Network security data evaluation system and method based on block chain
Through a blockchain-based network security data evaluation system, natural language processing technology and security topology diagram building modules are used to solve the problem that security data information cannot be fully identified in the existing technology, and efficient, accurate evaluation and intuitive display of network security data are achieved.
Patent Information
- Application Number
- CN202510635098.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-22
AI Technical Summary
Existing blockchain technology cannot fully identify security data information in network security data evaluation, cannot intuitively display security nodes and security relationships, and cannot evaluate the system's security protection capabilities.
A blockchain-based network security data evaluation system is adopted, including data collection, preprocessing, feature vector construction, security topology graph construction, protection topology graph construction and security level evaluation modules. Security feature information is extracted through natural language processing technology, security feature vectors are constructed, security nodes and relationships are displayed, and security level reports are generated.
It significantly improves the accuracy and intuitiveness of network security data evaluation, can more comprehensively identify network security-related information, support the identification of security nodes and relationships, and provide risk suggestions and protection improvement suggestions.
Smart Images

Figure CN120358065A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, specifically to a blockchain-based network security data evaluation system, and more specifically to a blockchain-based network security data evaluation method. Background Art
[0002] With the rapid development of information technology, data security and privacy protection have become the focus of global attention. Driven by technologies such as big data, cloud computing, and the Internet of Things, data has become an important asset of enterprises. However, security issues such as data leakage and privacy infringement occur frequently, causing huge losses to individuals and enterprises. Blockchain is a distributed and decentralized data storage and transaction technology. It ensures the security of data through encryption technology and records every transaction or event through a distributed ledger, ensuring the immutability and traceability of data, showing great potential in the field of data security and privacy protection.
[0003] In recent years, extensive research has been conducted on the application of blockchain technology in data security and privacy protection. It mainly focuses on aspects such as the consensus mechanism, encryption algorithm, and smart contract of blockchain, aiming to improve the performance and security of blockchain. As well as the practical application of blockchain technology in fields such as finance, logistics, and healthcare, and the integration and innovation of blockchain technology with technologies such as big data and artificial intelligence.
[0004] The application of blockchain technology in network security data evaluation is mainly reflected in the following aspects: data traceability and verification, data privacy protection, intelligent evaluation and automation, and efficient data sharing and access.
[0005] However, the existing blockchain technology in network security data evaluation has the problems that it cannot analyze and process security data information, and cannot more comprehensively identify network security-related information. It cannot intuitively display the security nodes and security relationships in the data; it cannot evaluate the security protection ability of the system.
[0006] In the prior art, the publication number is CN119496621A, and the name is a network security data evaluation system and method based on blockchain; it includes a data processing module, a risk assessment module, a permission adjustment module and a security supervision module. The method corresponds to the system. In this application, in the data processing module, user behavior and device operation data are collected and stored in the blockchain to ensure the security and traceability of the data; the risk assessment module uses the risk assessment model and consensus mechanism distributed in each node of the blockchain to accurately analyze user behavior risks and improve the reliability of security authentication; the permission adjustment module dynamically adjusts user permissions based on the consensus assessment results and preset rules to enhance the flexibility of the system to deal with security risks; the security supervision module records the permission adjustment process to ensure the compliance and traceability of the system; thereby realizing dynamic permission management of the network security authentication system based on blockchain, improving security and flexibility in security authentication, and being able to respond to various security challenges and user behavior changes in a timely manner.
[0007] The above information disclosed in the above Background section is only for enhancement of understanding of the background of the present disclosure and therefore it may contain information that does not form the prior art that is already known to one of ordinary skill in the art. Summary of the invention
[0008] The purpose of the present invention is to provide a network security data evaluation system and method based on blockchain to solve the problems raised in the above background technology.
[0009] To achieve the above object, the present invention provides the following technical solutions: A network security data evaluation system based on blockchain, including a data acquisition module, a preprocessing module, an identification module, a feature vector construction module, a security topology map construction module, a protection topology map construction module and a security level evaluation module: The recognition module is used to perform feature recognition on the security data information preprocessed by the preprocessing module, extract security-related feature information, and obtain a final keyword vector set and a final mapping probability; The security topology map construction module is used to construct a security topology map to display the security nodes and security relationships in the data, that is, to construct a security topology map by combining the final keyword vector set with the final mapping probability; The protection topology map construction module is used to analyze the security topology map, identify security nodes and security relationships, and construct a security protection topology map.
[0010] Furthermore, the data collection module is used to collect security data information of the blockchain, including system log data and user behavior data; The preprocessing module is used to preprocess the collected security data information, including cleaning, standardization and denoising the security data information; The feature vector construction module is used to convert the extracted feature information into vector form; The security level evaluation module is used to evaluate the security protection topology map, generate a security level report, and evaluate the network security status.
[0011] Furthermore, the recognition module extracts keywords from the security data information through natural language processing technology to recognize the feature information related to network security; The natural language processing technology first inputs the preprocessed security data information into a pre-trained language model to ensure that the text format meets the input requirements of the pre-trained language model, and uses the extraction pre-training task of the pre-trained language model to extract keywords; the cosine similarity or Jaccard similarity is used to evaluate the relevance between the keyword vector set and the vocabulary in the network security keyword library.
[0012] Furthermore, the specific steps of the natural language processing technology are as follows: First, input the system log data and user behavior data into the pre-trained language model to extract keywords, and combine the keywords into a keyword vector set through the feature vector construction module; then calculate the similarity between the keyword vector set and the network security keyword library through Jaccard similarity, and screen out the candidate words with high relevance; analyze the reliability of the candidate words through the mapping probability value, and optimize the keyword list according to the analysis result of the reliability, remove the irrelevant or low-relevance candidate words to obtain the final keyword vector set, and store the optimized final keyword vector set in the database or knowledge base for subsequent feature vector construction and network security evaluation.
[0013] Furthermore, the mapping probability value determines the probability that the candidate word is associated with the vocabulary in the keyword vector set A and the keyword vector set B by mapping the candidate word to the keyword vector set A and the keyword vector set B; It is assumed that the keyword vector set A is the keyword set of the system log data and user behavior data, and the keyword vector set B is the keyword set of the network security keyword library; Calculate the cosine similarity between the candidate word and the keyword vector set A and the keyword vector set B respectively through cosine similarity; ; Among them, represents the angle between two vectors. The smaller the angle, the higher the similarity between the vectors. represents the vector set composed of candidate words. represents the keyword vector set A or the keyword vector set are the product of the modulus length of the vector set of the candidate word and the keyword vector set A or the keyword vector set B respectively, and are used for normalization. Calculation of mapping probability values: ; Among them, and are the mapping probabilities of the vector set of candidate words to the keyword vector set A or the keyword vector set B respectively, is expressed as and joint mapping probability, is expressed as the final mapping probability between the vector set of candidate words and the keyword vector set A or the keyword vector set B; Candidate words with a final mapping probability lower than 30% are removed to obtain the final keyword vector set.
[0014] Furthermore, the security topology graph construction module combines the final keyword vector set and the final mapping probability to construct a security topology graph, where the final keyword is used as a security node and the final mapping probability is used as the security relationship between security nodes.
[0015] Furthermore, the protection topology graph construction module identifies the security relationship analysis of security nodes and security relationships in the security topology graph, and the security protection topology graph is a protection strength broken line schematic diagram; Among them, the security relationship analysis includes direct relationship, indirect relationship, strong relationship, and weak relationship; A final mapping probability of more than 90% indicates that the security node and the security relationship are in a direct relationship, and a final mapping probability of more than 80% indicates that the security node and the security relationship are in a strong relationship; If the final mapping probability is 70% - 80% or more, it indicates that the security node and the security relationship are in an indirect relationship, and if the final mapping probability is below 80%, it indicates that the security node and the security relationship are in a weak relationship.
[0016] Furthermore, the security level evaluation module generates a security level report to support visual display, including visual content such as security risk level, security vulnerability level, and security protection ability level; And the report is output in multiple formats, including text report, chart report, and executable report.
[0017] A blockchain-based network security data evaluation method includes the following steps: S1. Collect security data information of the blockchain through the data collection module; S2. Preprocess the collected security data information through the preprocessing module, which includes cleaning, standardizing, and denoising the security data information; S3. Use the recognition module to perform feature recognition on the preprocessed security data information and extract security-related feature information; S4. Use the feature vector construction module to convert the extracted feature information into vector form and construct a keyword vector set; S5. Use the security topology graph construction module to construct a security topology graph from the keyword vector set to display security nodes and security relationships in the data; S6. Use the protection topology graph construction module to analyze the security topology graph, identify security nodes and security relationships, and construct a security protection topology graph; S7. Use the security level assessment module to evaluate the security protection topology graph, generate a security level report, and evaluate the network security status.
[0018] Compared with the prior art, the beneficial effects of the present invention are: By introducing technologies such as security feature recognition, security topology graph construction, security protection topology graph analysis, and security level assessment, the present invention significantly improves the accuracy and intuitiveness of network security data assessment; adopting a distributed architecture design, it has good scalability and performance and can meet the needs of different scale networks; it has significant differences in aspects such as security feature recognition, security topology graph construction, security protection topology graph analysis, and security level assessment, and has high innovation and practicality; The present invention also uses natural language processing technology to extract security feature information and construct security feature vectors, which can more comprehensively identify network security-related information; construct a security topology graph to display security nodes and security relationships in the data, support security node recognition and security relationship construction, and can intuitively reflect the security status; deeply analyze the security topology graph, identify security nodes and security relationships, construct a security protection topology graph, and evaluate the security protection ability of the system; conduct security assessment based on the security protection topology graph, generate a security level report, and provide risk suggestions and protection improvement suggestions. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a schematic diagram of the overall system structure of the present invention; Figure 2 It is a schematic diagram of the overall method flow of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to specific embodiments. Embodiment
[0021] Please refer to Figure 1, the present invention provides a technical solution: a blockchain-based network security data evaluation system, including a data collection module, a preprocessing module, an identification module, a feature vector construction module, a security topology map construction module, a protection topology map construction module, and a security level evaluation module: The data collection module is used to collect the security data information of the blockchain, including but not limited to system log data and user behavior data; The data collection module adopts a distributed architecture, collects data simultaneously at nodes through multiple blockchain API interfaces, ensures the comprehensiveness and redundancy of data, and communicates and transfers data between data collection nodes through a message queue; The data collection module collects comprehensive and accurate security data from the blockchain network, including system log data and user behavior data. Through a distributed architecture, standardized data formats, and efficient data collection tools, the data collection module can ensure the quality and availability of data, providing reliable data support for subsequent preprocessing, feature extraction, and security evaluation; The preprocessing module is used to preprocess the collected security data information, including cleaning, standardizing, and denoising the security data information to ensure the integrity and consistency of the data; The preprocessing module ensures the integrity and consistency of the data, mainly used to improve data quality, data consistency, and data reliability. Through cleaning, standardizing, and denoising, it ensures the integrity and consistency of the data, unifies the data format and range, facilitates subsequent analysis and processing, eliminates noise and outliers, and ensures the reliability and accuracy of the data; Through specific preprocessing steps and optimization strategies, the preprocessing module can provide reliable data support for subsequent feature extraction, security topology map construction, and security level evaluation; The preprocessing process includes: Data cleaning is to remove unwanted, duplicate, missing, or abnormal data from the data to improve the accuracy and integrity of the data; Common data cleaning steps include: Removing duplicate data: Identifying duplicate data: Check whether there are duplicate records or fields in the dataset; Deleting duplicate data: Use data processing tools or programming languages to delete duplicate data records; Filling in missing values: Identifying missing values: Identify the missing values in the dataset through statistical methods; Filling methods: Mean imputation method: Estimate the missing value based on the mean of the adjacent values on the left and right; Deleting outliers: Identifying outliers: Identify outliers through Z-score or box plot; Delete outliers: Detect and delete outliers, and estimate outliers based on the mean of adjacent values on both sides; The purpose of data standardization is to ensure the consistency of data format and range, making the data easier to process and analyze. Data standardization mainly includes format standardization and range standardization; Format standardization: Unify the data format; Convert data type: Convert text data into codes; Range standardization: Normalize data values: Normalize data values to the interval [0, 1]; Data denoising is to remove or reduce noise from data to improve the reliability and accuracy of data; Use a moving average filter or a high-pass filter to filter the noisy data and reduce the impact of noise.
[0022] The recognition module is used to perform feature recognition on the preprocessed security data information, extract security-related feature information, and obtain the final keyword vector set and the final mapping probability; The recognition module extracts keywords from the security data information through natural language processing technology and recognizes feature information related to network security; The natural language processing technology first inputs the preprocessed security data information into a pre-trained language model to ensure that the text format meets the input requirements of the pre-trained language model, and uses the extraction pre-training task of the pre-trained language model to extract keywords; uses cosine similarity or Jaccard similarity to evaluate the relevance of the keyword vector set to the vocabulary in the network security keyword library; First, input the system log data and user behavior data into the pre-trained language model to extract keywords, and combine the keywords into a keyword vector set through the feature vector construction module. That is, the feature vector construction module is used to convert the extracted feature information into vector form, the vector length is D = 100, and the vector value is determined by the feature weight and position information; then calculate the similarity between the keyword vector set and the network security keyword library through Jaccard similarity, and screen out candidate words with high relevance; analyze the reliability of the candidate words through the mapping probability value, and optimize the keyword list according to the analysis results of the reliability, remove irrelevant or low-relevance candidate words to obtain the final keyword vector set, and store the optimized final keyword vector set in the database or knowledge base for subsequent feature vector construction and network security evaluation.
[0023] By extracting keywords from the above-mentioned system log data and user behavior data, it is convenient to compare with the network security keyword library, screen and optimize the keyword list, form the final keyword vector set, and accurately extract security-related feature information, providing reliable data support for subsequent construction of security topology maps and security level assessments.
[0024] The calculation formula of the Jaccard similarity is as follows: Suppose the keyword vector set A is the keyword set of system log data and user behavior data, and the keyword vector set B is the keyword set of the network security keyword library. ; Among them, represents the calculated similarity, represents the number of elements in the intersection of the keyword vector set A and the keyword vector set B, represents the number of elements in the union of the keyword vector set A and the keyword vector set B; And the closer the value of the Jaccard similarity is to 1, the higher the similarity between the keyword vector set A and the keyword vector set B. The closer the value of the Jaccard similarity is to 0, the lower the similarity between the keyword vector set A and the keyword vector set B.
[0025] Through the above calculation of the Jaccard similarity, the correlation analysis between the keyword vector set A and the keyword vector set B can be realized, identifying the keywords in the feature vector that contribute more to the network security features, and ensuring that the keyword vector set A can accurately reflect the network security features through the correlation analysis; And the application of the Jaccard similarity calculation formula in network security data evaluation has significant advantages. It can not only effectively measure the similarity between the keyword vector set A and the keyword vector set B, but also flexibly adapt to different data types and application scenarios. Through the Jaccard similarity, security-related feature information can be extracted, a security topology map can be constructed, and the security protection topology map can be analyzed to evaluate the network security status. It provides strong support for realizing efficient and accurate network security data evaluation.
[0026] The mapping probability value determines the probability that the candidate word is related to the words in the keyword vector set A and the keyword vector set B by mapping the candidate word to the keyword vector set A and the keyword vector set B; Calculate the cosine similarity of the candidate word with the keyword vector set A and the keyword vector set B respectively through the cosine similarity;
[0027] ; Among them, Expressed as the angle between two vectors, the smaller the angle, the higher the similarity between the vectors. Expressed as a vector set composed of candidate words. Expressed as keyword vector set A or keyword vector set They are respectively the product of the modulus length of the vector set of candidate words and keyword vector set A or keyword vector set B, used for normalization. Calculation of the mapping probability value: ; Among them, and are respectively the mapping probabilities of the vector set of candidate words and keyword vector set A or keyword vector set B. Expressed as and joint mapping probability. Expressed as the final mapping probability between the vector set of candidate words and keyword vector set A or keyword vector set B. Candidate words with a final mapping probability lower than 30% are eliminated to obtain the final keyword vector set.
[0028] The above mapping probability value ensures that the extracted feature information accurately reflects network security-related information by calculating the correlation between candidate words and keyword vector set A and keyword vector set B; the mapping probability value of candidate words can effectively distinguish security-related keywords from non-related words, ensuring the high quality and accuracy of feature vectors; candidate words with a mapping probability value higher than the threshold are considered to be related to the words in keyword vector set A and keyword vector set B and can accurately reflect network security-related information; and candidate words with a mapping probability value lower than the threshold are eliminated to avoid the interference of non-related or noise words. The calculation of the mapping probability value automates the keyword screening and optimization process, reduces manual intervention, and improves efficiency; without complex manual screening and optimization processes, the automated mapping probability calculation significantly improves the efficiency of feature extraction. The mapping probability value is combined with the Jaccard similarity to form diverse feature representations; it can enhance the comprehensiveness and accuracy of feature vectors, ensure the multi-dimensional reflection of feature information; and can more accurately capture network security-related feature information. The above content significantly improves the accuracy and efficiency of keyword extraction, enhances the flexibility and adaptability of the system; through the calculation of mapping probability values, it can automatically screen and optimize the keyword list to form an optimized keyword vector set, providing reliable data support for subsequent security topology graph construction and security level assessment; the mapping probability value is not only reflected in the accuracy of feature extraction, but also in aspects such as the system's automated processing, multi-modal information fusion, and scalability, providing strong support for achieving efficient and accurate network security data assessment.
[0029] The security topology graph construction module is used to construct a security topology graph to display the security nodes and security relationships in the data, that is, by combining the final keyword vector set and the final mapping probability to construct a security topology graph, where the final keywords are used as security nodes and the final mapping probability is used as the security relationship between security nodes; The specific calculation formula of the security topology graph construction module is as follows: ; Where, represents the semantic vector of the security node, represents the security relationship weight between security nodes; ; ; Where, represents the position of the keyword in the final keyword vector set, represents the position between the keyword and the final mapping probability; is the semantic vector of the security node, is the security relationship weight between security nodes; The above security topology graph shows the relationship between the final keyword vector set and the final mapping probability in a graphical way, providing an intuitive network security view, facilitating security analysis and the formulation of protection strategies. The security topology graph construction module uses the final keyword vector set and the final mapping probability, taking keywords as security nodes and mapping probability as the security relationship between security nodes to construct a security topology graph. It can clearly display the keywords related to network security and their relationships, support the analysis and visualization of the security protection topology graph, and provide reliable data support for subsequent security level assessment. The calculation of the mapping probability value and the construction of the security topology graph not only improve the accuracy and efficiency of network security data assessment, but also provide an intuitive network security view, significantly enhancing the decision-making ability of network security management.
[0030] The protection topology graph construction module is used to analyze the security topology graph, identify security nodes and security relationships, and construct a security protection topology graph, which is a line graph showing the protection strength; Among them, the analysis of security relationships includes direct relationships, indirect relationships, strong relationships, and weak relationships; A final mapping probability of more than 90% indicates that the security node and the security relationship are direct relationships, and a final mapping probability of more than 80% indicates that the security node and the security relationship are strong relationships; If the final mapping probability is 70%-80% or more, it indicates that the security node and the security relationship are indirect relationships, and if the final mapping probability is less than 80%, it indicates that the security node and the security relationship are weak relationships.
[0031] The above content classifies security relationships into direct relationships, indirect relationships, strong relationships, and weak relationships according to the final mapping probability, and connects direct relationships with strong relationships, and indirect relationships with weak relationships. That is, under strong relationships, direct relationships are judged again, and under weak relationships, indirect relationships are judged again.
[0032] Direct relationship: The relationship between security nodes is very close and highly correlated.
[0033] Indirect relationship: There is a certain degree of connection between security nodes, but not as close as direct relationships.
[0034] Strong relationship: The relationship between security nodes is relatively close, but not as close as direct relationships.
[0035] Weak relationship: The relationship between security nodes is weak and the correlation is low.
[0036] Through the classification of security relationships, the strength of the relationships between security nodes can be clearly shown, facilitating the identification of key security relationships; the line graph showing the protection strength shows the weights of security relationships in the form of a line graph, intuitively reflecting the strength of the relationships between security nodes.
[0037] The security level evaluation module is used to evaluate the security protection topology graph, generate a security level report, and evaluate the network security status, including the security risk level, the security vulnerability level, and the security protection ability level; And it supports the visual display of reports, such as visual contents of the security risk level, the security vulnerability level, the security protection ability level, etc.; And the report is output in multiple formats, including text reports, chart reports, executable reports, etc.; The above content is classified by level; the security risk level R: represents the severity of network security risks, ranging from 0 (lowest risk) to 3 (highest risk).
[0038] Parameter meaning: R = 0: The network security risk is extremely low, and the system runs stably.
[0039] R = 1: The network security risk is relatively low, and the system runs normally.
[0040] R = 2: The network security risk is medium, and there are certain security risks.
[0041] R = 3: The network security risk is high, and the system faces serious security threats.
[0042] Security vulnerability level V: Indicates the severity of network security vulnerabilities, ranging from 0 (no vulnerabilities) to 3 (high-risk vulnerabilities).
[0043] Parameter meaning: V = 0: No security vulnerabilities are found in the system.
[0044] V = 1: There are low-risk security vulnerabilities.
[0045] V = 2: There are medium-risk security vulnerabilities.
[0046] V = 3: There are high-risk security vulnerabilities, which may lead to serious consequences.
[0047] Security protection ability level Q: Represents the ability level of the network security protection system, ranging from 0 (lowest protection ability) to 3 (highest protection ability).
[0048] Parameter meaning: Q = 0: The protection ability is the lowest, and it is vulnerable to various security threats.
[0049] Q = 1: The protection ability is average, and it can resist some common security threats.
[0050] Q = 2: The protection ability is relatively strong, and it can resist various complex security threats.
[0051] Q = 3: The protection ability is the highest, and it can resist various advanced security threats.
[0052] The security level assessment module generates a security level report by analyzing the security protection topology map, evaluates the network security status, including the security risk level, security vulnerability level, and security protection ability level, and supports the visual display and output in various formats of the report; it can not only accurately evaluate the network security status, but also intuitively display security-related information in a graphical way, support the formulation and implementation of security protection strategies. And the calculation of mapping probability values and the construction of the security topology map provide reliable data support for the security level assessment module, significantly improving the accuracy and efficiency of network security data assessment.
[0053] Please refer to Figure 2, a blockchain-based network security data evaluation method, comprising the following steps: S1. Collect the security data information of the blockchain through a data collection module; S2. Preprocess the collected security data information through a preprocessing module, including cleaning, standardizing, and denoising the security data information; S3. Perform feature recognition on the preprocessed security data information through an identification module to extract security-related feature information; S4. Convert the extracted feature information into a vector form through a feature vector construction module to construct a keyword vector set; S5. Construct a security topology graph from the keyword vector set through a security topology graph construction module to display the security nodes and security relationships in the data; S6. Analyze the security topology graph through a protection topology graph construction module, identify the security nodes and security relationships, and construct a security protection topology graph; S7. Evaluate the security protection topology graph through a security level evaluation module to generate a security level report and evaluate the network security status; It should be noted that by using natural language processing technology to extract security feature information and construct security feature vectors, network security-related information can be more comprehensively identified; constructing a security topology graph to display the security nodes and security relationships in the data, supporting the identification of security nodes and the construction of security relationships, can intuitively reflect the security status; deeply analyzing the security topology graph, identifying the security nodes and security relationships, constructing a security protection topology graph, and evaluating the security protection ability of the system; based on the security protection topology graph for security evaluation, generating a security level report, and providing risk suggestions and protection improvement suggestions.
[0054] It should be explained that the above embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. A blockchain-based network security data evaluation system, characterized in that It includes a data acquisition module, a preprocessing module, an identification module, a feature vector construction module, a security topology graph construction module, a protection topology graph construction module, and a security level evaluation module: The identification module is used to perform feature identification on the security data information preprocessed by the preprocessing module, extract security-related feature information, and obtain a final keyword vector set and a final mapping probability; The security topology graph construction module is used to construct a security topology graph to display security nodes and security relationships in the data, that is, to construct a security topology graph by combining the final keyword vector set and the final mapping probability; The protection topology graph construction module is used to analyze the security topology graph, identify security nodes and security relationships, and construct a security protection topology graph.
2. The network security data evaluation system based on blockchain according to claim 1, characterized in that: The data acquisition module is used to collect security data information of the blockchain, including system log data and user behavior data; The preprocessing module is used to preprocess the collected security data information, including cleaning, standardizing, and denoising the security data information; The feature vector construction module is used to convert the extracted feature information into a vector form; The security level evaluation module is used to evaluate the security protection topology graph, generate a security level report, and evaluate the network security status.
3. A blockchain-based network security data evaluation system according to claim 2, characterized in that: The identification module extracts keywords from the security data information through natural language processing technology to identify network security-related feature information; The natural language processing technology first inputs the preprocessed security data information into a pre-trained language model to ensure that the text format meets the input requirements of the pre-trained language model, and uses the extraction pre-training task of the pre-trained language model to extract keywords; uses cosine similarity or Jaccard similarity to evaluate the relevance of the keyword vector set to the vocabulary in the network security keyword library.
4. A blockchain-based network security data evaluation system according to claim 3, wherein: The specific steps of the natural language processing technology are as follows: First, input the system log data and user behavior data into the pre-trained language model to extract keywords, and combine the keywords into a keyword vector set through the feature vector construction module; then calculate the similarity between the keyword vector set and the network security keyword library through Jaccard similarity to screen out candidate words with high relevance; analyze the reliability of the candidate words through the mapping probability value, and according to the analysis results of the reliability, optimize the keyword list, remove irrelevant or low-relevance candidate words, obtain the final keyword vector set, and store the optimized final keyword vector set in the database or knowledge base for subsequent feature vector construction and network security evaluation.
5. A network security data evaluation system based on blockchain according to claim 4, characterized in that: The mapping probability value determines the probability that the candidate word is associated with the vocabulary in the keyword vector set A and the keyword vector set B by mapping the candidate word to the keyword vector set A and the keyword vector set B; It is set that the keyword vector set A is the keyword set of the system log data and user behavior data, and the keyword vector set B is the keyword set of the network security keyword library; Calculate the cosine similarity between the candidate word and the keyword vector set A and the keyword vector set B respectively through cosine similarity; ; Among them, is represented as the angle between two vectors. The smaller the angle, the higher the similarity between the vectors. is represented as a vector set composed of candidate words. is represented as the keyword vector set A or the keyword vector set are respectively the product of the modulus length of the vector set of candidate words and the keyword vector set A or the keyword vector set B, and are used for normalization. Calculation of the mapping probability value: ; Among them, and are the mapping probabilities of the vector set of candidate words to keyword vector set A or keyword vector set B respectively, denoted as and the joint mapping probability, denoted as the final mapping probability between the vector set of candidate words and keyword vector set A or keyword vector set B; Candidate words with a final mapping probability lower than 30% are eliminated to obtain the final keyword vector set.
6. The network security data evaluation system based on blockchain according to claim 5, characterized in that: The security topology graph construction module combines the final keyword vector set with the final mapping probability to construct a security topology graph, where the final keywords serve as security nodes and the final mapping probability serves as the security relationship between security nodes.
7. A blockchain-based network security data evaluation system according to claim 6, characterized in that: The protection topology graph construction module identifies the security relationship analysis of security nodes and security relationships in the security topology graph, and the security protection topology graph is a schematic diagram of a protection strength broken line; Among them, the security relationship analysis includes direct relationship, indirect relationship, strong relationship, and weak relationship; A final mapping probability of more than 90% indicates that the security node and the security relationship are in a direct relationship, and a final mapping probability of more than 80% indicates that the security node and the security relationship are in a strong relationship; If the final mapping probability is 70%-80% or more, it indicates that the security node and the security relationship are in an indirect relationship, and if the final mapping probability is below 80%, it indicates that the security node and the security relationship are in a weak relationship.
8. A blockchain-based network security data evaluation system according to claim 7, characterized in that: The security level assessment module generates a security level report to support visual display, including visual content such as security risk level, security vulnerability level, and security protection ability level; And the report is output in multiple formats, including text report, chart report, and executable report.
9. A network security data evaluation method based on blockchain, which is applied to a network security data evaluation system based on blockchain as described in any one of claims 1-8, and is characterized in that: It includes the following steps: S1. Collect the security data information of the blockchain through the data collection module; S2. Preprocess the collected security data information through the preprocessing module, which includes cleaning, standardizing, and denoising the security data information; S3. Perform feature recognition on the preprocessed security data information through the recognition module to extract security-related feature information; S4. Convert the extracted feature information into a vector form through the feature vector construction module to construct a keyword vector set; S5. Construct a security topology graph from the keyword vector set through the security topology graph construction module to display the security nodes and security relationships in the data; S6. Analyze the security topology graph through the protection topology graph construction module, identify security nodes and security relationships, and construct a security protection topology graph; S7. Evaluate the security protection topology graph through the security level assessment module to generate a security level report and evaluate the network security status.
Citation Information
Patent Citations
Network security authentication system and method based on block chain
CN119496621A