Network security alarm processing method and system
By constructing an improved Bayesian game model in the network security alarm processing method and introducing an uncertainty reasoning mechanism, combined with a dynamic hierarchical algorithm, the problems of inaccurate hierarchy and low resource allocation efficiency in the existing technology are solved, and more efficient and accurate threat identification and response are achieved.
Patent Information
- Application Number
- CN202510135347.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-06-03
AI Technical Summary
The existing network threat alarm grading methods have problems such as high false alarm rates and missed response rates, difficulty in adapting to real-time changes, and ignoring context information of threat behavior in dynamic network environments, resulting in inaccurate grading results and low resource allocation efficiency.
A network security alarm processing method is proposed. By collecting real-time security data, improving Bayesian game model is constructed, uncertainty reasoning mechanism for attacker behavior is introduced, optimized alarm strategy collection is generated, and threats are graded through dynamic hierarchical algorithms to optimize resource allocation.
It significantly improves the accuracy of alarm grading and system robustness, reduces the resource usage of low-priority events, and reduces the response time of critical threats by more than 30%.
Smart Images

Figure CN120090820A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a network security alarm processing method and system. Background Art
[0002] With the rapid development of network technology and the in-depth application of informatization, the network environment has become increasingly complex, and network security issues have become more prominent. In the dynamic network environment, various threat behaviors emerge in an endless stream, posing higher requirements for the real-time response ability of the network security system. As an important part of the network security system, the accuracy and timeliness of network threat alarm classification are directly related to the effectiveness of security defense. However, there are still many problems in the existing technology for dynamic network threat alarm classification.
[0003] Currently, the mainstream network threat alarm classification methods usually rely on static rules or simple threshold settings, and classify threats fixedly according to network traffic characteristics, event logs, and the triggering situation of alarm rules. The advantages of such methods are relatively simple implementation and high computational efficiency. However, they expose significant limitations in the dynamic network environment. On the one hand, the behavior patterns of attackers are highly uncertain and adversarial. They often change their strategies to avoid detection by static rules, resulting in high false alarm rates and missed alarm rates of existing methods. On the other hand, static rules lack the ability of dynamic adjustment, are difficult to adapt to the real-time changes of the network environment, and cannot capture the evolution trend of potential threats in a timely manner. In addition, most of the existing classification methods ignore the context information of threat behaviors and cannot effectively distinguish the true risk levels of events, resulting in problems such as overly single alarm classification results or excessive redundant alarms.
[0004] In recent years, some threat detection methods based on artificial intelligence and machine learning have gradually been applied to the field of network security. Machine learning methods perform pattern recognition and prediction of threat behaviors in a data-driven manner and have a certain degree of adaptability. However, the application is mainly concentrated in the threat detection stage, and traditional classification rules are still used for the classification and management of threat alarms, lacking dynamics. In addition, the existing machine learning-based methods still have deficiencies in dealing with complex attack chains, adversarial behaviors, and uncertain threats, especially in the aspects of real-time response and optimization of resource allocation strategies, there is no effective solution.
[0005] Therefore, there is an urgent need for an innovative network threat alarm classification method that can combine the adversarial behaviors and uncertain inferences of threats in a dynamic network environment to achieve efficient threat recognition, classification, and resource scheduling, so as to make up for the deficiencies of the existing technology. Summary of the Invention
[0006] An object of the present invention is to provide a network security alarm processing method and system, which significantly improves the accuracy of alarm classification and the robustness of system operation.
[0007] A network security alarm processing method according to an embodiment of the present invention includes the following steps:
[0008] S1. Collect real-time security data sets in the network environment, and preprocess the real-time security data sets to generate security feature data sets for analysis;
[0009] S2. Construct an improved Bayesian game model for attackers and defenders based on the security feature data sets;
[0010] S3. Introduce an uncertainty reasoning mechanism for attacker behavior into the improved Bayesian game model, and generate an optimized alarm strategy set for the defender based on the probability distribution of the attacker's strategy space;
[0011] S4. Combine the optimized alarm strategy set and the real-time network environment to construct a dynamic classification algorithm, divide network threats into multiple levels according to severity, generate classification thresholds based on threats of different levels, and perform alarm classification on security events in the security feature data sets through the dynamic classification algorithm;
[0012] S5. According to the alarm classification results, preferentially process alarm events of high-risk levels, allocate defense resources, and record relevant data of alarm classification;
[0013] S6. Combine the classified alarm events to remove low-risk or duplicate alarm events, optimize the output of alarm results, and push the optimized alarm classification results.
[0014] Optionally, the S1 includes the following steps:
[0015] S11. Collect the real-time security data set D in the network environment raw :
[0016] D raw ={L flow , R event , A ids}:
[0017] Among them, L flow represents the traffic data collected from the network interface within a unit time, including the source address, destination address, port number, protocol type, and traffic size of the traffic packet, R event represents the security event log generated by the network device, including the event type, event timestamp, and event description, A ids represents the alarm record generated by the intrusion detection system, including the alarm level, trigger rule, and associated context information;
[0018] S12. For the real-time security dataset D raw Remove duplicate network traffic records in the data, correct or delete security event records with missing key fields, filter out invalid alarm data, and the judgment condition is that the alarm level is the lowest and there is no associated context information, and generate the cleaned real-time security dataset D clean ;
[0019] S13. For the cleaned real-time security dataset D clean Perform feature extraction and feature fusion to generate a unified security feature dataset D feature :
[0020] D feature ={F flow ,F event ,F ids};
[0021] Among them, F flow is the feature vector extracted from the network traffic log, F event is the feature matrix extracted from the security event record, and F ids is the feature vector extracted from the intrusion detection system alarm data.
[0022] Optionally, the S2 includes the following steps:
[0023] S21. Based on the security feature dataset D feature Construct a Bayesian game model, and define the strategy sets and payoff functions of the attacker and the defender;
[0024] The strategy set of the defender is S def ={s 1 ,s 2 ,…,s m} and represents the response strategies of the defender under different alarm rules;
[0025] The strategy set of the attacker is S att ={a 1 ,a 2 ,…,a n} and represents the evasion or direct attack strategies adopted by the attacker;
[0026] The payoff functions are U def (s i ,a j ) and U att (s i ,a j ), which respectively represent the payoffs of the defender and the attacker when the defender selects the strategy s i and the attacker selects the strategy a j ;
[0027] S22. Define the probability distribution P of the uncertainty of the attacker's behavior att (a j ), the probability distribution P att (a j ) represents the possibility that the attacker selects strategy a j , which is modeled by the context information extracted from the security feature dataset;
[0028] S23. The defender updates the posterior probability P of the attacker's strategy selection according to Bayes' theorem post (a j |D feature ):
[0029]
[0030] Among them, P post (a j |D feature ) represents the observation probability of the feature dataset D feature when the attacker selects strategy a j ;
[0031] S24. The defender combines the posterior probability P post (a j |D feature ) and the payoff function U def (s i ,a j ), and calculates the optimal response strategy by expected return
[0032]
[0033] S25. The attacker adjusts the attack strategy set S according to the defender's classification rules through prediction att , and selects the optimal attack strategy according to the deduction result to maximize the expected return of the attacker ;
[0034] S26. The defender and the attacker alternately optimize their respective strategies until the game reaches an equilibrium state The equilibrium state is used to guide the generation of the alarm classification strategy for dynamic network threats.
[0035] Optionally, the S3 includes the following steps:
[0036] S31. Define the uncertainty measure Ω(a att ) for the attacker's strategy set S in the improved Bayesian game model, and the uncertainty measure represents the attacker's selection of strategy a j ), the uncertainty measure represents the attacker's selection of strategy a jThe degree of behavioral fluctuations that may occur
[0037] S32. Incorporate the uncertainty measure Ω(a j ) into the defender's payoff function U def (s i , a j ) to form a revised uncertainty defense payoff function:
[0038] U′ def (s i , a j ) = U def (s i , a j ) - λ·Ω(a j );
[0039] where λ represents the coefficient for weighing the defense payoff and the uncertainty penalty;
[0040] S33. The defender calculates the uncertainty expected payoff based on the revised uncertainty defense payoff function U′ def (s i , a j ) and the posterior probability of the attacker's strategy selection:
[0041]
[0042] S34. The defender selects the optimal uncertainty defense strategy according to the uncertainty expected payoff E′ def (s i )
[0043]
[0044] S35. Incorporate the optimal uncertainty defense strategy into the defender's optimized alarm policy to generate the final optimized alarm policy set
[0045] Optionally, the S4 includes the following steps:
[0046] S41. Use the defender's optimized alarm policy set and the real-time network environment feature dataset D feature as inputs to define the grading criterion function of the dynamic grading algorithm for calculating the potential threat level and grading confidence of alarm events:
[0047]
[0048] where F flow,k , F event,j , Fids,p respectively represent the quantization indexes of the k-th, j-th, and p-th traffic, event, and alarm features, α k , β j , γ p are the feature weight coefficients respectively;
[0049] S42. Calculate the threat score Γ and the grading confidence level δ k of each alarm event based on the grading criterion function k :
[0050]
[0051] where Γ k represents the threat score of the k-th alarm event, which is calculated by the grading criterion function, and δ k represents the confidence level that the k-th alarm event belongs to the current threat score interval;
[0052] S43. Based on the threat score Γ k and the grading confidence level δ k , introduce a dual-threshold mechanism for dynamic grading:
[0053]
[0054] where τ 1 , τ 2 are the thresholds for threat score division, defining the boundaries of high-risk and low-risk grading respectively, and θ 1 , θ 2 are the thresholds for grading confidence level, defining the credibility requirements for high-risk and low-risk alarms respectively, and the grading result level k represents the threat level to which the k-th alarm event belongs;
[0055] S44. Combine historical data and the real-time network environment to adaptively adjust the dual thresholds τ 1 , τ 2 and the confidence level thresholds θ 1 , θ 2 so that the thresholds adapt to the changes in the current network environment and optimize the reliability of the grading result:
[0056]
[0057] where, and respectively represent the average threat score and average confidence level of the current high-risk alarm events, and η, ζ are dynamic adjustment step parameters used to balance the threshold update speed;
[0058] S45. Output the final grading result {L high , L medium,L low} and confidence reports.
[0059] Optionally, the S6 includes the following steps:
[0060] S61. Based on the alarm classification results {L high ,L medium ,L low}For the high-risk alarm event set L high By threat score Γ k and the classification confidence δ k Sort by events, giving priority to high-risk events with higher rankings. The sorting rules are as follows:
[0061] Priority k =ω 1 ·Γ k +ω 2 ·δ k ;;
[0062] Among them, the priority k represents the priority order of alarm event k, ω 1 ,ω 2 It is the weighted coefficient of threat score and confidence. The alarm events with higher priority will be processed by the system first.
[0063] S62. Allocate defense resources R from high to low according to the sorting results alloc Give high-risk alarm events L high The first t events in :
[0064] R alloc,k =ρ·Γ k +(1-ρ)·δ k ;
[0065] Among them, R alloc,k represents the amount of resources allocated to alarm event k, ρ is the weight coefficient of the threat score ratio in the allocated resources, and the total amount of resources satisfies Where R total is the total amount of available resources;
[0066] S63. Combine the allocated defense resources and take measures A for the high-risk alarm events ranked first k :
[0067] Start isolation mechanism A isolate , isolate the traffic of the attack source involved in event k;
[0068] Start Defense Upgrade A upgrade , strengthen relevant security strategies;
[0069] Triggering alarm notification A notify, send a high-risk alarm report to the network administrator.
[0070] S64. Record the classification and processing data for all processed high-risk alarm events;
[0071] S65. Analyze the relationship between resource allocation and processing effect by combining the recorded historical processing data, and optimize the priority ranking and resource allocation rules for subsequent high-risk alarm events:
[0072]
[0073] Among them, and respectively represent the threat score and resource allocation ratio that contribute the most to the processing effect in the historical data, η 1 , ζ 1 are optimization parameters used to dynamically adjust the weights of sorting and allocation. The adjusted rules will be applied to the next round of alarm classification and processing process.
[0074] A network security alarm processing system for implementing a network security alarm processing method, including:
[0075] A data acquisition module for collecting real-time security data sets in the network environment, including network traffic logs, security event records, and alarm data generated by intrusion detection systems, and generating a structured security feature data set as input through data cleaning, feature extraction, and formatting operations;
[0076] A game modeling module that constructs an improved Bayesian game model of the attacker and the defender based on the security feature data set. The game modeling module simulates the strategic behavior of the attacker and generates an optimized alarm strategy set for the defender by combining the uncertainty reasoning mechanism of the attacker's behavior;
[0077] A dynamic classification module that combines the optimized alarm strategy set and the security feature data set, calculates the threat score and classification confidence of alarm events through a classification criterion function, and divides the alarm events into high-risk, medium-risk, and low-risk levels based on a dynamic double-threshold mechanism, and adjusts the threshold in real time to adapt to the dynamic network environment;
[0078] A priority processing module that preferentially processes high-risk alarm events in the classification results, sorts them by combining the threat score and classification confidence, allocates defense resources according to the sorting results, and takes measures such as isolation, upgraded defense, or alarm notification for alarm events;
[0079] A data recording and feedback module that records all alarm classification and processing data, including the threat score, confidence, priority ranking, resource allocation amount, and response time of alarm events;
[0080] The adaptive optimization module continuously monitors the dynamic changes of the network environment, optimizes system parameters based on historical alarm data, and dynamically adjusts the classification threshold, confidence threshold, and resource allocation weight. The adaptive optimization module is linked with the game modeling module to update the strategy set of the Bayesian game model in real time.
[0081] The system interface module provides the connection function with external network security equipment and management platform, including:
[0082] Data collection interface: Real-time data transmission with traffic monitoring equipment, loggers and intrusion detection systems;
[0083] Classification result output interface: Provides classification reports, confidence analysis and processing suggestions to network administrators;
[0084] System expansion interface: supports access to multiple security environments to adapt to different network architectures and security requirements.
[0085] The beneficial effects of the present invention are:
[0086] (1) The present invention introduces an uncertainty reasoning mechanism into the Bayesian game model. By defining the uncertainty measure of the attacker's strategy and integrating it into the defender's payoff function, it effectively responds to the attacker's changeable strategic behavior. It uses the posterior probability and dynamic classification criterion function to dynamically adjust the threat score and confidence in the classification decision, which significantly improves the adaptability and robustness of the classification results to complex threat scenarios.
[0087] (2) The present invention adopts a dynamic dual-threshold classification algorithm, and realizes accurate classification of alarm events and priority response to high-risk events through adaptive adjustment of threat score threshold and confidence threshold. Combined with the classification results, the classification sorting and resource allocation model are used to allocate limited defense resources to the high-risk event set, which significantly improves the resource utilization efficiency. Compared with the resource allocation strategy of traditional methods, the present invention reduces the resource occupation of low-priority events, so that the response time of key threats is shortened by more than 30%. BRIEF DESCRIPTION OF THE DRAWINGS
[0088] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0089] Figure 1 The present invention provides a flowchart of a network security alarm processing method and system. DETAILED DESCRIPTION
[0090] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only illustrating the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.
[0091] Reference Figure 1 , a network security alarm processing method, comprising the following steps:
[0092] S1. Collect real-time security data sets in the network environment and preprocess the real-time security data sets to generate security feature data sets for analysis;
[0093] S2. Construct an improved Bayesian game model for attackers and defenders based on the security feature data sets;
[0094] S3. Introduce an uncertainty reasoning mechanism for attacker behavior into the improved Bayesian game model, and generate an optimized alarm strategy set for the defender based on the probability distribution of the attacker strategy space;
[0095] S4. Combine the optimized alarm strategy set and the real-time network environment to construct a dynamic grading algorithm, divide network threats into multiple levels according to severity, generate grading thresholds based on threats of different levels, and perform alarm grading on security events in the security feature data sets through the dynamic grading algorithm;
[0096] S5. According to the alarm grading results, prioritize the alarm events of high-risk levels, allocate defense resources, and record the relevant data of the alarm grading;
[0097] S6. Combine the graded alarm events to remove low-risk or duplicate alarm events, optimize the output of the alarm results, and push the optimized alarm grading results.
[0098] In this embodiment, S1 includes the following steps:
[0099] S11. Collect the real-time security data set D raw :
[0100] D raw ={L flow , R event , A ids}:
[0101] Among them, L flow represents the traffic data collected from the network interface per unit time, including the source address, destination address, port number, protocol type, and traffic size of the traffic packet, R event represents the security event log generated by the network device, including the event type, event timestamp, and event description, A ids represents the alarm record generated by the intrusion detection system, including the alarm level, trigger rule, and associated context information;
[0102] S12. For the real-time security data set D raw Remove duplicate network traffic records in the data, correct or delete security event records with missing key fields, filter out invalid alarm data, and the judgment condition is that the alarm level is the lowest and there is no associated context information, and generate the cleaned real-time security data set D clean ;
[0103] S13. For the cleaned real-time security data set D clean Perform feature extraction and perform feature fusion to generate a unified security feature data set D feature :
[0104] D feature ={F flow , F event , F ids};
[0105] Among them, F flow is the feature vector extracted from the network traffic log, F event is the feature matrix extracted from the security event record, and F ids is the feature vector extracted from the intrusion detection system alarm data.
[0106] In this embodiment, S2 includes the following steps:
[0107] S21. Based on the security feature data set D feature Construct a Bayesian game model and define the strategy sets and payoff functions of the attacker and the defender;
[0108] The strategy set of the defender is S def ={s 1 , s 2 , …, s m}, indicating the response strategies of the defender under different alarm rules;
[0109] The strategy set of the attacker is S att ={a 1 , a 2 , …, a n}, indicating the evasion or direct attack strategies adopted by the attacker;
[0110] The payoff functions are U def (s i , a j ) and U att (s i , a j ), respectively indicating the payoffs of the defender and the attacker when the defender selects the strategy s i and the attacker selects the strategy a j ;
[0111] S22. Define the probability distribution P of the uncertainty of the attacker's behavior att (a j ), the probability distribution P of the uncertainty att (a j ) represents the possibility that the attacker selects strategy a j , which is modeled by the context information extracted from the security feature dataset;
[0112] S23. The defender updates the posterior probability P of the attacker's strategy selection according to Bayes' theorem post (a j |D feature ):
[0113]
[0114] Among them, P post (a j |D feature ) represents the observation probability of the feature dataset D feature when the attacker selects strategy a j ;
[0115] S24. The defender combines the posterior probability P post (a j |D feature ) and the payoff function U def (s i ,a j ), and calculates the optimal response strategy by expected return
[0116]
[0117] S25. The attacker adjusts the attack strategy set S according to the defender's classification rules through prediction att , and selects the optimal attack strategy according to the deduction result to maximize the expected return of the attacker ;
[0118] S26. The defender and the attacker alternately optimize their respective strategies until the game reaches an equilibrium state The equilibrium state is used to guide the generation of the alarm classification strategy for dynamic network threats.
[0119] In this embodiment, S3 includes the following steps:
[0120] S31. Define the uncertainty measure Ω(a att ) for the attacker's strategy set S in the improved Bayesian game model, and the uncertainty measure represents the selection of strategy a by the attacker j j The degree of behavioral fluctuations that may occur
[0121] S32. Incorporate the uncertainty measure Ω(a j ) into the defender's payoff function U def (s i , a j ) to form a revised uncertainty defense revenue function:
[0122] U′ def (s i , a j ) = U def (s i , a j ) - λ·Ω(a j );
[0123] where λ represents the coefficient for weighing the defense revenue and the uncertainty penalty;
[0124] S33. The defender calculates the uncertainty expected revenue based on the revised uncertainty defense revenue function U′ def (s i , a j ) and the posterior probability of the attacker's strategy selection:
[0125]
[0126] S34. The defender selects the optimal uncertainty defense strategy according to the uncertainty expected revenue E′ def (s i );
[0127]
[0128] S35. Incorporate the optimal uncertainty defense strategy into the defender's optimized alarm policy to generate the final optimized alarm policy set
[0129] In this embodiment, S4 includes the following steps:
[0130] S41. Take the defender's optimized alarm policy set and the real-time network environment feature dataset D feature as inputs, and define the grading criterion function of the dynamic grading algorithm for calculating the potential threat degree and grading confidence of alarm events:
[0131]
[0132] where F flow,k , Fevent,j , F ids,p respectively represent the quantization indexes of the k-th, j-th, and p-th traffic, event, and alarm features, and α k , β j , γ p are the feature weight coefficients respectively;
[0133] S42. Calculate the threat score Γ and the grading confidence δ k of each alarm event based on the grading criterion function k :
[0134]
[0135] where Γ k represents the threat score of the k-th alarm event, which is calculated by the grading criterion function, and δ k represents the confidence that the k-th alarm event belongs to the current threat score interval;
[0136] S43. Based on the threat score Γ k and the grading confidence δ k , introduce a dual-threshold mechanism for dynamic grading:
[0137]
[0138] where τ 1 , τ 2 are the thresholds for threat score division, defining the boundaries of high-risk and low-risk grading respectively, and θ 1 , θ 2 are the thresholds for grading confidence, defining the credibility requirements for high-risk and low-risk alarms respectively, and the grading result level k represents the threat level to which the k-th alarm event belongs;
[0139] S44. Combine historical data and the real-time network environment to adaptively adjust the dual thresholds τ 1 , τ 2 and the confidence threshold θ 1 , θ 2 so that the thresholds adapt to changes in the current network environment and optimize the reliability of the grading result:
[0140]
[0141] where and respectively represent the average threat score and average confidence of current high-risk alarm events, and η, ζ are dynamic adjustment step parameters used to balance the threshold update speed;
[0142] S45. Output the final grading result {L high,L medium ,L low} and confidence reports.
[0143] In this implementation, S6 includes the following steps:
[0144] S61. Based on the alarm classification results {L high ,L medium ,L low}For the high-risk alarm event set L high By threat score Γ k and the classification confidence δ k Sort by events, giving priority to high-risk events with higher rankings. The sorting rules are as follows:
[0145] Priority k =ω 1 ·Γ k +ω 2 ·δ k ;;
[0146] Among them, the priority k represents the priority order of alarm event k, ω 1 ,ω 2 It is the weighted coefficient of threat score and confidence. The alarm events with higher priority will be processed by the system first.
[0147] S62. Allocate defense resources R from high to low according to the sorting results alloc Give high-risk alarm events L high The first t events in :
[0148] R alloc,k =ρ·Γ k +(1-ρ)·δ k ;
[0149] Among them, R alloc,k represents the amount of resources allocated to alarm event k, ρ is the weight coefficient of the threat score ratio in the allocated resources, and the total amount of resources satisfies Where R total is the total amount of available resources;
[0150] S63. Combine the allocated defense resources and take measures A for the high-risk alarm events ranked first k :
[0151] Start isolation mechanism A isolate , isolate the traffic of the attack source involved in event k;
[0152] Start Defense Upgrade A upgrade , strengthen relevant security strategies;
[0153] Triggering alarm notification Anotify , send a high-risk alarm report to the network administrator.
[0154] S64. Record the classification and processing data for all processed high-risk alarm events;
[0155] S65. Analyze the relationship between resource allocation and processing effect by combining the recorded historical processing data, and optimize the priority sorting and resource allocation rules for subsequent high-risk alarm events:
[0156]
[0157] Among them, and respectively represent the threat score and resource allocation ratio that contribute the most to the processing effect in the historical data, η 1 , ζ 1 are optimization parameters used to dynamically adjust the weights of sorting and allocation, and the adjusted rules will be applied to the next round of alarm classification and processing process.
[0158] A network security alarm processing system for executing a network security alarm processing method, including:
[0159] A data acquisition module for collecting real-time security data sets in the network environment, including network traffic logs, security event records, and alarm data generated by intrusion detection systems, and generating a structured security feature data set as input through data cleaning, feature extraction, and formatting operations;
[0160] A game modeling module that constructs an improved Bayesian game model between attackers and defenders based on the security feature data set. The game modeling module simulates the strategic behavior of attackers and generates an optimized alarm strategy set for defenders by combining the uncertainty reasoning mechanism of attacker behavior;
[0161] A dynamic classification module that combines the optimized alarm strategy set and the security feature data set, calculates the threat score and classification confidence level of alarm events through a classification criterion function, and divides the alarm events into high-risk, medium-risk, and low-risk levels based on a dynamic double-threshold mechanism, and adjusts the thresholds in real time to adapt to the dynamic network environment;
[0162] A priority processing module that preferentially processes high-risk alarm events in the classification results, sorts them by combining the threat score and classification confidence level, allocates defense resources according to the sorting results, and takes measures such as isolation, upgraded defense, or alarm notification for alarm events;
[0163] A data recording and feedback module that records all alarm classification and processing data, including the threat score, confidence level, priority sorting, resource allocation amount, and response time of alarm events;
[0164] The adaptive optimization module continuously monitors the dynamic changes of the network environment, optimizes system parameters based on historical alarm data, and dynamically adjusts the classification threshold, confidence threshold, and resource allocation weight. The adaptive optimization module is linked with the game modeling module to update the strategy set of the Bayesian game model in real time.
[0165] The system interface module provides the connection function with external network security equipment and management platform, including:
[0166] Data collection interface: Real-time data transmission with traffic monitoring equipment, loggers and intrusion detection systems;
[0167] Classification result output interface: Provides classification reports, confidence analysis and processing suggestions to network administrators;
[0168] System expansion interface: supports access to multiple security environments to adapt to different network architectures and security requirements.
[0169] Embodiment 1:
[0170] The data center of a financial institution is located in City A. It undertakes a large number of online payment, fund clearing and data storage functions. With the continuous escalation of network attack methods, the data center has frequently suffered from DDoS attacks, malicious code intrusions and data theft in recent years, resulting in a decrease in system operation efficiency and even a brief interruption. The previous threat management system relied on the alarm classification method based on static rules and could only issue simple alarms for traffic anomalies through preset thresholds. It was unable to distinguish the severity of the attack behavior, resulting in high-risk threats unable to be handled in a timely manner, while low-risk alarms occupied a lot of resources.
[0171] In order to improve the efficiency of network security management, the data center deploys the present invention for accurate classification and efficient disposal of real-time threats. The application process and effect of the present invention are demonstrated through a specific dynamic network threat scenario.
[0172] One day, the data center's security system detected the following events:
[0173] 1. An abnormal traffic surge occurs in a certain IP segment, which is suspected to be a DDoS attack;
[0174] 2. The access frequency of the database server is abnormal, which is suspected to be a SQL injection attack;
[0175] 3. The file server triggers multiple unauthorized access alarms, which may indicate data theft.
[0176] The security system collected network traffic logs, security event records, and intrusion detection alarm data for three events:
[0177] The traffic log of Event 1 records more than 5,000 packets per second, and the source IPs are concentrated in a certain overseas IP segment.
[0178] The database log of Event 2 shows that there are multiple SQL queries attempting to access sensitive data tables and triggering the access denial rules multiple times.
[0179] The file server alarm rule of Event 3 has triggered up to 50 unauthorized access requests, and some of these requests originate from internal IPs.
[0180] After preprocessing and feature extraction, a security feature dataset is generated, including traffic statistical features, event record features, and alarm rule features.
[0181] Based on the security feature dataset, an improved Bayesian game model between attackers and defenders is constructed. Through the uncertainty reasoning mechanism, the uncertainty measure of the attacker's strategy is calculated, and the posterior probabilities of the defender for the 3 events are respectively:
[0182] The posterior probability of Event 1 is 0.85, indicating that it is a typical DDoS attack.
[0183] The posterior probability of Event 2 is 0.65, indicating that it is a possible SQL injection attack.
[0184] The posterior probability of Event 3 is 0.55, indicating that it is a potential data stealing behavior.
[0185] Combined with the posterior probability and the profit function, an optimized alarm strategy set for the defender is generated.
[0186] Through the dynamic grading algorithm, the threat scores Γ k and confidence levels δ k of the 3 events are calculated respectively as follows:
[0187] Event 1: Γ 1 = 0.92, δ 1 = 0.88;
[0188] Event 2: Γ 2 = 0.67, δ 2 = 0.75;
[0189] Event 3: Γ 3 = 0.56, δ 3 = 0.64.
[0190] The system classifies the 3 events into different levels according to the double thresholds τ 1 = 0.7, τ 2 = 0.5 and the confidence level threshold θ 1 = 0.8, θ 2 = 0.6 as follows:
[0191] Event 1 is of high - risk level;
[0192] Event 2 is of medium - risk level;
[0193] Event 3 is of low - risk level.
[0194] For the high - risk Event 1, the system allocated 50% of the defense resources for traffic isolation to restrict connection requests from this IP segment;
[0195] For the medium - risk Event 2, the system activated the defense upgrade mechanism to increase the access restriction rules for sensitive data in the database;
[0196] For the low - risk Event 3, the system triggered an alarm notification to remind the administrator to conduct further investigation.
[0197] After the processing was completed, the system recorded the classification results, response times, and resource allocation amounts of the alarm events:
[0198] The response time for Event 1 was 5 seconds, and the resource allocation amount was traffic isolation of 500 MB / s;
[0199] The response time for Event 2 was 10 seconds, and 5 new access restriction rules were added;
[0200] Event 3 triggered 3 alarm messages for the administrator to handle later.
[0201] In summary, through the precise classification and efficient processing of dynamic network threats, the present invention solves the problems of insufficient classification adaptability and low resource allocation efficiency in the prior art, and provides a more secure and reliable network protection solution for the data centers of financial institutions.
[0202] The present invention introduces an uncertainty reasoning mechanism into the Bayesian game model. By defining the uncertainty measure of the attacker's strategy and integrating it into the defender's pay - off function, it effectively deals with the changing strategic behaviors of the attacker. Using the posterior probability and the dynamic classification criterion function, it dynamically adjusts the threat score and confidence level in the classification decision, significantly improving the adaptability and robustness of the classification results to complex threat scenarios.
[0203] The present invention adopts a dynamic double - threshold classification algorithm. Through the adaptive adjustment of the threat score threshold and the confidence level threshold, it realizes the precise classification of alarm events and the priority response to high - risk events. Combining the classification results, it uses the classification ranking and resource allocation model to allocate limited defense resources to the high - risk event set, significantly improving the utilization efficiency of resources. Compared with the resource allocation strategy of traditional methods, the present invention reduces the resource occupation by low - priority events and shortens the response time for critical threats by more than 30%.
[0204] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention should cover within the protection scope of the present invention any equivalent substitution or change made according to the technical solution and inventive concept of the present invention.
Claims
1. A network security alarm processing method, characterized in that: The steps include: S1. Collecting real-time security data sets in a network environment, and preprocessing the real-time security data sets to generate security feature data sets for analysis; S2. Construct an improved Bayesian game model between attackers and defenders based on the security feature dataset; S3. Introduce the uncertainty reasoning mechanism of attacker behavior into the improved Bayesian game model, and generate the optimized alarm strategy set of the defender based on the probability distribution of the attacker's strategy space; S4. Combine the optimized alarm strategy set and the real-time network environment to build a dynamic classification algorithm, classify network threats into multiple levels according to severity, generate classification thresholds based on different levels of threats, and classify the security events in the security feature data set through the dynamic classification algorithm; S5. According to the alarm classification results, high-risk alarm events are prioritized, defense resources are deployed, and relevant data of alarm classification is recorded; S6. Remove low-risk or repeated alarm events based on the classified alarm events, optimize the output of alarm results, and push the optimized alarm classification results.
2. A network security alarm processing method according to claim 1, characterized in that: The S1 comprises the following steps: S11. Collect real-time security datasets in network environments D raw : D raw ={L flow ,R event ,A ids }: Among them, L flow It represents the traffic data collected from the network interface per unit time, including the source address, destination address, port number, protocol type and traffic size of the traffic packet. event Represents a security event log generated by a network device, including event type, event timestamp, and event description. ids Represents the alarm record generated by the intrusion detection system, including the alarm level, triggering rules and associated context information; S12. The real-time security dataset D raw Remove duplicate network traffic records in the data, correct or delete security event records with missing key fields, filter invalid alarm data, and determine the alarm level to be the lowest and without associated context information to generate a cleaned real-time security data set D clean ; S13. Cleaned real-time security dataset D clean Perform feature extraction and feature fusion to generate a unified security feature dataset D feature : D feature ={F flow ,F event ,F ids }; Among them, F flow is the feature vector extracted from the network traffic log, F event is the feature matrix extracted from the security event records, F ids is the feature vector extracted from the intrusion detection system alarm data.
3. A network security alarm processing method according to claim 1, characterized in that: The S2 comprises the following steps: S21. Based on security feature dataset D feature Construct a Bayesian game model and define the strategy set and payment function of the attacker and defender; The defender's strategy set is S def ={s1, s2, ..., s m }, indicating the defender’s response strategy under different alarm rules; The attacker’s strategy set is S att ={a1, a2, ..., a n }, indicating the evasion or direct attack strategy adopted by the attacker; The payment function is U def (s i , a j ) and U att (s i , a j ), respectively represent the defender’s choice of strategy s i and the attacker chooses strategy a j The payoffs of the defender and attacker are: S22. Define the uncertainty probability distribution P of the attacker's behavior att (a j ), uncertainty probability distribution P att (a j ) indicates that the attacker chooses strategy a j The likelihood of,modeling is done by contextual information extracted from the security,signature dataset; S23. The defender updates the posterior probability P of the attacker's strategy selection according to Bayes' theorem post (a j |D feature ): Among them, P post (a j |D feature ) represents the feature data set D feature When the attacker chooses strategy a j The probability of observation under ; S24. Defender combines the posterior probability P post (a j |D feature ) and the payment function U def (s i , a j ), select the optimal response strategy by calculating the expected return S25. The attacker adjusts the attack strategy set S according to the defender's classification rules by prediction. att , and select the optimal attack strategy based on the deduction results The attacker's expected profit maximize; S26. The defender and the attacker optimize their strategies alternately until the game reaches equilibrium The equilibrium state is used to guide the generation of alarm classification strategies for dynamic network threats.
4. A network security alarm processing method according to claim 1, characterized in that: The S3 comprises the following steps: S31. In the improved Bayesian game model, the attacker's strategy set S att Define the uncertainty measure Ω(a j ), the uncertainty measure represents the attacker's choice of strategy a j the degree of behavioral fluctuations that may occur when S32. The uncertainty measure Ω(a j ) into the defender’s payoff function U def (s i , a j ), forming the modified uncertainty defense benefit function: U′ def (s i ,a j )=U def (s i ,a j )-λ·Ω(a j ); Among them, λ represents the coefficient that weighs the defense benefit and uncertainty penalty; S33. The defender’s defense benefit function U based on the modified uncertainty def (s i , a j ) and the posterior probability of the attacker's strategy selection to calculate the uncertain expected return: S34. The defender expects the expected return E′ according to uncertainty def (s i ), select the optimal uncertainty defense strategy S35. The optimal uncertainty defense strategy Incorporate the defender's optimized alarm strategy to generate the final optimized alarm strategy set 5. A network security alarm processing method according to claim 1, characterized in that: The S4 comprises the following steps: S41. Set the defender's optimized alarm strategy and real-time network environment feature dataset D feature As input, define the grading criteria function of the dynamic grading algorithm Used to calculate the potential threat level and confidence level of alarm events: Among them, F flow,k , F event,j , F ids,p Respectively represent the quantitative indicators of the kth, jth, and pth flow, event, and alarm characteristics, α k , β j , γ p are the feature weight coefficients respectively; S42. Based on the classification criteria function Calculate the threat score Γ for each alarm event k and the classification confidence δ k : Among them, Γ k represents the threat score of the kth alarm event, which is calculated by the classification criterion function, δ k Indicates the confidence that the kth alarm event belongs to the current threat score interval; S43. Based on threat score Γ k and the classification confidence δ k , introduce a dual threshold mechanism for dynamic classification: Among them, τ1 and τ2 are the thresholds for threat score division, which define the boundaries of high-risk and low-risk classification respectively; θ1 and θ2 are the thresholds for classification confidence, which define the credibility requirements of high-risk and low-risk alarms respectively; and the classification result level k Indicates the threat level to which the k-th alarm event belongs; S44. Combining historical data and real-time network environment, the dual thresholds τ1, τ2 and confidence thresholds θ1, θ2 are adaptively adjusted to adapt the thresholds to changes in the current network environment and optimize the reliability of the grading results: in, and They represent the average threat score and average confidence of the current high-risk alarm event, respectively. η and ζ are dynamically adjusted step size parameters used to balance the threshold update speed. S45. Output the final classification result {L high , L medium , L low } and confidence reports.
6. A network security alarm processing method according to claim 1, characterized in that: The S6 comprises the following steps: S61. Based on the alarm classification results {L high , L medium , L low }For the high-risk alarm event set L high By threat score Γ k and the classification confidence δ k Sort by events, giving priority to high-risk events with higher rankings. The sorting rules are as follows: priority k =ω1·C k +ω2·d k ;; Among them, the priority k represents the priority processing order of alarm event k, ω1 and ω2 are the weighted coefficients of threat score and confidence, and the alarm event with higher priority will be processed first by the system; S62. Allocate defense resources R from high to low according to the sorting results alloc Give high-risk alarm events L high The first t events in : R alloc,k =r·C k +(1-p)·d k ; Among them, R alloc,k represents the amount of resources allocated to alarm event k, ρ is the weight coefficient of the threat score ratio in the allocated resources, and the total amount of resources satisfies Where R total is the total amount of available resources; S63. Combine the allocated defense resources and take measures A for the high-risk alarm events ranked first k : Start isolation mechanism A isolate , isolate the traffic of the attack source involved in event k; Start Defense Upgrade A upgrade , strengthen relevant security strategies; Triggering alarm notification A notify , send high-risk alarm reports to network administrators. S64. Record the classification and processing data of all processed high-risk alarm events; S65. Analyze the relationship between resource allocation and processing effect based on the recorded historical processing data, and optimize the priority sorting and resource allocation rules for subsequent high-risk alarm events: in, and They respectively represent the threat score and resource allocation ratio that contribute most to the processing effect in the historical data. η1 and ζ1 are optimization parameters used to dynamically adjust the weights of sorting and allocation. The adjusted rules will be applied to the next round of alarm classification and processing flow.
7. A network security alarm processing system, used to execute a network security alarm processing method according to any one of claims 1 to 6, characterized in that: include: The data collection module is used to collect real-time security data sets in the network environment, including network traffic logs, security event records, and alarm data generated by the intrusion detection system. Through data cleaning, feature extraction, and formatting operations, a structured security feature data set is generated as input; Game modeling module, which builds an improved Bayesian game model between attackers and defenders based on the security feature data set. The game modeling module simulates the strategic behavior of the attacker and combines the uncertainty reasoning mechanism of the attacker's behavior to generate an optimized alarm strategy set for the defender. The dynamic classification module combines the optimized alarm strategy set and security feature data set to calculate the threat score and classification confidence of the alarm event through the classification criterion function. Based on the dynamic dual threshold mechanism, the alarm event is divided into high-risk, medium-risk and low-risk levels, and the threshold is adjusted in real time to adapt to the dynamic network environment. The priority processing module prioritizes high-risk alarm events in the classification results, sorts them based on threat scores and classification confidence, allocates defense resources based on the sorting results, and takes isolation, defense upgrade, or alarm notification processing measures for alarm events; Data recording and feedback module, which records all alarm classification and processing data, including the threat score, confidence level, priority ranking, resource allocation and response time of the alarm event; The adaptive optimization module continuously monitors the dynamic changes of the network environment, optimizes system parameters based on historical alarm data, and dynamically adjusts the classification threshold, confidence threshold, and resource allocation weight. The adaptive optimization module is linked with the game modeling module to update the strategy set of the Bayesian game model in real time. The system interface module provides the connection function with external network security equipment and management platform, including: Data collection interface: Real-time data transmission with traffic monitoring equipment, loggers and intrusion detection systems; Classification result output interface: Provides classification reports, confidence analysis and processing suggestions to network administrators; System expansion interface: supports access to multiple security environments to adapt to different network architectures and security requirements.