College network security deduction integrated platform based on digital twinning

By applying digital twin technology in the field of network security of colleges and universities and building an integrated deduction platform, the problems of insufficient protection of new attack methods, lack of comprehensive security situation awareness, and the disconnection between security drills and the actual network environment are solved, real-time and comprehensive monitoring and analysis of college networks are achieved, and the reliability of protection capabilities and security strategy formulation is improved.

CN120186035APending Publication Date: 2025-06-20HEBEI INST OF MACHINERY ELECTRICITY

Patent Information

Application Number
CN202510391243.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing university network security protection system lacks protection against new attack methods, lacks comprehensive security situation awareness, and the security drills are out of touch with the actual network environment.

Method used

The integrated platform for college network security deduction based on digital twins can realize real-time monitoring, accurate analysis and effective protection of college network security status through data collection and transmission modules, data processing and analysis modules, digital twin model construction modules, security deduction modules, security decision-making and response modules and visual display modules.

Benefits of technology

Real-time and comprehensive monitoring and analysis of university networks has been achieved, the protection ability of new attack methods has been improved, network security situation awareness has been enhanced, and the security drill results are closer to the actual network environment, providing a more reliable basis for the formulation and optimization of university network security strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120186035A_ABST
    Figure CN120186035A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a college network security deduction integrated platform based on digital twinning, which comprises a data acquisition and transmission module, a data processing and analysis module, a digital twinning model construction module, a security deduction module, a security decision and response module and a visual display module. According to the platform, through collecting college network multi-source data, constructing a digital twin model, simulating a network attack scene to carry out security deduction, and generating and executing a protection strategy, comprehensive perception, precise protection and efficient management of a college network security condition are realized, the defects of an existing college network security protection system are effectively solved, and the safety of a college network is improved. And the network security protection capability of colleges and universities is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and more specifically to an integrated network security deduction platform for universities based on digital twins. Background Art

[0002] In the digital age, the network environment of universities is becoming increasingly complex. It carries many key businesses such as teaching, scientific research, and management, and faces severe network security challenges. University networks cover a large number of information systems, such as the teaching management system, scientific research project management system, and campus card system. These systems store a large amount of personal information of teachers and students, teaching materials, and scientific research data. Once a network attack occurs, it will not only cause service interruption and affect the normal teaching order, but may also cause sensitive information leakage, bringing serious negative impacts.

[0003] Traditional university network security protection mainly relies on security devices such as firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS). However, these devices have certain limitations. On the one hand, they are often based on known attack features for detection and defense, and have limited protection effects on new and unknown attack methods, such as zero-day vulnerability attacks and advanced persistent threats (APTs). When a new malware appears and spreads using undisclosed vulnerabilities, traditional security devices may not be able to identify and block it in time. On the other hand, the existing security protection system lacks comprehensive perception and in-depth analysis of the overall network security situation. Security devices work independently, and the security alarm information generated is scattered, making it difficult to form a comprehensive assessment of the network security situation. University network administrators need to screen and analyze a large amount of alarm information, which consumes a lot of time and energy, and is prone to missing important security threats.

[0004] In addition, university network security drills usually adopt the method of simulated scenarios, which are somewhat different from the actual network environment. In simulated drills, it is difficult to truly reflect the complex relationships between various devices, systems, and services in the university network. This limits the reference value of the drill results and cannot provide sufficient basis for the formulation and optimization of university network security strategies. With the development of digital twin technology, it has been widely used in industries such as industry and urban management, but its application in the field of university network security is relatively small. Introducing digital twin technology into the field of university network security, building a digital twin model that can truly map the actual network environment of universities, and conducting network security deductions based on this model are of great significance to improving the network security protection capabilities of universities. Summary of the invention

[0005] The objective of the present invention is to provide an integrated platform for network security deduction in colleges and universities based on digital twins, aiming to solve problems such as the insufficient protection of existing college network security protection systems against new attack means, the lack of comprehensive security situation awareness, and the disconnection between security drills and the actual network environment, and to achieve real-time monitoring, accurate analysis, and effective protection of the network security situation in colleges and universities.

[0006] The technical solution adopted by the present invention to solve its technical problems is: an integrated platform for network security deduction in colleges and universities based on digital twins, including: A data collection and transmission module, which is used to collect configuration information, operating status data, network traffic data, alarm information generated by security devices, etc. of various devices in the college network, and transmit the data to the data processing module in real time; A data processing and analysis module, which processes the collected data through cleaning, deduplication, correlation analysis, etc., extracts key information, constructs a network asset information database, and uses machine learning algorithms and big data analysis technologies to detect anomalies in network traffic data; A digital twin model construction module, which constructs a digital twin model of the college network according to the network asset information database and the topological structure of the college network, and simulates the operating status and data interaction process of network devices and business systems; A security deduction module, which simulates various network attack scenarios on the digital twin model, analyzes the response and changes of the digital twin model during the attack process, and predicts the attack impact range and harm degree; A security decision-making and response module, which generates targeted security protection strategies according to the security deduction results and the real-time network security situation, executes the strategies and feeds back the results; A visualization display module, which displays the topological structure of the college network, device operating status, network security situation, and security deduction results through an intuitive visualization interface.

[0007] Specifically, the data collection and transmission module also includes the collection of data such as the signal strength and the number of connected users of wireless access points in the college network.

[0008] Specifically, in the data processing and analysis module, deep learning algorithms are used to classify network traffic data to improve the recognition accuracy of different types of network attacks.

[0009] Specifically, the digital twin model construction module uses a graph database to store the connection relationships between network devices and the data interaction relationships between business systems to improve the query and update efficiency of the model.

[0010] Specifically, when simulating attack scenarios, the security deduction module considers the performance parameters of network devices and the load conditions of business systems to more realistically reflect the impact of attacks on the actual network.

[0011] Specifically, the security decision-making and response module has the function of automatically executing security protection policies and supports manual intervention and adjustment.

[0012] Specifically, the visualization display module provides a variety of visualization views, such as network topology diagrams, traffic trend diagrams, security event heat maps, etc., to meet the needs of different users.

[0013] Specifically, the platform also includes interfaces with existing security devices in colleges and universities to achieve data sharing and collaborative work.

[0014] Advantages of the present invention: For the integrated platform for network security deduction in colleges and universities based on digital twin of the present invention, multi-source data in the college network is collected through the data collection and transmission module, and in-depth analysis is carried out using the data processing and analysis module, enabling real-time and comprehensive understanding of the operating status and security situation of the college network, and timely discovery of potential security threats.

[0015] Based on the digital twin model for security deduction, various network attack scenarios can be simulated, the possible impacts of the attacks can be predicted, and thus targeted security protection policies can be formulated to improve the protection ability of the college network against new attack means.

[0016] The digital twin model truly reflects the actual situation of the college network. Conducting security drills on this model can make the drill results closer to reality and provide a more reliable basis for the formulation and optimization of college network security policies.

[0017] The visualization display module presents complex network security information in an intuitive form to network administrators, facilitating their quick decision-making and timely taking of effective security protection measures. Description of the Drawings

[0018] The present invention will be further described below in conjunction with the drawings and embodiments.

[0019] Figure 1 It is a schematic diagram of the platform architecture of the integrated platform for network security deduction in colleges and universities based on digital twin provided by the present invention; Figure 2 It is a module diagram of the integrated platform for network security deduction in colleges and universities based on digital twin provided by the present invention; Figure 3 It is a data flow diagram of the integrated platform for network security deduction in colleges and universities based on digital twin provided by the present invention; Figure 4 It is a schematic diagram of the digital twin model of the integrated platform for network security deduction in colleges and universities based on digital twin provided by the present invention. Detailed Embodiments

[0020] In order to make the technical means, creative features, achieved purposes and effects of the present invention easy to understand, the present invention will be further described below in conjunction with specific embodiments.

[0021] As Figures 1 - 4 shown, the integrated platform for network security deduction in colleges and universities based on digital twin of the present invention includes: Data collection and transmission module: Collect configuration information, operating status data, network traffic data, alarm information generated by security devices, etc. of various devices (such as switches, routers, servers, etc.) in the college network through distributed sensors, network traffic monitoring tools, etc., and transmit these data to the data processing module in real time.

[0022] Data processing and analysis module: Process the collected data through cleaning, de-duplication, correlation analysis, etc., extract key information, and construct a network asset information database. Use machine learning algorithms and big data analysis techniques to perform anomaly detection on network traffic data and identify potential network security threats. By analyzing the time series data of network traffic, establish a normal traffic model, and issue an anomaly alarm when the actual traffic deviates from this model.

[0023] Digital twin model construction module: Construct a digital twin model of the college network according to the network asset information database and the topological structure of the college network. This model not only includes the physical attributes and logical connection relationships of network devices, but also simulates the operating status and data interaction processes of various business systems in the network, realizing an accurate mapping of the actual network environment of colleges and universities.

[0024] Security deduction module: Simulate various network attack scenarios on the digital twin model, such as DDoS attacks, SQL injection attacks, cross-site scripting attacks (XSS), etc. By analyzing the responses and changes of the digital twin model during the attack process, predict the possible impact range and harm degree of the attack, and provide a basis for formulating effective security protection strategies.

[0025] Security decision-making and response module: Generate targeted security protection strategies according to the results of security deduction and the real-time network security situation, such as adjusting firewall rules, isolating the attacked network area, starting an emergency response plan, etc. At the same time, feedback the execution results of the security protection strategy to the digital twin model and the data processing and analysis module to evaluate the protection effect in real time.

[0026] Visualization display module: Display the topological structure of the college network, device operating status, network security situation, and the results of security deduction through an intuitive visualization interface. Present complex network security information to college network administrators in the form of charts, graphs, etc., facilitating them to quickly understand the network security situation and make decisions.

[0027] The data acquisition and transmission module also includes the acquisition of data such as the signal strength of wireless access points and the number of connected users in the university network.

[0028] In the data processing and analysis module, deep learning algorithms are used to classify network traffic data to improve the recognition accuracy of different types of network attacks.

[0029] The digital twin model construction module uses a graph database to store the connection relationships between network devices and the data interaction relationships between business systems to improve the query and update efficiency of the model.

[0030] When simulating attack scenarios, the security deduction module considers the performance parameters of network devices and the load conditions of business systems to more realistically reflect the impact of attacks on the actual network.

[0031] The security decision-making and response module has the function of automatically executing security protection policies and supports manual intervention and adjustment.

[0032] The visualization display module provides various visualization views, such as network topology diagrams, traffic trend diagrams, security event heat maps, etc., to meet the needs of different users.

[0033] The platform also includes interfaces with existing security devices in the university to achieve data sharing and collaborative work.

[0034] Example 1: Data Acquisition and Transmission Device Data Acquisition: Deploy SNMP (Simple Network Management Protocol) agents on the core switches, aggregation switches, and access switches in the university network to collect basic configuration information of the devices, such as IP addresses, port configurations, VLAN divisions, etc., as well as operating status data, including CPU usage, memory usage, port traffic, etc. The CPU usage data of the switches is collected every 5 minutes to monitor the load conditions of the devices in real time. For servers, install server monitoring software to collect information such as the operating system version, hardware configuration, and process running status of the servers.

[0035] Network Traffic Monitoring: Use network traffic monitoring tools, such as Wireshark and Snort, to collect network traffic data at key nodes (such as egress routers and core switches) in the university network. These tools can capture network packets and analyze information such as the source IP address, destination IP address, port number, and protocol type of the packets. By analyzing the network traffic data, it is found that a large number of TCP connection requests from a specific IP address during a certain period may be a precursor to a DDoS attack.

[0036] Wireless Access Point Data Collection: For the wireless access points within a university, collect data such as signal strength, number of connected users, and user MAC addresses. By monitoring the changes in the signal strength of wireless access points, it is possible to determine whether there is signal interference or illegal access points. When the wireless signal strength in a certain area suddenly weakens, it may be affected by the surrounding environment or malicious signal shielding. Transmit the collected data to the data processing and analysis module in real time through a dedicated data transmission channel, such as a fiber optic network or VPN.

[0037] Example Two: Data Processing and Analysis Data Cleaning and Duplicate Removal: Clean the collected device configuration information, operating status data, network traffic data, etc., and remove the noise data and error data among them. For the data packets with a length of 0 in the network traffic data, regard them as invalid data and delete them. At the same time, perform duplicate removal processing on the duplicate data to ensure the accuracy and consistency of the data.

[0038] Association Analysis: Establish the association relationship between device configuration information, operating status data, and network traffic data. Associate the port traffic data of the switch with the network access situation of the server connected to this port to determine whether the network activities of the server are normal. Through association analysis, potential security problems can be discovered. For example, when the network traffic of a certain server suddenly increases and there are a large number of abnormal TCP connections on the switch port connected to it, it may mean that the server is under attack.

[0039] Anomaly Detection: Use machine learning algorithms, such as Support Vector Machine (SVM), K-Nearest Neighbor Algorithm (KNN), etc., to perform anomaly detection on network traffic data. First, collect the normal network traffic data within a period of time as training samples, train the machine learning model, and establish a normal traffic model. Then, input the real-time collected network traffic data into the model for detection. When the deviation between the actual traffic data and the normal traffic model exceeds a certain threshold, it is determined as abnormal traffic and an alarm is issued. By training the SVM model to classify the network traffic data, abnormal behaviors such as DDoS attacks and port scans can be accurately identified.

[0040] Example Three: Digital Twin Model Construction Network Asset Information Collection: Obtain the network asset information library from the data processing and analysis module, which contains detailed information about various devices in the university network, such as device names, models, IP addresses, MAC addresses, etc., as well as the connection relationships between devices. At the same time, collect the architecture information of the business systems in the university network and the data interaction processes.

[0041] Model construction: Use professional digital twin modeling tools, such as CityEngine, 3dsMax, etc., to construct a digital twin model of the university network based on network asset information and the university network topology. In the model, display the physical forms and location distributions of network devices, as well as the logical connection relationships between devices, in the form of three-dimensional graphics. Layout the network devices in areas such as teaching buildings, office buildings, and libraries according to their actual positions, and represent the network connections between devices with lines. For business systems, simulate their operating states and data interaction processes to establish dynamic models of business systems. For example, simulate business processes such as student course selection and teacher grade entry in the educational administration system, as well as the data transmission process between different servers and databases.

[0042] Model verification and optimization: After constructing the digital twin model, verify and optimize the model. Check the accuracy and reliability of the model by comparing the output results of the model with actual network data. Compare the operating state data of network devices in the model with the monitoring data of actual devices. If there are deviations, analyze the reasons and adjust the model. At the same time, update the digital twin model in a timely manner according to changes in the university network, such as new devices added and network topology adjustments, to ensure that it can always accurately reflect the actual situation of the university network.

[0043] Example 4: Security deduction and decision-making response Security deduction: Simulate various network attack scenarios on the digital twin model. Simulate a DDoS attack by sending a large number of forged network requests to the target server in the digital twin model, and observe the changes in network traffic, the load conditions of the server, and the responses of other related devices in the model. Analyze the impacts of the attack on aspects such as network bandwidth, server performance, and business system availability, and predict the possible degree of harm caused by the attack. For another example, simulate an SQL injection attack by attempting to send malicious SQL statements to the business system database in the digital twin model, and observe the changes in the operating state of the database and the data integrity, and evaluate the risk of damage to business data caused by the attack.

[0044] Security decision-making: According to the results of security deduction and the real-time network security situation, the security decision-making and response module generates targeted security protection strategies. If it is found in the security deduction that a DDoS attack may cause the network bandwidth to be exhausted and affect normal business operations, the generated protection strategies may include starting a traffic cleaning service to divert the attack traffic to a dedicated cleaning device for processing; at the same time, adjusting the firewall rules to restrict network access from the IP address of the attack source.

[0045] Response Execution and Effect Evaluation: The security decision-making and response module automatically executes the generated security protection policies and feeds back the execution results of the policies to the digital twin model and the data processing and analysis module. After starting the traffic cleaning service, observe the changes in network traffic through the digital twin model to verify whether the attack traffic is effectively controlled. At the same time, the data processing and analysis module monitors and analyzes the network traffic data in real time to evaluate the execution effect of the protection policy. If it is found that the protection policy fails to achieve the expected effect, adjust the policy in a timely manner and re-conduct security deduction and decision-making response.

[0046] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification only illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of protection required by the present invention. The scope of protection required by the present invention is defined by the appended claims and their equivalents.

Claims

1. The integrated platform for university network security simulation based on digital twins is characterized by: include: The data collection and transmission module is used to collect the configuration information, operation status data, network traffic data and alarm information generated by security devices of various devices in the university network, and transmit the data to the data processing module in real time; The data processing and analysis module cleans, removes duplicates, and performs correlation analysis on the collected data, extracts key information, builds a network asset information database, and uses machine learning algorithms and big data analysis technology to detect anomalies in network traffic data; The digital twin model construction module builds a digital twin model of the university network based on the network asset information database and the topological structure of the university network, simulating the operating status and data interaction process of network equipment and business systems; The security simulation module simulates various network attack scenarios on the digital twin model, analyzes the response and changes of the digital twin model during the attack, and predicts the impact scope and degree of damage of the attack; The security decision-making and response module generates targeted security protection strategies based on security simulation results and real-time network security situation, executes the strategies and provides feedback on the results; The visualization display module uses an intuitive visualization interface to display the topological structure of the university network, equipment operation status, network security situation, and security deduction results.

2. The integrated platform for network security simulation in colleges and universities based on digital twins according to claim 1 is characterized by: The data collection and transmission module also includes the collection of data such as the signal strength of wireless access points in the university network and the number of connected users.

3. The integrated platform for network security simulation in colleges and universities based on digital twins according to claim 1 is characterized by: In the data processing and analysis module, deep learning algorithms are used to classify network traffic data to improve the accuracy of identifying different types of network attacks.

4. The integrated platform for network security simulation in colleges and universities based on digital twins according to claim 1 is characterized by: The digital twin model building module uses a graph database to store the connection relationships between network devices and the data interaction relationships between business systems to improve the query and update efficiency of the model.

5. The integrated platform for network security simulation in colleges and universities based on digital twins according to claim 1 is characterized by: When simulating attack scenarios, the security simulation module takes into account the performance parameters of network equipment and the load of business systems to more realistically reflect the impact of attacks on the actual network.

6. The integrated platform for network security simulation in colleges and universities based on digital twins according to claim 1 is characterized by: The security decision and response module has the function of automatically executing security protection strategies and supports manual intervention and adjustment.

7. The integrated platform for network security simulation in colleges and universities based on digital twins according to claim 1 is characterized by: The visualization display module provides a variety of visualization views, such as network topology diagrams, traffic trend diagrams, security event heat maps, etc., to meet the needs of different users.

8. The integrated platform for network security simulation in colleges and universities based on digital twins according to claim 1 is characterized by: The platform also includes interfaces with existing security equipment in universities to enable data sharing and collaborative work.

Citation Information

Patent Citations

  • Extensible network attack behavior classification method

    CN111507385A

  • Three-dimensional visual management method, system and equipment for network security assets

    CN116827811A

  • Digital twinborn deduction simulation system

    CN116882145A

  • Rule model construction method, anomaly monitoring method, network equipment and storage medium

    CN117332255A

  • Network attack and defense decision support method and system based on artificial intelligence

    CN119155099A

Cited By

  • Vulnerability priority evaluation method, system and device based on large language model and storage medium

    CN121525052A

  • Vulnerability priority assessment method, system, device and storage medium based on large language model

    CN121525052B