Ship network asset identification and risk analysis method, device and equipment

By acquiring and structuring the data of ship network equipment and building a device knowledge graph, the limitations of ship network asset identification and risk analysis are solved, comprehensiveness and accuracy are improved, and the standardization and automation of risk assessment are achieved.

CN120450449AActive Publication Date: 2025-08-08CHINESE CLASSIFICATION SOC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510940024.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-08-08
Estimated Expiration
2045-07-09

AI Technical Summary

Technical Problem

The existing technology lacks asset identification and risk analysis solutions for the marine network environment, which leads to the inability to accurately identify dynamically changing network assets, making it difficult to conduct a comprehensive assessment of the marine network security risks, and poses great safety hazards.

Method used

By obtaining network equipment data in multiple different data formats, performing structured processing and classification, building equipment knowledge graphs, combining risk assessment and logical and spatial relationships, comprehensive identification and risk analysis of ship network assets can be achieved.

Benefits of technology

It improves the comprehensiveness of marine network asset identification and the accuracy of threat analysis, realizes the standardization of assignment assessment and the automation of risk assessment, and solves the limitations of asset identification and insufficient reliability of risk analysis in traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120450449A_ABST
    Figure CN120450449A_ABST
Patent Text Reader

Abstract

The invention provides a ship network asset identification and risk analysis method, device and equipment. The method comprises the following steps: acquiring network equipment data of multiple different data formats of a ship network; carrying out structured processing on the network equipment data in various different data formats to obtain target data; classifying the network equipment according to the target data to obtain an equipment classification result; performing risk assessment on the network equipment according to the equipment classification result to obtain a risk level; according to the equipment classification result, processing the relationship between the network equipment to obtain an equipment knowledge graph; and performing risk analysis processing on the ship network equipment assets according to the equipment knowledge graph and the risk level to obtain a risk analysis processing result. According to the scheme of the invention, the comprehensiveness of ship network asset identification and the accuracy of threat analysis can be improved, and the standardization of assignment evaluation and the automation of risk evaluation are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information processing technology, and in particular to a method, device and equipment for identifying and analyzing ship network assets and risks. Background Art

[0002] As ships become increasingly intelligent and information-based, their network systems (such as ship automation systems, satellite communications, and navigation systems) are becoming increasingly complex. The secure management of network assets (including hardware, software, and data) has become crucial for ensuring safe ship operations. However, existing technologies lack asset identification and risk analysis solutions tailored to the specific characteristics of ship network environments (such as mobility, heterogeneous network convergence, and offshore communication restrictions). This makes it difficult to accurately identify dynamically changing network assets and comprehensively assess ship network security risks, posing significant security risks.

[0003] With the deepening integration of intelligent and information-based shipbuilding, ship network architectures are becoming increasingly complex, with a vast array of electronic equipment, control systems, and communication systems intertwined. Ship cybersecurity has become a critical factor in ensuring safe ship operations. Cyberattacks can lead to catastrophic consequences, such as navigation system failure and power system failure. Accurately identifying network assets and scientifically assessing their risks are fundamental to building a ship's cybersecurity protection system. However, the diverse and dynamic nature of ship network assets poses significant challenges to traditional asset identification methods. Furthermore, the types and methods of cyber threats are becoming increasingly diverse, necessitating the use of specialized security products for real-time monitoring of cyberattacks. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method, device, and equipment for ship network asset identification and risk analysis. These methods can improve the comprehensiveness of ship network asset identification and the accuracy of threat analysis, while also achieving standardization of value assessment and automation of risk assessment.

[0005] In order to solve the above technical problems, the technical solutions of the present invention are as follows:

[0006] A method for identifying and analyzing ship network assets and risks, comprising:

[0007] Obtain network device data in various formats on the ship network;

[0008] Performing structured processing on the network device data in a plurality of different data formats to obtain target data;

[0009] Classifying network devices according to the target data to obtain device classification results;

[0010] Perform risk assessment on the network device based on the device classification result to obtain a risk level;

[0011] According to the device classification results, the relationships between network devices are processed to obtain a device knowledge graph;

[0012] According to the equipment knowledge graph and risk level, risk analysis processing is performed on the ship network equipment assets to obtain a risk analysis processing result.

[0013] Optionally, performing structured processing on the network device data in a plurality of different data formats to obtain target data includes:

[0014] Performing data cleaning on the network device data to obtain intermediate data;

[0015] The intermediate data is format-converted to obtain target data.

[0016] Optionally, classifying network devices according to the target data to obtain device classification results includes:

[0017] Extracting device tag information from the target data;

[0018] According to the label information, a basic probability assignment is obtained for each classification result;

[0019] The basic probability assignments are fused to obtain a device classification result.

[0020] Optionally, based on the device classification result, a risk assessment is performed on the network device to obtain a risk level, including:

[0021] Assigning evaluation indicators of various types of network devices according to the device classification results to obtain indicator assignment results;

[0022] The risk level is obtained based on the indicator assignment results and the probability of network threat occurrence.

[0023] Optionally, based on the device classification result, the relationship between network devices is processed to obtain a device knowledge graph, including:

[0024] Determine the dependency relationships between network devices based on the device classification results and obtain a logical relationship graph;

[0025] Determine the geographic location code of the network device based on the device classification result and obtain a spatial relationship map;

[0026] According to the device classification result, the component composition of the network device is determined to obtain a hierarchical relationship map.

[0027] Optionally, based on the device classification result, the dependency relationships between network devices are determined to obtain a logical relationship graph, including:

[0028] Obtaining device function service data according to the device classification result;

[0029] According to the device function service data, the device dependency probability is obtained by using the likelihood probability, prior probability and marginal probability of the device dependency;

[0030] According to the device dependency probability, a logical relationship graph is obtained.

[0031] Optionally, determining the geographic location code of the network device based on the device classification result to obtain a spatial relationship map includes:

[0032] Determine the coordinates of the network device in the ship space based on the device classification result to obtain three-dimensional coordinate data of the device;

[0033] Mapping the three-dimensional coordinate data of the device onto a two-dimensional plane to obtain two-dimensional coordinate data;

[0034] According to the two-dimensional coordinate data, the geographic location code of the network device is determined to obtain a spatial relationship map.

[0035] Optionally, processing the relationships between network devices based on the device classification results to obtain a device knowledge graph further includes:

[0036] When the device status changes, dynamically calculate the impact of the device status change on the relationship between devices;

[0037] The device knowledge graph is updated according to the impact scope to obtain an updated device knowledge graph.

[0038] An embodiment of the present invention further provides a device for identifying and analyzing ship network assets and risks, comprising:

[0039] An acquisition module is used to acquire network device data in various data formats of the ship network;

[0040] The processing module is used to perform structured processing on the network device data in multiple different data formats to obtain target data; classify the network devices according to the target data to obtain device classification results; perform risk assessment on the network devices according to the device classification results to obtain risk levels; process the relationships between network devices according to the device classification results to obtain a device knowledge graph; and perform risk analysis on the ship network device assets according to the device knowledge graph and risk levels to obtain risk analysis results.

[0041] An embodiment of the present invention also provides a computing device, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the ship network asset identification and risk analysis method described in the present invention.

[0042] The above technical solution of the present invention has at least the following technical effects:

[0043] The ship network asset identification and risk analysis method of the present invention obtains network device data in multiple different data formats from the ship network; performs structured processing on the network device data in multiple different data formats to obtain target data; classifies network devices based on the target data to obtain device classification results; performs risk assessment on network devices based on the device classification results to obtain risk levels; processes the relationships between network devices based on the device classification results to obtain a device knowledge graph; and performs risk analysis on ship network device assets based on the device knowledge graph and risk levels to obtain risk analysis results. This method solves the problems of limitations in ship network asset identification in the prior art, disconnection between threats and assets, lack of value assignment standards, and insufficient reliability of risk analysis results. It can improve the comprehensiveness of ship network asset identification and the accuracy of threat analysis, and achieve standardization of value assignment and automation of risk assessment. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 It is a flow chart of the ship network asset identification and risk analysis method of the present invention;

[0045] Figure 2 It is a schematic diagram of the ship network asset identification and risk analysis device of the present invention. DETAILED DESCRIPTION

[0046] Exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.

[0047] like Figure 1 As shown, an embodiment of the present invention provides a method for identifying and analyzing ship network assets and risks, including:

[0048] Step S1, obtaining network device data of a ship network in a plurality of different data formats;

[0049] Step S2, performing structured processing on the network device data in a plurality of different data formats to obtain target data;

[0050] Step S3, classifying the network devices according to the target data to obtain a device classification result;

[0051] Step S4, performing risk assessment on the network device based on the device classification result to obtain a risk level;

[0052] Step S5: processing the relationships between network devices based on the device classification results to obtain a device knowledge graph;

[0053] Step S6: performing risk analysis on the ship network equipment assets according to the equipment knowledge graph and risk level to obtain a risk analysis result.

[0054] In this embodiment, Figure 1As shown in FIG, in the ship network asset identification and risk analysis method, first, the data of network devices are collected through various methods and network protocols. The collected network device data include static data and dynamic data. The static data includes data such as device model, manufacturer, and deployment location. The dynamic data includes ship network device communication data collected through heterogeneous network protocols such as Simple Network Management Protocol (SNMP), CAN bus, Syslog, Transmission Control Protocol / Internet Protocol (TCP / IP protocol); the data of Automatic Identification System (AIS) of Ship is collected through Simple Network Management Protocol (SNMP). SNMP is a network management protocol that can be used to monitor and obtain status information of network devices. It can also configure required monitoring parameters such as CPU utilization, memory usage, hard disk space, etc. The performance and health status of the server can be monitored through SNMP, and potential problems can be discovered and solved in time. At the same time, regular analysis of server data can also help optimize resource utilization and plan system upgrades and expansions; Syslog is a standard protocol for storing system logs, which not only defines how to record events but also how these events should be transmitted on the network. Syslog has advantages such as unified storage, simplified monitoring, universal protocol, consistency, flexible configuration, and distributed architecture. Data from ship satellite communication terminals and network traffic collection probes is collected through the Transmission Control Protocol / Internet Protocol (TCP / IP). The TCP / IP protocol is the most basic communication protocol used in network use. The TCP / IP transmission protocol specifies the standards and methods for communication between various parts of the Internet and has wide compatibility, good scalability, and stable reliability. Data from ship environmental sensors is collected through the Modbus protocol, a protocol for communication between master and slave devices. It is open, simple, and reliable and is widely used in programmable logic controllers, sensors, instruments, and other fields. Manually entered data is collected through spreadsheets (Excel).

[0055] Then, the acquired network device data is subjected to structured processing such as data cleaning and format conversion to obtain target data that is easy to process and use; again, the network devices are classified according to the target data to obtain device classification results; again, the relationships between network devices are processed to obtain a device knowledge graph; finally, based on the device knowledge graph and risk level, risk analysis processing is performed on the ship's network device assets to obtain risk analysis processing results, thereby realizing structured management of ship network device assets; specifically, the network system performs a full network scan every 15 minutes, and the passive monitoring module captures traffic data in real time and dynamically updates the asset database; receives intrusion detection system (IDS) alarms in real time, matches affected assets through the IP-asset mapping table, and generates a "Threat-Asset Association Log"; updates the assignment data every month based on asset changes and vulnerability scan results; calculates risk levels based on real-time data, and pushes warnings to the security management platform when the preset risk level threshold is triggered.

[0056] The solution of the present invention constructs a three-dimensional dynamic knowledge graph that integrates the spatial location, logical dependencies, and hierarchical relationships of ship network equipment. Through a dynamic self-optimization algorithm, it uses incremental updates and dynamic weights to achieve real-time adaptive adjustment of the asset structure, and embeds ship domain knowledge and intelligent analysis models to break through the isolated management mode of traditional static ledgers.

[0057] In an optional embodiment of the present invention, in step S2, the network device data in a plurality of different data formats is subjected to structured processing to obtain target data, including:

[0058] Step S21, performing data cleaning on the network device data to obtain intermediate data;

[0059] Step S22: convert the format of the intermediate data to obtain target data.

[0060] In this embodiment, the network device data is structured. First, a reasonable threshold range for each parameter data is set according to the type of the network device data, and data exceeding the reasonable threshold range is discarded as an abnormal value to prevent the impact of data fluctuations on subsequent data processing. Then, duplicate values and missing values in the network device data are found, and invalid data such as duplicate values and missing values are removed to obtain intermediate data. Thirdly, the intermediate data is formatted. For example, if the network rate is 85.62 megabits per second, it consists of two original data (85 and 62), which represent the integer part and the decimal part of the network rate, respectively. The system converts the data into a format according to preset rules, and reports the value 85.62 to obtain the target data.

[0061] In an optional embodiment of the present invention, in step S3, classifying the network devices according to the target data to obtain a device classification result includes:

[0062] Step S31, extracting device tag information from the target data;

[0063] Step S32, obtaining a basic probability assignment for each classification result based on the label information;

[0064] Step S33: fusing the basic probability assignments to obtain a device classification result.

[0065] In this embodiment, during the device classification process, multiple device tag information is first extracted from target data from different sources. The tag information includes the device's function tag (such as navigation equipment, communication equipment, etc.), protocol tag (such as TCP / IP, marine electronic equipment format NMEA0183, etc.), location tag, manufacturer tag, etc.

[0066] Then, based on the set of all possible tag information, an evidence body is constructed for each tag, converting the tag information into basic probability assignments for network devices belonging to different classification results. For example, for a device's function tag, the probability distribution of the device belonging to different functional categories is determined based on the device's manual, operation log, and other information. If the probability of a device being judged as a navigation device is 0.8 and the probability of it being a communication device is 0.2, then an evidence body can be constructed to represent the device's functional classification.

[0067] Finally, the evidence bodies with different labels are fused according to the basic probability assignment. The fusion formula is:

[0068] Among them, m(A) is the basic probability distribution after fusion, , K is the conflict coefficient, which indicates the degree of conflict between two different evidence bodies; B and C represent possible device classification results, and A represents the fused device classification result; The intersection of the features of B and C is A; represents the basic probability distribution of outcome B, represents the basic probability distribution of outcome C;

[0069] Through multiple iterations of fusing evidence bodies with different labels, a final integrated body of evidence is obtained. Based on this integrated body of evidence, the final classification result of the device is determined. The maximum probability principle can be adopted, that is, the category with the highest probability after fusion is selected as the device classification result. Alternatively, a threshold can be set according to actual needs. When the probability of a certain category exceeds the threshold, the device is classified into that category. As the device operates and data is updated, new label information is continuously collected, and the device classification result is updated and optimized to adapt to changes in device status.

[0070] In an optional embodiment of the present invention, in step S4, risk assessment is performed on the network device based on the device classification result to obtain a risk level, including:

[0071] Step S41, assigning evaluation indicators to various types of network devices according to the device classification results to obtain indicator assignment results;

[0072] Step S42: Obtain the risk level based on the indicator evaluation result and the probability of network threat occurrence.

[0073] In this embodiment, the network's built-in intrusion detection system (IDS) component obtains raw threat data (attack type, source / destination IP, timestamp, etc.), and locates the specific asset under attack through the IP-asset mapping table (e.g., "target IP: 192.168.1.10" corresponds to the "bridge navigation server").

[0074] Risk levels are adjusted based on asset attributes and asset categories. The risk of an attack on a Class III system is automatically increased by 50%, while that on a Class II system is increased by 30%. For example, a DoS attack on a Class III propulsion system is marked as "very high risk."

[0075] Standardize the asset valuation method and establish a valuation indicator system based on ship cybersecurity requirements:

[0076] Importance (I): Classification is based on system categories, with Category III assigned a value of 5, Category II a value of 3, and Category I a value of 1. Using an arithmetic progression with a fixed difference (with a tolerance of 2) is suitable for representing "equidistant differences" between levels. For example, the main engine control system (Category III) is assigned a value of 5, and the cabin lighting (Category II) is assigned a value of 2.

[0077] Vulnerability value (V): Combined with the Common Vulnerabilities and Exposures (CVE) vulnerability level (high risk = level 5, medium risk = level 3, low risk = level 1), for example, a device with the high-risk vulnerability CVE-2023-1234 is assigned a level 5.

[0078] Data sensitivity assignment (D): Data is graded into low, medium, and high sensitivity, and assigned values of 1, 3, and 5 respectively.

[0079] Risk analysis uses a three-dimensional risk calculation model:

[0080] R=P×(I×V×D)

[0081] Among them, R is the risk level, P is the probability of threat occurrence, I is the importance, V is the vulnerability, and D is the data sensitivity.

[0082] The probability of threat occurrence (P) is based on statistical analysis of IDS historical data (such as the frequency of a certain type of attack in the past 30 days).

[0083] Grading criteria: High probability: frequent attacks (e.g., ≥15 attacks in the past 30 days); Medium probability: sporadic attacks (2-14 attacks in 30 days); Low probability: rare attacks (≤1 attack in 30 days). High probability P = 0.8, Medium probability P = 0.5, Low probability P = 0.3. Using an arithmetic progression with a fixed difference (with a tolerance of 0.3) is suitable for representing "equally spaced differences" between tiers.

[0084] Output visual risk reports, marking high-risk asset lists, threat hotspots, and protection priority recommendations.

[0085] In an optional embodiment of the present invention, in step S5, the relationships between network devices are processed according to the device classification results to obtain a device knowledge graph, including:

[0086] Step S51, determining the dependency relationships between network devices based on the device classification results, and obtaining a logical relationship graph;

[0087] Step S52, determining the geographic location code of the network device according to the device classification result, and obtaining a spatial relationship map;

[0088] Step S53: Determine the component composition of the network device based on the device classification result and obtain a hierarchical relationship map.

[0089] In this embodiment, when constructing the knowledge graph of ship network equipment, a logical relationship graph between devices is obtained through the Link Layer Discovery Protocol (LLDP protocol) and the network reasoning model. The LLDP protocol is a protocol that enables devices in the network to discover each other and notify status and exchange information; by constructing a ship space network, the spatial association of devices is realized based on geographic location coding to obtain a spatial relationship graph; through the device function tree hierarchy, the component composition of the device is determined to obtain a hierarchical relationship graph; the device knowledge graph is constructed in the form of a resource description framework (RDF triple), such as (device A, relationship type, device B), and stored in a graph database.

[0090] In an optional embodiment of the present invention, in step S51, the dependency relationships between network devices are determined based on the device classification results to obtain a logical relationship graph, including:

[0091] Step S511, obtaining device function service data according to the device classification result;

[0092] Step S512, obtaining the device dependency probability based on the device function service data using the likelihood probability, prior probability, and marginal probability of the device dependency;

[0093] Step S513: obtaining a logical relationship graph according to the device dependency probability.

[0094] In this embodiment, when constructing a logical relationship map between ship equipment, the operation data, log information, configuration information, etc. of the equipment are first extracted based on the target data and equipment classification results. This data contains the interaction relationship and dependency information between the devices. Then, based on the functions and business logic of the equipment, the possible dependencies between the devices are preliminarily determined, and the network topology is constructed. Expert knowledge, data mining, and other methods are used to determine the network structure. For example, based on the design documents and experience of the ship network, the connection relationship between the satellite terminal and the switch and server is determined. The parameters of the network structure are learned using the structured data, and the conditional probability distribution of each node is calculated. The maximum likelihood estimation, Bayesian estimation, and other methods can be used for parameter learning. The probability of the dependency relationship between the devices is estimated using a large amount of historical data. When new equipment operation data or events occur, the learned network topology is used to perform dependency reasoning and calculate the probability change of the dependency relationship between the devices. The parameters and structure of the network are updated based on the reasoning results to adapt to the dynamic changes in the equipment status. For example, when a switch fails, the probability of the dependency relationship of the related devices is updated.

[0095] Specifically, based on the device function business data, the likelihood probability of device dependency is obtained, which is expressed as P(X|D), where P represents the probability, X represents the vector of feature data, and D represents the dependency relationship between devices.

[0096] The distribution of the state data of the dependency relationship between devices is normal distribution, with a mean of μ and a variance of σ. 2 ,in, ;

[0097] Use P(D) to represent the prior probability of the dependency;

[0098] P(X) represents the marginal probability of feature data;

[0099] The probability P(D|X) of the dependency relationship between devices is obtained through the formula P(D|X)=P(X|D)P(D) / P(X).

[0100] According to the maximum value of the device dependency probability, the dependency relationship between devices is determined to obtain a logical relationship map.

[0101] In an optional embodiment of the present invention, in step S52, determining the geographic location code of the network device based on the device classification result to obtain a spatial relationship map includes:

[0102] Step S521, determining the coordinates of the network device in the ship space according to the device classification result, and obtaining the three-dimensional coordinate data of the device;

[0103] Step S522, mapping the three-dimensional coordinate data of the device onto a two-dimensional plane to obtain two-dimensional coordinate data;

[0104] Step S523: Determine the geographic location code of the network device based on the two-dimensional coordinate data to obtain a spatial relationship map.

[0105] In this embodiment, when constructing a spatial relationship map between ship equipment, the overall ship space is first divided into layers according to decks, cabins, cabinets, etc., to construct a hierarchical spatial structure. Specifically, a ship space network of the entire ship → deck → cabin → cabinet → equipment is constructed.

[0106] For example, a ship is divided into multiple decks, each deck is further divided into several cabins, and each cabin contains multiple cabinets; each spatial unit at each level is assigned a unique identifier, such as deck number, cabin number, cabinet number, etc.;

[0107] Then, the precise coordinates of each device in the ship space are determined to obtain the three-dimensional coordinate information of the device;

[0108] Thirdly, mapping the three-dimensional coordinate data of the device onto a two-dimensional plane to obtain two-dimensional coordinate data;

[0109] Again, the Hilbert curve is used for spatial encoding. According to the coordinates of the device on the two-dimensional plane, the corresponding Hilbert code is calculated. The calculation formula is as follows:

[0110] S=

[0111] Where n is the order of the Hilbert curve, E j Number the jth sub-area. The sub-area number is determined by the direction state and the binary bit.

[0112] The traversal order of the sub-areas at each level is determined by the direction state of the parent area. In this embodiment, a U-shaped direction state rule is adopted so that the sub-areas are arranged in a clockwise rotation.

[0113] The Hilbert code incorporates hierarchical information about the ship's spatial structure. For example, information such as the deck number and cabin number are added as prefixes or suffixes to the Hilbert code, forming a unique string code, such as "H3_Deck02_R05_03," where "H3" represents the deck number, "Deck02" denotes the second deck, "R05" denotes the fifth cabin, and "03" represents a specific location within that cabin. The improved Hilbert code for each device is stored in a graph database as its spatial identifier. An index is then created for the Hilbert code to facilitate rapid query and location of the device within the ship's spatial structure, improving spatial query efficiency.

[0114] In an optional embodiment of the present invention, step S53, determining the component composition of the network device based on the device classification result and obtaining a hierarchical relationship map, may include:

[0115] Through the device function tree hierarchy (for example: navigation system → AIS → antenna), the component composition of the device is determined to obtain a hierarchical relationship graph; the device knowledge graph is constructed in the form of a resource description framework (RDF triple), such as (device A, relationship type, device B), and stored in the graph database.

[0116] In an optional embodiment of the present invention, in step S5, the relationships between network devices are processed according to the device classification results to obtain a device knowledge graph, further comprising:

[0117] Step S54, when the device state changes, dynamically calculate the impact range of the device state change on the relationship between devices;

[0118] Step S55: Update the device knowledge graph according to the impact range to obtain an updated device knowledge graph.

[0119] In this embodiment, when the device status changes, such as when a device is added / deleted / attribute changed, the impact of the device change on the knowledge graph is first calculated, the changed device is designated as the starting node, its shortest path distance is initialized to 0 in the graph database, and the distance attributes of all other nodes are set to infinity. A predecessor node attribute is added to each node, and the predecessor node on the current shortest path is recorded. Initially, only the predecessor node of the starting node points to itself, and other nodes are set to empty. Using the traversal interface of the graph database, the node with the smallest distance value is selected from all nodes not marked as "visited" as the current processing node and marked as "visited". All adjacent nodes of the current node are traversed, and the total weight of the path from the current node to these adjacent nodes (i.e., the distance of the current node plus the edge weight) is calculated; if this value is less than the existing distance value of the adjacent node, the distance and predecessor node attributes of the adjacent node are updated until all nodes are marked as "visited" or the distance to the target node (such as the business system node affected by the change) no longer changes.

[0120] After the change is implemented, edge weights are updated based on real-time monitoring data (such as actual link load and configuration effectiveness status), and the shortest path is recalculated to verify whether the impact range exceeds expectations, achieving dynamic assessment. Among them, a dynamic weight algorithm (combining device importance and change frequency) is used to update the asset structure priority. The specific formula is as follows: W = α × T + β × F + γ × G;

[0121] Where W represents the weight, T represents the running time, F represents the number of failures, G represents the number of associated devices, α is the duration coefficient, β is the failure coefficient, γ is the association coefficient, and α+β+γ=1.

[0122] In an optional embodiment of the present invention, in step S6, risk analysis processing is performed on the ship network equipment assets according to the equipment knowledge graph and risk level to obtain a risk analysis processing result, including:

[0123] The risk analysis module calculates risk levels based on real-time data and sends alerts to the security management platform when preset risk thresholds are triggered. Risk analysis adjusts risk levels based on asset attributes and asset categories, automatically increasing the attack risk for Category III systems by 50% and for Category II systems by 30%. For example, a DoS attack on a Category III propulsion system is marked as "extremely high risk." A visual risk report is generated, highlighting a list of high-risk assets, threat hotspots, and recommended protection priorities.

[0124] The solution of this invention achieves real-time updates of device attributes through automatic data collection from multiple sources. The dynamic update module, combined with an incremental update algorithm, significantly reduces data update latency by calculating the impact range and combining local graph refreshes. Multiple tags are integrated to achieve complex classification, and the knowledge graph constructs spatial, logical, and hierarchical relationships. This supports fault propagation path analysis (e.g., switch failure → interruption of seven downstream terminals), enabling correlation analysis. A built-in network traffic collection probe collects real-time traffic logs via a mirrored port and is configured with an intrusion detection system rule base for real-time traffic monitoring, protecting against spoofing attacks. Abnormal behavior detection (with early warning of graph relationship mutations) allows security incident location accuracy to be refined from the network layer down to the device level (e.g., IP → device, ID → cabin), significantly improving security response speed. A graph database automatically generates dynamic topology (device online → automatically builds relationships). A shortest path algorithm calculates the impact range of a fault in real time. Logical relationship modeling integrates service data flows (satellite terminal → switch → server). A dynamic weighting algorithm optimizes resource scheduling (prioritizing high-weighted devices), reducing topology update latency from hours or days to minutes.

[0125] The solution of the present invention constructs a three-dimensional dynamic knowledge graph of ship network equipment (integrating spatial location, logical dependencies, and hierarchical relationships), realizes real-time adaptive adjustment of asset structure through a dynamic self-optimization algorithm (incremental updates and dynamic weights), and embeds ship domain knowledge and intelligent analysis models, breaking through the isolated management mode of traditional static ledgers.

[0126] This invention utilizes a multi-dimensional structured modeling approach that fuses Hilbert space coding with network dependency reasoning; a dynamic update mechanism that combines an incremental update algorithm with a configurable weight formula; and intelligent applications enhanced by domain knowledge. It also builds a ship-specific system architecture that integrates multi-protocol adaptation and security asset linkage. Through a four-dimensional approach encompassing methods, systems, data models, and scenario-based applications, it addresses the fundamental shortcomings of existing technologies, characterized by static, isolated, and manually dependent systems, and is applicable to the global digitalization needs of ships.

[0127] like Figure 2 As shown, an embodiment of the present invention further provides a ship network asset identification and risk analysis device 20, comprising:

[0128] An acquisition module 21 is used to acquire network device data of a ship network in a variety of different data formats;

[0129] The processing module 22 is used to perform structured processing on the network device data in a variety of different data formats to obtain target data; classify the network devices according to the target data to obtain device classification results; perform risk assessment on the network devices according to the device classification results to obtain risk levels; process the relationships between network devices according to the device classification results to obtain a device knowledge graph; perform risk analysis on the ship network device assets according to the device knowledge graph and risk levels to obtain risk analysis results.

[0130] Optionally, performing structured processing on the network device data in a plurality of different data formats to obtain target data includes:

[0131] Performing data cleaning on the network device data to obtain intermediate data;

[0132] The intermediate data is format-converted to obtain target data.

[0133] Optionally, classifying network devices according to the target data to obtain device classification results includes:

[0134] Extracting device tag information from the target data;

[0135] According to the label information, a basic probability assignment is obtained for each classification result;

[0136] The basic probability assignments are fused to obtain a device classification result.

[0137] Optionally, based on the device classification result, a risk assessment is performed on the network device to obtain a risk level, including:

[0138] Assigning evaluation indicators of various types of network devices according to the device classification results to obtain indicator assignment results;

[0139] The risk level is obtained based on the indicator assignment results and the probability of network threat occurrence.

[0140] Optionally, based on the device classification result, the relationship between network devices is processed to obtain a device knowledge graph, including:

[0141] Determine the dependency relationships between network devices based on the device classification results and obtain a logical relationship graph;

[0142] Determine the geographic location code of the network device based on the device classification result and obtain a spatial relationship map;

[0143] According to the device classification result, the component composition of the network device is determined to obtain a hierarchical relationship map.

[0144] Optionally, based on the device classification result, the dependency relationships between network devices are determined to obtain a logical relationship graph, including:

[0145] Obtaining device function service data according to the device classification result;

[0146] According to the device function service data, the device dependency probability is obtained by using the likelihood probability, prior probability and marginal probability of the device dependency;

[0147] According to the device dependency probability, a logical relationship graph is obtained.

[0148] Optionally, determining the geographic location code of the network device based on the device classification result to obtain a spatial relationship map includes:

[0149] Determine the coordinates of the network device in the ship space based on the device classification result to obtain three-dimensional coordinate data of the device;

[0150] Mapping the three-dimensional coordinate data of the device onto a two-dimensional plane to obtain two-dimensional coordinate data;

[0151] According to the two-dimensional coordinate data, the geographic location code of the network device is determined to obtain a spatial relationship map.

[0152] Optionally, processing the relationships between network devices based on the device classification results to obtain a device knowledge graph further includes:

[0153] When the device status changes, dynamically calculate the impact of the device status change on the relationship between devices;

[0154] The device knowledge graph is updated according to the impact scope to obtain an updated device knowledge graph.

[0155] All implementations in the above method embodiments are applicable to the embodiments of the device and can achieve the same technical effects.

[0156] An embodiment of the present invention further provides a computing device comprising: one or more processors; and a storage device configured to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the ship network asset identification and risk analysis method of the present invention. All implementations described in the aforementioned method embodiments are applicable to the embodiments of the computing device and can achieve the same technical effects.

[0157] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0158] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0159] In the embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0160] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0161] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0162] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for causing a computer device (such as a personal computer, server, or network device) to execute all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.

[0163] In addition, it should be pointed out that in the apparatus and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present invention. Moreover, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but they do not necessarily need to be performed in chronological order, and some steps can be performed in parallel or independently of each other. For those of ordinary skill in the art, it can be understood that all or any steps or components of the method and apparatus of the present invention can be implemented in hardware, firmware, software or a combination thereof in any computing device (including a processor, storage medium, etc.) or a network of computing devices. This can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.

[0164] Therefore, the purpose of the present invention can also be achieved by running a program or a group of programs on any computing device. The computing device can be a well-known general-purpose device. Therefore, the purpose of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or device. That is to say, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be pointed out that in the device and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. In addition, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but do not necessarily need to be performed in chronological order. Certain steps can be performed in parallel or independently of each other.

[0165] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A method for identifying and analyzing ship network assets, characterized in that: include: Obtain network device data in various formats on the ship network; Performing structured processing on the network device data in a plurality of different data formats to obtain target data; Classifying network devices according to the target data to obtain device classification results; Perform risk assessment on the network device based on the device classification result to obtain a risk level; According to the device classification results, the relationships between network devices are processed to obtain a device knowledge graph; According to the equipment knowledge graph and risk level, risk analysis processing is performed on the ship network equipment assets to obtain a risk analysis processing result.

2. The method for identifying and analyzing ship network assets and risks according to claim 1, characterized in that: Structural processing is performed on the network device data in a variety of different data formats to obtain target data, including: Performing data cleaning on the network device data to obtain intermediate data; The intermediate data is format-converted to obtain target data.

3. The method for identifying and analyzing ship network assets and risks according to claim 1, characterized in that: Classify the network devices according to the target data to obtain device classification results, including: Extracting device tag information from the target data; According to the label information, a basic probability assignment is obtained for each classification result; The basic probability assignments are fused to obtain a device classification result.

4. The method for identifying and analyzing ship network assets and risks according to claim 1, characterized in that: Based on the device classification results, a risk assessment is performed on the network device to obtain a risk level, including: Assigning evaluation indicators of various types of network devices according to the device classification results to obtain indicator assignment results; The risk level is obtained based on the indicator assignment results and the probability of network threat occurrence.

5. The method for identifying and analyzing ship network assets and risks according to claim 1, characterized in that: Based on the device classification results, the relationships between network devices are processed to obtain a device knowledge graph, including: Determine the dependency relationships between network devices based on the device classification results and obtain a logical relationship graph; Determine the geographic location code of the network device based on the device classification result and obtain a spatial relationship map; According to the device classification result, the component composition of the network device is determined to obtain a hierarchical relationship map.

6. The method for identifying and analyzing ship network assets and risks according to claim 5, characterized in that: Based on the device classification results, the dependencies between network devices are determined to obtain a logical relationship graph, including: Obtaining device function service data according to the device classification result; According to the device function service data, the device dependency probability is obtained by using the likelihood probability, prior probability and marginal probability of the device dependency; According to the device dependency probability, a logical relationship graph is obtained.

7. The method for identifying and analyzing ship network assets and risks according to claim 5, characterized in that: According to the device classification result, the geographic location code of the network device is determined to obtain a spatial relationship map, including: Determine the coordinates of the network device in the ship space based on the device classification result to obtain three-dimensional coordinate data of the device; Mapping the three-dimensional coordinate data of the device onto a two-dimensional plane to obtain two-dimensional coordinate data; According to the two-dimensional coordinate data, the geographic location code of the network device is determined to obtain a spatial relationship map.

8. The method for identifying and analyzing ship network assets and risks according to claim 5, characterized in that: According to the device classification results, the relationships between network devices are processed to obtain a device knowledge graph, which also includes: When the device status changes, dynamically calculate the impact of the device status change on the relationship between devices; The device knowledge graph is updated according to the impact scope to obtain an updated device knowledge graph.

9. A ship network asset identification and risk analysis device, characterized in that: include: An acquisition module is used to acquire network device data in various data formats of the ship network; a processing module, configured to perform structured processing on the network device data in a plurality of different data formats to obtain target data; Classifying network devices according to the target data to obtain device classification results; Perform risk assessment on the network device based on the device classification result to obtain a risk level; According to the device classification results, the relationships between network devices are processed to obtain a device knowledge graph; According to the equipment knowledge graph and risk level, risk analysis processing is performed on the ship network equipment assets to obtain a risk analysis processing result.

10. A computing device, characterized in that include: one or more processors; A storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Maritime accident analysis method and system based on knowledge graph, terminal and medium

    CN117933400A

  • Ocean wave disaster defensive area demarcation optimization method based on ship AIS data

    CN119379006A

  • Shipping risk assessment method

    CN119863116A

  • Multi-source data-based power grid knowledge graph construction method

    CN119886298A

  • Method for measuring cybersecurity state of ship, and method for evaluating cybersecurity risk and detecting abnormal sign of ship

    WO2024248529A1