Network security risk hidden danger monitoring and early warning method and system

The network security risk membership matrix is ​​constructed through the fuzzy C-means clustering algorithm and index weights, which solves the flexibility and accuracy of network security monitoring in the existing technology, and realizes accurate assessment and refined early warning of network security risks.

CN120263444APending Publication Date: 2025-07-04JIANGSU XUNAN INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510262493.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing network security monitoring technology lacks flexibility and adaptability, and is difficult to deal with new and complex network attacks. The false alarm rate and omission rate are high, the ambiguity and uncertainty of network security risks are difficult to deal with, and the comprehensive risk assessment ability is lacking, resulting in inaccurate risk assessment results.

Method used

The fuzzy C-mean clustering algorithm is used to calculate the risk membership of the basic indicators, build the basic risk membership matrix, and construct the dimension and total risk membership matrix through the index weight to achieve hierarchical risk assessment.

Benefits of technology

It has achieved accurate and meticulous assessment of network security risks, can accurately reflect the overall risk status of network security, and is refined to divide it under different risk levels, providing refined warning levels and response measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263444A_ABST
    Figure CN120263444A_ABST
Patent Text Reader

Abstract

The invention provides a network security risk hidden danger monitoring and early warning method and system. The method comprises the following steps: acquiring basic data of a network environment; determining indexes related to the network security risk, wherein the indexes comprise a basic index and a dimension index; performing risk membership calculation on each basic index by using a fuzzy C-means clustering algorithm, and constructing a basic risk membership matrix; determining a first index weight and a second index weight; based on the basic risk membership matrix and the first index weight, constructing a dimension risk membership matrix corresponding to all dimension indexes through matrix operation; carrying out membership combination calculation on the dimension risk membership matrix and the second index weight to obtain a total risk membership of the network security; and performing safety early warning according to the total risk membership degree. The obtained total risk membership degree can accurately present a refined division state of the network security risk under various risk levels, so that the early warning level and the corresponding risk degree are accurately determined, and the purpose of accurate early warning is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security risk hidden danger monitoring and early warning method and system. Background Art

[0002] The means of cyber attacks are constantly being updated, from traditional virus and Trojan attacks to modern DDoS attacks, phishing, ransomware, etc., network security threats are becoming more diverse and complex.

[0003] In order to cope with the increasingly severe network security situation, it is necessary to monitor and warn of network security, that is, to timely discover potential security threats through real-time monitoring and analysis of network traffic, logs, events and other information, and take corresponding early warning measures to prevent and respond.

[0004] Traditional network security monitoring technologies usually use rule-based intrusion detection systems and virus detection technologies that rely on virus signature libraries for detection. These detection technologies have the following defects: 1. Detection based on fixed rules and signature libraries lacks flexibility and adaptability, and it is difficult to deal with new and complex network attacks; 2. Due to the limitations of rule libraries and signature libraries, there are high false alarm rates and missed alarm rates; 3. Since network security risks are ambiguous and uncertain, traditional technologies often find it difficult to deal with this uncertainty, resulting in inaccurate risk assessment results; 3. Traditional technologies often only focus on risk assessment of a single indicator or dimension, lack comprehensive risk assessment capabilities, and cannot fully reflect the overall situation of network security. Summary of the invention

[0005] Based on this, the purpose of the present invention is to propose a network security risk hidden danger monitoring and early warning method and system to solve the above-mentioned problems.

[0006] According to the network security risk hidden danger monitoring and early warning method proposed by the present invention, the method comprises:

[0007] Collect basic data of the network environment;

[0008] Identify indicators related to cybersecurity risks, including basic indicators and dimensional indicators;

[0009] Apply the fuzzy C-means clustering algorithm to calculate the risk membership of each basic indicator and construct the basic risk membership matrix;

[0010] Determine the first indicator weight and the second indicator weight, where the first indicator weight is used to measure the relative importance of each basic indicator within its own dimension, and the second indicator weight is used to measure the relative importance of each dimension in the overall risk;

[0011] Construct a dimensional risk membership matrix corresponding to all dimensional indicators through matrix operations based on the basic risk membership matrix and the first indicator weight;

[0012] Perform membership combination calculation on the dimensional risk membership matrix and the second indicator weight to obtain the total risk membership of network security;

[0013] Conduct security early warning according to the total risk membership.

[0014] Furthermore, the steps of calculating the risk membership of each basic indicator by using the fuzzy C-means clustering algorithm and constructing the basic risk membership matrix include:

[0015] For each basic indicator, initialize its membership to each risk level, which is used to represent the degree to which the basic indicator belongs to each risk level, and the membership value is between [0, 1];

[0016] Initialize a clustering center for each risk level, and the clustering center is a point or vector representing the characteristics of the corresponding risk level;

[0017] For each basic indicator, calculate its distance to each clustering center, and update the membership of the basic indicator to each risk level according to the distance and the fuzzy index by using the membership update formula. The calculation formula is:

[0018]

[0019] where μ ij represents the membership of the i-th basic indicator to the j-th risk level, d(x i , v j ) represents the distance between the i-th basic indicator with the value of x i and the clustering center v j of the risk level j, d(x i , v a ) represents the distance between the i-th basic indicator with the value of x i and the clustering center v a of the risk level a, m is the fuzzy index, and c is the number of risk levels;

[0020] For each risk level, calculate a new clustering center according to the membership of all basic indicators to this risk level and the values of the basic indicators. The calculation formula is:

[0021]

[0022] where v j ′ represents the updated clustering center of the risk level j, x i is the value of the i-th basic indicator, and n is the number of basic indicators;

[0023] If the iterative stop condition is satisfied, stop the iteration and output the final membership degrees of each basic index to each risk level.

[0024] Furthermore, the steps of constructing the basic risk membership degree matrix include:

[0025] Arrange the membership degrees of each basic index belonging to each risk level in the order of the index and the order of the risk levels to form a basic risk membership degree matrix U. The element u in the matrix U ij represents the membership degree of the i-th basic index to the j-th risk level.

[0026] Furthermore, after the step of calculating the risk membership degrees of each basic index by applying the fuzzy C-means clustering algorithm, the following steps are also included:

[0027] Take the membership degrees of each basic index belonging to each risk level as conditional attributes and the risk levels as decision attributes to construct a decision table;

[0028] Reduce the membership degrees of each risk level in the decision table to retain the membership degrees that have an important impact on each risk level.

[0029] Furthermore, the steps of reducing the membership degrees of each risk level in the decision table to retain the membership degrees that have an important impact on each risk level include:

[0030] Calculate the conditional entropy of each risk level membership degree relative to the risk level, and calculate the increase in conditional entropy after removing it from the set of risk level membership degrees;

[0031] Add the risk level membership degree with the highest increase in conditional entropy to the reduction set as the initial set;

[0032] Add the remaining risk level membership degrees to the reduction set one by one until the reduction set can distinguish all different risk levels in the decision table. After adding each risk level membership degree, check whether the positive region of the reduction set changes;

[0033] If the positive region remains unchanged, remove it from the reduction set;

[0034] When the conditional entropy no longer decreases after adding a new risk level membership degree, stop adding risk level membership degrees to the reduction set.

[0035] Furthermore, the steps of constructing the dimension risk membership degree matrix corresponding to all dimension indexes through matrix operation based on the basic risk membership degree matrix and the first index weight include:

[0036] For each dimension, the basic risk membership sub-matrix corresponding to each basic indicator it contains and the first indicator weight are weighted and summed to obtain the risk membership of each dimension. The calculation formula is:

[0037] D k = U k × W 1k ,

[0038] where D k is the risk membership vector of the k-th dimension, K is the number of dimensions, U k is the basic risk membership sub-matrix corresponding to each basic indicator contained in the k-th dimension, and W 1k is the first indicator weight sub-vector corresponding to each basic indicator contained in the k-th dimension;

[0039] Arrange the risk membership vectors of all dimensions in the dimension order to form a dimension risk membership matrix D. Among them, each element in the dimension risk membership matrix represents the comprehensive membership of each dimension at different risk membership levels.

[0040] Furthermore, the step of calculating the membership combination of the dimension risk membership matrix and the second indicator weight to obtain the total risk membership of network security includes:

[0041] Perform matrix multiplication on the dimension risk membership matrix D and the second indicator weight vector W2 to obtain a total risk membership vector Y. The calculation formula is: Y = D × W2.

[0042] Furthermore, the steps of performing security warning according to the total risk membership include:

[0043] Determine the warning levels, including no warning, light warning, medium warning, and heavy warning;

[0044] Set membership thresholds for each warning level;

[0045] Compare the value of the total risk membership with the membership thresholds of each warning level to determine the warning level that meets the conditions;

[0046] Perform corresponding security warnings according to the determined warning levels.

[0047] The present invention also proposes a network security risk and hidden danger monitoring and warning system for implementing the above-mentioned network security risk and hidden danger monitoring and warning method. The system includes:

[0048] Data acquisition module: used to collect basic data of the network environment;

[0049] Indicator determination module: used to determine indicators related to network security risks, including basic indicators and dimension indicators;

[0050] Membership conversion module: used to apply the fuzzy C-means clustering algorithm to calculate the risk membership of each basic indicator and construct the basic risk membership matrix;

[0051] Weight determination module: used to determine the first indicator weight and the second indicator weight, wherein the first indicator weight is used to measure the relative importance of each basic indicator in its own dimension, and the second indicator weight is used to measure the relative importance of each dimension in the overall risk;

[0052] Dimension membership module: used to construct a dimensional risk membership matrix corresponding to all dimensional indicators through matrix operations based on the basic risk membership matrix and the first indicator weight;

[0053] Total membership module: used to calculate the membership of the dimensional risk membership matrix and the second indicator weight to obtain the total risk membership of network security;

[0054] Early warning module: used to issue safety warnings based on the overall risk affiliation.

[0055] In summary, the network security risk hidden danger monitoring and early warning method of the present invention divides the indicators related to network security risks into basic indicators and dimensional indicators, and assigns weights to them respectively, thereby realizing hierarchical risk analysis, so as to more clearly understand the source and composition of risks and realize more accurate comprehensive risk assessment;

[0056] The fuzzy C-means clustering algorithm is used to calculate the risk membership of each basic indicator and construct a basic risk membership matrix, which can reflect the membership degree of basic indicators at different risk levels, thereby quantifying the fuzzy relationship between basic indicators and different risk levels, making risk assessment more accurate and detailed.

[0057] Based on the basic risk membership matrix and the first indicator weight, a dimensional risk membership matrix is ​​constructed through matrix operation, and the dimensional risk membership matrix is ​​combined with the second indicator weight to calculate the membership to obtain the total risk membership of network security. The obtained total risk membership not only accurately reflects the overall risk status of the current network environment, but also presents a refined division of the overall risk of network security under various risk levels, so that when making security warnings based on the total risk membership, the warning level and its corresponding risk degree and response measures can be determined in detail and accurately, so as to achieve the purpose of accurate warning.

[0058] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description or will be learned through embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the following description of embodiments in conjunction with the accompanying drawings, in which:

[0060] Figure 1 is a flowchart of the network security risk and hidden danger monitoring and early warning method according to the first embodiment of the present invention;

[0061] Figure 2 is a system block diagram of the network security risk and hidden danger monitoring and early warning system according to the second embodiment of the present invention. Detailed Embodiments

[0062] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. Several embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.

[0063] It should be noted that when an element is referred to as being "fixedly provided on" another element, it can be directly on the other element or there may also be an intermediate element. When an element is considered to be "connected" to another element, it can be directly connected to the other element or there may be an intermediate element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are only for the purpose of illustration.

[0064] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the description of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0065] Embodiment 1

[0066] Please refer to Figure 1 , the present invention proposes a network security risk and hidden danger monitoring and early warning method, and the method includes steps S101 to S107:

[0067] S101, collecting basic data of the network environment; including conventional network traffic, access logs, system configurations, vulnerability scan results, etc.

[0068] It should be noted that the basic data of the network environment can be obtained from different sources, such as network device logs, system logs, user behavior records, network traffic monitoring data, vulnerability scan results, etc. These data may be stored on various nodes of the network and need to be uniformly collected and integrated through a data collection module.

[0069] The basic data of the network environment can include numerical data (such as network traffic, access frequency, the number of system vulnerabilities, etc.) and text data (such as log records, descriptions of abnormal behaviors, etc.). These data may have different time granularities, such as real-time data, daily data, weekly data, etc. After collecting the basic data of the network environment, preprocessing work such as data cleaning, deduplication, and formatting needs to be carried out to ensure the accuracy and consistency of the data.

[0070] S102, determine the indicators related to network security risks, including basic indicators and dimensional indicators.

[0071] It should be noted that network security risks are complex and multi-dimensional, involving multiple dimensions such as network access, system security, and user behavior. Each dimension may be composed of multiple basic indicators.

[0072] For example, K dimensional indicators and n basic indicators can be determined. Under the network access dimension, basic indicators such as abnormal network traffic and illegal access attempts are included. Under the system security dimension, basic indicators such as the malware infection rate and the number of system vulnerabilities are included. Under the user behavior dimension, basic indicators such as abnormal login behavior and abnormal file operations are included.

[0073] S103, apply the fuzzy C-means clustering algorithm to calculate the risk membership degree for each basic indicator and construct a basic risk membership degree matrix.

[0074] It should be noted that due to the fuzziness and uncertainty of network security risks. For example, some basic indicators (such as network traffic, access frequency, etc.) may exhibit different risk characteristics in different situations and are difficult to be divided by simple binary logic (i.e., the risk state of "yes" or "no"). Therefore, through the fuzzy C-means clustering algorithm, each basic indicator can belong to multiple risk levels with different membership degrees. This fuzzy division method is more in line with the actual situation of network security risks and can more accurately and precisely reflect the relationship between basic indicators and different risk levels.

[0075] The fuzzy C-means clustering algorithm of this embodiment learns and accurately captures the complex relationships between basic indicators through a data-driven iterative optimization process, automatically adjusts the membership degrees of each basic indicator in different clusters (i.e., risk levels), so as to improve the accuracy and reliability of risk membership degree calculation, thereby accurately reflecting the risk state of data points, and has obvious advantages in dealing with high-dimensional, non-linear, and non-Gaussian distributed network security data.

[0076] Further optionally, the step of applying the fuzzy C-means clustering algorithm to calculate the risk membership degree for each basic indicator includes:

[0077] According to the requirements of network security risk assessment, determine the number of risk levels;

[0078] For each basic indicator, initialize its membership to each risk level to indicate the degree to which the basic indicator belongs to each risk level. The membership value is between [0, 1].

[0079] Initialize a cluster center for each risk level, and the cluster center is used to represent a point or vector of the corresponding risk level characteristics;

[0080] For each basic indicator, calculate its distance to each cluster center, and based on the distance and fuzzy index, use the membership update formula to update the membership of the basic indicator to each risk level. The calculation formula is:

[0081]

[0082] Among them, μ ij represents the membership of the i-th basic indicator to the j-th risk level, d(x i , v j ) indicates the value is x i The cluster center v of the i-th basic indicator and risk level j j The distance between them, d(x i , v a ) indicates the value is x i The cluster center v of the i-th basic indicator and risk level a a The distance between them, m is the fuzzy index (usually between [1.5, 2.5]), and c is the number of risk levels;

[0083] For each risk level, a new cluster center is calculated based on the membership of all basic indicators to the risk level and the value of the basic indicators. The calculation formula is:

[0084]

[0085] Among them, v j ′ represents the cluster center of the updated risk level j, x i is the value of the ith basic indicator, and n is the number of basic indicators;

[0086] If the iteration stop condition is met (such as reaching the corresponding number of iterations or the difference between the updated membership value and the membership value before the update is less than the threshold), the iteration is stopped and the final membership of each basic indicator to each risk level is output.

[0087] It is understandable that applying the fuzzy C-means clustering algorithm to calculate the risk membership degree of basic indicators and constructing a basic risk membership degree matrix can effectively process the basic indicator data with ambiguity and uncertainty, thus more accurately reflecting the network security risk status. At the same time, by adjusting parameters such as the number of clusters and the fuzzy index, different network security monitoring requirements can be adapted.

[0088] Further optionally, the steps of constructing the basic risk membership degree matrix include:

[0089] Arrange the membership degrees of each basic indicator belonging to each risk level in the order of the indicators and the order of the risk levels to form a basic risk membership degree matrix U. The element u in the matrix U ij represents the membership degree of the i-th basic indicator to the j-th risk level.

[0090] Further optionally, in another implementation, after the step of applying the fuzzy C-means clustering algorithm to calculate the risk membership degree of each basic indicator, the following steps are also included:

[0091] Take the membership degrees of each basic indicator belonging to each risk level as conditional attributes and the risk levels as decision attributes to construct a decision table;

[0092] Reduce the membership degrees of each risk level in the decision table to retain the membership degrees that have an important impact on each risk level.

[0093] It is understandable that after applying the fuzzy C-means clustering algorithm to calculate the risk membership degree of each basic indicator, a reduction process can also be performed, that is, taking the membership degrees of each basic indicator belonging to each risk level as conditional attributes to construct a decision table, and reducing the conditional attributes (the membership degrees of each risk level) in the decision table to remove redundant or unnecessary attributes and retain the attributes that have an important impact on the decision attribute (i.e., the risk level), that is, removing redundant membership degrees and focusing on key membership degrees, thereby improving the accuracy and efficiency of network security risk judgment.

[0094] Further optionally, the steps of reducing the membership degrees of each risk level in the decision table to retain the membership degrees that have an important impact on each risk level include:

[0095] Calculate the conditional entropy of each risk level membership degree relative to the risk level, and calculate the increase in conditional entropy after removing it from the set of risk level membership degrees, which is used to represent the importance of the risk level membership degree;

[0096] Add the risk level membership degree with the highest increase in conditional entropy to the reduction set as the initial set. The risk level membership degree with the highest increase in conditional entropy is the risk level membership degree that has the greatest impact on the decision attribute and the highest importance;

[0097] Add the remaining risk level membership degrees to the reduction set one by one until the reduction set can distinguish all different risk levels in the decision table. After adding each risk level membership degree, check whether the positive region of the reduction set (i.e., the set of objects that can be correctly classified by the reduction set) changes;

[0098] If the positive region remains unchanged, it means that the newly added risk level membership degree is redundant and should be removed from the reduction set;

[0099] When the conditional entropy no longer decreases after adding a new risk level membership degree, it means that the reduction is sufficient and stop adding risk level membership degrees to the reduction set.

[0100] It can be understood that through the above steps, an optimal reduction set can be obtained, which contains the least and most critical conditional attributes (membership degrees of risk levels) and can accurately identify different risk levels.

[0101] For example, assuming that the membership degrees of all basic indicators in a certain time period are calculated, the following decision table (partial) can be constructed:

[0102] Basic index Low-risk membership degree Medium-risk membership degree High-risk membership degree <![CDATA[x1]]> 0.4 0.3 0.3 <![CDATA[x2]]> 0.6 0.3 0.1 <![CDATA[x3]]> 0.9 0.1 0 <![CDATA[x4]]> 0.5 0.4 0.1 <![CDATA[x5]]> 0.7 0.2 0.1 <![CDATA[x6]]> 0.4 0.5 0.1

[0103] Decision table

[0104] After constructing the decision table, use the reduction method to reduce the conditional attributes (i.e., membership degrees of each risk level) in the decision table to remove redundant or unnecessary attributes and retain the attributes that have an important impact on the decision attribute (i.e., risk level). The reduced decision table may contain fewer conditional attributes (membership degree values), but the decision attribute (risk level) remains unchanged.

[0105] Through reduction analysis, if it is found that the membership degrees of some indicators have little influence on risk level judgment, some membership degree values of these attributes can be reduced. The reduced decision table is as follows (partial):

[0106] Basic index Low-risk membership degree Medium-risk membership degree High-risk membership degree <![CDATA[x1]]> 0.4 0.3 0.3 <![CDATA[x2]]> 0.6 0.3 0.1 <![CDATA[x3]]> 0.9 - - <![CDATA[x4]]> 0.5 0.4 - <![CDATA[x5]]> 0.7 0.2 - <![CDATA[x6]]> - 0.5 0.1

[0107] Reduced decision table

[0108] In the reduced decision table, redundant membership degrees are removed and key membership degrees are focused, thus improving the accuracy and efficiency of network security risk judgment.

[0109] Then, based on the reduced decision table, a refined basic risk membership degree matrix U can be obtained:

[0110]

[0111] Basic risk membership degree matrix U

[0112] S104. Determine the first index weight and the second index weight, where the first index weight is used to measure the relative importance of each basic index within its dimension, and the second index weight is used to measure the relative importance of each dimension in the overall risk.

[0113] It should be noted that network security risks are complex and multi-dimensional. By classifying the indicators into basic indicators and dimension indicators and assigning weights respectively, hierarchical risk analysis can be carried out. This analysis method helps to more clearly understand the sources and compositions of risks, so as to formulate more targeted risk response measures.

[0114] The influence degrees of different basic indicators on the risks of their respective dimensions may be different. Therefore, the relative importance of each basic indicator within its dimension can be reflected by introducing the first index weight. The influence degrees of different dimensions on the overall risk may be different. Therefore, the relative importance of each dimension in the overall risk can be reflected by introducing the second index weight.

[0115] The first index weight and the second index weight can be determined by using the subjective weighting method or the objective weighting method. The subjective weighting method relies on the subjective experience judgment and verification of experts, and the objective weighting method is based on the statistical characteristics of data.

[0116] Taking the determination of the first index weight by the subjective weighting method as an example: Experts can be organized to make pairwise comparisons of the basic indicators to determine their relative importance within their dimensions, and then a judgment matrix can be constructed according to the relative importance of each basic indicator within its dimension. Then, the judgment matrix is normalized, and the weights of each basic indicator are calculated. Next, a consistency test is carried out to ensure the rationality of the weight distribution. Specifically, the consistency index CI and the random consistency index RI of the judgment matrix are calculated, and the consistency ratio CR = CI / RI is calculated. If the consistency ratio CR < 0.1, it is considered that the judgment matrix has satisfactory consistency and the weight distribution is reasonable; otherwise, the judgment matrix is adjusted and the weights are recalculated. In this way, the first index weight can be determined, and the second index weight can be determined by the same method.

[0117] S105. Based on the basic risk membership matrix and the first index weight, construct a dimension risk membership matrix corresponding to all dimension indicators through matrix operations.

[0118] It should be noted that by combining the basic risk membership matrix with the first index weights through matrix operations, a dimension risk membership matrix corresponding to all dimension indicators is constructed. Specifically, the risk memberships of all basic indicators within each dimension can be weighted and summed to obtain the comprehensive membership of the dimension at different risk membership levels. Each element in the dimension risk membership matrix represents the comprehensive membership of each dimension at different risk membership levels. During the operation process, the risk membership of each basic indicator will be weighted according to its weight, so as to reflect the different contributions of different basic indicators in the calculation of the dimension risk membership.

[0119] Further optionally, the step of constructing a dimension risk membership matrix corresponding to all dimension indicators through matrix operations based on the basic risk membership matrix and the first index weights includes:

[0120] For each dimension, the basic risk membership sub-matrix corresponding to each basic indicator it contains and the first index weights are weighted and summed to obtain the risk membership of each dimension. The calculation formula is:

[0121] D k = U k × W 1k ,

[0122] where D k is the risk membership vector of the k-th dimension, K is the number of dimensions, U k is the basic risk membership sub-matrix corresponding to each basic indicator contained in the k-th dimension, and W 1k is the first index weight sub-vector corresponding to each basic indicator contained in the k-th dimension;

[0123] Arrange the risk membership vectors of all dimensions in the dimension order to form a dimension risk membership matrix D. Among them, each element in the dimension risk membership matrix represents the comprehensive membership of each dimension at different risk membership levels.

[0124] It can be understood that taking the network access dimension, system security dimension, and user behavior dimension as examples, assuming that the first index weight vectors of the network access dimension, system security dimension, and user behavior dimension have been determined. For example, the first index weight vector of the network access dimension is W 1网络访问 = [0.6, 0.4] (including the weights of network traffic anomalies and illegal access attempts), the first index weight vector of the system security dimension is W 1系统安全 = [0.7, 0.3] (including the weights of malware infection rate and the number of system vulnerabilities), and the first index weight vector of the user behavior dimension is W 1用户行为 = [0.5, 0.5] (including the weights of abnormal login behavior and abnormal file operations).

[0125] For the network access dimension, its risk membership degree vector D 网络访问 The calculation formula is: D 网络访问 = R 网络访问 ×W 1网络访问 , and its risk membership degree sub-matrix R 网络访问 is Then D 网络访问 = [0.4×0.6 + 0.6×0.4, 0.3×0.6 + 0.3×0.4, 0.3×0.6 + 0.1×0.4] = [0.48, 0.3, 0.22].

[0126] And so on, calculate the risk membership degree vectors of the system security dimension and the user behavior dimension.

[0127] Arrange the risk membership degree vectors of all dimensions in the dimension order to form a dimension risk membership degree matrix D. Assuming there are 3 dimensions and each dimension has 3 risk levels (low, medium, high), then D is:[[]] Among them, the first row is the risk membership degree of the network access dimension, the second row is the risk membership degree of the system security dimension, and the third row is the risk membership degree of the user behavior dimension.

[0128] S106, perform membership degree combination calculation on the dimension risk membership degree matrix and the second index weight to obtain the total risk membership degree of network security.

[0129] It should be noted that perform combination calculation on the dimension risk membership degree matrix and the second index weight. Specifically, the risk membership degree of each dimension index can be weighted and summed according to its weight to obtain the total risk membership degree of the network security total index at different risk membership degree levels.

[0130] The calculated total risk membership degree not only accurately reflects the overall risk status of the current network environment, but also presents a refined division state of the current overall network security risk at various risk levels, enabling the accurate determination of the warning level, its corresponding different risk degrees and response measures when performing security warning based on the total risk membership degree, achieving the purpose of accurate warning.

[0131] Further optionally, the performing membership degree combination calculation on the dimension risk membership degree matrix and the second index weight to obtain the total risk membership degree of network security includes:

[0132] Perform matrix multiplication operation on the dimension risk membership degree matrix D and the second index weight vector W2 to obtain a total risk membership degree vector Y. The calculation formula is: Y = D × W2.

[0133] It can be understood that after calculating the dimension risk membership degree matrix After that, perform a matrix multiplication operation on the dimensional risk membership matrix D and the second index weight vector W2 to obtain a total risk membership vector Y, where Y = D × W2. If W2 = [0.4, 0.3, 0.3] (representing the weights of the network access dimension, system security dimension, and user behavior dimension in the total index respectively), then the calculation yields: Y = [0.48×0.4 + 0.8×0.3 + 0.3×0.3, 0.3×0.4 + 0.1×0.3 + 0.4×0.3, 0.22×0.4 + 0.05×0.3 + 0.3×0.3] = [0.522, 0.27, 0.193]. Each element in Y represents the total membership degree of the total network security index under different risk levels (low risk, medium risk, high risk).

[0134] Through the above steps, the total risk membership degree of network security can be obtained. The total risk membership degree can not only more comprehensively evaluate the security risk status of the network, but also reflect a refined division status of network security under each risk level, that is, the total membership degree under each risk level, and provide decision-making support for subsequent level warning.

[0135] S107, conduct security warning according to the total risk membership degree.

[0136] Further optionally, the steps of conducting security warning according to the total risk membership degree include:

[0137] Determine the warning levels, including no warning, light warning, medium warning, and heavy warning;

[0138] Set membership degree thresholds for each warning level;

[0139] Compare the value of the total risk membership degree with the membership degree thresholds of each warning level to determine the warning levels that meet the conditions;

[0140] Conduct corresponding security warnings according to the determined warning levels.

[0141] It can be understood that by quantifying and evaluating network security risks through the specific index (i.e., probability) presented at each security level of the total membership degree, the risk status of the current network environment can be accurately reflected in detail, realizing a refined division of risks. Thus, refined security status information is provided for level warning, thereby realizing a refined division of warning levels, avoiding subjective and vague judgments of warnings, achieving the purpose of accurate warning, and helping to timely discover and respond to potential security threats.

[0142] Specifically, set the warning levels. For example, no warning (green): indicates that the network security risk is very low and is basically in a safe state; light warning (yellow): indicates that there is a certain network security risk, but the risk level is relatively low and attention is required; medium warning (orange): indicates that the network security risk is relatively high and certain measures need to be taken for prevention; heavy warning (red): indicates that the network security risk is extremely high and immediate emergency measures need to be taken to respond.

[0143] And set the membership threshold for each warning level. For example:

[0144] No warning: membership degree of low risk > 0.7 (or set according to specific circumstances);

[0145] Light warning: 0.4 ≤ membership degree of low risk ≤ 0.7 and membership degree of medium risk < 0.4 (while considering the situation where the low risk is relatively high and the medium risk is not high), or: if the membership degree of medium risk is the highest, but lower than a certain specific value (such as 0.35), and the membership degree of high risk is very low, it can also be determined as a light warning;

[0146] Medium warning: membership degree of medium risk ≥ 0.4 and membership degree of high risk < 0.3;

[0147] Heavy warning: membership degree of high risk ≥ 0.3.

[0148] Compare the value of the total risk membership degree with the membership thresholds of each warning level to determine the warning level that meets the conditions. If the total risk membership degree Y = [0.522, 0.27, 0.193], corresponding to: membership degree of low risk is 0.522, membership degree of medium risk is 0.27, and membership degree of high risk is 0.193. Then determine the warning level:

[0149] The membership degree of low risk 0.522 does not meet the threshold of no warning (> 0.7), so it is not no warning;

[0150] The membership degree of medium risk 0.27 is relatively low, and the membership degree of low risk 0.522 is relatively high. However, since the condition of no warning is not met, and at the same time the membership degree of high risk 0.193 does not reach the heavy warning threshold, according to the determination condition of light warning (the membership degree of low risk is between 0.4 and 0.7, and the membership degree of medium risk < 0.4, while considering the situation where the low risk is relatively high and the medium risk is not high), it is found that the total risk membership degree Y meets the determination condition of light warning. Therefore, it can be determined as a light warning;

[0151] The conditions of medium warning and heavy warning are not met.

[0152] Finally, issue a warning message according to the determined warning level. The warning level is light warning (yellow), and the warning content can be: The overall network security indicators are in the low-risk area, but there are certain potential risks. It is recommended to strengthen daily monitoring, regularly check system security, and improve user security awareness.

[0153] In summary, the network security risk hidden danger monitoring and early warning method of the present invention divides the indicators related to network security risks into basic indicators and dimensional indicators, and assigns weights to them respectively, thereby realizing hierarchical risk analysis, so as to more clearly understand the source and composition of risks and realize more accurate comprehensive risk assessment;

[0154] The fuzzy C-means clustering algorithm is used to calculate the risk membership of each basic indicator and construct a basic risk membership matrix, which can reflect the membership degree of basic indicators at different risk levels, thereby quantifying the fuzzy relationship between basic indicators and different risk levels, making risk assessment more accurate and detailed.

[0155] Based on the basic risk membership matrix and the first indicator weight, a dimensional risk membership matrix is ​​constructed through matrix operation, and the dimensional risk membership matrix is ​​combined with the second indicator weight to calculate the membership to obtain the total risk membership of network security. The obtained total risk membership not only accurately reflects the overall risk status of the current network environment, but also presents a refined division of the overall risk of network security under various risk levels, so that when making security warnings based on the total risk membership, the warning level and its corresponding risk degree and response measures can be determined in detail and accurately, so as to achieve the purpose of accurate warning.

[0156] Embodiment 2

[0157] See also Figure 2 The network security risk hidden danger monitoring and early warning system proposed by the present invention comprises:

[0158] Data collection module: used to collect basic data of the network environment;

[0159] Indicator determination module: used to determine indicators related to network security risks, including basic indicators and dimensional indicators;

[0160] Membership conversion module: used to apply the fuzzy C-means clustering algorithm to calculate the risk membership of each basic indicator and construct the basic risk membership matrix;

[0161] Weight determination module: used to determine the first indicator weight and the second indicator weight, wherein the first indicator weight is used to measure the relative importance of each basic indicator in its own dimension, and the second indicator weight is used to measure the relative importance of each dimension in the overall risk;

[0162] Dimension membership module: used to construct a dimensional risk membership matrix corresponding to all dimensional indicators through matrix operations based on the basic risk membership matrix and the first indicator weight;

[0163] Total membership degree module: used to perform membership combination calculation on the dimension risk membership degree matrix and the second index weight to obtain the total risk membership degree of network security;

[0164] Early warning module: used to perform security early warning according to the total risk membership degree.

[0165] Further optionally, the membership degree conversion module is further used for:

[0166] For each basic index, initialize its membership degree to each risk level, which is used to represent the degree to which the basic index belongs to each risk level, and the membership degree value is between [0, 1];

[0167] Initialize a clustering center for each risk level, and the clustering center is used to represent a point or vector of the corresponding risk level characteristics;

[0168] For each basic index, calculate its distance to each clustering center, and update the membership degree of the basic index to each risk level according to the distance and the fuzzy index using the membership degree update formula. The calculation formula is:

[0169]

[0170] Among them, μ ij represents the membership degree of the i-th basic index to the j-th risk level, d(x i , v j ) represents the distance between the i-th basic index with the value of x i and the clustering center v j of the risk level j, d(x i , v a ) represents the distance between the i-th basic index with the value of x i and the clustering center v a of the risk level a, m is the fuzzy index, and c is the number of risk levels;

[0171] For each risk level, calculate a new clustering center according to the membership degree of all basic indexes to this risk level and the values of the basic indexes. The calculation formula is:

[0172]

[0173] Among them, v j ′ represents the updated clustering center of the risk level j, x i is the value of the i-th basic index, and n is the number of basic indexes;

[0174] If the iteration stop condition is satisfied, stop the iteration and output the final membership degree of each basic index to each risk level.

[0175] Further optionally, the membership degree conversion module is further configured to:

[0176] Arrange the membership degrees of each basic index belonging to each risk level in the order of the indexes and the order of the risk levels to form a basic risk membership degree matrix U, and the element u in the matrix U ij Represents the membership degree of the i-th basic index to the j-th risk level.

[0177] Further optionally, the membership degree conversion module is further configured to:

[0178] Take the membership degrees of each basic index belonging to each risk level as conditional attributes and the risk levels as decision attributes to construct a decision table;

[0179] Reduce the membership degrees of each risk level in the decision table to retain the membership degrees that have an important impact on each risk level.

[0180] Further optionally, the membership degree conversion module is further configured to:

[0181] Calculate the conditional entropy of each risk level membership degree relative to the risk level, and calculate the increase in the conditional entropy after it is removed from the set of risk level membership degrees;

[0182] Add the risk level membership degree with the highest increase in conditional entropy to the reduction set as the initial set;

[0183] Add the remaining risk level membership degrees to the reduction set one by one until the reduction set can distinguish all different risk levels in the decision table, and check whether the positive domain of the reduction set changes after each addition of a risk level membership degree;

[0184] If the positive domain remains unchanged, remove it from the reduction set;

[0185] When the conditional entropy no longer decreases after adding a new risk level membership degree, stop adding risk level membership degrees to the reduction set.

[0186] Further optionally, the dimension membership degree module is further configured to:

[0187] For each dimension, perform a weighted sum of the basic risk membership degree sub-matrix corresponding to each basic index it contains and the first index weight to obtain the risk membership degree of each dimension. The calculation formula is:

[0188] D k =U k ×W 1k ,

[0189] where D k is the risk membership degree vector of the k-th dimension, K is the number of dimensions, and U kis the sub - matrix of basic risk membership degrees corresponding to each basic index included in the k - th dimension, W 1k is the first index weight sub - vector corresponding to each basic index included in the k - th dimension;

[0190] Arrange the risk membership degree vectors of all dimensions in the order of dimensions to form a dimension risk membership degree matrix D. Among them, each element in the dimension risk membership degree matrix represents the comprehensive membership degree of each dimension at different risk membership degree levels.

[0191] Further optionally, the total membership degree module is further configured to:

[0192] Perform a matrix multiplication operation on the dimension risk membership degree matrix D and the second index weight vector W2 to obtain a total risk membership degree vector Y. The calculation formula is: Y = D×W2.

[0193] Further optionally, the warning module is further configured to:

[0194] Determine the warning levels, including no warning, light warning, medium warning, and heavy warning;

[0195] Set membership degree thresholds for each warning level;

[0196] Compare the value of the total risk membership degree with the membership degree thresholds of each warning level to determine the warning levels that meet the conditions;

[0197] Conduct corresponding safety warnings according to the determined warning levels.

[0198] The above - mentioned embodiments only represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention should be subject to the appended claims.

Claims

1. A method for monitoring and warning of potential network security risks, characterized in that, The method comprises: Collect basic data of the network environment; Identify indicators related to cybersecurity risks, including basic indicators and dimensional indicators; Apply the fuzzy C-means clustering algorithm to calculate the risk membership of each basic indicator and construct the basic risk membership matrix; Determine the first indicator weight and the second indicator weight, where the first indicator weight is used to measure the relative importance of each basic indicator within its own dimension, and the second indicator weight is used to measure the relative importance of each dimension in the overall risk; Based on the basic risk membership matrix and the first indicator weight, a dimensional risk membership matrix corresponding to all dimensional indicators is constructed through matrix operations; The dimensional risk membership matrix and the second indicator weight are combined to calculate the membership to obtain the total risk membership of network security; Issue safety warnings based on the overall risk affiliation.

2. The network security risk and potential threat monitoring and early warning method according to claim 1, wherein, The steps of applying the fuzzy C-means clustering algorithm to calculate the risk membership of each basic indicator and constructing a basic risk membership matrix include: For each basic indicator, initialize its membership to each risk level to indicate the degree to which the basic indicator belongs to each risk level. The membership value is between [0, 1]. Initialize a cluster center for each risk level, and the cluster center is used to represent a point or vector of the corresponding risk level characteristics; For each basic indicator, calculate its distance to each cluster center, and based on the distance and fuzzy index, use the membership update formula to update the membership of the basic indicator to each risk level. The calculation formula is: Among them, μ ij represents the membership degree of the i-th basic index to the j-th risk level, d(x i , v j ) represents the distance between the i-th basic index with value x i and the cluster center v j of risk level j, d(x i , v a ) represents the distance between the i-th basic index with value x i and the cluster center v a of risk level a, m is the fuzzy index, and c is the number of risk levels; For each risk level, a new cluster center is calculated based on the membership of all basic indicators to the risk level and the value of the basic indicators. The calculation formula is: Among them, v j ′ represents the cluster center of the updated risk level j, and x i is the value of the i-th basic index, and n is the number of basic indexes; If the iteration stop condition is met, the iteration is stopped and the final membership of each basic indicator to each risk level is output.

3. The network security risk hidden danger monitoring and early warning method according to claim 2, wherein The steps of constructing the basic risk membership matrix include: Arrange the membership degrees of each basic index belonging to each risk level in the order of the index and the order of the risk levels to form a basic risk membership degree matrix U. The element u in the matrix U ij represents the membership degree of the i-th basic index to the j-th risk level.

4. The network security risk hidden danger monitoring and early warning method according to claim 2, wherein After the step of applying the fuzzy C-means clustering algorithm to calculate the risk membership of each basic indicator, the method further includes: The membership degree of each basic indicator to each risk level is taken as the condition attribute, and the risk level is taken as the decision attribute to construct a decision table; The membership of each risk level in the decision table is simplified to retain the membership that has an important impact on each risk level.

5. The network security risk and potential threat monitoring and early warning method according to claim 4, characterized in that The step of simplifying the membership of each risk level in the decision table to retain the membership that has a significant impact on each risk level includes: Calculate the conditional entropy of each risk level membership relative to the risk level, and calculate the increase in conditional entropy after removing it from the risk level membership set; The risk level membership with the highest conditional entropy increase is added to the simplified set as the initial set; Add the remaining risk level memberships to the reduced set one by one until the reduced set can distinguish all the different risk levels in the decision table, and check whether the positive domain of the reduced set changes after each addition of risk level membership; If the positive domain remains unchanged, remove it from the reduced set; When the conditional entropy no longer decreases after adding new risk level memberships, stop adding risk level memberships to the reduced set.

6. The network security risk and potential hazard monitoring and early warning method according to claim 3, wherein The step of constructing a dimensional risk membership matrix corresponding to all dimensional indicators through matrix operation based on the basic risk membership matrix and the first indicator weight includes: For each dimension, the basic risk membership submatrix corresponding to each basic indicator contained in it and the weight of the first indicator are weighted summed to obtain the risk membership of each dimension. The calculation formula is: D k = U k × W 1k , Among them, D k is the risk membership degree vector of the k-th dimension, K is the number of dimensions, U k is the basic risk membership degree sub-matrix corresponding to each basic index included in the k-th dimension, W 1k is the first index weight sub-vector corresponding to each basic index included in the k-th dimension; The risk membership vectors of all dimensions are arranged in dimensional order to form a dimensional risk membership matrix D, where each element in the dimensional risk membership matrix represents the comprehensive membership of each dimension at different risk membership levels.

7. The network security risk and potential threat monitoring and early warning method according to claim 6, wherein The dimensional risk membership matrix and the second indicator weight are combined to calculate the membership to obtain the total risk membership of network security, including: Perform matrix multiplication operation on the dimensional risk membership matrix D and the second indicator weight vector W2 to obtain a total risk membership vector Y, and the calculation formula is: Y=D×W2.

8. The network security risk and potential hazard monitoring and early warning method according to claim 7, characterized in that The step of performing safety warning according to the total risk affiliation degree comprises: Determine the warning level, including no warning, light warning, medium warning and heavy warning; Set membership thresholds for each warning level; Compare the total risk membership value with the membership threshold of each warning level to determine the warning level that meets the conditions; Issue corresponding safety warnings according to the determined warning levels.

9. A network security risk and potential threat monitoring and early warning system for implementing the network security risk and potential threat monitoring and early warning method described in any one of claims 1 to 8, characterized in that, The device comprises: Data collection module: used to collect basic data of the network environment; Indicator determination module: used to determine indicators related to network security risks, including basic indicators and dimensional indicators; Membership conversion module: used to apply the fuzzy C-means clustering algorithm to calculate the risk membership of each basic indicator and construct the basic risk membership matrix; Weight determination module: used to determine the first indicator weight and the second indicator weight, wherein the first indicator weight is used to measure the relative importance of each basic indicator in its own dimension, and the second indicator weight is used to measure the relative importance of each dimension in the overall risk; Dimension membership module: used to construct a dimensional risk membership matrix corresponding to all dimensional indicators through matrix operations based on the basic risk membership matrix and the first indicator weight; Total membership module: used to calculate the membership of the dimensional risk membership matrix and the second indicator weight to obtain the total risk membership of network security; Early warning module: used to issue safety warnings based on the overall risk affiliation.