A network security risk assessment method and system based on fuzzy mathematics
By using a network security risk assessment method based on fuzzy mathematics, dynamically monitoring network node data, constructing an interactive risk distribution model, and screening risk factor groups with prominent characteristics, the problem of bias in risk assessment under dynamic threat environments in existing technologies is solved, and more accurate and real-time risk assessment is achieved.
Patent Information
- Application Number
- CN202510456023.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2045-04-11
AI Technical Summary
Existing cybersecurity risk assessment methods are unable to reflect the dynamic changes of risk factors in dynamic threat environments, lack systematic analysis of the interactions between multiple risk factors, resulting in biased assessment results, insufficient response speed and accuracy, and an inability to accurately capture the key characteristics of potential risk events.
The network security risk assessment method based on fuzzy mathematics extracts multiple risk factor parameters by dynamically monitoring network node data, generates a network risk factor membership distribution table, analyzes the influence of parameter distribution ratios, constructs an interactive risk distribution model, filters risk factor groups with prominent characteristics, generates a dataset of key network security risk features, and realizes dynamic assessment of risk factors.
It has improved the targeting and scientific nature of risk identification, enhanced the real-time monitoring capability of dynamic risk changes, and improved the accuracy and dynamic adaptability of risk assessment, effectively addressing complex cybersecurity threats.
Smart Images

Figure CN120378146B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information security technology, and in particular to a network security risk assessment method and system based on fuzzy mathematics. BACKGROUND
[0002] The field of information security technology includes security protection techniques related to computer systems and networks, and its core content includes ensuring the confidentiality, integrity, and availability of information, and preventing threats and attacks on data during storage, transmission, and processing. The field of information security technology covers cryptography, identity authentication, access control, network security system design, and security evaluation methods, and through the establishment of an information security management system and technical measures, information systems and their resources are protected from unauthorized access, destruction, and tampering. The research direction of this technical field mainly focuses on threat detection, risk assessment, security policy optimization, and security monitoring method development to cope with increasingly complex security threats.
[0003] Among them, the network security risk assessment method refers to the analysis and evaluation of potential security risks in computer network systems, which covers risk identification, risk analysis, and risk assessment, and is based on the construction of mathematical models, quantitative evaluation indicators, and logical reasoning methods. By establishing a risk assessment model based on fuzzy mathematics theory, the risk level of threat events in the network system is divided based on the fuzzy set theory of risk factors, and a comprehensive evaluation of different threat events is made using risk analysis methods to form the risk level evaluation results of the system.
[0004] The analysis of parameters in the prior art in risk assessment is mostly focused on static dimensions, which cannot effectively reflect the dynamic change characteristics of risk factors in the network environment. The risk identification method relies on single or limited risk factor data, and lacks systematic analysis of the interaction between multiple risk factors. This limitation easily leads to deviations in the evaluation results in complex threat environments. In the parameter division and evaluation process, the prior art mostly uses a static index system based on a fixed model, which is difficult to adapt to the rapid fluctuation characteristics of factor distribution in real-time network environments. For the parameter change law in the time dimension, the prior art relies more on periodic recording, and lacks the ability to deeply analyze the fluctuation range and offset characteristics of the parameters, resulting in insufficient response speed and accuracy of risk assessment in dynamic threats. This deficiency causes the identification of network threats to lag, and the key characteristics of potential risk events cannot be accurately captured, thereby reducing the overall effectiveness of network security protection. In the face of complex threats, the static characteristics and single factor analysis mode of the prior art become important bottlenecks that restrict the network security assessment capability. SUMMARY
[0005] In order to solve the problem that the analysis of parameters in risk assessment in the prior art is mostly focused on static dimensions, it is difficult to effectively reflect the dynamic change characteristics of risk factors in the network environment, the risk identification method depends on single or limited risk factor data, and the systematic analysis of the interaction between multiple risk factors is lacking, which is easy to cause the deviation of the evaluation result in a complex threat environment, in the parameter division and evaluation process of the prior art, a static index system based on a fixed model is mostly used, which is difficult to adapt to the rapid fluctuation characteristics of factor distribution in the real-time network environment, and for the parameter change law in the time dimension, the prior art mostly relies on periodic recording, and lacks the ability to deeply analyze the fluctuation range and offset characteristics of the parameters, resulting in insufficient response speed and accuracy of risk assessment in a dynamic threat, which causes the identification of network threats to lag, and cannot accurately capture the key characteristics of potential risk events, thereby reducing the overall effectiveness of network security protection, in response to complex threats, the static characteristics and single factor analysis mode of the prior art become important technical problems that restrict the network security evaluation capability, and the embodiment of the present application provides a network security risk assessment method and system based on fuzzy mathematics. The technical solution is as follows:
[0006] In one aspect, a network security risk assessment method based on fuzzy mathematics is provided, which comprises:
[0007] S1: based on the dynamic monitoring data of node data in the network environment, extracting multiple risk factor parameters, dividing the parameter value range, comparing the risk level interval, calculating the proportion of the difference interval distribution, and generating a network risk factor membership distribution table;
[0008] S2: based on the network risk factor membership distribution table, analyzing the influence of parameter distribution proportion, analyzing the influence degree of proportion difference on weight, calculating the influence range of the interaction characteristics of multiple risk factors, classifying the distribution and weight data, and generating an interaction risk distribution model;
[0009] S3: based on the interaction risk distribution model, analyzing the correlation between weight value and distribution proportion, calling the cumulative value of multiple risk factor weights, evaluating the correlation of parameter groups, screening risk factor groups with prominent characteristics, and generating a risk factor group mapping table;
[0010] S4: based on the risk factor group mapping table, calling the group data and time dimension record, calculating the time change range of the group, analyzing the concentration degree and change frequency of the distribution data, analyzing the parameter fluctuation law, classifying the group characteristics, and generating a network security key risk feature data set;
[0011] S5: Based on the dataset of key network security risk characteristics, analyze the time change records of key risk factors, call the distribution offset values and original records, evaluate the offset magnitude and scope of effect, statistically analyze the offset range and intensity of effect data, and generate dynamic assessment results of key network risks.
[0012] Optionally, the network risk factor membership distribution table includes: traffic anomaly rate distribution, port status fluctuation range, access frequency ratio, and intrusion alarm statistical distribution;
[0013] The interactive risk distribution model includes: the proportional relationship of parameter distribution, the factors affecting weight differences, the range of interaction characteristics of multiple risk factors, and the distribution and weight classification results;
[0014] The risk factor group mapping table includes: group association parameters, key risk factor groups, cumulative weights of multiple risk factors, and the scope of group interaction impact;
[0015] The cybersecurity key risk feature dataset includes: time-dimensional distribution records, parameter set variation distribution, fluctuation variation features, and group feature classification maps;
[0016] The results of the dynamic assessment of key network risks include: distribution offset amplitude records, offset range data, offset intensity statistics, and time change records of key risk factors.
[0017] Optionally, in S1, based on dynamic monitoring data of node data in the network environment, multiple risk factor parameters are extracted, parameter value ranges are divided, risk level intervals are compared, the distribution proportion of differential intervals is statistically analyzed, and a network risk factor membership distribution table is generated, including:
[0018] S101: Based on dynamic monitoring data of node data in the network environment, gradually extract parameters such as traffic anomaly rate, port status fluctuation, access frequency and intrusion alarm, verify the distribution values of the original records one by one, remove erroneous data, divide the data range according to the distribution trend, and obtain the parameter value range division dataset.
[0019] S102: Divide the dataset based on the parameter value range, extract the current value of the parameter in the dynamic monitoring data, analyze the difference in the risk interval values, divide the difference into categories, label the current value of the parameter with its category, and generate a parameter category distribution table.
[0020] S103: Based on the parameter affiliation interval distribution table, statistically analyze the distribution ratio of the current parameter value within the risk interval, analyze the changes in the interval segment ratio, organize the correlation of the distribution ratio of the classification parameters, and generate the network risk factor affiliation distribution table.
[0021] Optionally, in S2, based on the network risk factor membership distribution table, the parameter distribution proportion influence is analyzed, the influence degree of proportion difference on weight is analyzed, the influence range of multi-risk factor interaction characteristics is counted, the distribution and weight data are classified, and the interaction risk distribution model is generated, including:
[0022] S201: Based on the network risk factor membership distribution table, the distribution proportion data of the parameter is extracted, the distribution proportion and risk level relationship is analyzed, the distribution proportion original record and change range are analyzed, the distribution proportion and risk level matching relationship is classified, and the distribution proportion and risk level difference data is obtained;
[0023] S202: Based on the distribution proportion and risk level difference data, the distribution proportion and risk level weight relationship is analyzed, the weight change trend of the parameter distribution proportion is compared, the weight data of the classified change range is arranged, the distribution proportion and weight influence data is obtained;
[0024] S203: Based on the distribution proportion and weight influence data, the weight change relationship under the interaction condition is analyzed, the multi-risk factor interaction influence coverage range is counted, the interaction weight and distribution characteristic data is classified, the interaction characteristic influence data is integrated, the interaction risk distribution relationship weight is calculated, and the interaction risk distribution model is constructed.
[0025] Optionally, the interaction risk distribution relationship weight is calculated according to the following formula (1):
[0026]
[0027] Wherein, E represents the interaction risk distribution relationship weight, P a represents the distribution proportion of risk factor A in the initial state, W a represents the weight parameter of risk factor A, P b represents the distribution proportion of risk factor B in the initial state, W b represents the weight parameter of risk factor B, Q c represents the interaction influence intensity of risk factor C, W c represents the weight parameter of risk factor C, P d represents the standardized distribution density of risk factor D.
[0028] Optionally, in S3, based on the interaction risk distribution model, the correlation between weight value and distribution proportion is analyzed, the cumulative value of multi-risk factor weight is called, the correlation of parameter group is evaluated, the risk factor group with prominent characteristics is screened, and the risk factor group mapping table is generated, including:
[0029] S301: Based on the interaction risk distribution model, the weight value and distribution proportion of the risk factor are analyzed, the cumulative weight value is extracted, the correlation intensity in the distribution is calculated, the risk factor is classified, and the parameter group matching set is established;
[0030] S302: Based on the parameter group matching set, the correlation parameters of the risk factors in the group are analyzed, the interaction factors are extracted, the factor action range is analyzed, and the characteristic key factor group is constructed;
[0031] S303: Based on the characteristic key factor group, the data characteristic distribution law in the group is analyzed, the mapping processing is performed according to the distribution trend, the interaction parameter value is adjusted, the correlation characteristics between factors are integrated, and the risk factor group mapping table is generated.
[0032] Optionally, in S4, based on the risk factor group mapping table, the group data and the time dimension record are called, the time variation range of the group is counted, the concentration degree and the change frequency of the distribution data are analyzed, the parameter fluctuation law is analyzed, the parameters are classified as group characteristics, and the network security key risk characteristic data set is generated, including:
[0033] S401: Based on the risk factor group mapping table, the group data parameter distribution range is extracted, the corresponding parameter value data in the time dimension record is screened, the parameter value change amplitude in the time interval is compared, the change frequency is analyzed and the distribution concentration degree is judged, and the group parameter time distribution data is obtained;
[0034] S402: Based on the group parameter time distribution data, the time dimension distribution data is analyzed, the parameter value fluctuation range is extracted, the change amount in the time period is analyzed, the parameter time distribution law is judged, the periodic and persistent characteristic parameters are classified and arranged, and the key parameter classification characteristics are obtained.
[0035] S403: Based on the key parameter classification characteristics, the distribution data of the parameters in the classification characteristics is integrated, the characteristic value of the parameters is re-inducted combined with the time law of the parameters, the group characteristics are arranged according to the interaction characteristics of the time dimension and the classification data, the key risk characteristic score is calculated, and the network security key risk characteristic data set is generated.
[0036] Optionally, the key risk characteristic score is calculated according to the following formula (2):
[0037]
[0038] Wherein, R represents the key risk characteristic score, T represents the sum of the absolute values of the key characteristic value set extracted from the time dimension trend data, P i represents the absolute deviation mean of the parameter distribution data, ΔS represents the change rate of the time series residual, w1 is the trend weight adjustment parameter, w2 is the classification principal component characteristic weight parameter, w3 is the deviation mean weight coefficient, and w4 is the residual change rate adjustment parameter.
[0039] Optionally, in S5, based on the network security key risk feature data set, the time variation record of the key risk factor is parsed, the distribution offset value is called with the original record, the offset amplitude and the action range are evaluated, the offset range and the action intensity data are counted, and the network key risk dynamic evaluation result is generated, including:
[0040] S501: Based on the network security key risk feature data set, the time dimension variation record of the key risk factor is extracted, the time interval distribution data is parsed, the distribution offset value in the variation span is calculated, the distribution offset amplitude factor is screened, and the key risk factor distribution offset data is obtained;
[0041] S502: Based on the key risk factor distribution offset data, the original distribution law of the offset factor is extracted, the difference range of the offset value and the original distribution is analyzed, the offset amplitude is evaluated, the data in the offset range is extracted, the action area characteristics are combined with the time dimension, and the key risk factor offset action range is obtained;
[0042] S503: Based on the key risk factor offset action range, the action intensity of the key factor in the action range is counted, the intensity variation trend is analyzed, the intensity variation dynamic law is analyzed, the action range and the dynamic law characteristic data are integrated, and the network key risk dynamic evaluation result is generated.
[0043] On the other hand, a network security risk assessment system based on fuzzy mathematics is provided, which is used to execute the network security risk assessment method based on fuzzy mathematics, and the system comprises:
[0044] The risk factor dynamic monitoring module is used for extracting the traffic anomaly rate, the port state fluctuation, the access frequency and the intrusion alarm parameter based on the dynamic monitoring data of the node data in the network environment, comparing the risk level interval, analyzing the numerical proportion of the difference distribution, counting the distribution proportion, and generating a multi-parameter risk factor distribution proportion table;
[0045] The risk factor interval analysis module is used for analyzing the distribution law of the risk factor based on the multi-parameter risk factor distribution proportion table, comparing the risk level interval item by item, identifying the influence proportion of the level interval, integrating the risk level proportion and the weight difference data, and establishing a risk factor correlation weight distribution table;
[0046] The interaction characteristic analysis module is used for analyzing the weight and distribution proportion data based on the risk factor correlation weight distribution table, cross-comparing the weight coverage range and the distribution proportion, screening the associated risk factor combination, and generating a multi-risk factor interaction relationship model;
[0047] A risk factor time evolution module is configured to, based on a multi-risk factor interaction model, count a time variation range of a factor combination, compare a distribution offset and a fluctuation frequency in the time range, integrate time evolution characteristic data, and establish a time-dimension risk factor evolution distribution table;
[0048] A key characteristic correlation evaluation module is configured to, based on the time-dimension risk factor evolution distribution table, analyze a time distribution offset value, count a fluctuation range, filter a change amplitude characteristic group, and generate a network key risk dynamic evaluation result.
[0049] The technical scheme provided by the embodiment of the present application has at least the following beneficial effects:
[0050] By dynamically monitoring network node data, refining risk factor parameter extraction and attribution range division, precise analysis of multiple parameters such as traffic anomaly rate, port state fluctuation, access frequency and intrusion alarm can be realized, the differentiated distribution proportion between parameter values and risk level intervals can be determined, the influence and weight relationship of parameter distribution proportion on risk level are analyzed, the statistical analysis of multi-risk factor interaction characteristics is introduced, a multi-dimensional interaction risk distribution model is formed, the correlation between risk factors and their action range can be more comprehensively revealed, a risk factor group with significant characteristics is screened, the pertinence and scientificity of risk identification are improved, in the time dimension, the key risk feature data set of network security is further classified and refined by analyzing the change frequency and distribution concentration of the group parameters, thereby enhancing the real-time monitoring capability of dynamic changes of risks, combining the offset amplitude and action range evaluation of key risk factors, the security situation changes under complex threats, the accuracy, comprehensiveness and dynamic adaptability of risk assessment are greatly improved, the network security risk assessment is changed from static analysis to dynamic, multi-dimensional real-time response mode, and the efficiency and reliability of coping with complex network security threats are effectively improved. BRIEF DESCRIPTION OF DRAWINGS
[0051] Figure 1 A network security risk assessment method based on fuzzy mathematics provided by the embodiment of the present application is shown in the flowchart;
[0052] Figure 2 An S1 refinement flowchart provided by the embodiment of the present application is shown in the flowchart;
[0053] Figure 3 An S2 refinement flowchart provided by the embodiment of the present application is shown in the flowchart;
[0054] Figure 4 An S3 refinement flowchart provided by the embodiment of the present application is shown in the flowchart;
[0055] Figure 5 An S4 refinement flowchart provided by the embodiment of the present application is shown in the flowchart;
[0056] Figure 6 S5 refinement flowchart provided for the embodiments of the present application;
[0057] Figure 7 Flowchart of the network security risk assessment system based on fuzzy mathematics provided for the embodiments of the present application;
[0058] Figure 8 Electronic device diagram of the network security risk assessment based on fuzzy mathematics provided for the embodiments of the present application. DETAILED DESCRIPTION
[0059] The technical solutions in the present application will be described below with reference to the drawings.
[0060] In the embodiments of the present application, the words such as "example", "for example" are used to represent as an example, illustration or description. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "example" is intended to present the concept in a specific manner. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be one of the two.
[0061] In the embodiments of the present application, "image" and "picture" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized. "Of", "corresponding" and "corresponding" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized.
[0062] In the embodiments of the present application, sometimes the subscript such as W1 can be written in the form of non-subscript such as W1, and the meanings expressed are consistent when the distinction is not emphasized.
[0063] To make the technical problems, technical solutions and advantages to be solved by the present application clearer, specific embodiments will be described in detail below with reference to the drawings.
[0064] Please refer to Figure 1 The embodiments of the present application provide a network security risk assessment method based on fuzzy mathematics, and the processing flow of the method can include the following steps:
[0065] S1: Based on the dynamic monitoring data of the node data in the network environment, a plurality of risk factor parameters such as traffic anomaly rate, port state fluctuation, access frequency and intrusion alarm are extracted, the attribution range of the parameter value is divided, the numerical range of each parameter value and the risk level interval is compared, the distribution proportion of the parameter in the differentiated interval is counted, and a network risk factor membership distribution table is generated;
[0066] S2: Based on the network risk factor membership distribution table, the influence relationship of parameter distribution proportion on differentiated risk level is analyzed, the influence degree of distribution proportion difference on weight is analyzed, the influence range of multi-risk factor interaction characteristics is counted, the distribution and weight data are classified, and an interaction risk distribution model is generated;
[0067] S3: Based on the interaction risk distribution model, the correlation between weight value and distribution proportion in the interaction characteristics is analyzed, the cumulative value of multi-risk factor weight is called, the correlation of parameter group is evaluated, the influence range of associated parameters is determined, the risk factor group with prominent characteristics is screened, and a risk factor group mapping table is generated;
[0068] S4: Based on the risk factor group mapping table, the time dimension record of group data and parameter distribution range is called, the time change range of the group is counted, the concentration degree and change frequency of the distribution data are analyzed, the fluctuation law of the group parameters in the time dimension is analyzed, the parameter key characteristics are determined and classified as group characteristics, and a network security key risk feature data set is generated;
[0069] S5: Based on the network security key risk feature data set, the time dimension change record of the key risk factor is analyzed, the distribution offset value of the key risk factor and the distribution rule data in the original record are called, the amplitude and range of the distribution offset are evaluated, the offset range and strength data are counted, and a network key risk dynamic evaluation result is generated.
[0070] The network risk factor membership distribution table includes traffic anomaly rate distribution, port state fluctuation range, access frequency proportion, intrusion alarm statistical distribution, the interaction risk distribution model includes parameter distribution proportion relationship, weight difference influence factor, multi-risk factor interaction characteristic range, distribution and weight classification result, the risk factor group mapping table includes group associated parameters, key risk factor group, multi-risk factor cumulative weight, group interaction influence range, the network security key risk feature data set includes time dimension distribution record, parameter concentration change distribution, fluctuation change characteristics, group characteristic classification graph, and the network key risk dynamic evaluation result includes distribution offset amplitude record, offset range data, offset strength statistics, and key risk factor time change record.
[0071] In a feasible implementation manner, as shown in Figure 2 Based on the dynamic monitoring data of node data in the network environment, a plurality of risk factor parameters are extracted, parameter value ranges are divided, risk level intervals are compared, differentiated interval distribution proportions are counted, and the steps of generating a network risk factor membership distribution table are as follows:
[0072] S101: Based on the dynamic monitoring data of node data in the network environment, the traffic anomaly rate, port state fluctuation, access frequency and intrusion alarm parameters are gradually extracted, the original record distribution value is checked piece by piece, the error data is eliminated, the data range is divided according to the distribution trend, and the parameter value range division data set is obtained;
[0073] In the extraction of traffic anomaly rate, first, the abnormal fluctuation of a single node is extracted through the time series of traffic records, the reference value is set as the reference value of the baseline traffic mean value, the deviation of the traffic of each monitoring period is calculated, the anomaly rate of each period is calculated, the port state fluctuation is calculated by using the time window based on the node port state record data, the fluctuation amplitude value of each time period is calculated, the fluctuation times and fluctuation amplitude are obtained, and the records with amplitude change greater than the reference threshold value are extracted, the access frequency is calculated by analyzing the access request records between nodes in unit time, the average value of the access times is calculated, and the abnormal access value is marked, the intrusion alarm parameter extraction is cross-verified according to the source IP and type information of each record in the alarm log, the records not meeting the alarm rule are filtered out, the high-priority alarm events are retained, the data with value deviation or abnormality in the above extracted original records are checked piece by piece through the distribution curve fitting method, the record values with large deviation are eliminated, the check standard is that the deviation rate of the distribution fitting curve is less than 5%, the upper and lower boundary ranges are divided according to the normal distribution trend of the parameters, and the parameter value range division data set is generated, which lays a foundation for subsequent risk assessment analysis.
[0074] S102: Based on the parameter value range division data set, the current value of the parameter in the dynamic monitoring data is extracted, the difference amplitude of the risk interval segment value is analyzed, the difference amplitude is divided into attribution categories, the current value of the parameter is marked with attribution categories, and a parameter attribution interval distribution table is generated;
[0075] First, according to the risk interval delimited by its corresponding distribution range, the current value is classified and calculated, and by calculating the deviation amplitude between the current value and the upper and lower bounds of the risk interval, it is judged whether it belongs to the normal, safe or high-risk interval. The difference amplitude is divided according to the relative deviation formula of the current value and the interval median, and the deviation amplitude is defined as: less than 10% is normal, more than 30% is high risk, and between 10% and 30% is general risk. In the calculation process, the performance characteristics of each parameter in its belonging range are analyzed one by one, for example, the deviation of the abnormal rate of flow is confirmed by calculating the change amplitude of the real-time flow and the reference flow, the port state fluctuation is classified according to the deviation of the fluctuation value relative to the normal fluctuation amplitude range, the access frequency is classified by calculating the change degree of the current access frequency relative to the historical mean value, and the intrusion alarm parameter is classified by the deviation of the current alarm frequency and the historical alarm distribution. The belonging category of the current value of all parameters is recorded in the parameter belonging interval distribution table, and the table is arranged according to the category to provide data support for further evaluation of risk level and parameter distribution trend.
[0076] S103: Based on the parameter belonging interval distribution table, the distribution proportion of the parameter current value in the risk interval is counted, the interval segment proportion change is analyzed, the parameter distribution proportion correlation is arranged, and the network risk factor membership distribution table is generated;
[0077] According to the records in the parameter belonging interval distribution table, the number of all parameter current values in the high-risk, general-risk and normal interval is counted, and the potential risk state in the network is evaluated by calculating the proportion of different categories. The distribution proportion of each parameter is normalized by using the proportion calculation formula to obtain the trend value of the change of the proportion of each interval segment, for example, by calculating whether the proportion of the abnormal rate of flow in the high-risk interval increases compared with the last evaluation to analyze the intensification of potential flow abnormal behavior. For the distribution proportion of the port state fluctuation, by the ratio of the number of nodes with fluctuation value in the high-risk interval to the total number of nodes, it is judged whether there is a downward trend in the stability of the network. The distribution of access frequency is analyzed by the proportion change of the frequency abnormal value in the high-risk interval, and the potential access frequency abnormal trend is analyzed. The intrusion alarm parameter is evaluated according to the proportion of high-risk alarm records, and the severity of the alarm event and the potential intrusion risk are evaluated. The correlation of the distribution proportion of each parameter is arranged as the network risk factor membership distribution table, and the distribution trend and potential risk evaluation value of each factor are marked in the table to provide basis and support for subsequent network security risk evaluation.
[0078] In a feasible implementation manner, as shown in Figure 3 based on the network risk factor membership distribution table, the parameter distribution proportion influence is analyzed, the influence degree of the proportion difference on the weight is analyzed, the influence range of the interaction characteristics of multiple risk factors is counted, the distribution and weight data are classified, and the steps of generating the interaction risk distribution model are as follows:
[0079] S201: Extract the distribution proportion data of the parameters based on the network risk factor membership distribution table, analyze the relationship between the distribution proportion and the risk level, analyze the original record and the change range of the distribution proportion, classify the matching relationship between the distribution proportion and the risk level, and obtain the difference data between the distribution proportion and the risk level;
[0080] When extracting the distribution proportion data, first obtain the distribution proportion of each parameter through the network risk factor membership distribution table, and classify and count the proportion of the number of parameters in each risk level according to the risk level (normal, general risk, and high risk). When analyzing the relationship between the distribution proportion and the risk level, based on the risk level division threshold of different parameters, the difference in the distribution proportion in different risk level intervals is calculated, for example, by comparing the distribution proportion of the flow anomaly rate in the general risk and high risk intervals, the change trend of the risk level is analyzed. The analysis of the original record and the change range of the distribution proportion needs to compare the records in each time period vertically, determine the change range by difference calculation, and count the fluctuation degree of the distribution proportion of each parameter in each risk level. For classifying the matching relationship between the distribution proportion and the risk level, the distribution proportion of each parameter is matched to a specific risk level through matching rules, for example, if the distribution proportion of the flow anomaly rate exceeds the high risk threshold, it is classified into the high risk level. Combined with the corresponding relationship between the distribution proportion of all parameters and the risk level, the difference value is calculated to obtain the difference data between the distribution proportion and the risk level, which provides accurate data support for subsequent weight relationship analysis.
[0081] S202: Based on the difference data between the distribution proportion and the risk level, analyze the weight relationship between the distribution proportion and the risk level, compare the weight change trend of the parameter distribution proportion, sort and classify the weight data of the change range, and obtain the distribution proportion and weight influence data;
[0082] When analyzing the weight relationship between the distribution proportion and the risk level, different weight values are given to each level according to the influence degree of different risk levels on the overall network security. The weight change trend of the parameter distribution proportion needs to be compared by normalizing the change of the distribution proportion in different time periods. Taking time as the horizontal axis, the weight change curve of each parameter is drawn to observe its trend change. The weight values of each parameter in different risk levels are classified and counted, for example, whether the weight proportion of the port state fluctuation in the high risk level is significantly higher than that in other risk levels. The extreme value and the average value of the change range are recorded. Combined with the distribution proportion and weight relationship of all parameters, the distribution proportion and weight influence data are obtained as an important input basis for subsequent interaction condition analysis.
[0083] S203: Based on the distribution proportion and weight influence data, analyze the weight change relationship under the interaction condition, count the interaction influence coverage of multiple risk factors, classify the interaction weight and distribution characteristic data, integrate the interaction characteristic influence data, calculate the interaction risk distribution relationship weight, and construct the interaction risk distribution model;
[0084] The interaction risk distribution relationship weight is calculated according to the following formula (1):
[0085]
[0086] Wherein, E represents the interaction risk distribution relationship weight, P a represents the distribution proportion of risk factor A in the initial state, W a represents the weight parameter of risk factor A, P b represents the distribution proportion of risk factor B in the initial state, W b represents the weight parameter of risk factor B, Q c represents the interaction influence intensity of risk factor C, W c represents the weight parameter of risk factor C, P d represents the standardized distribution density of risk factor D.
[0087] The formula details and formula calculation derivation process are as follows:
[0088] The formula is used to calculate the risk distribution relationship weight under the interaction of multiple risk factors, and the result is used to establish the interaction risk distribution model;
[0089] P a is the distribution proportion of risk factor A in the initial state, which is set to 0.3, reflecting the initial proportion of risk factor A in the overall risk distribution;
[0090] W a is the weight parameter of risk factor A, which is set to 0.5, reflecting the weight ratio of the influence of risk factor A on the overall model;
[0091] P b is the distribution proportion of risk factor B in the initial state, which is set to 0.4, reflecting the initial proportion of risk factor B in the overall risk distribution;
[0092] W b is the weight parameter of risk factor B, which is set to 0.6, reflecting the weight ratio of the influence of risk factor B on the overall model;
[0093] Q c is the interaction influence intensity of risk factor C, which is set to 0.7, reflecting the specific influence intensity of risk factor C interacting with other factors;
[0094] Wc is a weight parameter of risk factor C, which is set to 0.8, reflecting the weight adjustment ratio of risk factor C in the interaction analysis;
[0095] P d is a standardized distribution density of risk factor D, which is set to 0.5, reflecting the standardized distribution intensity of risk factor D in the overall data;
[0096] Substitute the parameters into the formula to calculate E:
[0097] Calculate |P a W a -P b W b | : |0.3x0.5-0.4x0.6| = |0.15-0.24| = |-0.09| = 0.09;
[0098] Calculate
[0099] Calculate
[0100] Since Therefore:
[0101] Further calculation:
[0102] Add the above results: E = 0.3 + 0.792 = 1.092;
[0103] The result 1.092 indicates that under the condition of the set parameters, the risk distribution relationship weight under the interaction of multiple risk factors is 1.092. This result is used to establish an interaction risk distribution model, reflecting the degree of interaction between different risk factors.
[0104] In a feasible implementation manner, as shown in Figure 4 Based on the interaction risk distribution model, the correlation between the weight value and the distribution ratio is analyzed, the cumulative value of the multiple risk factor weight is called, the correlation of the parameter group is evaluated, the risk factor group with prominent characteristics is screened, and the steps of generating a risk factor group mapping table are as follows:
[0105] S301: Based on the interaction risk distribution model, the weight value and the distribution ratio of the risk factor are analyzed, the cumulative weight value is extracted, the correlation strength in the distribution is calculated, the risk factor is classified, and a parameter group matching set is established;
[0106] In the interactive risk distribution model, when analyzing the weight value and distribution proportion of each risk factor, first, the cumulative weight value of each risk factor in different risk levels is counted, and the total risk contribution is quantified by calculating the superposition of the weight values of different risk levels. For the distribution proportion, the weight contribution strength is calculated by combining the proportion of each factor in the interval segment. The calculation of the correlation strength is based on the synergistic effect of the cumulative weight value and the distribution proportion of different risk factors in the interaction interval, for example, the weight superposition relationship of the traffic anomaly rate and the port state fluctuation in the same interval, which is used to measure the correlation strength of the two. When classifying risk factors, factors with significant correlation strength are classified as high interaction risk factors, and the remaining factors are sorted by weight value and divided into general risk factors and low risk factors. Combined with the above classification results, according to the synergistic effect and distribution proportion characteristics between risk factors, the same type of factors are aggregated to establish a parameter group matching set, which provides basic data support for subsequent analysis of the internal correlation of risk factors.
[0107] S302: Based on the parameter group matching set, analyze the correlation parameters of risk factors in the group, extract the interaction factors, analyze the factor action range, and construct the characteristic key factor group;
[0108] In the parameter group matching set, when analyzing the correlation parameters of risk factors in each group, according to the matching relationship between the distribution proportion and the cumulative weight value, the correlation parameters with synergistic effect are selected, for example, between the access frequency anomaly and the intrusion alarm, the number of interaction nodes shared by the two and their weight contribution values are extracted to confirm the correlation strength. When extracting the interaction factors, the weight contribution proportion between different factors in the same group is calculated to select high correlation factors as interaction factors, which are marked as interaction factors. When analyzing the factor action range, the coverage range and the influence depth of the interaction factors in the network nodes are counted, for example, the number and proportion of nodes whose coverage range of high-risk weight of port state fluctuation overlap with the traffic anomaly rate. The interaction factors with significant action range and high correlation strength are aggregated, classified according to their characteristics, and recorded for subsequent analysis of their internal characteristics and correlation rules.
[0109] S303: Based on the characteristic key factor group, analyze the data characteristic distribution law in the group, map and process according to the distribution trend, adjust the interaction parameter value, integrate the correlation characteristics between factors, and generate a risk factor group mapping table;
[0110] When analyzing the data characteristic distribution law of each factor, based on the distribution proportion of the factor in each risk level, the distribution trend and fluctuation range are counted, when mapping according to the distribution trend, the cumulative weight value of the factor is projected onto the distribution trend curve by corresponding the distribution proportion and the risk level, when integrating the correlation characteristics between factors, the interaction weight contribution in the key factor group is calculated, the distribution characteristics are normalized to ensure the consistency of the correlation data between factors, according to all analysis results and adjusted interaction parameter values, a risk factor group mapping table is generated, the distribution law, interaction and risk level of each factor are marked, and further support for network security risk assessment is provided.
[0111] In a feasible implementation manner, as shown in Figure 5 Based on the risk factor group mapping table, the group data and time dimension record are called, the time variation range of the group is counted, the concentration degree and variation frequency of the distribution data are analyzed, the parameter fluctuation law is analyzed, the parameters are classified into group characteristics, and the steps of generating network security key risk characteristic data set are as follows:
[0112] S401: Based on the risk factor group mapping table, the parameter distribution range of the group data is extracted, the corresponding parameter value data in the time dimension record is screened, the parameter value variation amplitude in the time interval is compared, the variation frequency is analyzed and the distribution concentration degree is judged, and the group parameter time distribution data is obtained;
[0113] When extracting the parameter distribution range of each group, the parameter values are classified according to the high risk interval, the medium risk interval and the low risk interval recorded by the distribution proportion, and the upper and lower limit values of different intervals are marked, based on the record of time dimension, the numerical data of corresponding parameters in each time period is screened, the fluctuation amplitude of parameters in high frequency time period is counted by comparing the parameter value variation amplitude in time interval, the variation frequency is analyzed based on the fluctuation times of each parameter in unit time, the parameter distribution proportion of high fluctuation frequency interval is counted, the fluctuation frequency and the statistical results of distribution range are combined to judge the distribution concentration degree of parameter value in time dimension, the parameter value variation frequency and concentration degree of all time dimension records are summarized to obtain group parameter time distribution data, which provides a basis for subsequent time law analysis.
[0114] S402: Based on the group parameter time distribution data, the time dimension distribution data is analyzed, the parameter value fluctuation range is extracted, the variation amount in the time period is analyzed, the parameter time distribution law is judged, the periodic and persistent characteristic parameters are classified and arranged, and the key parameter classification characteristics are obtained;
[0115] First, according to the distribution proportion of each parameter in different time periods, the fluctuation range is calculated, for example, the fluctuation upper and lower limits of the abnormal rate of traffic flow in the night period are extracted, and the mean and range of the fluctuation range are recorded. The analysis of the change amount in the time period is based on the continuous record of different time periods. By calculating the increase and decrease of the parameter value in each time period, the change rate and direction are judged. For example, by analyzing the difference between the access frequency in the morning peak and the late night low peak, the significance of the change amount is judged. In judging the time distribution rule, the distribution concentration and change amplitude of the parameter in multiple time periods are used to classify and arrange the periodic and persistent characteristic parameters. All parameters are classified and arranged according to the time rule to clarify their periodicity and persistence characteristics. The characteristic parameters are extracted and labeled with their key risk levels to obtain the classification characteristics of key parameters, which provide data support for further feature arrangement and risk score calculation.
[0116] S403: Based on the classification characteristics of key parameters, integrate the distribution data of parameters in the classification characteristics, and combine the time rules of parameters to re-induce the characteristic values of parameters. According to the interaction characteristics of time dimension and classification data, arrange the group characteristics, calculate the key risk characteristic scores, and generate the network security key risk characteristic data set;
[0117] The key risk characteristic score R is calculated according to the following formula (2):
[0118]
[0119] Where, R represents the key risk characteristic score, T represents the sum of the absolute values of the key characteristic value set extracted from the time dimension trend data, P i represents the i-th principal component characteristic value in the classification characteristics, F represents the absolute deviation mean of the parameter distribution data, ΔS represents the change rate of the time series residual, w1 is the trend weight adjustment parameter, w2 is the classification principal component characteristic weight parameter, w3 is the deviation mean weight coefficient, and w4 is the residual change rate adjustment parameter;
[0120] Formula details and formula calculation derivation process:
[0121] The formula is used to calculate the network security key risk characteristic score R. This score is a comprehensive measure of network security risk characteristics, which is used to evaluate the size of potential risks in the network security environment. The formula considers multiple factors such as time dimension, classification principal component, distribution deviation, and time series residual change to comprehensively analyze the risk state of the network security environment;
[0122] T: represents the absolute value sum of the trend data set of the time dimension, reflecting the change trend of network security features in different time periods. The time trend data is quantitatively calculated by monitoring the changes of data flow, such as traffic fluctuations, attack activity occurrence time, etc. The time trend data uses daily, weekly or monthly data sets, and the relevant maximum change value and periodic characteristics need to be extracted when calculating;
[0123] By monitoring the network security data of a day, the absolute change value of daily network traffic fluctuation can be extracted, and the data set T = {15, 30, 25, 20} is obtained. The calculation is |T| = |15| + |30| + |25| + |20| = 90;
[0124] P i : represents the principal component characteristic value in the classification characteristics, which is used to reflect the network security key features (such as attack behavior pattern, traffic anomaly, etc.) under a certain category. The most important features are extracted from multi-dimensional characteristics by principal component analysis (PCA) method. Each P i corresponds to a principal component feature value. After PCA analysis, the weight of each principal component reflects its contribution to the overall risk. It is set that the principal component feature values obtained by PCA analysis are P1 = 20, P2 = 15, P3 = 10, and the total feature value of the first two principal components is selected for calculation, i.e. ∑P i = 20 + 15 = 35;
[0125] F: represents the absolute deviation mean of parameter distribution data, which is used to represent the deviation fluctuation of certain network security parameters (such as delay time, traffic size, etc.). The deviation mean is calculated by the difference between each sampling point data and its mean value, and the average deviation size is obtained. The deviation mean is calculated by absolute value method, which can measure the stability of some key parameters;
[0126] It is set that the parameter distribution data {10, 15, 20, 30} is found by monitoring the data, and the absolute deviation mean is calculated: |10-18| + |15-18| + |20-18| + |30-18| = 8 + 3 + 2 + 12 = 25;
[0127] deviation mean
[0128] ΔS: represents the rate of change of time series residuals, used to measure the fluctuation change of the unexplained part in the time series, through time series decomposition, the residual represents the part of the data that cannot be explained by the trend and seasonal pattern, and the residual rate of change measures the degree of change, a higher residual rate of change means higher instability of the system and greater potential risk, set the residual sequence calculated by time series decomposition as {-2, 1, 0, 3}, the residual rate of change ΔS can be quantified by calculating the absolute value of the difference between adjacent residuals, calculation: |ΔS| = |1-(-2)|+|0-1|+|3-0| = 3+1+3 = 7;
[0129] Weight parameter w1: adjust the influence weight of time trend characteristics on risk score, this parameter is determined by analysis of historical data, in a relatively stable environment, the value of w1 is smaller, indicating that the influence of time trend on the overall result is relatively weak; while in a larger fluctuation environment, the value of w1 is larger, indicating that the influence of time trend on network security risk is larger, set w1 = 0.8, to emphasize the influence of time trend data on network security risk assessment,
[0130] Weight parameter w2: adjust the influence weight of classification principal component on risk score, this parameter is set according to the contribution of principal component characteristics to the overall risk after PCA analysis, when the principal component characteristics dominate in the classification data, w2 will be larger, otherwise it will be smaller, set w2 = 0.5, indicating that the classification principal component has medium importance to the final risk assessment;
[0131] Weight parameter w3: adjust the influence of parameter distribution data deviation on risk assessment, data with larger deviation indicate potential risk, so the size of this weight coefficient will be set according to the stability of the distribution data, set w3 = 1.2, reflecting that larger deviation will have a greater impact on network security risk characteristics;
[0132] Weight parameter w4: adjust the influence of residual rate of change on risk assessment, the fluctuation of residual reflects the unpredictable change in the data, and such change is the source of potential risk, set w4 = 0.9, this value is larger when the residual rate of change has a significant impact on risk assessment;
[0133] Substitute the parameters into the formula to calculate:
[0134] Substitute the obtained numerical value into the formula to calculate:
[0135] First part:
[0136] Second part:
[0137] Final result: R = 0.037 + 0.374 = 0.411;
[0138] The calculation result R = 0.411 indicates that the risk score of network security is 0.411, which means that in the current network security environment, based on the comprehensive evaluation of time trend, classification principal component, parameter deviation and time series residual change, the overall risk level of the system is medium. This result reflects the potential risks of the system in terms of data volatility, trend change and abnormal situation, which needs further monitoring and improvement.
[0139] In a feasible implementation manner, as shown in Figure 6 Based on the network security key risk feature data set, the time variation record of the key risk factor is parsed, the distribution offset value and the original record are called, the offset amplitude and the action range are evaluated, the offset range and the action intensity data are counted, and the network key risk dynamic evaluation result is generated. The steps are as follows:
[0140] S501: Based on the network security key risk feature data set, the time dimension variation record of the key risk factor is extracted, the time interval distribution data is parsed, the distribution offset value in the change span is calculated, the distribution offset amplitude factor is screened, and the key risk factor distribution offset data is obtained;
[0141] When extracting the time dimension variation record of the key risk factor from the network security key risk feature data set, based on the risk level distribution proportion of each factor in different time periods, the distribution record is arranged in time order, when parsing the time interval distribution data, the distribution record in the time dimension is classified according to different risk levels, when calculating the distribution offset value in the change span, the difference between the maximum value and the minimum value in the distribution record is used as the offset value, when screening the distribution offset amplitude factor, the offset values are sorted according to the size, and the factors with significant offset values are marked as high offset factors. The time dimension distribution record and the corresponding offset value of the screened high offset amplitude factor are arranged as key risk factor distribution offset data, which provides support for the analysis of offset range and dynamic law.
[0142] S502: Based on the key risk factor distribution offset data, the original distribution law of the offset factor is extracted, the difference range of the offset value and the original distribution is analyzed, the offset amplitude is evaluated, the data in the offset range is extracted, and the action area characteristics are combined with the time dimension to obtain the key risk factor offset action range;
[0143] When extracting the original distribution law of the offset factor from the offset data of the key risk factor distribution, the original distribution proportion recorded according to the time dimension is used to count the basic distribution mean of each factor in each risk level. For example, when extracting the high-risk distribution mean of the access frequency abnormal factor in the normal period, marking the change trend of the distribution of each period, calculating the relative ratio of the offset value and the original mean, evaluating the offset amplitude, quantifying the significance of the offset amplitude according to the statistical results of the difference between the offset value and the original distribution, extracting the data in the offset range, recording the time period with significant offset value as the high-offset action area, and combining the time dimension to determine the action range, integrating the action area characteristic data, summarizing the time distribution and characteristic value of each factor in the offset range, forming the key risk factor offset action range, and evaluating its dynamic influence on the network security risk.
[0144] S503: Based on the key risk factor offset action range, the action strength of the key factor in the action range is counted, the change trend of the strength with time is analyzed, the dynamic law of the strength change is analyzed, the action range and the dynamic law characteristic data are integrated, and the network key risk dynamic evaluation result is generated;
[0145] When counting the action strength of the key factor in the key risk factor offset action range, the contribution value of each factor to the overall risk is calculated according to the cumulative distribution proportion and the offset value of each factor in the high-risk interval. When analyzing the change trend of the strength with time, the strength values of each key factor in the time dimension are plotted as a change curve, and the fluctuation amplitude and direction of each key factor in a specific time period are analyzed. When analyzing the dynamic law of the strength change, the frequency and trend of the action strength change are counted according to the fluctuation period and distribution characteristics of the factor, and the action strength and dynamic change law data in the action range are integrated to generate a data set containing time dimension distribution characteristics, strength change trend and dynamic law, forming a network key risk dynamic evaluation result, and providing a scientific basis for network security risk management.
[0146] As shown in Figure 7 , a network security risk assessment system based on fuzzy mathematics, the system comprises:
[0147] The risk factor dynamic monitoring module 310 is used for extracting the traffic anomaly rate, port state fluctuation, access frequency and intrusion alarm parameters based on the dynamic monitoring data of the node data in the network environment, comparing the risk level interval, analyzing the numerical proportion of the difference distribution, counting the distribution proportion, and generating a multi-parameter risk factor distribution proportion table.
[0148] The risk factor interval analysis module 320 is configured to analyze the distribution of the risk factors based on the multi-parameter risk factor distribution proportion table, compare the risk level intervals one by one, identify the influence proportion of the level intervals, integrate the risk level proportion and the weight difference data, and establish a risk factor correlation weight distribution table;
[0149] The interaction characteristic analysis module 330 is configured to analyze the weight and distribution proportion data based on the risk factor correlation weight distribution table, cross-compare the weight coverage range and the distribution proportion, screen the associated risk factor combinations, and generate a multi-risk factor interaction relationship model;
[0150] The risk factor time evolution module 340 is configured to, based on the multi-risk factor interaction relationship model, count the time variation range of the factor combinations, compare the distribution deviation and the fluctuation frequency in the time range, integrate the time evolution characteristic data, and establish a time-dimension risk factor evolution distribution table;
[0151] The key characteristic correlation evaluation module 350 is configured to, based on the time-dimension risk factor evolution distribution table, analyze the time distribution deviation value, count the fluctuation range, screen the change amplitude characteristic groups, and generate a network key risk dynamic evaluation result.
[0152] Optionally, the network risk factor membership distribution table includes a traffic anomaly rate distribution, a port state fluctuation range, an access frequency proportion, and an intrusion alarm statistical distribution.
[0153] The interaction risk distribution model includes a parameter distribution proportion relationship, a weight difference influence factor, a multi-risk factor interaction characteristic range, and a distribution and weight classification result.
[0154] The risk factor group mapping table includes a group correlation parameter, a key risk factor group, a multi-risk factor cumulative weight, and a group interaction influence range.
[0155] The network security key risk feature data set includes a time-dimension distribution record, a parameter centralized change distribution, a fluctuation change characteristic, and a group characteristic classification graph.
[0156] The network key risk dynamic evaluation result includes a distribution deviation amplitude record, a deviation action range data, a deviation intensity statistics, and a key risk factor time change record.
[0157] Optionally, the risk factor dynamic monitoring module 310 is configured to gradually extract the traffic anomaly rate, the port state fluctuation, the access frequency, and the intrusion alarm parameter based on the dynamic monitoring data of the node data in the network environment, check the original record distribution value piece by piece, eliminate the error data, divide the data range according to the distribution trend, and obtain a parameter value range division data set.
[0158] The data set is divided based on the parameter value range, the current value of the parameter in the dynamic monitoring data is extracted, the difference amplitude of the risk interval segment value is analyzed, the difference amplitude is divided into a belonging category, the current value of the parameter is labeled with the belonging category, and a parameter belonging interval distribution table is generated.
[0159] Based on the parameter belonging interval distribution table, the distribution proportion of the current value of the parameter in the risk interval is counted, the interval segment proportion change is analyzed, the classified parameter distribution proportion correlation is sorted out, and a network risk factor membership distribution table is generated.
[0160] Optionally, the risk factor interval analysis module 320 is configured to extract the distribution proportion data of the parameter based on the network risk factor membership distribution table, analyze the relationship between the distribution proportion and the risk level, analyze the original record and the change range of the distribution proportion, classify the matching relationship between the distribution proportion and the risk level, and obtain the difference data between the distribution proportion and the risk level.
[0161] Based on the difference data between the distribution proportion and the risk level, the weight relationship between the distribution proportion and the risk level is analyzed, the weight change trend of the parameter distribution proportion is compared, the weight data of the change range is sorted out, and the distribution proportion and the weight influence data are obtained.
[0162] Based on the distribution proportion and the weight influence data, the weight change relationship under the interaction condition is analyzed, the coverage range of the interaction influence of multiple risk factors is counted, the interaction weight and the distribution characteristic data are classified, the interaction characteristic influence data is integrated, the interaction risk distribution relationship weight is calculated, and an interaction risk distribution model is constructed.
[0163] Optionally, the interaction risk distribution relationship weight is calculated according to the following formula (1):
[0164]
[0165] Wherein, E represents the interaction risk distribution relationship weight, P a represents the distribution proportion of risk factor A in the initial state, W a represents the weight parameter of risk factor A, P b represents the distribution proportion of risk factor B in the initial state, W b represents the weight parameter of risk factor B, Q c represents the interaction influence intensity of risk factor C, W c represents the weight parameter of risk factor C, P d represents the standardized distribution density of risk factor D.
[0166] Optionally, the interaction characteristic analysis module 330 is configured to analyze the weight value and the distribution proportion of the risk factor based on the interaction risk distribution model, extract the cumulative weight value, calculate the correlation strength in the distribution, classify the risk factors, and establish a parameter group matching set.
[0167] Based on the parameter group matching set, the correlation parameters of the risk factors in the group are analyzed, the interaction factors are extracted, the action range of the factors is analyzed, and the characteristic key factor group is constructed;
[0168] Based on the characteristic key factor group, the distribution law of the data characteristics in the group is analyzed, the mapping processing is performed according to the distribution trend, the interaction parameter value is adjusted, the correlation characteristics between the factors are integrated, and the risk factor group mapping table is generated.
[0169] Optionally, the risk factor time evolution module 340 is configured to extract the group data parameter distribution range based on the risk factor group mapping table, filter the corresponding parameter value data in the time dimension record, compare the parameter value change amplitude in the time interval, analyze the change frequency and judge the distribution concentration degree, and obtain the group parameter time distribution data.
[0170] Based on the group parameter time distribution data, the time dimension distribution data is analyzed, the parameter value fluctuation range is extracted, the change amount in the time period is analyzed, the parameter time distribution law is judged, the periodic and persistent characteristic parameters are classified and arranged, and the key parameter classification characteristics are obtained.
[0171] Based on the key parameter classification characteristics, the distribution data of the parameters in the classification characteristics is integrated, the characteristic value of the parameter is re-inducted in combination with the time law of the parameter, the group characteristics are arranged according to the interaction characteristics of the time dimension and the classification data, the key risk feature score is calculated, and the network security key risk feature data set is generated.
[0172] Optionally, the key risk feature score is calculated according to the following formula (2):
[0173]
[0174] Wherein, R represents the key risk feature score, T represents the sum of the absolute values of the key characteristic value set extracted from the time dimension trend data, P i represents the i th principal component characteristic value in the classification characteristics, F represents the absolute mean deviation of the parameter distribution data, ΔS represents the change rate of the time series residual, w1 is the trend weight adjustment parameter, w2 is the classification principal component characteristic weight parameter, w3 is the mean deviation weight coefficient, and w4 is the residual change rate adjustment parameter.
[0175] Optionally, the key characteristic correlation evaluation module 350 is configured to extract the time dimension change record of the key risk factor based on the network security key risk feature data set, analyze the time interval distribution data, calculate the distribution offset value in the change span, filter the distribution offset amplitude factor, and obtain the key risk factor distribution offset data.
[0176] Based on the key risk factor distribution offset data, the original distribution law of the offset factor is extracted, the difference range of the offset value and the original distribution is analyzed, the offset amplitude is evaluated, the data in the offset range is extracted, the action region characteristics are integrated in combination with the time dimension, and the key risk factor offset action range is obtained;
[0177] Based on the key risk factor offset action range, the action strength of the key factor in the action range is counted, the strength change trend is analyzed, the strength change dynamic law is analyzed, the action range and the dynamic law characteristic data are integrated, and the network key risk dynamic evaluation result is generated.
[0178] As shown in Figure 8 The first processor 2001 in the embodiment of the application can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0179] It should also be understood that the memory in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0180] The above-described embodiments can be implemented in whole or in part by software, hardware (e.g., circuitry), firmware, or any combination thereof. When implemented in software, the above-described embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center through wired (e.g., infrared, wireless, microwave, etc.) or wireless means. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. containing one or more available medium collections. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. The semiconductor medium can be a solid state disk.
[0181] It should be understood that the term "and / or" herein merely describes an association relationship of associated objects, which means that there can be three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone, where A and B can be singular or plural. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects, but can also represent an "and / or" relationship, which can be understood in the context before and after.
[0182] In the present application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following" or the like means any combination of the items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.
[0183] It should be understood that in various embodiments of the present application, the size of the sequence number of the above-described processes does not mean the order of execution, and the execution order of the processes should be determined by their functions and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0184] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0185] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the devices, apparatuses and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.
[0186] In several embodiments provided by the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.
[0187] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A network security risk assessment method based on fuzzy mathematics, characterized in that, Includes the following steps: S1: Based on dynamic monitoring data of node data in the network environment, extract multiple risk factor parameters, divide parameter value ranges, compare risk level intervals, statistically analyze the distribution ratio of differential intervals, and generate a network risk factor membership distribution table. The specific steps for obtaining the network risk factor membership distribution table are as follows: S101: Based on dynamic monitoring data of node data in the network environment, gradually extract parameters such as traffic anomaly rate, port status fluctuation, access frequency and intrusion alarm, verify the distribution values of the original records one by one, remove erroneous data, divide the data range according to the distribution trend, and obtain the parameter value range division dataset. S102: Based on the parameter value range, divide the dataset, extract the current value of the parameter in the dynamic monitoring data, analyze the difference range of the risk interval values, divide the difference range into the category, label the current value of the parameter with the category, and generate a parameter belonging interval distribution table; S103: Based on the parameter affiliation interval distribution table, statistically analyze the distribution ratio of the current parameter value in the risk interval, analyze the change in the interval segment ratio, organize the correlation of the distribution ratio of the classification parameters, and generate a network risk factor affiliation distribution table. S2: Based on the network risk factor membership distribution table, analyze the influence of parameter distribution ratio, analyze the degree of influence of ratio difference on weight, statistically analyze the influence range of multi-risk factor interaction characteristics, classify distribution and weight data, and generate an interaction risk distribution model. S3: Based on the interactive risk distribution model, analyze the correlation between weight values and distribution ratios, call the cumulative value of multiple risk factor weights, evaluate the correlation effect of parameter groups, filter risk factor groups with prominent characteristics, and generate a risk factor group mapping table. S4: Based on the risk factor group mapping table, call the group data and time dimension records, count the time change range of the group, analyze the concentration and change frequency of the distribution data, analyze the parameter fluctuation pattern, classify it into group characteristics, and generate a dataset of key network security risk characteristics. S5: Based on the aforementioned network security key risk feature dataset, analyze the time change records of key risk factors, call the distribution offset values and original records, evaluate the offset magnitude and scope of effect, statistically analyze the offset range and intensity of effect data, and generate dynamic assessment results of network key risks.
2. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that, The network risk factor membership distribution table includes: traffic anomaly rate distribution, port status fluctuation range, access frequency ratio, and intrusion alarm statistical distribution. The interactive risk distribution model includes: the proportional relationship of parameter distribution, the influencing factors of weight differences, the range of interaction characteristics of multiple risk factors, and the distribution and weight classification results. The risk factor group mapping table includes: group association parameters, key risk factor groups, cumulative weights of multiple risk factors, and the scope of group interaction influence. The cybersecurity key risk feature dataset includes: time dimension distribution records, parameter set variation distribution, fluctuation variation features, and group feature classification map; The results of the dynamic assessment of key network risks include: distribution offset amplitude records, offset range data, offset intensity statistics, and time change records of key risk factors.
3. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that, In S2, based on the network risk factor membership distribution table, the influence of parameter distribution ratios is analyzed, the degree of influence of ratio differences on weights is analyzed, the influence range of multi-risk factor interaction characteristics is statistically analyzed, distribution and weight data are categorized, and an interaction risk distribution model is generated, including: S201: Based on the network risk factor membership distribution table, extract the distribution ratio data of the parameters, analyze the relationship between the distribution ratio and the risk level, analyze the original records and range of change of the distribution ratio, classify the matching relationship between the distribution ratio and the risk level, and obtain the difference data between the distribution ratio and the risk level. S202: Based on the distribution ratio and risk level difference data, analyze the relationship between the distribution ratio and risk level weights, compare the weight change trend of the parameter distribution ratio, organize the weight data of the classification change range, and obtain the distribution ratio and weight impact data. S203: Based on the distribution ratio and weight impact data, analyze the weight change relationship under interaction conditions, statistically analyze the coverage of the interaction impact of multiple risk factors, classify the interaction weight and distribution characteristic data, integrate the interaction characteristic impact data, calculate the interaction risk distribution relationship weight, and construct the interaction risk distribution model.
4. The network security risk assessment method based on fuzzy mathematics according to claim 3, characterized in that, The weights of the interactive risk distribution relationship are calculated according to the following formula (1): Where E represents the weight of the interactive risk distribution relationship, P a W represents the distribution proportion of risk factor A in the initial state. a P represents the weighting parameter of risk factor A. b W represents the distribution proportion of risk factor B in the initial state. b The weighting parameter Q represents risk factor B. c W represents the strength of the interaction effect of risk factor C. c P represents the weighting parameter of risk factor C. d The standardized distribution density represents the risk factor D.
5. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that, In S3, based on the interactive risk distribution model, the correlation between weight values and distribution proportions is analyzed, the cumulative value of multiple risk factor weights is called, the correlation effect of parameter groups is evaluated, risk factor groups with prominent characteristics are screened, and a risk factor group mapping table is generated, including: S301: Based on the interactive risk distribution model, analyze the weight values and distribution ratios of risk factors, extract the cumulative weight values, calculate the correlation strength in the distribution, classify risk factors, and establish a parameter group matching set; S302: Based on the parameter group matching set, analyze the correlation parameters of risk factors within the group, extract interaction factors, analyze the scope of factor influence, and construct a characteristic key factor group; S303: Based on the aforementioned key factor groups, analyze the distribution pattern of data characteristics within the groups, perform mapping processing according to the distribution trend, adjust the interaction parameter values, integrate the correlation characteristics between factors, and generate a risk factor group mapping table.
6. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that, In S4, based on the risk factor group mapping table, group data and time dimension records are called to statistically analyze the time variation range of the groups, analyze the concentration and frequency of change of the distribution data, analyze the fluctuation patterns of parameters, classify them into group characteristics, and generate a dataset of key cybersecurity risk characteristics, including: S401: Based on the risk factor group mapping table, extract the distribution range of group data parameters, filter the corresponding parameter value data in the time dimension records, compare the change range of parameter values within the time interval, analyze the change frequency and determine the degree of distribution concentration, and obtain the time distribution data of group parameters. S402: Based on the time distribution data of the group parameters, analyze the time dimension distribution data, extract the fluctuation range of parameter values, analyze the changes within the time period, determine the time distribution pattern of parameters, classify and organize periodic and continuous characteristic parameters, and obtain the classification characteristics of key parameters. S403: Based on the classification characteristics of the key parameters, integrate the distribution data of the parameters in the classification characteristics, re-summarize the characteristic values of the parameters in combination with the time pattern of the parameters, organize the group features according to the time dimension and the interaction characteristics of the classification data, calculate the key risk feature scores, and generate a network security key risk feature dataset.
7. The network security risk assessment method based on fuzzy mathematics according to claim 6, characterized in that, The key risk characteristic score is calculated according to the following formula (2): Where R represents the key risk feature score, T represents the sum of the absolute values of the set of key characteristic values extracted from the time-dimensional trend data, and P... i ΔS represents the characteristic value of the i-th principal component in the classification characteristics, F represents the mean absolute deviation of the parameter distribution data, ΔS represents the rate of change of the time series residuals, w1 is the trend weight adjustment parameter, w2 is the weight parameter of the classification principal component characteristics, w3 is the weight coefficient of the mean deviation, and w4 is the residual change rate adjustment parameter.
8. The network security risk assessment method based on fuzzy mathematics according to claim 1, characterized in that, In S5, based on the aforementioned cybersecurity key risk characteristic dataset, the time change records of key risk factors are parsed, distribution offset values and original records are retrieved, the offset magnitude and scope of influence are evaluated, the offset range and intensity data are statistically analyzed, and dynamic assessment results of cybersecurity key risks are generated, including: S501: Based on the aforementioned cybersecurity key risk feature dataset, extract the time dimension change records of key risk factors, parse the time interval distribution data, calculate the distribution offset value within the change span, filter the distribution offset magnitude factor, and obtain the key risk factor distribution offset data. S502: Based on the key risk factor distribution offset data, extract the original distribution pattern of the offset factors, analyze the difference range between the offset value and the original distribution, evaluate the offset magnitude, extract the data within the offset range, and combine the characteristics of the area of effect with the time dimension to obtain the area of effect of the key risk factor offset. S503: Based on the range of influence of the key risk factors, statistically analyze the intensity of the key factors within the range of influence, analyze the trend of intensity change over time, analyze the dynamic law of intensity change, integrate the data of the range of influence and the characteristics of dynamic law, and generate the dynamic assessment results of network key risks.
9. A network security risk assessment system based on fuzzy mathematics, characterized in that, According to any one of claims 1-8, the network security risk assessment method based on fuzzy mathematics, the system comprises: The risk factor dynamic monitoring module is used to dynamically monitor data based on node data in the network environment, extract parameters such as traffic anomaly rate, port status fluctuation, access frequency and intrusion alarm, compare risk level ranges, analyze the numerical proportion of differences in distribution, statistically analyze the distribution ratio, and generate a multi-parameter risk factor distribution ratio table. The risk factor interval analysis module is used to analyze the distribution pattern of risk factors based on the multi-parameter risk factor distribution ratio table, compare risk level intervals item by item, identify the influence ratio of level intervals, integrate risk level ratio and weight difference data, and establish a risk factor correlation weight distribution table. The interaction characteristic analysis module is used to analyze the weight and distribution ratio data based on the risk factor association weight distribution table, cross-compare the weight coverage and distribution ratio, screen the combination of related risk factors, and generate a multi-risk factor interaction relationship model. The risk factor time evolution module is used to statistically analyze the time variation range of factor combinations based on the multi-risk factor interaction relationship model, compare the distribution offset and fluctuation frequency within the time range, integrate time evolution characteristic data, and establish a time-dimensional risk factor evolution distribution table. The key characteristic correlation assessment module is used to analyze the time distribution offset value, count the fluctuation range, filter the change amplitude characteristic groups, and generate the dynamic assessment result of network key risks based on the time dimension risk factor evolution distribution table.
Citation Information
Patent Citations
Vulnerability management method and system based on network assets
CN117614744A
Foundation pit supporting performance evaluation method and system based on data analysis
CN118133672A