Space-time situation awareness assessment method for network risk
Through the spatial and temporal situation awareness evaluation method, a network node characteristic timing matrix is generated, abnormal event detection and node importance calculation are performed, which solves the problem of failure to fully consider the dynamic changes in the cyberspace situation in the existing technology, and achieves more efficient and accurate network risk monitoring.
Patent Information
- Application Number
- CN202510354219.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-27
AI Technical Summary
The existing cyber risk assessment methods fail to fully consider the dynamic changes in the cyberspace situation, resulting in low validity and accuracy of the evaluation results.
A spatial and temporal situation awareness evaluation method for network risks is proposed. By generating a network node characteristic timing matrix, abnormal event detection and preprocessing is performed, the importance of network nodes is calculated, and the characteristic difference value and spatial distribution difference value of abnormal nodes in adjacent time windows are evaluated. Finally, the situation evaluation is conducted based on the dynamic attenuation rate.
It significantly improves the sensitivity and accuracy of network risk monitoring, reduces the false alarm rate, and provides an efficient and intelligent solution for network security supervision.
Smart Images

Figure CN120223384A_ABST
Abstract
Description
Technical Field
[0001] The present invention proposes a spatio-temporal situation awareness evaluation method for network risks in view of problems such as single evaluation dimension, low efficiency, and too large evaluation quantization granularity in network risk assessment. Background Art
[0002] With the continuous evolution and complication of network attack technologies, traditional network security protection measures (such as intrusion detection) have been difficult to fully cope with the current changing security threats. Against this background, network risk assessment emerged as a new concept and technology and gradually became an important research topic in the field of network security. However, existing network risk assessment methods still face many challenges: on the one hand, qualitative assessment methods highly rely on the subjective judgment of experts, which easily leads to different evaluation results for different people and lacks consistency and standardization; on the other hand, quantitative assessment methods often require a large amount of accurate historical data and statistical information, and the analysis process is complex, significantly increasing the implementation cost of the assessment. In addition, these methods do not fully consider the dynamic changes of the network space situation when evaluating influencing factors, reducing the evaluation efficiency and accuracy. Summary of the Invention
[0003] The present invention provides a spatio-temporal situation awareness evaluation method for network risks to solve the technical problem of low effectiveness and accuracy of the perception evaluation results caused by the failure to fully consider the dynamic changes of risks in network time and space in the prior art.
[0004] To achieve the above object, the technical solution adopted by the present invention is: a spatio-temporal situation awareness evaluation method for network risks, and its steps are as follows:
[0005] Step 1): Collect the status data of network host nodes to generate a network node feature time series matrix;
[0006] Suppose there are q nodes in the network system, define the time interval [a, b] and divide it into multiple time windows with equal time intervals, and the length of each time window is Δφ, then the total number of time windows is:
[0007]
[0008] Within each time window, sample the status values of all nodes in the network system to form a node status value vector, and through a continuous sampling process, generate a network node feature time series matrix Z a:b :
[0009]
[0010] where q is the number of nodes in the network system, p is the number of time windows within the time interval [a, b]; z i,tRepresents the state value of the \(i\)-th node at the \(t\)-th time window; the \(i\)-th row \(z\) of the matrix i,: = [z i,1 , z i,2 , …, z i,p represents the state values of the \(i\)-th node in \(m\) consecutive time windows; the \(t\)-th column \(z\) of the matrix :,t = [z 1,t , z 2,t , …, z n,t T represents the state values of all nodes at the \(t\)-th time window.
[0011] Step 2): Perform preprocessing for anomaly event detection on the network node feature time series matrix to obtain the historical anomaly event node feature time series matrix and the current anomaly event node feature time series matrix.
[0012] 2.1) Use the state values of all nodes within the time window to represent the network state value of the current time window
[0013] f i = max(z i,1 , z i,2 , …, z i,q ), \(i\in[1, p]\)
[0014] where: \(f\) i is the network state value of the \(i\)-th time window;
[0015] 2.2) Anomaly event determination condition
[0016] When the network state value of each time window within a certain consecutive time window exceeds the preset threshold \(\theta\), and the length of the consecutive time window exceeds the minimum threshold \(\zeta\), it is determined as an anomaly event \(ev\) i , and the determination condition is as follows:
[0017] f t > \(\theta\) and
[0018] where: \(f\) t represents the network state value within the \(t\)-th time window; \(t\) istart and \(t\) iend respectively represent the start and end time windows of the anomaly event \(ev\) i ; \(\theta\) is the preset state value threshold; \(\zeta\) is the minimum number of consecutive time windows for the anomaly event;
[0019] 2.3) Anomaly event detection preprocessing algorithm
[0020] Event start: When the network state value first exceeds the threshold \(\theta\), mark the start time of the event;
[0021] Event end: If the network status value is lower than the threshold θ again and the abnormal event duration reaches the minimum threshold ζ, this time period is marked as the historical abnormal event time window;
[0022] Historical abnormal event output: Once the historical abnormal event is identified, the algorithm will output the start and end times of all detected historical abnormal events;
[0023] Current abnormal event: If the network status value in the last time window exceeds the threshold θ, it is considered that the abnormal event has not ended completely, indicating that the network status is still abnormal. Such abnormal events are regarded as the current abnormal time;
[0024] The set of abnormal events EV identified within the time interval [a, b] a:b Denoted as: EV a:b ={ev1, ev2, …, ev r}, where r is the total number of abnormal events identified within the time interval [a, b], and the event set {ev1, ev2, …, ev r-1} is the historical abnormal event. Each event ev i contains its complete event window where t istart is the start time window of event ev i ; t iend is the end time window of event ev i ; e r is the current abnormal event, which contains the start time window t rs .
[0025] Step 3): Calculate the importance of network nodes based on eigenvector centrality.
[0026] Adopt the method based on eigenvector centrality to calculate the importance of each node in the network. The eigenvector centrality measures the global influence of a node in the network through the principal eigenvector of the network adjacency matrix. The calculation process is as follows:
[0027] 3.1) Construct the adjacency matrix Given the network Ne = (V, E), where V and E represent the node set and the edge set respectively. First, construct the adjacency matrix B of the network; for any nodes i, j ∈ V, if there is an edge between node i and node j, then B ij = 1; otherwise B ij = 0;
[0028] 3.2) Calculate the eigenvalues and eigenvectors Perform eigenvalue decomposition on the adjacency matrix B to obtain its eigenvalue set and the corresponding eigenvector set {O k}; among them, the principal eigenvector O max is the one corresponding to the largest eigenvalue The corresponding eigenvector;
[0029] 3.3) Eigenvector normalization
[0030] To ensure that the node importance values are non - negative and sum to 1, for each component O of the principal eigenvector max of max,i perform absolute - value normalization to obtain the eigenvector centrality of node v i :
[0031]
[0032] Step 4): Calculate the feature difference values of abnormal nodes in adjacent time windows.
[0033] 4.1) Construct the set of abnormal nodes in adjacent time windows
[0034] Construct the sets of abnormal nodes in adjacent time windows as and
[0035] where: X t-1 represents the set of all abnormal nodes whose status values exceed the threshold in the (t - 1)-th time window within the time interval [a, b]; X t represents the set of all abnormal nodes whose status values exceed the threshold in the t - th time window within the time interval [a, b]; i represents the hierarchical number of the node in the network topology structure, starting from the top - most layer, numbered from top to bottom, with a value range of 1, 2,...; j represents the number of the node within the layer, numbered from left to right in sequence, with a value range of 1, 2,...; u represents the number of the corresponding parent node of the node within its layer;
[0036] Since there is a probability that the sets of abnormal nodes in the two consecutive time windows are different, considering different difference situations, the method for constructing the set of abnormal node status change differences is as follows:
[0037] If the indices of nodes and exactly match, it indicates the change in the status value of the same node in different time windows, and the change amount is calculated as:
[0038]
[0039] If node h i,j ∈X t but does not belong to X t-1 , it indicates that the node is a newly added abnormal node, and the change amount of its illegal quantity is calculated as:
[0040]
[0041] If node gi,j ∈X t-1 but not in X, indicating that this node is a disappearing abnormal node, and the change amount of its illegal quantity is calculated as:
[0042]
[0043] Obtain the set of differences in the state changes of abnormal nodes:
[0044]
[0045] Among them, represents the difference in the node state value, and the indices i, j, k describe the position information of the node in the network topology structure;
[0046] 4.2) Calculate the state changes of abnormal nodes in adjacent time windows
[0047] Define the abnormal state change amount ΔSA t as:
[0048]
[0049] Among them: represents the difference in the state of abnormal nodes in the t-th time window compared to the (t - 1)-th time window; represents the importance of the abnormal nodes that cause the state difference.
[0050] Step 5): Calculate the difference value of the spatial distribution of abnormal nodes in adjacent time windows.
[0051] 5.1) Define the spatial domain
[0052] Define the abnormal nodes that can be connected through the control node as a spatial domain. Each spatial domain formed by the nodes in X t is denoted as d t_i , where t represents the time window number within the time interval [a, b], and i is the domain index number in the set of spatial domains; each domain d t_i contains a group of nodes that can be connected to each other through the control node;
[0053] If there are multiple spatial domains in the abnormal node set X t that can be connected to each other through the intermediate node, these spatial domains form a set of spatial domains, denoted as D t , which is expressed as:
[0054]
[0055] Among them: n is the number of spatial domains that can be connected to each other through the intermediate node in the abnormal node set X t , and d t_iis the set of abnormal nodes X t the i-th spatial domain in;
[0056] 5.2) Evaluate the situation impact of the spatial domain
[0057] The more nodes there are in the spatial domain, the more extensive the abnormal distribution is, the greater the abnormal impact is, and the evaluation value Es(d t_i ) of the situation impact of the spatial domain is:
[0058]
[0059] Where: is the sum of the importance of all nodes in the spatial domain, expressed as the sum of the importance measures of all nodes v in the domain; E(|d t_i |) is the influence function of the number of abnormal nodes on the situation value of the spatial domain, defined as:
[0060]
[0061] Where |d t_i | is the number of nodes in the i-th domain of the abnormal node set X t in, is a constant that controls the growth rate of the number of nodes. As the number of nodes increases, the spatial situation value increases exponentially; β1 and β2 are weight coefficients that respectively control the contributions of node importance and node number to the influence degree;
[0062] 5.3) Define four spatial distributions of abnormal nodes
[0063] 5.3.1) Spatial single-point abnormal situation:
[0064] When |X t | = 1, it indicates that there is only one abnormal node state in the node state space distribution matrix X t corresponding to the t-th time window. In this situation, since there is only a single abnormal node, its impact on the overall system situation is weak;
[0065] 5.3.2) Spatial scattered-point abnormal situation When |X t | > 1, and any two nodes i and j in the abnormal node set X t are not adjacent. These abnormal elements are in an isolated state in the spatial distribution. This situation appears in the early development stage of the event or the end stage of the event. Since the abnormal points are isolated in space, the impact on the overall system situation is limited;
[0066] 5.3.3) Spatial single-domain abnormal situation
[0067] When |X t | > 1, and the abnormal node set X tAll elements in it can be interconnected through intermediate nodes to form an interconnected spatial domain. In this situation, the abnormal nodes belong to the same spatial domain, are connected to each other in spatial distribution, and show the characteristics of local concentrated distribution. This occurs in the outbreak stage of abnormal events and exacerbates the impact on the overall situation of the system;
[0068] 5.3.4) Spatial multi-domain abnormal situation
[0069] If |X t | > 1, and all elements in the abnormal node set X t can form multiple interconnected spatial domains through intermediate nodes, and the abnormalities in multiple domains show concurrent distribution, indicating that the abnormal impact has spread to multiple domains, and the abnormal event has entered the rapid development stage, having an abnormal impact on the overall situation of the system;
[0070] 5.4) Quantify the impact of the spatial situation
[0071] 5.4.1) Spatial distribution quantization value of single-point abnormal situation or spatial scattered-point abnormal situation
[0072] For the current time window t, if its spatial distribution is a single-point abnormal situation or a spatial scattered-point abnormal situation, the spatial distribution quantization value is the sum of the importance of all abnormal nodes, and the calculation formula is as follows:
[0073]
[0074] Among them, Im(v) is the importance measurement value of node v, and X t is the abnormal node set of the t-th time window.
[0075] 5.4.2) Spatial distribution quantization value of single-domain spatial abnormal situation or multi-domain spatial abnormal situation
[0076] For the current time window t, if its spatial distribution is a single-domain spatial abnormal situation or a multi-domain spatial abnormal situation, when quantifying the spatial distribution impact, consider the importance of the domain and the importance of other abnormal scattered points within the current window, and the calculation formula is as follows:
[0077]
[0078] where is the importance of all abnormal scattered points within the t-th time window; is the situation impact evaluation value of all spatial domains within the t-th time window;
[0079] 5.5) Spatial distribution change
[0080] Define ΔSP t to represent the node state time series matrix Z a:bIn it, the abnormal node set X of the t-th time window t Compared with the abnormal node set X of the (t - 1)-th time window t-1 The corresponding change in spatial distribution, which is used to characterize the trend change characteristics of the spatial distribution;
[0081] ΔSP t = SP t - SP t-1 .
[0082] Step 6): Based on the dynamic decay rate that is positively correlated with the time distance between the evaluation window and the current window, conduct a trend assessment on the feature fluctuations and spatial distribution fluctuations within the time window of historical abnormal events.
[0083] Based on the dynamic decay rate that is positively correlated with the time distance between the evaluation window and the current window, the formula for the trend assessment of the feature fluctuations and spatial distribution fluctuations within the time window of historical abnormal events is as follows:
[0084]
[0085] Among them, T represents the time window set of the historical abnormal event set {ev1, ev2,..., ev k-1}; ΔSA τ represents the change in abnormal state between the τ-th time window and the previous time window; ΔSP τ : represents the change in spatial distribution between the τ-th time window and the previous time window; ω1 and ω2 are the weight coefficients of the state abnormal change and the spatial distribution change respectively; Time decay function, used to control the decay rate.
[0086] Step 7): Based on different stages of event development, conduct a trend assessment on the feature fluctuations and spatial distribution fluctuations within the time window of the current abnormal event.
[0087] 7.1) Introduce a trend determination window, analyze the dynamic changes of the abnormal state node set X t within the trend determination window, and the linear fitting slope k t , which is used as the determination basis for different event development stages where the current time window is located.
[0088] Given the time window set {t - n, t - n + 1,..., t}, the number of abnormal state nodes in each time window i is Nu i = |X i |, and the calculation formula for the slope K t is:
[0089]
[0090] Among them, n represents the size of the situation determination window, and are respectively the average values of the time window index and the number of abnormal nodes;
[0091] Based on the value of the slope k t , the development stage of the abnormal event is divided into the following three parts:
[0092] Situation increasing stage: k t > ξ, that is, the slope is positive and greater than the set threshold;
[0093] Situation decreasing stage: k t < - ξ, that is, the slope is negative and less than the set threshold;
[0094] Situation stable stage: - ξ ≤ k t ≤ ξ;
[0095] 7.2) The calculation formula for the situation assessment of the current abnormal event is as follows:
[0096]
[0097] Among them, T‘ represents the time window set of the current abnormal event ev k ; ΔSA τ represents the change in the abnormal state between the τ - th time window and the previous time window; ΔSP τ : represents the change in the spatial distribution between the τ - th time window and the previous time window; ω1 and ω2 are respectively the weight coefficients of the state abnormal change and the spatial distribution change; J(k τ ) is an adjustment function used to dynamically adjust the situation weight of each time window according to the value of the slope k τ , and its form is:
[0098]
[0099] Among them: γ1 > 1 is the influence coefficient in the situation increasing stage, used to strengthen the evaluation weight of this stage; 0 < γ2 < 1 is the influence coefficient in the situation decreasing stage, used to weaken the evaluation weight of this stage; γ3 = 1 is the influence coefficient in the situation stable stage, which has no influence on the evaluation weight of this stage;
[0100] 7.3) The calculation formula for the risk assessment value of the final network node feature time - series matrix Z a:b is as follows:
[0101] S(Z a:b ) = S e (Z a:b ) + S′ e (Z a:b )
[0102] Among them, S e (Z a:b ) is the situation assessment value of historical abnormal events, and S′ e (Z a:b ) is the situation assessment value of the current abnormal event.
[0103] The beneficial effects of the present invention are as follows:
[0104] To solve the problems existing in the prior art, the present invention provides a spatio-temporal situation awareness assessment method for network risks. First, generate a time series matrix of network node features, perform preprocessing on the time series matrix of network node features for abnormal event detection, screen out the time window of abnormal events, and calculate the importance of network nodes based on eigenvector centrality; then, calculate the feature difference value of abnormal nodes in adjacent time windows and the spatial distribution difference value of abnormal nodes; finally, based on the dynamic attenuation rate that is positively correlated with the time distance between the evaluation window and the current window, perform situation assessment on the feature fluctuations and spatial distribution fluctuations within the time window of historical abnormal events, perform situation assessment on the feature fluctuations and spatial distribution fluctuations within the time window of the current event based on the event development stage, and finally generate a situation assessment value for the time series matrix of network node features. The present invention proposes a spatio-temporal situation awareness assessment scheme for network risks. This scheme can comprehensively and real-time capture the dynamic changes of each node in the network in the spatio-temporal dimension, thereby greatly improving the accuracy of network abnormal state detection. At the same time, by introducing a dynamic attenuation mechanism, the impact of historical events is reasonably weighed to ensure that the evaluation results are more timely and forward-looking. In addition, the scheme finely quantifies the abnormal states and their spatial distribution fluctuations in adjacent time windows, providing a solid scientific data support for network security risk assessment. In summary, through multi-dimensional comprehensive evaluation, this technical method not only significantly improves the sensitivity and accuracy of network risk monitoring, but also effectively reduces the false alarm rate, providing an efficient and intelligent solution for network security supervision. Brief Description of the Drawings
[0105] Figure 1 It is a flowchart of the method of the present invention. Detailed Embodiments
[0106] The spatio-temporal situation awareness assessment method for network risks includes the following steps:
[0107] 1), Generate a time series matrix of network node features
[0108] Within each time window, sample the state values of all nodes in the network system to form a node state value vector. Through continuous sampling processes, generate a time series matrix Z a:b of network node features, and the specific form is as follows:
[0109]
[0110] where q is the number of nodes in the network system, and p is the number of time windows within the time interval [a, b]; z i,t represents the state value of the i-th node in the t-th time window; the i-th row of the matrix z i,: = [z i,1 , z i,2 , …, z i,p represents the state values of the i-th node in m consecutive time windows; the t-th column of the matrix z :,t = [z 1,t , z 2,t , …, z n,t T represents the state values of all nodes in the t-th time window.
[0111] 2), perform preprocessing for abnormal event detection on the time series matrix of network node features;
[0112] (1) Use the state values of all nodes within the time window to represent the network state value of the current time window
[0113] f i = max(z i,1 , z i,2 , …, z i,q ), i ∈ [1, p]
[0114] where: f i is the network state value of the i-th time window.
[0115] (2) Abnormal event determination condition
[0116] When the network state value of each time window within a certain consecutive time window exceeds the preset threshold θ, and the length of the consecutive time window exceeds the minimum threshold ζ, it is determined as an abnormal event ev i . The determination condition is as follows:
[0117] f t > θ and
[0118] where: f t represents the network state value within the t-th time window; t istart and t iend respectively represent the start and end time windows of the abnormal event ev i ; θ is the preset state value threshold; ζ is the minimum number of consecutive time windows for the abnormal event.
[0119] (3) Abnormal event detection preprocessing algorithm
[0120] Event start: When the network status value first exceeds the threshold θ, mark the start time of the event.
[0121] Event end: If the network status value drops below the threshold θ again and the duration of the abnormal event reaches the minimum threshold ζ, this time period is marked as the historical abnormal event time window.
[0122] Historical abnormal event output: Once the historical abnormal event is identified, the algorithm will output the start and end times of all detected historical abnormal events.
[0123] Current abnormal event: If the network status value in the last time window exceeds the threshold θ, it is considered that the abnormal event has not ended completely, indicating that the network status is still abnormal. Such an abnormal event is regarded as the current abnormal time.
[0124] The set of abnormal events EV identified within the time interval [a, b] a:b Denoted as: EV a:b = {ev1, ev2, …, ev r}, where r is the total number of abnormal events identified within the time interval [a, b]. The event set {ev1, ev2, …, ev r-1} is the historical abnormal event, and each event ev i contains its complete event window where t istart is the start time window of event ev i ; t iend is the end time window of event ev i . e r is the current abnormal event, containing its start time window t rstart .
[0125] 3) Calculate the importance of network nodes based on eigenvector centrality;
[0126] (1) Construct the adjacency matrix Given a network Ne = (V, E), where V and E represent the set of nodes and the set of edges respectively. First, construct the adjacency matrix B of the network. For any nodes i, j ∈ V, if there is an edge between node i and node j, then B ij = 1; otherwise B ij = 0.
[0127] (2) Calculate the eigenvalues and eigenvectors Perform eigenvalue decomposition on the adjacency matrix B to obtain its set of eigenvalues and the corresponding set of eigenvectors {O k}. Among them, the principal eigenvector O max is the eigenvector corresponding to the largest eigenvalue .
[0128] (3) Feature vector normalization
[0129] To ensure that the node importance values are non - negative and sum to 1, for each component O of the principal eigenvector max perform absolute value normalization to obtain the eigenvector centrality of node v max,i : i
[0130]
[0131] 4), Calculate the feature difference values of abnormal nodes in adjacent time windows;
[0132] (1) Construct sets of abnormal nodes in adjacent time windows
[0133] Construct sets of abnormal nodes in adjacent time windows as and where: X t-1 represents the set of all abnormal nodes whose status values exceed the threshold in the (t - 1)-th time window within the time interval [a, b]; X t represents the set of all abnormal nodes whose status values exceed the threshold in the t-th time window within the time interval [a, b]; i represents the hierarchical number of the node in the network topology structure, starting from the top - most layer, numbered from top to bottom, with a value range of 1, 2, …; j represents the number within the layer of the node, numbered from left to right in sequence, with a value range of 1, 2, …; u represents the number of the corresponding parent node of the node within its layer.
[0134] Since the sets of abnormal nodes in the two consecutive time windows may be different, considering different difference situations, the method for constructing the set of differences in abnormal node status changes is as follows:
[0135] If the indices of nodes and are exactly matched, it indicates the change in the status value of the same node in different time windows. The change amount is calculated as:
[0136]
[0137] If node h i,j ∈X t but does not belong to X t-1 , it indicates that this node is a newly added abnormal node. The change amount of its illegal quantity is calculated as:
[0138]
[0139] If node g i,j ∈X t-1 but does not belong to X, it indicates that this node is a disappearing abnormal node. The change amount of its illegal quantity is calculated as:
[0140]
[0141] Finally, obtain the set of differences in the state changes of abnormal nodes:
[0142]
[0143] Among them, represents the difference in node state values, and the indices i, j, k describe the position information of the node in the network topology.
[0144] (2) Calculate the state changes of abnormal nodes in adjacent time windows
[0145] Define the abnormal state change amount ΔSA t as:
[0146]
[0147] Among them: represents the difference in the state of abnormal nodes in the t-th time window compared to the (t - 1)-th time window; represents the importance of the abnormal nodes that cause the state difference.
[0148] 5) Calculate the difference value of the spatial distribution of abnormal nodes in adjacent time windows;
[0149] (1) Define the spatial domain
[0150] In this paper, the abnormal nodes that can be connected through control nodes are defined as a spatial domain. Each spatial domain formed by the nodes in X t through the control nodes is denoted as d t_i , where t represents the time window serial number within the time interval [a, b], and i is the domain index number in the set of spatial domains. Each domain d t_i contains a group of nodes that can be connected to each other through control nodes.
[0151] If there are multiple spatial domains in the abnormal node set X t that can be connected to each other through intermediate nodes, these spatial domains form a set of spatial domains, denoted as D t , denoted as:
[0152]
[0153] Among them: n is the number of spatial domains formed by the abnormal node set X t that can be connected to each other through intermediate nodes, and d t_i is the i-th spatial domain in the abnormal node set X t .
[0154] (2) Evaluate the situation impact of the spatial domain
[0155] The more nodes there are in the spatial domain, the wider the abnormal distribution is, and the greater the abnormal impact is. Based on the above considerations, this paper proposes the situation impact evaluation value Es(d t_i ) of the spatial domain, and the calculation formula is as follows
[0156]
[0157] where: is the sum of the importance of all nodes in the spatial domain, expressed as the sum of the importance measures of all nodes v in the domain; E(|d t_i |) is the influence function of the number of abnormal nodes on the situation value of the spatial domain, defined as:
[0158]
[0159] where |d t_i | is the number of the i-th in-domain node in the abnormal node set X t , is a constant that controls the growth rate of the number of nodes. As the number of nodes increases, the spatial situation value increases exponentially; β1 and β2 are weight coefficients that respectively control the contributions of node importance and the number of nodes to the influence degree.
[0160] (3) Define four spatial distributions of abnormal nodes
[0161] Spatial single-point abnormal situation When |X t | = 1, it indicates that there is only one abnormal node state in the node state space distribution matrix X t corresponding to the t-th time window. In this situation, since there is only a single abnormal node, its impact on the overall system situation is weak.
[0162] Spatial scattered-point abnormal situation When |X t | > 1, and any two nodes i and j in the abnormal node set X t are not adjacent, these abnormal elements are in an isolated state in the spatial distribution. This situation often appears in the early development stage or the end stage of an event. Due to the isolated distribution of abnormal points in space, the impact on the overall system situation is limited.
[0163] Spatial single-domain abnormal situation
[0164] When |X t | > 1, and the abnormal node set X tAll elements in it can be interconnected through intermediate nodes to form an interconnected spatial domain. In this situation, the abnormal nodes belong to the same spatial domain, are connected to each other in terms of spatial distribution, and show the characteristic of local concentrated distribution. This usually occurs in the outbreak stage of abnormal events, when the impact on the overall situation of the system is significantly aggravated.
[0165] Spatial multi-domain abnormal situation
[0166] If |X t | > 1, and all elements in the abnormal node set X t can form multiple interconnected spatial domains through intermediate nodes, and the abnormalities in multiple domains show concurrent distribution, indicating that the abnormal impact has spread to multiple domains, and the abnormal event enters the rapid development stage, having a serious abnormal impact on the overall situation of the system.
[0167] (4) Quantify the impact of the spatial situation
[0168] Quantification value of the spatial distribution of single-point abnormal situation or spatial scattered-point abnormal situation
[0169] For the current time window t, if its spatial distribution is a single-point abnormal situation or a spatial scattered-point abnormal situation, the quantification value of the spatial distribution is the sum of the importance of all abnormal nodes, and the calculation formula is as follows:
[0170]
[0171] Among them, Im(v) is the importance measurement value of node v, and X t is the abnormal node set of the t-th time window.
[0172] Quantification value of the spatial distribution of single-domain abnormal situation or multi-domain abnormal situation
[0173] For the current time window t, if its spatial distribution is a single-domain abnormal situation or a multi-domain abnormal situation, when quantifying the spatial distribution impact, consider the importance of the domain and the importance of other abnormal scattered points within the current window, and the calculation formula is as follows:
[0174]
[0175] where is the importance of all abnormal scattered points within the t-th time window; is the situation impact evaluation value of all spatial domains within the t-th time window.
[0176] (5) Spatial distribution change
[0177] Define ΔSP t to represent the abnormal node set X of the t-th time window in the node state time series matrix Z a:b int Compared with the set of abnormal nodes X in the (t - 1)-th time window t-1 The corresponding change in spatial distribution, which is used to characterize the trend change characteristics of the spatial distribution.
[0178] ΔSP t = SP t - SP t-1
[0179] 6), Based on the dynamic decay rate that is positively correlated with the time distance between the evaluation window and the current window, conduct a trend assessment on the feature fluctuations and spatial distribution fluctuations within the time window of historical abnormal events
[0180] Based on the dynamic decay rate that is positively correlated with the time distance between the evaluation window and the current window, the calculation formula for conducting a trend assessment on the feature fluctuations and spatial distribution fluctuations within the time window of historical abnormal events is as follows:[[]]
[0181]
[0182] Among them, T represents the set of time windows of the historical abnormal event set {ev1, ev2,..., ev k-1}; ΔSA τ represents the change in abnormal state between the τ-th time window and the previous time window; ΔSP τ : represents the change in spatial distribution between the τ-th time window and the previous time window; ω1 and ω2 are the weight coefficients of the state abnormal change and the spatial distribution change respectively; Time decay function, used to control the decay rate.
[0183] 7), Based on different stages of event development, conduct a trend assessment on the feature fluctuations and spatial distribution fluctuations within the time window of the current abnormal event
[0184] (1) Introduce a trend determination window, analyze the dynamic changes of the set of abnormal state nodes X t within the trend determination window, and the linear fitting slope k t , as the determination basis for different event development stages where the current time window is located.
[0185] Given a set of time windows {t - n, t - n + 1,..., t}, the number of abnormal state nodes in each time window i is Nu i = |X i |, and the calculation formula for the slope K t is as follows:[[]]
[0186]
[0187] Among them, n represents the size of the trend determination window, and are the average values of the time window index and the number of abnormal nodes respectively.
[0188] Based on the value of the slope k t the development stage of the abnormal event is divided into the following three parts:
[0189] Situation increasing stage: k t > ξ, that is, the slope is positive and greater than the set threshold;
[0190] Situation decreasing stage: k t < - ξ, that is, the slope is negative and less than the set threshold;
[0191] Situation stable stage: - ξ ≤ k t ≤ ξ.
[0192] (2) The formula for evaluating the situation of the current abnormal event is as follows:
[0193]
[0194] where T‘ represents the time window set of the current abnormal event ev k ; ; ΔSA τ represents the change in the abnormal state between the τ - th time window and the previous time window; ΔSP τ : represents the change in the spatial distribution between the τ - th time window and the previous time window; ω1 and ω2 are the weight coefficients of the state abnormal change and the spatial distribution change respectively; J(k τ ) is an adjustment function used to dynamically adjust the situation weight of each time window according to the value of the slope k τ The form is:
[0195]
[0196] where: γ1 > 1 is the influence coefficient of the situation increasing stage, used to strengthen the evaluation weight of this stage; 0 < γ2 < 1 is the influence coefficient of the situation decreasing stage, used to weaken the evaluation weight of this stage; γ3 = 1 is the influence coefficient of the situation stable stage, which has no influence on the evaluation weight of this stage.
[0197] (3) The formula for calculating the risk assessment value of the final network node feature time - series matrix Z a:b is as follows:
[0198] S(Z a:b ) = S e (Z a:b ) + S′ e (Z a:b )
[0199] where, S e(Z a:b ) is the situation assessment value of historical abnormal events, S′ e (Z a:b ) is the situation assessment value of current abnormal events.
Claims
1. A method for assessing network risk in space and time, characterized in that: The steps are: (Step 1), collecting network host node status data and generating a network node characteristic timing matrix; (Step 2) performing abnormal event detection preprocessing on the network node feature time series matrix to obtain the historical abnormal event node feature time series matrix and the current abnormal event node feature time series matrix; (Step 3), calculating the importance of network nodes based on eigenvector centrality; (Step 4), calculating the feature difference values of abnormal nodes in adjacent time windows; (Step 5), calculating the spatial distribution difference value of abnormal nodes in adjacent time windows; (Step 6) Based on the dynamic decay rate of the positive correlation between the time distance between the evaluation window and the current window, a situation assessment is performed on the characteristic fluctuations and spatial distribution fluctuations within the time window of the historical abnormal event; (Step 7) Based on the different stages of the event development, a situation assessment is performed on the characteristic fluctuations and spatial distribution fluctuations within the time window of the current abnormal event.
2. The method for evaluating network risk spatiotemporal situational awareness according to claim 1, characterized in that: In the step 1), the specific method is: Assume that there are q nodes in the network system, define the time interval [a, b] and divide it into multiple time windows with equal time intervals. The length of each time window is Δφ. Then the total number of time windows is: In each time window, the state values of all nodes in the network system are sampled to form a node state value vector. Through the continuous sampling process, the network node feature time series matrix Z is generated. a:b : Where q is the number of nodes in the network system, p is the number of time windows in the time interval [a, b]; z i,t represents the state value of the i-th node in the t-th time window; the i-th row z of the matrix i,: =[z i,1 ,z i,2 ,…,z i,p ] represents the state value of the ith node in m continuous time windows; the tth column z of the matrix :,t =[z 1,t ,z 2,t ,…,z n,t ] T Represents the state value of all nodes in the tth time window.
3. The method for assessing network risk in time and space according to claim 1, characterized in that: In the step 2), the specific method is: (2.1) Use the state values of all nodes in the time window to represent the network state value of the current time window f i =max(z i,1 ,z i,2 ,…,z i,q ),i∈[1,p] Where: f i is the network status value of the i-th time window; (2.2) Abnormal event determination conditions When the network status value of each time window in a continuous time window exceeds the preset threshold θ, and the length of the continuous time window exceeds the minimum threshold ζ, it is determined to be an abnormal event ev i , the judgment conditions are as follows: and Where: f t Represents the network status value in the tth time window; and Respectively represent abnormal events ev i The start and end time windows of the abnormal event; θ is the preset state value threshold; ζ is the minimum duration window number of the abnormal event; (2.3) Abnormal event detection preprocessing algorithm Event start: When the network state value exceeds the threshold θ for the first time, the start time of the event is marked; Event end: If the network status value is lower than the threshold θ again, and the duration of the abnormal event reaches the minimum threshold ζ, the time period is marked as the historical abnormal event time window; Historical abnormal event output: Once a historical abnormal event is identified, the algorithm will output the start and end time of all detected historical abnormal events; Current abnormal event: If the network status value of the last time window exceeds the threshold θ, it is considered that the abnormal event has not yet completely ended, indicating that the network status is still in an abnormal state. Such abnormal events are regarded as the current abnormal time; The set of abnormal events EV identified in the time interval [a,b] a:b Expressed as: EV a:b ={ev1,ev2,…,ev r }, where r is the total number of abnormal events identified in the time interval [a,b], and the event set {ev1,ev2,…,ev r-1 } is a historical abnormal event, each event ev i Contains its complete event window where t istart For event i The start time window of iend For event i The end time window of e r is the current abnormal event, including the start time window t rstart .
4. The method for assessing network risk in time and space according to claim 1, characterized in that: In the step 3), the specific method is: The importance of each node in the network is calculated using a method based on eigenvector centrality. Eigenvector centrality measures the global influence of a node in the network through the main eigenvector of the network adjacency matrix. The calculation process is as follows: (3.1) Constructing the adjacency matrix Given a network Ne = (V, E), where V and E represent the node set and edge set respectively, we first construct the adjacency matrix B of the network; for any node i, j ∈ V, if there is an edge between node i and node j, then B ij =1; otherwise B ij =0; (3.2) Calculate the eigenvalues and eigenvectors and perform eigenvalue decomposition on the adjacency matrix B to obtain its eigenvalue set And the corresponding eigenvector set {O k }; Among them, the main eigenvector O max is the maximum eigenvalue The corresponding eigenvector; (3.3) Eigenvector normalization To ensure that the node importance value is non-negative and the sum is 1, the main eigenvector O max Each component O max,i Perform absolute value normalization to obtain node v i The eigenvector centrality of :
5. The method for predicting the number of illegal online transactions based on the spatiotemporal characteristics of data according to claim 1 is characterized in that: In the step 4), the specific method is: (4.1) Constructing a set of abnormal nodes in adjacent time windows The abnormal node sets for constructing adjacent time windows are: and Where: X t-1 represents the set of all abnormal nodes whose state values exceed the threshold in the t-1th time window within the time interval [a, b]; X t represents the set of all abnormal nodes whose state values exceed the threshold in the t-th time window within the time interval [a, b]; i represents the hierarchical number of the node in the network topology, starting from the top layer, numbered from top to bottom, with a value range of 1, 2, ...; j represents the number of the node in the layer, numbered from left to right, with a value range of 1, 2, ...; u represents the number of the node's corresponding parent node in its layer; Since there is a probability that the abnormal node sets in the two time windows are different, considering different difference situations, the method for constructing the abnormal node state change difference set is as follows: If the node and The indexes of the nodes are completely matched, indicating that the state value of the same node changes in different time windows. The change amount is calculated as: If the node h i,j ∈X t Not X t-1 , indicating that the node is a newly added abnormal node, and the change in the number of violations is calculated as: If the node g i,j ∈X t-1 It does not belong to X, indicating that the node is a disappeared abnormal node, and the change in the number of violations is calculated as: Get the abnormal node state change difference set: in, Indicates the difference in node status values, and the indexes i, j, and k describe the location information of the node in the network topology; (4.2) Calculate the abnormal node state changes in adjacent time windows Definition of abnormal state change ΔSA t for: in: Indicates the difference in abnormal node status between the t-th time window and the t-1-th time window; Indicates the importance of the abnormal node that caused the state difference.
6. The method for predicting the number of illegal online transactions based on the spatiotemporal characteristics of data according to claim 1 is characterized in that: In the step 5), the specific method is: (5.1) Define the spatial domain The abnormal nodes that can be connected through the control nodes are defined as a spatial domain, each of which is represented by X t The spatial domain formed by the middle node through the control node is denoted as d t_i , where t represents the time window number in the time interval [a, b], i is the domain index number in the spatial domain set; each domain d t_i It consists of a set of nodes that can be connected to each other through a control node; If in the abnormal node set X t There are multiple spatial domains that can be connected to each other through control intermediate nodes. These spatial domains constitute a spatial domain set, denoted as D t , expressed as: Where: n is the abnormal node set X t The number of spatial domains that can be connected to each other through intermediate nodes, d t_i is the abnormal node set X t The i-th spatial domain in ; (5.2) Assessing situational impact in the space domain The more nodes there are in the spatial domain, the wider the abnormal distribution is, the greater the impact of the abnormality is, and the situation impact assessment value Es(d t_i )for: in: is the sum of the importance of all nodes in the spatial domain, expressed as the sum of the importance measures of all nodes v in the domain; E(|d t_i |) is the influence function of the number of abnormal nodes on the spatial domain situation value, which is defined as: where |d t_i | is the abnormal node set X t The number of nodes in the ith domain, is a constant that controls the growth rate of the number of nodes. As the number of nodes increases, the spatial situation value increases exponentially. β1 and β2 are weight coefficients that control the contribution of node importance and node number to influence, respectively. (5.3) Define four types of abnormal node spatial distribution (5.3.1) Abnormal situation of a single point in space: When |X t When |=1, it indicates that the node state space distribution matrix X corresponding to the t-th time window t In this situation, only one node is abnormal. Since there is only one abnormal node, its impact on the overall situation of the system is weak. (5.3.2) When the spatial scattered point is abnormal, |X t |>1, and the abnormal node set X t Any two nodes i and j in the combination are not adjacent. These abnormal elements are isolated in spatial distribution. This situation appears in the early development stage of the event or at the end of the event. Since the distribution of abnormal points in space is isolated, the impact on the overall situation of the system is limited. (5.3.3) Abnormal situation in a single spatial domain When |X t |>1, and the abnormal node set X t All elements in the system can be interconnected through intermediate nodes to form an interconnected spatial domain. Under this situation, abnormal nodes belong to the same spatial domain and are interconnected in spatial distribution, showing the characteristics of local concentrated distribution. This situation occurs at the outbreak stage of abnormal events, which aggravates the impact on the overall situation of the system. (5.3.4) Abnormal situation in multiple spatial domains If |X t |>1, and the abnormal node set X t All elements in the can form multiple interconnected spatial domains through intermediate nodes. The anomalies in multiple domains are distributed concurrently, indicating that the impact of the anomaly has spread to multiple domains. The abnormal event has entered a rapid development stage, which has an abnormal impact on the overall situation of the system. (5.4) Quantifying the impact of spatial situation (5.4.1) Quantified value of spatial distribution of single point abnormal situation or spatial scattered point abnormal situation For the current time window t, if its spatial distribution is a single-point abnormal situation or a spatial scattered point abnormal situation, the spatial distribution quantification value is the sum of the importance of all abnormal nodes, and the calculation formula is as follows: Among them, Im(v) is the importance metric of node v, X t is the set of abnormal nodes in the tth time window. (5.4.2) Quantified value of spatial distribution of abnormal situation in a single space domain or abnormal situation in multiple space domains For the current time window t, if its spatial distribution is a single-domain abnormal situation or a multi-domain abnormal situation, the importance of the domain and the importance of other abnormal scattered points in the current window are considered when quantifying the impact of the spatial distribution. The calculation formula is as follows: That is the importance of all abnormal scattered points in the tth time window; is the situation impact assessment value of all spatial domains in the t-th time window; (5.5) Spatial distribution changes Defining ΔSP t Represents the node state timing matrix Z a:b The abnormal node set X in the tth time window t Compared with the abnormal node set X in the t-1th time window t-1 The corresponding spatial distribution change is used to characterize the trend change characteristics of spatial distribution; ΔSP t =SP t -SP t-1 。 7. The method for assessing network risk in time and space according to claim 1, characterized in that: The specific method of step 6) is as follows: Based on the dynamic decay rate of the positive correlation between the time distance between the evaluation window and the current window, the situation assessment calculation formula for the characteristic fluctuation and spatial distribution fluctuation within the time window of historical abnormal events is as follows: Where T represents the set of historical abnormal events {ev1,ev2,…,ev k-1 } time window set; ΔSA τ Indicates the abnormal state change between the τth time window and the previous time window; ΔSP τ : represents the spatial distribution change between the τth time window and the previous time window; ω1 and ω2 are the weight coefficients of abnormal state change and spatial distribution change respectively; The time decay function, Used to control the decay rate.
8. The method for evaluating network risk spatiotemporal situational awareness according to claim 1, characterized in that: The specific method of step 7) is as follows: (7.1) Introduce the situation judgment window and analyze the abnormal state node set X in the situation judgment window t Dynamic changes of linear fitting slope k t , as the basis for determining the different development stages of events in the current time window. Given a set of time windows {tn, t-n+1, …, t}, the number of abnormal nodes in each time window i is Nu i =|X i |, slope K t The calculation formula is: Among them, n represents the size of the situation judgment window, and are the average values of the time window index and the number of abnormal nodes, respectively; Based on the slope k t The value of, the abnormal event development stage is divided into the following three parts: Situation increase stage: k t >ξ, that is, the slope is positive and greater than the set threshold; Declining stage: k t <-ξ, that is, the slope is negative and less than the set threshold; Stable stage: -ξ≤k t ≤ξ; (7.2) The calculation formula for the current abnormal event situation assessment is as follows: Among them, T' represents the current abnormal event ev k A time window set; ΔSA τ Indicates the abnormal state change between the τth time window and the previous time window; ΔSP τ : represents the spatial distribution change between the τth time window and the previous time window; ω1 and ω2 are the weight coefficients of abnormal state change and spatial distribution change respectively; J(k τ ) is the adjustment function, which is used to adjust the slope k τ The value of dynamically adjusts the situation weight of each time window, which is in the form of: Among them: γ1>1 is the influence coefficient of the stage of increasing situation, which is used to strengthen the evaluation weight of this stage; 0<γ2<1 is the influence coefficient of the stage of decreasing situation, which is used to weaken the evaluation weight of this stage; γ3=1 is the influence coefficient of the stage of stable situation, which has no effect on the evaluation weight of this stage; (7.3) The final network node feature time series matrix Z a:b The risk assessment value is calculated as follows: S(Z a:b )=S e (Z a:b )+S′ e (Z a:b ) Among them, S e (Z a:b ) is the situation assessment value of historical abnormal events, S′ e (Z a:b ) is the situation assessment value of the current abnormal event.
Citation Information
Cited By
Trusted data space dynamic risk assessment method and system based on space-time sequence
CN121309193A