A network security monitoring and early warning method and system based on multi-source data
By acquiring and analyzing multi-source heterogeneous data in the network through multi-source data monitoring methods, the problem of traditional network security monitoring relying on a single data source is solved, and accurate judgment and timely response to network security incidents are achieved.
Patent Information
- Application Number
- CN202510686268.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-05-27
AI Technical Summary
Traditional network security monitoring and early warning methods rely on a single data source and are unable to comprehensively and effectively detect network security incidents, resulting in poor monitoring results.
Adopting a multi-source data monitoring method, we acquire multi-source heterogeneous data through multiple channels, conduct pre-processing, independent and comprehensive security situation analysis, make judgments on network security incidents, and issue early warnings and coordinated emergency response when incidents are detected.
It improves the accuracy of judging network security incidents and the timeliness of handling them, and enhances the effectiveness of network security monitoring and control.
Smart Images

Figure CN120200860B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a network security monitoring and early warning method and system based on multi-source data. Background Art
[0002] With the rapid development of information technology, the network environment has become increasingly complex, and network security is facing unprecedented challenges. Therefore, network security monitoring is particularly important.
[0003] However, traditional network security monitoring and early warning methods often target a single type of data, such as network traffic data or system log data. This single data source monitoring approach has limitations. For example, relying solely on network traffic data may not accurately detect malicious operations by insiders, while relying solely on system log data may overlook network layer attacks, making it impossible to conduct comprehensive and effective network security monitoring and control, thereby significantly reducing the effectiveness of network security monitoring and early warning.
[0004] Therefore, in order to overcome the above-mentioned defects, the present invention provides a network security monitoring and early warning method and system based on multi-source data. Summary of the Invention
[0005] The present invention provides a network security monitoring and early warning method and system based on multi-source data, which is used to obtain multi-source heterogeneous data in the network by adopting multiple methods, thereby ensuring the comprehensiveness and reliability of the obtained multi-source heterogeneous data. Secondly, the multi-source heterogeneous data is preprocessed, and network security events are analyzed and judged based on the preprocessing results, thereby ensuring security event monitoring from multiple angles and improving the accuracy of network security event judgment. Finally, when a network security event occurs, early warning and coordinated emergency response are carried out, thereby ensuring the timeliness and safety of network security event processing and improving the effect of network security monitoring and control.
[0006] The present invention provides a network security monitoring and early warning method based on multi-source data, comprising:
[0007] Step 1: Acquire multi-source heterogeneous data in the network based on a multi-channel approach and preprocess the multi-source heterogeneous data;
[0008] Step 2: Perform independent security situation analysis and comprehensive security situation analysis on the pre-processed multi-source heterogeneous data to identify network security incidents.
[0009] Step 3: Issue early warning notifications for network security incidents and coordinate emergency response for network resources in the network based on the early warning notifications.
[0010] Preferably, a network security monitoring and early warning method based on multi-source data, in step 1, obtaining multi-source heterogeneous data in the network based on a multi-channel method, includes:
[0011] Determine the monitoring objects in the network based on security monitoring requirements, and determine the network attributes of each monitoring object in the network;
[0012] Determine the personalized multi-channel mode for each monitoring object based on network attributes, and configure the data collection frequency for each personalized multi-channel mode;
[0013] The parallel communication permissions are opened for the personalized multi-channel mode of each monitoring object, and based on the open results, real-time data collection is carried out on each monitoring object in the network to obtain multi-source heterogeneous data in the network.
[0014] Preferably, a network security monitoring and early warning method based on multi-source data, in step 1, preprocessing the multi-source heterogeneous data includes:
[0015] Obtain multi-source heterogeneous data and perform distributed data reporting based on the basic information of the multi-source heterogeneous data;
[0016] Based on distributed data reporting, multi-source heterogeneous data is audited according to audit indicators. After the audit is passed, the multi-source heterogeneous data is classified and counted, and a data statistics list for each monitoring object is generated based on the classification and statistical results;
[0017] The obtained multi-source heterogeneous data is stored in the database based on the data statistical list, and after the storage is successful, the retrieval conditions of the multi-source heterogeneous data are generated based on the storage address;
[0018] Feedback and save the search conditions.
[0019] Preferably, a network security monitoring and early warning method based on multi-source data performs classification statistics on multi-source heterogeneous data after review, including:
[0020] Extracting the data sources of the multi-source heterogeneous data, and performing a first classification on the multi-source heterogeneous data based on the data sources to obtain a data set under each data source;
[0021] Performing statistics on the first data volume and data category composition of the data set under each data source, and generating global statistics for each data source based on the statistical results;
[0022] At the same time, a second classification is performed on the data set under each data source based on the data category, and a second data volume statistics is performed on the data of each category based on the second classification result;
[0023] Based on global statistics and statistics of the second data volume, an overview of data assets of multi-source heterogeneous data is obtained, and classification statistics of multi-source heterogeneous data are completed based on the data asset overview.
[0024] Preferably, a network security monitoring and early warning method based on multi-source data, in step 2, performs independent security situation analysis and comprehensive security situation analysis on the pre-processed multi-source heterogeneous data to determine network security events existing in the network, including:
[0025] Perform conditional access and retrieval on the original log library based on the data source of multi-source heterogeneous data, retrieve historical alarm data from each data source in the multi-source heterogeneous data, and parse the historical alarm data to obtain an alarm overview for each data source;
[0026] Based on the alarm overview, the alarm dimensions and alarm behavior events under each data source are determined, and the alarm behavior events are analyzed to obtain the alarm event characteristics under each alarm dimension.
[0027] Determine the network security monitoring quantitative indicators for each data source based on the characteristics of the alarm event, and build a security detection model corresponding to each data source based on the network security monitoring quantitative indicators;
[0028] At the same time, the association relationship between multi-source heterogeneous data is determined based on the network operation protocol, and the security detection models corresponding to different data sources are cascaded based on the association relationship. The parameters of the security detection model are adapted based on the cascade result to obtain a hybrid security detection model.
[0029] Detect multi-source heterogeneous data based on security detection models and hybrid security detection models, and determine independent security status and comprehensive security status based on the detection results;
[0030] Determine abnormal indicators in the network based on independent security situation and comprehensive security situation, and determine the direction of abnormal indicators;
[0031] Based on the pointing information, the pointing objects of different abnormal indicators are determined. When the number of abnormal indicators corresponding to the pointing objects exceeds the preset range and the abnormal characteristics of the pointing objects are not within the range of conventional security failures, the pointing objects are locked and it is determined that a network security incident has occurred.
[0032] Preferably, a network security monitoring and early warning method based on multi-source data, for determining the presence of a network security incident, includes:
[0033] Read the network security incident based on the judgment result to determine the attack characteristics and attack scope of the network security incident;
[0034] Tracing the attack source based on attack characteristics to obtain the attack source, and at the same time, determining the attack purpose of the network security incident based on the attack scope;
[0035] Evaluate the attack purpose and scope based on pre-set event assessment indicators to determine the severity of the current network security incident;
[0036] Record the attack source, attack purpose, and severity level.
[0037] Preferably, a network security monitoring and early warning method based on multi-source data, in step 3, early warning notification of network security events includes:
[0038] Obtain the event type of the network security event and call the event monitoring node management center;
[0039] Input the event type into the event monitoring node management center for matching and determine the target monitoring node associated with the event type;
[0040] At the same time, core key data of network security events are retrieved based on the event type;
[0041] Extracting a network security data set corresponding to a network security incident, locating the core key data in the network security data set, and determining several associated data segments of the core key data based on the locating results;
[0042] Obtain the impact weight of each associated data segment and core key data, and obtain the preset weight threshold;
[0043] Compare the impact weight of each associated data segment and core key data with the preset weight threshold;
[0044] taking the associated data segment whose influence weight is greater than the preset weight threshold as the first associated data segment;
[0045] taking the associated data segment whose influence weight is less than or equal to the preset weight threshold as the second associated data segment;
[0046] Performing a first data encapsulation on the first associated data segment and the core key data to obtain a first warning data packet, and simultaneously performing a second data encapsulation on the second associated data segment to obtain a second warning data packet;
[0047] Sending a first warning data packet to a target monitoring node for a first warning notification, and when the target monitoring node generates a response signal, the warning notification is completed;
[0048] When the target monitoring node does not generate a response signal, the second warning data packet is sent to the target monitoring node, and when the sending is successful, the warning notification is completed.
[0049] Preferably, a network security monitoring and early warning method based on multi-source data, in step 3, collaborative emergency response is performed on network resources in the network based on the early warning notification, including:
[0050] Determine the emergency resource requirements for cybersecurity incidents based on early warning notification information, and determine the network resources in the network based on the emergency resource requirements. At the same time, determine the handling process based on the network resources;
[0051] Conduct collaborative emergency response to cybersecurity incidents according to the response process, and feedback the response results to the management terminal. At the same time, the response standards are retrieved based on the management terminal.
[0052] Verify the matching of disposal results with disposal standards;
[0053] When the disposal result matches the disposal standard, the verification result is that the coordinated emergency disposal of the cybersecurity incident is successful;
[0054] When the disposal result does not match the disposal standard, the verification result is that the coordinated emergency disposal of the network security incident has failed, and the coordinated emergency disposal is performed again until the verification result is that the coordinated emergency disposal of the network security incident has been successful.
[0055] The present invention provides a network security monitoring and early warning system based on multi-source data, comprising:
[0056] The data acquisition module is used to acquire multi-source heterogeneous data in the network based on a multi-channel method and pre-process the multi-source heterogeneous data;
[0057] The security event analysis module is used to perform independent security situation analysis and comprehensive security situation analysis on pre-processed multi-source heterogeneous data to identify network security events.
[0058] The early warning and emergency response module is used to issue early warning notifications for network security incidents and to coordinate emergency disposal of network resources in the network based on the early warning notifications.
[0059] Preferably, a network security monitoring and early warning system based on multi-source data, the data acquisition module includes:
[0060] A monitoring preparation unit, configured to determine monitoring objects in the network based on security monitoring requirements, and determine network attributes of each monitoring object in the network;
[0061] a parameter configuration unit, configured to determine a personalized multi-channel mode for each monitoring object based on network attributes, and to configure a data collection frequency for each personalized multi-channel mode;
[0062] The data acquisition unit is used to open the parallel communication permissions for the personalized multi-channel mode of each monitoring object, and based on the opening results, perform real-time data collection on each monitoring object in the network to obtain multi-source heterogeneous data in the network.
[0063] Compared with the prior art, the present invention has the following beneficial effects:
[0064] By adopting multiple methods to obtain multi-source heterogeneous data in the network, the comprehensiveness and reliability of the obtained multi-source heterogeneous data are ensured. Secondly, the multi-source heterogeneous data are preprocessed, and network security incidents are analyzed and judged based on the preprocessing results, ensuring security incident monitoring from multiple angles and improving the accuracy of network security incident judgment. Finally, when there is a network security incident, early warning and coordinated emergency response are carried out to ensure the timeliness and security of network security incident handling and improve the effectiveness of network security monitoring and control.
[0065] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in this application document.
[0066] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0068] Figure 1 This is a flow chart of a network security monitoring and early warning method based on multi-source data in an embodiment of the present invention;
[0069] Figure 2 This is a flowchart of step 1 in a network security monitoring and early warning method based on multi-source data in an embodiment of the present invention;
[0070] Figure 3 This is a structural diagram of a network security monitoring and early warning system based on multi-source data in an embodiment of the present invention. DETAILED DESCRIPTION
[0071] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0072] This embodiment provides a network security monitoring and early warning method based on multi-source data, such as Figure 1As shown, including:
[0073] Step 1: Acquire multi-source heterogeneous data in the network based on a multi-channel approach and preprocess the multi-source heterogeneous data;
[0074] Step 2: Perform independent security situation analysis and comprehensive security situation analysis on the pre-processed multi-source heterogeneous data to identify network security incidents.
[0075] Step 3: Issue early warning notifications for network security incidents and coordinate emergency response for network resources in the network based on the early warning notifications.
[0076] In this embodiment, the multi-channel approach refers to obtaining multi-source heterogeneous data in the network through a variety of different approaches, including active detection, traffic analysis, manual reporting, data import, and the like.
[0077] In this embodiment, multi-source heterogeneous data refers to working data obtained from different sources, systems or devices, such as abnormal behavior data, traffic data, network device operation data, and code data.
[0078] In this embodiment, preprocessing refers to operations such as cleaning and reviewing multi-source heterogeneous data.
[0079] In this embodiment, independent security situation analysis refers to performing a separate analysis on the network data under each data source to determine whether there is a network security incident under each data source.
[0080] In this embodiment, comprehensive security situation analysis refers to performing correlation analysis on multi-source heterogeneous data to determine whether there is a network security incident in the network.
[0081] In this embodiment, the network security event refers to a network vulnerability or a Trojan attack.
[0082] In this embodiment, collaborative emergency response refers to scheduling or arranging available resources in the network to respond to network security incidents.
[0083] The beneficial effects of the above technical solution are: by adopting multiple methods to obtain multi-source heterogeneous data in the network, the comprehensiveness and reliability of the obtained multi-source heterogeneous data are ensured; secondly, the multi-source heterogeneous data are preprocessed, and network security incidents are analyzed and judged based on the preprocessing results, ensuring security incident monitoring from multiple angles and improving the accuracy of network security incident judgment; finally, when a network security incident occurs, early warning and coordinated emergency response are carried out, ensuring the timeliness and security of network security incident handling, and improving the effectiveness of network security monitoring and control.
[0084] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. Figure 2 As shown, in step 1, multi-source heterogeneous data in the network is obtained based on a multi-channel approach, including:
[0085] Step 101: Determine monitoring objects in the network based on security monitoring requirements, and determine network attributes of each monitoring object in the network;
[0086] Step 102: Determine a personalized multi-channel mode for each monitoring object based on network attributes, and configure data collection frequencies for each personalized multi-channel mode;
[0087] Step 103: Open parallel communication rights for the personalized multi-channel mode of each monitoring object, and based on the opening result, collect real-time data for each monitoring object in the network to obtain multi-source heterogeneous data in the network.
[0088] In this embodiment, the security monitoring requirements are known in advance, including the objects to be monitored and the monitoring standards.
[0089] In this embodiment, network attributes refer to the types corresponding to different monitoring objects, such as network operation equipment and user access behavior.
[0090] In this embodiment, the personalized multi-channel method refers to the method of collecting network resource data of each monitored object, which can be a combination of active detection, traffic analysis, manual reporting, data import, etc.
[0091] In this embodiment, opening the parallel communication authority refers to authorizing the communication authority in a personalized multi-channel manner, thereby facilitating the execution of corresponding data collection tasks.
[0092] The beneficial effects of the above technical solution are: ensuring the comprehensiveness and reliability of the acquisition of multi-source heterogeneous data in the network, and providing reliable data support for network security monitoring.
[0093] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. In step 1, multi-source heterogeneous data is preprocessed, including:
[0094] Obtain multi-source heterogeneous data and perform distributed data reporting based on the basic information of the multi-source heterogeneous data;
[0095] Based on distributed data reporting, multi-source heterogeneous data is audited according to audit indicators. After the audit is passed, the multi-source heterogeneous data is classified and counted, and a data statistics list for each monitoring object is generated based on the classification and statistical results;
[0096] The obtained multi-source heterogeneous data is stored in the database based on the data statistical list, and after the storage is successful, the retrieval conditions of the multi-source heterogeneous data are generated based on the storage address;
[0097] Feedback and save the search conditions.
[0098] In this embodiment, basic information refers to information such as the service type, corresponding representation object, and corresponding value range of multi-source heterogeneous data.
[0099] In this embodiment, the audit indicators are known in advance, including the limited range of data values.
[0100] In this embodiment, classification statistics refers to classifying and integrating multi-source heterogeneous data according to data categories, thereby facilitating corresponding network security monitoring and early warning.
[0101] In this embodiment, the retrieval condition refers to a reference basis for searching the stored multi-source heterogeneous data, that is, the retrieval condition is used to retrieve the corresponding data from the database according to the demand.
[0102] The beneficial effects of the above technical solution are: ensuring the reliability of the preprocessing of the obtained multi-source heterogeneous data, and also ensuring the accuracy and reliability of the multi-source heterogeneous data finally obtained. At the same time, the multi-source heterogeneous data is stored in the database and the corresponding retrieval conditions are generated, which provides convenience and guarantee for the subsequent retrieval of the corresponding multi-source heterogeneous data.
[0103] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided, which classifies and counts the multi-source heterogeneous data after review, including:
[0104] Extracting the data sources of the multi-source heterogeneous data, and performing a first classification on the multi-source heterogeneous data based on the data sources to obtain a data set under each data source;
[0105] Performing statistics on the first data volume and data category composition of the data set under each data source, and generating global statistics for each data source based on the statistical results;
[0106] At the same time, a second classification is performed on the data set under each data source based on the data category, and a second data volume statistics is performed on the data of each category based on the second classification result;
[0107] Based on global statistics and statistics of the second data volume, an overview of data assets of multi-source heterogeneous data is obtained, and classification statistics of multi-source heterogeneous data are completed based on the data asset overview.
[0108] In this embodiment, the first classification refers to classifying the obtained multi-source heterogeneous data according to the data source. For example, user behavior data and network device operation data may be distinguished, which is the first classification.
[0109] In this embodiment, the first data volume refers to statistics on the volume of data included in each data set after the first classification.
[0110] In this embodiment, global statistics refers to the amount of data contained in each data source and the composition of data types.
[0111] In this embodiment, the second classification refers to classifying the data set under each data source. For example, if the data set is user behavior data, the second classification is to classify the user access behavior data and the user operation behavior data.
[0112] In this embodiment, the second data volume refers to the amount of data corresponding to each data category in the data set under each data source.
[0113] In this embodiment, the data asset overview refers to the overall composition of multi-source heterogeneous data obtained based on global statistics and second data volume statistics.
[0114] The beneficial effect of the above technical solution is: ensuring the accuracy of classification statistics of multi-source heterogeneous data, thereby facilitating comprehensive and effective monitoring of network security based on the classification statistics results.
[0115] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. In step 2, independent security situation analysis and comprehensive security situation analysis are performed on the pre-processed multi-source heterogeneous data to determine network security events existing in the network, including:
[0116] Perform conditional access and retrieval on the original log library based on the data source of multi-source heterogeneous data, retrieve historical alarm data from each data source in the multi-source heterogeneous data, and parse the historical alarm data to obtain an alarm overview for each data source;
[0117] Based on the alarm overview, the alarm dimensions and alarm behavior events under each data source are determined, and the alarm behavior events are analyzed to obtain the alarm event characteristics under each alarm dimension.
[0118] Determine the network security monitoring quantitative indicators for each data source based on the characteristics of the alarm event, and build a security detection model corresponding to each data source based on the network security monitoring quantitative indicators;
[0119] At the same time, the association relationship between multi-source heterogeneous data is determined based on the network operation protocol, and the security detection models corresponding to different data sources are cascaded based on the association relationship. The parameters of the security detection model are adapted based on the cascade result to obtain a hybrid security detection model.
[0120] Based on the security detection model and the hybrid security detection model, multi-source heterogeneous data is tested respectively, and the independent security situation and the comprehensive security situation are determined based on the detection results;
[0121] Determine abnormal indicators in the network based on independent security situation and comprehensive security situation, and determine the direction of abnormal indicators;
[0122] Based on the pointing information, the pointing objects of different abnormal indicators are determined. When the number of abnormal indicators corresponding to the pointing objects exceeds the preset range and the abnormal characteristics of the pointing objects are not within the range of conventional security failures, the pointing objects are locked and it is determined that a network security incident has occurred.
[0123] In this embodiment, the original log library is known in advance and is used to record historical alarm data from different data sources.
[0124] In this embodiment, conditional access and retrieval is to retrieve historical alarm data of corresponding data types from the original log library according to the types of current multi-source heterogeneous data.
[0125] In this embodiment, the alarm overview refers to the historical alarm status of each data source, including the alarm type (ie, alarm dimension) and the cause of the alarm.
[0126] In this embodiment, the alarm behavior event refers to the specific behavior of generating an alarm.
[0127] In this embodiment, the alarm event feature refers to the data state when the alarm is generated, including the value of the data and the composition of the data.
[0128] In this embodiment, the network security monitoring quantitative index refers to the monitoring standard for each data source when performing network security monitoring and early warning, such as a specific limited range of network traffic, and traffic outside the range is considered abnormal.
[0129] In this embodiment, the network operation protocol is known in advance and is used to characterize the association relationship between various data sources during network operation.
[0130] In this embodiment, cascading refers to associating and integrating the security monitoring models under various data sources according to the determined association relationships.
[0131] In this embodiment, parameter adaptation refers to coordinating and adapting the working parameters of the cascaded security monitoring models to ensure compatibility between the security monitoring models.
[0132] In this embodiment, the hybrid security detection model refers to a result obtained by cascading the security detection models under various data sources.
[0133] In this embodiment, the abnormality indicator refers to an abnormal situation existing in the network.
[0134] In this embodiment, the pointing information refers to a specific object corresponding to the abnormal indicator, such as a network operation device or network traffic.
[0135] In this embodiment, the pointed object refers to a specific network object corresponding to the abnormal indicator, for example, a certain network device.
[0136] The beneficial effects of the above technical solution are: by constructing a security detection model and a hybrid security detection model under each data source, and detecting multi-source heterogeneous data through the security detection model and the hybrid security detection model respectively, it is possible to effectively determine the independent security situation and the comprehensive security situation, and then lock the abnormal indicators existing in the network. Finally, the abnormal objects are determined according to the abnormal indicators, thereby realizing accurate and effective judgment of network security incidents existing in the network, and also providing convenience and guarantee for timely security response.
[0137] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided, which determines the presence of a network security incident, including:
[0138] Read the network security incident based on the judgment result to determine the attack characteristics and attack scope of the network security incident;
[0139] Tracing the attack source based on attack characteristics to obtain the attack source, and at the same time, determining the attack purpose of the network security incident based on the attack scope;
[0140] Evaluate the attack purpose and scope based on pre-set event assessment indicators to determine the severity of the current network security incident;
[0141] Record the attack source, attack purpose, and severity level.
[0142] In this embodiment, the attack characteristics refer to the attack method corresponding to the network security event and the specific data node of the attack.
[0143] In this embodiment, the preset event evaluation index is set in advance and is used to evaluate the severity of the current network security event according to the attack purpose and attack scope. Different attack scopes and attack purposes correspond to different severity levels.
[0144] The beneficial effect of the above technical solution is: it can determine the source and purpose of the attack, and then determine the severity level of the network security incident based on the source and purpose of the attack, providing a reference basis for taking corresponding security emergency measures.
[0145] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. In step 3, an early warning notification of a network security incident is issued, including:
[0146] Obtain the event type of the network security event and call the event monitoring node management center;
[0147] Input the event type into the event monitoring node management center for matching and determine the target monitoring node associated with the event type;
[0148] At the same time, core key data of network security events are retrieved based on the event type;
[0149] Extracting a network security data set corresponding to a network security incident, locating the core key data in the network security data set, and determining several associated data segments of the core key data based on the locating results;
[0150] Obtain the impact weight of each associated data segment and core key data, and obtain the preset weight threshold;
[0151] Compare the impact weight of each associated data segment and core key data with the preset weight threshold;
[0152] taking the associated data segment whose influence weight is greater than the preset weight threshold as the first associated data segment;
[0153] taking the associated data segment whose influence weight is less than or equal to the preset weight threshold as the second associated data segment;
[0154] Performing a first data encapsulation on the first associated data segment and the core key data to obtain a first warning data packet, and simultaneously performing a second data encapsulation on the second associated data segment to obtain a second warning data packet;
[0155] Sending a first warning data packet to a target monitoring node for a first warning notification, and when the target monitoring node generates a response signal, the warning notification is completed;
[0156] When the target monitoring node does not generate a response signal, the second warning data packet is sent to the target monitoring node, and when the sending is successful, the warning notification is completed.
[0157] In this embodiment, the event monitoring node management center is set up in advance and is used to respond to and manage existing network security events.
[0158] In this embodiment, the target monitoring node refers to a monitoring node corresponding to the event type of the current network security event.
[0159] In this embodiment, core key data refers to data information that can characterize the type of network security incidents and attack behaviors.
[0160] In this embodiment, the plurality of associated data segments refer to core key data and data segments that are to be matched in the network security data set.
[0161] In this embodiment, the influence weight is used to represent the importance of the associated data segment and the core key data in the entire data.
[0162] In this embodiment, the preset weight threshold is set in advance.
[0163] In this embodiment, the first warning data packet refers to a data packet obtained by performing a first data encapsulation on the first associated data segment and the core key data.
[0164] In this embodiment, the second warning data packet refers to data obtained by performing second data encapsulation on the second associated data segment.
[0165] The beneficial effect of the above technical solution is: ensuring the accuracy and timeliness of early warning notifications of network security incidents, thereby facilitating timely response to network security incidents and ensuring network operation reliability.
[0166] In one embodiment, a network security monitoring and early warning method based on multi-source data is provided. In step 3, based on the early warning notification, a coordinated emergency response is performed on network resources in the network, including:
[0167] Determine the emergency resource requirements for cybersecurity incidents based on early warning notification information, and determine the network resources in the network based on the emergency resource requirements. At the same time, determine the handling process based on the network resources;
[0168] Conduct collaborative emergency response to cybersecurity incidents according to the response process, and feedback the response results to the management terminal. At the same time, the response standards are retrieved based on the management terminal.
[0169] Verify the matching of disposal results with disposal standards;
[0170] When the disposal result matches the disposal standard, the verification result is that the coordinated emergency disposal of the cybersecurity incident is successful;
[0171] When the disposal result does not match the disposal standard, the verification result is that the coordinated emergency disposal of the network security incident has failed, and the coordinated emergency disposal is performed again until the verification result is that the coordinated emergency disposal of the network security incident has been successful.
[0172] In this embodiment, the emergency resource demand refers to the emergency resources required to resolve network security incidents.
[0173] In this embodiment, network resources refer to resources currently available in the network.
[0174] In this embodiment, the handling process refers to a strategy or plan for scheduling and coordinating network resources.
[0175] In this embodiment, the handling standard refers to the requirement for collaborative scheduling of network resources.
[0176] The beneficial effects of the above technical solution are: ensuring timely and effective coordinated emergency handling of network resources in the network when a network security incident occurs, ultimately ensuring timely and reliable emergency response to network security, improving the safety factor of network operation, and improving the effectiveness of network security monitoring and early warning.
[0177] This embodiment provides a network security monitoring and early warning system based on multi-source data, such as Figure 3 As shown, including:
[0178] The data acquisition module is used to acquire multi-source heterogeneous data in the network based on a multi-channel method and pre-process the multi-source heterogeneous data;
[0179] The security event analysis module is used to perform independent security situation analysis and comprehensive security situation analysis on pre-processed multi-source heterogeneous data to identify network security events.
[0180] The early warning and emergency response module is used to issue early warning notifications for network security incidents and to coordinate emergency disposal of network resources in the network based on the early warning notifications.
[0181] The beneficial effects of the above technical solution are: by adopting multiple methods to obtain multi-source heterogeneous data in the network, the comprehensiveness and reliability of the obtained multi-source heterogeneous data are ensured; secondly, the multi-source heterogeneous data are preprocessed, and network security incidents are analyzed and judged based on the preprocessing results, ensuring security incident monitoring from multiple angles and improving the accuracy of network security incident judgment; finally, when a network security incident occurs, early warning and coordinated emergency response are carried out, ensuring the timeliness and security of network security incident handling, and improving the effectiveness of network security monitoring and control.
[0182] In one embodiment, a network security monitoring and early warning system based on multi-source data is provided, wherein the data acquisition module includes:
[0183] A monitoring preparation unit, configured to determine monitoring objects in the network based on security monitoring requirements, and determine network attributes of each monitoring object in the network;
[0184] a parameter configuration unit, configured to determine a personalized multi-channel mode for each monitoring object based on network attributes, and to configure a data collection frequency for each personalized multi-channel mode;
[0185] The data acquisition unit is used to open the parallel communication permissions for the personalized multi-channel mode of each monitoring object, and based on the opening results, perform real-time data collection on each monitoring object in the network to obtain multi-source heterogeneous data in the network.
[0186] The beneficial effects of the above technical solution are: ensuring the comprehensiveness and reliability of the acquisition of multi-source heterogeneous data in the network, and providing reliable data support for network security monitoring.
[0187] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A network security monitoring and early warning method based on multi-source data, characterized in that: include: Step 1: Acquire multi-source heterogeneous data in the network based on a multi-channel approach and preprocess the multi-source heterogeneous data; Step 2: Perform independent security situation analysis and comprehensive security situation analysis on the pre-processed multi-source heterogeneous data to identify network security incidents. Step 3: Issue early warning notifications for network security incidents and coordinate emergency response for network resources based on the early warning notifications. In step 3, early warning notification of network security incidents includes: Obtain the event type of the network security event and call the event monitoring node management center; Input the event type into the event monitoring node management center for matching and determine the target monitoring node associated with the event type; At the same time, core key data of network security events are retrieved based on the event type; Extracting a network security data set corresponding to a network security incident, locating the core key data in the network security data set, and determining several associated data segments of the core key data based on the locating results; Obtain the impact weight of each associated data segment and core key data, and obtain the preset weight threshold; Compare the impact weight of each associated data segment and core key data with the preset weight threshold; taking the associated data segment whose influence weight is greater than the preset weight threshold as the first associated data segment; taking the associated data segment whose influence weight is less than or equal to the preset weight threshold as the second associated data segment; Performing a first data encapsulation on the first associated data segment and the core key data to obtain a first warning data packet, and simultaneously performing a second data encapsulation on the second associated data segment to obtain a second warning data packet; Sending a first warning data packet to a target monitoring node for a first warning notification, and when the target monitoring node generates a response signal, the warning notification is completed; When the target monitoring node does not generate a response signal, the second warning data packet is sent to the target monitoring node, and when the sending is successful, the warning notification is completed.
2. A network security monitoring and early warning method based on multi-source data according to claim 1, characterized in that: In step 1, multi-source heterogeneous data in the network is obtained based on a multi-channel approach, including: Determine the monitoring objects in the network based on security monitoring requirements, and determine the network attributes of each monitoring object in the network; Determine the personalized multi-channel mode for each monitoring object based on network attributes, and configure the data collection frequency for each personalized multi-channel mode; The parallel communication permissions are opened for the personalized multi-channel mode of each monitoring object, and based on the open results, real-time data collection is carried out on each monitoring object in the network to obtain multi-source heterogeneous data in the network.
3. The network security monitoring and early warning method based on multi-source data according to claim 1 is characterized in that: In step 1, preprocessing of multi-source heterogeneous data is performed, including: Obtain multi-source heterogeneous data and perform distributed data reporting based on the basic information of the multi-source heterogeneous data; Based on distributed data reporting, multi-source heterogeneous data is audited according to audit indicators. After the audit is passed, the multi-source heterogeneous data is classified and counted, and a data statistics list for each monitoring object is generated based on the classification and statistical results; The obtained multi-source heterogeneous data is stored in the database based on the data statistical list, and after the storage is successful, the retrieval conditions of the multi-source heterogeneous data are generated based on the storage address; Feedback and save the search conditions.
4. A network security monitoring and early warning method based on multi-source data according to claim 3, characterized in that: After the review is passed, the multi-source heterogeneous data will be classified and counted, including: Extracting the data sources of the multi-source heterogeneous data, and performing a first classification on the multi-source heterogeneous data based on the data sources to obtain a data set under each data source; Performing statistics on the first data volume and data category composition of the data set under each data source, and generating global statistics for each data source based on the statistical results; At the same time, a second classification is performed on the data set under each data source based on the data category, and a second data volume statistics is performed on the data of each category based on the second classification result; Based on global statistics and statistics of the second data volume, an overview of data assets of multi-source heterogeneous data is obtained, and classification statistics of multi-source heterogeneous data are completed based on the data asset overview.
5. The network security monitoring and early warning method based on multi-source data according to claim 1 is characterized in that: In step 2, independent security situation analysis and comprehensive security situation analysis are performed on the pre-processed multi-source heterogeneous data to identify network security events, including: Perform conditional access and retrieval on the original log library based on the data source of multi-source heterogeneous data, retrieve historical alarm data from each data source in the multi-source heterogeneous data, and parse the historical alarm data to obtain an alarm overview for each data source; Based on the alarm overview, the alarm dimensions and alarm behavior events under each data source are determined, and the alarm behavior events are analyzed to obtain the alarm event characteristics under each alarm dimension. Determine the network security monitoring quantitative indicators for each data source based on the characteristics of the alarm event, and build a security detection model corresponding to each data source based on the network security monitoring quantitative indicators; At the same time, the association relationship between multi-source heterogeneous data is determined based on the network operation protocol, and the security detection models corresponding to different data sources are cascaded based on the association relationship. The parameters of the security detection model are adapted based on the cascade result to obtain a hybrid security detection model. Detect multi-source heterogeneous data based on security detection models and hybrid security detection models, and determine independent security status and comprehensive security status based on the detection results; Determine abnormal indicators in the network based on independent security situation and comprehensive security situation, and determine the direction of abnormal indicators; Based on the pointing information, the pointing objects of different abnormal indicators are determined. When the number of abnormal indicators corresponding to the pointing objects exceeds the preset range and the abnormal characteristics of the pointing objects are not within the range of conventional security failures, the pointing objects are locked and it is determined that a network security incident has occurred.
6. A network security monitoring and early warning method based on multi-source data according to claim 5, characterized in that: Determining the existence of a cybersecurity incident includes: Read the network security incident based on the judgment result to determine the attack characteristics and attack scope of the network security incident; Tracing the attack source based on attack characteristics to obtain the attack source, and at the same time, determining the attack purpose of the network security incident based on the attack scope; Evaluate the attack purpose and scope based on pre-set event assessment indicators to determine the severity of the current network security incident; Record the attack source, attack purpose, and severity level.
7. The network security monitoring and early warning method based on multi-source data according to claim 1 is characterized in that: In step 3, based on the early warning notification, coordinated emergency response is performed on network resources in the network, including: Determine the emergency resource requirements for cybersecurity incidents based on early warning notification information, and determine the network resources in the network based on the emergency resource requirements. At the same time, determine the handling process based on the network resources; Conduct collaborative emergency response to cybersecurity incidents according to the response process, and feedback the response results to the management terminal. At the same time, the response standards are retrieved based on the management terminal. Verify the matching of disposal results with disposal standards; When the disposal result matches the disposal standard, the verification result is that the coordinated emergency disposal of the cybersecurity incident is successful; When the disposal result does not match the disposal standard, the verification result is that the coordinated emergency disposal of the network security incident has failed, and the coordinated emergency disposal is performed again until the verification result is that the coordinated emergency disposal of the network security incident has been successful.
8. A network security monitoring and early warning system based on multi-source data, characterized in that: include: The data acquisition module is used to acquire multi-source heterogeneous data in the network based on a multi-channel method and pre-process the multi-source heterogeneous data; The security event analysis module is used to perform independent security situation analysis and comprehensive security situation analysis on pre-processed multi-source heterogeneous data to identify network security events. The early warning and emergency response module is used to issue early warning notifications for network security incidents and coordinate emergency response to network resources in the network based on the early warning notifications; Among them, the early warning and emergency response module includes: Obtain the event type of the network security event and call the event monitoring node management center; Input the event type into the event monitoring node management center for matching and determine the target monitoring node associated with the event type; At the same time, core key data of network security events are retrieved based on the event type; Extracting a network security data set corresponding to a network security incident, locating the core key data in the network security data set, and determining several associated data segments of the core key data based on the locating results; Obtain the impact weight of each associated data segment and core key data, and obtain the preset weight threshold; Compare the impact weight of each associated data segment and core key data with the preset weight threshold; taking the associated data segment whose influence weight is greater than the preset weight threshold as the first associated data segment; taking the associated data segment whose influence weight is less than or equal to the preset weight threshold as the second associated data segment; Performing a first data encapsulation on the first associated data segment and the core key data to obtain a first warning data packet, and simultaneously performing a second data encapsulation on the second associated data segment to obtain a second warning data packet; Sending a first warning data packet to a target monitoring node for a first warning notification, and when the target monitoring node generates a response signal, the warning notification is completed; When the target monitoring node does not generate a response signal, the second warning data packet is sent to the target monitoring node, and when the sending is successful, the warning notification is completed.
9. The network security monitoring and early warning system based on multi-source data according to claim 8 is characterized in that: Data acquisition module, including: A monitoring preparation unit, configured to determine monitoring objects in the network based on security monitoring requirements, and determine network attributes of each monitoring object in the network; a parameter configuration unit, configured to determine a personalized multi-channel mode for each monitoring object based on network attributes, and to configure a data collection frequency for each personalized multi-channel mode; The data acquisition unit is used to open the parallel communication permissions for the personalized multi-channel mode of each monitoring object, and based on the opening results, perform real-time data collection on each monitoring object in the network to obtain multi-source heterogeneous data in the network.