Computer network information management method based on big data
By drawing node distribution connection diagrams and calculating real-time defense coefficients, combining attack path length and transfer probability, the problem of insufficient global monitoring in traditional network security management methods is solved, timely discovery and accurate identification of network security threats is achieved, and the accuracy and efficiency of network security management is improved.
Patent Information
- Application Number
- CN202510547210.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-08-01
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional network security management methods lack global monitoring and dynamic management capabilities, making it difficult to comprehensively and accurately evaluate network security status and predict attack trends, and fail to promptly and effectively protect the network from attacks.
The computer network information management method based on big data, by drawing the node distribution connection graph, calculating the real-time defense coefficient of the node, determining whether the attack node is transferred, and combining the attack path length and transfer probability, accurately identifying the main attack nodes.
It realizes timely discovery and accurate identification of network security threats, provides effective preventive measures, and improves the accuracy and efficiency of network security management.
Smart Images

Figure CN120415818A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer information management, and in particular relates to a computer network information management method based on big data. Background Art
[0002] With the rapid development of computer networks, network scale continues to expand, network structures become increasingly complex, and the types and number of devices connected to the network increase dramatically, including various computers, servers, routers, switches, and a large number of IoT terminal devices. This complexity poses severe security challenges to networks, and the means and methods of network attacks are becoming increasingly diverse and covert, such as hacker attacks, virus infections, and malware intrusions.
[0003] Traditional network security management methods often focus on single-point defense, protecting only individual devices or local networks, and lack the ability to globally monitor and dynamically manage the entire network. Furthermore, relying on a single security indicator or rule makes it difficult to comprehensively and accurately assess the network's security status and predict attack trends. Attacks are typically detected only after they have occurred, lacking early awareness and prediction of attack path evolution. Risk scoring is based solely on single nodes, failing to fully consider inter-node connectivity and actual propagation paths, making it impossible to effectively and timely protect the network from attacks. Therefore, a computer network information management method based on big data is proposed. Summary of the Invention
[0004] The purpose of the present invention is to provide a computer network information management method based on big data, which solves the technical problems of relying on a single security indicator or rule, making it difficult to comprehensively and accurately assess the security status of the network and predict the development trend of attacks, and not fully considering the connection relationship between nodes and the actual transmission path, and being unable to timely and effectively protect the network from attacks.
[0005] A computer network information management method based on big data, comprising the following steps: Step 1: Obtain the location of each node in the computer network and draw a node distribution connection diagram of the generated computer network; Step 2: Mark the initial nodes according to the attacker's initial position. Obtain the real-time defense coefficient for each node based on its vulnerability exposure and attack frequency within a preset time period t. Determine whether the attacking node has shifted based on the real-time defense coefficient. The preset time period t is 1 hour. Step 3: When the attack node is transferred, the transfer probability corresponding to each remaining node is obtained, and the transfer node is determined according to the transfer probability; Step 4: When the transfer nodes are not unique, obtain the attack path lengths from the attack node to each transfer node. Based on the attack path lengths from the attack node to each transfer node and the transfer probabilities of the transfer nodes, determine the main attack node.
[0006] As a further solution of the present invention: The specific method for drawing the distribution connection diagram of computer network nodes is as follows: According to the position information of the nodes, draw a grid diagram of each node in the computer network. Take each node as the root node respectively, and at the same time connect the adjacent nodes corresponding to each root node respectively to generate the distribution connection diagram of the computer network nodes.
[0007] As a further solution of the present invention: The specific method for obtaining the real-time defense coefficient corresponding to each node is as follows: Obtain the mean Ap and standard deviation U of the real-time defense coefficients of all nodes. Take the sum of the mean Ap and three times the standard deviation U as the transfer threshold Y1. Obtain the high, medium, and low vulnerability numbers corresponding to the initial node within the preset time period t, and take the sum of their products with the coefficients 3, 2, and 1 respectively as the vulnerability exposure degree V of the initial node. Take the number of node attacks of the initial node as the number of calculations, and take the ratio of the number of calculations to the maximum number of attacks among all node attacks as the attack frequency L of the initial node within the preset time period t. Take the sum of the products of the vulnerability exposure degree V and attack frequency L of the initial node within the preset time period t and the preset coefficients β1 and β2 respectively as the real-time defense coefficient of the initial node. Use the same method as the real-time defense coefficient of the initial node to obtain the real-time defense coefficients of all nodes.
[0008] As a further solution of the present invention: The specific method for determining whether the attack node has transferred according to the real-time defense coefficient is as follows: When the real-time defense coefficient of the initial node is greater than the transfer threshold Y1, it is determined that the defense level of the initial node has increased and the attack node has transferred; otherwise, it is determined that the defense level of the initial node has not increased and the attack node has not transferred.
[0009] As a further solution of the present invention: The specific method for determining the transfer node according to the transfer probability is as follows: The specific method for the connection coefficient corresponding to each remaining node is as follows: Determine whether each remaining node is an adjacent node of the initial node. Mark the connection coefficient Jh of the adjacent node as 1, and mark the connection coefficient Jh of other non - adjacent nodes as 0. Take the defense coefficient of each remaining node at the end of the previous preset time period t as the original defense coefficient Hh corresponding to each remaining node. Take the absolute value of the difference between the original defense coefficient of each remaining node and the real - time defense coefficient as the defense coefficient deviation △HFh of each remaining node. Obtain the sum G of the defense coefficient deviations of the adjacent nodes corresponding to the attack node. Obtain the ratio between the defense coefficient deviation △HFh of each remaining node and G. At the same time, obtain the sum of the product of the connection coefficient Jh corresponding to each remaining node and the preset connection coefficient weighting factor ω and 1. Add the obtained ratio and sum as the transfer probability Ph of each remaining node, where ω takes the value of 0.2; Take the remaining nodes with the transfer probability Ph greater than the preset value Y2 as the transfer nodes of the attack node. When the transfer node is unique, isolate the corresponding node.
[0010] As a further solution of the present invention: When the transfer nodes are not unique, the specific method for obtaining the attack path length from the attack node to each transfer node is as follows: When the transfer nodes are not unique, establish a two - dimensional coordinate system in the node distribution connection graph. Take the grid center points corresponding to the attack node and each transfer node in the node distribution connection graph as the position points corresponding to the attack node and each transfer node respectively. Obtain the position coordinates corresponding to the position points of the attack node and each transfer node. According to the position coordinates corresponding to the position points of the attack node and each transfer node, obtain the attack path length Mi between the attack node and each transfer node. Obtain the transfer probability Pi of each transfer node from the transfer probabilities Ph of each remaining node. Take the sum of the attack path length Mi and the reciprocal of the transfer probability Pi as the attack priority value of each transfer node. Take the transfer nodes with the attack priority value greater than the high - risk threshold G1 as the main attack nodes, and directly isolate the main attack nodes. Apply access restriction measures to the transfer nodes with the attack priority value less than or equal to the high - risk threshold G1 and greater than or equal to the high - risk threshold G2. Continue to monitor the transfer nodes with the attack priority value less than the high - risk threshold G2, where the high - risk threshold G1 is greater than G2.
[0011] Compared with the prior art, the beneficial effects of the present invention are: (1) In the present invention, by comprehensively considering various factors such as vulnerability exposure and attack frequency, calculating the real - time defense coefficient of the node, and comparing it with the transfer threshold, accurately determining whether the attack node has transferred, it can timely detect changes in the attacker's attack path and provide a basis for taking effective preventive measures; (2)In the present invention, by combining the attack path length and the transfer probability to calculate the attack priority value, and based on the comparison between the attack priority value and the high-risk threshold, the main attack nodes are accurately determined, and corresponding processing measures are taken. This method of comprehensive evaluation of multiple indicators can more accurately identify the nodes that pose the greatest threat to network security, providing strong support for network security management. Based on the attack priority value, it is possible to effectively track security vulnerabilities in the network and conduct attack path analysis, and clearly present the attack process and path by constructing a directed graph, which helps to monitor and prevent potential security threats in real time. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 It is a schematic diagram of the method framework structure of the present invention; Figure 2 It is a schematic diagram of the method framework structure of the node distribution connection diagram of the present invention; Figure 3 It is a schematic diagram of the attack route of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0013] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.
[0014] Embodiment 1: Please refer to Figure 1 , Figure 2 and Figure 3 , this application provides a computer network information management method based on big data, including the following steps: Step 1: Obtain the positions of each node in the computer network and draw a node distribution connection diagram of the computer network. The specific method is as follows: First, obtain the positions of each node in the computer network through methods such as network topology scanning or device management systems. These nodes represent different devices, routers, switches, servers, terminals, etc. in the computer network; Then, collect the position information of each node from the network topology. According to the position information of the nodes, draw a grid diagram of each node in the computer network. This grid diagram shows the spatial distribution of each node in the network and their mutual position relationships. Each node has a clear position in the diagram, helping to visualize the network structure; Finally, identify the adjacent nodes corresponding to each node and determine the connection relationship corresponding to each node. The specific method is to use each node as the root node respectively, and at the same time connect the adjacent nodes corresponding to each root node respectively, generating a node distribution connection diagram of the computer network to show the connectivity between each node in the network; By means of technical means such as network topology scanning or device management systems, obtain the location information of each node in the computer network. Based on this location information, draw a grid diagram of each node in the computer network to clearly display the spatial distribution of each node in the network and their mutual position relationships, identify the adjacent nodes of each node, take each node as the root node, and connect its adjacent nodes correspondingly, thereby generating a node distribution connection diagram of the computer network to visually present the connectivity between each node in the network. By drawing the node distribution connection diagram of the computer network, the spatial distribution and mutual connection relationships of each node in the network can be visually displayed, helping network administrators quickly understand the overall architecture and topological structure of the network, facilitating network planning, management, and fault troubleshooting.
[0015] Step 2: Mark the initial node according to the initial position where the attacker is located. Based on the vulnerability exposure and attack frequency corresponding to each node within a preset time period t, obtain the real-time defense coefficient corresponding to each node. Determine whether the attack node has transferred according to the real-time defense coefficient. The specific determination method is as follows: Mark the initial position where the attacker is located as the initial node. Determine the initial position of the attacker according to methods such as network monitoring systems, intrusion detection systems, and log analysis. The initial node may be the first device invaded by the attacker or the first system controlled by the attacker. The specific analysis methods and steps used above are all existing and mature technologies, so they will not be elaborated here; If the attacker's attack causes the defense level of the initial node to increase, it is determined that the attack node has transferred. If the attacker's attack does not cause the defense level of the initial node to increase, it is determined that the attack node has not transferred; The specific method for determining whether the defense level of the initial node has increased is as follows: Obtain the vulnerability exposure and attack frequency corresponding to the initial node within the preset time period t. Calculate the real-time defense coefficient Ff of the initial node according to the vulnerability exposure and the number of attacks within the preset time period t. The specific value of the preset time period t is determined by relevant staff according to actual needs. Here, the value is 1 hour; The specific method for obtaining the real-time defense coefficient Ff of the initial node is as follows: Obtain the number of high, medium, and low vulnerabilities corresponding to the initial node within the preset time period t, and take the sum of the products of each of them and the coefficients 3, 2, and 1 as the vulnerability exposure V of the initial node, that is, vulnerability exposure V = number of high vulnerabilities × 3 + number of medium vulnerabilities × 2 + number of low vulnerabilities × 1; Obtain the number of node attacks corresponding to all nodes within the preset time period t, and use the number of node attacks of the initial node as the calculation count. At the same time, obtain the maximum number of attacks among the node attack counts, and use the ratio between the calculation count and the maximum number of attacks as the attack frequency L corresponding to the initial node within the preset time period t; Take the sum of the products of the vulnerability exposure V and the attack frequency L corresponding to the initial node within the preset time period t and the preset coefficients β1 and β2 respectively as the real-time defense coefficient F of the initial node, that is, F = V×β1 + L×β2, where both β1 and β2 are preset coefficients, and the specific values are determined by relevant staff according to actual needs. Here, 1 = β1 + β2, and β1 > β2; When the real-time defense coefficient F is greater than the transfer threshold Y1, it is determined that the defense level of the initial node has increased and the attack node has transferred. Otherwise, it is determined that the defense level of the initial node has not increased and the attack node has not transferred. Here, the transfer threshold Y1 is calculated based on the mean and standard deviation of the defense coefficients of all nodes. The specific method is as follows: Use the same method as the real-time defense coefficient F of the initial node to obtain the real-time defense coefficients of all nodes, and obtain the mean Ap and standard deviation U of the real-time defense coefficients of all nodes. Take the sum of the mean Ap and three times the standard deviation U as the transfer threshold Y1, that is, Y1 = Ap + 3×U; The specific methods for obtaining the mean Ap and standard deviation of the real-time defense coefficients of all nodes are existing and mature technologies, so no further elaboration will be made here; Calculate the real-time defense coefficient of the node according to the node vulnerability exposure and attack frequency, and dynamically determine whether the attack node has transferred; when the real-time defense coefficient increases, it is regarded that the defense behavior of the corresponding node has been triggered, such as upgrading strategies, dynamic enhancement of firewalls, etc., that is, the attacker's attack attempt fails and the attack path transfers; otherwise, it is considered that the attack behavior has not caused an effective response and the attack remains at this node; Comprehensively consider various factors such as vulnerability exposure and attack frequency, calculate the real-time defense coefficient of the node, and accurately determine whether the attack node has transferred by comparing with the transfer threshold. This method can timely detect changes in the attacker's attack path and provide a basis for taking effective preventive measures.
[0016] Step three: When the attack node transfers, obtain the transfer probabilities corresponding to each remaining node, and determine the transfer node according to the transfer probabilities, that is, analyze the probabilities of each remaining node being the transfer node and determine the transfer node. The specific method is as follows: Obtain whether each remaining node is an adjacent node of the initial node. Mark the connection coefficient Jh of the adjacent node as 1, and mark the connection coefficient Jh of other non - adjacent nodes as 0. Introduce connection - coefficient correction in the calculation of the transition probability to reflect the realistic law that the attack is more inclined to spread along the existing connections.
[0017] Obtain the original defense coefficient Hh corresponding to each remaining node. The original defense coefficient is the defense coefficient at the end of the previous preset time period t corresponding to each remaining node. The specific obtaining method is the same as the method for obtaining the real - time defense coefficient of all nodes, where h represents different remaining nodes; Take the absolute value of the difference between the original defense coefficient and the real - time defense coefficient of each remaining node as the defense - coefficient deviation △HFh of each remaining node. Obtain the sum G of the defense - coefficient deviations of the adjacent nodes corresponding to the attacking node. Obtain the ratio between the defense - coefficient deviation △HFh of each remaining node and G. At the same time, obtain the sum of the product of the connection coefficient Jh corresponding to each remaining node and the preset connection - coefficient weighting factor ω and 1. Add the obtained ratio and sum as the transition probability Ph of each remaining node, that is, Ph = △HFh / G+(1 + ω×Jh). The specific value of the preset connection - coefficient weighting factor ω is determined by relevant staff according to actual needs, and the value range is 1>ω>0. Here, it is 0.2, where h represents each remaining node; Take the remaining nodes with the transition probability Ph greater than the preset value Y2 as the transition nodes of the attacking node. When the transition node is unique, isolate the corresponding node and start the emergency - response plan; When the transition nodes are not unique, restrict the transition nodes with the transition probability Ph greater than the preset value Y2 and less than the preset value Y3. Isolate the transition nodes with the transition probability Ph greater than the preset value Y3 and start the emergency - response plan; Among them, the specific values of the preset values Y2 and Y3 are both determined by relevant staff according to actual needs, and Y3 is greater than Y2; When determining the transition nodes of the attacking node, not only the defense - coefficient deviation of the node is considered, but also the connection coefficient and the preset connection - coefficient weighting factor are introduced, making the calculation of the transition probability more scientific and reasonable. Classifying the transition nodes according to the transition probability can take different emergency - response measures targeted, improving the security of the network and the efficiency of dealing with attacks.
[0018] Embodiment 2: As the second embodiment of the present invention, when the present application is specifically implemented, compared with Embodiment 1, the technical solution of this embodiment is only different from that of Embodiment 1 in that this embodiment further includes Step 4; Step 4: When the transfer nodes are not unique, according to the position coordinates of the grid center points corresponding to the attack node and each transfer node in the node distribution connection graph, obtain the attack path lengths from the attack node to each transfer node. According to the attack path lengths from the attack node to each transfer node and the transfer probabilities of the transfer nodes, obtain the attack priority values of each transfer node. Determine the main attack nodes according to the attack priority values. The specific method is as follows: Take the grid center points corresponding to the attack node and each transfer node in the node distribution connection graph as the position points corresponding to the attack node and each transfer node respectively. Connect the attack node position point and the position points corresponding to each transfer node respectively, so as to obtain the attack paths from the attack node to each transfer node. Establish a two-dimensional coordinate system in the node distribution connection graph, obtain the position coordinates corresponding to the position points of the attack node and each transfer node respectively, and mark them as O (Ox, Oy) and Ri (xi, yi) respectively, where O (Ox, Oy) is the position coordinate of the attack node position point, and Ri (xi, yi) is the position coordinate of the position point of each transfer node, where i represents different transfer nodes; According to the position coordinates corresponding to the position points of the attack node and each transfer node, obtain the attack path length Mi between the attack node position and each transfer node, that is , and the attack path length represents the geometric distance from the attack node to each transfer node, that is, their spatial distance on the grid graph. Calculate the attack path length based on the node positions, which reflects the propagation cost of the attack migrating from the source node to the target node.
[0019] Illustrate with an example. If the attack node transfers from node A to node B, then add an edge pointing from node A to node B in the directed graph as the attack path for the attack node to transfer from node A to node B; Obtain the transfer probability Pi of each transfer node from the transfer probabilities Ph of each remaining node. Take the sum of the attack path length Mi and the reciprocal of the transfer probability P as the attack priority value of each transfer node; Set high-risk thresholds G1 and G2. Regard the transfer nodes with attack priority values greater than the high-risk threshold G1 as the main attack nodes, directly isolate the main attack nodes, and start the emergency response plan. Apply access restriction measures to the transfer nodes with attack priority values less than or equal to the high-risk threshold G1 and greater than or equal to the high-risk threshold G2. Continue to monitor the transfer nodes with attack priority values less than the high-risk threshold G2, do not immediately execute isolation, but only increase the node behavior monitoring frequency; Among them, the specific values of the high-risk thresholds G1 and G2 are determined by relevant staff according to the network security management requirements, and the high-risk threshold G1 is greater than G2; Calculate the attack priority value by combining the attack path length and the transfer probability. Based on the comparison between the attack priority value and the high-risk threshold, accurately determine the main attack nodes and take corresponding treatment measures. This method of comprehensive evaluation of multiple indicators can more accurately identify the nodes that pose the greatest threat to network security, providing strong support for network security management. Based on the attack priority value, it is possible to effectively track security vulnerabilities in the network and conduct attack path analysis, and clearly present the attack process and path by constructing a directed graph, which helps to monitor and prevent potential security threats in real time.
[0020] By collecting the location, connection relationship, and security attribute data of each node in the computer network, form a node distribution connection graph; by combining the vulnerability exposure and attack frequency of the node within a preset time period, calculate the node defense coefficient in real time and determine whether the attack node has transferred; by optimizing the connection relationship between the initial node and the remaining nodes, introduce a connection tendency correction in the calculation of the attack transfer probability; by calculating the attack path length based on the node position coordinates, reflect the spatial cost of attack diffusion; finally, by combining the transfer probability and the path length, dynamically determine the main attack nodes and take response measures; During the evolution process of the attack behavior, fuse the changes in the node defense state, network connection topology, and spatial distribution information in real time, construct a dynamic attack path graph and accurately predict the diffusion trend, so as to achieve fast isolation based on priority and intelligent security protection. This solution can effectively improve the accuracy of network intrusion detection, the rationality of attack path prediction, and the intelligence of response strategies, and significantly enhance the overall network security defense ability and resource scheduling efficiency; Embodiment 3: As Embodiment 3 of the present invention, when the present application is specifically implemented, compared with Embodiment 1 and Embodiment 2, the technical solution of this embodiment is to combine and implement the solutions of the above Embodiment 1 and Embodiment 2.
[0021] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula that is closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.
[0022] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A computer network information management method based on big data, characterized in that It includes the following steps: Step 1: Obtain the positions of each node in the computer network and draw a node distribution connection diagram of the computer network; Step 2: Mark the initial nodes according to the initial position of the attacker. According to the vulnerability exposure and attack frequency corresponding to each node within the preset time period t, obtain the real-time defense coefficient corresponding to each node. Determine whether the attack node has transferred according to the real-time defense coefficient. The preset time period t is taken as 1 hour; Step 3: When the attack node transfers, obtain the transfer probability corresponding to each remaining node and determine the transfer node according to the transfer probability; Step 4: When the transfer node is not unique, obtain the attack path length from the attack node to each transfer node. Determine the main attack node according to the attack path length from the attack node to each transfer node and the transfer probability of the transfer node.
2. The computer network information management method based on big data according to claim 1, wherein The specific method for drawing the node distribution connection diagram of the computer network is as follows: According to the position information of the nodes, draw a grid diagram of each node in the computer network. Take each node as the root node respectively, and at the same time connect the adjacent nodes corresponding to each root node respectively to generate the node distribution connection diagram of the computer network.
3. A computer network information management method based on big data according to claim 1, characterized in that, The specific method for obtaining the real-time defense coefficient corresponding to each node is as follows: Obtain the high, medium, and low vulnerability numbers corresponding to the initial node within the preset time period t, and take the sum of their products with the coefficients 3, 2, and 1 respectively as the vulnerability exposure V of the initial node. Take the number of node attacks of the initial node as the calculation times, and take the ratio of the calculation times to the maximum number of attacks among all node attacks as the attack frequency L of the initial node within the preset time period t. Take the sum of the products of the vulnerability exposure V and attack frequency L of the initial node within the preset time period t with the preset coefficients β1 and β2 respectively as the real-time defense coefficient of the initial node. Obtain the real-time defense coefficients of all nodes by the same method as the real-time defense coefficient of the initial node.
4. A computer network information management method based on big data according to claim 3, characterized in that, The specific method for determining whether the attack node has transferred according to the real-time defense coefficient is as follows: When the real-time defense coefficient of the initial node is greater than the transfer threshold Y1, it is determined that the defense level of the initial node has increased and the attack node has transferred. Otherwise, it is determined that the defense level of the initial node has not increased and the attack node has not transferred.
5. A computer network information management method based on big data according to claim 1, characterized in that, The specific method for determining the transfer node according to the transfer probability is as follows: Take the defense coefficient of each remaining node at the end of the previous preset time period t as the original defense coefficient Hh corresponding to each remaining node. Take the absolute value of the difference between the original defense coefficient of each remaining node and the real-time defense coefficient as the defense coefficient deviation △HFh of each remaining node. Obtain the sum G of the defense coefficient deviations of the adjacent nodes corresponding to the attack node. Obtain the ratio of the defense coefficient deviation △HFh of each remaining node to G, and at the same time obtain the sum of the product of the connection coefficient Jh corresponding to each remaining node and the preset connection coefficient weighting factor ω and 1. Add the obtained ratio and sum as the transfer probability Ph of each remaining node. ω is taken as 0.2; The remaining nodes with a transfer probability Ph greater than the preset value Y2 are used as the transfer nodes of the attacking node. When the transfer node is unique, the corresponding node is isolated.
6. A computer network information management method based on big data according to claim 5, characterized in that, When the transfer nodes are not unique, the specific method for obtaining the attack path lengths from the attacking node to each transfer node is as follows: When the transfer nodes are not unique, a two-dimensional coordinate system is established in the node distribution connection graph. The grid center points corresponding to the attacking node and each transfer node in the node distribution connection graph are used as the position points corresponding to the attacking node and each transfer node respectively. The position coordinates corresponding to the position points of the attacking node and each transfer node are obtained. According to the position coordinates corresponding to the position points of the attacking node and each transfer node, the attack path length Mi between the attacking node and each transfer node is obtained. The transfer probability Pi of each transfer node is obtained from the transfer probabilities Ph of each remaining node. The sum of the attack path length Mi and the reciprocal of the transfer probability Pi is used as the attack priority value of each transfer node. The transfer nodes with an attack priority value greater than the high-risk threshold G1 are used as the main attacking nodes, and the main attacking nodes are directly isolated.
7. A computer network information management method based on big data according to claim 6, characterized in that, Access restriction measures are imposed on the transfer nodes with an attack priority value less than or equal to the high-risk threshold G1 and greater than or equal to the high-risk threshold G2. The transfer nodes with an attack priority value less than the high-risk threshold G2 are continuously monitored. The high-risk threshold G1 is greater than G2.
8. A computer network information management method based on big data according to claim 3, characterized in that The specific value of the transfer threshold Y1 is: The mean Ap and standard deviation U of the real-time defense coefficients of all nodes are obtained, and the sum of the mean Ap and three times the standard deviation U is used as the transfer threshold Y1.
9. A computer network information management method based on big data according to claim 5, characterized in that, The specific method for the connection coefficient corresponding to each remaining node is: It is determined whether each remaining node is an adjacent node of the initial node. The connection coefficient Jh of the adjacent node is marked as 1, and the connection coefficient Jh of other non-adjacent nodes is marked as 0.