Network security risk dynamic simulation analysis system based on big data analysis
The network security risk dynamic simulation analysis system, which utilizes big data analytics, acquires and simulates network risk information in real time, solving the problem of identifying and interfering with rapidly iterating attack methods in network security analysis, and achieving dynamic response and precise protection of network security.
Patent Information
- Application Number
- CN202510385628.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-29
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-03-29
AI Technical Summary
Existing big data technologies are ill-suited to the rapidly evolving nature of cyberattacks in cybersecurity analysis. This results in significant interference when multiple attack methods are combined, hindering timely risk alerts and leading to insufficient cybersecurity risk response capabilities.
A network security risk dynamic simulation and analysis system based on big data analytics is used to acquire and simulate network risk information in real time. By building a database and updating models, joint analysis and verification of risk information are carried out to achieve dynamic response.
It improves the timeliness and accuracy of network security protection, enabling timely detection and response to network risks, meeting dynamic response needs, and enhancing the effectiveness of network security protection.
Smart Images

Figure CN120151064B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the field of network security, and in particular to a network security risk dynamic simulation analysis system based on big data analysis. BACKGROUND
[0002] With the continuous development of computer networks, global informatization has become a major trend of human development, but due to the characteristics of computer networks, such as diversity of connection form, uneven distribution of terminals, openness and interconnection of networks, the networks are vulnerable to attacks by hackers, malicious software and other unscrupulous attacks, so, in order to prevent and avoid attacks and intrusions, to ensure the safety of online information, network security systems play a great role, and the three common network security systems currently widely used are firewall, IDS network intrusion monitoring system and IPS intrusion prevention system.
[0003] At present, with the development and maturity of big data technology, big data technology is gradually applied to network security work, and the wide application of big data technology provides new power for network security analysis and defense, and becomes an indispensable existence in the construction of network security analysis system, and the existing patent application CN2022106719893 discloses a technical solution, which compares abnormal data with big data through qualitative analysis of data, can realize real-time monitoring of network data and corresponding data security analysis, has the advantages of high processing efficiency and data reliability, however, in network protection, with the rapid iteration of network attack means, the simple big data comparison method cannot adapt to the rapid development of attack means, and when multiple network attack means are combined, great interference is caused to the comparison and identification of big data, so that the risk cannot be alarmed in time, and the network security is affected.
[0004] In view of the above technical problems, the application provides a solution. SUMMARY
[0005] The application continuously obtains new risk information in the time axis direction when simulating and analyzing network risks, and further simulates and predicts the risks through the new risk information, so as to jointly analyze the results of multiple predictions, review the judged risk results, realize further confirmation or correction of the risk simulation in the network, meet the dynamic response demand in the network security protection process, improve the network security protection effect, solve the problem that the network risk analysis lacks the response ability to the rapid change of risk factors and the combination of multiple risk factors, and improve the dynamic response ability of network security risks.
[0006] The purpose of the application can be achieved by the following technical solutions:
[0007] The network security risk dynamic simulation analysis system based on big data analysis comprises a network risk composite collection unit, a network risk monitoring module, a database construction module, a simulation analysis module and a dynamic early warning updating module. The network risk composite collection unit is used for collecting various network operation information, classifying and recording the collected information, obtaining a network operation information set, and sending the collected network operation information set to the network risk monitoring module.
[0008] The network risk monitoring module performs compliance judgment on different classified network operation information in the network operation information set after obtaining the network operation information set, divides the network operation information into risk information and normal information, and sends the risk information to the database construction module and the simulation analysis module.
[0009] The database construction module updates the database by continuously receiving risk information. Meanwhile, the database construction module is connected to a third-party platform through an external window and updates the risk model in real time through the third-party platform.
[0010] The simulation analysis module compares the obtained risk information with the database constructed by the database construction module, generates a risk output warning according to the comparison result, and sends the risk output warning to the dynamic early warning updating module.
[0011] The dynamic early warning updating module responds to the risk output warning and performs early warning reminding.
[0012] After the simulation analysis module generates the risk output warning, it continues to receive risk information, mixes the newly received risk information with the risk information when the risk output warning is generated, constructs a risk information dynamic feature, and compares the risk information dynamic feature with the risk model to generate a risk adjustment warning. The risk adjustment warning is continuously reminded through the dynamic early warning updating module.
[0013] As a preferred embodiment of the present application, the network operation information collected by the network risk composite collection unit comprises network operation logs, network traffic and user behaviors. When the network risk composite collection unit collects network operation logs, it acquires network operation logs within an interval time every interval time through a preset interval.
[0014] When the network risk composite collection unit collects network traffic, it is counted through network nodes. Meanwhile, the collected network traffic is the total number of network transmission bytes within each preset time period.
[0015] When the network risk composite collection unit collects user behaviors, the same IP identity is regarded as the same user, and the user behaviors of the same IP identity are recorded.
[0016] The network risk composite collection unit divides the network operation log, network traffic and user behavior into three subsets for statistics, and combines the three subsets into a network operation information set.
[0017] As a preferred embodiment of the present application, the network risk monitoring module selects the network operation log subset, extracts and marks the abnormal behavior in the network operation log through a preset self-checking program, and counts the total amount of abnormal behavior in the network operation log as risk information.
[0018] The network risk monitoring module selects the network traffic subset, compares the network traffic with the set traffic range, and if the network traffic is within the set traffic range, it is classified as normal information, and if the network traffic is outside the set traffic range, it is classified as risk information.
[0019] The network risk monitoring module selects the user behavior subset, and compares the user behavior in the subset with the set high-risk behavior database, and if the user behavior coincides with the database, it is classified as normal information, and if the user behavior does not coincide with the database, it is classified as risk information.
[0020] As a preferred embodiment of the present application, when the simulation analysis module compares the risk information with the risk model, it first selects a blank risk model, fills all the risk information into the blank risk model to form a risk actual model, and then compares the risk actual model with multiple risk models to obtain the coincidence degree between the models, records the risk model with the highest coincidence degree as the adaptive model, and records the coincidence degree between the risk actual model and the adaptive model as the risk coincidence degree.
[0021] The simulation analysis module compares the risk coincidence degree with the set coincidence threshold, and if the risk coincidence degree is greater than the set coincidence threshold, a risk output warning is generated, and if the risk coincidence degree is not greater than the set coincidence threshold, no warning is generated.
[0022] As a preferred embodiment of the present application, after the simulation analysis module generates the risk output warning, it records the received risk information as fixed information, and after receiving new risk information, it records the new risk information as supplementary information.
[0023] The simulation analysis module constructs a new risk actual model through the supplementary information, and compares the new risk actual model with the adaptive model again to obtain a rechecked risk coincidence degree.
[0024] As a preferred embodiment of the present application, the simulation analysis unit compares the review risk coincidence degree with the risk coincidence degree, and if the review risk coincidence degree is greater than or equal to the set risk coincidence degree, a risk confirmation signal is generated, and if the review risk coincidence degree is less than the risk coincidence degree, a risk abnormal signal is generated.
[0025] As a preferred embodiment of the present application, after the simulation analysis unit generates the risk abnormal signal, the risk actual model constructed by the supplementary information is compared with the plurality of risk models in the database, a plurality of sets of coincidence degrees are obtained again, and the coincidence degrees greater than the review risk coincidence degree in the plurality of sets of coincidence degrees are marked, and the risk models corresponding thereto are recorded as review models.
[0026] As a preferred embodiment of the present application, the simulation analysis unit records the highest coincidence degree in the review model as an adjusted risk model, and generates a risk adjustment warning, and sends the risk adjustment warning to the dynamic warning update module.
[0027] Compared with the prior art, the present application has the following beneficial effects:
[0028] 1. In the present application, the database constructed by big data is used to judge the risk information in the network operation process, and the risk information and the risk information stored in the database are used for model construction and repetition comparison, so that the simulation online and repetition comparison of the risk information are realized, and the existing risk conditions in the network are discovered in time through big data, so that the network risk can be responded in advance, and the model library can be updated in time through the database with a cloud interface, so that the accuracy and timeliness of the risk simulation analysis are improved.
[0029] 2. In the present application, when the network risk is simulated and analyzed, new risk information is continuously obtained in the time axis direction, and the simulation prediction of the risk is further carried out through the new risk information, so that the results of multiple predictions are jointly analyzed, the judged risk results are reviewed, the network risk is further confirmed or corrected, the dynamic response demand in the network security protection process can be met, and the network security protection effect is improved. BRIEF DESCRIPTION OF DRAWINGS
[0030] In order to facilitate the understanding of those skilled in the art, the present application will be further described below with reference to the drawings.
[0031] Figure 1 The system block diagram of the present application;
[0032] Figure 2 The system flowchart of the present application. DETAILED DESCRIPTION
[0033] The technical solutions of the present application will be described clearly and completely below in connection with the embodiments. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0034] Embodiment one:
[0035] Please refer to Figure 1 - Figure 2 As shown in the figure, the network security risk dynamic simulation analysis system based on big data analysis includes a network risk composite collection unit, a network risk monitoring module, a database construction module, a simulation analysis module, and a dynamic early warning update module. The network risk composite collection unit is used to collect various network operation information. The network operation information collected by the network risk composite collection unit includes network operation logs, network traffic, and user behavior. The collected information is classified and recorded to obtain a network operation information set, and the collected network operation information set is sent to the network risk monitoring module. The network operation information set includes three subsets: network operation log subset, network traffic subset, and user behavior subset.
[0036] When the network risk composite collection unit collects network operation logs, it acquires network operation logs every interval time through a preset interval.
[0037] When the network risk composite collection unit collects network traffic, it is counted through network nodes, and the collected network traffic is the total number of network transmission bytes in each preset time period.
[0038] When the network risk composite collection unit collects user behavior, it regards the same IP identity as the same user and records the user behavior of the same IP identity.
[0039] After the network risk monitoring module obtains the network operation information set, it judges the compliance of different categories of network operation information in the network operation information set, divides them into risk information and normal information, and sends the risk information to the database construction module and the simulation analysis module.
[0040] The specific method for the network risk monitoring module to judge the compliance of network operation information is as follows:
[0041] The network risk monitoring module selects a network operation log subset, extracts and marks abnormal behaviors in the network operation log through a preset self-checking program, and counts the total amount of abnormal behaviors in the network operation log, which is recorded as risk information. The abnormal behaviors in the network operation log include high-frequency failed login records, access to sensitive paths, brute force cracking records, abnormal IP addresses, continuous access to non-existent URLs, and suspicious file creation records.
[0042] The network risk monitoring module selects a network traffic subset, compares the network traffic with a set traffic range, and if the network traffic is within the set traffic range, it is classified as normal information, and if the network traffic is outside the set traffic range, it is classified as risk information.
[0043] The network risk monitoring module selects a user behavior subset, and compares the user behavior in the subset with a set high-risk behavior database. If the user behavior coincides with the database, it is classified as normal information, and if the user behavior does not coincide with the database, it is classified as risk information.
[0044] The database construction module updates the database by continuously receiving risk information, and at the same time, the database construction module connects with a third-party platform through an external window and updates the risk model in real time through the third-party platform to improve the update speed of the risk model in the database. When simulating and analyzing risks, risk behaviors can be more comprehensively and accurately identified.
[0045] The simulation analysis module compares the obtained risk information with the database constructed by the database construction module, generates a risk output warning according to the comparison result, and sends the risk output warning to the dynamic warning update module.
[0046] When the simulation analysis module compares the risk information with the risk model, it first selects a blank risk model and fills all the risk information into the blank risk model to form a risk actual model. Then, the risk actual model is compared with multiple risk models to obtain the coincidence degree between the models. The higher the coincidence degree, the more similar the risk information is to the risk situation stored in the database. The risk model with the highest coincidence degree is recorded as the adaptive model, and the coincidence degree between the risk actual model and the adaptive model is recorded as the risk coincidence degree.
[0047] The simulation analysis module compares the risk coincidence degree with a set coincidence threshold. If the risk coincidence degree is greater than the set coincidence threshold, a risk output warning is generated. If the risk coincidence degree is not greater than the set coincidence threshold, no warning is generated.
[0048] The dynamic warning update module responds to the risk output warning and generates a warning reminder, prompting the management personnel or the network system to automatically perform risk killing or make corresponding processing, so as to avoid the impact on the network operation.
[0049] Embodiment two:
[0050] Please refer to Figure 1 - Figure 2 As shown, after generating the risk output warning, the simulation analysis module continues to receive risk information, and after generating the risk output warning, the simulation analysis module records the received risk information as fixed information, and after receiving new risk information, records the new risk information as supplementary information, the simulation analysis module constructs a new risk actual model through the supplementary information, and compares the new risk actual model with the adaptive model again to obtain a review risk coincidence degree, the simulation analysis unit compares the review risk coincidence degree with the risk coincidence degree, if the review risk coincidence degree is greater than or equal to the set risk coincidence degree, a risk confirmation signal is generated, if the review risk coincidence degree is less than the risk coincidence degree, a risk abnormal signal is generated, thereby forming a risk information dynamic feature, dynamically responding to the change of the risk information.
[0051] The simulation analysis module continues to compare the risk information dynamic feature through the risk model, compares the risk actual model constructed by the supplementary information with the plurality of risk models in the database, obtains a plurality of coincidence degrees again, and marks the coincidence degrees greater than the review risk coincidence degree, records the risk models corresponding thereto as review models, the simulation analysis unit records the highest coincidence degree in the review models as an adjusted risk model, and generates a risk adjustment warning, and sends the risk adjustment warning to the dynamic warning update module, and continues to remind through the dynamic warning update module.
[0052] The preferred embodiments of the application disclosed above are only used to help explain the application. The preferred embodiments do not describe all the details, nor limit the application to the specific embodiments. Obviously, according to the content of the specification, many modifications and changes can be made. The specification selects and describes these embodiments in order to better explain the principles and practical applications of the application, so that those skilled in the art can well understand and utilize the application. The application is limited by the claims and their entire scope and equivalents.
Claims
1. A network security risk dynamic simulation analysis system based on big data analysis, characterized in that, The network risk composite acquisition unit is used for acquiring various network operation information, classifying and recording the acquired information, obtaining a network operation information set, and sending the acquired network operation information set to the network risk monitoring module; The network risk monitoring module performs compliance judgment on different classified network operation information in the network operation information set after obtaining the network operation information set, divides the network operation information into risk information and normal information, and sends the risk information to the database construction module and the simulation analysis module; The database construction module updates the database by continuously receiving risk information, and connects with a third-party platform through an external window, and updates the risk model in real time through the third-party platform; The simulation analysis module compares the acquired risk information with the database constructed by the database construction module, generates a risk output warning according to the comparison result, and sends the risk output warning to the dynamic warning update module; The dynamic warning update module responds to the risk output warning and performs warning prompting; After generating the risk output warning, the simulation analysis module continues to receive risk information, mixes the newly received risk information with the risk information when the risk output warning is generated, forms a risk information dynamic feature, and continues to compare the risk information dynamic feature with the risk model through the risk model, generates a risk adjustment warning, and continues to prompt the risk adjustment warning through the dynamic warning update module; When the simulation analysis module compares the risk information with the risk model, a blank risk model is first selected, the risk information is filled into the blank risk model to form a risk actual model, and the risk actual model is compared with multiple risk models to obtain the coincidence degree between the models, and the risk model with the highest coincidence degree is recorded as an adaptive model, and the coincidence degree between the risk actual model and the adaptive model is recorded as a risk coincidence degree; The simulation analysis module compares the risk coincidence degree with the set coincidence threshold value, if the risk coincidence degree is greater than the set coincidence threshold value, a risk output warning is generated, if the risk coincidence degree is not greater than the set coincidence threshold value, no warning is generated; After generating the risk output warning, the simulation analysis module records the received risk information as fixed information, and records the new risk information as supplementary information after receiving the new risk information; The simulation analysis module constructs a new risk actual model through the supplementary information, and compares the new risk actual model with the adaptive model again to obtain a review risk coincidence degree; The simulation analysis module compares the review risk coincidence degree with the risk coincidence degree, if the review risk coincidence degree is greater than or equal to the set risk coincidence degree, a risk confirmation signal is generated, if the review risk coincidence degree is less than the risk coincidence degree, a risk abnormal signal is generated; The simulation analysis module compares the risk actual model constructed by the supplementary information with multiple risk models in the database after generating the risk abnormal signal, obtains multiple sets of coincidence degrees again, marks the coincidence degrees greater than the review risk coincidence degree, and records the risk model corresponding thereto as a review model; The simulation analysis module records the highest coincidence degree in the review model as an adjusted risk model, generates a risk adjustment early warning, and sends the risk adjustment early warning to the dynamic early warning update module.
2. The big data analysis based cyber security risk dynamic simulation analysis system according to claim 1, wherein, The network operation information collected by the network risk composite collection unit includes network operation logs, network traffic, and user behaviors. When the network operation logs are collected, the network operation logs within a certain interval are obtained once every interval through a preset interval; When the network traffic is collected, the network traffic is counted through the network nodes, and the collected network traffic is the total number of network transmission bytes within each preset time period; When the user behaviors are collected, the same IP identity is regarded as the same user, and the user behaviors of the same IP identity are recorded; The network operation logs, network traffic, and user behaviors are divided into three subsets for statistics, and the three subsets are combined into a network operation information set.
3. The big data analytics based cyber security risk dynamic simulation analysis system of claim 1, wherein, The network risk monitoring module selects the network operation log subset, extracts and marks the abnormal behaviors in the network operation logs through a preset self-checking program, counts the total amount of abnormal behaviors in the network operation logs, and records the total amount as risk information; The network risk monitoring module selects the network traffic subset, compares the network traffic with the set traffic range, and if the network traffic is within the set traffic range, it is classified as normal information, and if the network traffic is outside the set traffic range, it is classified as risk information; The network risk monitoring module selects the user behavior subset, and compares the user behaviors in the subset with the set high-risk behavior database. If the user behaviors coincide with the database, they are classified as normal information, and if the user behaviors do not coincide with the database, they are classified as risk information.
Citation Information
Patent Citations
Dynamic early warning system and early warning method for network and information security
CN118827159A