Network security situation awareness and early warning method and system
By using prediction models in the network security situation awareness and early warning system to analyze the equipment communication data of the target network, determine the hazard communication information and equipment information, and calculate the network hazard parameters, the problem of low accuracy in network risk assessment in the prior art is solved, and more accurate and timely risk identification and protection are achieved.
Patent Information
- Application Number
- CN202510590130.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-05-08
AI Technical Summary
The prior art lacks an effective prediction matching mechanism when evaluating communication data and equipment information of large networks, resulting in low accuracy of the overall risk assessment results of the network, and the problems of large risks of underreport and low efficiency.
By acquiring the multiple device communication data of the target network within a preset historical time period, determining the hazard communication information based on the first prediction model, determining the hazard equipment information based on the second prediction model, and computing the network hazard parameters through the matching results to evaluate the potential risk of the network being penetrated or being attacked.
The accurate assessment of the potential risks of the target network has been achieved, the timeliness and accuracy of network security risks has been improved, and the network security protection effect has been strengthened.
Smart Images

Figure CN120223431A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular, to a network security situation awareness and early warning method and system. Background Art
[0002] In the prior art, network security risk assessment usually relies on fixed rules or historical attack samples for detection, mainly by setting static thresholds or simple pattern recognition to discover abnormal communication behaviors or abnormal devices. However, with the continuous complexity of network structures and attack methods, especially the emergence of large-scale network penetration attack methods, it is difficult to identify potential penetration or attack risks in a timely and accurate manner relying solely on single-dimensional data analysis. In addition, when analyzing communication data and device information in a large-scale network, the prior art often lacks an effective prediction and matching mechanism, resulting in a low accuracy rate of the overall network risk assessment result, and problems such as a large risk of missed reports and low efficiency. It can be seen that the prior art has defects and urgently needs to be solved. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a network security situation awareness and early warning method and system, which can accurately evaluate the potential risks of a target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect.
[0004] To solve the above technical problem, in the first aspect of the present invention, a network security situation awareness and early warning method is disclosed, and the method includes:
[0005] Obtain multiple device communication data of a target network within a preset historical time period;
[0006] Based on a first prediction model, determine dangerous communication information according to the multiple device communication data;
[0007] Based on a second prediction model, determine dangerous device information according to the multiple device communication data;
[0008] Based on the matching result between the dangerous communication information and the dangerous device information, determine the network danger parameter of the target network; the network danger parameter is used to indicate the danger possibility of the target network corresponding to being penetrated or attacked.
[0009] As an optional implementation manner, in the first aspect of the present invention, the determining dangerous communication information according to the multiple device communication data based on the first prediction model includes:
[0010] Input each device communication data into the trained first prediction model to obtain a first danger type and a first danger probability corresponding to each device communication data;
[0011] Based on the predicted sending time point, divide all the device communication data into multiple data sets;
[0012] Calculate the average value of the first hazard probabilities corresponding to all the device communication data in each data set to obtain the first set hazard probability corresponding to each data set;
[0013] According to the corresponding first set hazard probability, correct the first hazard probability corresponding to each device communication data to obtain the first corrected probability corresponding to each device communication data;
[0014] Determine all the device communication data with the first corrected probability greater than the first probability threshold and the corresponding first hazard types as hazardous communication information.
[0015] As an optional implementation manner, in the first aspect of the present invention, the step of dividing all the device communication data into multiple data sets based on the predicted sending time point includes:
[0016] For each device communication data, determine whether there is a sending time point in the data content of the device communication data to obtain a first determination result;
[0017] When the first determination result is yes, determine the existing sending time point as the predicted sending time point of the device communication data;
[0018] When the second determination result is no, input all the time-related information in the data content of the device communication data into the trained sending time point prediction model to obtain the predicted sending time point of the device communication data;
[0019] Based on the clustering grouping algorithm, divide all the device communication data into multiple data sets according to the predicted sending time point; wherein, the time difference between the predicted sending time points of any two device communication data in each data set is less than the time difference threshold; the time difference threshold is proportional to the average value of the time differences between the predicted sending time points of all the device communication data.
[0020] As an optional implementation manner, in the first aspect of the present invention, the step of correcting the first hazard probability corresponding to each device communication data according to the corresponding first set hazard probability to obtain the first corrected probability corresponding to each device communication data includes:
[0021] For each data set, calculate the first probability difference between the first set hazard probability corresponding to the data set and the first probability mean parameter; the first probability mean parameter is the average value of the first set hazard probabilities of all the data sets;
[0022] Calculate a first correction weight proportional to the first probability difference;
[0023] Calculate the product of the first hazard probability corresponding to each device communication data in the data set and the first correction weight to obtain a first corrected probability corresponding to each device communication data in the data set.
[0024] As an optional implementation manner, in the first aspect of the present invention, the determining of the hazardous device information based on the second prediction model according to the multiple device communication data includes:
[0025] Determine device-related information in the data content of all the device communication data to obtain multiple communication device information; the device-related information is a sending device, a receiving device, a relay device, or a firewall device;
[0026] For each of the communication device information, based on the communication of the device corresponding to the communication device information and / or the communication with the gateway device of the target network, obtain the device parameter data and the device historical communication data corresponding to the communication device information;
[0027] Input the device parameter data and the device historical communication data corresponding to the communication device information into the trained second prediction model to obtain a second hazard type and a second hazard probability corresponding to the communication device information;
[0028] Determine multiple hazardous communication devices from all the communication device information based on the second hazard probability;
[0029] Determine all the hazardous communication devices and the corresponding second hazard types as the hazardous device information.
[0030] As an optional implementation manner, in the first aspect of the present invention, the determining of multiple hazardous communication devices from all the communication device information based on the second hazard probability includes:
[0031] Based on a clustering grouping algorithm, group all the communication device information to obtain multiple device sets; wherein, the similarity between the device parameter data corresponding to any two of the communication device information in each device set is greater than a similarity threshold;
[0032] For each device set, calculate the average value of the second hazard probabilities corresponding to all the communication device information in the device set to obtain a second set hazard probability corresponding to the device set;
[0033] Calculate a second probability difference between the second set of risk probabilities and the second probability mean parameter; the second probability mean parameter is the average of the second set of risk probabilities of all the device sets.
[0034] Calculate a second correction weight proportional to the second probability difference.
[0035] Calculate the product of the second risk probability corresponding to each communication device information in the device set and the second correction weight to obtain a second corrected probability corresponding to each communication device information in the device set.
[0036] Determine the communication device information with the second corrected probability greater than the second probability threshold as the risky communication device.
[0037] As an optional implementation manner, in the first aspect of the present invention, both the first prediction model and the second prediction model are CNN network models. First, they are jointly trained based on a common training data set including multiple training device communication data and corresponding device parameter annotations and risk annotations to obtain a basic model, and then the first prediction model and the second prediction model are respectively trained based on corresponding fine-tuning training data sets for the basic model.
[0038] As an optional implementation manner, in the first aspect of the present invention, determining the network risk parameter of the target network based on the matching result between the risky communication information and the risky device information includes:
[0039] Calculate the type similarity and device similarity between the risky communication information and the risky device information.
[0040] Calculate the product of the type similarity and the device similarity to obtain a matching degree parameter.
[0041] Calculate the average of the differences between the prediction accuracies of the first prediction model and the second prediction model for the same validation data set in the fine-tuning stage to obtain a prediction difference degree parameter.
[0042] Calculate a risk reference value proportional to the prediction difference degree parameter.
[0043] Calculate the difference between the matching degree parameter and the risk reference value to obtain the network risk parameter of the target network.
[0044] The second aspect of the embodiments of the present invention discloses a network security situation awareness and warning system, and the system includes:
[0045] An acquisition module, configured to acquire multiple device communication data of a target network within a preset historical time period.
[0046] A first prediction module, configured to determine dangerous communication information based on a first prediction model according to the multiple device communication data;
[0047] A second prediction module, configured to determine dangerous device information based on a second prediction model according to the multiple device communication data;
[0048] A matching module, configured to determine a network danger parameter of the target network based on a matching result between the dangerous communication information and the dangerous device information; the network danger parameter is used to indicate the danger possibility of being penetrated or attacked corresponding to the target network.
[0049] As an optional implementation manner, in the second aspect of the present invention, the specific manner in which the first prediction module determines dangerous communication information based on a first prediction model according to the multiple device communication data includes:
[0050] Input each of the device communication data into a trained first prediction model to obtain a first danger type and a first danger probability corresponding to each of the device communication data;
[0051] Based on the expected sending time point, divide all the device communication data into multiple data sets;
[0052] Calculate the average value of the first danger probabilities corresponding to all the device communication data in each data set to obtain a first set danger probability corresponding to each data set;
[0053] According to the corresponding first set danger probability, correct the first danger probability corresponding to each device communication data to obtain a first corrected probability corresponding to each device communication data;
[0054] Determine all the device communication data with the first corrected probability greater than a first probability threshold and the corresponding first danger type as dangerous communication information.
[0055] As an optional implementation manner, in the second aspect of the present invention, the specific manner in which the first prediction module divides all the device communication data into multiple data sets based on the expected sending time point includes:
[0056] For each device communication data, determine whether there is a sending time point in the data content of the device communication data to obtain a first determination result;
[0057] When the first determination result is yes, determine the existing sending time point as the expected sending time point of the device communication data;
[0058] When the second judgment result is negative, all time-related information in the data content of the device communication data is input into the trained sending time point prediction model to obtain the predicted sending time point of the device communication data;
[0059] Based on the clustering grouping algorithm, all the device communication data is divided into multiple data sets according to the predicted sending time point; wherein, the time difference between any two device communication data in each data set is less than the time difference threshold; the time difference threshold is proportional to the average value of the time differences between the predicted sending time points of all the device communication data.
[0060] As an optional implementation manner, in the second aspect of the present invention, the specific manner in which the first prediction module corrects the first risk probability corresponding to each device communication data according to the corresponding first set risk probability to obtain the first corrected probability corresponding to each device communication data includes:
[0061] For each data set, calculate the first probability difference between the first set risk probability corresponding to the data set and the first probability mean parameter; the first probability mean parameter is the average value of the first set risk probabilities of all the data sets;
[0062] Calculate the first correction weight proportional to the first probability difference;
[0063] Calculate the product of the first risk probability corresponding to each device communication data in the data set and the first correction weight to obtain the first corrected probability corresponding to each device communication data in the data set.
[0064] As an optional implementation manner, in the second aspect of the present invention, the specific manner in which the second prediction module determines the dangerous device information based on the second prediction model according to the multiple device communication data includes:
[0065] Determine device-related information in the data content of all the device communication data to obtain multiple communication device information; the device-related information is a sending device, a receiving device, a relay device or a firewall device;
[0066] For each communication device information, based on the communication of the device corresponding to the communication device information and / or the communication with the gateway device of the target network, obtain the device parameter data and the device historical communication data corresponding to the communication device information;
[0067] Input the device parameter data and the device historical communication data corresponding to the communication device information into the trained second prediction model to obtain the second dangerous type and the second risk probability corresponding to the communication device information;
[0068] Determine multiple dangerous communication devices from all the communication device information based on the second danger probability;
[0069] Determine all the dangerous communication devices and the corresponding second danger types as dangerous device information.
[0070] As an optional implementation manner, in the second aspect of the present invention, the specific manner in which the second prediction module determines multiple dangerous communication devices from all the communication device information based on the second danger probability includes:
[0071] Group all the communication device information based on a clustering grouping algorithm to obtain multiple device sets; wherein, the similarity between the device parameter data corresponding to any two communication device information in each device set is greater than a similarity threshold;
[0072] For each device set, calculate the average value of the second danger probabilities corresponding to all the communication device information in this device set to obtain the second set danger probability corresponding to this device set;
[0073] Calculate the second probability difference between the second set danger probability and the second probability mean parameter; the second probability mean parameter is the average value of the second set danger probabilities of all the device sets;
[0074] Calculate a second correction weight proportional to the second probability difference;
[0075] Calculate the product of the second danger probability corresponding to each communication device information in this device set and the second correction weight to obtain the second corrected probability corresponding to each communication device information in this device set;
[0076] Determine the communication device information with the second corrected probability greater than the second probability threshold as a dangerous communication device.
[0077] As an optional implementation manner, in the second aspect of the present invention, both the first prediction model and the second prediction model are CNN network models. First, they are jointly trained based on a common training data set including multiple training device communication data and corresponding device parameter annotations and danger annotations to obtain a basic model, and then the basic model is respectively trained based on the corresponding fine-tuning training data sets to obtain the first prediction model and the second prediction model.
[0078] As an optional implementation manner, in the second aspect of the present invention, the specific manner in which the matching module determines the network danger parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information includes:
[0079] Calculate the type similarity and device similarity between the dangerous communication information and the dangerous device information;
[0080] Calculate the product of the type similarity and the device similarity to obtain a matching degree parameter;
[0081] Calculate the average value of the difference between the prediction accuracies of the first prediction model and the second prediction model for the same validation data set during the fine-tuning stage to obtain a prediction difference degree parameter;
[0082] Calculate a dangerous reference value proportional to the prediction difference degree parameter;
[0083] Calculate the difference between the matching degree parameter and the dangerous reference value to obtain the network dangerous parameter of the target network.
[0084] The third aspect of the present invention discloses another network security situation awareness and early warning system, and the system includes:
[0085] A memory storing executable program code;
[0086] A processor coupled to the memory;
[0087] The processor calls the executable program code stored in the memory and executes some or all of the steps in the network security situation awareness and early warning method disclosed in the first aspect of the present invention.
[0088] The fourth aspect of the present invention discloses a computer storage medium, and the computer storage medium stores computer instructions, which are used to execute some or all of the steps in the network security situation awareness and early warning method disclosed in the first aspect of the present invention when called.
[0089] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:
[0090] The present invention obtains multiple device communication data of the target network within a preset historical time period, processes the multiple device communication data based on the first prediction model to determine dangerous communication information, further processes the multiple device communication data based on the second prediction model to determine dangerous device information, and determines the network dangerous parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information, so as to accurately evaluate the potential risk of the target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0091] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0092] Figure 1 It is a schematic flowchart of a network security situation awareness and early warning method disclosed in an embodiment of the present invention.
[0093] Figure 2 It is a schematic structural diagram of a network security situation awareness and early warning system disclosed in an embodiment of the present invention.
[0094] Figure 3 It is a schematic structural diagram of another network security situation awareness and early warning system disclosed in an embodiment of the present invention. Detailed implementation manners
[0095] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0096] The terms "first", "second", etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or equipment.
[0097] Referring to "embodiment" herein means that a specific feature, structure or characteristic described in connection with the embodiment can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0098] The present invention discloses a network security situation awareness and early warning method and system. By obtaining multiple device communication data of a target network within a preset historical time period, processing the multiple device communication data based on a first prediction model to determine dangerous communication information, further processing the multiple device communication data based on a second prediction model to determine dangerous device information, and determining the network danger parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information, it is possible to accurately evaluate the potential risk of the target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect. The following will be described in detail respectively.
[0099] Embodiment 1
[0100] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a network security situation awareness and early warning method disclosed in an embodiment of the present invention. Among them, Figure 1 the described network security situation awareness and early warning method can be applied to a data processing system / data processing device / data processing server (wherein, the server includes a local processing server or a cloud processing server). As Figure 1 shown, the network security situation awareness and early warning method may include the following operations:
[0101] 101. Obtain multiple device communication data of a target network within a preset historical time period.
[0102] 102. Based on the first prediction model, determine dangerous communication information according to the multiple device communication data.
[0103] 103. Based on the second prediction model, determine dangerous device information according to the multiple device communication data.
[0104] 104. Based on the matching result between the dangerous communication information and the dangerous device information, determine the network danger parameter of the target network.
[0105] Optionally, the network danger parameter is used to indicate the danger possibility of the target network being penetrated or attacked.
[0106] It can be seen that through the above-mentioned embodiment of the invention, by obtaining multiple device communication data of a target network within a preset historical time period, processing the multiple device communication data based on the first prediction model to determine dangerous communication information, further processing the multiple device communication data based on the second prediction model to determine dangerous device information, and determining the network danger parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information, it is possible to accurately evaluate the potential risk of the target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect.
[0107] As an alternative embodiment, in the above steps, based on the first prediction model, determining the dangerous communication information according to multiple device communication data includes:
[0108] Inputting each device communication data into the trained first prediction model to obtain the first dangerous type and the first dangerous probability corresponding to each device communication data;
[0109] Based on the expected sending time point, dividing all device communication data into multiple data sets;
[0110] Calculating the average value of the first dangerous probabilities corresponding to all device communication data in each data set to obtain the first set dangerous probability corresponding to each data set;
[0111] According to the corresponding first set dangerous probability, correcting the first dangerous probability corresponding to each device communication data to obtain the first corrected probability corresponding to each device communication data;
[0112] Determining all device communication data with the first corrected probability greater than the first probability threshold and the corresponding first dangerous types as the dangerous communication information.
[0113] It can be seen that through the above alternative embodiments, through the prediction of the prediction model and the probability correction of the grouping algorithm, the accuracy and robustness of the dangerous identification of communication data can be improved, the screening efficiency and early warning effect of potential dangerous communication behaviors can be improved, the accurate assessment of the potential risks of the target network being penetrated or attacked can be assisted, the timeliness and accuracy of network security risk identification can be improved, and the network security protection effect can be strengthened.
[0114] As an alternative embodiment, in the above steps, based on the expected sending time point, dividing all device communication data into multiple data sets includes:
[0115] For each device communication data, determining whether there is a sending time point in the data content of the device communication data to obtain a first judgment result;
[0116] When the first judgment result is yes, determining the existing sending time point as the expected sending time point of the device communication data;
[0117] When the second judgment result is no, inputting all time-related information in the data content of the device communication data into the trained sending time point prediction model to obtain the expected sending time point of the device communication data;
[0118] Based on the clustering grouping algorithm, all device communication data is divided into multiple data sets according to the predicted sending time points; optionally, among them, the time difference between any two device communication data in each data set is less than the time difference threshold; the time difference threshold is proportional to the average value of the time differences between the predicted sending time points of all device communication data.
[0119] Optionally, this time-related information can be a time stamp, a communication trigger moment, or a data generation time, which is not limited in the present invention.
[0120] Optionally, this sending time point prediction model can be a convolutional neural network model, a recurrent neural network model, or a time series prediction model, which is not limited in the present invention.
[0121] It can be seen that through the above optional embodiments, the predicted sending time points are extracted or predicted according to the device communication data content, and the communication data is divided into multiple sets according to time proximity through the clustering grouping algorithm, realizing the complementation and reasonable grouping of time information, providing an accurate data basis for subsequent communication data risk identification, assisting in accurately evaluating the potential risks of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0122] As an optional embodiment, in the above steps, according to the corresponding first set risk probability, the first risk probability corresponding to each device communication data is corrected to obtain the first corrected probability corresponding to each device communication data, including:
[0123] For each data set, calculate the first probability difference between the first set risk probability corresponding to this data set and the first probability mean parameter; optionally, the first probability mean parameter is the average value of the first set risk probabilities of all data sets;
[0124] Calculate the first correction weight proportional to the first probability difference;
[0125] Calculate the product of the first risk probability corresponding to each device communication data in this data set and the first correction weight to obtain the first corrected probability corresponding to each device communication data in this data set.
[0126] It can be seen that through the above optional embodiments, it is possible to measure the risk deviation degree of a single set based on the difference between the set risk probability and the average set probability of each data set, and calculate the proportional correction weight based on this, so as to accurately correct the probability of each device communication data, provide an accurate data basis for subsequent communication data risk identification, assist in accurately evaluating the potential risks of the target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect.
[0127] As an alternative embodiment, in the above steps, based on the second prediction model, determining the dangerous device information according to multiple device communication data includes:
[0128] Determine device-related information from the data content of all device communication data to obtain multiple communication device information; optionally, the device-related information is a sending device, a receiving device, a transit device, or a firewall device;
[0129] For each communication device information, based on the communication of the device corresponding to the communication device information and / or the communication with the gateway device of the target network, obtain the device parameter data and device historical communication data corresponding to the communication device information;
[0130] Input the device parameter data and device historical communication data corresponding to the communication device information into the trained second prediction model to obtain the second danger type and second danger probability corresponding to the communication device information;
[0131] Determine multiple dangerous communication devices from all communication device information based on the second danger probability;
[0132] Determine all dangerous communication devices and the corresponding second danger types as dangerous device information.
[0133] Optionally, the communication device information can be extracted from metadata, protocol fields, or log records in the data content, and the present invention does not make limitations. Optionally, the determination process of the communication device information can be based on regular expression matching, feature extraction algorithms, or preset rule parsing, and the present invention does not make limitations.
[0134] It can be seen that through the above alternative embodiments, it is possible to determine all relevant devices in all communications based on the analysis of the data content of device communication data, and screen out dangerous devices based on the prediction of the parameters and historical communications of the devices by the second prediction model, providing an accurate data basis for subsequent network risk analysis, assisting in accurately evaluating the potential risks of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0135] As an alternative embodiment, in the above steps, determining multiple dangerous communication devices from all communication device information based on the second danger probability includes:
[0136] Based on the clustering grouping algorithm, group all communication device information to obtain multiple device sets; optionally, among them, the similarity between the device parameter data corresponding to any two communication device information in each device set is greater than the similarity threshold;
[0137] For each set of devices, calculate the average value of the second hazard probabilities corresponding to all communication device information in the set of devices to obtain the second set hazard probability corresponding to the set of devices;
[0138] Calculate the second probability difference between the second set hazard probability and the second probability mean parameter; Optionally, the second probability mean parameter is the average value of the second set hazard probabilities of all sets of devices;
[0139] Calculate the second correction weight proportional to the second probability difference;
[0140] Calculate the product of the second hazard probability corresponding to each communication device information in the set of devices and the second correction weight to obtain the second corrected probability corresponding to each communication device information in the set of devices;
[0141] Determine the communication device information with the second corrected probability greater than the second probability threshold as the hazardous communication device.
[0142] Optionally, the clustering grouping algorithm can be the K-means clustering, hierarchical clustering or density clustering algorithm, which is not limited in the present invention.
[0143] Optionally, the device parameter data can be device performance parameters, communication protocol parameters or operating status parameters, which is not limited in the present invention.
[0144] Optionally, the similarity threshold can be a fixed threshold, a dynamic threshold or a threshold adaptively adjusted based on the application scenario, which is not limited in the present invention.
[0145] It can be seen that through the above optional embodiments, it is possible to determine all relevant devices in all communications based on the analysis of the data content of the device communication data, and screen out hazardous devices based on the prediction of the device parameters and historical communications by the second prediction model, providing an accurate data basis for subsequent network risk analysis, assisting in accurately evaluating the potential risks of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0146] As an optional embodiment, in the above steps, both the first prediction model and the second prediction model are CNN network models. The two are first jointly trained on a common training data set including multiple training device communication data and corresponding device parameter annotations and hazard annotations to obtain a basic model, and then the basic model is respectively trained on the corresponding fine-tuning training data sets to obtain the first prediction model and the second prediction model.
[0147] Optionally, the CNN network model can be a deep convolutional network, a residual network or an efficient network, which is not limited in the present invention.
[0148] Optionally, the co-training dataset may include simulation data, historical data, or real-time collected data, which is not limited in the present invention.
[0149] Optionally, the fine-tuning training dataset may be customized based on specific tasks, device types, or environmental conditions, which is not limited in the present invention.
[0150] It can be seen that through the above optional embodiments, the training details of the first prediction model and the second prediction model are defined, and two models with comparable and accurate prediction results can be obtained based on co-training and separate fine-tuning training, providing accurate prediction results for subsequent network risk analysis, assisting in accurately evaluating the potential risks of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and enhancing the network security protection effect.
[0151] As an optional embodiment, in the above steps, determining the network risk parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information includes:
[0152] Calculating the type similarity and device similarity between the dangerous communication information and the dangerous device information;
[0153] Calculating the product of the type similarity and the device similarity to obtain a matching degree parameter;
[0154] Calculating the average value of the difference between the prediction accuracies of the first prediction model and the second prediction model for the same validation dataset in the fine-tuning stage to obtain a prediction difference degree parameter;
[0155] Calculating a danger reference value proportional to the prediction difference degree parameter;
[0156] Calculating the difference between the matching degree parameter and the danger reference value to obtain the network risk parameter of the target network.
[0157] Specifically, the type similarity may be calculated by calculating the similarity between the dangerous types in the dangerous communication information and the dangerous device information. For example, all the first dangerous types in the dangerous communication information may be determined as the first dangerous type set, and all the second dangerous types in the dangerous device information may be determined as the second dangerous type set, and then the vector distance, intersection size, or intersection ratio between the first dangerous type set and the second dangerous type set may be calculated to obtain the type similarity.
[0158] Specifically, the device similarity can be calculated for the similarity of the corresponding devices between the dangerous communication information and the dangerous device information. For example, all the device communication data in the dangerous communication information can be used to determine the relevant devices, and then the similarity between all the relevant devices and the dangerous device information can be calculated to determine the device similarity. Optionally, the determination of the relevant devices can be obtained by analyzing the device-related information corresponding to all the device communication data in the dangerous communication information.
[0159] It can be seen that through the above optional embodiments, the matching degree between two prediction results can be accurately measured based on the calculation of the type similarity and the device similarity between the dangerous communication and the dangerous device, and the dangerous reference value can be determined based on the prediction difference degree between the prediction models, so as to accurately calculate the parameters that can characterize the risk of the network being attacked or penetrated, and finally accurately evaluate the potential risk of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification and strengthening the network security protection effect.
[0160] Embodiment 2
[0161] Please refer to Figure 2 , Figure 2 which is a schematic structural diagram of a network security situation awareness and early warning system disclosed in an embodiment of the present invention. Among them, Figure 2 the described network security situation awareness and early warning system can be applied to a data processing system / data processing device / data processing server (wherein, the server includes a local processing server or a cloud processing server). As Figure 2 shown, the network security situation awareness and early warning system can include:
[0162] An acquisition module 201, configured to acquire multiple device communication data of a target network within a preset historical time period.
[0163] A first prediction module 202, configured to determine dangerous communication information based on a first prediction model according to multiple device communication data.
[0164] A second prediction module 203, configured to determine dangerous device information based on a second prediction model according to multiple device communication data.
[0165] A matching module 204, configured to determine a network danger parameter of the target network based on a matching result between the dangerous communication information and the dangerous device information.
[0166] Optionally, the network danger parameter is used to indicate the danger possibility of the target network being penetrated or attacked.
[0167] It can be seen that in the above-mentioned embodiments of the invention, by obtaining multiple device communication data of the target network within a preset historical time period, processing the multiple device communication data based on the first prediction model to determine dangerous communication information, further processing the multiple device communication data based on the second prediction model to determine dangerous device information, and determining the network risk parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information, it is possible to accurately evaluate the potential risk of the target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect.
[0168] As an optional embodiment, the specific manner in which the first prediction module determines dangerous communication information based on the first prediction model according to multiple device communication data includes:
[0169] Input each device communication data into the trained first prediction model to obtain the first dangerous type and the first dangerous probability corresponding to each device communication data;
[0170] Based on the expected sending time point, divide all device communication data into multiple data sets;
[0171] Calculate the average value of the first dangerous probabilities corresponding to all device communication data in each data set to obtain the first set dangerous probability corresponding to each data set;
[0172] According to the corresponding first set dangerous probability, correct the first dangerous probability corresponding to each device communication data to obtain the first corrected probability corresponding to each device communication data;
[0173] Determine all device communication data with the first corrected probability greater than the first probability threshold and the corresponding first dangerous types as dangerous communication information.
[0174] It can be seen that through the above optional embodiment, it is possible to improve the accuracy and robustness of dangerous communication data identification through the prediction of the prediction model and the probability correction of the grouping algorithm, improve the screening efficiency and early warning effect of potential dangerous communication behaviors, assist in accurately evaluating the potential risk of the target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect.
[0175] As an optional embodiment, the specific manner in which the first prediction module divides all device communication data into multiple data sets based on the expected sending time point includes:
[0176] For each device communication data, determine whether there is a sending time point in the data content of the device communication data to obtain a first judgment result;
[0177] When the first judgment result is yes, determine the existing sending time point as the predicted sending time point of the device communication data;
[0178] When the second judgment result is no, input all time-related information in the data content of the device communication data into the trained sending time point prediction model to obtain the predicted sending time point of the device communication data;
[0179] Based on the clustering grouping algorithm, divide all device communication data into multiple data sets according to the predicted sending time point; Optionally, among them, the time difference between any two device communication data in each data set is less than the time difference threshold; The time difference threshold is proportional to the average value of the time differences between the predicted sending time points of all device communication data.
[0180] It can be seen that through the above optional embodiments, the predicted sending time point is extracted or predicted according to the device communication data content, and the communication data is divided into multiple sets according to time proximity through the clustering grouping algorithm, realizing the complementation and reasonable grouping of time information, providing an accurate data basis for subsequent communication data risk identification, assisting in accurately evaluating the potential risk of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0181] As an optional embodiment, the specific manner in which the first prediction module corrects the first risk probability corresponding to each device communication data according to the corresponding first set risk probability to obtain the first corrected probability corresponding to each device communication data includes:
[0182] For each data set, calculate the first probability difference between the first set risk probability corresponding to the data set and the first probability mean parameter; Optionally, the first probability mean parameter is the average value of the first set risk probabilities of all data sets;
[0183] Calculate the first correction weight proportional to the first probability difference;
[0184] Calculate the product of the first risk probability corresponding to each device communication data in the data set and the first correction weight to obtain the first corrected probability corresponding to each device communication data in the data set.
[0185] It can be seen that through the above optional embodiments, the degree of danger deviation of a single set can be measured based on the difference between the set danger probability and the average set probability of each data set, and a proportional correction weight can be calculated based on this to accurately correct the probability of each device communication data, providing an accurate data basis for subsequent communication data danger identification, assisting in accurately evaluating the potential risk of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0186] As an optional embodiment, the specific manner in which the second prediction module determines the dangerous device information based on the second prediction model according to multiple device communication data includes:
[0187] Determine device-related information from the data content of all device communication data to obtain multiple communication device information; optionally, the device-related information is a sending device, a receiving device, a relay device, or a firewall device;
[0188] For each communication device information, based on the communication of the device corresponding to the communication device information and / or the communication with the gateway device of the target network, obtain the device parameter data and device historical communication data corresponding to the communication device information;
[0189] Input the device parameter data and device historical communication data corresponding to the communication device information into the trained second prediction model to obtain the second danger type and the second danger probability corresponding to the communication device information;
[0190] Determine multiple dangerous communication devices from all communication device information based on the second danger probability;
[0191] Determine all dangerous communication devices and the corresponding second danger types as dangerous device information.
[0192] It can be seen that through the above optional embodiments, all relevant devices in all communications can be determined based on the analysis of the data content of the device communication data, and dangerous devices can be screened out based on the prediction of the device parameters and historical communications by the second prediction model, providing an accurate data basis for subsequent network risk analysis, assisting in accurately evaluating the potential risk of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0193] As an optional embodiment, the specific manner in which the second prediction module determines multiple dangerous communication devices from all communication device information based on the second danger probability includes:
[0194] Based on the clustering grouping algorithm, group all communication device information to obtain multiple device sets; optionally, among them, the similarity between the device parameter data corresponding to any two communication device information in each device set is greater than the similarity threshold;
[0195] For each device set, calculate the average value of the second hazard probabilities corresponding to all communication device information in the device set to obtain the second set hazard probability corresponding to the device set;
[0196] Calculate the second probability difference between the second set hazard probability and the second probability mean parameter; optionally, the second probability mean parameter is the average value of the second set hazard probabilities of all device sets;
[0197] Calculate the second correction weight proportional to the second probability difference;
[0198] Calculate the product of the second hazard probability corresponding to each communication device information in the device set and the second correction weight to obtain the second correction probability corresponding to each communication device information in the device set;
[0199] Determine the communication device information with the second correction probability greater than the second probability threshold as the dangerous communication device.
[0200] It can be seen that through the above optional embodiments, it is possible to determine all relevant devices in all communications based on the analysis of the data content of the device communication data, and screen out dangerous devices based on the prediction of the device parameters and historical communications by the second prediction model, providing an accurate data basis for subsequent network risk analysis, assisting in accurately evaluating the potential risk of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0201] As an optional embodiment, both the first prediction model and the second prediction model are CNN network models. First, they are jointly trained based on a common training data set including multiple training device communication data and corresponding device parameter annotations and hazard annotations to obtain a basic model, and then the basic model is separately trained based on the corresponding fine-tuning training data sets to obtain the first prediction model and the second prediction model.
[0202] It can be seen that through the above optional embodiments, the training details of the first prediction model and the second prediction model are limited, and two models with comparable and precise prediction results can be obtained based on joint training and separate fine-tuning training, providing accurate prediction results for subsequent network risk analysis, assisting in accurately evaluating the potential risk of the target network being penetrated or attacked, improving the timeliness and accuracy of network security risk identification, and strengthening the network security protection effect.
[0203] As an optional embodiment, the specific manner in which the matching module determines the network risk parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information includes:
[0204] Calculate the type similarity and device similarity between the dangerous communication information and the dangerous device information;
[0205] Calculate the product of the type similarity and the device similarity to obtain a matching degree parameter;
[0206] Calculate the average value of the difference between the prediction accuracies of the first prediction model and the second prediction model for the same validation data set during the fine-tuning stage to obtain a prediction difference degree parameter;
[0207] Calculate a dangerous reference value proportional to the prediction difference degree parameter;
[0208] Calculate the difference between the matching degree parameter and the dangerous reference value to obtain the network risk parameter of the target network.
[0209] It can be seen that through the above optional embodiment, it is possible to accurately measure the matching degree between two prediction results based on the calculation of the type similarity and device similarity between dangerous communication and dangerous devices, and determine the dangerous reference value based on the prediction difference degree between prediction models, so as to accurately calculate the parameter that can characterize the risk of network being attacked or penetrated, and finally realize the accurate evaluation of the potential risk of the target network being penetrated or attacked, improve the timeliness and accuracy of network security risk identification, and strengthen the network security protection effect.
[0210] Embodiment Three
[0211] Please refer to Figure 3 , Figure 3 which is another network security situation awareness and warning system disclosed in the embodiments of the present invention. Figure 3 The described network security situation awareness and warning system is applied to a data processing system / data processing device / data processing server (wherein, the server includes a local processing server or a cloud processing server). As Figure 3 shown, the network security situation awareness and warning system may include:
[0212] A memory 301 storing executable program code;
[0213] A processor 302 coupled to the memory 301;
[0214] Wherein, the processor 302 calls the executable program code stored in the memory 301 to execute the steps of the network security situation awareness and warning method described in Embodiment One.
[0215] Embodiment Four
[0216] An embodiment of the present invention discloses a computer-readable storage medium that stores a computer program for electronic data exchange, wherein the computer program causes a computer to execute the steps of the network security situation awareness and warning method described in Embodiment 1.
[0217] Embodiment 5
[0218] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute the steps of the network security situation awareness and warning method described in Embodiment 1.
[0219] The above describes specific embodiments of this specification, and other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily have to be performed in the specific order or continuous order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0220] The systems, devices, modules, or units illustrated in the above embodiments may be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0221] For convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing this specification, the functions of each unit may be implemented in one or more software and / or hardware.
[0222] Those skilled in the art should understand that the embodiments of this specification may be provided as a method, a system, or a computer program product. Therefore, the embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0223] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 one or more of the blocks for implementing the specified functions.
[0224] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 one or more of the blocks.
[0225] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 one or more of the blocks.
[0226] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0227] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0228] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information that can be accessed by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0229] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article or apparatus comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.
[0230] This specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0231] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, they are described relatively simply, and the relevant parts can be referred to the description of the method embodiments.
[0232] Finally, it should be noted that what is disclosed in a network security situation awareness and early warning method and system disclosed by an embodiment of the present invention is only a preferred embodiment of the present invention, and is only used to illustrate the technical solution of the present invention, rather than limiting it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A network security situation awareness and early warning method, characterized in that: The method comprises: Obtain communication data of multiple devices on the target network within a preset historical time period; Based on the first prediction model, determining dangerous communication information according to the plurality of device communication data; Based on the second prediction model, determining dangerous device information according to the plurality of device communication data; Based on the matching result between the dangerous communication information and the dangerous device information, a network danger parameter of the target network is determined; the network danger parameter is used to indicate the danger possibility of the target network being infiltrated or attacked.
2. The network security situation awareness and early warning method according to claim 1 is characterized in that: The determining of dangerous communication information based on the first prediction model and the plurality of device communication data comprises: Inputting each of the device communication data into the trained first prediction model to obtain a first danger type and a first danger probability corresponding to each of the device communication data; Based on the expected sending time point, dividing all the device communication data into multiple data sets; Calculate an average value of the first danger probabilities corresponding to all the device communication data in each of the data sets to obtain a first set danger probability corresponding to each of the data sets; Correcting the first danger probability corresponding to each of the device communication data according to the corresponding first set danger probability to obtain a first corrected probability corresponding to each of the device communication data; All the device communication data for which the first modified probability is greater than a first probability threshold and the corresponding first danger type are determined as dangerous communication information.
3. The network security situation awareness and early warning method according to claim 2 is characterized in that: The method of dividing all the device communication data into multiple data sets based on the expected sending time point includes: For each of the device communication data, determining whether there is a sending time point in the data content of the device communication data, and obtaining a first determination result; When the first judgment result is yes, determining the existing sending time point as the expected sending time point of the device communication data; When the second judgment result is no, inputting all time-related information in the data content of the device communication data into the trained sending time point prediction model to obtain the estimated sending time point of the device communication data; Based on the clustering grouping algorithm, all the device communication data are divided into multiple data sets according to the expected sending time points; wherein the time difference between any two expected sending time points of the device communication data in each of the data sets is less than a time difference threshold; and the time difference threshold is proportional to the average value of the time differences between the expected sending time points of all the device communication data.
4. The network security situation awareness and early warning method according to claim 2 is characterized in that: The step of correcting the first danger probability corresponding to each of the device communication data according to the corresponding first set danger probability to obtain a first corrected probability corresponding to each of the device communication data includes: For each of the data sets, calculating a first probability difference between a first set risk probability corresponding to the data set and a first probability mean parameter; the first probability mean parameter is an average value of the first set risk probabilities of all the data sets; Calculating a first correction weight proportional to the first probability difference; The product of the first danger probability corresponding to each device communication data in the data set and the first correction weight is calculated to obtain a first correction probability corresponding to each device communication data in the data set.
5. The network security situation awareness and early warning method according to claim 1 is characterized in that: The determining of dangerous device information based on the second prediction model and the plurality of device communication data includes: Determine device-related information from the data content of all the device communication data to obtain multiple communication device information; the device-related information is a sending device, a receiving device, a transfer device or a firewall device; For each piece of communication device information, based on the communication of the device corresponding to the communication device information and / or the communication with the gateway device of the target network, acquiring the device parameter data and the device historical communication data corresponding to the communication device information; Inputting device parameter data and device historical communication data corresponding to the communication device information into a trained second prediction model to obtain a second danger type and a second danger probability corresponding to the communication device information; Determine a plurality of dangerous communication devices from all the communication device information based on the second danger probability; All the dangerous communication devices and the corresponding second dangerous types are determined as dangerous device information.
6. The network security situation awareness and early warning method according to claim 5 is characterized in that: The determining of a plurality of dangerous communication devices from all the communication device information based on the second danger probability includes: Based on a clustering grouping algorithm, all the communication device information is grouped to obtain a plurality of device sets; wherein the similarity between the device parameter data corresponding to any two pieces of communication device information in each of the device sets is greater than a similarity threshold; For each of the device sets, calculating an average of the second danger probabilities corresponding to all the communication device information in the device set to obtain a second set danger probability corresponding to the device set; Calculating a second probability difference between the second set danger probability and a second probability mean parameter; the second probability mean parameter is an average value of the second set danger probabilities of all the equipment sets; calculating a second revised weight proportional to the second probability difference; Calculate the product of the second danger probability corresponding to each communication device information in the device set and the second correction weight to obtain the second correction probability corresponding to each communication device information in the device set; The communication device information for which the second modified probability is greater than a second probability threshold is determined as a dangerous communication device.
7. The network security situation awareness and early warning method according to claim 1 is characterized in that: The first prediction model and the second prediction model are both CNN network models. The two are first trained together based on a common training data set including communication data of multiple training devices and corresponding device parameter annotations and hazard annotations to obtain a basic model, and then the basic models are trained separately based on the corresponding fine-tuning training data set to obtain the first prediction model and the second prediction model.
8. The network security situation awareness and early warning method according to claim 7 is characterized in that: The determining the network risk parameter of the target network based on the matching result between the dangerous communication information and the dangerous device information includes: Calculating type similarity and device similarity between the dangerous communication information and the dangerous device information; Calculating the product of the type similarity and the device similarity to obtain a matching parameter; Calculating an average value of the difference between the prediction accuracy of the first prediction model and the second prediction model for the same validation data set in the fine-tuning stage to obtain a prediction difference parameter; Calculating a risk reference value proportional to the predicted difference parameter; The difference between the matching degree parameter and the risk reference value is calculated to obtain the network risk parameter of the target network.
9. A network security situation awareness and early warning system, characterized in that: The system comprises: An acquisition module is used to acquire communication data of multiple devices in a target network within a preset historical time period; A first prediction module, configured to determine dangerous communication information according to the plurality of device communication data based on a first prediction model; A second prediction module, configured to determine dangerous device information according to the plurality of device communication data based on a second prediction model; A matching module is used to determine the network danger parameters of the target network based on the matching result between the dangerous communication information and the dangerous device information; the network danger parameters are used to indicate the danger possibility of the target network being infiltrated or attacked.
10. A network security situation awareness and early warning system, characterized in that: The system comprises: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the network security situation awareness and early warning method as described in any one of claims 1-8.
Citation Information
Patent Citations
Network alarm evaluation method and device, electronic equipment and storage medium
CN117478380A
Network security situation awareness and early warning method and system based on big data
CN118075005A
Network security perception early warning method and system for smart power plant
CN119363438A
Network security situation adaptive active defense system and method
WO2023077617A1