Network security monitoring method and system based on dynamic vulnerability verification
Through real-time monitoring and dynamic verification of vulnerability exploit status, the problem of resource allocation imbalance in network security monitoring is solved, and more efficient security response and verification process are achieved, which improves the flexibility and reliability of network security.
Patent Information
- Application Number
- CN202510872751.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-06-27
AI Technical Summary
The existing network security monitoring technology lacks real-time dynamic verification of the true exploitability of vulnerabilities, resulting in an imbalance in the allocation of security resources and making it difficult to effectively respond to actual threats.
By collecting real-time network security monitoring data, identifying abnormal operation events, using Brownian motion trajectory modeling to extract thermal noise entropy values, generating dynamic random seeds, mapping target execution body sequence numbers, building isolated container instances, running security verification scripts, determining the exploitable status of vulnerabilities based on the consistency decision mechanism, and generating an audit log covering the entire process.
The dynamic and non-deterministic vulnerability verification process is realized, the randomness and robustness of the verification process is enhanced, the evasion resistance and security are improved in complex network environments, and the flexible response ability of heterogeneous executor scheduling strategies is improved.
Smart Images

Figure CN120389908A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technologies, and particularly to a network security monitoring method and system based on dynamic vulnerability verification. Background Art
[0002] With the wide deployment of information infrastructure and the rapid development of Internet technologies, network security risks have shown a trend of being concealed, intelligent, and continuous. Traditional network security protection means, such as intrusion detection systems (IDS) based on signature matching, vulnerability scanning systems (VSS), and security information and event management platforms (SIEM), have become standard configurations for organizations to achieve security protection. These methods mostly rely on attack signature libraries or historical vulnerability information for security situation analysis and alerting. When detecting potential threats, they usually adopt a static rule matching mechanism to identify abnormal behaviors or suspicious communication behaviors.
[0003] In the existing network security monitoring mechanism, the exploitation status of vulnerabilities is usually determined based on static analysis or manual audit results, lacking dynamic association with behaviors in the actual operating environment. This judgment method based on "speculative risks" often fails to reflect whether a vulnerability is truly exploitable in a specific context, thus easily leading to an imbalance in the allocation of security resources, that is, excessive protection measures are invested in non-exploitable vulnerabilities, while the response to vulnerabilities with actual exploitation channels is lagged. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a network security monitoring method based on dynamic vulnerability verification to solve the problem in the existing network security monitoring technology that there is a lack of real-time dynamic verification of the true exploitability of vulnerabilities.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides a network security monitoring method based on dynamic vulnerability verification, which includes collecting real-time network security monitoring raw data, detecting abnormal operations through predefined attack behavior rules, identifying potential abnormal operation events, triggering an alarm logic and generating suspicious event alarm data; according to the suspicious event alarm data, collecting a thermal noise signal as a physical entropy source, and calculating the fluctuation parameters of the time series of the Brownian motion trajectory through a Brownian motion trajectory modeling method, and extracting the thermal noise entropy value; performing a hash process on the thermal noise entropy value to generate a dynamic random seed, and based on the dynamic random seed and a preset heterogeneous executor mapping strategy rule, performing a mapping rule calculation to obtain a target executor number; according to the target executor number, constructing an isolated container instance through a container management interface at an edge node, and inputting a list of vulnerability numbers into the scheduling mechanism of the isolated container instance for screening to obtain a security verification script; running the security verification script through heterogeneous executors in the isolated container instance, and based on a determination threshold in a preset consistency decision mechanism, determining the comprehensive credibility score to generate a vulnerability exploitable status; performing blocking and warning operations on the vulnerability exploitable status to form a preliminary security disposal record, and summarizing the preliminary security disposal record and the disposal action and verification process information in the verification result set to generate an audit log covering the whole process.
[0008] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification according to the present invention, wherein: the specific steps of generating the suspicious event alarm data are as follows.
[0009] Collect real-time network communication traffic, host logs and user behavior information, generate real-time network security monitoring raw data, and perform format normalization processing to generate a structured monitoring feature data set.
[0010] Match the structured monitoring feature data set with predefined attack behavior rules, identify potential abnormal operation events, trigger an alarm logic and generate suspicious event alarm data.
[0011] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification according to the present invention, wherein: the specific steps of extracting the thermal noise entropy value are as follows.
[0012] According to the suspicious event alarm data, activate the physical entropy source chip of the target terminal and collect the thermal noise signal.
[0013] Perform filtering and noise reduction processing on the thermal noise signal, and use a random walk modeling method to convert the filtered and noise-reduced thermal noise signal into a time series of Brownian motion trajectories.
[0014] Through the Brownian motion trajectory modeling method, calculate the fluctuation parameters of the time series of the Brownian motion trajectory and extract the thermal noise entropy value.
[0015] As a preferred solution of the network security monitoring method based on vulnerability dynamic verification according to the present invention, wherein: the steps of obtaining the target execution body number are as follows,
[0016] Calculate the thermal noise entropy value using a hash function to generate an initial hash value, and perform a secondary perturbation process to obtain a dynamic random seed;
[0017] According to the dynamic random seed, combined with the preset heterogeneous execution body mapping strategy rules, use the weighted round-robin scheduling algorithm to calculate the mapping rules and obtain the target execution body number.
[0018] As a preferred solution of the network security monitoring method based on vulnerability dynamic verification according to the present invention, wherein: the steps of obtaining the security verification script are as follows,
[0019] Use a feature extraction algorithm to extract vulnerability feature parameters from suspicious event alarm data;
[0020] Match the corresponding vulnerability numbers in the vulnerability number database through the vulnerability feature parameters to generate a vulnerability number list;
[0021] According to the target execution body number, construct an isolated container instance through the container management interface at the edge node;
[0022] Input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the corresponding security verification script.
[0023] As a preferred solution of the network security monitoring method based on vulnerability dynamic verification according to the present invention, wherein: the steps of generating the vulnerability exploitable state are as follows,
[0024] Distribute the security verification script to multiple heterogeneous execution bodies in the isolated container instance, and run the security verification script respectively to generate verification result data, and summarize the verification result data of multiple heterogeneous execution bodies to form a verification result set;
[0025] Based on the statistical characteristics of the verification result set, set the judgment threshold, voting rules and anomaly detection methods through threshold setting, voting mechanism design and anomaly detection methods to form a consistency decision-making mechanism;
[0026] According to the voting rules and anomaly rejection strategies in the consistency decision-making mechanism, perform weighted statistics and result fusion on the verification result set to obtain a comprehensive credibility score;
[0027] Based on the judgment threshold in the consistency decision-making mechanism, judge the comprehensive credibility score to generate the vulnerability exploitable state.
[0028] As a preferred solution of the network security monitoring method based on vulnerability dynamic verification according to the present invention, wherein: the generation of audit logs covering the whole process is specifically carried out as follows.
[0029] Taking the exploitable state of the vulnerability as input, matching the predefined security policy rule library, identifying the corresponding blocking and warning operation instructions, and forming a preliminary security disposal record.
[0030] Summarizing the preliminary security disposal records and the disposal action and verification process information in the verification result set to generate audit logs covering the whole process.
[0031] In a second aspect, the present invention provides a network security monitoring system based on vulnerability dynamic verification, including a real-time monitoring module, an entropy value extraction module, a seed generation module, a container construction module, a verification execution module, and a security disposal module; the real-time monitoring module is used to collect raw data of real-time network security monitoring, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger an alarm logic and generate suspicious event alarm data; the entropy value extraction module is used to collect a thermal noise signal as a physical entropy source according to the suspicious event alarm data, and calculate the fluctuation parameters of the time series of the Brownian motion trajectory by means of a Brownian motion trajectory modeling method to extract the thermal noise entropy value; the seed generation module is used to perform a hash process on the thermal noise entropy value to generate a dynamic random seed, and perform mapping rule calculation based on the dynamic random seed and the preset heterogeneous executor mapping strategy rule to obtain the target executor number; the container construction module is used to, according to the target executor number, construct an isolated container instance at the edge node through a container management interface, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain a security verification script; the verification execution module is used to run the security verification script through heterogeneous executors in the isolated container instance, and determine the comprehensive credibility score based on the determination threshold in the preset consistency decision mechanism to generate the exploitable state of the vulnerability; the security disposal module is used to perform blocking and warning operations on the exploitable state of the vulnerability to form a preliminary security disposal record, and summarize the preliminary security disposal record and the disposal action and verification process information in the verification result set to generate audit logs covering the whole process.
[0032] In a third aspect, the present invention provides a computer device, including a memory and a processor, wherein: when the computer program is executed by the processor, any step of the network security monitoring method based on vulnerability dynamic verification as described in the first aspect of the present invention is implemented.
[0033] Fourthly, the present invention provides a computer-readable storage medium, on which a computer program is stored, wherein: when the computer program is executed by a processor, any step of the network security monitoring method based on vulnerability dynamic verification described in the first aspect of the present invention is implemented.
[0034] The beneficial effects of the present invention are as follows: By generating a dynamic random seed based on the thermal noise entropy value and combining it with the weighted round-robin scheduling algorithm to map the target execution body, the dynamic and non-deterministic resource allocation in the vulnerability verification process is realized, avoiding the attack prediction risk brought by the fixed execution path. The randomness and robustness of the verification process are enhanced, effectively improving the anti-evasion ability and security in complex network environments, further ensuring the comprehensiveness and concealment of vulnerability verification, and enhancing the flexible response ability and scheduling efficiency of the heterogeneous execution body scheduling strategy in a changing task environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0036] Figure 1 It is a flowchart of the network security monitoring method based on vulnerability dynamic verification in the present invention.
[0037] Figure 2 It is a schematic diagram of the network security monitoring system based on vulnerability dynamic verification in the present invention.
[0038] Figure 3 It is a flowchart of the thermal noise entropy value extraction in the present invention.
[0039] Figure 4 It is a flowchart of the generation of the exploitable state of the vulnerability in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific embodiments of the present invention in conjunction with the drawings of the specification.
[0041] Many specific details are set forth in the following description in order to provide a thorough understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0042] Second, the "one embodiment" or "embodiment" referred to herein means a specific feature, structure, or characteristic that may be included in at least one implementation manner of the present invention. The phrase "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that excludes other embodiments.
[0043] Referring to Figures 1 to 4 , which is an embodiment of the present invention. This embodiment provides a file encryption method, including the following steps:
[0044] S1. Collect raw data of real-time network security monitoring, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger the alarm logic, and generate suspicious event alarm data.
[0045] S1.1. Collect real-time network communication traffic, host logs, and user behavior information, generate raw data of real-time network security monitoring, and perform format normalization processing to generate a structured monitoring feature dataset.
[0046] Specifically, collect real-time network communication traffic data, including network packet header information and transmission content, collect host log data, covering operation events, process activities, and error records, collect user behavior information, such as login and logout records and operation instruction sequences; parse and clean according to a unified data format, remove invalid fields and outliers; perform format normalization processing on the cleaned raw data of real-time network security monitoring according to a preset field mapping rule, and convert it into a standardized raw data structure of real-time network security monitoring; extract features from the raw data of real-time network security monitoring after format normalization to generate a structured monitoring feature dataset, including traffic features, log features, and behavior features, etc.
[0047] S1.2. Match the structured monitoring feature dataset with the predefined attack behavior rules, identify potential abnormal operation events, trigger the alarm logic, and generate suspicious event alarm data.
[0048] Specifically, relevant features are extracted one by one from each feature sample data in the structured monitoring feature dataset, and then compared item by item with each matching condition in the predefined attack behavior rules. The specific comparison process is as follows: for each feature sample data in the structured monitoring feature dataset, the network protocol field, host log field, and user operation field are extracted; they are respectively compared with the network protocol anomaly matching conditions, host behavior anomaly matching conditions, and user operation anomaly matching conditions defined in the attack behavior rule library; when the network protocol field exceeds the protocol anomaly threshold statistically obtained based on historical normal communication behaviors, the host log field conforms to the behavior anomaly pattern, or the user operation field hits the abnormal instruction sequence, the feature sample is marked as an abnormal operation event, and the abnormal event identification data is output. For the identified abnormal operation events, the abnormal alarm processing logic is further called to generate suspicious event alarm data including the abnormal event type, trigger time, target host identification, and suspected user identification.
[0049] It should also be noted that the predefined attack behavior rules include the establishment and maintenance of the rule library. According to known attack features and security threat intelligence, rule templates are formulated, covering abnormal network traffic patterns, malicious instruction sequences, privilege abnormal operations, etc.; then matching conditions, matching thresholds, trigger thresholds, and priorities are set for each rule in the rule library. Among them, the matching conditions are defined based on the characteristic fields of typical attack behaviors, including specific protocol types, abnormal characteristics of packet structures, or operation behavior patterns; the matching thresholds set critical values according to the statistical distribution of historical normal behavior data, such as the frequency range of field values or the similarity threshold of operation sequences; the trigger thresholds are set according to the security event response strategy, generally depending on the continuous hit times or the upper limit of the hit probability; the priorities are set by grading according to the harm level, propagation speed, and historical trigger frequency of the rules associated with vulnerabilities. And the rule library is updated and optimized regularly to adapt to new types of attacks; during the application process of the rule library, the structured monitoring feature dataset is compared item by item with the matching conditions of each rule in the rule library, and whether to trigger an abnormal event is judged based on the matching degree and the matching threshold, so as to achieve the accurate identification of potential attack behaviors.
[0050] S2. Collect the thermal noise signal as the physical entropy source according to the suspicious event alarm data, and calculate the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method to extract the thermal noise entropy value.
[0051] S2.1. Activate the physical entropy source chip of the target terminal according to the suspicious event alarm data to collect the thermal noise signal.
[0052] Specifically, extract the target terminal identification parameter from the suspicious event alert data and parse the physical address information of the target terminal; subsequently, send a remote activation instruction to the control interface of the physical entropy source chip of the target terminal to start the physical entropy source chip to enter the working state; the physical entropy source chip continuously collects the thermal noise voltage signal generated by the internal thermosensitive element in the activated state, and the sampling frequency and sampling duration are set according to the event level parameter included in the suspicious event alert data. For example, when the event level parameter is high, the sampling frequency is 10 kHz and the sampling duration is 5 seconds; after the collection is completed, buffer and store the thermal noise voltage signal in the form of a time series, and output the thermal noise signal for subsequent processing.
[0053] S2.2. Perform filtering and noise reduction processing on the thermal noise signal, and use the random walk modeling method to convert the filtered and noise-reduced thermal noise signal into a Brownian motion trajectory time series.
[0054] Specifically, use the band-pass filtering method to perform preliminary filtering on the thermal noise signal data, and set the filter passband range to 100 Hz to 10 kHz to remove the low-frequency drift component and high-frequency spike interference; subsequently, use the wavelet denoising method to perform refinement processing on the filtered thermal noise signal data, select the Daubechies wavelet basis function and set the decomposition level to three layers, and perform signal decomposition, threshold denoising, and reconstruction operations to obtain the noise-reduced thermal noise signal data. Then, use the random walk modeling method to perform the conversion with the noise-reduced thermal noise signal data as the input. Specifically: set the initial position to zero, regard the thermal noise voltage value corresponding to each time step as the current position increment, and accumulate them in sequence according to the time series order to construct a Brownian motion trajectory time series.
[0055] It should also be noted that the specific steps for performing signal decomposition, threshold denoising, and reconstruction operations are as follows: perform wavelet decomposition on the thermal noise signal data after band-pass filtering, select the Daubechies wavelet basis function, and split the signal into approximation coefficients and detail coefficients at multiple scales according to the set three-layer decomposition level; perform denoising processing on the detail coefficients of each layer according to the denoising rules, set the low-amplitude coefficients to zero or reduce them to suppress the high-frequency noise components; synthesize the processed approximation coefficients and the denoised detail coefficients into a time-domain signal through the wavelet reconstruction method, and output it as the noise-reduced thermal noise signal data.
[0056] S2.3. Calculate the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method, and extract the thermal noise entropy value.
[0057] Specifically, perform a difference operation on the time series of the Brownian motion trajectory at equal interval time steps to obtain the amplitude change values between adjacent time points, and obtain the difference amplitude sequence; use the arithmetic mean formula and the unbiased sample standard deviation calculation formula in statistical analysis methods to calculate the mean and standard deviation of the difference amplitude sequence respectively, and construct the fluctuation amplitude distribution sequence; then perform sliding window segmentation statistics based on each segment of the fluctuation amplitude sequence, and use the sliding window variance estimation method to calculate the variance of the difference values within each sliding window of a fixed length to obtain the variance value reflecting the change of local fluctuation intensity; subsequently, normalize the variance value sequence to form a probability distribution function; according to the probability distribution function, calculate the thermal noise entropy value, and the expression is:
[0058] ;
[0059] Among them, represents the thermal noise entropy value, represents the probability of the thermal noise amplitude level appearing in the time series of the Brownian motion trajectory, represents the logarithm value of represents the thermal noise amplitude level.
[0060] S3. Generate a dynamic random seed by performing a hash process on the thermal noise entropy value, and perform mapping rule calculation based on the dynamic random seed and the preset heterogeneous executor mapping strategy rules to obtain the target executor number.
[0061] S3.1. Calculate the thermal noise entropy value using a hash function to generate an initial hash value, and perform a secondary perturbation process to obtain the dynamic random seed.
[0062] Specifically, perform numerical normalization on the thermal noise entropy value and convert it into a binary representation of a fixed length; subsequently, use an existing hash function, such as the SHA-256 hash function, to perform a one-time hash operation on the binary representation to generate an initial hash value; then, use the initial hash value as the input, concatenate and encode it with the current timestamp parameter and the event level parameter to generate a perturbation input string; and then perform a second hash operation on the perturbation input string, and output the perturbed hash result as the dynamic random seed.
[0063] S3.2. According to the dynamic random seed, combine the preset heterogeneous executor mapping strategy rules, and use the weighted round-robin scheduling algorithm to perform mapping rule calculation to obtain the target executor number.
[0064] Specifically, analyze the preset heterogeneous executor mapping policy rules in the task scheduling configuration. The heterogeneous executors include three types: edge nodes, fog computing nodes, and cloud computing nodes, which come from the edge device cluster, local intermediate computing nodes, and remote cloud resource pool in the IoT hierarchical architecture respectively; extract the performance weight parameters and current load status parameters corresponding to each heterogeneous executor. The performance weight parameters are constant values predefined according to static indicators such as hardware processing capabilities, network bandwidth, and response latency, and the current load status parameters are calculated based on the task queue length and average task processing latency collected in real time; then use the weighted round-robin scheduling algorithm, with the dynamic random seed as the initial offset, traverse all heterogeneous executors in order, combine and calculate the performance weight parameters and current load status parameters of each executor to generate the corresponding weighted score value, and construct a scheduling candidate sequence; finally, according to the scheduling candidate sequence and the modulo calculation result of the dynamic random seed, determine the corresponding target position, and then select the heterogeneous executor at the target position as the target executor number of the current task.
[0065] It should also be noted that the specific steps of the preset heterogeneous executor mapping policy rules: divide edge nodes, fog computing nodes, and cloud computing nodes according to the IoT architecture, and set performance weight parameters respectively; set the acquisition method and calculation rules of the load status parameters, such as the real-time monitoring method of the task queue length and processing latency; clarify the combined calculation formula and priority sorting rules of the weight parameters in the mapping policy; define the input parameter format required by the scheduling algorithm and the application method of the dynamic random seed; regularly update the mapping policy rules to reflect the performance changes and load dynamics of heterogeneous executors, and ensure the accuracy and timeliness of the mapping rules.
[0066] S4. According to the target executor number, construct an isolated container instance through the container management interface on the edge node, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script.
[0067] S4.1. Use the feature extraction algorithm to extract vulnerability feature parameters from the suspicious event alarm data.
[0068] Specifically, read the original field data containing vulnerability-related information from the suspicious event alarm data; then use the feature extraction algorithm to extract parameters such as vulnerability type, attack source address, attack timestamp, and attack payload characteristics in sequence according to the preset fields and formats of the vulnerability feature parameters; perform format conversion and normalization processing on the extracted parameters to ensure that the vulnerability feature data structure meets the requirements of subsequent analysis; encapsulate the processed vulnerability feature parameters in a predetermined format to form a structured set of vulnerability feature parameters, and complete the extraction of vulnerability feature parameters.
[0069] S4.2. Match the corresponding vulnerability numbers in the vulnerability number database based on the vulnerability feature parameters to generate a vulnerability number list.
[0070] Specifically, according to the key fields in the vulnerability feature parameters, such as vulnerability type, attack payload characteristics, and timestamp, access the vulnerability number database. The vulnerability number database is sourced from public vulnerability libraries and security vendor updated data. Compare the vulnerability feature parameters with the records in the vulnerability number database item by item according to the matching rules. During the comparison process, based on the preset field matching threshold, judge the consistency and similarity of the feature fields. If the preset matching conditions are met, extract the corresponding vulnerability number and record it. If the matching conditions are not met, mark the vulnerability feature parameters as "unrecognized status" and skip the current vulnerability number database record, then continue to match the next vulnerability number database information. Repeat the matching operation until all vulnerability feature parameter comparisons and queries are completed. Finally, summarize all successfully matched vulnerability numbers in order to generate a vulnerability number list.
[0071] It should also be noted that the specific steps for the preset field matching threshold: According to the type of key fields in the vulnerability number database, for enumerated type fields, use equality judgment; for text type fields, calculate the edit distance to judge similarity; for time type fields, compare whether the time difference is within the allowed range. Compare the judgment results with the field matching threshold. Those that meet the field matching threshold conditions are considered successfully matched, and those that do not are considered failed matches. Decide whether to extract the corresponding vulnerability number according to the matching results.
[0072] S4.3. Based on the target execution entity number, construct an isolated container instance at the edge node through the container management interface.
[0073] Specifically, according to the target execution entity number, send a construction request through the container management interface, select the container image version and running configuration parameters corresponding to the target execution entity number, such as 2 cores of CPU resources and 4GB of memory resources, to create an isolated container instance. After receiving the construction request, the container management interface calls the container engine to initialize the isolated container instance, including mounting the file system, allocating network resources, and configuring security policies. After the initialization is completed, start the isolated container instance and return the instance identifier and running status information to complete the construction process of the isolated container instance.
[0074] S4.4. Input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the corresponding security verification script.
[0075] Specifically, a list of vulnerability numbers is used as input, and a scheduling request is sent through the scheduling mechanism interface of the isolated container instance. The scheduling mechanism matches the vulnerability number list item by item with the corresponding security verification script identifier according to the pre-set vulnerability security verification script mapping rules. The vulnerability security verification script mapping rules are established based on historical vulnerability verification experience and the vulnerability type and applicable scope of the security verification script. The vulnerability security verification script mapping rules include the association between the vulnerability category and the corresponding verification script, the verification script priority and compatibility requirements;
[0076] The specific steps for screening security verification scripts are as follows: read each vulnerability number in the vulnerability number list, parse it one by one, and perform a one-to-one matching operation based on the correspondence between the vulnerability number and the security verification script identifier established in the locally deployed mapping database; for the records with successful matching, extract the corresponding security verification script identifier and summarize it to form a security verification script identifier; then, based on the security verification script identifier, load the corresponding script content from the locally maintained security verification script resource library, and finally generate a security verification script for vulnerability verification.
[0077] S5. Run the security verification script by isolating the heterogeneous executors in the container instance, and determine the comprehensive credibility score based on the judgment threshold in the preset consistency decision mechanism to generate the vulnerability exploitability status.
[0078] S5.1. Distribute the security verification script to multiple heterogeneous execution bodies within the isolated container instance, and run the security verification script separately to generate verification result data. The verification result data of multiple heterogeneous execution bodies are aggregated to form a verification result set.
[0079] Specifically, the security verification script to be distributed is sent to each heterogeneous executor in turn through the scheduling communication interface inside the isolated container instance; then the corresponding security verification script execution engine is called in each heterogeneous executor, the execution command is parsed according to the security verification script definition format, and the running process is started; during the running of the security verification script, the security verification script execution status, system response data, return information and abnormal log information are collected in real time to form the verification result data; after all heterogeneous executors complete the running of the security verification script, the internal scheduling mechanism of the isolated container instance will number and identify the verification result data corresponding to each heterogeneous executor, and output it to form the final verification result set.
[0080] S5.2. Based on the statistical characteristics of the verification result set, through threshold setting, voting mechanism design and anomaly detection method, the judgment threshold, voting rules and anomaly elimination strategy are set to form a consistent decision-making mechanism.
[0081] Specifically, based on the verification result set, the hit status value, response time value and error code value in each group of verification result data are extracted to form the statistical characteristics of the verification result set; based on the frequency distribution and security requirements of the hit status value in the verification result set, combined with empirical data and business scenarios, the judgment threshold is set, for example, setting a hit rate of more than 70% as a high confidence judgment threshold; then construct a voting rule, adopt a majority voting mechanism, and count the values with the largest proportion in the hit status value and output it as a collective judgment, for example, the majority voting rule is set to more than half, which means consensus; for the response time value and error code value, an anomaly detection method based on the box plot method is adopted to eliminate outlier data falling outside the upper and lower quartiles to form an anomaly rejection strategy; finally, the judgment threshold, voting rules and anomaly rejection strategy are integrated to construct a consistency decision-making mechanism for verification result set decision-making.
[0082] S5.3. Based on the voting rules and anomaly rejection strategy in the consistency decision-making mechanism, perform weighted statistics and result fusion on the verification result set to obtain a comprehensive credibility score.
[0083] Specifically, each set of verification result data in the verification result set is preliminarily screened according to the anomaly rejection strategy set in the consistency decision mechanism, and outliers falling outside the upper and lower quartiles of the response time value and the error code value are removed; according to the voting rules set in the consistency decision mechanism, the number of occurrences of each hit status value in the remaining verification results is counted, and the proportion of the hit status value is calculated as the basic weight, which is expressed as follows:
[0084] ;
[0085] in, Indicates the The proportion of class hit status values, Indicates the The number of times the class hit status value appears in the remaining verification results, Indicates the total number of hit status values in the remaining verification results. The index indicating the hit status;
[0086] The inverse of the response time value is used as the performance stability weight item, and the statistical results of each hit status value are weighted accordingly; the weighted statistical results are mapped to the [0,1] interval using the linear normalization method to form a preliminary credibility value; finally, the preliminary credibility value and the anomaly-free ratio of the error code value are weighted and fused, for example, superimposed at a ratio of 0.7 and 0.3 to obtain a comprehensive credibility score.
[0087] S5.4. Based on the determination threshold in the consistency decision mechanism, the comprehensive credibility score is determined to generate the vulnerability exploitability status.
[0088] Specifically, compare the comprehensive credibility score with the determination threshold. If the comprehensive credibility score is greater than or equal to the determination threshold, it is determined that the vulnerability is in an "exploitable" state. If the comprehensive credibility score is less than the determination threshold, it is determined that the vulnerability is in a "non-exploitable" state. For example, if the determination threshold is set to 0.8, when the comprehensive credibility score is 0.85, the vulnerability is determined to be in an "exploitable" state. If the comprehensive credibility score is 0.75, the vulnerability is determined to be in a "non-exploitable" state. Finally, generate the corresponding exploitable state of the vulnerability according to the determination result.
[0089] S6. Block and alarm the exploitable state of the vulnerability, form a preliminary security handling record, and summarize the handling actions and verification process information in the preliminary security handling record and the verification result set to generate an audit log covering the whole process.
[0090] S6.1. Use the exploitable state of the vulnerability as input, match the predefined security policy rule library, identify the corresponding block and alarm operation instructions, and form a preliminary security handling record.
[0091] Specifically, use the exploitable state of the vulnerability as input, read each rule item in the predefined security policy rule library, including the corresponding relationship between the exploitable state of the vulnerability and the block operation instruction and the alarm operation instruction. Compare the exploitable state of the vulnerability with the vulnerability state fields of all rule items in the predefined security policy rule library one by one, and filter out the rule items whose exploitable state fields are exactly the same as the current input. Extract the corresponding block operation instruction and alarm operation instruction from the successfully matched rule items. Combine the exploitable state of the vulnerability, the matched block operation instruction and the alarm operation instruction to generate a structured preliminary security handling record.
[0092] It should also be noted that the specific steps of the predefined security policy rule library are as follows: set the structural fields of the rule library, including at least the exploitable state field of the vulnerability, the block operation instruction field and the alarm operation instruction field. Based on the previous security incident response records, collect representative vulnerability exploitation scenarios, and classify and label each exploitable state of the vulnerability, such as marked as "high-risk exploitable", "medium-risk suspected exploitable" or "low-risk non-exploitable". For each type of exploitable state of the vulnerability, determine the corresponding content of the block operation instruction, such as "interrupt process", "block IP", "disable port", etc., and the content of the alarm operation instruction, such as "push email notification", "generate audit log" and "trigger audible and visual alarm", etc. Organize the content of the three types of fields in a one-to-one correspondence manner into rule items and store them in the predefined security policy rule library. Verify the constructed rule items to ensure that the content of the exploitable state field of the vulnerability is unique, and each item contains complete block operation instruction and alarm operation instruction fields.
[0093] S6.2. Summarize the disposal actions and verification process information in the preliminary security disposal records and the verification result set, and generate an audit log covering the entire process.
[0094] Specifically, adopt the multi-source heterogeneous data fusion and time series correlation analysis method to extract the timestamp, type, and execution result information of the disposal actions from the security disposal records. At the same time, extract the timestamp, steps, and corresponding result information of the verification process from the verification result set, and sort according to the timestamp to form unified time series data; based on the time series correlation analysis method, calculate the time dependence relationship and trigger order between the disposal actions and the verification process, and eliminate abnormal time series data; generate an audit log covering the entire process of vulnerability detection, verification, and disposal according to the preset log format for the fused time series data.
[0095] This embodiment also provides a network security monitoring system based on dynamic vulnerability verification, including: a real-time monitoring module, an entropy value extraction module, a seed generation module, a container construction module, a verification execution module, and a security disposal module; the real-time monitoring module is used to collect raw real-time network security monitoring data, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger the alarm logic and generate suspicious event alarm data; the entropy value extraction module is used to collect thermal noise signals as a physical entropy source according to the suspicious event alarm data, and calculate the fluctuation parameters of the time series of the Brownian motion trajectory through the Brownian motion trajectory modeling method to extract the thermal noise entropy value; the seed generation module is used to perform hash processing on the thermal noise entropy value to generate a dynamic random seed, and perform mapping rule calculation based on the dynamic random seed and the preset heterogeneous execution body mapping strategy rules to obtain the target execution body number; the container construction module is used to construct an isolated container instance at the edge node through the container management interface according to the target execution body number, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain a security verification script; the verification execution module is used to run the security verification script through the heterogeneous execution body in the isolated container instance, and judge the comprehensive credibility score based on the judgment threshold in the preset consistency decision mechanism to generate the exploitable state of the vulnerability; the security disposal module is used to perform blocking and warning operations on the exploitable state of the vulnerability, form preliminary security disposal records, and summarize the disposal actions and verification process information in the preliminary security disposal records and the verification result set to generate an audit log covering the entire process.
[0096] This embodiment also provides a computer device applicable to the situation of the network security monitoring method based on dynamic vulnerability verification, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the network security monitoring method based on dynamic vulnerability verification proposed in the above embodiment.
[0097] The computer device may be a terminal, which includes a processor, a memory, a communication interface, a display screen, and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or buttons, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0098] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the network security monitoring method based on vulnerability dynamic verification proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.
[0099] In summary, the present invention realizes the dynamic and non-deterministic resource allocation in the vulnerability verification process by generating a dynamic random seed based on the thermal noise entropy value and combining it with the weighted round-robin scheduling algorithm to map the target execution entity, avoiding the attack prediction risk brought by a fixed execution path. It enhances the randomness and robustness of the verification process, effectively improves the anti-evasion ability and security in a complex network environment, further ensures the comprehensiveness and concealment of vulnerability verification, and improves the flexible response ability and scheduling efficiency of the heterogeneous execution entity scheduling strategy in a changing task environment.
[0100] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. A network security monitoring method based on dynamic vulnerability verification, characterized in that: including Collecting real-time network security monitoring raw data, detecting abnormal operations through predefined attack behavior rules, identifying potential abnormal operation events, triggering alarm logic, and generating suspicious event alarm data; According to the suspicious event alarm data, collecting thermal noise signals as physical entropy sources, and calculating the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method to extract the thermal noise entropy value; Performing hash processing on the thermal noise entropy value to generate a dynamic random seed, and performing mapping rule calculation based on the dynamic random seed and the preset heterogeneous executor mapping strategy rules to obtain the target executor number; According to the target executor number, constructing an isolated container instance through the container management interface at the edge node, and inputting the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain a security verification script; Running the security verification script through the heterogeneous executor in the isolated container instance, and judging the comprehensive credibility score based on the decision threshold in the preset consistency decision mechanism to generate the exploitable status of the vulnerability; Performing blocking and warning operations on the exploitable status of the vulnerability to form a preliminary security disposal record, and summarizing the disposal actions and verification process information in the preliminary security disposal record and the verification result set to generate an audit log covering the whole process.
2. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for generating the suspicious event alarm data are as follows: Collecting real-time network communication traffic, host logs, and user behavior information, generating real-time network security monitoring raw data, and performing format normalization processing to generate a structured monitoring feature data set; Matching the structured monitoring feature data set with predefined attack behavior rules, identifying potential abnormal operation events, triggering alarm logic, and generating suspicious event alarm data.
3. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for extracting the thermal noise entropy value are as follows: According to the suspicious event alarm data, activating the physical entropy source chip of the target terminal to collect thermal noise signals; Performing filtering and noise reduction processing on the thermal noise signals, and using the random walk modeling method to convert the filtered and noise-reduced thermal noise signals into a Brownian motion trajectory time series; Calculating the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method, and extracting the thermal noise entropy value.
4. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for obtaining the target executor number are as follows: Calculating the thermal noise entropy value using a hash function to generate an initial hash value, and performing secondary perturbation processing to obtain a dynamic random seed; According to the dynamic random seed, combining the preset heterogeneous executor mapping strategy rules, and using the weighted round-robin scheduling algorithm to perform mapping rule calculation to obtain the target executor number.
5. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for obtaining the security verification script are as follows: Using a feature extraction algorithm to extract vulnerability feature parameters from the suspicious event alarm data; Matching the corresponding vulnerability numbers in the vulnerability number database through the vulnerability feature parameters to generate a vulnerability number list; According to the target executor number, constructing an isolated container instance through the container management interface at the edge node; Inputting the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the corresponding security verification script.
6. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for generating the exploitable status of the vulnerability are as follows: Distribute the security verification script to multiple heterogeneous executors within the isolated container instance, run the security verification script separately, generate verification result data, and summarize the verification result data of multiple heterogeneous executors to form a verification result set; Based on the statistical characteristics of the verification result set, set the decision threshold, voting rules, and anomaly rejection strategy through threshold setting, voting mechanism design, and anomaly detection methods to form a consistency decision-making mechanism; According to the voting rules and anomaly rejection strategy in the consistency decision-making mechanism, perform weighted statistics and result fusion on the verification result set to obtain a comprehensive credibility score; Based on the decision threshold in the consistency decision-making mechanism, judge the comprehensive credibility score to generate the exploitable status of the vulnerability.
7. The network security monitoring method based on dynamic vulnerability verification according to claim 1, wherein: The steps for generating the audit log covering the entire process are as follows: Use the exploitable status of the vulnerability as input, match the predefined security policy rule library, identify the corresponding blocking and warning operation instructions, and form preliminary security handling records; Summarize the preliminary security handling records and the handling actions and verification process information in the verification result set to generate an audit log covering the entire process.
8. A network security monitoring system based on dynamic vulnerability verification, based on the network security monitoring method based on dynamic vulnerability verification according to any one of claims 1 to 7, characterized in that: It includes a real-time monitoring module, an entropy value extraction module, a seed generation module, a container construction module, a verification execution module, and a security handling module; The real-time monitoring module is used to collect raw data of real-time network security monitoring, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger the alarm logic, and generate suspicious event alarm data; The entropy value extraction module is used to collect the thermal noise signal as the physical entropy source according to the suspicious event alarm data, and calculate the fluctuation parameters of the time series of the Brownian motion trajectory through the Brownian motion trajectory modeling method to extract the thermal noise entropy value; The seed generation module is used to perform hash processing on the thermal noise entropy value to generate a dynamic random seed, and perform mapping rule calculation based on the dynamic random seed and the preset heterogeneous executor mapping strategy rule to obtain the target executor number; The container construction module is used to construct an isolated container instance through the container management interface at the edge node according to the target executor number, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script; The verification execution module is used to run the security verification script through the heterogeneous executors within the isolated container instance, and judge the comprehensive credibility score based on the decision threshold in the preset consistency decision-making mechanism to generate the exploitable status of the vulnerability; The security handling module is used to perform blocking and warning operations on the exploitable status of the vulnerability to form preliminary security handling records, and summarize the preliminary security handling records and the handling actions and verification process information in the verification result set to generate an audit log covering the entire process.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the network security monitoring method based on dynamic vulnerability verification according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the network security monitoring method based on dynamic vulnerability verification according to any one of claims 1 to 7.
Citation Information
Patent Citations
Security monitoring alarm device and method for network security vulnerabilities
CN120074857A
Network security event vulnerability detection method and system
CN120090851A
Autonomous distributed cybersecurity testing
US20240291848A1