Network security situation assessment method fusing fuzzy clustering analysis and fuzzy comprehensive evaluation decision

By integrating fuzzy clustering analysis and fuzzy comprehensive judgment decision-making methods, the flexibility and adaptability of network security situation awareness are solved, and dynamic assessment and accurate early warning of network security situation are achieved.

CN120342780AActive Publication Date: 2025-07-18CHENGDU UNIV OF INFORMATION TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510780752.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-18
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

The existing network security situation awareness methods cannot flexibly adapt to the dynamic changes in the network security situation, it is difficult to cover new attacks and unknown threats, and it is difficult to fully capture the correlation between events, resulting in the inability to discover new threats in a timely manner.

Method used

The method of fusion fuzzy clustering analysis and fuzzy comprehensive judgment decision-making is adopted, and the data is standardized through the translation-extreme transformation method, the fuzzy similarity matrix and fuzzy equivalent matrix are constructed, the characteristic attributes of dynamic clustering are determined, the weight is determined in combination with the hierarchical analysis method, and the fuzzy comprehensive judgment matrix is calculated to realize network security situation evaluation.

Benefits of technology

It realizes the flexibility and adaptability of network security situation evaluation, can respond to changes in the network environment in a timely manner, comprehensively consider the fuzzy interaction and weight distribution of various clustering factors, and improves the accuracy and reliability of the evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342780A_ABST
    Figure CN120342780A_ABST
Patent Text Reader

Abstract

The invention discloses a network security situation assessment method fusing fuzzy clustering analysis and fuzzy comprehensive judgment decision, which relates to the technical field of network security, and comprises the following steps: firstly, acquiring an initial data matrix, standardizing by using a translation-range transformation method, constructing a fuzzy similar matrix by using a similar coefficient-quantitative product method, and establishing a fuzzy clustering result; then, on the basis of closure transfer characteristics, a fuzzy equivalence matrix is obtained, dynamic clustering is carried out, and a first-level situation factor set and a second-level situation factor set are constructed; according to expert suggestions, a feature attribute single-factor fuzzy mapping set of each cluster is obtained, and a corresponding weight vector is obtained by using an analytic hierarchy process; and a fuzzy comprehensive evaluation matrix is calculated by using a weighted average operator, and then the condition of the network security situation is obtained through a maximum membership principle. Therefore, by adopting the method, the fuzzy interaction and weight distribution of each clustering factor can be comprehensively considered, the network security situation assessment is realized, and the assessment framework is more flexible and higher in adaptability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security situation assessment method that combines fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making. Background Art

[0002] With the increasing complexity and diversification of network security threats, ensuring the security and stability of the network has risen to an urgent task for social development. The importance of network security situation awareness has become increasingly prominent. It is not only the cornerstone of maintaining network security but also the key technology for enhancing network defense capabilities and ensuring the stability of the network environment.

[0003] Currently, network security situation awareness plays an irreplaceable role in blocking potential security threats and optimizing defense strategies. However, in traditional models, the fixed nature of indicators and their static definitions make it impossible to flexibly adapt to the dynamic changes in the network security situation and adjust in a timely manner to deal with emerging and unexpected security events. Secondly, the existing indicators have limited generalization ability and are difficult to cover the monitoring of unknown attacks and zero-day vulnerabilities, resulting in the inability to effectively warn of new types of attacks. Moreover, due to the complexity of network security events, the current indicator system is difficult to comprehensively capture the correlations between events, thus unable to reveal deeper security threats.

[0004] Therefore, it is necessary to provide a network security situation assessment method that can flexibly respond to changes in the network environment, and at the same time quickly adjust assessment indicators according to changes in threat intelligence and analyze their degree of association to ensure that new threats can be discovered and addressed in a timely manner. Summary of the Invention

[0005] The purpose of the present invention is to provide a network security situation assessment method that combines fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making, which can effectively conduct security situation assessment and has stronger flexibility and adaptability.

[0006] To achieve the above purpose, the present invention provides a network security situation assessment method that combines fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making, including the following steps: S1. Use the characteristic attributes of different attack types as the first-level index domain, and use the attack types as the second-level index traits to obtain an initial data matrix; S2. Standardize the initial data matrix using the translation-range transformation method, and based on the standardized matrix, obtain the similarity measure of each pair of characteristic attributes through the similarity coefficient-dot product method, and then construct a fuzzy similarity matrix; S3. Based on the closure transfer, use the fuzzy similarity matrix to obtain a fuzzy equivalence matrix, and set a threshold through analyzing the fuzzy equivalence matrix for dynamic clustering, and then construct a first-level situation factor set and a second-level situation factor set; S4. Abstract the scenarios of network security situation assessment into a judgment set, and conduct single-factor judgment on the characteristic attributes of the secondary situation factor set to obtain the single-factor fuzzy mapping set of the characteristic attributes of each cluster; S5. Use the analytic hierarchy process to obtain the judgment matrices of the primary situation factor set and the secondary situation factor set respectively, and obtain the corresponding weight vectors according to the judgment matrices; S6. Calculate the fuzzy comprehensive judgment matrix using the weighted average operator, and then obtain the situation value through the maximum membership degree principle, and further obtain the status of the network security situation.

[0007] Preferably, construct a fuzzy similarity matrix, and the formula is as follows: ; where, , is the similarity between the th characteristic attribute and the th characteristic attribute, , are respectively the th characteristic attribute of the th attack type and the th characteristic attribute of the th attack type.

[0008] Preferably, dynamic clustering divides the primary index domain into , where is the number of classifications in dynamic clustering, and , ; The set of each cluster is the primary situation factor set, and the set , of the characteristic attributes in each cluster is the secondary situation factor set, where .

[0009] Preferably, obtain the fuzzy equivalence matrix, including using the fuzzy similarity matrix and successively finding the square, as follows: ; where, is the fuzzy similarity matrix. When = , is the fuzzy equivalence matrix.

[0010] Preferably, the single-factor fuzzy mapping set is based on the suggestions and experiences of network security experts for the secondary situation factor set of Perform single - factor evaluation on each characteristic attribute, and then for each cluster of characteristic attributes, for the network security situation evaluation set The membership degree of each element Assign values to obtain the single - factor fuzzy mapping set of the characteristic attributes of each cluster Furthermore, obtain the single - factor evaluation matrix of the characteristic attributes of each cluster .

[0011] Preferably, calculate the fuzzy comprehensive evaluation matrix as follows: Let the secondary situation factor set The corresponding weight vector is , and use the average weighted operator to and Perform calculations to obtain the comprehensive evaluation matrix of the characteristic attributes in each cluster: , ; In the formula, Represents the average weighted operator; Combine the comprehensive evaluation matrices of the characteristic attributes in each cluster to obtain the total evaluation matrix as: ; Similarly, let the weight vector of the primary situation factor set be , and then use the average weighted operator to obtain the comprehensive evaluation matrix.

[0012] Preferably, the maximum membership degree principle includes selecting the situation value with the highest membership degree from the evaluation set to minimize the fuzziness and uncertainty of the situation assessment, and further the situation of the network security situation.

[0013] Therefore, the network security situation assessment method of the present invention that combines fuzzy clustering analysis and fuzzy comprehensive evaluation decision - making has the following technical effects: (1) By using fuzzy clustering analysis, dynamically cluster the characteristic attributes of various network attacks, thereby constructing the primary situation factor set and the secondary situation factor set, making the evaluation framework more flexible and adaptable.

[0014] (2) Apply the fuzzy comprehensive evaluation decision - making technology, comprehensively consider the fuzzy interaction and weight distribution of each clustering factor, and determine the weights of each index through the analytic hierarchy process to ensure the effectiveness and reliability of the evaluation results, thereby realizing the network security situation assessment.

[0015] Next, through the accompanying drawings and embodiments, the technical solutions of the present invention will be further described in detail. Description of the Drawings

[0016] Figure 1It is a schematic diagram of fuzzy clustering analysis in an embodiment of a network security situation assessment method that integrates fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making; Figure 2 It is a schematic diagram of a fuzzy equivalence matrix construction model in an embodiment of a network security situation assessment method that integrates fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making; Figure 3 It is a schematic diagram of fuzzy comprehensive evaluation decision-making in an embodiment of a network security situation assessment method that integrates fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making; Figure 4 It is a heat map of fuzzy equivalence relationship in an embodiment of a network security situation assessment method that integrates fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making; Figure 5 It is a dynamic clustering analysis diagram in an embodiment of a network security situation assessment method that integrates fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making. Detailed implementation mode

[0017] The present invention can be more specifically explained through the following embodiments. The purpose of disclosing the present invention is to protect all changes and improvements within the scope of the present invention. The present invention is not limited to the following embodiments.

[0018] The current network environment is becoming increasingly complex, and the emerging diverse network attack methods pose a major challenge to network security situation awareness. Understanding and analyzing the characteristic attributes of these network attacks is crucial for maintaining network security. These characteristic attributes (such as the data inflow volume, transmission delay, transmission rate, etc. of nodes) are key indicators for describing the characteristics of network nodes or connections. Based on this, this embodiment uses fuzzy clustering analysis to systematically classify these attributes, which helps to identify the internal connections and differences between different attributes, thereby improving the accuracy and reliability of network security situation assessment, as Figure 1 shown.

[0019] As a highly adaptable data processing technology, fuzzy clustering analysis allows for the fuzzy membership of data points, that is, a data point can be simultaneously classified into multiple categories. This flexibility in classification is particularly suitable for processing network security data with cross characteristics, because the characteristic attributes of network attacks are often intertwined and complex, and it is not easy to be classified into a single clear category. Through the fuzzy clustering method, the commonalities and differences of different network attack types can be deeply understood, providing a new perspective and technical path for network security situation assessment.

[0020] In this embodiment, in-depth fuzzy clustering analysis is carried out with the NUSW-NB15 dataset as the research object, which contains seven key characteristic attributes of nine types of network attack types, as shown in Table 1.

[0021] Table 1 Description of Attack Types and Their Characteristic Attributes in the NUSW-NB15 Dataset ;

[0022] As Figure 2 shown, by constructing a fuzzy equivalence matrix, the similarity and mutual correlation between objects or variables are quantified and revealed, so as to analyze the potential correlation of the characteristic attributes of different attack types. It describes the relationship between different entities through a numerical method, thus providing a perspective for quantitative interaction. In this embodiment, the characteristic attributes of different attacks in the network environment are abstracted as the research object, and the similarity between these characteristic attributes is numerically represented by means of a fuzzy equivalence matrix, which provides an effective way for constructing the first-level and second-level network situation factor sets, and can also carefully evaluate the correlation and linkage between the characteristic attributes of different attacks, and further provide a more accurate benchmark for calculating the situation value of the network security situation, as follows: (1) Matrix initialization: The characteristic attributes of different attacks are used as the elements in the domain and set as the first-level index domain, while the attack type is used as its second-level index trait and set as , . In this embodiment, , . Based on this, an initial data matrix composed of characteristic attributes and attack types is constructed as follows: .

[0023] (2) Data standardization: In order to ensure that the characteristic attributes of network security situation can be objectively processed and analyzed in fuzzy clustering analysis, the "translation-range transformation method" is used to standardize the initial matrix composed of characteristic attributes and attack types. This method reasonably translates and scales the data, which not only ensures that the data follows a given standard distribution, but also ensures that different measurement dimensions, such as attack duration, data inflow, data transmission rate, and network bandwidth and other attributes, can have similar measurement scales in the analysis, so as to reduce the result deviation and improve the accuracy and reliability of clustering analysis.

[0024] (3) Establish a fuzzy similarity matrix: Each characteristic attribute in the standardized matrix can be regarded as a characteristic vector, the dimension of which is consistent with the number of attack types involved, and the element values in the characteristic vector show the representation of this network characteristic under various attack conditions.

[0025] The similarity between eigenvectors can be measured by calculating the dot product between them, which reflects the similarity degree of two vectors in each dimension. The larger the value, the higher the similarity. Specifically, for the standardized matrix, the "similarity coefficient - dot product method" is adopted, and the similarity measurement results between each pair of characteristic attributes form a fuzzy similarity matrix. The elements of this matrix represent the similarity degree between and ; where .

[0026] (4) Closure transitivity: Similarity measurement is usually used to compare the similarity degree between two objects. When there are multiple objects to be compared, a similarity matrix can be constructed to represent the similarity relationship between them. However, these similarity relationships may not be transitive, that is, if object is similar to object , and object is similar to object , it does not necessarily mean that object is similar to object . This requires the use of closure transitivity to handle.

[0027] In this embodiment, the fuzzy similarity matrix formed by the similarity measurement results of each pair of characteristic attributes is used to form a fuzzy equivalence matrix through closure transitivity, which can further transmit and strengthen the similarity relationship between characteristic attributes; moreover, transfer rules are introduced, and by iteratively applying these rules, the directly similar relationship can be transmitted to the indirectly similar relationship.

[0028] Specifically, during the transfer process, first define a similarity relationship on the matrix , and continuously update the fuzzy similarity matrix by multiplying the current fuzzy similarity matrix with , that is, integrate the new similarity relationship together. Then, starting from the fuzzy similarity matrix , successively calculate the square (such as ). When appears for the first time, it indicates that has transitivity. At this time is the required transitive closure , and at the same time it is also the fuzzy equivalence matrix , and each element reflects the similarity degree between characteristic attributes. The fuzzy equivalence matrix is: ; where represents the The numerical representation of the similarity degree between the characteristic attributes of the rows and the characteristic attributes of the columns. This matrix covers the characteristic attributes of various attack types, provides a structured and quantitative display form for the similarity and correlation between characteristic attributes, carries comprehensive information about the similarity between each characteristic attribute, and also provides a reference for in-depth understanding of the internal relationship between different characteristic attributes, becoming the core basis for further analysis and clustering research. By precisely quantifying the similarity degree between these characteristic attributes, the dynamic clustering method can more effectively identify and divide data groups with high similarity.

[0029] As Figure 4 shown, the fuzzy equivalence matrix is visualized through a heatmap (Heatmap) to intuitively understand the relationship between each characteristic attribute. The value at the diagonal position is 1, which reflects the similarity degree between itself and itself. In other words, for the same characteristic attribute, the similarity degree within it is the highest. The off-diagonal positions, on the other hand, represent the similarity between different characteristic attributes. This similarity is based on multiple factors, including attack characteristics, behavior patterns, and affected systems. The value at each position is represented by fuzzy logic, ranging from 0 to 1. The closer the value is to 1, the higher the similarity; the closer it is to 0, the lower the similarity. This numerical representation of fuzzy logic can more accurately quantify the similarity between different characteristic attributes, thus playing an important role in the dynamic clustering process.

[0030] By analyzing the similarity between each characteristic attribute and other characteristic attributes, it is found that the presentation of these equivalence relationships is diverse. Some have high stability, while some show significant fluctuations or changes. The analysis of these differences can obtain important clues for the clustering of characteristic attributes. These clues not only help determine whether specific attributes should be classified into the same category but also help understand the degree of interaction and influence between these attributes. Specifically, if there is a stable equivalence relationship between certain characteristic attributes, this usually means that there is an inherent and strong correlation between these attributes, and their relationship pattern is stable and persistent. This stable relationship often helps to identify the essential characteristics of network attacks or the key indicators in the field of network security. In contrast, those characteristic attributes that show obvious fluctuations or changes may indicate that the internal relationship between the attributes is relatively weak, or that these relationships are more affected by external factors, such as a sudden increase in network traffic, the emergence of new attack methods, or the change of security policies.

[0031] In dynamic clustering, it is necessary to explore the fuzzy equivalence matrix in detail and set several thresholds, and then further optimize the thresholds. First, The elements in it are sorted from small to large and duplicates are removed, obtaining six distinct partitioning thresholds, which are 1.0000, 0.8561, 0.4074, 0.1586, 0.0086, and 0 respectively. Then, according to the opinions and suggestions of domain experts, 0.4074 is selected as the optimal classification threshold. When the threshold is [condition], the characteristic attributes are divided into four different categories, and at this time, the first-level situation factor set can be obtained, where , , , are the second-level situation factor sets respectively, as shown in Figure 5 . It should be noted that the setting of the threshold is crucial and needs to be flexibly adjusted according to research requirements. If the threshold is set too low, many element values in the matrix will be close to the threshold, indicating extensive similarity among characteristic attributes. On the contrary, a higher threshold setting will result in sparse connection relationships, and only a very small number of characteristic attributes meet the criteria of high similarity. These characteristics are often more important and have specific meanings. Therefore, in practical applications, appropriately setting the threshold to construct the first-level and second-level network situation factor sets is the key to effectively reflecting the network security situation.

[0032] As shown in Figure 3 , a fuzzy comprehensive evaluation decision model is constructed. In this embodiment, for nine types of network attacks, the average values of their respective characteristic attributes are extracted as the benchmark values characterized by seven key characteristic attributes, refining the characteristic attributes from diverse and complex data, so as to define a set of representative characteristic attribute values for each type of network attack, facilitating subsequent fuzzy comprehensive evaluation decision-making.

[0033] In the stage of fuzzy comprehensive evaluation decision-making, first, according to the semantic principle, a five-level evaluation standard is determined through a hierarchical evaluation method, providing a clear and practical guiding framework for the comprehensive evaluation of network security situations; at the same time, ensuring the orderliness and systematicness of the evaluation process, and improving the interpretability and operability of the evaluation results.

[0034] In this embodiment, the network security situation evaluation set [good, good, average, poor, bad]. According to the suggestions of experienced network security experts, the membership degrees of the characteristic attributes of each cluster to all elements in the network security situation evaluation set are assigned. The range of the assignment is required to be between 0 and 1, and it is required that the sum of the membership degrees of the characteristic attributes of each cluster to the elements in the network security situation evaluation set is 1. According to the membership degrees of the characteristic attributes of each cluster to all elements in the network security situation evaluation set, the single-factor evaluation matrix of the characteristic attributes is formed. The second-level situation factor set , , , are respectively mapped to the judgment set ; Among them, ; ; ; .

[0035] In addition, during the process of network situation assessment, not all attributes contribute equally to the network situation assessment. In this embodiment, according to the suggestions and experience of experts in the field, each factor in the first-level situation factor set ( ) is compared pairwise, and a judgment matrix of the first-level situation factor set is constructed in combination with Table 2 as follows: .

[0036] Through the judgment matrix of the first-level situation factor set, a quantitative assessment of the relative importance of different situation factors can be carried out. Moreover, during the process of establishing the judgment matrix, the internal connectivity and action mechanism between factors are emphasized, ensuring the rationality of the analysis process. The construction of the judgment matrix is a meticulous and comprehensive process, involving a detailed assessment of the influence difference between each pair of factors, ensuring that the final obtained weight distribution can accurately reflect the actual role and importance of each factor in the network security situation assessment.

[0037] Table 2 1-9 scale table ;

[0038] After establishing the judgment matrix, the analytic hierarchy process (AHP) is adopted as the main method for determining weights to accurately measure the weights of the first-level situation factor set and the second-level situation factor set. First, a key eigenvalue analysis is carried out on this judgment matrix, specifically including solving the maximum eigenvalue and its corresponding eigenvector , is the weight vector of each index in the factor set. It should be particularly noted that to ensure the applicability of the weight vector, if the sum of the elements in the eigenvector is not equal to 1, it needs to be normalized so that the sum of its element values reaches 1, ensuring the probability interpretation and application prerequisite of the weight coefficient. In this embodiment, the maximum eigenvalue of the first-level factor set judgment matrix is , and a consistency test is carried out as follows: ; In the formula, is the random consistency ratio, is the consistency index of the judgment matrix, is the average random consistency index of the corresponding order. Since , the judgment matrix established by the analytic hierarchy process is effective and meets the consistency. It can be seen that the weight coefficient distribution of the primary factor set this time is reasonable, and its eigenvector is: ; Similarly, the weight coefficients of the secondary situation factor set are obtained by using the analytic hierarchy process. At the same time, considering that in the primary situation factor set , and both contain only one situation factor. Therefore, only the analytic hierarchy process needs to be carried out on , and its eigenvector is obtained as: ; Then, the weighted average type operator is used to find the comprehensive evaluation matrix of : ; Since both have only one situation factor, their comprehensive evaluation matrices are: ; ; ; In summary, the total evaluation matrix is: ; Then, using the weighted average type operator, the primary index weight coefficient and the total evaluation matrix are operated to obtain the final fuzzy comprehensive evaluation matrix: ; Finally, according to the maximum membership degree principle, the situation value is: ; At this time, The "poor" element in the evaluation set corresponding to the column where it is located conforms to the actual situation of the current network security situation.

[0039] Therefore, the network security situation assessment method of the present invention that combines fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making can comprehensively consider the fuzzy interaction and weight distribution of each clustering factor, realize network security situation assessment, and the assessment framework is more flexible and has stronger adaptability.

[0040] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify or equivalently replace the technical solutions of the present invention, and these modifications or equivalent replacements cannot make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A network security situation assessment method that integrates fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making, characterized in that, It includes the following steps: S1. Take the characteristic attributes of different attack types as the first-level index domain, and take the attack type as the second-level index trait to obtain the initial data matrix; S2. Standardize the initial data matrix by using the translation-range transformation method, and based on the standardized matrix, obtain the similarity measure of each pair of characteristic attributes by using the similarity coefficient-dot product method, and then construct a fuzzy similarity matrix; S3. Based on the closure transfer, use the fuzzy similarity matrix to obtain a fuzzy equivalence matrix, and set a threshold through analyzing the fuzzy equivalence matrix for dynamic clustering, and then construct a first-level situation factor set and a second-level situation factor set; S4. Abstract the context of network security situation assessment as a judgment set, and conduct single-factor judgment on the characteristic attributes of the second-level situation factor set to obtain the single-factor fuzzy mapping set of the characteristic attributes of each cluster; S5. Use the analytic hierarchy process to obtain the judgment matrices of the first-level situation factor set and the second-level situation factor set respectively, and obtain the corresponding weight vectors according to the judgment matrices; S6. Use the weighted average type operator to calculate the fuzzy comprehensive judgment matrix, and then obtain the situation value through the maximum membership degree principle, and then obtain the situation of network security situation.

2. The network security situation assessment method integrating fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making according to claim 1, characterized in that Construct a fuzzy similarity matrix, and the formula is as follows: ; Among them, , is the similarity between the -th characteristic attribute and the -th characteristic attribute, , are respectively the -th characteristic attribute of the -th attack type and the -th characteristic attribute of the -th attack type.

3. The network security situation assessment method integrating fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making according to claim 1, characterized in that, Dynamic clustering divides the first-level index domain into , where is the number of categories in dynamic clustering, and , ; The set of each cluster is the first-level situation factor set, and the set of characteristic attributes in each cluster , is the second-level situation factor set, where .

4. The network security situation assessment method integrating fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making according to claim 1, characterized in that Obtain a fuzzy equivalence matrix, including using the fuzzy similarity matrix to successively calculate the square, as follows: ; Among them, is a fuzzy similarity matrix. When = then is a fuzzy equivalence matrix.

5. The network security situation assessment method integrating fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making according to claim 1, characterized in that According to the suggestions and experiences of network security experts, the single-factor fuzzy mapping set conducts single-factor evaluation on the characteristic attributes of the secondary situation factor set of characteristic attributes. Then, the membership degrees of the characteristic attributes of each cluster to each element of the network security situation evaluation set are assigned values to obtain the single-factor fuzzy mapping set of the characteristic attributes of each cluster, and further obtain the single-factor evaluation matrix of the characteristic attributes of each cluster 6. The network security situation assessment method integrating fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making according to claim 1, characterized in that, Calculate the fuzzy comprehensive judgment matrix, as follows: Let the secondary situation factor set The corresponding weight vector is , and use the average weighted operator to and Perform calculations to obtain the comprehensive evaluation matrix of the characteristic attributes in each cluster: , ; In the formula, represents an average weighted operator; Combine the comprehensive judgment matrices of the characteristic attributes in each cluster to obtain the total judgment matrix as: ; Similarly, obtain the first-level situation factor set The weight vector of is , and then use the average weighted operator to calculate to obtain the comprehensive evaluation matrix.

7. The network security situation assessment method integrating fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making according to claim 1, characterized in that The maximum membership degree principle involves selecting the situation value with the highest membership degree from the evaluation set to minimize the fuzziness and uncertainty of the situation assessment, and thus the status of the network security situation.

Citation Information

Patent Citations

  • Network security situation fuzzy evaluation method based on uncertain data

    CN102457411A

  • Network security prediction method based on dynamic fuzzy clustering and gray neural network

    CN112260870A

  • Hierarchical partner risk evaluation using fuzzy logic

    US20250037056A1