Network security risk assessment method and system based on fuzzy mathematics

Through the network security risk assessment method based on fuzzy mathematics, network node data is dynamically monitored and interactive risk distribution model is constructed, which solves the problem that the dynamic change characteristics of risk factors in the existing technology is difficult to reflect, and achieves multi-dimensional real-time response and accurate identification of network threats.

CN120378146AActive Publication Date: 2025-07-25JINQICHUANG (BEIJING) TECH CO LTD

Patent Information

Application Number
CN202510456023.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-25
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

The existing technology is difficult to reflect the dynamic changing characteristics of risk factors in network security risk assessment, and lacks systematic analysis of interactions between multiple risk factors, resulting in the deviation of the evaluation results in complex threat environments, insufficient response speed and accuracy, and the inability to accurately capture the key characteristics of potential risk events.

Method used

Using a method based on fuzzy mathematics, we dynamically monitor network node data, extract multiple risk factor parameters, generate network risk factor membership distribution tables, analyze the impact of parameter distribution proportions, build an interactive risk distribution model, filter out risk factor groups with outstanding characteristics, and generate network security key risk feature data sets to achieve multi-dimensional real-time response to risk factors.

Benefits of technology

It improves the accuracy and dynamic adaptability of risk assessment, can reveal the correlation between risk factors more comprehensively, and enhances the efficiency of identifying and responding to complex cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378146A_ABST
    Figure CN120378146A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to a network security risk assessment method and system based on fuzzy mathematics, and the method comprises the following steps: based on dynamic monitoring data of node data in a network environment, extracting multiple risk factor parameters, dividing a parameter value range, comparing risk level intervals, and carrying out the statistics of a differentiation interval distribution proportion. And generating a network risk factor membership distribution table. According to the method, network node data are dynamically monitored, multiple risk factors are accurately analyzed, attribution range division is refined, the distribution relation between parameters and risk levels is defined, the distribution proportion and weight influence are analyzed, an interactive risk distribution model is formed, factor relevance is revealed, a significant characteristic group is screened, and the time dimension change rule is combined, so that the risk level of the network is determined. And key risk feature data is extracted, the dynamic monitoring capability is enhanced, the accuracy, comprehensiveness and dynamic adaptability of risk assessment are improved, the conversion from static analysis to real-time response is realized, and complex network threats are effectively dealt with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security, and particularly to a network security risk assessment method and system based on fuzzy mathematics. Background Art

[0002] The technical field of information security includes security protection technologies related to computer systems and networks. Its core content includes ensuring the confidentiality, integrity, and availability of information, and preventing threats and attacks on data during storage, transmission, and processing. The technical field of information security covers cryptography, identity authentication, access control, network security system design, and security assessment methods, etc. By establishing an information security management system and technical measures, information systems and their resources are protected from unauthorized access, destruction, and tampering. The research directions in this technical field mainly focus on threat detection, risk assessment, security policy optimization, and the development of security monitoring methods to cope with increasingly complex security threats.

[0003] Among them, the network security risk assessment method refers to the technical matter of analyzing and evaluating potential security risks in a computer network system. This method covers three aspects: risk identification, risk analysis, and risk assessment, and is specifically based on constructing a mathematical model, quantifying evaluation indicators, and logical reasoning methods. By establishing a risk assessment model based on the fuzzy mathematics theory, and based on the fuzzy set theory of risk factors, the risk levels of threat events in the network system are divided, and a risk analysis method is used to comprehensively evaluate different threat events to form a risk level evaluation result of the system.

[0004] In the prior art, the analysis of parameters in risk assessment mostly focuses on the static dimension, and it is difficult to effectively reflect the dynamic change characteristics of risk factors in the network environment. Its risk identification method relies on single or limited risk factor data and lacks a systematic analysis of the interaction between multiple risk factors. This limitation easily leads to deviations in the evaluation results in a complex threat environment. In the prior art, during parameter division and evaluation, a static index system based on a fixed model is mostly used, and it is difficult to adapt to the rapid fluctuation characteristics of factor distribution in the real-time network environment. Regarding the parameter change law in the time dimension, the prior art more relies on periodic records and lacks the ability to deeply analyze the fluctuation range and deviation characteristics of parameters, resulting in insufficient response speed and accuracy in risk assessment in dynamic threats. This insufficiency causes a lag in the identification of network threats and cannot accurately capture the key characteristics of potential risk events, thereby reducing the overall effectiveness of network security protection. In dealing with complex threats, the static characteristics and single-factor analysis mode of the prior art have become an important bottleneck restricting network security assessment capabilities. Summary of the Invention

[0005] To address the problems in the prior art where the analysis of parameters in risk assessment mainly focuses on the static dimension, making it difficult to effectively reflect the dynamic change characteristics of risk factors in the network environment. The risk identification method relies on single or limited risk factor data and lacks a systematic analysis of the interaction between multiple risk factors. This limitation easily leads to deviations in the assessment results in complex threat environments. In the prior art, during parameter division and assessment, a static index system based on a fixed model is mostly used, which is difficult to adapt to the rapid fluctuation characteristics of factor distribution in the real-time network environment. Regarding the parameter change law in the time dimension, the prior art more relies on periodic recording and lacks the ability to deeply analyze the parameter fluctuation range and deviation characteristics, resulting in insufficient response speed and accuracy in risk assessment in dynamic threats. This deficiency causes a lag in the identification of network threats and fails to accurately capture the key characteristics of potential risk events, thus reducing the overall effectiveness of network security protection. In dealing with complex threats, the static characteristics and single-factor analysis mode of the prior art have become important bottlenecks restricting network security assessment capabilities. The embodiments of the present invention provide a network security risk assessment method and system based on fuzzy mathematics. The technical solutions are as follows:

[0006] On the one hand, a network security risk assessment method based on fuzzy mathematics is provided. The method includes:

[0007] S1: Based on the dynamic monitoring data of node data in the network environment, extract multiple risk factor parameters, divide the parameter value range, compare the risk level intervals, count the proportion of the differential interval distribution, and generate a network risk factor membership distribution table;

[0008] S2: Based on the network risk factor membership distribution table, analyze the influence of the parameter distribution ratio, analyze the influence degree of the ratio difference on the weight, count the influence range of the interaction characteristics of multiple risk factors, classify the distribution and weight data, and generate an interaction risk distribution model;

[0009] S3: Based on the interaction risk distribution model, analyze the correlation between the weight value and the distribution ratio, call the cumulative value of the weights of multiple risk factors, evaluate the association effect of the parameter group, screen out the risk factor group with prominent characteristics, and generate a risk factor group mapping table;

[0010] S4: Based on the risk factor group mapping table, call the group data and the time dimension record, count the time change range of the group, analyze the concentration degree and change frequency of the distribution data, analyze the parameter fluctuation law, classify it as group characteristics, and generate a network security key risk characteristic data set;

[0011] S5: Based on the network security key risk feature data set, parse the time change records of key risk factors, call the distribution offset value and the original record, evaluate the offset amplitude and scope of action, count the offset range and intensity data, and generate dynamic assessment results of network key risks.

[0012] Optionally, the network risk factor membership distribution table includes: traffic anomaly rate distribution, port status fluctuation range, access frequency ratio, and intrusion alarm statistical distribution;

[0013] The interactive risk distribution model includes: parameter distribution ratio relationship, weight difference influencing factors, the range of interactive characteristics of multiple risk factors, and distribution and weight classification results;

[0014] The risk factor group mapping table includes: group association parameters, key risk factor groups, cumulative weights of multiple risk factors, and group interaction impact range;

[0015] The key risk feature datasets for cybersecurity include: time dimension distribution records, parameter concentration change distribution, fluctuation change characteristics, and group feature classification diagrams;

[0016] The dynamic assessment results of key network risks include: distribution deviation amplitude records, deviation scope data, deviation intensity statistics and time change records of key risk factors.

[0017] Optionally, in S1, based on the dynamic monitoring data of node data in the network environment, multiple risk factor parameters are extracted, the parameter value range is divided, the risk level intervals are compared, the distribution ratio of the differentiated intervals is statistically analyzed, and a network risk factor affiliation distribution table is generated, including:

[0018] S101: Based on the dynamic monitoring data of node data in the network environment, the traffic anomaly rate, port status fluctuation, access frequency and intrusion alarm parameters are gradually extracted, the original record distribution values are verified one by one, the erroneous data are eliminated, and the data range is divided according to the distribution trend to obtain the parameter value range division data set;

[0019] S102: Divide the data set based on the parameter value range, extract the current value of the parameter in the dynamic monitoring data, analyze the difference range of the risk interval segment value, divide the difference range into attribution categories, mark the attribution category for the current value of the parameter, and generate a parameter attribution interval distribution table;

[0020] S103: Based on the parameter belonging interval distribution table, the distribution ratio of the current parameter value in the risk interval is counted, the change of the interval segment proportion is analyzed, the correlation of the distribution proportion of the classified parameters is sorted out, and the network risk factor belonging distribution table is generated.

[0021] Optionally, in S2, based on the membership distribution table of network risk factors, analyze the influence of the distribution ratio of parameters, analyze the degree of influence of the ratio difference on the weight, count the influence range of the interaction characteristics of multiple risk factors, classify the distribution and weight data, and generate an interaction risk distribution model, including:

[0022] S201: Based on the membership distribution table of network risk factors, extract the distribution ratio data of parameters, analyze the relationship between the distribution ratio and the risk level, analyze the original record and the change range of the distribution ratio, classify the matching relationship between the distribution ratio and the risk level, and obtain the difference data between the distribution ratio and the risk level;

[0023] S202: Based on the difference data between the distribution ratio and the risk level, analyze the weight relationship between the distribution ratio and the risk level, compare the weight change trend of the parameter distribution ratio, sort out and classify the weight data of the change range, and obtain the influence data of the distribution ratio on the weight;

[0024] S203: Based on the influence data of the distribution ratio on the weight, analyze the weight change relationship under the interaction condition, count the coverage range of the interaction influence of multiple risk factors, classify the interaction weight and distribution characteristic data, integrate the influence data of the interaction characteristics, calculate the weight of the interaction risk distribution relationship, and construct an interaction risk distribution model.

[0025] Optionally, calculate the weight of the interaction risk distribution relationship according to the following formula (1):

[0026]

[0027] where E represents the weight of the interaction risk distribution relationship, P a represents the distribution ratio of risk factor A in the initial state, W a represents the weight parameter of risk factor A, P b represents the distribution ratio of risk factor B in the initial state, W b represents the weight parameter of risk factor B, Q c represents the interaction influence intensity of risk factor C, W c represents the weight parameter of risk factor C, P d represents the standardized distribution density of risk factor D.

[0028] Optionally, in S3, based on the interaction risk distribution model, analyze the correlation between the weight value and the distribution ratio, call the cumulative value of the weights of multiple risk factors, evaluate the association effect of the parameter group, screen out the risk factor groups with prominent features, and generate a risk factor group mapping table, including:

[0029] S301: Based on the interaction risk distribution model, analyze the weight value and the distribution ratio of the risk factor, extract the cumulative weight value, calculate the association intensity in the distribution, classify the risk factors, and establish a parameter group matching set;

[0030] S302: Based on the parameter group matching set, analyze the associated parameters of the risk factors within the group, extract interaction factors, analyze the scope of factor action, and construct a characteristic key factor group;

[0031] S303: Based on the characteristic key factor group, analyze the distribution law of data characteristics within the group, perform mapping processing according to the distribution trend, adjust the interaction parameter values, integrate the associated characteristics between factors, and generate a risk factor group mapping table.

[0032] Optionally, in S4, based on the risk factor group mapping table, call the group data and time dimension records, statistically analyze the time change range of the group, analyze the concentration degree and change frequency of the distribution data, analyze the parameter fluctuation law, classify it as group characteristics, and generate a network security key risk characteristic data set, including:

[0033] S401: Based on the risk factor group mapping table, extract the distribution range of group data parameters, filter the data with corresponding parameter values in the time dimension records, compare the change amplitude of parameter values within the time interval, analyze the change frequency and judge the distribution concentration degree, and obtain the time distribution data of group parameters;

[0034] S402: Based on the time distribution data of group parameters, analyze the distribution data in the time dimension, extract the fluctuation range of parameter values, analyze the change amount within the time period, judge the parameter time distribution law, classify and organize the periodic and persistent characteristic parameters, and obtain the key parameter classification characteristics;

[0035] S403: Based on the key parameter classification characteristics, integrate the distribution data of the parameters in the classification characteristics, re - summarize the characteristic values of the parameters in combination with the time law of the parameters, organize the group characteristics according to the interaction characteristics of the time dimension and classification data, calculate the key risk characteristic score, and generate a network security key risk characteristic data set.

[0036] Optionally, calculate the key risk characteristic score according to the following formula (2):

[0037]

[0038] where, R represents the key risk characteristic score, T represents the sum of the absolute values of the key characteristic value set extracted from the time dimension trend data, P i represents the i - th principal component characteristic value in the classification characteristics, F represents the mean absolute deviation of the parameter distribution data, ΔS represents the change rate of the time series residual, w1 is the trend weight adjustment parameter, w2 is the classification principal component characteristic weight parameter, w3 is the deviation mean weight coefficient, and w4 is the residual change rate adjustment parameter.

[0039] Optionally, in S5, based on the network security key risk feature dataset, parse the time change record of the key risk factors, call the distribution offset value and the original record, evaluate the offset amplitude and the scope of action, count the offset range and the action intensity data, and generate the dynamic evaluation result of the network key risk, including:

[0040] S501: Based on the network security key risk feature dataset, extract the time dimension change record of the key risk factors, parse the time interval distribution data, calculate the distribution offset value within the change span, screen the distribution offset amplitude factors, and obtain the key risk factor distribution offset data;

[0041] S502: Based on the key risk factor distribution offset data, extract the original distribution law of the offset factors, analyze the difference range between the offset value and the original distribution, evaluate the offset amplitude, extract the data within the offset range, and integrate the characteristics of the action area in combination with the time dimension to obtain the key risk factor offset action range;

[0042] S503: Based on the key risk factor offset action range, count the action intensity of the key factors within the action range, parse the trend of the intensity change with time, analyze the dynamic law of the intensity change, and integrate the action range and the dynamic law characteristic data to generate the dynamic evaluation result of the network key risk.

[0043] On the other hand, a network security risk assessment system based on fuzzy mathematics is provided. The network security risk assessment system based on fuzzy mathematics is used to execute the above-mentioned network security risk assessment method based on fuzzy mathematics. The system includes:

[0044] A risk factor dynamic monitoring module, which is used to extract the traffic anomaly rate, port status fluctuation, access frequency and intrusion warning parameters based on the dynamic monitoring data of the node data in the network environment, compare the risk level intervals, analyze the numerical proportion of the differential distribution, count the distribution ratio, and generate a multi-parameter risk factor distribution ratio table;

[0045] A risk factor interval analysis module, which is used to parse the distribution law of the risk factors based on the multi-parameter risk factor distribution ratio table, make item-by-item comparisons of the risk level intervals, identify the influence ratio of the level intervals, and integrate the risk level ratio and the weight difference data to establish a risk factor associated weight distribution table;

[0046] An interaction characteristic analysis module, which is used to parse the weight and distribution ratio data based on the risk factor associated weight distribution table, make a cross comparison of the weight coverage range and the distribution ratio, screen the associated risk factor combinations, and generate a multi-risk factor interaction relationship model;

[0047] A risk factor time evolution module, which is used to statistically analyze the time variation range of factor combinations based on a multi-risk factor interaction relationship model, compare the distribution shift and fluctuation frequency within the time range, integrate the time evolution characteristic data, and establish a risk factor evolution distribution table in the time dimension;

[0048] A key characteristic correlation evaluation module, which is used to analyze the time distribution shift value based on the risk factor evolution distribution table in the time dimension, statistically analyze the fluctuation range, screen the characteristic groups of the change amplitude, and generate a dynamic evaluation result of the key risks of the network.

[0049] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:

[0050] By dynamically monitoring network node data, refining the extraction of risk factor parameters and the division of attribution ranges, realizing the precise analysis of multiple parameters such as traffic anomaly rate, port status fluctuation, access frequency, and intrusion alarm, being able to clarify the differential distribution ratio between the parameter values and the risk level intervals, introducing the statistical analysis of the interaction characteristics of multiple risk factors by analyzing the influence and weight relationship of the parameter distribution ratio on the risk level, forming a multi-dimensional interaction risk distribution model, being able to more comprehensively reveal the correlation between risk factors and their scope of action, screening the risk factor groups with significant characteristics, enhancing the pertinence and scientific nature of risk identification. In the time dimension, by analyzing the change frequency and distribution concentration degree of the group parameters, further classifying and refining the key risk characteristic data set of network security, thereby enhancing the real-time monitoring ability of the dynamic changes of risks, combining the evaluation of the deviation amplitude and scope of action of key risk factors, and the security situation changes under complex threats, greatly improving the accuracy, comprehensiveness, and dynamic adaptation ability of risk assessment, making the network security risk assessment shift from static analysis to a dynamic and multi-dimensional real-time response mode, and effectively improving the efficiency and reliability of dealing with complex network security threats. Description of the Drawings

[0051] Figure 1 It is a schematic diagram of the working process of the network security risk assessment method based on fuzzy mathematics provided by the embodiment of the present invention;

[0052] Figure 2 It is a detailed flowchart of S1 provided by the embodiment of the present invention;

[0053] Figure 3 It is a detailed flowchart of S2 provided by the embodiment of the present invention;

[0054] Figure 4 It is a detailed flowchart of S3 provided by the embodiment of the present invention;

[0055] Figure 5 It is a detailed flowchart of S4 provided by the embodiment of the present invention;

[0056] Figure 6 The refined flowchart of S5 provided by the embodiment of the present invention;

[0057] Figure 7 The flowchart of the network security risk assessment system based on fuzzy mathematics provided by the embodiment of the present invention;

[0058] Figure 8 The electronic device diagram of the network security risk assessment based on fuzzy mathematics provided by the embodiment of the present invention. Specific implementation manners

[0059] Next, the technical solutions in the present invention will be described with reference to the accompanying drawings.

[0060] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.

[0061] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same. "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same.

[0062] In the embodiments of the present invention, sometimes subscripts such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meanings they express are the same.

[0063] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0064] Please refer to Figure 1 , the embodiment of the present invention provides a network security risk assessment method based on fuzzy mathematics. The processing flow of this method can include the following steps:

[0065] S1: Based on the dynamic monitoring data of node data in the network environment, extract multiple risk factor parameters such as traffic anomaly rate, port status fluctuation, access frequency, and intrusion warning, divide the attribution range of parameter values, compare each parameter value with the numerical range of the risk level interval, and count the distribution ratio of the parameters in the differential interval to generate a network risk factor membership distribution table;

[0066] S2: Based on the membership distribution table of network risk factors, analyze the influence relationship of the parameter distribution ratio on the differentiated risk levels, analyze the influence degree of the distribution ratio difference on the weights, count the influence scope of the interaction characteristics of multiple risk factors, classify the distribution and weight data, and generate an interactive risk distribution model;

[0067] S3: Based on the interactive risk distribution model, analyze the correlation between the weight values and the distribution ratios in the interaction characteristics, call the cumulative values of the weights of multiple risk factors, evaluate the associated effects of the parameter groups, determine the influence scope of the associated parameters, screen out the risk factor groups with prominent characteristics, and generate a risk factor group mapping table;

[0068] S4: Based on the risk factor group mapping table, call the time dimension records of the group data and the parameter distribution range, count the time change range of the groups, analyze the concentration degree and change frequency of the distribution data, analyze the fluctuation law of the group parameters in the time dimension, determine the key characteristics of the parameters and classify them as group characteristics, and generate a dataset of key network security risk characteristics;

[0069] S5: Based on the dataset of key network security risk characteristics, analyze the time dimension change records of the key risk factors, call the distribution offset values of the key risk factors and the distribution law data in the original records, evaluate the amplitude and action scope of the distribution offset, count the offset range and action intensity data, and generate a dynamic assessment result of network key risks.

[0070] The membership distribution table of network risk factors includes the distribution of traffic anomaly rate, the fluctuation range of port states, the proportion of access frequencies, and the statistical distribution of intrusion alarms. The interactive risk distribution model includes the parameter distribution ratio relationship, the influencing factors of weight differences, the interaction characteristic scope of multiple risk factors, and the classification results of distribution and weights. The risk factor group mapping table includes the group associated parameters, the key risk factor groups, the cumulative weights of multiple risk factors, and the group interaction influence scope. The dataset of key network security risk characteristics includes the time dimension distribution records, the concentrated change distribution of parameters, the fluctuation change characteristics, and the group characteristic classification diagram. The dynamic assessment result of network key risks includes the distribution offset amplitude record, the offset action scope data, the offset intensity statistics, and the time change record of the key risk factors.

[0071] In a feasible implementation manner, as Figure 2 shown, the steps of extracting multiple risk factor parameters, dividing the parameter value range, comparing the risk level intervals, and counting the proportion of the differentiated interval distribution based on the dynamic monitoring data of node data in the network environment to generate the membership distribution table of network risk factors are specifically as follows:

[0072] S101: Based on the dynamic monitoring data of node data in the network environment, gradually extract the traffic anomaly rate, port status fluctuation, access frequency, and intrusion alarm parameters. Check each original record distribution value one by one, eliminate the error data, and divide the data range according to the distribution trend to obtain the parameter value range division data set;

[0073] In the extraction of the traffic anomaly rate, it is first necessary to extract the abnormal fluctuations of a single node through the time series of traffic records. Set the reference value of the baseline traffic mean, calculate the deviation of the traffic in each monitoring period, and calculate the anomaly rate of each period. For the port status fluctuation, use the node port status record data based on the time window to calculate the fluctuation amplitude value of the status in each time period, obtain the number of fluctuations and the fluctuation amplitude, and extract the records with the amplitude change greater than the reference threshold. For the access frequency, calculate the average value of the access times by analyzing the access request records between nodes within a unit time, and mark the abnormal access values. For the extraction of the intrusion alarm parameters, perform cross-checking according to the source IP and type information of each record in the alarm log, filter out the records that do not conform to the alarm rules, and retain the high-priority alarm events. Check the data with numerical deviations or anomalies in the above-mentioned extracted original records one by one through the distribution curve fitting method, and eliminate the record values with large deviations. The verification standard is that the deviation rate of the distribution fitting curve is less than 5%. Divide the upper and lower bound ranges according to the normal distribution trend of the parameters, and generate the parameter value range division data set to lay a foundation for the subsequent risk assessment and analysis.

[0074] S102: Based on the parameter value range division data set, extract the current parameter values in the dynamic monitoring data, analyze the difference amplitude of the risk interval segment values, divide the difference amplitude into attribution categories, mark the attribution categories for the current parameter values, and generate the parameter attribution interval distribution table;

[0075] First, classify and calculate the current value according to the risk intervals defined by their corresponding distribution ranges. By calculating the deviation amplitude between the current value and the upper and lower bounds of the risk interval, determine whether it belongs to the normal, safe, or high-risk interval. The division of the difference amplitude is based on the relative deviation formula between the current value and the median of the interval. Define the deviation amplitude as: less than 10% belongs to normal, more than 30% belongs to high risk, and between 10% and 30% is general risk. During the calculation process, analyze the performance characteristics of each parameter within its belonging range item by item. For example, the deviation of the flow anomaly rate is confirmed by calculating the change amplitude between the real-time flow and the reference flow to determine its belonging category. The port status fluctuation is classified according to the deviation of the fluctuation value relative to the normal fluctuation amplitude range. The access frequency is divided into risk levels by calculating the change degree of the current access times relative to the historical average value. The intrusion alarm parameter is marked and classified by the deviation between the current alarm frequency and the historical alarm distribution. Record the belonging categories of the current values of all parameters in the parameter belonging interval distribution table, and organize them into a table by category to provide data support for further evaluating the risk level and the parameter distribution trend.

[0076] S103: Based on the parameter belonging interval distribution table, count the distribution ratio of the current values of the parameters within the risk interval, analyze the change of the proportion of the interval segments, sort out the correlation between the classified parameter distributions, and generate the membership distribution table of network risk factors;

[0077] According to the records in the parameter belonging interval distribution table, count the number of current values of all parameters that are respectively in the high-risk, general-risk, and normal intervals. By calculating the proportion of different categories, evaluate the potential risk status in the network. For the distribution ratio of each parameter, perform normalization processing using the proportion calculation formula to obtain the trend value of the proportion change of each interval segment. For example, analyze the exacerbation of potential flow anomaly behavior by calculating whether the proportion of the flow anomaly rate in the high-risk interval has increased compared with the previous evaluation. For the distribution ratio of the port status fluctuation, judge whether there is a downward trend in network stability by the ratio of the number of nodes with fluctuation values in the high-risk interval to the total number of nodes. Analyze the potential abnormal access frequency trend through the change of the proportion of frequency abnormal values in the high-risk area for the access frequency distribution. For the intrusion alarm parameter, evaluate the severity of the alarm event and the potential intrusion risk based on the proportion of high-risk alarm records. Organize the correlation between the distribution ratios of each parameter into the membership distribution table of network risk factors, and mark the distribution trend and potential risk evaluation value of each factor in the table to provide a basis and support for subsequent network security risk assessment.

[0078] In a feasible implementation, as Figure 3 shown, based on the membership distribution table of network risk factors, the steps to analyze the influence of the parameter distribution ratio, analyze the influence degree of the ratio difference on the weight, count the influence range of the interaction characteristics of multiple risk factors, classify the distribution and weight data, and generate the interactive risk distribution model are specifically as follows:

[0079] S201: Based on the membership distribution table of network risk factors, extract the distribution ratio data of parameters, analyze the relationship between the distribution ratio and the risk level, analyze the original records and the change range of the distribution ratio, classify the matching relationship between the distribution ratio and the risk level, and obtain the difference data between the distribution ratio and the risk level;

[0080] When extracting the distribution ratio data, first obtain the distribution ratio of each parameter through the membership distribution table of network risk factors, and classify and count the proportion of the number of parameters within each risk level according to the risk levels (normal, general risk, high risk). When analyzing the relationship between the distribution ratio and the risk level, based on the risk level division thresholds of different parameters, calculate the distribution ratio difference in different risk level intervals. For example, by comparing the distribution ratios of the traffic anomaly rate in the general risk and high risk intervals, analyze the changing trend of its risk level. The analysis of the original records and the change range of the distribution ratio requires a vertical comparison of the records within each time period, determine the change range through difference calculation, and count the fluctuation degree of the distribution ratio of each parameter in each risk level. For classifying the matching relationship between the distribution ratio and the risk level, map the distribution ratio of each parameter to a specific risk level through the matching rules. For example, if the distribution ratio of the traffic anomaly rate exceeds the high risk threshold, it is classified into the high risk level. Combining the corresponding relationships between the distribution ratios and the risk levels of all parameters, calculate the difference value to obtain the difference data between the distribution ratio and the risk level, providing accurate data support for the subsequent weight relationship analysis.

[0081] S202: Based on the difference data between the distribution ratio and the risk level, analyze the weight relationship between the distribution ratio and the risk level, compare the changing trend of the weights of the parameter distribution ratios, sort out and classify the weight data of the change range, and obtain the data on the influence of the distribution ratio on the weights;

[0082] When analyzing the weight relationship between the distribution ratio and the risk level, assign different weight values to each level according to the influence degree of different risk levels on the overall network security. To compare the changing trend of the weights of the parameter distribution ratios, it is necessary to normalize the changes in the distribution ratios over different time periods, use time as the horizontal axis, plot the weight change curves of each parameter, and observe their trend changes. Classify and count the weight values of each parameter in different risk levels. For example, whether the proportion of the weight fluctuation of the port status in the high risk level is significantly higher than that in other risk levels, and record the extreme values and the average values of the change range. Combining the distribution ratios and the weight relationships of all parameters, obtain the data on the influence of the distribution ratio on the weights, which serves as an important input basis for the subsequent interactive condition analysis.

[0083] S203: Analyze the relationship of weight changes under interaction conditions based on distribution ratio and weight influence data, count the coverage range of the interactive influence of multiple risk factors, classify the interactive weight and distribution characteristic data, integrate the data affected by interactive characteristics, calculate the weight of the interactive risk distribution relationship, and construct an interactive risk distribution model;

[0084] Calculate the weight of the interactive risk distribution relationship according to the following formula (1):

[0085]

[0086] Among them, E represents the weight of the interactive risk distribution relationship, and P a represents the distribution ratio of risk factor A in the initial state, and W a represents the weight parameter of risk factor A, and P b represents the distribution ratio of risk factor B in the initial state, and W b represents the weight parameter of risk factor B, and Q c represents the interactive influence intensity of risk factor C, and W c represents the weight parameter of risk factor C, and P d represents the standardized distribution density of risk factor D.

[0087] The detailed explanation of the formula and the derivation process of the formula calculation are as follows:

[0088] This formula is used to calculate the weight of the risk distribution relationship under the interaction of multiple risk factors, and the obtained result is used to establish an interactive risk distribution model;

[0089] P a is the distribution ratio of risk factor A in the initial state, set to 0.3, reflecting the initial ratio of risk factor A in the overall risk distribution;

[0090] W a is the weight parameter of risk factor A, set to 0.5, reflecting the weight ratio of the influence of risk factor A on the overall model;

[0091] P b is the distribution ratio of risk factor B in the initial state, set to 0.4, reflecting the initial ratio of risk factor B in the overall risk distribution;

[0092] W b is the weight parameter of risk factor B, set to 0.6, reflecting the weight ratio of the influence of risk factor B on the overall model;

[0093] Q c is the interactive influence intensity of risk factor C, set to 0.7, reflecting the specific influence intensity of the interaction between risk factor C and other factors;

[0094] W​​c It is the weight parameter for risk factor C, set to 0.8, which reflects the weight adjustment ratio of risk factor C in the interaction analysis;

[0095] P d It is the standardized distribution density of risk factor D, set to 0.5, which reflects the standardized distribution intensity of risk factor D in the overall data;

[0096] Substitute the parameters into the formula to calculate E:

[0097] Calculate |P a W a -P b W b |: |0.3×0.5 - 0.4×0.6| = |0.15 - 0.24| = |-0.09| = 0.09;

[0098] Calculate

[0099] Calculate

[0100] Since Therefore:

[0101] Further calculate:

[0102] Add the above results: E = 0.3 + 0.792 = 1.092;

[0103] The result 1.092 indicates that under the set parameter conditions, the weight of the risk distribution relationship under the interaction of multiple risk factors is 1.092. This result is used to establish an interaction risk distribution model, reflecting the degree of interaction between different risk factors.

[0104] In a feasible implementation, as Figure 4 shown, based on the interaction risk distribution model, the steps to analyze the correlation between the weight value and the distribution ratio, call the cumulative value of the weights of multiple risk factors, evaluate the associated effect of the parameter group, screen the risk factor group with prominent features, and generate a risk factor group mapping table are specifically as follows:

[0105] S301: Based on the interaction risk distribution model, analyze the weight value and distribution ratio of the risk factors, extract the cumulative weight value, calculate the correlation strength in the distribution, classify the risk factors, and establish a parameter group matching set;

[0106] In the interactive risk distribution model, when analyzing the weight values and distribution ratios of each risk factor, first, the cumulative weight values of each risk factor in different risk levels are statistically calculated, and the total risk contribution is quantified by calculating the superposition of the weight values in different risk levels. For the distribution ratio, the weight contribution intensity is calculated by combining the proportion of each factor in the interval segment. The calculation of the association intensity is based on the synergistic effect of the cumulative weight value and the distribution ratio of different risk factors in the interaction interval. For example, the weight superposition relationship between the traffic anomaly rate and the port status fluctuation in the same interval is used to measure their association intensity. When classifying risk factors, the factors with significant association intensity are classified as high-interaction risk factors, and the remaining factors are sorted by weight values and divided into general risk factors and low-risk factors. Combining the above classification results, according to the synergistic effect and distribution ratio characteristics among risk factors, the same type of factors are aggregated to establish a parameter group matching set, providing basic data support for subsequent analysis of the internal correlation of risk factors.

[0107] S302: Based on the parameter group matching set, analyze the association parameters of risk factors within the group, extract interaction factors, analyze the action range of factors, and construct a characteristic key factor group;

[0108] In the parameter group matching set, when analyzing the association parameters of risk factors within each group, according to the matching relationship between their distribution ratio and cumulative weight value, filter out the association parameters with synergistic effects. For example, between the abnormal access frequency and intrusion warning, extract the number of shared interaction nodes and their weight contribution values, and confirm their association intensity. When extracting interaction factors, by calculating the weight contribution ratio between different factors within the same group, filter out the high-association factors as interaction factors and mark them as interaction factors. When analyzing the action range of factors, statistically calculate the coverage range and influence depth of interaction factors in network nodes. For example, the number and proportion of nodes where the high-risk weight coverage range of port status fluctuation overlaps with the traffic anomaly rate. Aggregate the interaction factors with significant action range and high association intensity, classify them into characteristic key factor groups according to their characteristics, and record their factor characteristics and weight distribution, laying a data foundation for subsequent analysis of their internal characteristics and association rules.

[0109] S303: Based on the characteristic key factor group, analyze the distribution law of data characteristics within the group, perform mapping processing according to the distribution trend, adjust the interaction parameter values, integrate the association characteristics between factors, and generate a risk factor group mapping table;

[0110] When analyzing the data characteristic distribution law of each factor, based on the distribution ratio of the factor within each risk level, its distribution trend and fluctuation range are statistically analyzed. When performing mapping processing according to the distribution trend, by corresponding the distribution ratio with the risk level, the cumulative weight value of the factor is projected onto the distribution trend curve. When integrating the correlation characteristics between factors, the interactive weight contribution within the characteristic key factor group is calculated, and its distribution characteristics are normalized to ensure the consistency of the correlation data between factors. Based on all the analysis results and the adjusted interactive parameter values, a risk factor group mapping table is generated, marking the distribution law, interaction, and risk level of each factor, providing further support for network security risk assessment.

[0111] In a feasible implementation manner, as Figure 5 shown, based on the risk factor group mapping table, the steps of calling the group data and time dimension records, statistically analyzing the time change range of the group, analyzing the concentration degree and change frequency of the distribution data, parsing the parameter fluctuation law, and classifying it as group characteristics to generate a network security key risk characteristic data set are specifically as follows:

[0112] S401: Based on the risk factor group mapping table, extract the parameter distribution range of the group data, screen the data of the corresponding parameter values in the time dimension records, compare the change amplitude of the parameter values within the time interval, analyze the change frequency and judge the distribution concentration degree, and obtain the time distribution data of the group parameters;

[0113] When extracting the parameter distribution range of each group, classify the parameter values according to the high-risk interval, medium-risk interval, and low-risk interval recorded by the distribution ratio, and mark the upper and lower limit values of different intervals. Based on the records of the time dimension, screen the numerical data of the corresponding parameters within each time period. By comparing the change amplitude of the parameter values within the time interval, statistically calculate the fluctuation amplitude of the parameters in the high-frequency time period. The analysis of the change frequency is based on the number of fluctuations of each parameter per unit time, and statistically calculate the distribution ratio of the parameters in the high-fluctuation frequency interval. Combining the statistical results of the fluctuation frequency and the distribution range, judge the distribution concentration degree of the parameter values in the time dimension. Summarize the change frequency and concentration degree of the parameter values recorded in all time dimensions to obtain the time distribution data of the group parameters, providing a basis for subsequent time law analysis.

[0114] S402: Based on the time distribution data of the group parameters, parse the distribution data of the time dimension, extract the parameter value fluctuation range, analyze the change amount within the time period, judge the time distribution law of the parameters, and classify and organize the periodic and persistent characteristic parameters to obtain the key parameter classification characteristics;

[0115] First, calculate the fluctuation range based on the distribution ratios of each parameter in different time periods. For example, extract the upper and lower limits of the fluctuation of the traffic anomaly rate during the night period, and record the mean and range of the fluctuation range. The analysis of the change amount within a time period is based on continuous records in different time periods. By calculating the increase and decrease amounts of the parameter values in each time period, judge the change rate and direction. For example, judge the significance of the change amount by analyzing the difference in access frequency between the morning peak and the late-night low peak. When judging the time distribution law, use the concentration degree and change amplitude of the distribution of the parameter in multiple time periods, classify and sort the periodic and persistent characteristic parameters, classify and sort all parameters according to the time law, clarify their periodic and persistent characteristics, extract the characteristic parameters and mark their key risk levels, and obtain the classification characteristics of the key parameters, providing data support for further feature sorting and risk score calculation.

[0116] S403: Based on the classification characteristics of the key parameters, integrate the distribution data of the parameters in the classification characteristics, re-induce the characteristic values of the parameters in combination with the time law of the parameters, sort out the group characteristics according to the interaction characteristics of the time dimension and the classification data, calculate the key risk characteristic scores, and generate a dataset of key network security risk characteristics;

[0117] Calculate the key risk characteristic score according to the following formula (2):

[0118]

[0119] where, R represents the key risk characteristic score, T represents the sum of the absolute values of the set of key characteristic values extracted from the time dimension trend data, P i represents the i-th principal component characteristic value in the classification characteristics, F represents the mean absolute deviation of the parameter distribution data, ΔS represents the change rate of the time series residual, w1 is the trend weight adjustment parameter, w2 is the classification principal component characteristic weight parameter, w3 is the deviation mean weight coefficient, and w4 is the residual change rate adjustment parameter;

[0120] Detailed explanation of the formula and the derivation process of the formula calculation:

[0121] This formula is used to calculate the key network security risk characteristic score R, which is a comprehensive measure of the network security risk characteristics and is used to evaluate the magnitude of potential risks in the network security environment. By considering multi-dimensional factors such as the time dimension, classification principal components, distribution deviation, and time series residual change, the formula comprehensively analyzes the risk status of the network security environment;

[0122] T: Represents the absolute sum of the trend data set in the time dimension, reflecting the change trend of network security features in different time periods. The time trend data is quantitatively calculated by monitoring the changes in data streams, such as traffic fluctuations and the occurrence time of attack activities. The time trend data uses daily, weekly, or monthly data sets, and relevant maximum change values and periodic characteristics of the changes need to be extracted during calculation;

[0123] It is assumed that by monitoring the network security data of one day, the absolute change value of the daily network traffic fluctuation can be extracted, and the data set T = {15, 30, 25, 20} is obtained. Calculate: |T| = |15| + |30| + |25| + |20| = 90;

[0124] P i : Represents the principal component characteristic value in the classification characteristics, used to reflect the key network security features (such as attack behavior patterns, traffic anomalies, etc.) under a specific category. Through the principal component analysis (PCA) method, the most important features are extracted from multi-dimensional characteristics. Each P i corresponds to the characteristic value of a principal component. After PCA analysis, the weight of each principal component reflects its contribution to the overall risk. It is assumed that through PCA analysis, the principal component characteristic values are P1 = 20, P2 = 15, P3 = 10, and the sum of the characteristic values of the first two principal components is selected for calculation, that is, ∑P i = 20 + 15 = 35;

[0125] F: Represents the mean absolute deviation of the parameter distribution data, used to represent the deviation fluctuation of specific network security parameters (such as delay time, traffic size, etc.). The deviation mean is calculated by calculating the difference between the data of each sampling point and its mean value to obtain its average deviation size. This deviation mean is calculated by the absolute value method and can measure the stability of some key parameters;

[0126] It is assumed that by monitoring the data, the parameter distribution data {10, 15, 20, 30} is found, and its mean absolute deviation is calculated: |10 - 18| + |15 - 18| + |20 - 18| + |30 - 18| = 8 + 3 + 2 + 12 = 25;

[0127] Deviation mean

[0128] ΔS: Represents the change rate of the time series residuals, which is used to measure the fluctuation of the unexplained part in the time series. Through time series decomposition, the residuals represent the part of the data that cannot be explained by trends and seasonal patterns. The residual change rate measures the degree of change. A higher residual change rate means a higher system instability and greater potential risks. It is assumed that the residual sequence obtained through time series decomposition is {-2, 1, 0, 3}. The residual change rate ΔS can be quantified by calculating the absolute value of the difference between adjacent residuals. Calculation: |ΔS| = |1 - (-2)| + |0 - 1| + |3 - 0| = 3 + 1 + 3 = 7;

[0129] Weight parameter w1: Adjusts the influence weight of the time trend characteristic on the risk score. This parameter is determined through the analysis of historical data. In a relatively stable environment, the value of w1 is small, indicating that the time trend has a relatively weak influence on the overall result; while in a more volatile environment, the value of w1 is large, indicating that the time trend has a greater impact on network security risks. It is assumed that w1 = 0.8, which is used to emphasize the influence of time trend data on network security risk assessment.

[0130] Weight parameter w2: Adjusts the influence weight of the classification principal component on the risk score. This parameter is set according to the contribution degree of the principal component characteristics after PCA analysis to the overall risk. When the principal component characteristics dominate in the classification data, w2 will be large; otherwise, it will be small. It is assumed that w2 = 0.5, indicating the medium importance of the classification principal component to the final risk assessment;

[0131] Weight parameter w3: Adjusts the influence of the deviation of the parameter distribution data on the risk assessment. Larger deviation data indicates potential risks, so the size of this weight coefficient will be set according to the stability of the distribution data. It is assumed that w3 = 1.2, reflecting that a larger deviation will have a greater impact on network security risk characteristics;

[0132] Weight parameter w4: Adjusts the influence of the residual change rate on the risk assessment. The fluctuation of the residuals reflects the unpredictable changes in the data, and this kind of change is the source of potential risks. It is assumed that w4 = 0.9. When this value is large, it indicates that the residual change rate has a significant impact on the risk assessment;

[0133] Substitute the parameters into the formula for calculation:

[0134] Substitute the obtained values into the formula for specific calculation:

[0135] The first part:

[0136] The second part:

[0137] Final result: R = 0.037 + 0.374 = 0.411;

[0138] The calculated result R = 0.411 indicates that the risk score of network security is 0.411, which shows that in the current network security environment, based on the comprehensive evaluation of time trend, classification principal components, parameter deviation, and time series residual changes, the overall risk level of the system is medium. This result reflects the potential risks of the system in aspects such as data volatility, trend changes, and abnormal situations, and further monitoring and improvement are required.

[0139] In a feasible implementation, as Figure 6 shown, based on the network security key risk feature dataset, the steps of parsing the time change records of key risk factors, calling the distribution offset value and the original record, evaluating the offset amplitude and the scope of action, and statistically analyzing the data of the offset range and the action intensity to generate the dynamic evaluation result of network key risks are specifically as follows:

[0140] S501: Based on the network security key risk feature dataset, extract the time - dimension change records of key risk factors, parse the time - interval distribution data, calculate the distribution offset value within the change span, screen the distribution offset amplitude factors, and obtain the key risk factor distribution offset data;

[0141] When extracting the time - dimension change records of key risk factors from the network security key risk feature dataset, based on the risk - level distribution ratio of each factor in different time periods, organize its distribution records in chronological order. When parsing the time - interval distribution data, classify the distribution records within the time dimension according to different risk levels. When calculating the distribution offset value within the change span, use the difference between the maximum value and the minimum value in the distribution record as the offset value. When screening the distribution offset amplitude factors, sort them according to the size of the offset value, mark the factors with significant offset values as high - offset factors, and organize the time - dimension distribution records and the corresponding offset values of the screened high - offset amplitude factors into the key risk factor distribution offset data to provide support for the subsequent analysis of the offset range and dynamic rules.

[0142] S502: Based on the key risk factor distribution offset data, extract the original distribution law of the offset factors, analyze the difference range between the offset value and the original distribution, evaluate the offset amplitude, extract the data within the offset range, and integrate the characteristics of the action area in combination with the time dimension to obtain the key risk factor offset action range;

[0143] When extracting the original distribution law of the offset factor from the offset data of key risk factor distributions, record the original distribution ratio according to the time dimension, and statistically calculate the basic distribution mean of each factor within each risk level. For example, when extracting the high-risk distribution mean of the access frequency anomaly factor during normal periods, marking the change trend of the distribution in each period, analyzing the difference range between the offset value and the original distribution, calculating the relative ratio of the offset value to the original mean, evaluating the offset amplitude, quantifying the significance of the offset amplitude based on the statistical results of the difference between the offset value and the original distribution, when extracting the data within the offset range, record and organize the time periods with significant offset values as high-offset effect regions, delimit the effect range in combination with the time dimension, integrate the characteristic data of the effect regions, summarize the time distribution and characteristic values within the offset range of each factor, and form the offset effect range of key risk factors for evaluating their dynamic impact on network security risks.

[0144] S503: Based on the offset effect range of key risk factors, statistically calculate the effect intensity of key factors within the effect range, analyze the change trend of the intensity over time, analyze the dynamic law of the intensity change, integrate the characteristic data of the effect range and the dynamic law, and generate the dynamic assessment result of network key risks;

[0145] Within the offset effect range of key risk factors, when statistically calculating the effect intensity of key factors, calculate their contribution value to the overall risk based on the cumulative distribution ratio and offset value of each factor within the high-risk interval. When analyzing the change trend of the intensity over time, plot the intensity values of each key factor over the time dimension as a change curve, and analyze its fluctuation amplitude and direction within a specific time period. When analyzing the dynamic law of the intensity change, combine the fluctuation period and distribution characteristics of the factor, statistically calculate the frequency and trend of the change in the effect intensity, integrate the factor effect intensity and dynamic change law data within the effect range, generate a data set including the distribution characteristics in the time dimension, the change trend of the intensity, and the dynamic law, and form the dynamic assessment result of network key risks to provide a scientific basis for network security risk management.

[0146] As Figure 7 shown, a network security risk assessment system based on fuzzy mathematics, the system includes:

[0147] The risk factor dynamic monitoring module 310 is used to extract the traffic anomaly rate, port status fluctuation, access frequency, and intrusion alarm parameters based on the dynamic monitoring data of node data in the network environment, compare the risk level intervals, analyze the numerical proportion of the differential distribution, statistically calculate the distribution ratio, and generate a multi-parameter risk factor distribution ratio table;

[0148] The risk factor interval analysis module 320 is used to analyze the distribution law of risk factors based on the multi-parameter risk factor distribution ratio table, compare item by item the risk level intervals, identify the influence ratio of the level intervals, integrate the risk level ratio and weight difference data, and establish a risk factor associated weight distribution table;

[0149] The interaction characteristic analysis module 330 is used to analyze the weight and distribution ratio data based on the risk factor associated weight distribution table, cross-compare the weight coverage range and the distribution ratio, screen the relevant risk factor combinations, and generate a multi-risk factor interaction relationship model;

[0150] The risk factor time evolution module 340 is used to statistically analyze the time change range of the factor combinations based on the multi-risk factor interaction relationship model, compare the distribution shift and fluctuation frequency within the time range, integrate the time evolution characteristic data, and establish a risk factor evolution distribution table in the time dimension;

[0151] The key characteristic association evaluation module 350 is used to analyze the time distribution shift value based on the risk factor evolution distribution table in the time dimension, statistically analyze the fluctuation range, screen the change amplitude characteristic groups, and generate the network key risk dynamic evaluation result.

[0152] Optionally, the network risk factor membership distribution table includes: traffic anomaly rate distribution, port status fluctuation range, access frequency ratio, and intrusion alarm statistics distribution;

[0153] The interaction risk distribution model includes: parameter distribution ratio relationship, weight difference influencing factors, multi-risk factor interaction characteristic range, and distribution and weight classification results;

[0154] The risk factor group mapping table includes: group associated parameters, key risk factor groups, multi-risk factor cumulative weights, and group interaction influence ranges;

[0155] The network security key risk feature data set includes: time dimension distribution records, parameter centralized change distributions, fluctuation change characteristics, and group feature classification diagrams;

[0156] The network key risk dynamic evaluation result includes: distribution shift amplitude records, shift action range data, shift intensity statistics, and key risk factor time change records.

[0157] Optionally, the risk factor dynamic monitoring module 310 uses the dynamic monitoring data of node data in the network environment to gradually extract the traffic anomaly rate, port status fluctuation, access frequency, and intrusion alarm parameters, verify each original record distribution value one by one, eliminate the error data, and divide the data range according to the distribution trend to obtain a parameter value range division data set;

[0158] Divide the data set based on the parameter value range, extract the current value of the parameter in the dynamic monitoring data, analyze the difference amplitude of the risk interval segment values, divide the difference amplitude into attribution categories, label the attribution category for the current value of the parameter, and generate a parameter attribution interval distribution table;

[0159] Based on the parameter attribution interval distribution table, count the distribution proportion of the current value of the parameter within the risk interval, analyze the change in the proportion of the interval segment, sort out the correlation between the classified parameter distribution proportions, and generate a network risk factor membership distribution table.

[0160] Optionally, the risk factor interval analysis module 320 is used to extract the distribution proportion data of the parameter based on the network risk factor membership distribution table, analyze the relationship between the distribution proportion and the risk level, analyze the original record and the change range of the distribution proportion, classify the matching relationship between the distribution proportion and the risk level, and obtain the difference data between the distribution proportion and the risk level;

[0161] Based on the difference data between the distribution proportion and the risk level, analyze the weight relationship between the distribution proportion and the risk level, compare the weight change trend of the parameter distribution proportion, sort out the weight data of the classified change range, and obtain the influence data of the distribution proportion and the weight;

[0162] Based on the influence data of the distribution proportion and the weight, analyze the weight change relationship under the interaction condition, count the coverage range of the multi-risk factor interaction influence, classify the interaction weight and the distribution characteristic data, integrate the interaction characteristic influence data, calculate the interaction risk distribution relationship weight, and construct an interaction risk distribution model.

[0163] Optionally, calculate the interaction risk distribution relationship weight according to the following formula (1):

[0164]

[0165] Among them, E represents the interaction risk distribution relationship weight, P a represents the distribution proportion of risk factor A in the initial state, W a represents the weight parameter of risk factor A, P b represents the distribution proportion of risk factor B in the initial state, W b represents the weight parameter of risk factor B, Q c represents the interaction influence intensity of risk factor C, W c represents the weight parameter of risk factor C, P d represents the standardized distribution density of risk factor D.

[0166] Optionally, the interaction characteristic analysis module 330 is used to analyze the weight value and the distribution proportion of the risk factor based on the interaction risk distribution model, extract the cumulative weight value, calculate the correlation intensity in the distribution, classify the risk factors, and establish a parameter group matching set;

[0167] Based on the parameter group matching set, analyze the associated parameters of the risk factors within the group, extract interaction factors, analyze the scope of factor action, and construct a characteristic key factor group;

[0168] Based on the characteristic key factor group, analyze the distribution law of data characteristics within the group, perform mapping processing according to the distribution trend, adjust the interaction parameter values, integrate the associated characteristics between factors, and generate a risk factor group mapping table.

[0169] Optionally, the risk factor time evolution module 340 is used to extract the distribution range of group data parameters based on the risk factor group mapping table, screen the data with corresponding parameter values in the time dimension records, compare the change amplitude of parameter values within the time interval, analyze the change frequency and judge the distribution concentration degree, and obtain the time distribution data of group parameters;

[0170] Based on the time distribution data of group parameters, analyze the distribution data in the time dimension, extract the fluctuation range of parameter values, analyze the change amount within the time period, judge the time distribution law of parameters, classify and sort the periodic and persistent characteristic parameters, and obtain the classification characteristics of key parameters;

[0171] Based on the classification characteristics of key parameters, integrate the distribution data of parameters in the classification characteristics, re-induce the characteristic values of parameters in combination with the time law of parameters, sort out the group characteristics according to the interaction characteristics of the time dimension and classification data, calculate the key risk characteristic scores, and generate a network security key risk characteristic data set.

[0172] Optionally, calculate the key risk characteristic score according to the following formula (2):

[0173]

[0174] Among them, R represents the key risk characteristic score, T represents the sum of the absolute values of the set of key characteristic values extracted from the time dimension trend data, and P i represents the i-th principal component characteristic value in the classification characteristics, F represents the average absolute deviation of the parameter distribution data, ΔS represents the change rate of the time series residual, w1 is the trend weight adjustment parameter, w2 is the classification principal component characteristic weight parameter, w3 is the deviation mean weight coefficient, and w4 is the residual change rate adjustment parameter.

[0175] Optionally, the key characteristic association evaluation module 350 is used to extract the time dimension change records of key risk factors based on the network security key risk characteristic data set, analyze the distribution data in the time interval, calculate the distribution offset value within the change span, screen the distribution offset amplitude factors, and obtain the key risk factor distribution offset data;

[0176] Based on the data of the distribution shift of key risk factors, extract the original distribution law of the shift factors, analyze the difference range between the shift values and the original distribution, evaluate the shift amplitude, extract the data within the shift range, and integrate the characteristics of the action area in combination with the time dimension to obtain the scope of the shift action of key risk factors.

[0177] Based on the scope of the shift action of key risk factors, count the action intensity of the key factors within the action scope, analyze the trend of the intensity change over time, analyze the dynamic law of the intensity change, and integrate the data of the action scope and the characteristics of the dynamic law to generate the dynamic assessment result of the key risks of the network.

[0178] Figure 8 It is a schematic structural diagram of a core RQD detection device based on contour recognition and image processing provided by an embodiment of the present invention. As Figure 8 shown, the core RQD detection device based on contour recognition and image processing may include the above-mentioned Figure 7 core RQD detection device shown. Optionally, the core RQD detection device 410 based on contour recognition and image processing may include a first processor 2001.

[0179] Optionally, the core RQD detection device 410 based on contour recognition and image processing may further include a memory 2002 and a transceiver 2003.

[0180] Among them, the first processor 2001, the memory 2002, and the transceiver 2003 may be connected through a communication bus, for example.

[0181] Next, in combination with Figure 8 each component of the network data asset security classification device 410 for small sample constraints will be specifically introduced:

[0182] Among them, the first processor 2001 is the control center of the network data asset security classification device 410 for small sample constraints, which may be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 is one or more central processing units (CPUs), or may be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, for example: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0183] Optionally, the first processor 2001 can execute various functions of the network data asset security classification device 410 for small sample constraints by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.

[0184] In a specific implementation, as an example, the first processor 2001 may include one or more CPUs, such as Figure 8 CPU0 and CPU1 shown in

[0185] In a specific implementation, as an example, the network data asset security classification device 410 for small sample constraints may also include multiple processors, such as Figure 8 the first processor 2001 and the second processor 2004 shown in

[0186] Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0187] Among them, the memory 2002 is used to store the software program for implementing the solution of the present invention and is controlled by the first processor 2001 for execution. The specific implementation manner may refer to the above method embodiments and will not be elaborated here.

[0187] Optionally, the memory 2002 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but not limited thereto. The memory 2002 may be integrated with the first processor 2001 or may exist independently and is coupled to the first processor 2001 through an interface circuit ( Figure 8 not shown in

[0188] A transceiver 2003 is used to communicate with a network device or with a terminal device.

[0189] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 8 not shown separately). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0190] Optionally, the transceiver 2003 may be integrated with the first processor 2001, or may exist independently, and is coupled to the first processor 2001 through an interface circuit ( Figure 8 not shown) of the network data asset security classification device 410 for small sample constraints. The embodiments of the present invention do not make specific limitations thereto.

[0191] It should be noted that Figure 8 the structure of the network data asset security classification device 410 for small sample constraints shown does not constitute a limitation to the router. The actual knowledge structure recognition device may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0192] In addition, the technical effects of the network data asset security classification device 410 for small sample constraints may refer to the technical effects of the network data asset security classification method for small sample constraints described in the above method embodiments, and will not be elaborated here.

[0193] It should be understood that the first processor 2001 in the embodiments of the present invention may be a central processing unit (CPU), and this processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.

[0194] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0195] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0196] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context.

[0197] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0198] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0199] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0200] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the devices, apparatuses, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0201] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.

[0202] As described above, the above are only specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A network security risk assessment method based on fuzzy mathematics, characterized in that, The following steps are involved: S1: Based on the dynamic monitoring data of node data in the network environment, extract multiple risk factor parameters, divide the parameter value range, compare the risk level intervals, count the distribution proportions of differentiated intervals, and generate a network risk factor membership distribution table; S2: Based on the network risk factor membership distribution table, analyze the influence of parameter distribution ratio, analyze the influence of ratio difference on weight, count the influence range of multi-risk factor interaction characteristics, classify distribution and weight data, and generate an interactive risk distribution model; S3: Based on the interactive risk distribution model, analyze the correlation between the weight value and the distribution ratio, call the cumulative value of the weights of multiple risk factors, evaluate the correlation effect of parameter groups, screen risk factor groups with prominent characteristics, and generate a risk factor group mapping table; S4: Based on the risk factor group mapping table, call the group data and time dimension records, count the time change range of the group, analyze the concentration and change frequency of the distribution data, analyze the parameter fluctuation law, classify it into group characteristics, and generate a network security key risk characteristic data set; S5: Based on the network security key risk feature data set, analyze the time change records of key risk factors, call the distribution offset value and the original record, evaluate the offset amplitude and scope of action, and statistically analyze the offset range and intensity of action data to generate a dynamic assessment result of network key risks.

2. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that, The network risk factor membership distribution table includes: traffic anomaly rate distribution, port status fluctuation range, access frequency ratio and intrusion alarm statistical distribution; The interactive risk distribution model includes: parameter distribution ratio relationship, weight difference influencing factors, multi-risk factor interactive characteristic range, and distribution and weight classification results; The risk factor group mapping table includes: group association parameters, key risk factor groups, cumulative weights of multiple risk factors, and group interaction impact ranges; The network security key risk feature data set includes: time dimension distribution records, parameter concentration change distribution, fluctuation change characteristics and group feature classification diagram; The network key risk dynamic assessment results include: distribution deviation amplitude records, deviation scope data, deviation intensity statistics and key risk factor time change records.

3. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that In S1, based on the dynamic monitoring data of node data in the network environment, multiple risk factor parameters are extracted, the parameter value range is divided, the risk level intervals are compared, the distribution ratio of differentiated intervals is statistically analyzed, and the network risk factor affiliation distribution table is generated, including: S101: Based on the dynamic monitoring data of node data in the network environment, the traffic anomaly rate, port status fluctuation, access frequency and intrusion alarm parameters are gradually extracted, the original record distribution values are verified one by one, the erroneous data are eliminated, and the data range is divided according to the distribution trend to obtain the parameter value range division data set; S102: Divide the data set based on the parameter value range, extract the current value of the parameter in the dynamic monitoring data, analyze the difference amplitude of the risk interval segment value, divide the difference amplitude into attribution categories, mark the attribution category for the current value of the parameter, and generate a parameter attribution interval distribution table; S103: Based on the parameter attribution interval distribution table, count the distribution ratio of the current parameter value within the risk interval, analyze the change in the proportion of the interval segment, sort out the association between the classification parameter distributions, and generate a membership distribution table of network risk factors.

4. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that In S2, based on the membership distribution table of network risk factors, analyze the influence of the parameter distribution ratio, analyze the degree of influence of the ratio difference on the weight, count the influence range of the interaction characteristics of multiple risk factors, classify the distribution and weight data, and generate an interactive risk distribution model, including: S201: Based on the membership distribution table of network risk factors, extract the distribution ratio data of the parameters, analyze the relationship between the distribution ratio and the risk level, analyze the original record and the change range of the distribution ratio, and classify the matching relationship between the distribution ratio and the risk level to obtain the difference data between the distribution ratio and the risk level; S202: Based on the difference data between the distribution ratio and the risk level, analyze the weight relationship between the distribution ratio and the risk level, compare the weight change trend of the parameter distribution ratio, sort out the weight data of the change range, and obtain the influence data of the distribution ratio and the weight; S203: Based on the influence data of the distribution ratio and the weight, analyze the weight change relationship under the interaction condition, count the coverage range of the interaction influence of multiple risk factors, classify the interactive weights and distribution characteristic data, integrate the influence data of the interaction characteristics, calculate the interactive risk distribution relationship weight, and construct an interactive risk distribution model.

5. The network security risk assessment method based on fuzzy mathematics according to claim 4, characterized in that Calculate the interactive risk distribution relationship weight according to the following formula (1): (1); Among them, represents the weight of the interactive risk distribution relationship, represents the distribution ratio of risk factor A in the initial state, represents the weight parameter of risk factor A, represents the distribution ratio of risk factor B in the initial state, represents the weight parameter of risk factor B, represents the interactive influence intensity of risk factor C, represents the weight parameter of risk factor C, represents the standardized distribution density of risk factor D.

6. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that, In S3, based on the interactive risk distribution model, analyze the correlation between the weight value and the distribution ratio, call the cumulative value of the weights of multiple risk factors, evaluate the association effect of the parameter group, screen the risk factor groups with prominent characteristics, and generate a mapping table of risk factor groups, including: S301: Based on the interactive risk distribution model, analyze the weight value and the distribution ratio of the risk factors, extract the cumulative weight value, calculate the correlation intensity in the distribution, classify the risk factors, and establish a matching set of parameter groups; S302: Based on the matching set of parameter groups, analyze the associated parameters of the risk factors within the group, extract the interactive factors, analyze the action range of the factors, and construct a key factor group with characteristics; S303: Based on the key factor group with characteristics, analyze the distribution law of the data characteristics within the group, perform mapping processing according to the distribution trend, adjust the interactive parameter value, integrate the associated characteristics between the factors, and generate a mapping table of risk factor groups.

7. The network security risk assessment method based on fuzzy mathematics according to claim 1, wherein In S4, based on the mapping table of risk factor groups, call the group data and the time dimension records, count the time change range of the group, analyze the concentration degree and change frequency of the distribution data, analyze the parameter fluctuation law, classify it as group characteristics, and generate a dataset of key network security risk characteristics, including: S401: Based on the mapping table of risk factor groups, extract the distribution range of the group data parameters, screen the corresponding parameter value data in the time dimension records, compare the change amplitude of the parameter values within the time interval, analyze the change frequency and judge the concentration degree of the distribution, and obtain the time distribution data of the group parameters; S402: Based on the time distribution data of the group parameters, analyze the time - dimension distribution data, extract the fluctuation range of parameter values, analyze the change amount within the time period, judge the parameter time distribution law, classify and sort the periodic and persistent characteristic parameters, and obtain the key parameter classification characteristics; S403: Based on the key parameter classification characteristics, integrate the distribution data of the parameters in the classification characteristics, re - summarize the characteristic values of the parameters in combination with the time law of the parameters, sort out the group characteristics according to the interaction characteristics of the time dimension and the classification data, calculate the key risk characteristic scores, and generate a network security key risk characteristic data set.

8. The network security risk assessment method based on fuzzy mathematics according to claim 7, wherein Calculate the key risk characteristics according to the following formula (2): (2); Among them, R represents the key risk feature score, and T represents the sum of the absolute values of the set of key feature values extracted from the time - dimension trend data. represents the i - th principal - component feature value in the classification features, and F represents the mean absolute deviation of the parameter distribution data. represents the change rate of the time - series residuals. is the trend weight adjustment parameter. is the classification principal - component feature weight parameter. is the mean absolute - deviation weight coefficient. is the residuals change - rate adjustment parameter.

9. The network security risk assessment method based on fuzzy mathematics according to claim 1, wherein In S5, based on the network security key risk characteristic data set, analyze the time - change record of the key risk factors, call the distribution offset value and the original record, evaluate the offset amplitude and the action range, count the offset range and the action intensity data, and generate a network key risk dynamic assessment result, including: S501: Based on the network security key risk characteristic data set, extract the time - dimension change record of the key risk factors, analyze the time - interval distribution data, calculate the distribution offset value within the change span, screen the distribution offset amplitude factors, and obtain the key risk factor distribution offset data; S502: Based on the key risk factor distribution offset data, extract the original distribution law of the offset factors, analyze the difference range between the offset value and the original distribution, evaluate the offset amplitude, extract the data within the offset range, and integrate the action area characteristics in combination with the time dimension to obtain the key risk factor offset action range; S503: Based on the key risk factor offset action range, count the action intensity of the key factors within the action range, analyze the trend of the intensity change with time, analyze the dynamic law of the intensity change, integrate the action range and the dynamic law characteristic data, and generate a network key risk dynamic assessment result.

10. A network security risk assessment system based on fuzzy mathematics, characterized in that, According to the network security risk assessment method based on fuzzy mathematics according to any one of claims 1 - 9, the system includes: A risk factor dynamic monitoring module, which is used to extract the traffic anomaly rate, port status fluctuation, access frequency and intrusion warning parameters based on the dynamic monitoring data of node data in the network environment, compare the risk level intervals, analyze the numerical proportion of the differential distribution, count the distribution ratio, and generate a multi - parameter risk factor distribution ratio table; A risk factor interval analysis module, which is used to analyze the distribution law of the risk factors based on the multi - parameter risk factor distribution ratio table, make item - by - item comparisons of the risk level intervals, identify the influence ratio of the level intervals, integrate the risk level ratio and the weight difference data, and establish a risk factor correlation weight distribution table; An interaction characteristic analysis module, which is used to analyze the weight and distribution ratio data based on the risk factor correlation weight distribution table, make cross - comparisons of the weight coverage range and the distribution ratio, screen the relevant risk factor combinations, and generate a multi - risk factor interaction relationship model; A risk factor time evolution module, which is used to, based on the multi-risk factor interaction relationship model, statistically calculate the time variation range of the factor combination, compare the distribution shift and fluctuation frequency within the time range, integrate the time evolution characteristic data, and establish a risk factor evolution distribution table in the time dimension; A key characteristic correlation evaluation module, which is used to, based on the risk factor evolution distribution table in the time dimension, analyze the time distribution shift value, statistically calculate the fluctuation range, screen the change amplitude characteristic groups, and generate a dynamic evaluation result of the key risks of the network.

Citation Information

Patent Citations

  • Electric power communication backbone data network security comprehensive evaluation method based on AHP-RST

    CN114548637A

  • Vulnerability management method and system based on network assets

    CN117614744A

  • Foundation pit supporting performance evaluation method and system based on data analysis

    CN118133672A

  • Heart disease prediction system based on AI

    CN119480113A

  • Substrate management controller access control method and system

    CN119513932A

Cited By

  • Live broadcast e-commerce accounting management data processing system based on privacy calculation

    CN120996958A

  • Detection platform-oriented multi-dimensional information security risk dynamic evaluation system and method

    CN122093175A

  • Multi-dimensional information security risk dynamic assessment system and method for detection platform

    CN122093175B

  • Security threat investigation

    US20250097246A1