Knowledge graph creating method and device based on network security entity

By defining entity categories and extracting ontology term keywords, determining the ontology scope and evaluating ontology relationships, the problem of difficult limiting the scope of the entity and attribute relationship in network security entity information is solved, and the precise creation of knowledge graphs and efficient processing of network security data is achieved.

CN120197684APending Publication Date: 2025-06-24LANZHOU RESOURCES & ENVIRONMENT VOC TECH COLLEGE
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510588610.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art cannot effectively limit and optimize the relationship range between entities and attributes in network security entity information, thereby affecting the accuracy of the knowledge graph.

Method used

By defining entity categories, entity characteristics and individual relationships, extracting ontology keywords, determining ontology scope, extracting the hierarchical relationships of target ontology keywords, and performing ontology relationship evaluation to build an optimized knowledge graph.

Benefits of technology

It realizes the precise definition and optimization of the risk scope of the network security ontology, and improves the accuracy of the creation of knowledge graphs and the efficiency of network security data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197684A_ABST
    Figure CN120197684A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of natural language processing, and particularly discloses a knowledge graph creation method and device based on a network security entity. The creation method comprises the following steps: S1, defining entity categories, entity characteristics and individual interrelationships, and extracting and determining ontology term keywords from a collected historical entity data set; s2, performing ontology range determination on the historical entity data set according to the extracted and determined ontology term keywords; s3, extracting a target ontology term keyword in the network security entity platform based on the ontology range, defining a hierarchical relationship of the target ontology term keyword, and performing ontology relationship evaluation based on the hierarchical relationship of the target ontology term keyword; s4, outputting an ontology relationship evaluation result and constructing a knowledge graph according to the ontology relationship; the risk range of the network security ontology in the entity information is optimized and determined, and the accuracy of the knowledge graph is optimized by utilizing ontology relationship evaluation and analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of natural language processing, and particularly to a method and device for creating a knowledge graph based on network security entities. Background Art

[0002] As a structured semantic knowledge representation model, a knowledge graph can be used to perform text understanding on a large amount of information data resources and can be applied in fields such as intelligent search and response.

[0003] With the increasingly severe network security situation, creating a knowledge graph based on network security entities can better cope with network threats and provide a basis for tracing the source of attack information, and a method for creating a knowledge graph that can build for key information is needed. For this reason, the existing patent No. CN107665252B, "A Method and Device for Creating a Knowledge Graph", obtains the association relationship between each entity and its attributes in the entity set; creates and outputs a knowledge graph according to the entity set, the attribute set, and the association relationship between the entity and its attributes. The knowledge graph includes entities, entity attributes, the association relationship between the entity and its attributes, and the association relationship between entities. By adopting this solution, a knowledge graph can be accurately created, and the relationship between entities and attributes, as well as the association relationship between entities, can be intuitively presented; however, there are still the following problems:

[0004] It is impossible to determine the relationship range between entities and attributes in entity information, and it is impossible to evaluate according to the risk range of the network security ontology of different entity information, thereby affecting the accuracy of knowledge graph creation. Summary of the Invention

[0005] The purpose of the present invention is to provide a method and device for creating a knowledge graph based on network security entities, and solve the technical problem of how to limit and optimize the risk range of the network security ontology in entity information and evaluate and analyze to achieve the accuracy of optimizing the knowledge graph;

[0006] The purpose of the present invention can be achieved through the following technical solutions:

[0007] A method for creating a knowledge graph based on network security entities, the method includes:

[0008] S1. Define entity categories, entity characteristics, and individual relationships, and extract and determine ontology term keywords from the collected historical entity data set;

[0009] S2. Determine the ontology range of the historical entity data set according to the extracted and determined ontology term keywords;

[0010] S3. Extract the target ontology term keywords in the network security entity platform based on the ontology scope, define the hierarchical relationship of the target ontology term keywords, and evaluate the ontology relationships based on the hierarchical relationship of the target ontology term keywords;

[0011] S4. Output the ontology relationship evaluation result and construct a knowledge graph based on the ontology relationship.

[0012] Preferably, S1 includes:

[0013] Obtain the integration requirements of the historical data set. The content of the integration requirements includes the amount of data to be integrated, the integration path, and the types of data to be integrated, and evaluate the entity risk based on the content of the integration requirements;

[0014] After the evaluated entity risk conforms to the set risk threshold range, determine the ontology term extraction process and determine the processing time of the ontology term extraction process;

[0015] When the processing time of the ontology term extraction process meets the preset processing time requirements, extract the ontology term keywords and enter step S2.

[0016] Preferably, the specific process of evaluating the entity risk includes:

[0017] Obtain the amount of data to be integrated corresponding to the integration requirements of the preset network platform; and evaluate the decomposition risk of the integration requirements based on the amount of data to be integrated corresponding to the integration requirements, the number of iterations of the integration requirements, and the risk type of the integration requirements;

[0018] Obtain the amount of data to be integrated corresponding to the integration requirements of the preset network platform; and evaluate the aggregation risk of the integration requirements based on the intermediate amount obtained by decomposing the amount of data corresponding to the integration requirements and the number of iterations of the intermediate amount corresponding to the integration requirements;

[0019] Evaluate the primary risk of the integration requirements based on the decomposition risk and the aggregation risk of the integration requirements, and determine whether the decomposition risk or the aggregation risk of the integration requirements is greater than the set risk threshold. If so, proceed to the next step; if not, use the primary risk of the integration requirements as the entity risk of the integration requirements;

[0020] Determine the correction amount of the decomposition risk by the ratio of the decomposition risk to the set risk threshold, determine the correction amount of the aggregation risk by the ratio of the aggregation risk to the set risk threshold, and determine the entity risk of the integration requirements based on the correction amount of the decomposition risk, the correction amount of the aggregation risk, and the primary risk.

[0021] Preferably, determine the risk type of the integration requirements according to the path to be integrated and the type of data to be integrated; the amount of data to be integrated is determined according to the risk type of the integration requirements, specifically determined according to the number of iterations of the integration requirements or the accuracy of the result analysis of the integration requirements.

[0022] Preferably, the ontology term extraction process includes:

[0023] Determine the average processing time when processing the integration requirements of the entity dataset with different entity risks based on a preset knowledge model in the field of network security; and determine the estimated processing time of the integration requirements by combining the risk of the current integration requirement processing and the number of integration requirements with different risks.

[0024] Obtain the number of integration requirements, and judge whether it is necessary to correct according to the estimated processing time of the integration requirements based on the number of integration requirements:

[0025] If not, divide the integration requirements according to the risk of the integration requirements into high-risk integration requirements and low-risk integration requirements, and determine whether it is necessary to correct the estimated processing time of the integration requirements according to the number and risk ratio of the integration requirements:

[0026] If not, use the estimated processing time of the current integration requirement as the determination of the processing time of the ontology term extraction process, and extract the ontology term keywords within the range of the number of integration requirements.

[0027] If so, determine the corrected time of the integration requirements through the number of integration requirements, the number of high-risk integration requirements, and combine with the entity risk assessment value, and determine the processing time of the ontology term extraction process according to the corrected time and the estimated processing time of the integration requirements, and extract the ontology term keywords within the range of the number of integration requirements.

[0028] If so, determine the corrected time of the integration requirements through the number of integration requirements, the number of high-risk integration requirements, and combine with the entity risk assessment value, and determine the processing time of the ontology term extraction process according to the corrected time and the estimated processing time of the integration requirements, and extract the ontology term keywords within the range of the number of integration requirements.

[0029] Preferably, S2 includes:

[0030] Generate an ontology term keyword library according to the historical entity dataset and the ontology term keywords, and use the ontology term keyword library as a training sample to input into a recurrent neural network model for entity extraction.

[0031] The method based on network security language rules uses predefined language rules to identify the entity relationships corresponding to the ontology term keywords after entity extraction. Specifically, through the supervised learning method, the labeled ontology term keywords and their corresponding entity relationships are used as training data and input into a recurrent neural network model to learn the relationships between entities, construct an ontology model, and output the entity relationship scope.

[0032] Judge the entity relationship scope to determine the probability of the entity relationship scope, and record the entity relationship scope probability that meets the preset probability as the ontology scope.

[0033] Preferably, the process of extracting the target ontology term keywords in the network security entity platform based on the ontology scope, defining the hierarchical relationship of the target ontology term keywords, and evaluating the ontology relationship based on the hierarchical relationship of the target ontology term keywords is as follows:

[0034] After determining the ontology scope, extract the probability related to security terms in the ontology term keywords, and use those with the probability related to security terms in the ontology term keywords greater than the set threshold of the probability related to security terms as the target ontology term keywords.

[0035] Define the hierarchical relationship of the target ontology term keywords, divide the hierarchical relationship of the target ontology term keywords into low-level relationships and high-level relationships, and determine the ontology relationship evaluation based on the high-level relationships of different target ontology term keywords and the number of target ontology term keywords in the high-level relationships.

[0036] A knowledge graph creation device based on network security entities, including:

[0037] An ontology extraction module, used to define entity categories, entity characteristics, and the mutual relationships of individuals, and extract and determine ontology term keywords from the collected historical entity data set.

[0038] An ontology determination module, used to determine the ontology scope of the historical entity data set according to the ontology term keywords extracted and determined.

[0039] A relationship evaluation module, used to extract the target ontology term keywords in the network security entity platform based on the ontology scope, define the hierarchical relationship of the target ontology term keywords, and evaluate the ontology relationship based on the hierarchical relationship of the target ontology term keywords.

[0040] A graph construction module, used to output the ontology relationship evaluation result and construct a knowledge graph based on the ontology relationship.

[0041] A storage medium, on which computer instructions are stored, and when the computer instructions run, they execute the steps of the knowledge graph creation method based on network security entities.

[0042] An electronic device includes a memory and a processor. Computer instructions capable of running on the processor are stored on the memory. When the processor runs the computer instructions, it executes the steps of a method for creating a knowledge graph based on network security entities.

[0043] Advantages of the present invention:

[0044] (1) The present invention determines the amount of data to be integrated according to the risk type of the integration requirement, and evaluates the entity riskiness according to the content of the integration requirement. Through the entity risk assessment process, that is, through the information determined by the risk assessment of the integration requirement processing, it is ensured that the precise selection of ontology term keywords is carried out within the time range that meets the ontology term extraction processing, thereby ensuring that the basic information for determining the risk range of the network security ontology optimizes the ontology range.

[0045] (2) The present invention sets ontology term extraction processing. During the process of determining the ontology range, add integration processing to be set in a preset network platform to ensure the determination of ontology term keywords within the risk range and the determination of the estimated processing time for the integration processing requirement and the completion of the estimated processing time correction process; determine the processing time of the ontology term extraction processing according to the corrected time and the estimated processing time of the integration requirement; ensure that the processing time of the integration processing is adjusted according to the real-time state to achieve the rapid acquisition of ontology term keywords and reduce the information delay of the integration processing.

[0046] Of course, it is not necessary for any product implementing the present invention to achieve all the above-described advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for describing the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0048] Figure 1 It is a step diagram of the method for creating a knowledge graph based on network security entities of the present invention;

[0049] Figure 2 It is a structural diagram of the device for creating a knowledge graph based on network security entities of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0050] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0051] Please refer to Figure 1 As shown, the present invention is a method for creating a knowledge graph based on network security entities. In the embodiment, the specific method includes:

[0052] S1. Define entity categories, entity characteristics, and individual relationships, and extract and determine the ontology term keywords for the collected historical entity dataset;

[0053] S2. Determine the ontology scope for the historical entity dataset according to the extracted and determined ontology term keywords;

[0054] S3. Extract the target ontology term keywords in the network security entity platform based on the ontology scope, define the hierarchical relationship of the target ontology term keywords, and evaluate the ontology relationship based on the hierarchical relationship of the target ontology term keywords;

[0055] S4. Output the ontology relationship evaluation result and construct a knowledge graph based on the ontology relationship.

[0056] In the above technical solution, first, step S1 is to obtain the historical entity dataset by processing the data source containing multiple entities. The data source obtained through the background knowledge of network security contains the definition of security-related information and distinguishes between the network security ontology and the attack side. Therefore, it is considered to evaluate the risk of data entities for the obtained entity dataset, and then it is possible to ensure the extraction and determination of ontology term keywords for the historical entity dataset. Through the evaluation process of entity risk, the determination of the risk scope of the network security ontology is ensured.

[0057] Specifically, in one embodiment, step S1 includes:

[0058] Obtain the integration requirements of the historical dataset. The content of the integration requirements includes the amount of data to be integrated, the integration path, and the types of data to be integrated, and evaluate the entity risk according to the content of the integration requirements;

[0059] After the evaluated entity risk meets the set risk threshold range, perform the extraction and determination of ontology terms, and determine the processing time for the extraction and determination of ontology terms;

[0060] When the processing time for the extraction and determination of ontology terms meets the preset processing time requirement, extract the ontology term keywords and enter step S2.

[0061] In the embodiments of the present invention, specifically, the risk type of the integration requirement is determined according to the integration path to be integrated and the types of data to be integrated; the amount of data to be integrated is determined according to the risk type of the integration requirement, specifically determined according to the number of iterations of the integration requirement or the accuracy of the result analysis of the integration requirement, ensuring the determination of the risk type of the integration requirement in the current system through the integration path to be integrated and the types of data to be integrated, screening the amount of data of the integration requirement according to the risk type, and then performing entity risk assessment according to the risk type, thereby ensuring the selection of the risk assessment scope of the integration requirement. According to the selected risk assessment scope, ontology term extraction processing and the determination of processing time are carried out, and ontology term keywords that meet the required processing time are selected.

[0062] Then, step S2 is to determine the ontology scope for the historical entity dataset according to the extracted and determined ontology term keywords, thereby ensuring the accurate machine recognition of the scope of the network security ontology and ensuring that the entity recognition can be effectively carried out using the deep learning model, and being able to effectively capture security entity recognition features from a large amount of text data; training and updating the ontology term keyword library through a deep learning model such as a recurrent neural network model can not only effectively capture the context information of the ontology term keywords, but also help the recurrent neural network model to more accurately process the efficiency of delimiting the scope of the security network ontology; solve the problem that the ontology scope of the network cannot be accurately delimited, and then solve the problem of determining the security boundary and type of security entities.

[0063] Specifically, in one embodiment, step S2 includes:

[0064] First, an ontology term keyword library is generated according to the historical entity dataset and the ontology term keywords, and the ontology term keyword library is used as a training sample and input into the recurrent neural network model for entity extraction; after data cleaning of the historical entity dataset, normalization processing is carried out, the ontology term keyword information of the entity dataset is matched, and according to the multi-dimensional library structure, the ontology term keywords are divided into attack categories and defense categories, and then the fusion processing of word vectors is carried out. The above are all conventional library construction processes; then the design of the RNN entity extraction model is carried out, and the training data in the ontology term keyword library information is obtained for training to realize the entity extraction process;

[0065] Then, the method based on network security language rules uses predefined language rules to identify the entity relationships corresponding to the ontology term keywords after entity extraction. Specifically, the labeled ontology term keywords and their corresponding entity relationships are used as training data and input into a recurrent neural network model through a supervised learning method. By automatically learning the relationships between entities, an ontology model is constructed and the entity relationship scope is output. And the probability of the entity relationship scope is determined by judging the entity relationship scope, and the entity relationship scope probability that meets the preset probability is recorded as the ontology scope. By determining the entity scope probability in step S2, the basic information of the ontology scope is optimized.

[0066] Next, in step S3, the target ontology term keywords in the network security entity platform are extracted based on the ontology scope, the hierarchical relationship of the target ontology term keywords is defined, and the ontology relationship evaluation is performed based on the hierarchical relationship of the target ontology term keywords, ensuring that the feedback on the optimization of the ontology scope is achieved through the evaluation of the ontology relationship. According to the hierarchical relationship between the divided target ontology term keywords, the processing efficiency of the knowledge graph for network security data is improved.

[0067] Specifically, in one embodiment, the specific process in step S3 is as follows:

[0068] After determining the ontology scope, extract the probability related to security terms in the ontology term keywords, and use those with a probability related to security terms in the ontology term keywords greater than the set security term related probability threshold as the target ontology term keywords;

[0069] Define the hierarchical relationship of the target ontology term keywords, divide the hierarchical relationship of the target ontology term keywords into low-level relationships and high-level relationships, and determine the ontology relationship evaluation based on the high-level relationships of different target ontology term keywords and the number of target ontology term keywords in the high-level relationships; ensure that the optimization process of the knowledge graph is achieved through the analysis of the ontology relationship evaluation.

[0070] Finally, step S4 completes the creation process of the knowledge graph of the security entity by outputting the ontology relationship evaluation result.

[0071] As an implementation manner of the present invention, the specific process of the entity risk assessment includes:

[0072] Obtain the amount of data to be integrated corresponding to the integration requirements of the preset network platform; and evaluate the decomposition risk of the integration requirements according to the amount of data to be integrated corresponding to the integration requirements, the number of iterations of the integration requirements, and the risk type of the integration requirements;

[0073] Obtain the amount of data to be integrated corresponding to the integration requirements of the preset network platform; and evaluate the aggregation risk of the integration requirements based on the intermediate quantity decomposed from the data quantity corresponding to the integration requirements and the number of iterations of the intermediate quantity corresponding to the integration requirements.

[0074] Evaluate the primary risk of the integration requirements based on the decomposition risk and the aggregation risk of the integration requirements, and determine whether the decomposition risk or the aggregation risk of the integration requirements is greater than the set risk threshold. If so, proceed to the next step; if not, use the primary risk of the integration requirements as the entity risk of the integration requirements.

[0075] Determine the correction amount of the decomposition risk by the ratio of the decomposition risk to the set risk threshold, determine the correction amount of the aggregation risk by the ratio of the aggregation risk to the set risk threshold, and determine the entity risk of the integration requirements based on the correction amount of the decomposition risk, the correction amount of the aggregation risk, and the primary risk.

[0076] In the above technical solution, specifically, by evaluating the entity risk of the data information of the preset network platform, first, send the integration requirements by the preset network platform and evaluate according to the amount of data to be integrated in the content of the integration requirements; evaluate the decomposition risk of the integration requirements by using the amount of data to be integrated, the number of iterations of the integration requirements, and the risk type of the integration requirements; after evaluating the decomposition risk, enter the intermediate quantity of the decomposition information corresponding to the amount of data to be integrated during the entity decomposition stage to the aggregation stage, that is, the quantity statistics after the data quantity corresponding to the integration requirements is decomposed; and evaluate the aggregation risk according to the number of iterations of this intermediate quantity; further, use the decomposition risk and the aggregation risk to further judge the size of the risk, determine the primary risk, and correct the situation that does not meet the requirements of the risk threshold setting, and determine the entity risk assessment result according to the change of the risk correction amount, that is, the decomposition risk correction amount and the aggregation risk correction amount, to ensure the determination of the risk range of the network security ontology.

[0077] As an implementation manner of the present invention, the ontology term extraction processing process includes:

[0078] Determine the average processing time when processing the integration requirements of the entity data set with different entity risks based on the preset network security domain knowledge model; and determine the estimated processing time of the integration requirements in combination with the risk of the current integration requirements processing and the number of integration requirements with different risks.

[0079] Obtain the number of integration requirements, and determine whether it is necessary to correct according to the estimated processing time of the integration requirements based on the number of integration requirements.

[0080] If not, divide the integration requirements to be integrated according to the risk into high-risk integration requirements and low-risk integration requirements, and determine whether it is necessary to correct the estimated processing time of the integration requirements to be integrated according to the quantity and risk ratio of the integration requirements to be integrated:

[0081] If not, determine the processing time for ontology term extraction processing using the estimated processing time of the current integration requirements to be integrated, and extract the ontology term keywords within the quantity range of the integration requirements to be integrated;

[0082] If so, determine the corrected time of the integration requirements to be integrated through the quantity of the integration requirements to be integrated, the quantity of high-risk integration requirements, and in combination with the entity risk assessment value, and determine the processing time for ontology term extraction processing according to the corrected time and the estimated processing time of the integration requirements to be integrated, and extract the ontology term keywords within the quantity range of the integration requirements to be integrated;

[0083] If so, determine the corrected time of the integration requirements to be integrated through the quantity of the integration requirements to be integrated, the quantity of high-risk integration requirements, and in combination with the entity risk assessment value, and determine the processing time for ontology term extraction processing according to the corrected time and the estimated processing time of the integration requirements to be integrated, and extract the ontology term keywords within the quantity range of the integration requirements to be integrated.

[0084] In the above technical solution, after determining the accuracy of the evaluation result when the evaluated entity risk conforms to the set risk threshold range, it is necessary to further determine the ontology term extraction processing, and realize the determination of the processing time of the ontology term extraction processing. In this embodiment, the setting of the ontology term extraction processing is used to ensure that the determination of the ontology term keywords within the risk range and the determination of the estimated processing time of the integration processing requirements and the correction process of the estimated processing time are ensured during the integration processing; determine the processing time for ontology term extraction processing according to the corrected time and the estimated processing time of the integration requirements to be integrated; ensure the adjustment of the processing time of the integration processing according to the real-time state to realize the rapid acquisition of ontology term keywords and reduce the information delay of the integration processing.

[0085] In the embodiment, please refer to Figure 2 as shown, a knowledge graph creation device based on network security entities is further provided, including:

[0086] An ontology extraction module, configured to define entity categories, entity characteristics, and individual relationships with each other, and extract and determine ontology term keywords from the collected historical entity data set;

[0087] An ontology determination module, configured to determine the ontology scope of the historical entity data set according to the ontology term keywords determined by extraction;

[0088] A relationship evaluation module, configured to extract target ontology term keywords in a cybersecurity entity platform based on an ontology scope, define a hierarchical relationship of the target ontology term keywords, and perform ontology relationship evaluation based on the hierarchical relationship of the target ontology term keywords;

[0089] A graph construction module, configured to output an ontology relationship evaluation result and construct a knowledge graph based on the ontology relationship.

[0090] In one embodiment, a storage medium is provided, on which computer instructions are stored, and when the computer instructions run, the steps of a method for creating a knowledge graph based on a cybersecurity entity are executed.

[0091] In one embodiment, an electronic device is provided, including a memory and a processor. Computer instructions capable of running on the processor are stored on the memory, and when the processor runs the computer instructions, the steps of a method for creating a knowledge graph based on a cybersecurity entity are executed.

[0092] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the embodiments of the device, equipment, and non-volatile computer storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments.

[0093] The above content is only an example and illustration of the concept of the present invention. Those skilled in the art in the technical field to which the present application pertains can make various modifications or supplements or use similar methods to replace the specific embodiments described, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present application, they should fall within the protection scope of the present invention.

Claims

1. A method for creating a knowledge graph based on network security entities, characterized in that: The method comprises: S1. Define entity categories, entity characteristics and individual relationships, and extract and determine the ontology term keywords from the collected historical entity data set; S2, determining the ontology scope of the historical entity data set based on the extracted and determined ontology term keywords; S3, extracting target ontology term keywords in the network security entity platform based on the ontology scope, defining the hierarchical relationship of the target ontology term keywords, and performing ontology relationship evaluation based on the hierarchical relationship of the target ontology term keywords; S4. Output the ontology relationship evaluation results and construct a knowledge graph based on the ontology relationship.

2. The method for creating a knowledge graph based on network security entities according to claim 1, characterized in that: The S1 includes: Obtain the requirements for historical data sets to be integrated, including the amount of data to be integrated, the path to be integrated, and the type of data to be integrated, and conduct an entity risk assessment based on the content of the requirements; When the assessed entity risk meets the set risk threshold range, ontology term extraction processing is performed, and the processing time of ontology term extraction processing is determined; When the processing time of the ontology term extraction process meets the preset processing time requirement, the ontology term keywords are extracted and the process proceeds to step S2.

3. The method for creating a knowledge graph based on network security entities according to claim 2, characterized in that: The specific process of evaluating the entity's riskiness includes: Obtaining the amount of data to be integrated corresponding to the requirements to be integrated of the preset network platform; and evaluating the decomposition risk of the requirements to be integrated according to the amount of data to be integrated corresponding to the requirements to be integrated, the number of iterations of the requirements to be integrated, and the risk type of the requirements to be integrated; Obtaining the amount of data to be integrated corresponding to the demand to be integrated of the preset network platform; and evaluating the aggregation risk of the demand to be integrated according to the intermediate amount of the decomposition of the amount of data corresponding to the demand to be integrated and the number of iterations of the intermediate amount corresponding to the demand to be integrated; According to the decomposed risk of the demand to be integrated and the aggregated risk of the demand to be integrated, the primary risk of the demand to be integrated is evaluated, and it is determined whether the decomposed risk of the demand to be integrated or the aggregated risk of the demand to be integrated is greater than the set risk threshold. If so, proceed to the next step; if not, the primary risk of the demand to be integrated is used as the entity risk of the demand to be integrated; The correction amount of the decomposed risk is determined by the ratio of the decomposed risk to the set risk threshold, the correction amount of the aggregated risk is determined by the ratio of the aggregated risk to the set risk threshold, and the entity risk of the demand to be integrated is determined based on the corrected decomposed risk correction amount, the corrected aggregated risk correction amount and the primary risk.

4. The method for creating a knowledge graph based on network security entities according to claim 2, characterized in that: Determine the risk type of the requirements to be integrated according to the paths to be integrated and the types of data to be integrated; The amount of data to be integrated is determined according to the risk type of the demand to be integrated, and specifically according to the number of iterations of the demand to be integrated or the accuracy of the result analysis of the demand to be integrated.

5. The method for creating a knowledge graph based on network security entities according to claim 3 is characterized in that: The ontology term extraction process includes: Determine the average processing time of the requirements to be integrated for entity data sets with different entity risks based on the preset network security domain knowledge model; and determine the estimated processing time of the requirements to be integrated based on the risk of processing the current requirements to be integrated and the number of requirements to be integrated with different risks; Obtain the number of the requirements to be integrated, and determine whether to modify the estimated processing time of the requirements to be integrated based on the number of the requirements to be integrated: If not, the requirements to be integrated are divided into high-risk integration requirements and low-risk integration requirements according to their risk, and whether the estimated processing time of the requirements to be integrated needs to be revised is determined according to the number and risk ratio of the requirements to be integrated: If not, the estimated processing time of the current requirements to be integrated is used as the processing time for the ontology term extraction process, and the ontology term keywords of the quantity range of the requirements to be integrated are extracted; If yes, the correction time of the requirements to be integrated is determined by the number of the requirements to be integrated, the number of high-risk integration requirements, and the entity risk assessment value, and the processing time of the ontology term extraction is determined according to the correction time and the estimated processing time of the requirements to be integrated, and the ontology term keywords within the number range of the requirements to be integrated are extracted; If so, the correction time of the requirements to be integrated is determined by the number of the requirements to be integrated, the number of high-risk integration requirements, and the entity risk assessment value, and the processing time of the ontology term extraction is determined based on the correction time and the estimated processing time of the requirements to be integrated, and the ontology term keywords within the number range of the requirements to be integrated are extracted.

6. The method for creating a knowledge graph based on network security entities according to claim 1, characterized in that: The S2 includes: Generate an ontology term keyword thesaurus based on the historical entity data set and the ontology term keywords, and input the ontology term keyword thesaurus as training samples into a recurrent neural network model for entity extraction; The method based on network security language rules uses predefined language rules to identify the entity relationships corresponding to the ontology term keywords after entity extraction. Specifically, the labeled ontology term keywords and their corresponding entity relationships are input into the recurrent neural network model as training data through a supervised learning method to learn the relationship between entities, build an ontology model, and output the entity relationship range. The entity relationship range is judged to determine the entity relationship range probability, and the entity relationship range probability that meets the preset probability is recorded as the entity range.

7. The method for creating a knowledge graph based on network security entities according to claim 1, characterized in that: The process of extracting target ontology term keywords in the network security entity platform based on the ontology scope, defining the hierarchical relationship of the target ontology term keywords, and evaluating the ontology relationship based on the hierarchical relationship of the target ontology term keywords in S3 is as follows: After determining the ontology scope, extract the security term related probabilities in the ontology term keywords, and use the security term related probabilities in the ontology term keywords that are greater than the set security term related probability threshold as the target ontology term keywords; The hierarchical relationship of target ontology term keywords is defined, and the hierarchical relationship of target ontology term keywords is divided into low-level relationship and high-level relationship. The ontology relationship is evaluated and determined based on the high-level relationship of different target ontology term keywords and the number of target ontology term keywords of the high-level relationship.

8. A knowledge graph creation device based on network security entities, characterized in that: include: The ontology extraction module is used to define entity categories, entity characteristics and individual relationships, and to extract and determine the keywords of ontology terms from the collected historical entity data sets; An ontology determination module, used for determining the ontology scope of the historical entity data set according to the extracted and determined ontology term keywords; A relationship evaluation module, used for extracting target ontology term keywords in the network security entity platform based on the ontology scope, defining the hierarchical relationship of the target ontology term keywords, and performing ontology relationship evaluation based on the hierarchical relationship of the target ontology term keywords; The graph construction module is used to output the ontology relationship evaluation results and construct a knowledge graph based on the ontology relationship.

9. A storage medium having computer instructions stored thereon, characterized in that: When the computer instructions are executed, the steps of the method according to any one of claims 1 to 7 are executed.

10. An electronic device, comprising a memory and a processor, wherein the memory stores computer instructions that can be executed on the processor, characterized in that: When the processor executes the computer instructions, the steps of the method according to any one of claims 1 to 7 are performed.

Citation Information

Patent Citations

  • A method and apparatus for creating knowledge graphs

    CN107665252B