Big data analysis processing method and system for network security

Through big data analysis and processing methods, including data collection, preprocessing, feature extraction and machine learning model construction, the problem that traditional security detection methods are difficult to adapt to complex network environments is solved, and efficient and accurate network attack detection and automatic response are achieved.

CN120128362AInactive Publication Date: 2025-06-10呼和浩特职业技术大学
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510208391.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional security detection methods based on rules or feature matching are difficult to adapt to complex and changeable network environments, resulting in insufficient processing speed, accuracy and real-time performance of network security.

Method used

The big data analysis and processing methods for network security are adopted, including collecting data from network devices, preprocessing and feature extraction, using machine learning algorithms to build a network attack detection model, real-time detection and automatic security response measures, and providing a visual interface to display the analysis results.

Benefits of technology

Real-time and accurate detection of network attacks is achieved, the efficiency and accuracy of network security protection is improved, and it can adapt to changing network security threats and respond to network security incidents in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128362A_ABST
    Figure CN120128362A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security and big data analysis, and discloses a big data analysis processing method and system for network security, and the method comprises the steps: S1, data collection: collecting network flow data, log data and user behavior data from network equipment, a server and terminal equipment; s2, data preprocessing: carrying out cleaning, formatting and normalization preprocessing operation on the collected data; s3, feature extraction: extracting related features from the preprocessed data according to the requirements of network security; the method can accurately detect the network attack in real time, improves the efficiency and accuracy of network security protection, has good expansibility and flexibility, and can adapt to continuously changing network security threats; rapid analysis and processing of mass data are realized through a big data processing framework; according to a threat detection result, corresponding security response measures are automatically taken, and a network security event is responded in time; and a visual interface is provided, so that operation and maintenance personnel can conveniently monitor the network security situation in real time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security and big data analysis, and specifically to a big data analysis processing method and system for network security. Background Art

[0002] With the popularization of the Internet in today's society, human economic production and life are increasingly closely integrated through the network. With the increase in the complexity of processing tasks, the network structure has not only become more complex, but the data scale has also become larger and larger, which has led to network security threats and risks faced by users in the process of using the Internet. Network attacks have the characteristics and development trends of being distributed, large-scale and complex, and network security issues have become the focus of attention.

[0003] Due to the rapid development of the Internet, the amount of network data is growing exponentially. How to extract valuable information from these massive data and timely discover and respond to network security threats has become a major challenge in the current network security field. Traditional security detection methods based on rules or feature matching have been difficult to adapt to the complex and changing network environment, resulting in deficiencies in network security processing speed, accuracy and real-time performance. Therefore, a big data analysis and processing method and system for network security are proposed. Summary of the invention

[0004] The purpose of the present invention is to provide a big data analysis and processing method and system for network security, so as to solve the problem that the traditional security detection method based on rules or feature matching mentioned in the above background technology has been difficult to adapt to the complex and changeable network environment, resulting in insufficient processing speed, accuracy and real-time performance of network security.

[0005] To achieve the above object, the present invention provides the following technical solution: a big data analysis and processing method for network security, comprising the following steps:

[0006] S1. Collect network traffic data, log data and user behavior data from network devices, servers and terminal devices;

[0007] S2. Perform preprocessing operations such as cleaning, formatting, and normalization on the collected data;

[0008] S3. Extract relevant features from the preprocessed data according to network security requirements;

[0009] S4. Use machine learning algorithms to train the extracted features and build a network attack detection model;

[0010] S5, input the real-time collected data into the trained model to detect network attacks;

[0011] S6. Automatically take corresponding safety response measures based on the detection results;

[0012] S7. Provide an intuitive visualization interface to display the analysis results of network data, threat situation, and the execution status of security policies.

[0013] Preferably, in the above S2, the collected data is converted into a unified scale, and the conversion formula is as follows:

[0014]

[0015] Where x is the original data, μ is the mean, σ is the standard deviation, and x' is the normalized data.

[0016] Preferably, in the above S3, the features used include network traffic features, protocol anomaly features, user behavior features, and system log features. The PCA algorithm is adopted, and by calculating the covariance matrix between feature vectors and performing feature dimensionality reduction, the calculation formula is as follows:

[0017]

[0018] Where C is the covariance matrix, X is the feature matrix, and n is the number of samples.

[0019] Preferably, in the above S4, the machine learning algorithms used include support vector machines, random forests, neural networks, and deep learning algorithms.

[0020] Preferably, in the above S5, a real-time data processing algorithm based on a sliding window is adopted, and the formula is as follows:

[0021]

[0022] Where S(t) represents the security score at time point t, w i represents the weight of the i-th feature, and f(x i ,t) represents the function value of the i-th feature at time point t.

[0023] Preferably, in the above S6, a rule-based response strategy is adopted, and its rule set is as follows:

[0024] R = {(C 1 , A 1 ), (C 2 , A 2 ),..., (C n , A n )}

[0025] Where R represents the rule set, C i represents the condition of the i-th rule, and A i represents the response action taken when the condition C i is satisfied.

[0026] A big data analysis and processing system for network security, including a data collection module, a data preprocessing module, a feature extraction module, a model training module, a real-time monitoring module, a response processing module, and a visualization display module;

[0027] The data collection module is used to collect network traffic data, log data, and user behavior data from network devices, servers, and terminal devices;

[0028] The data preprocessing module is used to perform cleaning, formatting, and normalization preprocessing operations on the collected data;

[0029] The feature extraction module is used to extract relevant features from the preprocessed data according to the requirements of network security;

[0030] The model training module is used to train the extracted features using machine learning algorithms to build a network attack detection model;

[0031] The real-time monitoring module is used to input the real-time collected data into the trained model for network attack detection;

[0032] The response processing module is used to automatically take corresponding security response measures according to the detection results;

[0033] The visualization display module is used to provide an intuitive visualization interface to display the analysis results of network data, threat situations, and the execution status of security policies.

[0034] Preferably, the data collection module is connected to the data preprocessing module, the data preprocessing module is connected to the feature extraction module, the feature extraction module is connected to the model training module, the model training module is connected to the real-time monitoring module, the real-time monitoring module is connected to the response processing module, and the response processing module is connected to the visualization display module.

[0035] Preferably, the data collection module collects network traffic data and log data through network probes and proxy servers.

[0036] Preferably, the feature extraction module can extract user behavior features and system log features.

[0037] Compared with the prior art, the present invention adopting the above technical solutions has the following technical effects: The present invention can detect network attacks in real time and accurately, improve the efficiency and accuracy of network security protection. At the same time, the system of the present invention has good scalability and flexibility, and can adapt to the constantly changing network security threats; through the big data processing framework, the rapid analysis and processing of massive data are realized; according to the threat detection results, corresponding security response measures are automatically taken to respond to network security incidents in a timely manner; a visual interface is provided to facilitate the operation and maintenance personnel to monitor the network security situation in real time. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.

[0039] Figure 1 is the flowchart of the method of the present invention;

[0040] Figure 2 is the system schematic diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0042] It should be noted that the structures, ratios, sizes, etc. shown in the drawings of this specification are only used to cooperate with the content disclosed in the specification for those who are familiar with this technology to understand and read, and are not used to limit the limited conditions that can be implemented in the present application. Therefore, they do not have any technical essence. Any modification of the structure, change of the proportional relationship or adjustment of the size, without affecting the effects that the present application can produce and the purposes that can be achieved, should still fall within the scope that the technical content disclosed in the present application can cover.

[0043] Embodiment

[0044] Please refer to Figure 1-2 , the present invention provides a technical solution: a big data analysis and processing method for network security, including the following steps:

[0045] S1. Collect network traffic data, log data, and user behavior data from network devices, servers, and terminal devices;

[0046] S2. Clean, format, and normalize the collected data for preprocessing operations;

[0047] S3. Extract relevant features from the preprocessed data according to network security requirements;

[0048] S4. Use machine learning algorithms to train the extracted features and build a network attack detection model;

[0049] S5. Input the real-time collected data into the trained model for network attack detection;

[0050] S6. Automatically take corresponding security response measures according to the detection results;

[0051] S7. Provide an intuitive visualization interface to display the analysis results of network data, threat situation, and the execution status of security policies.

[0052] In S2, convert the collected data into a unified scale, and the conversion formula is as follows:

[0053]

[0054] where x is the original data, μ is the mean, σ is the standard deviation, and x' is the normalized data.

[0055] In S3, the features used include network traffic features, protocol anomaly features, user behavior features, and system log features. The PCA algorithm is adopted. By calculating the covariance matrix between feature vectors and performing feature dimensionality reduction, the calculation formula is as follows:

[0056]

[0057] where C is the covariance matrix, X is the feature matrix, and n is the number of samples.

[0058] In S4, the machine learning algorithms used include support vector machines, random forests, neural networks, and deep learning algorithms.

[0059] In S5, adopt a real-time data processing algorithm based on a sliding window, and the formula is as follows:

[0060]

[0061] where S(t) represents the security score at time point t, w i represents the weight of the i-th feature, and f(x i ,t) represents the function value of the i-th feature at time point t.

[0062] In S6, adopt a rule-based response strategy, and its rule set is as follows:

[0063] R = {(C 1 , A 1 ), (C 2 , A 2 ),..., (C n , A n )}

[0064] Among them, R represents the rule set, C i represents the condition of the i-th rule, and A i represents the response action to be taken when the condition C i is satisfied.

[0065] A big data analysis and processing system for network security includes a data collection module, a data preprocessing module, a feature extraction module, a model training module, a real-time monitoring module, a response processing module, and a visualization display module;

[0066] The data collection module is used to collect network traffic data, log data, and user behavior data from network devices, servers, and terminal devices;

[0067] The data preprocessing module is used to perform cleaning, formatting, and normalization preprocessing operations on the collected data;

[0068] The feature extraction module is used to extract relevant features from the preprocessed data according to the requirements of network security;

[0069] The model training module is used to train the extracted features using machine learning algorithms to build a network attack detection model;

[0070] The real-time monitoring module is used to input the real-time collected data into the trained model for network attack detection;

[0071] The response processing module is used to automatically take corresponding security response measures according to the detection results;

[0072] The visualization display module is used to provide an intuitive visualization interface to display the analysis results of network data, threat situations, and the execution status of security policies.

[0073] The data collection module is connected to the data preprocessing module, the data preprocessing module is connected to the feature extraction module, the feature extraction module is connected to the model training module, the model training module is connected to the real-time monitoring module, the real-time monitoring module is connected to the response processing module, and the response processing module is connected to the visualization display module.

[0074] The data collection module collects network traffic data and log data through network probes and proxy servers.

[0075] The feature extraction module can extract user behavior features and system log features.

[0076] In summary, the present invention can detect network attacks in real time and accurately, improve the efficiency and accuracy of network security protection. At the same time, the system of the present invention has good scalability and flexibility, and can adapt to changing network security threats; through the big data processing framework, it realizes the rapid analysis and processing of massive data; according to the threat detection results, it automatically takes corresponding security response measures to respond to network security incidents in a timely manner; it provides a visual interface to facilitate the operation and maintenance personnel to monitor the network security situation in real time.

[0077] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present invention can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features recited in the various embodiments and / or claims of the present invention can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.

Claims

1. A big data analysis and processing method for network security, characterized by: The following steps are involved: S1. Collect network traffic data, log data and user behavior data from network devices, servers and terminal devices; S2. Perform preprocessing operations such as cleaning, formatting, and normalization on the collected data; S3. Extract relevant features from the preprocessed data according to network security requirements; S4. Use machine learning algorithms to train the extracted features and build a network attack detection model; S5, input the real-time collected data into the trained model to detect network attacks; S6. Automatically take corresponding safety response measures based on the detection results; S7. Provides an intuitive visual interface to display the analysis results of network data, threat situation and the implementation of security policies.

2. The method for analyzing and processing big data for network security according to claim 1, characterized in that: In S2, the collected data is converted into a unified scale. The conversion formula is as follows: Among them, x is the original data, μ is the mean, σ is the standard deviation, and x′ is the normalized data.

3. The method for analyzing and processing big data for network security according to claim 1, characterized in that: In S3, the features used include network traffic features, protocol anomaly features, user behavior features, and system log features. The PCA algorithm is used to calculate the covariance matrix between feature vectors and perform feature dimensionality reduction. The calculation formula is as follows: Among them, C is the covariance matrix, X is the feature matrix, and n is the number of samples.

4. The method for analyzing and processing big data for network security according to claim 1, characterized in that: In S4, the machine learning algorithms used include support vector machines, random forests, neural networks, and deep learning algorithms.

5. The method for analyzing and processing big data for network security according to claim 1, characterized in that: In S5, a real-time data processing algorithm based on a sliding window is adopted, and the formula is as follows: Among them, S(t) represents the safety score at time point t, w i represents the weight of the i-th feature, f(x i ,t) represents the function value of the i-th feature at time point t.

6. The method for analyzing and processing big data for network security according to claim 1, characterized in that: In S6, a rule-based response strategy is adopted, and its rule set is as follows: R={(C1,A1),(C2,A2),...,(C n ,A n )} Among them, R represents the rule set, C i represents the condition of the i-th rule, A i Indicates that condition C is met i The response action to be taken.

7. A big data analysis and processing system for network security, characterized by: It includes data acquisition module, data preprocessing module, feature extraction module, model training module, real-time monitoring module, response processing module and visualization display module; The data collection module is used to collect network traffic data, log data and user behavior data from network devices, servers and terminal devices; The data preprocessing module is used to perform cleaning, formatting, and normalization preprocessing operations on the collected data; The feature extraction module is used to extract relevant features from the preprocessed data according to network security requirements; The model training module is used to train the extracted features using a machine learning algorithm to build a network attack detection model; The real-time monitoring module is used to input the real-time collected data into the trained model to perform network attack detection; The response processing module is used to automatically take corresponding security response measures according to the detection results; The visualization display module is used to provide an intuitive visualization interface to display the analysis results of network data, threat situation and the implementation of security policies.

8. The network security big data analysis and processing method and system according to claim 7, characterized in that: The data acquisition module is connected to the data preprocessing module, the data preprocessing module is connected to the feature extraction module, the feature extraction module is connected to the model training module, the model training module is connected to the real-time monitoring module, the real-time monitoring module is connected to the response processing module, and the response processing module is connected to the visualization display module.

9. The network security big data analysis and processing method and system according to claim 7, characterized in that: The data collection module collects network flow data and log data through network probes and proxy servers.

10. The network security big data analysis and processing method and system according to claim 7, characterized in that: The feature extraction module can extract user behavior features and system log features.