Network security situation awareness system

Through the feature dictionary module, situational awareness module and BP neural network to analyze the similarity and causality of network attack events, the problem of difficult to predict network attacks in the existing technology is solved, early warning and prevention of network attacks is achieved, and the active defense capabilities of network security are improved.

CN120342790AActive Publication Date: 2025-07-18LUZHOU XINGLU IND DEVELOPMENT CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510820299.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-07-18
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

Existing network security situation awareness systems are difficult to predict cyber attacks, especially targeted attacks, and lack the ability to warn and prevent attacks.

Method used

The feature dictionary module is used to preset the keyword database, combine the situational awareness module to monitor and disclose network information, and the self-identification module captures network data. The analysis module analyzes the similarity and causality of network attack events through the BP neural network, and uses tree structure data and regional correction similarity to judge the causality of network attacks.

Benefits of technology

It realizes early warning and prevention of network attacks, can identify network system characteristics, analyze the purpose and cause and effect of attacks, and improves the active defense capabilities of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342790A_ABST
    Figure CN120342790A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network security, in particular to a network security situation awareness system, which comprises a feature dictionary module used for presetting a keyword library; the situation awareness module is used for monitoring the public network information and extracting attacked target information and network attack information in a network attack event occurring in the public network information through a keyword library; the self-recognition module is used for capturing network data in a network system, extracting a target keyword in the network data through a keyword library and judging network system information; and the analysis module is used for acquiring the network attack events of the situation awareness module, the analysis module further comprises a trained BP neural network, and the BP neural network is used for inputting network system information and outputting causality of occurrence of each piece of network attack information based on historical network attack events. By adopting the technical scheme provided by the invention, the currently reported network attack characteristics can be sensed, and the causality of the network attack can be predicted by combining the characteristics of the network system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a network security situation awareness system. Background Art

[0002] A network security situation awareness system is an intelligent security protection system based on big data and artificial intelligence technologies. By collecting multi-source data such as network traffic, device logs, and threat intelligence in real time, and combining machine learning and rule engines for in-depth analysis, it dynamically identifies abnormal behaviors, attack patterns, and potential risks. Its core value lies in converting fragmented security information into a global visual situation. For example, through attack path tracing, risk heat maps, etc., it helps managers quickly locate the threat source, evaluate the vulnerability of assets, and predict attack trends, thus supporting the transformation from passive response to active defense. This system is widely used in fields such as finance, energy, and government affairs. It can not only improve the threat response efficiency, reduce the losses of security incidents, but also meet regulatory requirements through automated compliance reports, becoming a key infrastructure for building a resilient security architecture in the digital age.

[0003] In the prior art, for example, the patent publication number CN110049015B discloses a network security situation awareness system, which monitors the network security of a power monitoring system by collecting data in the power monitoring system in real time and analyzing the data. The patent publication number CN117097539A discloses a network security state awareness method and system based on situation awareness. According to the current attack process corresponding to each device in the network, it evaluates the current security state of each device, and combines the current security states of all devices to generate a real-time security state awareness result of the network. However, in the prior art, only data generated due to its own being attacked is collected, and it is difficult to predict attacks. Network attacks are human events and often have a certain degree of pertinence. For example, attacking enterprises in the same industry, scale, or location. Therefore, by perceiving the characteristics of existing reported network attacks and combining the characteristics of its own network system, it is possible to effectively warn against and prevent network attacks. Summary of the Invention

[0004] To solve the above problems, the present invention provides a network security situation awareness system for perceiving the characteristics of existing reported network attacks and combining the characteristics of its own network system to predict the causality of being attacked by a network attack.

[0005] To achieve the above object, the technical solution of the present invention is as follows: A network security situation awareness system, comprising: A feature dictionary module: used to preset a keyword library, the keyword library includes a number of target keywords and attack keywords, the target keywords are bound with the industry, system type, and geographical information where the target keywords appear, and the attack keywords are bound with the attack method, source, time, and purpose corresponding to the attack keywords; Situation awareness module: used to monitor public network information, extract the target information and network attack information of network attack events occurring in the public network information through a keyword library, where the target information under attack includes industry, system type and geographical information, and the network attack information includes attack method, source, time and purpose; Self-identification module: used to capture network data in the network system, extract target keywords from the network data through a keyword library, and judge the industry, system type and geographical information of the network system; Analysis module: used to obtain network attack events of the situation awareness module, divide the network attack events into new network attack events and historical network attack events by time nodes; a similarity judgment function is set in the analysis module, and the similarity judgment function is used to judge the similarity between two network attack events; the analysis module is used to calculate the number of network attack events with similarity within a preset value range to the new network attack event in the historical network attack events, and calculate the causality based on the number of network attack events within the preset value range and the time node distribution; the analysis module also includes a trained BP neural network, and the BP neural network is used to train based on the new network attack event, historical network attack events and their causality samples, and the BP neural network is used to input the industry, system type and geographical information of the network system and output the causality of the occurrence of each network attack information based on the historical network attack events.

[0006] The following beneficial effects can be obtained by adopting the above scheme: 1. In this scheme, the self-identification module can effectively identify the user's network system, extract keywords therefrom based on network data packet capture, and judge the characteristics of the user's network system. The situation awareness module obtains information in the public network, and the public network can be information in news, reports or professional websites, extracts network attack events occurring in the public network information, and analyzes the information of each network attack event.

[0007] 2. In this scheme, since network attacks are human behaviors with certain purposes, attacks may be launched when the target meets their purposes. Therefore, the purpose of network attacks can be analyzed through the big data accumulated in the public network information. First, it is necessary to judge which network attacks are for the same purpose. The analysis module can analyze the similarity between two network attacks. A high similarity indicates that there is the same purpose between the two network attacks. In addition, the same purpose does not necessarily mean there is an association. Therefore, the analysis module is also used to calculate the causality based on the number of network attack events and the time node distribution. A high causality indicates that multiple attacks are indeed driven by the same purpose, and the characteristics of its related cases can be used to judge whether the user's network system is also a target for potential attackers to achieve their purposes.

[0008] 3. In this solution, the BP neural network can form a mapping between each feature and network attacks through training. By inputting the features of the user's network system, it can determine the causality of each network attack information based on the features of the user's network system, so that the user can carry out relevant protection or means to solve network attacks.

[0009] Furthermore, both the target information of the attacked object and the network attack information extracted in the situation awareness module are tree-structured data. In the tree-structured data, the parent node data is the parent class of the child node data.

[0010] Beneficial effect: Usually, a network system has multiple sub-modules, and the sub-modules serve in domain segmentation. Therefore, the extracted features are also represented by tree-structured data that can represent the parent-child relationship, and each parent node data is the parent class of the child node data. In this way, the parent-child relationship can be well summarized and the consistency of the parent-child relationship can be maintained, which is convenient for subsequent similarity judgment.

[0011] Furthermore, the industry, system type, and geographical information of the network system judged in the self-identification module are also tree-structured data. The target keyword extraction of the self-identification module includes variable names and variable values in network data.

[0012] Beneficial effect: When the self-identification module extracts target keywords, in addition to extracting variable values, according to the naming habits during system design, variable names can also reflect the relationship between the network system and industry, system type, and geographical information to a certain extent.

[0013] Furthermore, the keyword library in the feature dictionary module includes Chinese words and English words.

[0014] Beneficial effect: The network system mixes languages such as Chinese and English. Therefore, the feature dictionary module needs to include at least Chinese words and English words.

[0015] Furthermore, in the analysis module, both newly emerging network attack events and historical network attack events are deduplicated.

[0016] Beneficial effect: The same network attack events may repeatedly appear in the publicly available network information. Therefore, it is necessary to deduplicate newly emerging network attack events and historical network attack events.

[0017] Furthermore, network attack events within one month are newly emerging network attack events, and network attack events in the time period from one month to three years are historical network attack events.

[0018] Beneficial effect: Both newly emerging network attack events and historical network attack events can be multiple within a certain period of time. Therefore, they can be classified respectively with one month and three years as time points.

[0019] Further, in the analysis module, the network attack event with the largest time node value is a new network attack event, and all those before the new network attack event are historical network attack events.

[0020] Beneficial effect: There can be only one new network attack event, so that more network attack events can be considered when calculating causality.

[0021] Further, the similarity judgment function judges the similarity based on the target information and network attack information of the two network attack events. When there are no identical nodes in the tree structure data of the two network attack events, the similarity is 0; when there are identical nodes in the tree structure data of the two network attack events, the similarity is proportional to the number of identical nodes.

[0022] Beneficial effect: Since the tree structure data is adopted, various events under the same parent class will be traced back to the same parent node. Therefore, when comparing the tree structure data, whether there is the same parent class will be directly considered. Therefore, it is only necessary to judge whether there are identical nodes to know whether the network attack events are similar, and the similarity is proportional to the number of identical nodes.

[0023] Further, when the similarity judgment function judges the similarity of geographical information, it also corrects the similarity value based on the spatial distance between the regions of the two network attack events.

[0024] Beneficial effect: The tree structure data of geographical information can reflect the belonging of the region. However, for example, cities located at the provincial border have a small spatial distance but different provincial affiliations. Therefore, when judging the similarity of geographical information, the spatial distance between the regions of the two network attack events also needs to be considered to better evaluate the relevance between the two network attack events.

[0025] Further, the causality is proportional to the number of network attack events within a preset value range, and the causality is proportional to the size of the time node.

[0026] Beneficial effect: Causality represents the probability that network attack events are driven by the same purpose. Therefore, it is proportional to the number of network attack events, and the closer the occurrence time is to the new network attack event, the greater the causality.

[0027] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 It is a schematic diagram of the modules of an embodiment of the network security situation awareness system of the present invention; Figure 2It is a logical schematic diagram of an embodiment of the network security situation awareness system of the present invention. Detailed implementation manners

[0029] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0030] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.

[0031] In the description of the present invention, it should be noted that unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0032] The following will be further described in detail through specific implementation manners: Embodiment 1:

[0033] As shown in the attached Figure 1 - Figure 2 figure: A network security situation awareness system includes: Feature dictionary module: It is used to preset a keyword library. The keyword library includes a number of target keywords and attack keywords. The target keywords are bound with the industries, system types, and geographical information where the target keywords appear. The attack keywords are bound with the corresponding attack methods, sources, times, and purposes of the attack keywords. The keyword library in the feature dictionary module includes Chinese words and English words.

[0034] Situation awareness module: It is used to monitor public network information, and extract the target information of the attacked object and network attack information in the network attack events that occur in the public network information through a keyword library. The target information of the attacked object includes industry, system type, and geographical information, and the network attack information includes attack method, source, time, and purpose. Both the target information of the attacked object and the network attack information extracted in the situation awareness module are tree-structured data. The parent node data in the tree-structured data is the parent class of the child node data. For example, the industry information is expressed as: dairy farming - cattle farming - animal husbandry - agriculture.

[0035] Self-identification module: It is used to capture network data in the network system, extract target keywords from the network data through a keyword library, and judge the industry, system type, and geographical information of the network system. The industry, system type, and geographical information of the network system judged in the self-identification module are also tree-structured data. The target keyword extraction of the self-identification module includes variable names and variable values in the network data.

[0036] Analysis module: It is used to obtain the network attack events of the situation awareness module, and divide the network attack events into new network attack events and historical network attack events according to time nodes. Both the new network attack events and the historical network attack events are de-duplicated. Among them, the network attack event with the largest time node value is the new network attack event, and those before the new network attack event are historical network attack events. A similarity judgment function is set in the analysis module, and the similarity judgment function is used to judge the similarity between two network attack events. The similarity judgment function judges the similarity based on the target information of the attacked object and the network attack information of the two network attack events. When there are no identical nodes in the tree-structured data of the two network attack events, the similarity is 0; when there are identical nodes in the tree-structured data of the two network attack events, the similarity is proportional to the number of identical nodes. When the similarity judgment function judges the similarity of geographical information, it also corrects the similarity value based on the spatial distance of the geographical areas between the two network attack events.

[0037] The analysis module is used to calculate the number of network attack events in the historical network attack events whose similarity to the new network attack event is within a preset range, and calculate the causality based on the number and time node distribution of the network attack events within the preset range. The causality is proportional to the number of network attack events whose similarity is within the preset range, and the causality is proportional to the size of the time node.

[0038] The analysis module also includes a trained BP neural network. The BP neural network is used to train based on the new network attack events, historical network attack events, and their causality samples. The BP neural network is used to input the industry, system type, and geographical information of the network system, and output the causality of the occurrence of each network attack information based on the historical network attack events.

[0039] The self-identification module can effectively identify the user's network system. Based on packet capture of network data, it extracts the keywords therein and determines the characteristics of the user's network system. The situation awareness module obtains information within the public network, which can be information in news, reports or professional websites, extracts network attack events occurring in the publicly available network information, and analyzes the information of each network attack event. Since network systems all have multiple sub-modules and the sub-modules serve in domain subdivision, the extracted characteristics are also represented using tree-structured data that can represent the parent-child relationship. And each parent node data is the parent class of the child node data, so that the parent-child relationship can be well summarized and the consistency of the parent-child relationship can be maintained, facilitating subsequent similarity judgment.

[0040] When the self-identification module extracts target keywords, in addition to extracting variable values, according to the naming convention during system design, variable names usually summarize the types represented by the variable values. For example, the variable name ID for uploading user information is usually named UserID, and the variable name for uploading object information is also named with the English name of the object + the attribute name of the object. And the network data captured is usually in the form of KEY-VALUE pairs, so the variable names can be obtained conveniently. The variable names can also reflect the relationship between the network system and the industry, system type and geographical information to a certain extent.

[0041] The network system mixes languages such as Chinese and English. Therefore, the feature dictionary module needs to include at least Chinese words and English words. For example, variable names are usually in English expressions, while variable values are in Chinese expressions. Therefore, the feature dictionary module adapts Chinese words and English words, which can effectively extract target keywords.

[0042] Since network attacks are human behaviors with certain purposes, when the target meets their purposes, attacks may be launched. Therefore, the purposes of network attacks can be analyzed through the big data accumulated in the publicly available network information. The publicly available network information usually describes the information of the attacked object, as well as the losses and impacts caused by the attacks. Thus, various keywords are extracted from the reports, the information of the attacked target and network attack information are evaluated, and a data set is formed for analysis.

[0043] When conducting analysis, first of all, it is necessary to determine which network attacks are for the same purpose. The analysis module can analyze the similarity between two network attacks. A high similarity indicates that there is the same purpose between the two network attacks. Since tree-structured data is used, various events under the same parent class will be traced back to the same parent node. Therefore, when comparing tree-structured data, whether there is the same parent class will be directly considered. Therefore, it is only necessary to determine whether there are the same nodes to know whether the network attack events are similar, and the similarity is proportional to the number of the same nodes. The tree-structured data of geographical information can reflect the affiliation of the region. However, for example, cities located on the provincial border have a small spatial distance but different provincial affiliations. Therefore, when judging the similarity of geographical information, the spatial distance between the regions of the two network attack events also needs to be considered to better evaluate the relevance between the two network attack events.

[0044] In addition, the same purpose does not necessarily mean there is a connection. For example, if the number of similar times is scarce, it is very likely that it is just attacked by chance, or the time interval is relatively long, and the relevance between the two network attack events will also be small. Therefore, the analysis module is also used to calculate the causality based on the number of network attack events and the time node distribution. A high causality indicates that multiple attacks are indeed driven by the same purpose, and the characteristics of its related cases can be used to judge whether the user's network system is also the target for potential attackers to achieve their goals.

[0045] The BP neural network can form the mapping between each feature and the network attack suffered through training. Bring in the characteristics of the user's network system, and can judge the causality of each network attack information according to the characteristics of the user's network system. When the causality is strong, it indicates that there is a potential attack source that will launch a network attack, so that the user can carry out relevant protection or means to solve the network attack.

[0046] Example 2:

[0047] The difference from the above embodiment is that the network attack events within one month are new network attack events, and the network attack events in the time period from one month to three years are historical network attack events.

[0048] Both the new network attack events and the historical network attack events can be multiple within a period of time. Therefore, they can be classified respectively with one month and three years as time points.

[0049] Obviously, the above embodiments are only examples clearly described and not limitations on the implementation manners. For those of ordinary skill in the art, other different forms of changes or alterations can be made based on the above description. It is not necessary and impossible to enumerate all the implementation manners here. And the obvious changes or alterations derived therefrom are still within the protection scope of the present invention.

Claims

1. A network security situation awareness system, characterized in that, Including: Feature dictionary module: used to preset a keyword library, which includes a number of target keywords and attack keywords. The target keywords are bound with the industries, system types, and regional information where the target keywords appear, and the attack keywords are bound with the corresponding attack methods, sources, times, and purposes of the attack keywords; Situation awareness module: used to monitor public network information, and extract the target information of the attacked targets and network attack information in the network attack events that occur in the public network information through the keyword library. The target information of the attacked targets includes industry, system type, and regional information, and the network attack information includes attack method, source, time, and purpose; Self-identification module: used to capture network data in the network system, extract target keywords from the network data through the keyword library, and judge the industry, system type, and regional information of the network system; Analysis module: used to obtain the network attack events of the situation awareness module, and divide the network attack events into new network attack events and historical network attack events by time nodes; there is a similarity judgment function in the analysis module, and the similarity judgment function is used to judge the similarity between two network attack events; The analysis module is used to calculate the number of network attack events in the historical network attack events that have a similarity with the new network attack event within a preset value range, and calculate the causality based on the number and time node distribution of the network attack events within the preset value range; the analysis module also includes a trained BP neural network, and the BP neural network is used to train based on the new network attack event, historical network attack events, and their causality samples. The BP neural network is used to input the industry, system type, and regional information of the network system, and output the causality of the occurrence of each network attack information based on the historical network attack events.

2. The cybersecurity situation awareness system according to claim 1, wherein Both the target information of the attacked targets and the network attack information extracted in the situation awareness module are tree-structured data, and the parent node data in the tree-structured data is the parent class of the child node data.

3. The network security situation awareness system according to claim 2, wherein, The industry, system type, and regional information of the network system judged by the self-identification module are also tree-structured data, and the target keyword extraction of the self-identification module includes variable names and variable values in the network data.

4. The network security situation awareness system according to claim 3, characterized in that, The keyword library in the feature dictionary module includes Chinese words and English words.

5. The cybersecurity situation awareness system according to claim 4, wherein In the analysis module, both the new network attack events and the historical network attack events are de-duplicated.

6. The network security situation awareness system according to claim 5, characterized in that, The network attack events within one month are new network attack events, and the network attack events in the time period from one month to three years are historical network attack events.

7. The network security situation awareness system according to claim 5, characterized in that In the analysis module, the network attack event with the largest time node value is the new network attack event, and all those before the new network attack event are historical network attack events.

8. The network security situation awareness system according to claim 7, characterized in that The similarity judgment function judges the similarity based on the target information of the attacked targets and the network attack information of two network attack events. When there are no identical nodes in the tree-structured data of the two network attack events, the similarity is 0; when there are identical nodes in the tree-structured data of the two network attack events, the similarity is proportional to the number of identical nodes.

9. The network security situation awareness system according to claim 8, characterized in that, When the similarity judgment function judges the similarity of regional information, it also corrects the similarity value based on the spatial distance between the regions of the two network attack events.

10. The network security situation awareness system according to claim 9, wherein The causality is directly proportional to the number of network attack events within the preset value range, and the causality is directly proportional to the size of the time node.

Citation Information

Patent Citations

  • Network security situation awareness system

    CN110049015B

  • Network security state sensing method and system based on situation awareness

    CN117097539A

  • Online recognition method for network multi-step attack intension

    CN101242278A

  • Network security situation self-adaptive active defense system and method

    CN113965404A

  • Network security event analysis method and device and storage medium

    CN115484100A