, a regional association compensation ability evaluation unit, and a compensation strategy formulation unit. The performance analysis unit is used to, when detecting that the network security risk of a region reaches a threshold, separate the performance indicators related to the affected region from the overall network performance indicators, combine historical data and real-time monitoring data, obtain the frequency characteristics of the performance indicators related to the affected region in the normal state, and obtain the function G(t) of the network performance loss and time after a security problem occurs in this region through frequency domain transformation and inverse transformation; the regional association compensation ability evaluation unit is used to number the other regions except the affected region, obtain the corresponding frequency components according to the performance indicators during normal operation, denoted as set D, conduct a correlation analysis on the network performance loss situation of the affected region reflected by the function G(t) and the frequency components of each region in set D, use principal component analysis to find the potential association between the affected region and other regions, consider the remaining network resources, performance elasticity, and performance index matching degree of each region, calculate the comprehensive compensation ability index through weighted calculation, set the evaluation criteria and thresholds, and screen out the key compensation regions; the compensation strategy formulation unit is used to formulate an overall performance compensation strategy covering traffic scheduling, service load balancing, and resource allocation priority according to the proportion of the comprehensive compensation ability index of each region. When implementing the compensation strategy, it monitors the network performance indicators of the affected region and the participating compensation regions in real time, and uses a feedback control mechanism to dynamically adjust the compensation task allocation according to the monitoring data.
[0031] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0032] 1. During the detection process, the present invention not only focuses on the security risks of individual regions, but also calculates the predicted moments when the risks of different regions in the network reach the threshold respectively, and generates a network security inspection task arrangement table, realizing the overall control of the risks of each region in the network;
[0033] 2. By constructing a network security feature vector and generating a function that changes with time, the multi-source data of network traffic, system logs, and user behavior are transformed into representative feature information, realizing the processing of the original data and avoiding the disadvantages of simply relying on manual experience to analyze massive data. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 It is a schematic flowchart of a network detection method based on network security of the present invention;
[0035] Figure 2 It is a schematic structural diagram of a network detection system based on network security of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0036] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0037] In the embodiment: As Figure 1 - Figure 2 shown, the present invention provides a technical solution, a network detection method based on network security, and the method includes the following steps:
[0038] Filter network traffic through the border firewall, collect system logs and user behavior data, and preprocess the data;
[0039] Obtain features related to network security from the preprocessed data, construct a network security feature vector according to the obtained features, and generate a function of network security features changing with time;
[0040] Calculate the derivative of the network security feature function, set a risk threshold, predict the moment when the network security risk reaches the threshold, calculate the risk prediction moment according to different regions, and generate a network security inspection task schedule;
[0041] By analyzing the performance indicators and frequency characteristics of the affected regions, calculate the network performance loss function, conduct correlation analysis with the performance frequency components of other regions, use principal component analysis to find potential inter-regional associations, evaluate the compensation capabilities of each region, and formulate a network performance compensation strategy.
[0042] Deploy a border firewall in the secure area at the network boundary. For the data packets flowing through the firewall, filter them according to the security rules to obtain the filtered network traffic data. Among them, the security rules determine their security by checking the source IP address, destination IP address, port number, and protocol type of the data packets. The network traffic data includes the number of data packets flowing through each node of the network, the data transmission rate, the source IP address, the destination IP address, the port number, and the protocol type information;
[0043] Collect system log information and user behavior data related to the network. Among them, the system log data includes login information, operation records, and error information. The user behavior data includes operation frequency and access rights. Count the number of logins within a specific time period through the system log interface, and use user behavior monitoring software to record the number of accesses by users to resources with different permissions;
[0044] Preprocess the obtained data, including using the median filtering algorithm to remove random interference in the data, deleting duplicate and incorrect data records through data cleaning operations, and converting the data format into a unified format.
[0045] Specifically, for a medium-sized enterprise network that contains multiple subnets for different business departments such as the sales department, R & D department, and finance department. There is a border firewall in the network to isolate the enterprise internal network from the external network. At the same time, multiple servers are deployed to host the enterprise's business systems. At the border firewall, a collection period of every 5 minutes is set, and the network traffic data collected is as follows: The number of data packets flowing through each node of the network: within the first 5 minutes, the number of data packets is 5000; within the second 5 minutes, the number of data packets is 5500; Data transfer rate: within the first 5 minutes, the average transfer rate is 10 Mbps; within the second 5 minutes, the average transfer rate is 12 Mbps; Source IP address, destination IP address, port number, and protocol type information: It is found that there are data packets from the external IP address 192.168.1.100 accessing the enterprise internal server 10.0.0.10 through port 80 using the HTTP protocol; within a day, the system log records 100 login messages, among which there are 5 login failure records. The operation records show that a user frequently attempts to access the unauthorized financial data module. In the error messages, there are 10 database connection errors; through the user behavior monitoring software, it is found that an employee in the sales department accesses the R & D department's materials beyond their own authority 5 times within one hour.
[0046] Obtain the characteristics related to network traffic data, system log data, and user behavior data. Based on the calculated characteristics, construct a network security feature vector. Based on this feature vector, generate a function of the network security features changing over time. The specific steps include:
[0047] For the network traffic data, with the set time window as the period, count the total traffic within this time period, and calculate the traffic proportion of different source IP addresses;
[0048] For the system log data, first filter out the log entries related to security (logs containing keywords such as "attack", "abnormal", "error"), and then count the number of times error messages appear in the filtered logs within the time window, and calculate the frequency of error messages appearing;
[0049] For the user behavior data, determine the list of the user's permission scope. By monitoring the user's operation records, count the number of times the user accesses beyond their own authority within the time window, and calculate the frequency of the user accessing beyond their own authority;
[0050] Integrate the above calculated characteristics to construct a network security feature vector S = [P 1 ,P 2 ,...,P n ,E,O], where P 1 ,P 2 ,...,P nIt represents the traffic proportion of the 1st, 2nd, …, nth source IP addresses within the time window. E represents the occurrence frequency of the filtered error messages in the system logs within the time window. O represents the access frequency of users exceeding their own permissions within the time window;
[0051] Taking the time interval as the period, according to the constructed network security feature vector, a function F(t) of network security features changing with time is generated. Among them, the function F(t) represents the integration of the feature values changing with time through weighted summation.
[0052] Specifically, taking 1 hour as the time window, the total traffic within this time period is counted as 60,000 data packets. The traffic proportion of different source IP addresses is calculated, and it is found that the traffic proportion of the external IP address 192.168.1.100 reaches 20%; the system log entries containing the keyword “error” are filtered out. Within 1 hour, the error messages appear 8 times in such logs, and the occurrence frequency of the error messages is calculated as 0.13 times per minute; it is determined that the employee's permission scope does not include accessing the R & D department's materials. Within 1 hour, the number of times the employee exceeds their own permissions is 5 times, and the access frequency of exceeding their own permissions is calculated as 0.08 times per minute; a network security feature vector S = [0.2, 0.13, 0.08] is constructed. Taking 1 hour as the time interval, a function F(t) of network security features changing with time is generated through weighted summation (setting the weights to 0.5, 0.3, and 0.2 respectively). At the moment t, F(t) = 0.5×0.2 + 0.3×0.13 + 0.2×0.08 = 0.155.
[0053] Calculate the derivative of the network security feature function, set the risk threshold, and calculate the predicted moment t when the network security risk reaches the threshold based on the current moment, the preset risk threshold, the network security risk value at the current moment, and the derivative parameter of the network security feature function at the current moment risk , and the calculation formula is as follows:
[0054]
[0055] Among them, t risk represents the predicted moment when the network security risk reaches the threshold, t 0 represents the current moment, R threshold represents the preset risk threshold, R(t 0 ) represents the network security risk value at the current moment t 0 The network security risk value, F’(t 0 ) represents the derivative of the network security feature function at the current moment, and the risk threshold can be obtained from historical data;
[0056] Calculate the predicted moment t when the risk reaches the threshold for different regions in the network respectively risk,i, take the moment when the risk reaches the threshold as the moment when network security inspection or protective measures need to be taken, and generate a network security inspection task schedule according to the calculated prediction moment and the corresponding area identifier, where i represents the i-th area.
[0057] Specifically, by analyzing historical data, set the risk threshold R threshold to be 0.3, and the network security risk value R(t 0 ) at the current moment t 0 = 10:00 is 0.155, and the derivative F ’ (t 0 ) of the network security characteristic function at the current moment is calculated to be 0.01. Calculate the predicted moment t risk when the network security risk reaches the threshold according to the predicted moment calculation formula of the network security risk reaching the threshold, which is 10:14:30; calculate the predicted moments when the risk reaches the threshold for areas such as the sales department, R & D department, and finance department in the network respectively. It is found that the predicted moment of the sales department is the earliest, which is 10:14:30. Generate a network security inspection task schedule according to this predicted moment and the area identifier, and arrange a key security inspection for the sales department network at 10:14.
[0058] When it is detected that the network security risk in the i-th area reaches the threshold, separate the performance indicators related to the affected area from the overall network performance indicators. By analyzing historical data and combining real-time monitoring data, obtain the frequency characteristics of the performance indicators related to the affected area in the normal state. Perform a frequency domain transformation on the overall network performance indicators, separate the frequency components related to the affected area, and then perform an inverse transformation to obtain the function G(t) of the network performance loss and time after a security problem occurs in this area. Among them, the performance indicators related to the affected area include the traffic of the attacked subnet and the response time of specific business systems, and the frequency characteristics of the performance indicators related to the affected area in the normal state include the fluctuation frequency of normal traffic and the change frequency of response time;
[0059] Number the other areas except the affected area, and obtain the corresponding frequency components according to the performance indicators during normal operation, denoted as the set D = {f 1 , f 2 ,..., f m ,..., f z}, where z represents the number of the remaining areas, and f m represents the frequency component corresponding to the area numbered m. Among them, the performance indicators during normal operation include normal traffic and response time;
[0060] For the network performance loss of the affected area reflected by the function G(t), conduct a correlation analysis with the frequency components of each area in the set D. Use principal component analysis to find the potential correlations between the affected area and other areas. Based on the analysis results, consider the remaining network resources, performance elasticity, and performance index matching degree of each area. Calculate the comprehensive compensation ability index through weighted calculation, set the evaluation criteria and thresholds, screen out the key compensation areas, and formulate an overall performance compensation strategy covering traffic scheduling, service load balancing, and resource allocation priorities according to the proportion of the comprehensive compensation ability index of each area. When implementing the compensation strategy, monitor the network performance indicators of the affected area and the participating compensation areas in real time, and use the feedback control mechanism to dynamically adjust the compensation task allocation according to the monitored data.
[0061] Specifically, when checking the sales department network at 10:14, it is found that the network security risk in this area reaches the threshold. Separate the performance indicators related to the sales department from the overall network performance indicators: the traffic of the attacked subnet has suddenly increased by 50% in the past 10 minutes, and the response time of a specific business system (CRM system) has extended from an average of 2 seconds to 5 seconds. Through the analysis of historical data and combined with real-time monitoring data, obtain the fluctuation frequency of the normal traffic of the sales department as 100 - 150 packets per minute, and the change frequency of the response time is an average fluctuation of 0.5 seconds per hour. Perform a frequency domain transformation on the overall network performance indicators, separate the frequency components related to the sales department, and then perform an inverse transformation to obtain the function G(t) of the network performance loss of the sales department after a security problem occurs over time. Number the other 4 areas except the sales department, and obtain the corresponding frequency components according to the performance indicators during normal operation, denoted as the set D. According to the frequency component f of the R & D department 1 It shows that its normal traffic fluctuation frequency is 80 - 120 packets per minute, and the change frequency of the response time is an average fluctuation of 0.3 seconds per hour. Conduct a correlation analysis between the network performance loss of the sales department reflected by the function G(t) and the frequency components of each area in the set D. Use principal component analysis to find the potential correlations between the sales department and the R & D department in terms of traffic and response time. Consider the remaining network resources, performance elasticity, and performance index matching degree of each area. Calculate the comprehensive compensation ability index of each area through weighted calculation, and obtain that the comprehensive compensation ability index of the R & D department is the highest. According to the proportion of the comprehensive compensation ability index of each area, formulate an overall performance compensation strategy, and decide to schedule some non-critical business traffic of the sales department to the R & D department for processing. At the same time, adjust the service load balancing and forward some requests of the CRM system to the backup server of the R & D department. When implementing the compensation strategy, monitor the network performance indicators of the sales department and the R & D department in real time: the traffic of the sales department, the response time of the CRM system, and the resource utilization rate of the R & D department, etc. Use the feedback control mechanism to dynamically adjust the compensation task allocation according to the monitored data. When it is found that the resource utilization rate of the R & D department is too high, reduce the traffic and service requests scheduled from the sales department.
[0062] A network detection system based on network security, the system includes a data acquisition module, a security feature analysis module, a security task planning module and a compensation module. The data acquisition module is used to filter network traffic through a border firewall, collect system logs and user behavior data, and preprocess the data. The security feature analysis module is used to obtain features related to network security from the preprocessed data, construct a network security feature vector based on the obtained features, and generate a function of network security features changing with time. The security task planning module is used to calculate the derivative of the network security feature function, set a risk threshold, predict the moment when the network security risk reaches the threshold, calculate the risk prediction moment according to different regions, and generate a network security inspection task schedule. The compensation module is used to calculate the network performance loss function by analyzing the performance indicators and frequency characteristics of the affected regions, conduct correlation analysis with the performance frequency components of other regions, evaluate the compensation capabilities of each region, and formulate a network performance compensation strategy.
[0063] The data acquisition module includes a network traffic collection unit, a system log collection unit, a user behavior monitoring unit and a preprocessing unit. The network traffic collection unit is used to deploy a border firewall in the secure area at the network boundary, filter the data packets flowing through the firewall according to security rules, and obtain the filtered network traffic data. The system log collection unit is used to collect system log data related to network security, including login information, operation records and error information. The user behavior monitoring unit is used to record the behavior data of users, including access permissions and operation records. The preprocessing unit is used to preprocess the obtained data, including using a median filtering algorithm to remove random interference in the data, deleting duplicate and incorrect data records through data cleaning operations, and converting the data format into a unified format.
[0064] The security feature analysis module includes a feature extraction unit and a network security risk prediction unit. The feature extraction unit is used to obtain features related to network traffic data, system log data and user behavior data. The network security risk prediction unit is used to comprehensively extract the features, construct a network security feature vector, and integrate the time-varying feature values through weighted summation at a time interval as a period, and generate a function of network security features changing with time.
[0065] The security task planning module includes a risk calculation unit and a task planning unit. The risk calculation unit is used to predict the moment when the network security risk reaches the threshold according to the network security feature function and its derivative. The task planning unit is used to calculate the predicted moment when the risk reaches the threshold for different regions in the network respectively, use the moment when the risk reaches the threshold as the moment when network security inspection or protective measures need to be taken, and generate a network security inspection task schedule according to the predicted moment and the corresponding region identifier.
[0066] The compensation module includes a performance analysis unit, a regional association compensation ability evaluation unit, and a compensation strategy formulation unit. The performance analysis unit is used to, when detecting that the network security risk of a region reaches a threshold, separate the performance indicators related to the affected region from the overall network performance indicators, combine historical data and real-time monitoring data, obtain the frequency characteristics of the performance indicators related to the affected region in a normal state, and obtain the function G(t) of the network performance loss and time after a security problem occurs in this region through frequency domain transformation and inverse transformation. The regional association compensation ability evaluation unit is used to number the other regions except the affected region, obtain the corresponding frequency components according to the performance indicators during normal operation, denoted as set D, conduct a correlation analysis on the network performance loss situation of the affected region reflected by the function G(t) and the frequency components of each region in set D, use principal component analysis to find the potential association between the affected region and other regions, consider the remaining network resources, performance elasticity, and performance indicator matching degree of each region, calculate the comprehensive compensation ability index through weighted calculation, set the evaluation criteria and thresholds, and screen out the key compensation regions. The compensation strategy formulation unit is used to formulate an overall performance compensation strategy covering traffic scheduling, service load balancing, and resource allocation priority according to the proportion of the comprehensive compensation ability index of each region. When implementing the compensation strategy, it monitors the network performance indicators of the affected region and the regions participating in the compensation in real time, and uses a feedback control mechanism to dynamically adjust the compensation task allocation according to the monitoring data.
[0067] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present invention. Any reference signs in the claims should not be regarded as limiting the claims involved.
Claims
1. A network detection method based on network security, characterized in that: The method comprises the following steps: Filter network traffic through border firewalls, collect system logs and user behavior data, and pre-process the data; Obtain network security-related features from the preprocessed data, construct a network security feature vector based on the acquired features, and generate a function of network security features changing over time; Calculate the derivative of the network security characteristic function, set the risk threshold, predict the time when the network security risk reaches the threshold, calculate the risk prediction time according to different areas, and generate a network security inspection task schedule; By analyzing the performance indicators and frequency characteristics of the affected areas, calculating the network performance loss function, and performing correlation analysis with the performance frequency components of other areas, the compensation capacity of each area is evaluated and a network performance compensation strategy is formulated.
2. A network detection method based on network security according to claim 1, characterized in that: Deploy a border firewall in the security area at the network boundary, filter the data packets passing through the firewall according to the security rules, and obtain the filtered network traffic data. The security rules determine the security of the data packet by checking its source IP address, destination IP address, port number and protocol type; Collect network-related system log information and user behavior data, where system log data includes login information, operation records, and error information, and user behavior data includes operation frequency and access rights; The acquired data is preprocessed, and the median filtering algorithm is used to remove random interference in the data. Through data cleaning operations, duplicate and erroneous data records are deleted, and the data format is converted into a unified format.
3. A network detection method based on network security according to claim 2, characterized in that: Obtain the features related to network traffic data, system log data, and user behavior data, and construct a network security feature vector based on the calculated features. Based on the feature vector, generate a function of how the network security features change over time. The specific steps include: For network traffic data, the total traffic within the set time window is counted, and the traffic proportion of different source IP addresses is calculated; For system log data, first filter out security-related log entries, then count the number of times error messages appear in the filtered logs within the time window, and calculate the frequency of error messages. For user behavior data, determine the user's permission range list, monitor the user's operation records, count the number of times the user exceeds his or her permission within the time window, and calculate the frequency of the user's access exceeding his or her permission; Combining the above calculation features, we construct a network security feature vector S = [P1, P2, ..., P n ,E,O], where P1,P2,...,P n It represents the traffic proportion of the 1st, 2nd, ..., nth source IP addresses in the time window, E represents the frequency of error messages filtered in the system log in the time window, and O represents the frequency of users exceeding their own permissions in the time window; Taking the time interval as a period, a function F(t) of network security feature changing over time is generated according to the constructed network security feature vector, wherein the function F(t) represents the integration of feature values changing over time by weighted summation.
4. A network detection method based on network security according to claim 3, characterized in that: Calculate the derivative of the network security characteristic function, set the risk threshold, and calculate the predicted time t when the network security risk reaches the threshold based on the current time, the preset risk threshold, the network security risk value at the current time, and the derivative parameter of the network security characteristic function at the current time. risk ; Calculate the predicted time t when the risk reaches the threshold for different areas in the network risk,i , the moment when the risk reaches the threshold is taken as the moment when network security inspection or protective measures need to be taken. According to the calculated predicted time and the corresponding area identification, a network security inspection task schedule is generated, where i represents the i-th area.
5. A network detection method based on network security according to claim 4, characterized in that: When it is detected that the network security risk of the i-th area reaches the threshold, the performance indicators related to the affected area are separated from the overall network performance indicators. By analyzing the historical data and combining the real-time monitoring data, the frequency characteristics of the performance indicators related to the affected area in the normal state are obtained. The overall network performance indicators are transformed in the frequency domain to separate the frequency components related to the affected area, and then the inverse transformation is performed to obtain the function G(t) of the network performance loss and time after the security problem occurs in the area, where the performance indicators related to the affected area include the traffic of the attacked subnet and the response time of the specific business system, and the frequency characteristics of the performance indicators related to the affected area in the normal state include the fluctuation frequency of the normal traffic and the change frequency of the response time; The other areas except the affected area are numbered, and the corresponding frequency components are obtained according to the performance indicators during normal operation, which are recorded as a set D = {f1, f2, ..., f m ,...,f z }, where z represents the number of remaining regions, and f m represents the frequency component corresponding to the region numbered m, where the performance indicators during normal operation include normal flow and response time; The network performance loss of the affected area reflected by the function G(t) is analyzed in correlation with the frequency components of each area in the set D. The principal component analysis is used to find the potential correlation between the affected area and other areas. Based on the analysis results, the remaining network resources, performance elasticity and performance index matching of each area are considered. The comprehensive compensation capability index is obtained through weighted calculation. The evaluation criteria and thresholds are set to screen out the key compensation areas. According to the proportion of the comprehensive compensation capability index of each area, an overall performance compensation strategy covering traffic scheduling, business load balancing and resource allocation priority is formulated. When the compensation strategy is implemented, the network performance indicators of the affected area and the area participating in the compensation are monitored in real time. The feedback control mechanism is used to dynamically adjust the compensation task allocation according to the monitoring data.
6. A network detection system based on network security, characterized in that: The system includes a data acquisition module, a security feature analysis module, a security task planning module and a compensation module. The data acquisition module is used to filter network traffic through a border firewall, collect system logs and user behavior data, and pre-process the data; the security feature analysis module is used to obtain features related to network security from the pre-processed data, construct a network security feature vector based on the acquired features, and generate a function of network security features changing over time; the security task planning module is used to calculate the derivative of the network security feature function, set a risk threshold, predict the moment when the network security risk reaches the threshold, calculate the risk prediction moment based on different areas, and generate a network security inspection task schedule; the compensation module is used to calculate the network performance loss function by analyzing the performance indicators and frequency characteristics of the affected area, perform correlation analysis with the performance frequency components of other areas, evaluate the compensation capacity of each area, and formulate a network performance compensation strategy.
7. A network detection system based on network security according to claim 6, characterized in that: The data acquisition module includes a network flow acquisition unit, a system log acquisition unit, a user behavior monitoring unit and a preprocessing unit. The network flow acquisition unit is used to deploy a border firewall in a secure area at the network boundary, filter the data packets passing through the firewall according to security rules, and obtain the filtered network flow data; The system log collection unit is used to collect system log data related to network security, including login information, operation records and error information; The user behavior monitoring unit is used to record the user's behavior data, including access rights and operation records; the preprocessing unit is used to preprocess the acquired data, use a median filtering algorithm to remove random interference in the data, delete duplicate and erroneous data records through data cleaning operations, and convert the data format into a unified format.
8. A network detection system based on network security according to claim 7, characterized in that: The security feature analysis module includes a feature extraction unit and a network security risk prediction unit, wherein the feature extraction unit is used to obtain features related to network traffic data, system log data and user behavior data; The network security risk prediction unit is used to comprehensively extract the features, construct a network security feature vector, and integrate the feature values that change over time by weighted summation with a time interval as a period, to generate a function of network security features that change over time.
9. A network detection system based on network security according to claim 8, characterized in that: The security task planning module includes a risk calculation unit and a task planning unit. The risk calculation unit is used to predict the moment when the network security risk reaches a threshold based on the network security characteristic function and its derivative; the task planning unit is used to calculate the predicted moment when the risk reaches the threshold for different areas in the network, and use the moment when the risk reaches the threshold as the moment when network security inspection is required or protective measures are required, and generate a network security inspection task schedule according to the predicted moment and the corresponding area identifier.
10. A network detection system based on network security according to claim 9, characterized in that: The compensation module includes a performance analysis unit, a regional associated compensation capability evaluation unit and a compensation strategy formulation unit. The performance analysis unit is used to separate the performance indicators related to the affected area from the overall network performance indicators when it is detected that the network security risk of the area reaches a threshold, and to obtain the frequency characteristics of the relevant performance indicators of the affected area under normal conditions by combining historical data and real-time monitoring data. The function G(t) of the network performance loss and time after the security problem occurs in the area is obtained through frequency domain transformation and inverse transformation; the regional associated compensation capability evaluation unit is used to number the other areas except the affected area, obtain the corresponding frequency components according to the performance indicators during normal operation, record them as set D, and represent the frequency components reflected by the function G(t) The network performance loss in the affected area is analyzed in correlation with the frequency components of each area in the set D, and the principal component analysis is used to find the potential correlation between the affected area and other areas. The network resource surplus, performance elasticity and performance index matching degree of each area are considered, and the comprehensive compensation capability index is obtained through weighted calculation. The evaluation criteria and thresholds are set to screen out the key compensation areas; the compensation strategy formulation unit is used to formulate an overall performance compensation strategy covering traffic scheduling, business load balancing and resource allocation priority according to the proportion of the comprehensive compensation capability index of each area. When the compensation strategy is implemented, the network performance indicators of the affected area and the area participating in the compensation are monitored in real time, and the feedback control mechanism is used to dynamically adjust the compensation task allocation according to the monitoring data.