Network security monitoring and early warning method and system based on multi-source data
By acquiring and analyzing multi-source heterogeneous data, multi-angle monitoring and collaborative emergency response of network security events are solved, and the problem of insufficient monitoring of single data source in traditional methods is improved, and the accuracy and timeliness of network security monitoring are improved.
Patent Information
- Application Number
- CN202510686268.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-05-27
AI Technical Summary
Traditional network security monitoring and early warning methods usually rely on a single type of data, and cannot fully and effectively monitor and control network security, resulting in a reduced monitoring effect.
Multi-source data is used to obtain multiple heterogeneous data in the network, and by pre-processing and analyzing these data, network security events are monitored from multiple angles, and early warning and coordinated emergency responses are carried out when events are detected.
It improves the accuracy and timeliness of network security incident judgments, enhances the effectiveness of network security monitoring and control, and ensures the timely handling and safe response of network security incidents.
Smart Images

Figure CN120200860A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly relates to a network security monitoring and early warning method and system based on multi-source data. Background Art
[0002] With the rapid development of information technology, the network environment has become increasingly complex, and network security faces unprecedented challenges. Therefore, network security monitoring is particularly important; However, traditional network security monitoring and early warning methods often target single-type data, such as network traffic data or system log data. This monitoring method based on a single data source has limitations. For example, malicious operations by internal personnel may not be accurately detected only based on network traffic data, and attacks at the network layer may be ignored only relying on system log data, making it impossible to comprehensively and effectively monitor and control the network, thus greatly reducing the effect of network security monitoring and early warning; Therefore, in order to overcome the above defects, the present invention provides a network security monitoring and early warning method and system based on multi-source data. Summary of the Invention
[0003] The present invention provides a network security monitoring and early warning method and system based on multi-source data, which obtains multi-source heterogeneous data in the network by various means, ensuring the comprehensiveness and reliability of the obtained multi-source heterogeneous data. Secondly, the multi-source heterogeneous data is preprocessed, and network security events are analyzed and judged according to the preprocessing results, ensuring security event monitoring from multiple perspectives and improving the accuracy of network security event determination. Finally, when there are network security events, early warning notification and collaborative emergency response are carried out, ensuring the timeliness and security of network security event handling and improving the effect of network security monitoring and control.
[0004] The present invention provides a network security monitoring and early warning method based on multi-source data, including: Step 1: Obtain multi-source heterogeneous data in the network based on a multi-channel method and preprocess the multi-source heterogeneous data; Step 2: Conduct independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively to determine network security events existing in the network; Step 3: Issue early warning notifications for network security events and conduct collaborative emergency response to network resources in the network based on the early warning notifications.
[0005] Preferably, in a network security monitoring and early warning method based on multi-source data, in Step 1, obtaining multi-source heterogeneous data in the network based on a multi-channel method includes: Determine the monitoring objects in the network based on security monitoring requirements, and determine the network attributes of each monitoring object in the network; Determine the personalized multi-channel mode of each monitoring object based on the network attributes, and configure the data collection frequency for each personalized multi-channel mode respectively; Open the parallel communication permissions for the personalized multi-channel mode of each monitoring object, and perform real-time data collection on each monitoring object in the network based on the opening result to obtain multi-source heterogeneous data in the network.
[0006] Preferably, for a network security monitoring and early warning method based on multi-source data, in step 1, preprocess the multi-source heterogeneous data, including: Obtain the obtained multi-source heterogeneous data, and perform distributed data filling based on the basic information of the multi-source heterogeneous data; Based on the distributed data filling, perform data review on the multi-source heterogeneous data according to the review indicators, perform classification statistics on the multi-source heterogeneous data after the review is passed, and generate a data statistics list for each monitoring object based on the classification statistics result; Based on the data statistics list, store the obtained multi-source heterogeneous data, and generate a retrieval condition for the multi-source heterogeneous data based on the storage address after the storage is successful; Feedback and save the retrieval condition.
[0007] Preferably, for a network security monitoring and early warning method based on multi-source data, perform classification statistics on the multi-source heterogeneous data after the review is passed, including: Extract the data sources of the multi-source heterogeneous data, and perform the first classification on the multi-source heterogeneous data based on the data sources to obtain a data set under each data source; Perform statistics on the first data volume and data category composition of the data set under each data source, and generate a global statistic for each data source based on the statistical result; At the same time, perform the second classification on the data set under each data source based on the data category, and perform statistics on the second data volume for each category of data based on the second classification result; Based on the global statistic and the statistics of the second data volume, obtain the data asset overview of the multi-source heterogeneous data, and complete the classification statistics of the multi-source heterogeneous data based on the data asset overview.
[0008] Preferably, for a network security monitoring and early warning method based on multi-source data, in step 2, perform independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively to determine the network security events existing in the network, including: Conditionally access and retrieve the original log library based on data sources of multi-source heterogeneous data, retrieve historical alarm data under each data source in the multi-source heterogeneous data, and parse the historical alarm data to obtain an alarm overview under each data source; Determine the alarm dimensions and alarm behavior events under each alarm dimension based on the alarm overview, and parse the alarm behavior events to obtain alarm event characteristics under each alarm dimension; Determine the network security measurement quantization indicators for each data source based on the alarm event characteristics, and construct a security detection model corresponding to each data source based on the network security measurement quantization indicators; Meanwhile, determine the association relationship between multi-source heterogeneous data based on the network operation protocol, cascade the security detection models corresponding to different data sources based on the association relationship, and adapt the parameters of the security detection model based on the cascade result to obtain a hybrid security detection model; Detect the multi-source heterogeneous data based on the security detection model and the hybrid security detection model respectively, and determine the independent security situation and the comprehensive security situation based on the detection results; Determine the abnormal indicators existing in the network based on the independent security situation and the comprehensive security situation, and determine the pointing information of the abnormal indicators; Determine the pointing objects of different abnormal indicators based on the pointing information, and when the number of abnormal indicators corresponding to the pointing object exceeds the preset range and the abnormal characterization of the pointing object is not within the range of conventional security failures, lock the pointing object and determine that there is a network security event.
[0009] Preferably, a network security monitoring and early warning method based on multi-source data, determining that there is a network security event, includes: Read the network security event based on the determination result, and determine the attack characteristics and attack scope of the network security event; Trace the attack source based on the attack characteristics to obtain the attack source. Meanwhile, determine the attack purpose of the network security event based on the attack scope; Conduct a level assessment on the attack purpose and attack scope based on preset event evaluation indicators to determine the severity level of the current network security event; Record the attack source, attack purpose and severity level.
[0010] Preferably, in step 3 of a network security monitoring and early warning method based on multi-source data, giving an early warning notice for the network security event, includes: Obtain the event type of the network security event. Meanwhile, retrieve the event monitoring node management center; Input the event type into the event monitoring node management center for matching to determine the target monitoring node associated with the event type; Meanwhile, retrieve the core key data of network security events based on the event type; Extract the network security data set corresponding to the network security event, locate it in the network security data set according to the core key data, and determine several associated data segments of the core key data according to the positioning result; Obtain the influence weight of each associated data segment and the core key data, and obtain the preset weight threshold; Compare the influence weight of each associated data segment and the core key data with the preset weight threshold respectively; Take the associated data segment with an influence weight greater than the preset weight threshold as the first associated data segment; Take the associated data segment with an influence weight less than or equal to the preset weight threshold as the second associated data segment; Perform first data encapsulation on the first associated data segment and the core key data to obtain the first early warning data packet. Meanwhile, perform second data encapsulation on the second associated data segment to obtain the second early warning data packet; Send the first early warning data packet to the target monitoring node for the first early warning notification. When the target monitoring node generates a response signal, the early warning notification is completed; When the target monitoring node does not generate a response signal, send the second early warning data packet to the target monitoring node, and when the sending is successful, the early warning notification is completed.
[0011] Preferably, in a network security monitoring and early warning method based on multi-source data, in step 3, perform collaborative emergency disposal on network resources in the network based on the early warning notification, including: Determine the emergency resource requirements for the network security event according to the early warning notification information, determine the network resources in the network according to the emergency resource requirements, and determine the disposal process according to the network resources; Perform collaborative emergency disposal on the network security event according to the disposal process, and feedback the disposal result to the management terminal. Meanwhile, retrieve the disposal standard based on the management terminal; Match and verify the disposal result with the disposal standard; When the disposal result matches the disposal standard, the verification result is that the collaborative emergency disposal of the network security event is successful; When the disposal result does not match the disposal standard, the verification result is that the collaborative emergency disposal of the network security event fails, and re-perform the collaborative emergency disposal until the verification result is that the collaborative emergency disposal of the network security event is successful.
[0012] The present invention provides a network security monitoring and early warning system based on multi-source data, including: A data acquisition module, which is used to obtain multi-source heterogeneous data in the network based on a multi-channel method and preprocess the multi-source heterogeneous data; A security event analysis module, which is used to perform independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively, and determine the network security events existing in the network; An early warning and emergency response module, which is used to issue early warnings about network security events and conduct coordinated emergency disposal of network resources in the network based on the early warning notifications.
[0013] Preferably, a network security monitoring and early warning system based on multi-source data, the data acquisition module includes: A monitoring preparation unit, which is used to determine the monitoring objects in the network based on the security monitoring requirements and determine the network attributes of each monitoring object in the network; A parameter configuration unit, which is used to determine the personalized multi-channel modes of each monitoring object based on the network attributes and configure the data acquisition frequencies for the personalized multi-channel modes respectively; A data acquisition unit, which is used to open the parallel communication permissions for the personalized multi-channel modes of each monitoring object and perform real-time data acquisition on each monitoring object in the network based on the opening results to obtain multi-source heterogeneous data in the network.
[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: By adopting various methods to obtain multi-source heterogeneous data in the network, the comprehensiveness and reliability of the obtained multi-source heterogeneous data are ensured. Secondly, the multi-source heterogeneous data is preprocessed, and network security events are analyzed and judged according to the preprocessing results, ensuring security event monitoring from multiple angles and improving the accuracy of network security event determination. Finally, when there are network security events, early warnings are issued and coordinated emergency disposal is carried out, ensuring the timeliness and security of network security event handling and improving the effect of network security monitoring and control.
[0015] Other features and advantages of the present invention will be described in the subsequent specification, and, in part, will become obvious from the specification or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in this application document.
[0016] The technical solutions of the present invention will be further described in detail below through the accompanying drawings and embodiments. Description of the Drawings
[0017] The accompanying drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation to the present invention. In the accompanying drawings: Figure 1 It is a flowchart of a network security monitoring and early warning method based on multi-source data in an embodiment of the present invention; Figure 2 This is the flowchart of step 1 in a network security monitoring and early warning method based on multi-source data in an embodiment of the present invention; Figure 3 This is the structural diagram of a network security monitoring and early warning system based on multi-source data in an embodiment of the present invention. Specific embodiments
[0018] The following describes the preferred embodiments of the present invention with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present invention, and are not used to limit the present invention.
[0019] This embodiment provides a network security monitoring and early warning method based on multi-source data, as Figure 1 shown, including: Step 1: Obtain multi-source heterogeneous data in the network based on a multi-channel method, and preprocess the multi-source heterogeneous data; Step 2: Perform independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively to determine the network security events existing in the network; Step 3: Issue early warning notifications for network security events, and perform collaborative emergency response on network resources in the network based on the early warning notifications.
[0020] In this embodiment, the multi-channel method refers to obtaining multi-source heterogeneous data in the network through a variety of different methods, including active detection, traffic analysis, manual reporting, data import, etc.
[0021] In this embodiment, the multi-source heterogeneous data refers to the working data obtained from different sources, systems or devices. For example, it can be abnormal behavior data, traffic data, network device operation data, and code data, etc.
[0022] In this embodiment, the preprocessing refers to operations such as cleaning and auditing of multi-source heterogeneous data.
[0023] In this embodiment, the independent security situation analysis refers to separately analyzing the network data under each data source to determine whether there are network security events under each data source.
[0024] In this embodiment, the comprehensive security situation analysis refers to performing correlation analysis on multi-source heterogeneous data to determine whether there are network security events in the network.
[0025] In this embodiment, the network security events refer to network vulnerabilities or Trojan attacks, etc.
[0026] In this embodiment, the collaborative emergency response refers to scheduling or arranging the available resources in the network for responding to network security events.
[0027] The beneficial effects of the above technical solution are as follows: By obtaining multi-source heterogeneous data in the network through various methods, the comprehensiveness and reliability of the obtained multi-source heterogeneous data are ensured. Secondly, the multi-source heterogeneous data is preprocessed, and based on the preprocessing results, the analysis and judgment of network security events are carried out, ensuring the monitoring of security events from multiple perspectives and improving the accuracy of the determination of network security events. Finally, in the presence of network security events, early warning and collaborative emergency response are carried out, ensuring the timeliness and security of the handling of network security events and improving the effect of network security monitoring and control.
[0028] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. As Figure 2 shown, in step 1, multi-source heterogeneous data in the network is obtained based on a multi-channel method, including: Step 101: Determine the monitoring objects in the network based on the security monitoring requirements, and determine the network attributes of each monitoring object in the network; Step 102: Determine the personalized multi-channel method for each monitoring object based on the network attributes, and configure the data collection frequency for each personalized multi-channel method respectively; Step 103: Open the parallel communication permissions for the personalized multi-channel method of each monitoring object, and perform real-time data collection on each monitoring object in the network based on the opening result to obtain multi-source heterogeneous data in the network.
[0029] In this embodiment, the security monitoring requirements are known in advance, including the objects to be monitored and the monitoring criteria, etc.
[0030] In this embodiment, the network attributes refer to the types corresponding to different monitoring objects, such as network operation devices and user access behaviors, etc.
[0031] In this embodiment, the personalized multi-channel method refers to the method for collecting network resource data of each monitoring object, which can be a combination of multiple methods such as active detection, traffic analysis, manual reporting, and data import.
[0032] In this embodiment, the opening of parallel communication permissions refers to authorizing the communication permissions of the personalized multi-channel method to facilitate the execution of the corresponding data collection tasks.
[0033] The beneficial effects of the above technical solution are as follows: It ensures the comprehensiveness and reliability of the acquisition of multi-source heterogeneous data in the network, providing reliable data support for network security monitoring.
[0034] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. In step 1, the multi-source heterogeneous data is preprocessed, including: Obtain the multi-source heterogeneous data, and perform distributed data reporting based on the basic information of the multi-source heterogeneous data; Based on the distributed data reporting, perform data review on the multi-source heterogeneous data according to the review indicators, and after the review is passed, classify and count the multi-source heterogeneous data, and generate a data statistics list for each monitoring object based on the classification and counting results; Based on the data statistics list, store the obtained multi-source heterogeneous data, and after the storage is successful, generate a retrieval condition for the multi-source heterogeneous data based on the storage address; Feedback and save the retrieval condition.
[0035] In this embodiment, the basic information refers to information such as the business type of the multi-source heterogeneous data, the corresponding characterization object, and the corresponding value range.
[0036] In this embodiment, the review indicators are known in advance, including the limited range of data values, etc.
[0037] In this embodiment, the classification and counting refer to classifying and integrating the multi-source heterogeneous data according to the data category, so as to facilitate the corresponding network security monitoring and early warning.
[0038] In this embodiment, the retrieval condition refers to the reference basis for retrieving the stored multi-source heterogeneous data, that is, according to the requirements, the corresponding data is retrieved from the database using the retrieval condition.
[0039] The beneficial effects of the above technical solution are: ensuring the reliability of the preprocessing of the obtained multi-source heterogeneous data, and also ensuring the accuracy and reliability of the finally obtained multi-source heterogeneous data. At the same time, storing the multi-source heterogeneous data and generating the corresponding retrieval conditions provide convenience and guarantee for retrieving the corresponding multi-source heterogeneous data subsequently.
[0040] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. After the review is passed, classify and count the multi-source heterogeneous data, including: Extract the data sources of the multi-source heterogeneous data, and perform the first classification on the multi-source heterogeneous data based on the data sources to obtain a data set under each data source; Perform statistics on the first data volume and data category composition of the data set under each data source, and generate a global statistics for each data source based on the statistical results; At the same time, perform the second classification on the data set under each data source based on the data category, and perform statistics on the second data volume of each category of data based on the second classification results; Based on the global statistics and the statistics of the second data volume, obtain an overview of the data assets of the multi-source heterogeneous data, and complete the classification and counting of the multi-source heterogeneous data based on the overview of the data assets.
[0041] In this embodiment, the first classification refers to classifying the multi-source heterogeneous data obtained according to the data sources. For example, it can be distinguishing user behavior data and network device operation data, which is the first classification.
[0042] In this embodiment, the first data volume refers to counting the amount of data contained in each data set after the first classification.
[0043] In this embodiment, the global statistics refer to the number of data and the composition of data types contained under each data source.
[0044] In this embodiment, the second classification refers to classifying the data sets under each data source. For example, if the data set is user behavior data, the second classification is to classify user access behavior data and user operation behavior data.
[0045] In this embodiment, the second data volume refers to the number of data corresponding to each data category in the data sets under each data source.
[0046] In this embodiment, the overview of data assets refers to the overall composition of multi-source heterogeneous data obtained based on global statistics and second data volume statistics.
[0047] The beneficial effects of the above technical solutions are: ensuring the accuracy of classifying and counting multi-source heterogeneous data, thus facilitating comprehensive and effective monitoring of network security according to the classification and counting results.
[0048] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. In step 2, independent security situation analysis and comprehensive security situation analysis are respectively performed on the preprocessed multi-source heterogeneous data to determine network security events existing in the network, including: Based on the data sources of multi-source heterogeneous data, perform conditional access and retrieval on the original log library, retrieve the historical alarm data under each data source in the multi-source heterogeneous data, and parse the historical alarm data to obtain the alarm overview under each data source; Based on the alarm overview, determine the alarm dimensions under each data source and the alarm behavior events under the alarm dimensions, and parse the alarm behavior events to obtain the alarm event characteristics under each alarm dimension; Based on the alarm event characteristics, determine the network security monitoring quantification indicators under each data source, and construct a security detection model corresponding to each data source based on the network security monitoring quantification indicators; At the same time, based on the network operation protocol, determine the association relationship between multi-source heterogeneous data, cascade the security detection models corresponding to different data sources based on the association relationship, and adapt the parameters of the security detection model based on the cascade result to obtain a hybrid security detection model; Detect multi-source heterogeneous data based on a security detection model and a hybrid security detection model respectively, and determine an independent security situation and a comprehensive security situation based on the detection results; Determine the abnormal indicators existing in the network based on the independent security situation and the comprehensive security situation, and determine the pointing information of the abnormal indicators; Determine the pointing objects of different abnormal indicators based on the pointing information, and when the number of abnormal indicators corresponding to the pointing object exceeds a preset range and the abnormal characterization of the pointing object is not within the scope of conventional security faults, lock the pointing object and determine that a network security event exists.
[0049] In this embodiment, the original log library is known in advance and is used to record historical alarm data under different data sources.
[0050] In this embodiment, conditional access and retrieval are to retrieve historical alarm data of the corresponding data type from the original log library according to the types of current multi-source heterogeneous data.
[0051] In this embodiment, the alarm overview refers to the historical alarm situation under each data source, including the alarm type (i.e., the alarm dimension) and the reason for generating the alarm, etc.
[0052] In this embodiment, the alarm behavior event refers to the specific behavior of generating an alarm.
[0053] In this embodiment, the alarm event feature refers to the data state when an alarm is generated, including the value of the data and the composition of the data, etc.
[0054] In this embodiment, the network security monitoring quantization index refers to the monitoring standard for network security monitoring and early warning of each data source. For example, the specific limit range for network traffic, and being outside this range is considered abnormal.
[0055] In this embodiment, the network operation protocol is known in advance and is used to characterize the association relationship between data sources during network operation, etc.
[0056] In this embodiment, cascading refers to performing association and integration operations on the security detection models under each data source according to the determined association relationship.
[0057] In this embodiment, parameter adaptation refers to coordinating and adapting the working parameters between the cascaded security detection models to ensure compatibility between the security detection models.
[0058] In this embodiment, the hybrid security detection model refers to the result obtained by cascading the security detection models under each data source.
[0059] In this embodiment, the abnormal indicator refers to the abnormal situation existing in the network.
[0060] In this embodiment, the pointing information refers to the specific object corresponding to the abnormal index, which can be, for example, a network operation device or network traffic, etc.
[0061] In this embodiment, the pointed object refers to the specific network object corresponding to the abnormal index, which can be, for example, a certain network device, etc.
[0062] The beneficial effects of the above technical solution are as follows: By constructing a security detection model and a hybrid security detection model under each data source, and detecting multi-source heterogeneous data through the security detection model and the hybrid security detection model respectively, an effective determination of the independent security situation and the comprehensive security situation is realized. Furthermore, the abnormal indexes existing in the network are locked, and finally, the abnormal object is determined according to the abnormal index, so as to realize an accurate and effective determination of the network security events existing in the network, and also provide convenience and guarantee for timely security response.
[0063] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. When it is determined that there is a network security event, it includes: Reading the network security event based on the determination result, and determining the attack characteristics and attack scope of the network security event; Tracing the attack source based on the attack characteristics to obtain the attack source. At the same time, determining the attack purpose of the network security event based on the attack scope; Evaluating the levels of the attack purpose and attack scope based on the preset event evaluation index to determine the severity level of the current network security event; Recording the attack source, attack purpose and severity level.
[0064] In this embodiment, the attack characteristics refer to the attack method corresponding to the network security event and the specific data nodes attacked, etc.
[0065] In this embodiment, the preset event evaluation index is set in advance and is used to evaluate the severity of the current network security event according to the attack purpose and attack scope. Different attack scopes and attack purposes correspond to different severity levels.
[0066] The beneficial effects of the above technical solution are as follows: The attack source and attack purpose are determined, and then the severity level of the network security event is determined according to the attack source and attack purpose, providing a reference basis for taking corresponding security emergency measures.
[0067] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. In step 3, warning and notification of the network security event includes: Obtaining the event type of the network security event, and at the same time, retrieving the event monitoring node management center; Input the event type into the event monitoring node management center for matching to determine the target monitoring node associated with the event type; Meanwhile, retrieve the core key data of the network security event based on the event type; Extract the network security data set corresponding to the network security event, locate it in the network security data set according to the core key data, and determine several associated data segments of the core key data according to the positioning result; Obtain the influence weight of each associated data segment and the core key data, and obtain the preset weight threshold; Compare the influence weight of each associated data segment and the core key data with the preset weight threshold respectively; Take the associated data segment with an influence weight greater than the preset weight threshold as the first associated data segment; Take the associated data segment with an influence weight less than or equal to the preset weight threshold as the second associated data segment; Perform first data encapsulation on the first associated data segment and the core key data to obtain the first early warning data packet. Meanwhile, perform second data encapsulation on the second associated data segment to obtain the second early warning data packet; Send the first early warning data packet to the target monitoring node for the first early warning notification, and when the target monitoring node generates a response signal, the early warning notification is completed; When the target monitoring node does not generate a response signal, send the second early warning data packet to the target monitoring node, and when the sending is successful, the early warning notification is completed.
[0068] In this embodiment, the event monitoring node management center is set in advance and is used to respond to and manage existing network security events.
[0069] In this embodiment, the target monitoring node refers to the monitoring node corresponding to the event type of the current network security event.
[0070] In this embodiment, the core key data refers to the data information that can characterize the type of network security event and the attack behavior.
[0071] In this embodiment, several associated data segments refer to the data segments that match between the core key data and the network security data set.
[0072] In this embodiment, the influence weight is used to characterize the importance degree of the associated data segment and the core key data in the whole data.
[0073] In this embodiment, the preset weight threshold is set in advance.
[0074] In this embodiment, the first early warning data packet refers to the one obtained by performing first data encapsulation on the first associated data segment and the core key data.
[0075] In this embodiment, the second warning data packet refers to the one obtained by performing second data encapsulation on the second associated data segment.
[0076] The beneficial effects of the above technical solution are as follows: It ensures the accuracy and timeliness of warning notifications for network security incidents, thereby facilitating timely response to network security incidents and ensuring the reliability of network operation.
[0077] In one embodiment, a network security monitoring and warning method based on multi-source data is provided. In step 3, collaborative emergency handling of network resources in the network is performed based on the warning notification, including: Determine the emergency resource requirements for the network security incident according to the warning notification information, determine the network resources in the network according to the emergency resource requirements, and at the same time, determine the handling process according to the network resources; Perform collaborative emergency handling of the network security incident according to the handling process, and feedback the handling result to the management terminal. At the same time, retrieve the handling standard based on the management terminal; Match and verify the handling result with the handling standard; When the handling result matches the handling standard, the verification result is that the collaborative emergency handling of the network security incident is successful; When the handling result does not match the handling standard, the verification result is that the collaborative emergency handling of the network security incident fails, and re-perform collaborative emergency handling until the verification result is that the collaborative emergency handling of the network security incident is successful.
[0078] In this embodiment, the emergency resource requirements refer to the emergency resources required to solve the network security incident.
[0079] In this embodiment, the network resources refer to the currently available resources in the network.
[0080] In this embodiment, the handling process refers to the strategy or plan for scheduling and coordinating network resources.
[0081] In this embodiment, the handling standard refers to the requirements for collaborative scheduling of network resources.
[0082] The beneficial effects of the above technical solution are as follows: It ensures timely and effective collaborative emergency handling of network resources in the network in the presence of network security incidents, ultimately ensuring timely and reliable emergency response to network security, improving the security factor of network operation, and also improving the effect of network security monitoring and warning.
[0083] This embodiment provides a network security monitoring and warning system based on multi-source data, as Figure 3 shown, including: A data acquisition module, which is used to acquire multi-source heterogeneous data in the network based on a multi-channel manner and preprocess the multi-source heterogeneous data; A security event analysis module, which is used to perform independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively to determine the network security events existing in the network; A warning and emergency response module, which is used to issue warning notifications for network security events and perform collaborative emergency handling on network resources in the network based on the warning notifications.
[0084] The beneficial effects of the above technical solution are as follows: By adopting various methods to acquire multi-source heterogeneous data in the network, the comprehensiveness and reliability of the obtained multi-source heterogeneous data are ensured. Secondly, the multi-source heterogeneous data is preprocessed, and the network security events are analyzed and judged according to the preprocessing results, ensuring the monitoring of security events from multiple perspectives and improving the accuracy of the determination of network security events. Finally, when there are network security events, warning notifications are issued and collaborative emergency handling is carried out, ensuring the timeliness and security of the handling of network security events and improving the effect of network security monitoring and control.
[0085] In one embodiment, a network security monitoring and warning system based on multi-source data is provided. The data acquisition module includes: A monitoring preparation unit, which is used to determine the monitoring objects in the network based on the security monitoring requirements and determine the network attributes of each monitoring object in the network; A parameter configuration unit, which is used to determine the personalized multi-channel manner of each monitoring object based on the network attributes and configure the data acquisition frequency for each personalized multi-channel manner respectively; A data acquisition unit, which is used to open the parallel communication permissions for the personalized multi-channel manner of each monitoring object and perform real-time data acquisition on each monitoring object in the network based on the opening results to obtain multi-source heterogeneous data in the network.
[0086] The beneficial effects of the above technical solution are as follows: The comprehensiveness and reliability of the acquisition of multi-source heterogeneous data in the network are ensured, providing reliable data support for network security monitoring.
[0087] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications.
Claims
1. A network security monitoring and early warning method based on multi-source data, characterized in that, Including: Step 1: Obtain multi-source heterogeneous data in the network based on a multi-channel approach and preprocess the multi-source heterogeneous data; Step 2: Conduct independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively to determine the network security events existing in the network; Step 3: Issue early warnings about the network security events and conduct collaborative emergency response handling on the network resources in the network based on the early warnings.
2. The network security monitoring and early warning method based on multi-source data according to claim 1, wherein, In Step 1, obtaining multi-source heterogeneous data in the network based on a multi-channel approach includes: Determine the monitoring objects in the network based on security monitoring requirements and determine the network attributes of each monitoring object in the network; Determine the personalized multi-channel approach for each monitoring object based on the network attributes and configure the data collection frequency for each personalized multi-channel approach respectively; Open the parallel communication permissions for the personalized multi-channel approach of each monitoring object and conduct real-time data collection on each monitoring object in the network based on the opening results to obtain the multi-source heterogeneous data in the network.
3. A network security monitoring and early warning method based on multi-source data according to claim 1, characterized in that, In Step 1, preprocessing the multi-source heterogeneous data includes: Obtain the obtained multi-source heterogeneous data and conduct distributed data filling based on the basic information of the multi-source heterogeneous data; Conduct data review on the multi-source heterogeneous data according to the review indicators based on the distributed data filling, conduct classification statistics on the multi-source heterogeneous data after the review is passed, and generate a data statistics list for each monitoring object based on the classification statistics results; Store the obtained multi-source heterogeneous data based on the data statistics list, and generate a retrieval condition for the multi-source heterogeneous data based on the storage address after the storage is successful; Feed back and save the retrieval condition.
4. A network security monitoring and early warning method based on multi-source data according to claim 3, characterized in that, Conducting classification statistics on the multi-source heterogeneous data after the review is passed includes: Extract the data sources of the multi-source heterogeneous data and conduct the first classification on the multi-source heterogeneous data based on the data sources to obtain the data sets under each data source; Conduct statistics on the first data volume and data category composition of the data sets under each data source and generate the global statistics for each data source based on the statistics results; Meanwhile, conduct the second classification on the data sets under each data source based on the data categories, and conduct statistics on the second data volume of each category of data based on the second classification results; Obtain the data asset overview of the multi-source heterogeneous data based on the global statistics and the statistics of the second data volume, and complete the classification statistics of the multi-source heterogeneous data based on the data asset overview.
5. A network security monitoring and early warning method based on multi-source data according to claim 1, characterized in that In Step 2, conducting independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively to determine the network security events existing in the network includes: Conduct conditional access and retrieval on the original log library based on the data sources of the multi-source heterogeneous data, retrieve the historical alarm data under each data source in the multi-source heterogeneous data, and parse the historical alarm data to obtain the alarm overview under each data source; Determine the alarm dimensions under each data source and the alarm behavior events under the alarm dimensions based on the alarm overview, and parse the alarm behavior events to obtain the alarm event characteristics under each alarm dimension; Determine the network security measurement quantization indicators for each data source based on the alarm event characteristics, and construct a security detection model corresponding to each data source based on the network security measurement quantization indicators; Meanwhile, determine the association relationship between multi-source heterogeneous data based on the network operation protocol, cascade the security detection models corresponding to different data sources based on the association relationship, and adapt the parameters of the security detection models based on the cascading result to obtain a hybrid security detection model; Detect the multi-source heterogeneous data based on the security detection model and the hybrid security detection model respectively, and determine the independent security situation and the comprehensive security situation based on the detection results; Determine the abnormal indicators existing in the network based on the independent security situation and the comprehensive security situation, and determine the pointing information of the abnormal indicators; Determine the pointing objects of different abnormal indicators based on the pointing information, and when the number of abnormal indicators corresponding to the pointing object exceeds the preset range and the abnormal characterization of the pointing object is not within the range of conventional security failures, lock the pointing object and determine that a network security event exists.
6. A network security monitoring and early warning method based on multi-source data according to claim 5, characterized in that, Determining that a network security event exists includes: Read the network security event based on the determination result, and determine the attack characteristics and attack scope of the network security event; Trace the attack source based on the attack characteristics to obtain the attack source. Meanwhile, determine the attack purpose of the network security event based on the attack scope; Conduct a level assessment of the attack purpose and attack scope based on the preset event evaluation indicators to determine the severity level of the current network security event; Record the attack source, attack purpose, and severity level.
7. A network security monitoring and early warning method based on multi-source data according to claim 1, characterized in that, In step 3, issue a warning notice for the network security event, including: Obtain the event type of the network security event. Meanwhile, retrieve the event monitoring node management center; Input the event type into the event monitoring node management center for matching to determine the target monitoring node associated with the event type; Meanwhile, retrieve the core key data of the network security event based on the event type; Extract the network security data set corresponding to the network security event, locate it in the network security data set according to the core key data, and determine several associated data segments of the core key data according to the positioning result; Obtain the influence weight of each associated data segment on the core key data, and obtain the preset weight threshold; Compare the influence weight of each associated data segment on the core key data with the preset weight threshold respectively; Regard the associated data segment with an influence weight greater than the preset weight threshold as the first associated data segment; Regard the associated data segment with an influence weight less than or equal to the preset weight threshold as the second associated data segment; Perform first data encapsulation on the first associated data segment and the core key data to obtain the first warning data packet. Meanwhile, perform second data encapsulation on the second associated data segment to obtain the second warning data packet; Send the first warning data packet to the target monitoring node for the first warning notice, and when the target monitoring node generates a response signal, the warning notice is completed; When the target monitoring node does not generate a response signal, send the second warning data packet to the target monitoring node, and when the sending is successful, the warning notice is completed.
8. A network security monitoring and early warning method based on multi-source data according to claim 1, characterized in that, In step 3, perform collaborative emergency disposal on the network resources in the network based on the warning notice, including: Determine the emergency resource requirements for the network security event according to the warning notice information, determine the network resources in the network according to the emergency resource requirements, and determine the disposal process according to the network resources; Collaboratively conduct emergency response to network security incidents according to the disposal process, and feedback the disposal results to the management terminal. At the same time, retrieve the disposal standards based on the management terminal; Match and verify the disposal results with the disposal standards; When the disposal results match the disposal standards, the verification result is that the collaborative emergency response to the network security incident is successful; When the disposal results do not match the disposal standards, the verification result is that the collaborative emergency response to the network security incident fails, and the collaborative emergency response is carried out again until the verification result is that the collaborative emergency response to the network security incident is successful.
9. A network security monitoring and early warning system based on multi-source data, characterized in that, Including: A data acquisition module, which is used to obtain multi-source heterogeneous data in the network based on a multi-channel method and preprocess the multi-source heterogeneous data; A security incident analysis module, which is used to conduct independent security situation analysis and comprehensive security situation analysis on the preprocessed multi-source heterogeneous data respectively to determine the network security incidents existing in the network; An early warning and emergency response module, which is used to issue early warning notifications for network security incidents and conduct collaborative emergency response to network resources in the network based on the early warning notifications.
10. A network security monitoring and early warning system based on multi-source data according to claim 9, characterized in that, The data acquisition module includes: A monitoring preparation unit, which is used to determine the monitoring objects in the network based on security monitoring requirements and determine the network attributes of each monitoring object in the network; A parameter configuration unit, which is used to determine the personalized multi-channel method of each monitoring object based on the network attributes and configure the data acquisition frequency for each personalized multi-channel method respectively; A data acquisition unit, which is used to open parallel communication permissions for the personalized multi-channel method of each monitoring object and conduct real-time data acquisition on each monitoring object in the network based on the open result to obtain multi-source heterogeneous data in the network.
Citation Information
Patent Citations
Method and system for evaluating network safety situation
CN101436967A
Safety comprehensive management system based on multi-source heterogeneous information
CN104852927A
Electronic information network security system based on multi-source data exception monitoring
CN116389159A
Network security situation awareness and early warning method and system based on big data
CN118075005A
Smart station monitoring visualization system and method based on multi-source heterogeneous data fusion
CN119047848A
Cited By
Network security abnormal behavior early warning management method
CN121418209A
A network security abnormal behavior early warning management method
CN121418209B
Comprehensive situation monitoring method and device
CN121750681A