Big Data-Based Platform Security Situation Prediction System and Method

Through big data analysis and modal decomposition technology, combined with dynamic weight allocation and Transformer model, a security situation prediction system is built, which solves the problem of real-time and dynamic prediction of platform security situation in the existing technology, and accurately identify and respond to potential risks, and improves the platform's security protection capabilities.

CN120105435BActive Publication Date: 2025-07-11HEFEI SHENGWEN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510578156.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-11
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The prior art is difficult to predict the security situation of public communication platforms through accurate real-time and dynamic methods, and cannot effectively identify potential security risks. Traditional methods cannot fully consider the variability of time and space and the influence of dynamic factors.

Method used

A platform security situation prediction system based on big data is adopted, and through data acquisition, feature analysis, data processing and model prediction modules, combined with modal decomposition, dynamic weight allocation and Transformer model, space-time alignment and hyperparameter optimization are carried out to build a security situation prediction model.

Benefits of technology

Real-time and accurate security situation prediction of the public communication platform is realized, potential risks can be discovered in a timely manner, and the ability to respond to equipment failures and security threats is improved, and the stable operation and information security of the platform is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105435B_ABST
    Figure CN120105435B_ABST
Patent Text Reader

Abstract

The present invention provides a platform security situation prediction system and method based on big data, which relates to the technical field of platform security situation prediction. The present invention obtains the security situation influencing factors and equipment failure types of the platform to be predicted, obtains the intrinsic modal features of the security situation influencing factors through modal decomposition, divides the security situation influencing factor data by sliding window according to the frequency distribution of all intrinsic modal features, determines the hidden value and security coefficient of each position through the dynamic weight allocation method according to the attacked data in each window time period, and forms a prediction data set with the security situation influencing factors. By establishing a security situation prediction model, the equipment failure type in the next step sliding window time period is predicted, and by constructing a prediction optimization model, the hyperparameters during the training of the security situation prediction model are optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of platform security situation prediction, and specifically provides a platform security situation prediction system and method based on big data. Background Art

[0002] With the rapid development of information technology, public communication command platforms have become an indispensable part of social operation and management. However, these platforms often face complex security threats during operation, such as network attacks, equipment failures, and external environmental changes. Under the combined action of these factors, the security situation of the platform becomes very complex. Therefore, how to effectively predict its security situation in order to take defensive measures in a timely manner has become an urgent problem to be solved.

[0003] Currently, in the field of security situation prediction, many traditional methods mainly rely on static data analysis or simple statistical models. These methods cannot fully consider the variability of time and space and the influence of dynamic factors. In addition, it is also difficult for existing technologies to discover potential security risks in advance through accurate prediction, and there is a lack of real-time and dynamic security situation assessment methods. Therefore, traditional prediction methods face great challenges in dealing with increasingly complex security threats.

[0004] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] The purpose of the present invention is to provide a platform security situation prediction system and method based on big data to solve the problems raised in the above background art.

[0006] To achieve the above purpose, the present invention provides the following technical solutions:

[0007] A platform security situation prediction system based on big data, comprising:

[0008] A data acquisition module, which is used to obtain the security situation influencing factors and equipment failure types during a period of time before a failure occurs in the historical working process of the platform to be predicted, stamp time stamps on the security situation influencing factors and equipment failure types, and perform space-time alignment;

[0009] A feature analysis module, which is used to divide each data of the security situation influencing factors at the same time interval, obtain intrinsic modal features through modal decomposition, and divide the security situation influencing factor data through a sliding window according to the frequency distribution of all intrinsic modal features;

[0010] A data processing module, which is used to judge the hidden value and safety factor of each location through the dynamic weight distribution method according to the attacked location information, the number of attacks at each location, the number of successful interceptions within each window time period, and the distance of the window time from the current moment, and form a prediction data set with the security situation influencing factors. According to the sliding window where the fault occurs, calculate the failure rate of the fault type of each sliding window as the training output set;

[0011] A model prediction module, which is used to establish a security situation prediction model and train the model. By using the prediction data set within the current window time period as the input of the prediction model, the training output set within the next step-size sliding window time period is output through the trained prediction model;

[0012] A model optimization module, which is used to construct a prediction optimization model and optimize the hyperparameters during the training of the security situation prediction model.

[0013] Further, the security situation influencing factors include network traffic data, device status data, user behavior data, external threat data, and environmental data;

[0014] The device failure types include failure parts, network interruption, and device interruption;

[0015] The failure parts include the command system, database, communication terminal, and command terminal.

[0016] Further, the specific method for performing spatio-temporal alignment is as follows: Among them, is the time-series data sequence after time alignment, are respectively the time-series data sequences of the th data type to be aligned among the security situation influencing factors and the device failure types, are respectively the th data type to be aligned, the nd time-series data, the th data type to be aligned, and the rd time-series data, is the set of alignment paths, are all positive integers.

[0017] Further, the calculation formula for obtaining the intrinsic mode features through modal decomposition is: Among them, is the th data type of the security situation influencing factors at the th moment, is the th moment, the The th intrinsic mode function in a set of data, is the remaining term at time in the th set of data, and

[0018] Further, the specific steps for window partitioning of the security situation influencing factor data through a sliding window are as follows:

[0019] Screening effective intrinsic mode functions through an energy threshold: Among them, is the effective intrinsic mode function, is the energy of the th intrinsic mode function component, is the number of energies of the intrinsic mode function components, is the energy threshold;

[0020] The calculation formula for the energy of the intrinsic mode function component is: Among them, is the energy of the th intrinsic mode function component, is the th intrinsic mode function at time

[0021] The calculation formula for the sliding window is: Among them, is the size of the sliding window, is the basic window size, is the adjustment coefficient, controlling the sensitivity of the window to the number of intrinsic mode functions, is the effective intrinsic mode function in the th set of data in the security situation influencing factors, is the number of security situation influencing factors, is the basic effective intrinsic mode function, is the step value of the sliding window, is the overlap factor.

[0022] Further, the calculation formula for the hidden value is: Among them, is the hidden value, is the number of attacks, is the data exchange volume, is the number of nodes connected to this location;

[0023] The calculation formula for the security coefficient is: Among them, is the security coefficient, is the number of attacks intercepted, is the number of illegal operations by users, is the environmental outlier, are respectively the interception failure rate, the number of illegal operations by users, and the weights of environmental outliers, .

[0024] Furthermore, the specific method for judging the hidden value and safety factor of each position by the dynamic weight allocation method is as follows: Among them, is the attenuation coefficient in the th window time period, is the current window time, is the attenuation factor, is the hidden value in the th window time period, is the hidden value after dynamic allocation, is the total number of windows, is the safety factor after dynamic allocation, is the safety factor in the th window time period;

[0025] The calculation method for calculating the failure rate of the failure type of each sliding window according to the sliding window where the failure occurs is as follows: Among them, is the failure rate of the failure type of the th sliding window, is the number of sliding windows, , are all positive integers.

[0026] Furthermore, the security situation prediction model is established based on the Transformer model, including:

[0027] Embedding layer: Among them, is the embedded feature vector, is the input prediction data set, is the embedding matrix;

[0028] Position encoding layer: Among them, is the position encoding function, is the position index in the input prediction data set sequence, is the index of the model hidden layer dimension, is the grouping index of the hidden layer dimension, is the model hidden layer dimension;

[0029] Among them, is the embedded feature vector after the position encoding is superimposed;

[0030] Multi-head self-attention layer: Among them, is the attention function, are the query matrix, key matrix, and value matrix respectively, is the dimension of the key and query, represents the time step of the input sequence;

[0031] Feed-forward network layer: Among them, is the feed-forward network function, , are the first-layer weight and first-layer bias respectively, are the second-layer weight and second-layer bias respectively, is the output value of the multi-head self-attention layer;

[0032] Residual connection layer: Among them, is the normalization function, , is the intermediate feature after being processed by the self-attention sublayer, is the final output after being processed by the feed-forward network sublayer;

[0033] Output layer: Among them, is the predicted training output set, are the output layer weight and output layer bias respectively, is the non-linear activation function.

[0034] Furthermore, the model optimization module is based on the WOA optimization algorithm, and the specific optimization steps of the WOA optimization algorithm are as follows;

[0035] Encirclement process: Among them, is the hyperparameter of the security situation prediction model at time is the optimal hyperparameter of the security situation prediction model at time is the coefficient vector used to control the search steps and directions, is the distance between the optimal hyperparameter of the security situation prediction model and the optimal hyperparameter;

[0036] Approaching process: Among them, is the tightness of the spiral update, A constant of spiral shape, used to control the direction and radius of the spiral, taking a random number in the range of [-1, 1];

[0037] Search process: Wherein, is the position of a randomly selected agent, used to introduce randomness and explore the solution space.

[0038] The present invention further provides a method for predicting the security situation of a platform based on big data. The detection method is obtained by executing the above-mentioned system for predicting the security situation of a platform based on big data. The specific steps include:

[0039] Step 1: Obtain the security situation influencing factors and equipment failure types in a period of time before a failure during the historical operation of the platform to be predicted, stamp time stamps on the security situation influencing factors and equipment failure types, and perform spatio-temporal alignment;

[0040] Step 2: Divide each data of the security situation influencing factors at the same time interval, obtain the intrinsic mode characteristics through modal decomposition, and divide the security situation influencing factor data through a sliding window according to the frequency distribution of all intrinsic mode characteristics;

[0041] Step 3: According to the attacked position information, the number of attacks at each position, and the number of successful interceptions within each window time period, and according to the distance of the window time from the current moment, judge the hidden value and security coefficient of each position through the dynamic weight distribution method, and form a prediction data set with the security situation influencing factors. According to the sliding window where the failure occurs, calculate the failure rate of the failure type of each sliding window as the training output set;

[0042] Step 4: Establish a security situation prediction model and train the model. By taking the prediction data set within the current window time period as the input of the prediction model, the training output set within the next step sliding window time period is output through the trained prediction model;

[0043] Step 5: Construct a prediction optimization model to optimize the hyperparameters during the training of the security situation prediction model.

[0044] Compared with the prior art, the beneficial effects of the present invention are:

[0045] The present invention obtains the security situation influencing factors and equipment failure types of the platform to be predicted, obtains the intrinsic modal characteristics of the security situation influencing factors through modal decomposition, divides the security situation influencing factor data into windows through a sliding window according to the frequency distribution of all intrinsic modal characteristics, judges the hidden value and security coefficient of each position through the dynamic weight allocation method based on the attacked data within each window time period, forms a prediction data set with the security situation influencing factors, predicts the equipment failure type within the next step sliding window time period through establishing a security situation prediction model, and optimizes the hyperparameters during the training of the security situation prediction model by constructing a prediction optimization model.

[0046] The present invention combines the technologies of big data analysis and spatio-temporal alignment. By timestamping the security situation influencing factors and equipment failure types, and using the modal decomposition technology to perform multi-level analysis on the data, it can extract the key factors affecting the security situation and their dynamic change trends, thereby providing real-time and accurate predictions for the security protection of the platform.

[0047] Through the dynamic weight allocation method and the sliding window mechanism, the present solution can more flexibly perform dynamic evaluation of the security situation according to historical data and the actual situation at the current moment, and timely discover potential risks. The dynamic weight allocation method comprehensively considers the hidden value and security coefficient of each position, dynamically adjusts multi-dimensional data, enables the system to be more sensitive to potential risk points in different time periods and different situations, ensures that the impacts of different time periods and different attack positions on the security situation are reasonably quantified, avoids overemphasis on unimportant positions or historical data, thereby improving the ability to identify real threat points. Finally, by optimizing the prediction model and adjusting hyperparameters, the accuracy and real-time performance of the prediction are improved, greatly enhancing the response ability of the public communication command platform in dealing with equipment failures and security threats, thus ensuring the stable operation of the platform and information security. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 It is a schematic diagram of the overall system structure of the present invention;

[0049] Figure 2 It is a schematic diagram of the overall method flow of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0050] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to specific embodiments.

[0051] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the present invention shall have the ordinary meanings understood by those of ordinary skill in the field to which the present invention pertains. The "first", "second" and similar terms used in the present invention do not denote any order, quantity or importance, but are only used to distinguish different components. Words such as "including" or "comprising" mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Words such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Upper", "lower", "left", "right", etc. are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0052] Embodiment

[0053] Please refer to Figure 1 , the present invention provides a technical solution:

[0054] A platform security situation prediction system based on big data, including a data collection module, a feature analysis module, a data processing module, a model prediction module and a model optimization module, wherein:

[0055] The data collection module is used to obtain the security situation influencing factors and equipment failure types in a period of time before a failure occurs during the historical operation process of the platform to be predicted, stamp time stamps on the security situation influencing factors and equipment failure types, and perform spatio-temporal alignment.

[0056] In this embodiment, the security situation influencing factors include network traffic data, equipment status data, user behavior data, external threat data, and environmental data;

[0057] The equipment failure types include failure parts, network interruption, and equipment interruption;

[0058] The failure parts include a command system, a database, a communication terminal, and a command terminal.

[0059] Network traffic is the basic communication channel of the platform. Any abnormal traffic pattern may be a potential sign of an attack, such as a DDoS attack or data leakage. By monitoring traffic data, abnormal traffic or communication interruptions can be detected in a timely manner, network attacks (such as DDoS) or malicious intrusion behaviors can be identified, providing important references for predicting platform failures and threats.

[0060] The device status directly reflects whether there are potential faults or performance degradation in the platform hardware, such as server hardware failures or network device damages. Device status data can provide immediate device health information, identify the risks of device failures in advance, avoid affecting the platform stability, and enhance the fault prediction and emergency response capabilities.

[0061] User behavior data can reveal whether there are malicious operations or human errors, such as the misoperations of commanders or unauthorized accesses. By recording and analyzing user behaviors, potential security threats, such as internal threats, abuse of permissions, or intentional data tampering, can be identified, and the platform administrators can be warned in advance to take preventive measures.

[0062] External threat information is an important basis for judging whether the platform is under targeted attacks. The APT attack fingerprint database can help identify known advanced persistent threats. External threat information can enhance the identification capabilities of network attacks, intrusion behaviors, and malware, help with early warnings and proactive defense measures, and reduce the success rate of attacks.

[0063] Environmental factors directly affect the operation and stability of devices. Excessive temperature, humid environment, or too much dust may cause hardware failures or performance degradation. By monitoring these environmental parameters, device anomalies caused by environmental changes can be detected in a timely manner, device failures caused by environmental problems can be avoided, and thus the reliability and stability of the system can be improved.

[0064] In summary, the health status of the platform can be effectively monitored in real time from multiple perspectives, and the security threats faced by the platform can be comprehensively and accurately reflected. Through the fusion analysis of multi-modal data, the accuracy of security situation prediction can be improved. Especially in complex attack and defense environments, potential security risks can be identified and addressed in a timely manner.

[0065] In this embodiment, the specific method for performing spatio-temporal alignment is as follows: Among them, is the time-series data sequence after time alignment, are respectively the time-series data sequences of the th data types to be aligned among the security situation influencing factors and device fault types, are respectively the th th time-series data in the th data type, the th time-series data in the is the set of alignment paths, are all positive integers.

[0066] The security situation of the public communication command platform is affected by multiple factors, such as network traffic, device status, user behavior, external threats, and environmental factors. These data come from different monitoring systems and usually have different collection frequencies and time stamps. Therefore, there will be problems of inconsistent time series when directly comparing and analyzing these data. The occurrence of security situations and device failure types usually has obvious spatio-temporal correlations. For example, some attacks may be targeted at specific regions or devices, and the failures of devices may be due to the influence of the external environment or network attacks. Through spatio-temporal alignment, data from different sources can be compared and analyzed in terms of time and space, thereby helping to identify these spatio-temporal related patterns, contributing to discovering potential security risks and the correlations of failures, and improving the accuracy of prediction.

[0067] The feature analysis module is used to divide each data of the security situation influencing factors at the same time interval, obtain the intrinsic mode features through modal decomposition, and divide the security situation influencing factor data through a sliding window according to the frequency distribution of all intrinsic mode features.

[0068] Dividing each data at the same time interval helps to unify the time granularity of all data. Different security situation influencing factors (such as network traffic, device status, user behavior, etc.) may have different collection frequencies, and standardizing the time interval helps to better integrate and compare various types of data in subsequent analysis.

[0069] Modal decomposition is a signal processing technique that decomposes complex time series data into multiple intrinsic mode functions, and these intrinsic mode functions represent different frequency components in the data. Each intrinsic mode function reflects the information of a specific period or trend in the data. For example, in security situation prediction, the changes in network traffic, device status, or external threats may have different frequency components. Through modal decomposition, features related to security threats such as attack patterns and device failures can be extracted from these factors, helping to better capture the dynamic features of the data. By extracting the intrinsic mode functions, the high-frequency noise and low-frequency trends in the data can be separated, enabling the security situation prediction model to focus more on the truly useful frequency components related to the security situation. This helps to avoid overfitting and reduce the interference of irrelevant features on the model.

[0070] In this embodiment, the calculation formula for obtaining the intrinsic mode features through modal decomposition is: where is the th data type in the security situation influencing factors at is the th intrinsic mode function in the At the remaining term in the n - th data,

[0071] In this embodiment, the specific steps of window partitioning the security situation impact factor data through a sliding window are as follows:

[0072] Filter valid intrinsic mode functions through an energy threshold: Where is a valid intrinsic mode function, is the energy of the n - th intrinsic mode function component, is the number of energies of intrinsic mode function components,

[0073] The calculation formula for the energy of an intrinsic mode function component is: Where is the energy of the n - th intrinsic mode function component, is the

[0074] The calculation formula for the sliding window is: Where is the size of the sliding window, is the basic window size, is an adjustment coefficient that controls the sensitivity of the window to the number of intrinsic mode functions, is the n - th valid intrinsic mode function in the security situation impact factors, is the number of security situation impact factors, is the basic valid intrinsic mode function, is the step value of the sliding window, is the overlap factor.

[0075] The energy of the intrinsic mode function components reflects the intensity of the data in different frequency components, that is, the importance of the information within a certain frequency range. If the energy of a certain intrinsic mode function component is large, it means that the changes within that frequency range play a more important role in the current data. Conversely, it may represent noise or minor changes. By dynamically adjusting the size of the sliding window according to the energy quantity of the intrinsic mode function components, it is possible to ensure that a smaller window is used in areas where the data fluctuates greatly (i.e., high-energy areas) to accurately capture short-term changes; a larger window is used in areas where the data fluctuates less or is stable (low-energy areas) to improve the calculation efficiency and avoid over-catching irrelevant minor fluctuations. During the process of security situation prediction on the platform, a large amount of complex time-series data (such as network traffic, device status, etc.) is faced. These data may have sudden abnormal changes or long-term stable states. By dynamically adjusting the window size, it is possible to quickly respond in areas with frequent fluctuations (such as when network attack events occur), and improve the analysis efficiency in a relatively stable system situation to avoid overfitting. Security situation prediction involves detecting and predicting abnormal behaviors, such as attack events, device failures, etc. These abnormalities often manifest as sudden changes or abnormal fluctuations in the data, and these fluctuations usually appear in the high-energy part of the modal decomposition. By adjusting the size of the sliding window according to the energy quantity of the intrinsic mode function components, it is possible to ensure that when an abnormal event occurs, a smaller window is used for fine analysis, thereby improving the sensitivity and accuracy of anomaly detection.

[0076] The data processing module is used to determine the hidden value and security coefficient of each location through the dynamic weight allocation method according to the attacked location information, the number of attacks at each location, and the number of successful interceptions within each window time period, and according to the distance of the window time from the current moment. A prediction data set is formed with the security situation influencing factors. According to the sliding window where the failure occurs, the failure rate of the failure type of each sliding window is calculated as the training output set.

[0077] In this embodiment, the calculation formula for the hidden value is: Where, is the hidden value, is the number of attacks, is the data exchange volume, is the number of nodes connected to this location;

[0078] The calculation formula for the security coefficient is: Where, is the security coefficient, is the number of times the attack is intercepted, is the number of illegal operations by users, is the environmental outlier, They are the interception failure rate, the number of illegal user operations, and the weight of environmental outliers respectively. .

[0079] Among them, the calculation method of the environmental outlier is as follows: Among them, is the environmental outlier, is the temperature of the environment where the platform is located, is the standard temperature of the environment where the platform is located, is the humidity of the environment where the platform is located, is the standard humidity of the environment where the platform is located, is the dust concentration of the environment where the platform is located, is the standard dust concentration of the environment where the platform is located.

[0080] The hidden value of each location reflects its importance in historical attacks, which may refer to the sensitivity of the location, the frequency of being attacked, the degree of impact of the attack, etc. The safety factor is related to the security protection ability, interception success rate, historical performance, etc. of the location. By judging these characteristics of each location, it is possible to more accurately identify which locations have higher security risks or potential threats. In the security situation prediction of the platform, some key locations (such as core servers, data center entrances, external communication interfaces, etc.) may be hotspots for attacks. Although the attack frequency is low, once attacked, it may have a serious impact on the entire platform. By comprehensively evaluating the hidden value and safety factor of these locations, it can help the platform prioritize attention to these high-risk locations and dynamically allocate protection resources. For example, if a location has a small number of attacks historically, but its importance is high and the attack success rate is low, its hidden value may be large, indicating that this location may be attacked more frequently or severely in the future.

[0081] In this embodiment, the specific method for judging the hidden value and safety factor of each location by the dynamic weight allocation method is as follows: Among them, is the attenuation coefficient in the th window time period, is the current window time, is the attenuation factor, is the hidden value in the th window time period, is the hidden value after dynamic allocation, is the total number of windows, is the safety factor after dynamic allocation, is the th safety factor in the window time period;

[0082] The calculation method for calculating the failure rate of the failure type of each sliding window according to the sliding window where the failure occurs is as follows: Among them, is the failure rate of the failure type of the th sliding window, is the number of sliding windows, , are all positive integers.

[0083] Time decay takes into account the timeliness of attack behavior, that is, the weights of historical data and current data need to be adjusted according to the time difference. Attack events are usually highly time-sensitive. The closer an attack event is to the current time, the greater its impact on the security situation, while the older the historical data, the smaller the impact. Therefore, using a decay coefficient to reduce the impact of past events helps the model focus more on the dynamic changes at the current moment, avoid over-relying on historical data, and maintain a high real-time prediction ability. A security situation prediction platform needs to flexibly respond to various emergencies and new threats. By reducing the impact of historical data, the platform can more quickly identify changes in the current security situation. For example, the system can pay more attention to recently occurred attack events and reduce its reliance on older events. This dynamic adjustment can enhance the platform's response ability in the face of new types of attacks, emergencies, or complex security threats.

[0084] By combining hidden value, number of attacks, interception success rate, and time decay coefficient, the platform can obtain a more global security situation analysis. This is not limited to the judgment of a single event, but can also accurately grasp the current and future security situations based on comprehensive information from multiple dimensions. The security and hidden value of each location are dynamically evaluated and weighed, and appropriate weights can be assigned to each location in the overall security situation to more accurately predict and respond to potential attack risks.

[0085] The model prediction module is used to establish a security situation prediction model, train the model, and use the prediction data set within the current window time period as the input of the prediction model, and output the training output set within the next step-size sliding window time period through the trained prediction model.

[0086] By introducing the self-attention mechanism and the multi-head attention mechanism, the Transformer model can efficiently process long-sequence data and capture the complex relationships between elements in the sequence. Using the Transformer model, the platform can efficiently capture the data features over a long time span, such as the long-term trend of device failures, potential changes in attack patterns, etc. This is crucial for the accurate prediction of the security situation. For example, when the model attempts to predict the future type of device failure, it may need to capture potential patterns based on historical data over the past few hours, days, or even weeks. The Transformer can maintain good performance in such long time series. The Transformer can, through its multi-level feature learning, comprehensively consider various factors at different time scales and make more accurate security predictions. For example, frequent network attacks in the short term may affect short-term fault warnings, while long-term hardware performance degradation may lead to device failures. The Transformer can consider these factors simultaneously and provide a more comprehensive prediction.

[0087] In this embodiment, the security situation prediction model is established based on the Transformer model and includes:

[0088] Embedding layer: Among them, is the embedded feature vector, is the input prediction data set, is the embedding matrix;

[0089] Position encoding layer: Among them, is the position encoding function, is the position index in the input prediction data set sequence, is the index of the model hidden layer dimension, is the grouping index of the hidden layer dimension, is the model hidden layer dimension;

[0090] Among them, is the embedded feature vector after the position encoding is superimposed;

[0091] Multi-head self-attention layer: Among them, is the attention function, are the query matrix, key matrix, and value matrix respectively, is the dimension of the key and the query, represents the time step of the input sequence;

[0092] Feed-forward network layer: Among them, is the feed-forward network function, , are the weights of the first layer and the biases of the first layer respectively, are the weights of the second layer and the biases of the second layer respectively, is the output value of the multi-head self-attention layer;

[0093] Residual connection layer: wherein, is the normalization function, , is the intermediate feature processed by the self-attention sublayer, is the final output processed by the feed-forward network sublayer;

[0094] Output layer: wherein, is the predicted training output set, are the weights of the output layer and the biases of the output layer respectively, is the non-linear activation function;

[0095] The steps for training the model are as follows: using the prediction data set in the previous step window time period as the input of the security situation prediction model, and the training output set in the next step window time period as the output of the security situation prediction model for training, and optimizing the hyperparameters of the security situation prediction model through the prediction optimization model.

[0096] The model optimization module is used to construct a prediction optimization model and optimize the hyperparameters during the training of the security situation prediction model.

[0097] WOA is a heuristic optimization algorithm that simulates the "spiral hunting behavior" and "bubble net hunting strategy" in the whale hunting method. WOA mainly searches for the optimal solution by the positions of whales in the search space, and uses its powerful global search ability to gradually approach the optimal solution of the objective function. The WOA optimization algorithm is a swarm intelligence algorithm that does not rely on gradient information, so it is very effective in solving non-linear, high-dimensional, and complex optimization problems.

[0098] When training the Transformer model, it is usually necessary to optimize multiple hyperparameters (such as learning rate, batch size, number of layers, number of attention heads, etc.), and these hyperparameters have a crucial impact on the performance of the model. Optimizing these hyperparameters can significantly improve the prediction accuracy and training efficiency of the model. However, since the space of these hyperparameters is usually very large, using traditional manual tuning methods is both time-consuming and laborious, and may not be able to find the optimal configuration.

[0099] The WOA optimization algorithm finds the optimal configuration in the complex hyperparameter space through global search, avoiding the inefficiency of traditional manual tuning methods. Through WOA optimization, the Transformer model can better adapt to variable security data and improve the prediction accuracy.

[0100] For the platform's security situation prediction task, the WOA optimization algorithm can enhance the generalization ability and adaptability of the Transformer model. Platform security situation prediction involves complex spatio-temporal data (such as network traffic, device status, attack events, etc.), and these data have dynamic changes in time and space. Through WOA optimization, the model can automatically adjust hyperparameters to better capture potential security threats and avoid prediction errors for new attacks and device failures. The global search ability of the WOA algorithm enables the model to issue more accurate early warnings when facing various security threats.

[0101] In addition, the WOA optimization algorithm improves the training efficiency of the model when optimizing hyperparameters. In platform security situation prediction, real-time performance is crucial. The fast convergence ability of the WOA algorithm enables the Transformer model to complete training in a shorter time and provide high-quality prediction results. This is crucial for dealing with sudden security events in the public communication platform, which can help the platform respond faster to potential security threats, make defense decisions in a timely manner, and ensure the stable operation and information security of the platform.

[0102] In this embodiment, the model optimization module is based on the WOA optimization algorithm, and the specific optimization steps of the WOA optimization algorithm are as follows;

[0103] Encirclement process: Among them, is the hyperparameter of the security situation prediction model at time is the optimal hyperparameter of the security situation prediction model at time is the coefficient vector used to control the search step and direction, is the distance between the optimal hyperparameter and the optimal hyperparameter of the security situation prediction model;

[0104] Approaching process: Among them, is the tightness of the spiral update, is the constant of the spiral shape, used to control the direction and radius of the spiral, and takes a random number between [-1, 1];

[0105] Search process: Among them, is the position of the randomly selected agent, used to introduce randomness and explore the solution space.

[0106] Please refer to Figure 2 , the present invention further provides a method for predicting the security situation of a platform based on big data. The detection method is obtained by executing the above-mentioned system for predicting the security situation of a platform based on big data. The specific steps include:

[0107] Step 1: Obtain the security situation influencing factors and equipment failure types in a period of time before a failure occurred during the historical operation of the platform to be predicted, stamp time stamps on the security situation influencing factors and equipment failure types, and perform spatio-temporal alignment;

[0108] Step 2: Divide each data of the security situation influencing factors at the same time interval, obtain the intrinsic mode features through modal decomposition, and divide the security situation influencing factor data through a sliding window according to the frequency distribution of all the intrinsic mode features;

[0109] Step 3: According to the attacked location information, the number of attacks at each location, and the number of successful interceptions within each window time period, and according to the distance of the window time from the current moment, judge the hidden value and security coefficient of each location through the dynamic weight allocation method, and form a prediction data set with the security situation influencing factors. According to the sliding window where the failure occurred, calculate the failure rate of the failure type of each sliding window as the training output set;

[0110] Step 4: Establish a security situation prediction model and train the model. By taking the prediction data set within the current window time period as the input of the prediction model, the training output set within the next step-size sliding window time period is output through the trained prediction model;

[0111] Step 5: Construct a prediction optimization model to optimize the hyperparameters during the training of the security situation prediction model.

[0112] The above formulas are all dimensionless and take their numerical calculations. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0113] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed by hardware or software methods depends on the specific application and design constraints of the technical solution.

[0114] The unit described as a separating component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, and it may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0115] As described above, the specific implementation manners of the present application are only provided, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application.

Claims

1. A platform security situation prediction system based on big data, characterized in that Including: A data acquisition module, which is used to obtain the security situation influencing factors and equipment failure types in a period of time before a failure occurs during the historical operation of the platform to be predicted, stamp time stamps on the security situation influencing factors and equipment failure types, and perform spatio-temporal alignment; A feature analysis module, which is used to divide each data of the security situation influencing factors at the same time interval, obtain the intrinsic mode features through modal decomposition, and divide the security situation influencing factor data through a sliding window according to the frequency distribution of all the intrinsic mode features; A data processing module, which is used to judge the hidden value and security coefficient of each location according to the attacked location information, the number of attacks at each location, and the number of successful interceptions within each window time period, and according to the distance of the window time from the current moment, through the dynamic weight allocation method, and form a prediction data set with the security situation influencing factors. According to the sliding window where the failure occurs, calculate the failure rate of the failure type of each sliding window as the training output set; A model prediction module, which is used to establish a security situation prediction model, train the model, use the prediction data set in the current window time period as the input of the prediction model, and output the training output set in the next step-size sliding window time period through the trained prediction model; A model optimization module, which is used to construct a prediction optimization model and optimize the hyperparameters during the training of the security situation prediction model.

2. The platform security situation prediction system based on big data according to claim 1, characterized in that: The security situation influencing factors include network traffic data, equipment status data, user behavior data, external threat data, and environmental data; The equipment failure types include failure parts, network interruption, and equipment interruption; The failure parts include the command system, database, communication terminal, and command terminal.

3. The platform security situation prediction system based on big data according to claim 1, characterized in that: The specific method for performing spatio-temporal alignment is as follows: Among them, is the time-series data sequence after time alignment, are respectively the time-series data sequences of the th data types to be aligned in the security situation influencing factors and equipment failure types, are respectively the th data type's th time-series data, the th data type's th time-series data, is the set of alignment paths, are all positive integers.

4. A platform security situation prediction system based on big data according to claim 1, characterized in that: The calculation formula for obtaining the eigenmode features through modal decomposition is as follows: Among them, is the th data type among the influencing factors of the security situation at time is the th intrinsic mode function among the th data at time is the residual term among the th data at time is the number of intrinsic mode functions.

5. A platform security situation prediction system based on big data according to claim 1, characterized in that: The specific steps for dividing the security situation influencing factor data through a sliding window are as follows: Screening effective intrinsic mode functions through energy thresholds: Among them, is the effective intrinsic mode function, is the th energy of the intrinsic mode function component, is the number of energies of the intrinsic mode function components, is the energy threshold; The calculation formula for the energy of the intrinsic mode function component is as follows: Wherein, is the energy of the th intrinsic mode function component, is the th intrinsic mode function at time The calculation formula of the sliding window is: in, is the size of the sliding window, is the base window size, is the adjustment coefficient that controls the sensitivity of the window to the number of intrinsic mode functions, The first factor affecting security situation The effective intrinsic mode function in the data, is the number of factors affecting security situation, is the basic effective intrinsic mode function, is the step size of the sliding window, is the overlap factor.

6. The platform security situation prediction system based on big data according to claim 1, characterized in that: The calculation formula for the hidden value is as follows: Among them, is the hidden value, is the number of attack times, is the data exchange volume, is the number of nodes connected to this position; The calculation formula for the safety factor is as follows: Among them, is the safety factor, is the number of times the attack is intercepted, is the number of times of illegal operations by users, is the environmental outlier, are the interception failure rate, the number of times of illegal operations by users, and the weights of environmental outliers respectively, .

7. A platform security situation prediction system based on big data according to claim 6, characterized in that: The specific method for judging the hidden value and safety factor of each position by the dynamic weight allocation method is as follows: Among them, is the attenuation coefficient in the -th window time period, is the current window time, is the attenuation factor, is the hidden value in the -th window time period, is the hidden value after dynamic allocation, is the total number of windows, is the safety factor after dynamic allocation, is the -th safety factor in the window time period; The calculation method for calculating the failure rate of the failure type of each sliding window according to the sliding window where the failure occurs is as follows: Among them, is the failure rate of the failure type of the th sliding window, is the number of sliding windows, , are all positive integers.

8. A platform security situation prediction system based on big data according to claim 1, characterized in that: The security situation prediction model is established based on the Transformer model, including: Embedding layer: Among them, is the embedded feature vector, is the input prediction data set, is the embedding matrix; Position encoding layer: Among them, is the position encoding function, is the position index in the input predicted dataset sequence, is the index of the model hidden layer dimension, is the grouping index of the hidden layer dimension, is the model hidden layer dimension; Among them, is the feature vector after embedding with positional encoding superimposed. Multi-head self-attention layer: Among them, is the attention function, are the query matrix, key matrix, and value matrix respectively, is the dimension of the key and query, represents the time step of the input sequence; Feedforward network layer: Among them, is the feedforward network function, , are the weights of the first layer and the bias of the first layer respectively, are the weights of the second layer and the bias of the second layer respectively, is the output value of the multi-head self-attention layer; Residual connection layer: Among them, is a normalization function, , is the intermediate feature after the self-attention sublayer processing, is the final output after the feed-forward network sublayer processing; Output layer: Among them, is the predicted training output set, are the output layer weights and the output layer bias respectively, is the non-linear activation function.

9. A platform security situation prediction system based on big data according to claim 1, characterized in that: The model optimization module is based on the WOA optimization algorithm, and the specific optimization steps of the WOA optimization algorithm are as follows: Surrounding process: Among them, is the hyperparameter of the moment security situation prediction model, is the optimal hyperparameter of the moment security situation prediction model, is the coefficient vector used to control the search step and direction, is the distance between the optimal hyperparameter of the security situation prediction model and the optimal hyperparameter; Approaching process: Among them, is the tightness of spiral update, is a constant of the spiral shape, used to control the direction and radius of the spiral, and takes a random number in the range of [-1, 1]; Search process: Among them, is the position of a randomly selected agent, which is used to introduce randomness and explore the solution space.

10. A platform security situation prediction method based on big data, characterized in that: The security situation prediction method is executed by a platform security situation prediction system based on big data according to any one of claims 1-9, and the specific steps include: Step 1: Obtain the security situation influencing factors and equipment failure types in a period of time before a failure occurs during the historical operation of the platform to be predicted, stamp time stamps on the security situation influencing factors and equipment failure types, and perform spatio-temporal alignment; Step 2: Divide each data of the security situation influencing factors at the same time interval, obtain the intrinsic mode features through modal decomposition, and divide the security situation influencing factor data through a sliding window according to the frequency distribution of all the intrinsic mode features; Step 3: According to the attacked location information within each window time period, the number of attacks at each location, and the number of successful interceptions, and based on the distance of the window time from the current moment, judge the hidden value and safety factor of each location through the dynamic weight allocation method, and form a prediction data set with the security situation influencing factors. According to the sliding window where the failure occurs, calculate the failure rate of the failure type for each sliding window of the failure as the training output set; Step 4: Establish a security situation prediction model and train the model. By using the prediction data set within the current window time period as the input of the prediction model, the training output set within the next step-size sliding window time period is output through the trained prediction model; Step 5: Build a prediction optimization model to optimize the hyperparameters during the training of the security situation prediction model.

Citation Information

Patent Citations

  • Network security situation prediction method and system

    CN114037145A

  • Software vulnerability trend prediction method based on EEMD and ARMA

    CN115098865A