A network security attack threat analysis method and device based on rough sets

Through the rough set-based network security attack threat analysis method, the time window and resource allocation are dynamically adjusted, abnormal behavior patterns are identified, network threat scenarios are simulated, and network security configuration is optimized. This solves the problems of insufficient network security threat adaptability and protection strategies in existing technologies, and improves the flexibility and overall defense capabilities of network security.

CN120165971BActive Publication Date: 2025-09-12JINQICHUANG (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510501487.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-09-12
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

Existing network security technologies have limited capabilities in processing ambiguous or incomplete information and are difficult to adapt to the increasingly complex network security threat environment. Static protection strategies can be easily bypassed by new or mutated threats, and there is a lack of effective security threat simulation and testing methods, resulting in a high risk of data leakage or system intrusion.

Method used

A network security attack threat analysis method based on rough sets is adopted. By collecting real-time network traffic data, dynamically adjusting the time window size, using the random forest algorithm to identify abnormal behavior patterns, dynamically configuring resources, simulating network security attack threat scenarios, and conducting network security tests, the network security configuration is optimized.

Benefits of technology

It improves the efficiency and response speed of network security monitoring, enhances the defense capability of the network security system, improves the overall security and stability of the network, and realizes proactive and forward-looking management of network threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165971B_ABST
    Figure CN120165971B_ABST
Patent Text Reader

Abstract

The present invention provides a rough set-based network security attack threat analysis method and device, relating to the technical field of network security. The method comprises: collecting real-time network traffic data, applying data attribute evaluation techniques from rough set theory to analyze the characteristics of the network traffic data, assessing the intensity and amplitude of data fluctuations, and dynamically adjusting the size of the time window to obtain a time window size adjustment parameter. The present invention rapidly locates abnormal data through statistical features, improving the efficiency and response speed of network security monitoring. By evaluating the frequency and severity of anomalies in the data stream, resources are dynamically allocated and the frequency of network monitoring is optimized, making network security management more proactive and forward-looking. By dynamically adjusting the attack frequency to detect the network's response and processing capabilities, network security configuration is further optimized, significantly improving the overall security and stability of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a network security attack threat analysis method and device based on rough sets. Background Art

[0002] The field of cybersecurity encompasses a wide range of technologies and methods, from data protection to preventing unauthorized access. This field focuses on protecting computer systems, networks, and data from attack, damage, and unauthorized access. The core components of cybersecurity include information security, application security, network defense, endpoint protection, and cloud security. Together, these components form a comprehensive system designed to protect against various network threats and attacks. From basic firewalls and antivirus protection to advanced intrusion detection systems and encryption, cybersecurity attempts to prevent or mitigate security threats.

[0003] The rough set cybersecurity attack threat analysis method refers to a technique that uses rough set theory to analyze and identify cybersecurity threats. As a data analysis tool, rough set theory allows for processing ambiguous and incomplete information, making it particularly suitable for dynamic cybersecurity environments. The patented subject matter involves using a rough set model to identify patterns and associations in data, effectively discerning potential security threats and anomalous behavior. This method primarily assesses threats based on the relevance and importance of data attributes, rather than relying on traditional data processing or filtering algorithms.

[0004] Existing network security technologies primarily rely on traditional firewalls, virus protection, and intrusion detection systems, which have limited capabilities when processing ambiguous or incomplete information and struggle to adapt to the increasingly complex network security threat environment. Fixed time window sizes cannot be adjusted promptly in the face of sudden fluctuations in network traffic, leading to missed opportunities to identify critical abnormal behavior. Traditional methods are static in resource allocation and cannot be dynamically optimized based on changes in real-time data streams, resulting in inefficient resource utilization and risk management. In practice, such static protection strategies can easily be bypassed by new or evolving security threats, creating the risk of data leakage or system intrusion. The lack of effective security threat simulation and testing methods is also a major shortcoming of existing technologies, making it impossible to foresee and prepare for future security challenges, leading to vulnerability of the entire network. Summary of the Invention

[0005] To address the existing problems of limited ability to process ambiguous or incomplete information and difficulty adapting to the increasingly complex network security threat environment, as well as the fact that static protection strategies can be easily bypassed by new or mutated security threats, resulting in the risk of data leakage or system intrusion, and the lack of effective security threat simulation and testing methods, the present invention provides a network security attack threat analysis method and device based on rough sets. The technical solution is as follows:

[0006] In one aspect, a network security attack threat analysis method based on rough sets is provided. The method is implemented by a network security attack threat analysis device and includes:

[0007] S1: Collect real-time network traffic data, apply data attribute evaluation technology in rough set theory to analyze the characteristics of network traffic data, evaluate the fluctuation intensity and amplitude of the data, dynamically adjust the size of the time window, and obtain the time window size adjustment parameter;

[0008] S2: Use the time window size adjustment parameters and the random forest algorithm to analyze real-time network traffic. By counting features and recording abnormal data, it identifies abnormal behavior patterns in the real-time network environment and obtains abnormal pattern recognition results.

[0009] S3: Based on the results of abnormal pattern recognition, the frequency and severity of abnormalities in the data stream are evaluated, resources are dynamically allocated, risky data streams are prioritized, monitoring frequency is adjusted, and the real-time changing network threat environment is analyzed to achieve optimal resource allocation.

[0010] S4: Based on resource optimization and configuration, simulate network security attack threat scenarios, automatically adjust simulation parameters using real-time updated network status data, simulate key security risk points, and obtain network security attack threat simulation results based on network traffic and attack patterns;

[0011] S5: Use the network security attack threat simulation results to conduct network security testing, dynamically adjust the attack frequency, detect the network's response and processing capabilities, optimize the network security configuration, and obtain network security assessment results.

[0012] On the other hand, a rough set-based network security attack threat analysis device is provided. The device is applied to a rough set-based network security attack threat analysis method. The device includes:

[0013] The data attribute evaluation module is used to collect real-time network traffic data, apply the data attribute evaluation technology in rough set theory to analyze the characteristics of network traffic data, evaluate the fluctuation intensity and amplitude of the data, dynamically adjust the size of the time window, and obtain the time window size adjustment parameter;

[0014] The real-time traffic analysis module is used to adjust parameters using the time window size and utilize the random forest algorithm to analyze real-time network traffic. By statistically analyzing features and recording abnormal data, it identifies abnormal behavior patterns in the real-time network environment and obtains abnormal pattern recognition results.

[0015] The abnormal pattern diagnosis module is used to evaluate the frequency and severity of abnormalities in data streams based on the abnormal pattern recognition results, dynamically allocate resources, prioritize risky data streams, adjust monitoring frequency, analyze the real-time changing network threat environment, and obtain optimal resource allocation;

[0016] The security scenario simulation module is used to simulate network security attack threat scenarios based on resource optimization configuration. It automatically adjusts simulation parameters using real-time updated network status data, simulates key security risk points, and obtains network security attack threat simulation results based on network traffic and attack patterns.

[0017] The network defense optimization module is used to use the network security attack threat simulation results to conduct network security testing, dynamically adjust the attack frequency, detect the network's response and processing capabilities, optimize network security configuration, and obtain network security assessment results.

[0018] On the other hand, a network security attack threat analysis device is provided, which includes: a processor; a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, any one of the above-mentioned rough set-based network security attack threat analysis methods is implemented.

[0019] On the other hand, a computer-readable storage medium is provided, wherein the storage medium stores at least one instruction, and the at least one instruction is loaded and executed by a processor to implement any one of the above-mentioned rough set-based network security attack threat analysis methods.

[0020] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:

[0021] The present invention proposes a network security attack threat analysis method based on rough sets. By collecting network traffic data in real time and applying data attribute evaluation technology, it can dynamically analyze the characteristics of network traffic, adjust the time window size through volatility and variability evaluation, and effectively enhance the flexibility and accuracy of data processing. Further analysis of the data using the random forest algorithm can not only identify abnormal behavior patterns, but also quickly locate abnormal data through statistical features, thereby improving the efficiency and response speed of network security monitoring. By evaluating the frequency and severity of anomalies in the data stream, resources can be dynamically configured and the frequency of network monitoring can be optimized, which not only improves resource utilization efficiency but also makes network security management more proactive and forward-looking. Simulating network security attack threat scenarios and dynamically adjusting simulation parameters allows security protection measures to be updated in a timely manner and cover key security risk points, thereby enhancing the defense capabilities of the entire network security system. The simulation results are used for network security testing. By dynamically adjusting the attack frequency to detect the response and processing capabilities of the network, the network security configuration is further optimized, greatly improving the overall security and stability of the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0023] Figure 1 This is a flowchart of a network security attack threat analysis method based on rough sets provided by an embodiment of the present invention;

[0024] Figure 2 This is a block diagram of a network security attack threat analysis device based on rough sets provided by an embodiment of the present invention;

[0025] Figure 3 This is a structural diagram of a network security attack threat analysis device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0026] The technical solution of the present invention is described below in conjunction with the accompanying drawings.

[0027] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.

[0028] In the embodiments of the present invention, the terms "image" and "picture" may be used interchangeably. It should be noted that, when the distinction between them is not emphasized, their intended meanings are the same. The terms "of," "corresponding," and "corresponding" may be used interchangeably. It should be noted that, when the distinction between them is not emphasized, their intended meanings are the same.

[0029] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.

[0030] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0031] The embodiment of the present invention provides a network security attack threat analysis method based on rough sets, which can be implemented by a network security attack threat analysis device, which can be a terminal or a server. Figure 1 The flowchart of the network security attack threat analysis method based on rough sets is shown. The processing flow of the method may include the following steps:

[0032] S1: Collect real-time network traffic data, apply the data attribute evaluation technology in rough set theory to analyze the characteristics of network traffic data, evaluate the fluctuation intensity and amplitude of the data, dynamically adjust the size of the time window, and obtain the time window size adjustment parameter.

[0033] Among them, the time window size adjustment parameters include window duration, traffic threshold that triggers expansion, and dynamic reduction rate;

[0034] Abnormal pattern recognition results include the frequency, duration, and impact range of abnormal events;

[0035] Resource optimization configuration includes risk traffic processing priority, key resource backup strategy and key service monitoring;

[0036] The network security attack threat simulation results include the type of simulated attack, the success rate of the simulation and the network's defense response;

[0037] Cybersecurity assessment results include the number of vulnerabilities detected, the speed of remediation, and cybersecurity recovery capabilities.

[0038] Optionally, real-time network traffic data is collected, and data attribute evaluation technology in rough set theory is applied to analyze the characteristics of the network traffic data, evaluate the fluctuation intensity and amplitude of the data, and dynamically adjust the size of the time window to obtain the time window size adjustment parameters, including:

[0039] S101: Collect real-time network traffic data, classify and record data packets, analyze the source addresses of data packets, evaluate the size and sending frequency of data packets, perform initial screening of data traffic, set a dynamically adjusted time window to capture traffic fluctuations, and obtain real-time network traffic records.

[0040] In a feasible implementation method, the capture of data packets is performed in stages. Each data packet in the network traffic is obtained through a traffic collection tool, and the data packets are classified according to protocol types using a protocol parsing tool, such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc.; the core fields of the data packet, such as the source address, destination address, data length and timestamp, are extracted, all data packets are sorted according to the timestamp and a complete traffic record table is generated, the size of the data packet is statistically analyzed, and the frequency of data packet sending is calculated to capture the characteristics of high-frequency data packets. The traffic is preliminarily screened based on the statistical results, and the number of data packets per unit time is calculated by setting a dynamically adjusted time window, the time point of traffic fluctuation is identified, and real-time network traffic records are obtained.

[0041] S102: Using real-time network traffic records and applying rough set theory, the data is divided into upper approximate sets and lower approximate sets. The statistical characteristics and frequency distribution of elements in the differentiated sets are analyzed. The differences between the upper approximate sets and the lower approximate sets are compared to identify the volatility and abnormal data points of network traffic and obtain the data attribute fluctuation analysis results.

[0042] In a feasible implementation method, the rough set theory is introduced to analyze the characteristics of data traffic, and the data packets in the traffic record are divided into discrete sets. An upper approximate set and a lower approximate set are constructed for each set. The upper approximate set includes elements belonging to the target data classification, and the lower approximate set includes elements that must belong to the target data classification. The statistical characteristics of the upper and lower approximate sets are extracted, including the number of elements in the set, the frequency of occurrence of elements, etc. The fluctuation characteristics and abnormal data points in the traffic are identified by analyzing the degree of difference between the two sets. The statistical distribution of the differentiated sets is compared to find the significant fluctuation points of the traffic. Combined with the location and time of the abnormal data points, the data attribute fluctuation analysis results are obtained.

[0043] S103: Based on the data attribute fluctuation analysis results, dynamically adjust the size of the time window, compare the data variability under short time windows and long time windows, calculate the window size, and obtain the time window size adjustment parameter.

[0044] The calculation formula of the window size is as follows (1):

[0045]

[0046] Among them, W t Represents the window size at time point t, w i Represents the weight coefficient of time point ti, X t-i represents the data value at time point ti, n represents the number of data points in the window, X t represents the data value at time point t, represents the mean value of the data within the window, σ represents the standard deviation of the data within the window, and β represents the adjustment coefficient.

[0047] In a feasible implementation, w i is the weight coefficient, obtained by the time-decreasing function of the data points in the window, to ensure that recent data has a greater impact on the calculation results. For a 5-point window, it is set to [0.5, 0.7, 0.8, 0.9, 1.0]; the setting based on the more relevant recent data;

[0048] X t-i For historical data point values, values ​​collected from data in real time, such as temperature or price data;

[0049] n is the window size, which is set to 5. Based on historical data analysis, shorter windows can effectively capture data trends;

[0050] X t is the value of the current data point, collected in real time from the sensor or data;

[0051] is the average value of the data in the window, calculated as

[0052] σ is the standard deviation, which is obtained by the standard deviation calculation function of all data points in the window;

[0053] β is the adjustment coefficient, which is set according to the volatility of the data. A larger β strengthens the response to the mutation. It is set to 0.5 based on the response pattern of previous data deviations from the mean;

[0054] Substitute the parameters into the formula for calculation:

[0055] Set data point X t-1 to X t-5 They are [100, 102, 98, 104, 103] respectively, and the current data point X t is 105, the window average Calculated as:

[0056]

[0057] The standard deviation σ is set to 2, and the adjustment coefficient β is 0.5;

[0058]

[0059] The results show that under the current data and settings, the calculated window size should be adjusted to approximately 114.24, reflecting the variability of the data within the window and the deviation of the current data, providing a specific quantitative indicator for data variability analysis, which will help to further adjust and optimize the time window size and improve the accuracy of data processing and analysis.

[0060] S2: Use the time window size adjustment parameters and the random forest algorithm to analyze the real-time network traffic. By statistically analyzing the features and recording abnormal data, the abnormal behavior patterns in the real-time network environment are identified to obtain the abnormal pattern recognition results.

[0061] Optionally, a time window size adjustment parameter is used to analyze real-time network traffic using a random forest algorithm. By statistically analyzing features and recording abnormal data, abnormal behavior patterns in the real-time network environment are identified, and abnormal pattern recognition results are obtained, including:

[0062] S201: Adjust parameters according to the time window size, perform initial filtering on the network data within the target time, remove irrelevant data, and extract basic statistical features from the remaining data, including traffic size, number of connections, and duration, to obtain a basic feature data set.

[0063] In a feasible implementation method, network traffic data within a target time range is processed, data traffic is divided into multiple segments according to the length of the time window, data packets in each segment are classified according to protocol type and source address, irrelevant data such as background noise and data packets irrelevant to the analysis target are filtered out, and traffic statistics analysis is performed on the remaining data to extract basic statistical features of the data, including traffic size, number of connected sources and targets, average duration and fluctuation range of data packets. By calculating the above features within each time window and performing preliminary verification of the features, redundant data or abnormal invalid data omitted during the feature extraction process are removed to obtain a basic feature data set.

[0064] S202: Based on the basic feature data set, the data is standardized, the data format is processed, the data is screened for outliers, and potential outlier data is screened based on the deviation from the mean and the standard deviation to obtain an outlier candidate data set.

[0065] In a feasible implementation method, the data is standardized and the feature data in different time windows are unified into the same format and unit value. For example, the traffic size is converted into a value in bytes, the duration is converted into seconds, and the number of connections is recorded as an integer value. The data set is normalized by the mean and standard deviation of the statistical features, and all feature values ​​are standardized to the range between 0 and 1. At the same time, abnormal points in the feature data are screened, and potential anomalies are judged based on the degree to which each feature value deviates from the mean. The difference between the feature value and the mean is calculated and the standard deviation is used as the boundary to determine whether it is an abnormal data point, thereby obtaining an abnormal candidate data set.

[0066] S203: Analyze the network data behavior pattern using the abnormal candidate data set, compare the data behavior with the abnormal behavior pattern through a pattern matching algorithm, and generate an abnormal behavior pattern recognition result.

[0067] In a feasible implementation, the behavioral patterns of network data are deeply analyzed. By presetting abnormal behavior patterns, matching analysis is performed based on the multi-dimensional characteristics of network traffic and predefined abnormal behavior patterns. The pattern matching algorithm is used to compare the similarity between data traffic characteristics and abnormal behavior templates one by one, and the matched abnormal behavior patterns are marked. The degree of consistency between the data and the abnormal pattern is quantified by calculating the feature similarity. For the matched abnormal pattern, key data points of the behavioral characteristics are further extracted, including the starting time, duration and target address of the abnormal traffic, to generate abnormal behavior pattern recognition results.

[0068] S3: Based on the results of abnormal pattern recognition, evaluate the frequency and severity of anomalies in the data stream, dynamically configure resources, prioritize risky data streams, adjust monitoring frequency, analyze the real-time changing network threat environment, and obtain optimal resource configuration.

[0069] Optionally, based on the anomaly pattern recognition results, evaluate the anomaly frequency and severity in the data stream, dynamically allocate resources, prioritize risky data streams, adjust monitoring frequency, analyze the real-time changing network threat environment, and obtain optimal resource configuration, including:

[0070] S301: Based on the abnormal pattern recognition results, the frequency and severity of the identified abnormal behaviors are analyzed, the potential impact and urgency of the abnormal events are evaluated, and the abnormal risk assessment results are obtained.

[0071] In a feasible implementation method, the behavior patterns in the network traffic log data are analyzed, and the number of triggering of each abnormal behavior in a specific time window is obtained by performing statistical frequency analysis on the identified abnormal behavior. The key influencing factors, including time, source address, traffic category, and traffic fluctuation characteristics, are decomposed through a behavioral feature extraction method, and classified into different abnormal behavior patterns. The corresponding trigger weight is calculated for each abnormal behavior pattern. The trigger weight is combined with the cumulative impact value of the abnormal behavior to establish a behavior pattern impact weight set. At the same time, a specific algorithm is used to calculate the potential risk impact factor of each abnormal behavior in different network environments, including the estimated resource usage or the service failure time caused. The overall risk index of the abnormal behavior is further calculated through a weighted model to obtain the abnormal risk assessment result.

[0072] S302: Using the abnormal risk assessment results, dynamically configure network monitoring and protection resources, prioritize identified risk data flows, adjust the resource allocation and response mechanism for network security data monitoring, optimize the distribution and use of network resources, and obtain risk priority processing results.

[0073] In a feasible implementation, priority processing is performed on the identified risk data streams, and the risk priority score is calculated according to formula (2):

[0074]

[0075] Among them, R represents the risk priority score, F p Represents the triggering frequency of the p-th risk, S p represents the severity score of the impact of the p-th risk, Z is the total monitoring resource allocation value, and U is the risk type;

[0076] Detailed explanation of the formula and the calculation process of the formula: trigger frequency F p By classifying and counting the total number of times each type of risk behavior is triggered in the historical monitoring data, assuming that within a certain time period, the number of times the first type of risk behavior is triggered is 120, then F1 = 120;

[0077] The number of times the second type of risk behavior is triggered is 80, then F2 = 80, and the impact severity score is S p It is calculated by comprehensively evaluating the resource usage ratio and interruption time caused by each type of risk behavior. If the comprehensive impact score of the first type of risk behavior is set to 70, then S1 = 70, and the comprehensive score of the second type of risk behavior is 90, then S2 = 90;

[0078] The total monitoring resource allocation value Z is obtained by counting the total amount of currently available resources. For example, if the current network monitoring resource is 2000 units, then Z = 2000.

[0079] Substituting the above values:

[0080]

[0081] The results show that the current priority score of the risk data flow is 7.8, indicating that risk handling requires certain resource priority adjustments. Based on the calculation results, the risk types and severity that require priority resource allocation can be clearly identified.

[0082] S303: Based on the risk prioritization results, adjust the monitoring frequency, analyze the real-time changes in network traffic, evaluate the dynamic characteristics of the network threat environment, and optimize resource allocation by continuously monitoring and matching changes in the network environment.

[0083] In a feasible implementation method, the network monitoring frequency is adjusted, the data feature decomposition and classification of the changing trend of real-time network traffic are performed, the mean value and fluctuation amplitude of the traffic feature distribution are obtained, the main characteristic factors of the traffic change in the time window are extracted, and the historical traffic anomaly distribution pattern in a specific sub-network area is combined to construct a real-time traffic trend prediction model to predict traffic anomaly behavior that occurs in the short term. Based on the predicted abnormal behavior, the frequency distribution of network monitoring is adjusted first, and the existing network monitoring resources are reallocated. Priority is given to monitoring sub-network areas with large traffic anomaly fluctuations. The monitoring data is used to analyze the characteristics of the network threat environment in real time. The flow direction, source and frequency changes of network traffic are deeply analyzed. By comparing the differences between real-time monitoring data and historical abnormal behaviors, the monitoring strategy is dynamically adjusted to further improve the monitoring capability and protection efficiency of the overall network resources and obtain optimal resource configuration.

[0084] S4: Based on resource optimization configuration, simulate network security attack threat scenarios, automatically adjust simulation parameters using real-time updated network status data, simulate and cover key security risk points, and obtain network security attack threat simulation results by referring to network traffic and attack patterns.

[0085] Optionally, based on resource optimization configuration, network security attack threat scenarios are simulated, simulation parameters are automatically adjusted using real-time updated network status data, simulation covers key security risk points, and network traffic and attack patterns are referenced to obtain network security attack threat simulation results, including:

[0086] S401: According to the resource optimization configuration, the initial parameters of the network security simulation are set, the simulation behavior and parameters are automatically adjusted using the real-time updated network status data, the consistency of the simulation is verified, and the adjusted simulation parameters are obtained.

[0087] In a feasible implementation method, the parameter settings of the network security simulation are initialized, the resource distribution status and optimization configuration strategy of the current network are extracted, and the initial simulation parameters are set according to the extracted status data, including parameters such as traffic baseline, number of connections, and data packet size. The real-time status data of the network is used as dynamic input, and the behavioral characteristics of the simulation are adjusted in real time. The difference between the output results of the simulation data and the actual network status is analyzed, and the consistency of the simulation is verified by comparing the simulation output results with the real-time status data of the network. The simulation parameters are gradually adjusted, such as dynamically adjusting the traffic fluctuation range and attack frequency, until the simulation parameters can accurately reflect the real-time status of the network, and the adjusted simulation parameters are output.

[0088] S402: Using the adjusted simulation parameters, construct and execute security attack threat scenarios in network security simulation, perform security attack simulations on key network nodes, calculate quantitative evaluation values ​​of network responses, and obtain security risk coverage records.

[0089] The calculation formula of the quantitative evaluation value of the network response is as follows (3):

[0090]

[0091] Where RQ is the quantitative evaluation value of network response, N represents the total number of attack events in the simulation, and w a represents the weight of the a-th attack event, s a represents the security status score of the a-th node before the attack, t a Represents the security status score of the a-th node after being attacked.

[0092] In a feasible implementation, the parameter meanings and setting values ​​are:

[0093] N represents the total number of attack events simulated in the simulation. This number is determined by the number of key nodes in the network system. If there are 10 key nodes in the actual network, then N is set to 10.

[0094] w a is the weight of the a-th attack event, which is quantified based on the network traffic of the node and the frequency of historical security events. Assuming that the network traffic of node A accounts for 20% and the frequency of attacks in history is higher than the average level, w a Can be set to 1.2;

[0095] s a Represents the security status score of the a-th node before the attack. This score is obtained by combining the vulnerability scanning and intrusion detection results of the node through the security monitoring tool. The number of vulnerabilities of node A is set to be medium, and s a It can be set at 70 points;

[0096] ta represents the security status score of node a after being attacked, which is also obtained through the evaluation of security monitoring tools. For example, after the attack, the vulnerability of node A is partially exploited, t a It can be set at 50 points;

[0097] Substitute the parameters into the formula for calculation: Assume that there are 3 key nodes in the network, and the parameters of each node are set as follows: N = 3w1 = 1.0, w2 = 1.2, w3 = 0.8, s1 = 90, s2 = 70, s3 = 85, t1 = 60, t2 = 50, t3 = 75;

[0098] Compute the term for each node:

[0099]

[0100] Calculate the sum:

[0101]

[0102] Substituting the sum into the formula:

[0103]

[0104] The results show the average impact of the simulated attack. This value represents the average decrease in the security score of each node after being attacked in the three key nodes of the simulation. This result reflects the actual impact of the attack simulation on the security status of network nodes and is further used to evaluate and adjust the network security policy.

[0105] S403: Based on the security risk coverage records, analyze the network traffic data and simulated attack patterns, evaluate the correlation and impact between the two, optimize the authenticity and coverage of the simulation, and obtain the network security attack threat simulation results.

[0106] In a feasible implementation method, the interactive characteristics of network traffic data and simulated attack patterns are analyzed, and key parameters in historical security risk records, such as attack type, target resources, time window, etc., are extracted. Statistical analysis is performed in combination with the characteristics of current network traffic data. By comparing the degree of matching between actual traffic fluctuations and simulated attack patterns, the correlation and potential impact between the two are evaluated, and the behavioral characteristics of the simulated attack patterns are adjusted, including attack entry selection, data packet sending frequency, and attack duration, etc., to improve the adaptability of simulated attacks to the current network status, further expand the coverage of the simulation, optimize the authenticity of the simulation by combining multiple attack behavior patterns and historical risk records, and generate network security attack threat simulation results.

[0107] S5: Use the network security attack threat simulation results to conduct network security testing, dynamically adjust the attack frequency, detect the network's response and processing capabilities, optimize the network security configuration, and obtain network security assessment results.

[0108] Optionally, network security attack threat simulation results can be used to conduct network security testing, dynamically adjust attack frequency, detect network response and processing capabilities, optimize network security configuration, and obtain network security assessment results, including:

[0109] S501: Using the network security attack threat simulation results, configure the network security test environment, set and adjust the frequency and intensity of attack simulation, simulate differentiated types of network attacks, detect the real-time response and defense capabilities of the network, and obtain network response test records.

[0110] In a feasible implementation method, multiple attack types and related indicator data in the current network environment are collected, including basic information such as the intensity, frequency, duration, and entry point distribution of the attack type. Combined with the network topology analysis and the distribution of attack points, a customizable threat simulation scenario is constructed through a threat modeling tool or an attack simulation platform. In the scenario, different types of network attacks are gradually simulated, including DDoS attacks, SQL injections, malware propagation, zero-day vulnerability exploits, etc. By adjusting the grading threshold of the attack intensity and the fluctuation parameters of the attack frequency, the stress test of the network is refined, and data packet analysis tools and network log monitoring tools are used to monitor and record the traffic data and network behavior changes generated during the simulated attack in real time. The technical indicators such as traffic distribution, throughput, delay, and packet loss rate during the attack are extracted through packet capture technology. The network response process under the attack pressure is recorded and stored in its entirety. By comprehensively analyzing the data, a network response test record is obtained.

[0111] S502: By analyzing the network response test records, the network's performance and processing capabilities in the attack scenario are evaluated, and the network's response to the attack threat is adjusted and optimized to obtain an optimized security configuration.

[0112] In a feasible implementation, by analyzing the network response test records, the average response capability of the network under various attack scenarios is calculated according to formula (4):

[0113]

[0114] Among them, R represents the average response capability of the network, L represents the attack traffic size, S represents the attack intensity level, T represents the attack duration, and Q represents the total number of attack tests.

[0115] Detailed explanation of the formula and the process of formula calculation and derivation:

[0116] The specific calculation process of each parameter is as follows:

[0117] The value of traffic size L is the attack packet size per unit time collected by network monitoring tools and quantified in megabytes. For example, the total amount of packets collected in a certain attack scenario is 480MB.

[0118] The attack intensity level S is defined in a graded manner, quantified based on the number of queries per second or connections per second generated by the attack tool. For example, if the QPS generated in a certain attack scenario is 1800, then S is 3 (according to the QPS grading standard, 1-1000 is low intensity, 1001-5000 is medium intensity, and 5001 and above is high intensity);

[0119] Duration T is calculated by the actual duration of the attack simulation in seconds. For example, the duration of an attack simulation is 150 seconds.

[0120] The total number Q is the number of attack scenarios that have passed the complete test. For example, in multiple simulated attacks, the total number of tests is 12;

[0121] Combined example:

[0122] Assume that the test record includes the following data:

[0123] Test 1: L = 480MB, S = 3, T = 150 seconds;

[0124] Test 2: L = 520MB, S = 2, T = 130 seconds;

[0125] Test 3: L = 600MB, S = 3, T = 140 seconds;

[0126] Similar data were recorded for the remaining 9 tests, and the first 3 records were substituted into formula (4):

[0127]

[0128]

[0129] The results show that the average response capability of the network in the first three attack scenarios is 201066.67 units. This result shows that the network's response capability changes significantly under the combined effects of attack traffic, intensity level, and duration. The calculation results can provide an important basis for optimizing network security configuration.

[0130] S503: Apply the optimized security configuration, conduct network security testing, continuously monitor the network's defense response, evaluate the adjusted network security protection effect and processing efficiency, and obtain network security assessment results.

[0131] In a feasible implementation method, the performance of the network during the defense process is monitored in all aspects, and the log data generated during the defense process is collected at a high frequency, including key technical indicators such as CPU occupancy, memory usage, network bandwidth consumption, and delayed response time. During the attack simulation, the centralized monitoring platform automatically screens high-priority security events that occur during the defense process and extracts corresponding feature data. The response details of all security events are recorded using distributed storage devices. The protection effects of the security configurations before and after optimization are compared one by one through data comparison and analysis tools. The response performance changes of high-frequency attack scenarios and the key performance improvements after optimization are quantitatively summarized, and the protection strategies for efficient processing are summarized in detail. The adaptation effect and processing efficiency of the optimized configuration in different attack scenarios are analyzed, and the optimized configuration effect is verified layer by layer to obtain the network security assessment results.

[0132] The present invention proposes a network security attack threat analysis method based on rough sets. By collecting network traffic data in real time and applying data attribute evaluation technology, it can dynamically analyze the characteristics of network traffic, adjust the time window size through volatility and variability evaluation, and effectively enhance the flexibility and accuracy of data processing. Further analysis of the data using the random forest algorithm can not only identify abnormal behavior patterns, but also quickly locate abnormal data through statistical features, thereby improving the efficiency and response speed of network security monitoring. By evaluating the frequency and severity of anomalies in the data stream, resources can be dynamically configured and the frequency of network monitoring can be optimized, which not only improves resource utilization efficiency but also makes network security management more proactive and forward-looking. Simulating network security attack threat scenarios and dynamically adjusting simulation parameters allows security protection measures to be updated in a timely manner and cover key security risk points, thereby enhancing the defense capabilities of the entire network security system. The simulation results are used for network security testing. By dynamically adjusting the attack frequency to detect the response and processing capabilities of the network, the network security configuration is further optimized, greatly improving the overall security and stability of the network.

[0133] Figure 2 This is a block diagram of a network security attack threat analysis device based on rough sets according to an exemplary embodiment. The device is used in a network security attack threat analysis method based on rough sets. Figure 2 The device includes a data attribute evaluation module 210, a real-time traffic analysis module 220, an abnormal pattern diagnosis module 230, a security scenario simulation module 240, and a network defense optimization module 250. Among them:

[0134] The data attribute evaluation module 210 is used to collect real-time network traffic data, apply data attribute evaluation technology in rough set theory to analyze the characteristics of the network traffic data, evaluate the fluctuation intensity and amplitude of the data, dynamically adjust the size of the time window, and obtain the time window size adjustment parameter;

[0135] The real-time traffic analysis module 220 is used to analyze real-time network traffic using a random forest algorithm by adjusting parameters of a time window size, and to identify abnormal behavior patterns in the real-time network environment by statistically analyzing features and recording abnormal data, thereby obtaining abnormal pattern recognition results.

[0136] Anomaly pattern diagnosis module 230 is used to evaluate the frequency and severity of anomalies in data streams based on anomaly pattern recognition results, dynamically allocate resources, prioritize risky data streams, adjust monitoring frequency, analyze the real-time changing network threat environment, and obtain optimal resource allocation;

[0137] The security scenario simulation module 240 is used to simulate network security attack threat scenarios based on resource optimization configuration, automatically adjust simulation parameters using real-time updated network status data, simulate key security risk points, and obtain network security attack threat simulation results based on network traffic and attack patterns;

[0138] The network defense optimization module 250 is used to use the network security attack threat simulation results to conduct network security testing, dynamically adjust the attack frequency, detect the network's response and processing capabilities, optimize the network security configuration, and obtain network security assessment results.

[0139] Among them, the time window size adjustment parameters include window duration, traffic threshold that triggers expansion, and dynamic reduction rate;

[0140] Abnormal pattern recognition results include the frequency, duration, and impact range of abnormal events;

[0141] Resource optimization configuration includes risk traffic processing priority, key resource backup strategy and key service monitoring;

[0142] The network security attack threat simulation results include the type of simulated attack, the success rate of the simulation and the network's defense response;

[0143] Cybersecurity assessment results include the number of vulnerabilities detected, the speed of remediation, and cybersecurity recovery capabilities.

[0144] Optionally, the data attribute evaluation module 210 is further configured to:

[0145] S101: Collect real-time network traffic data, classify and record data packets, analyze the source addresses of data packets, evaluate the size and transmission frequency of data packets, perform initial screening of data traffic, set a dynamically adjusted time window to capture traffic fluctuations, and obtain real-time network traffic records;

[0146] S102: Using real-time network traffic records and applying rough set theory, the data is divided into upper and lower approximate sets. The statistical characteristics and frequency distribution of elements in the differentiated sets are analyzed. The differences between the upper and lower approximate sets are compared to identify network traffic volatility and abnormal data points, and obtain data attribute fluctuation analysis results.

[0147] S103: Based on the data attribute fluctuation analysis results, dynamically adjust the size of the time window, compare the data variability under short time windows and long time windows, calculate the window size, and obtain the time window size adjustment parameter.

[0148] The calculation formula of the window size is as follows (1):

[0149]

[0150] Among them, W t Represents the window size at time point t, w i Represents the weight coefficient of time point ti, X t-i represents the data value at time point ti, n represents the number of data points in the window, X t represents the data value at time point t, represents the mean value of the data within the window, σ represents the standard deviation of the data within the window, and β represents the adjustment coefficient.

[0151] Optionally, the real-time traffic analysis module 220 is further configured to:

[0152] S201: Adjust parameters according to the time window size, perform initial filtering on the network data within the target time, remove irrelevant data, and extract basic statistical features from the remaining data, including traffic volume, number of connections, and duration, to obtain a basic feature data set;

[0153] S202: Based on the basic feature data set, the data is standardized, the data format is processed, and the data is screened for outliers. Potential outlier data is screened based on deviation from the mean and standard deviation to obtain an outlier candidate data set;

[0154] S203: Analyze the network data behavior pattern using the abnormal candidate data set, compare the data behavior with the abnormal behavior pattern through a pattern matching algorithm, and generate an abnormal behavior pattern recognition result.

[0155] Optionally, the abnormal mode diagnosis module 230 is further configured to:

[0156] S301: Based on the abnormal pattern recognition results, the frequency and severity of the identified abnormal behaviors are analyzed to assess the potential impact and urgency of the abnormal events and obtain abnormal risk assessment results;

[0157] S302: Using the abnormal risk assessment results, dynamically configure network monitoring and protection resources, prioritize identified risk data flows, adjust resource allocation and response mechanisms for network security data monitoring, optimize the distribution and use of network resources, and obtain risk priority processing results;

[0158] S303: Based on the risk prioritization results, adjust the monitoring frequency, analyze the real-time changes in network traffic, evaluate the dynamic characteristics of the network threat environment, and optimize resource allocation by continuously monitoring and matching changes in the network environment.

[0159] Optionally, the security scenario simulation module 240 is further configured to:

[0160] S401: setting initial parameters for network security simulation based on resource optimization configuration, automatically adjusting simulation behavior and parameters using real-time updated network status data, verifying simulation consistency, and obtaining adjusted simulation parameters;

[0161] S402: Using the adjusted simulation parameters, construct and execute security attack threat scenarios in network security simulation, simulate security attacks on key network nodes, calculate quantitative assessment values ​​of network responses, and obtain security risk coverage records;

[0162] S403: Based on the security risk coverage records, analyze the network traffic data and simulated attack patterns, evaluate the correlation and impact between the two, optimize the authenticity and coverage of the simulation, and obtain the network security attack threat simulation results.

[0163] The calculation formula of the quantitative evaluation value of the network response is as follows (2):

[0164]

[0165] Where RQ is the quantitative evaluation value of network response, N represents the total number of attack events in the simulation, and w a represents the weight of the a-th attack event, s a represents the security status score of the a-th node before the attack, t a Represents the security status score of the a-th node after being attacked.

[0166] Optionally, the network defense optimization module 250 is further configured to:

[0167] S501: Using the network security attack threat simulation results, configure the network security test environment, set and adjust the attack simulation frequency and intensity, simulate different types of network attacks, test the network's real-time response and defense capabilities, and obtain network response test records;

[0168] S502: By analyzing the network response test records, the network's performance and handling capabilities in attack scenarios are evaluated, and the network's response to attack threats is adjusted and optimized to obtain an optimized security configuration.

[0169] S503: Apply the optimized security configuration, conduct network security testing, continuously monitor the network's defense response, evaluate the adjusted network security protection effect and processing efficiency, and obtain network security assessment results.

[0170] The present invention proposes a network security attack threat analysis method based on rough sets. By collecting network traffic data in real time and applying data attribute evaluation technology, it can dynamically analyze the characteristics of network traffic, adjust the time window size through volatility and variability evaluation, and effectively enhance the flexibility and accuracy of data processing. Further analysis of the data using the random forest algorithm can not only identify abnormal behavior patterns, but also quickly locate abnormal data through statistical features, thereby improving the efficiency and response speed of network security monitoring. By evaluating the frequency and severity of anomalies in the data stream, resources can be dynamically configured and the frequency of network monitoring can be optimized, which not only improves resource utilization efficiency but also makes network security management more proactive and forward-looking. Simulating network security attack threat scenarios and dynamically adjusting simulation parameters allows security protection measures to be updated in a timely manner and cover key security risk points, thereby enhancing the defense capabilities of the entire network security system. The simulation results are used for network security testing. By dynamically adjusting the attack frequency to detect the response and processing capabilities of the network, the network security configuration is further optimized, greatly improving the overall security and stability of the network.

[0171] Figure 3 FIG. 1 is a schematic diagram of a network security attack threat analysis device provided by an embodiment of the present invention. Figure 3 As shown, the network security attack threat analysis device may include the above Figure 2 Optionally, the network security attack threat analysis device 310 may include a first processor 2001 .

[0172] Optionally, the network security attack threat analysis device 310 may further include a memory 2002 and a transceiver 2003 .

[0173] The first processor 2001, the memory 2002 and the transceiver 2003 may be connected via a communication bus.

[0174] The following combination Figure 3 The components of the network security attack threat analysis device 310 are described in detail:

[0175] The first processor 2001 is the control center of the network security attack threat analysis device 310 and can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 can be one or more central processing units (CPUs), or an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement an embodiment of the present invention, such as one or more microprocessors (digital signal processors, DSPs) or one or more field programmable gate arrays (FPGAs).

[0176] Optionally, the first processor 2001 can perform various functions of the network security attack threat analysis device 310 by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.

[0177] In a specific implementation, as an embodiment, the first processor 2001 may include one or more CPUs, such as Figure 3 CPU0 and CPU1 are shown in FIG.

[0178] In a specific implementation, as an embodiment, the network security attack threat analysis device 310 may also include multiple processors, such as Figure 3 1 and 2. The first processor 2001 and the second processor 2004 are shown in FIG. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0179] The memory 2002 is used to store the software program for executing the solution of the present invention, and is controlled by the first processor 2001 for execution. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0180] Alternatively, the memory 2002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 may be integrated with the first processor 2001 or exist independently and accessed through the interface circuit ( Figure 3 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.

[0181] The transceiver 2003 is used to communicate with a network device or a terminal device.

[0182] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 3 (not shown separately in the figure). The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0183] Optionally, the transceiver 2003 may be integrated with the first processor 2001 or may exist independently and be connected to the network security attack threat analysis device 310 through the interface circuit ( Figure 3 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.

[0184] It should be noted that Figure 3 The structure of the network security attack threat analysis device 310 shown in the figure does not constitute a limitation on the router. The actual knowledge structure identification device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0185] In addition, the technical effects of the network security attack threat analysis device 310 can refer to the technical effects of the network security attack threat analysis method based on rough sets described in the above method embodiment, and will not be repeated here.

[0186] It should be understood that the first processor 2001 in the embodiment of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0187] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus random access memory (DR RAM).

[0188] The above embodiments can be implemented in whole or in part through software, hardware (such as circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired method (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0189] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0190] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0191] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0192] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0193] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0194] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of the device or unit, which can be electrical, mechanical or other forms.

[0195] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0196] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0197] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0198] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A network security attack threat analysis method based on rough sets, characterized by: The method comprises: S1: Collect real-time network traffic data, apply data attribute evaluation technology in rough set theory to analyze the characteristics of network traffic data, evaluate the fluctuation intensity and amplitude of the data, dynamically adjust the size of the time window, and obtain the time window size adjustment parameter; S2: Use the time window size adjustment parameters and the random forest algorithm to analyze real-time network traffic. By counting features and recording abnormal data, it identifies abnormal behavior patterns in the real-time network environment and obtains abnormal pattern recognition results. S3: Based on the results of abnormal pattern recognition, the frequency and severity of abnormalities in the data stream are evaluated, resources are dynamically allocated, risky data streams are prioritized, monitoring frequency is adjusted, and the real-time changing network threat environment is analyzed to achieve optimal resource allocation. S4: Based on resource optimization and configuration, simulate network security attack threat scenarios, automatically adjust simulation parameters using real-time updated network status data, simulate key security risk points, and obtain network security attack threat simulation results based on network traffic and attack patterns; S5: Use the network security attack threat simulation results to conduct network security testing, dynamically adjust the attack frequency, detect the network's response and processing capabilities, optimize the network security configuration, and obtain network security assessment results; The method collects real-time network traffic data, applies data attribute evaluation technology in rough set theory, analyzes the characteristics of the network traffic data, evaluates the fluctuation intensity and amplitude of the data, dynamically adjusts the size of the time window, and obtains the time window size adjustment parameters, including: S101: Collect real-time network traffic data, classify and record data packets, analyze the source addresses of data packets, evaluate the size and transmission frequency of data packets, perform initial screening of data traffic, set a dynamically adjusted time window to capture traffic fluctuations, and obtain real-time network traffic records; S102: Using real-time network traffic records and applying rough set theory, the data is divided into upper and lower approximate sets. The statistical characteristics and frequency distribution of elements in the differentiated sets are analyzed. The differences between the upper and lower approximate sets are compared to identify network traffic volatility and abnormal data points, and obtain data attribute fluctuation analysis results. S103: Based on the data attribute fluctuation analysis results, dynamically adjust the size of the time window, compare the data variability under short and long time windows, calculate the window size, and obtain the time window size adjustment parameter; The calculation formula of the window size is as follows (1): Among them, W t Represents the window size at time point t, w i Represents the weight coefficient of time point ti, X t-i represents the data value at time point ti, n represents the number of data points in the window, X t represents the data value at time point t, represents the mean value of the data within the window, σ represents the standard deviation of the data within the window, and β represents the adjustment coefficient.

2. The network security attack threat analysis method based on rough sets according to claim 1 is characterized in that: The time window size adjustment parameters include window duration, flow threshold for triggering expansion, and dynamic reduction rate; The abnormal pattern recognition results include the frequency, duration and impact range of abnormal events; The resource optimization configuration includes the processing priority of risky traffic, the backup strategy of key resources and the monitoring of key services; The network security attack threat simulation results include the type of simulated attack, the success rate of the simulation and the network's defense response; The network security assessment results include the number of vulnerabilities detected, the speed of repair, and network security recovery capabilities.

3. The network security attack threat analysis method based on rough sets according to claim 1 is characterized in that: The time window size adjustment parameter is used to analyze real-time network traffic using a random forest algorithm, and abnormal behavior patterns in a real-time network environment are identified by statistically analyzing features and recording abnormal data, thereby obtaining abnormal pattern recognition results, including: S201: Adjust parameters according to the time window size, perform initial filtering on the network data within the target time, remove irrelevant data, and extract basic statistical features from the remaining data, including traffic volume, number of connections, and duration, to obtain a basic feature data set; S202: Based on the basic feature data set, the data is standardized, the data format is processed, and the data is screened for outliers. Potential outlier data is screened based on deviation from the mean and standard deviation to obtain an outlier candidate data set; S203: Analyze the network data behavior pattern using the abnormal candidate data set, compare the data behavior with the abnormal behavior pattern through a pattern matching algorithm, and generate an abnormal behavior pattern recognition result.

4. The network security attack threat analysis method based on rough sets according to claim 1 is characterized in that: Based on the abnormal pattern recognition results, the abnormal frequency and severity in the data flow are evaluated, resources are dynamically configured, risky data flows are prioritized, monitoring frequency is adjusted, and the real-time changing network threat environment is analyzed to obtain optimal resource configuration, including: S301: Based on the abnormal pattern recognition results, the frequency and severity of the identified abnormal behaviors are analyzed to assess the potential impact and urgency of the abnormal events and obtain abnormal risk assessment results; S302: Using the abnormal risk assessment results, dynamically configure network monitoring and protection resources, prioritize identified risk data flows, adjust resource allocation and response mechanisms for network security data monitoring, optimize the distribution and use of network resources, and obtain risk priority processing results; S303: Based on the risk prioritization results, adjust the monitoring frequency, analyze the real-time changes in network traffic, evaluate the dynamic characteristics of the network threat environment, and optimize resource allocation by continuously monitoring and matching changes in the network environment.

5. The network security attack threat analysis method based on rough sets according to claim 1 is characterized in that: The network security attack threat scenario is simulated based on resource optimization configuration, and simulation parameters are automatically adjusted using real-time updated network status data. The simulation covers key security risk points and refers to network traffic and attack patterns to obtain network security attack threat simulation results, including: S401: setting initial parameters for network security simulation based on resource optimization configuration, automatically adjusting simulation behavior and parameters using real-time updated network status data, verifying simulation consistency, and obtaining adjusted simulation parameters; S402: Using the adjusted simulation parameters, construct and execute security attack threat scenarios in network security simulation, simulate security attacks on key network nodes, calculate quantitative assessment values ​​of network responses, and obtain security risk coverage records; S403: Based on the security risk coverage records, analyze the network traffic data and simulated attack patterns, evaluate the correlation and impact between the two, optimize the authenticity and coverage of the simulation, and obtain the network security attack threat simulation results.

6. The network security attack threat analysis method based on rough sets according to claim 5 is characterized in that: The calculation formula of the quantitative evaluation value of the network response is as follows (2): Where RQ is the quantitative evaluation value of network response, N represents the total number of attack events in the simulation, and w a represents the weight of the a-th attack event, s a represents the security status score of the a-th node before the attack, t a Represents the security status score of the a-th node after being attacked.

7. The network security attack threat analysis method based on rough sets according to claim 1 is characterized in that: The network security attack threat simulation results are used to conduct network security testing, dynamically adjust the attack frequency, detect the network's response and processing capabilities, optimize the network security configuration, and obtain network security assessment results, including: S501: Using the network security attack threat simulation results, configure the network security test environment, set and adjust the attack simulation frequency and intensity, simulate different types of network attacks, test the network's real-time response and defense capabilities, and obtain network response test records; S502: By analyzing the network response test records, the network's performance and handling capabilities in attack scenarios are evaluated, and the network's response to attack threats is adjusted and optimized to obtain an optimized security configuration. S503: Apply the optimized security configuration, conduct network security testing, continuously monitor the network's defense response, evaluate the adjusted network security protection effect and processing efficiency, and obtain network security assessment results.

8. A rough set-based network security attack threat analysis device, the rough set-based network security attack threat analysis device is used to implement the rough set-based network security attack threat analysis method according to any one of claims 1 to 7, characterized in that: The device comprises: The data attribute evaluation module is used to collect real-time network traffic data, apply the data attribute evaluation technology in rough set theory to analyze the characteristics of network traffic data, evaluate the fluctuation intensity and amplitude of the data, dynamically adjust the size of the time window, and obtain the time window size adjustment parameter; The real-time traffic analysis module is used to adjust parameters using the time window size and utilize the random forest algorithm to analyze real-time network traffic. By statistically analyzing features and recording abnormal data, it identifies abnormal behavior patterns in the real-time network environment and obtains abnormal pattern recognition results. The abnormal pattern diagnosis module is used to evaluate the frequency and severity of abnormalities in data streams based on the abnormal pattern recognition results, dynamically allocate resources, prioritize risky data streams, adjust monitoring frequency, analyze the real-time changing network threat environment, and obtain optimal resource allocation; The security scenario simulation module is used to simulate network security attack threat scenarios based on resource optimization configuration. It automatically adjusts simulation parameters using real-time updated network status data, simulates key security risk points, and obtains network security attack threat simulation results based on network traffic and attack patterns. The network defense optimization module is used to use the network security attack threat simulation results to conduct network security testing, dynamically adjust the attack frequency, detect the network's response and processing capabilities, optimize network security configuration, and obtain network security assessment results.

Citation Information

Patent Citations

  • Network security situation assessment method based on fuzzy rough set

    CN105306438A

  • Security risk assessment method for risk cascade of power distribution network under network attack

    CN115361150A