Network security risk dynamic simulation analysis system based on big data analysis
By continuously obtaining and analyzing new risk information in the direction of the time axis, conducting risk simulation prediction and joint analysis, the problem that the existing technology cannot adapt to the rapid iterative network attack methods is solved, dynamic response and confirmation of network risks is achieved, and network security protection is improved.
Patent Information
- Application Number
- CN202510385628.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-29
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-29
AI Technical Summary
The existing big data comparison methods cannot adapt to the rapid iterative cyber attack methods, especially when multiple attack methods are combined, it is difficult to identify risks in a timely manner and issue warnings, affecting network security.
By constantly obtaining new risk information in the time axis direction, conducting risk simulation and prediction, and jointly analyzing and reviewing multiple prediction results, dynamic simulation and confirmation of network risks can be achieved.
It improves the dynamic response ability of network security protection, enhances the ability to respond to rapidly changing risk factors and multiple risk factors, and improves the effectiveness of network security protection.
Smart Images

Figure CN120151064A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and specifically to a dynamic simulation analysis system for network security risks based on big data analysis. Background Art
[0002] With the continuous development of computer networks, global informatization has become a major trend in human development. However, due to the diverse connection forms, uneven distribution of terminals, openness, and interconnectivity of computer networks, the network is vulnerable to attacks by hackers, malware, and other malicious parties. Therefore, in order to prevent and avoid attacks and intrusions and ensure the security of online information, network security systems play a crucial role. Currently, three commonly used network security systems are widely applied - firewalls, IDS (Intrusion Detection System) network intrusion detection systems, and IPS (Intrusion Prevention System) intrusion prevention systems;
[0003] Currently, with the development and maturity of big data technology, big data technology has been gradually applied to network security assurance work. The wide application of big data technology provides new impetus for network security analysis and defense and has become an indispensable part in the construction of network security analysis systems. The prior patent application CN2022106719893 discloses a technical solution. This solution can achieve real-time monitoring of network data and corresponding data security analysis by qualitatively analyzing data and comparing abnormal data with big data, and has the advantages of high processing efficiency and data reliability. However, in network protection, with the rapid iteration of network attack methods, simple big data comparison methods cannot adapt to the rapidly developing attack methods. At the same time, when multiple network attack methods are combined, it will cause great interference to the comparison and identification of big data, making it difficult to timely alarm risks and affecting network security;
[0004] In view of the above technical problems, this application proposes a solution. Summary of the Invention
[0005] When the present invention conducts simulation analysis on network risks, it continuously obtains new risk information in the time axis direction and further conducts risk simulation prediction through the new risk information. Then, the results of multiple predictions are jointly analyzed, and the judged risk results are reviewed to further confirm or correct the risk simulation in the network, which can meet the dynamic response requirements in the network security protection process, improve the network security protection effect, solve the problem of lacking the ability to respond to the rapid changes of risk factors and the combination of multiple risk factors during network risk analysis, and thus the problem of insufficient dynamic response ability of network security risks. Therefore, a dynamic simulation analysis system for network security risks based on big data analysis is proposed.
[0006] The object of the present invention can be achieved through the following technical solutions:
[0007] A network security risk dynamic simulation analysis system based on big data analysis, including a network risk composite acquisition unit, a network risk monitoring module, a database construction module, a simulation analysis module, and a dynamic warning update module. The network risk composite acquisition unit is used to collect various network operation information, classify and record the collected information to obtain a network operation information set, and send the collected network operation information set to the network risk monitoring module;
[0008] After obtaining the network operation information set, the network risk monitoring module makes a compliance judgment on the network operation information of different classifications in the network operation information set, divides it into risk information and normal information, and sends the risk information to the database construction module and the simulation analysis module;
[0009] The database construction module updates the database by continuously receiving risk information. At the same time, the database construction module is connected to a third-party platform through an external window and updates the risk model in real time through the third-party platform;
[0010] The simulation analysis module compares the obtained risk information with the database constructed by the database construction module, generates a risk output warning according to the comparison result, and sends the risk output warning to the dynamic warning update module;
[0011] The dynamic warning update module responds to the risk output warning and gives a warning reminder;
[0012] After generating the risk output warning, the simulation analysis module continues to receive risk information, mixes and analyzes the newly received risk information with the risk information when generating the risk output warning to form a dynamic feature of risk information, and continues to compare the dynamic feature of risk information through the risk model to generate a risk adjustment warning, and continues to remind through the dynamic warning update module for the risk adjustment warning.
[0013] As a preferred implementation manner of the present invention, the network operation information collected by the network risk composite acquisition unit includes network operation logs, network traffic, and user behavior. When the network risk composite acquisition unit collects network operation logs, it obtains the network operation logs within a certain time interval at a preset interval;
[0014] When the network risk composite acquisition unit collects network traffic, it is statistically analyzed through network nodes, and the collected network traffic is the total number of network transmission bytes within each preset time period;
[0015] When the network risk composite acquisition unit collects user behavior, the same IP identity is regarded as the same user, and the user behavior of the same IP identity is recorded;
[0016] The network risk composite acquisition unit separately counts the network operation logs, network traffic, and user behaviors as three subsets, and then combines the three subsets into a network operation information set.
[0017] As a preferred embodiment of the present invention, the network risk monitoring module selects the subset of network operation logs, extracts and marks abnormal behaviors in the network operation logs through a preset self-check program, and counts the total amount of abnormal behaviors existing in the network operation logs, which is recorded as risk information;
[0018] The network risk monitoring module selects the subset of network traffic, compares the network traffic with a set traffic range. If the network traffic is within the set traffic range, it is classified as normal information; if the network traffic is outside the set traffic range, it is classified as risk information;
[0019] The network risk monitoring module selects the subset of user behaviors, and compares the user behaviors in the subset with a set high-risk behavior database. If the user behavior coincides with the database, it is classified as normal information; if the user behavior does not coincide with the database, it is classified as risk information.
[0020] As a preferred embodiment of the present invention, when the simulation analysis module compares the risk information with the risk model, it first selects a blank risk model, fills all the risk information into the blank risk model to form an actual risk model, and then compares the actual risk model with multiple risk models to obtain the coincidence degree between the models. The group of risk models with the highest coincidence degree is recorded as the adapted model, and the coincidence degree between the actual risk model and the adapted model is recorded as the risk coincidence degree;
[0021] The simulation analysis module compares the risk coincidence degree with a set coincidence threshold. If the risk coincidence degree is greater than the set coincidence threshold, a risk output warning is generated; if the risk coincidence degree is not greater than the set coincidence threshold, no warning is generated.
[0022] As a preferred embodiment of the present invention, after the simulation analysis module generates a risk output warning, the received risk information is recorded as fixed information, and after receiving new risk information, the new risk information is recorded as supplementary information;
[0023] The simulation analysis module constructs a new actual risk model through the supplementary information, and compares the new actual risk model with the adapted model again to obtain a rechecked risk coincidence degree.
[0024] As a preferred embodiment of the present invention, the simulation analysis unit compares the rechecked risk coincidence degree with the risk coincidence degree. If the rechecked risk coincidence degree is greater than or equal to the set risk coincidence degree, a risk confirmation signal is generated; if the rechecked risk coincidence degree is less than the risk coincidence degree, a risk anomaly signal is generated.
[0025] As a preferred embodiment of the present invention, after generating the risk anomaly signal, the simulation analysis unit compares the actual risk model constructed by the supplementary information with multiple risk models in the database to obtain multiple groups of coincidence degrees again, marks those greater than the rechecked risk coincidence degree among the multiple groups of coincidence degrees, and records the corresponding risk models as the rechecked models.
[0026] As a preferred embodiment of the present invention, the simulation analysis unit records the risk model with the highest coincidence degree in the rechecked models as the adjusted risk model, generates a risk adjustment warning, and sends the risk adjustment warning to the dynamic warning update module.
[0027] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0028] 1. In the present invention, the database constructed by big data is used to judge the risk information during the network operation process, and then the risk information and the risk information stored in the database are used for model construction and coincidence degree comparison, so as to realize the simulation online of the risk information and the comparison of the repetition degree. Furthermore, the risk situation existing in the network can be discovered in time through big data, which is convenient for dealing with the network risk in advance. At the same time, through the database with a cloud interface, the model library can be updated in time, thereby improving the accuracy and timeliness of the risk simulation analysis.
[0029] 2. In the present invention, when simulating and analyzing the network risk, new risk information is continuously obtained in the time axis direction, and the risk simulation prediction is further carried out through the new risk information. Then, the results of multiple predictions are jointly analyzed to recheck the judged risk results, so as to further confirm or correct the risk in the network, which can meet the dynamic response requirements in the network security protection process and improve the network security protection effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.
[0031] Figure 1 is the system block diagram of the present invention;
[0032] Figure 2 is the system flow chart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0034] Embodiment 1:
[0035] Please refer to Figure 1 - Figure 2 As shown, a dynamic simulation analysis system for network security risks based on big data analysis includes a network risk composite collection unit, a network risk monitoring module, a database construction module, a simulation analysis module, and a dynamic warning update module. The network risk composite collection unit is used to collect various network operation information. The network operation information collected by the network risk composite collection unit includes network operation logs, network traffic, and user behavior. The collected information is classified and recorded to obtain a network operation information set, and the collected network operation information set is sent to the network risk monitoring module. The network operation information set includes three subsets: a network operation log subset, a network traffic subset, and a user behavior subset;
[0036] When the network risk composite collection unit collects network operation logs, it obtains the network operation logs within a certain time interval at a preset interval;
[0037] When the network risk composite collection unit collects network traffic, it is statistically analyzed through network nodes, and the collected network traffic is the total number of network transmission bytes within each preset time period;
[0038] When the network risk composite collection unit collects user behavior, the same IP identity is regarded as the same user, and the user behavior of the same IP identity is recorded;
[0039] After obtaining the network operation information set, the network risk monitoring module makes a compliance judgment on the network operation information of different classifications in the network operation information set, divides it into risk information and normal information, and sends the risk information to the database construction module and the simulation analysis module;
[0040] The specific method for the network risk monitoring module to make a compliance judgment on the network operation information is:
[0041] The network risk monitoring module selects a subset of network operation logs, extracts and marks abnormal behaviors in the network operation logs through a preset self-check program, and counts the total number of abnormal behaviors in the network operation logs, which is recorded as risk information. The abnormal behaviors in the network operation logs include high-frequency failed login records, access to sensitive paths, brute-force cracking records, abnormal IP addresses, continuous access to non-existent URLs, and suspicious file creation records, etc.;
[0042] The network risk monitoring module selects a subset of network traffic, compares the network traffic with the set traffic range. If the network traffic is within the set traffic range, it is classified as normal information. If the network traffic is outside the set traffic range, it is classified as risk information;
[0043] The network risk monitoring module selects a subset of user behaviors, and compares the user behaviors in the subset with a set high-risk behavior database. If the user behavior coincides with the database, it is classified as normal information. If the user behavior does not coincide with the database, it is classified as risk information;
[0044] The database construction module updates the database by continuously receiving risk information. At the same time, the database construction module connects to a third-party platform through an external window and updates the risk model in real time through the third-party platform to improve the update speed of the risk model in the database. When simulating and analyzing risks, it can identify risk behaviors more comprehensively and accurately;
[0045] The simulation analysis module compares the obtained risk information with the database constructed by the database construction module, generates a risk output warning according to the comparison result, and sends the risk output warning to the dynamic warning update module;
[0046] When the simulation analysis module compares the risk information with the risk model, it first selects a blank risk model, fills all the risk information into the blank risk model to form a risk actual model, and then compares the risk actual model with multiple risk models to obtain the coincidence degree between the models. The higher the coincidence degree, the more similar the risk information is to the risk situation stored in the database. The group of risk models with the highest coincidence degree is recorded as the adapted model, and the coincidence degree between the risk actual model and the adapted model is recorded as the risk coincidence degree;
[0047] The simulation analysis module compares the risk coincidence degree with the set coincidence threshold. If the risk coincidence degree is greater than the set coincidence threshold, a risk output warning is generated. If the risk coincidence degree is not greater than the set coincidence threshold, no warning is generated;
[0048] The dynamic warning update module responds to the risk output warning and gives a warning reminder, so as to remind the management personnel or the network system to automatically perform risk killing or make corresponding processing, avoiding the impact on network operation;
[0049] Embodiment 2:
[0050] Please refer to Figure 1 - Figure 2 As shown, after the simulation analysis module generates a risk output warning, it continues to receive risk information. And after the simulation analysis module generates a risk output warning, it records the received risk information as fixed information. After receiving new risk information, it records the new risk information as supplementary information. The simulation analysis module constructs a new actual risk model through the supplementary information and compares the new actual risk model with the adaptation model again to obtain the review risk coincidence degree. The simulation analysis unit compares the review risk coincidence degree with the risk coincidence degree. If the review risk coincidence degree is greater than or equal to the set risk coincidence degree, a risk confirmation signal is generated. If the review risk coincidence degree is less than the risk coincidence degree, a risk anomaly signal is generated, thereby constituting the dynamic characteristics of risk information and dynamically responding to the changes in risk information;
[0051] The simulation analysis module continues to compare the dynamic characteristics of risk information through the risk model, compares the actual risk model constructed by the supplementary information with multiple risk models in the database, obtains multiple groups of coincidence degrees again, marks those greater than the review risk coincidence degree among the multiple groups of coincidence degrees, and records the corresponding risk models as review models. The simulation analysis unit records the risk model with the highest coincidence degree in the review models as the adjusted risk model and generates a risk adjustment warning, and sends the risk adjustment warning to the dynamic warning update module for continuous reminder through the dynamic warning update module.
[0052] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific implementation manners shown. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the relevant technical fields can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A network security risk dynamic simulation analysis system based on big data analysis, characterized by: It includes a network risk composite collection unit, a network risk monitoring module, a database construction module, a simulation analysis module and a dynamic warning update module. The network risk composite collection unit is used to collect a variety of network operation information, classify and record the collected information, obtain a network operation information set, and send the collected network operation information set to the network risk monitoring module; After obtaining the network operation information set, the network risk monitoring module performs compliance judgment on the network operation information of different categories in the network operation information set, divides it into risk information and normal information, and sends the risk information to the database construction module and the simulation analysis module; The database construction module updates the database by continuously receiving risk information. At the same time, the database construction module is connected to the third-party platform through an external window, and updates the risk model in real time through the third-party platform; The simulation analysis module compares the acquired risk information with the database constructed by the database construction module, generates a risk output warning according to the comparison result, and sends the risk output warning to the dynamic warning update module; The dynamic warning update module responds to the risk output warning and issues a warning reminder; After generating the risk output warning, the simulation analysis module continues to receive risk information, and performs mixed analysis on the newly received risk information and the risk information when generating the risk output warning to form dynamic characteristics of the risk information, and continues to compare the dynamic characteristics of the risk information through the risk model to generate a risk adjustment warning, and continues to remind the risk adjustment warning through the dynamic warning update module.
2. The network security risk dynamic simulation analysis system based on big data analysis according to claim 1 is characterized in that: The network operation information collected by the network risk composite collection unit includes network operation logs, network traffic and user behavior. When the network risk composite collection unit collects network operation logs, the network operation logs within the interval are obtained once every certain period of time at a preset interval; When the network risk composite collection unit collects network traffic, statistics are performed through network nodes, and the collected network traffic is the total number of bytes transmitted by the network in each preset time period; The network risk composite collection unit collects user behaviors, treating the same IP identity as the same user, and records the user behaviors of the same IP identity; The network risk composite collection unit divides the network operation log, network traffic and user behavior into three subsets for statistics respectively, and then combines the three subsets into a network operation information set.
3. The network security risk dynamic simulation analysis system based on big data analysis according to claim 1 is characterized in that: The network risk monitoring module selects a subset of network operation logs, extracts and marks abnormal behaviors in the network operation logs through a preset self-checking program, and counts the total amount of abnormal behaviors in the network operation logs and records them as risk information; The network risk monitoring module selects a subset of network traffic, compares the network traffic with a set traffic range, and classifies the network traffic as normal information if it is within the set traffic range, and classifies the network traffic as risk information if it is outside the set traffic range; The network risk monitoring module selects a user behavior subset and compares the user behavior in the subset with a set high-risk behavior database. If the user behavior coincides with the database, it is classified as normal information; if the user behavior does not coincide with the database, it is classified as risk information.
4. The network security risk dynamic simulation analysis system based on big data analysis according to claim 1 is characterized in that: When the simulation analysis module compares the risk information with the risk model, it first selects a blank risk model and fills all the risk information into the blank risk model to form a risk actual model, then compares the risk actual model with multiple risk models to obtain the overlap between the models, and records the group of risk models with the highest overlap as the adaptation model, and records the overlap between the risk actual model and the adaptation model as the risk overlap; The simulation analysis module compares the risk overlap with the set overlap threshold. If the risk overlap is greater than the set overlap threshold, a risk output warning is generated. If the risk overlap is not greater than the set overlap threshold, no warning is generated.
5. The network security risk dynamic simulation analysis system based on big data analysis according to claim 1 is characterized in that: After generating the risk output warning, the simulation analysis module records the received risk information as fixed information, and after receiving new risk information, records the new risk information as supplementary information; The simulation analysis module constructs a new actual risk model through supplementary information, and compares the new actual risk model with the adaptation model again to obtain the verified risk overlap.
6. The network security risk dynamic simulation analysis system based on big data analysis according to claim 5 is characterized in that: The simulation analysis unit compares the verified risk overlap with the risk overlap. If the verified risk overlap is greater than or equal to the set risk overlap, a risk confirmation signal is generated. If the verified risk overlap is less than the risk overlap, a risk abnormality signal is generated.
7. The network security risk dynamic simulation analysis system based on big data analysis according to claim 6 is characterized in that: After generating a risk anomaly signal, the simulation analysis unit compares the actual risk model constructed by the supplementary information with multiple risk models in the database, and obtains multiple groups of overlaps again. The multiple groups of overlaps that are greater than the review risk overlap are marked, and the corresponding risk model is recorded as the review model.
8. The network security risk dynamic simulation analysis system based on big data analysis according to claim 7 is characterized in that: The simulation analysis unit records the model with the highest degree of overlap in the review model as the adjusted risk model, generates a risk adjustment warning, and sends the risk adjustment warning to the dynamic warning update module.
Citation Information
Patent Citations
Intelligent supervision and early warning system and method for campus safety
CN116486586A
Communication information security risk early warning management and control method and system based on big data
CN117955712A
Dynamic early warning system and early warning method for network and information security
CN118827159A
Data security risk assessment early warning system
CN119128899A
Information security network integrated management system using big data and artificial intelligence, and a method thereof
KR101814368B1