A ship network asset identification and risk analysis method, device and equipment

By acquiring and structuring ship network device data and constructing a device knowledge graph, the limitations of ship network asset identification and risk analysis are overcome, enabling accurate threat assessment and automated risk management, and improving the comprehensiveness and reliability of ship network security management.

CN120450449BActive Publication Date: 2025-12-09CHINESE CLASSIFICATION SOC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510940024.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-12-09
Estimated Expiration
2045-07-09

AI Technical Summary

Technical Problem

Existing technologies lack asset identification and risk analysis solutions for ship network environments, making it impossible to accurately identify dynamically changing network assets and conduct a comprehensive assessment of ship network security risks, resulting in significant security vulnerabilities.

Method used

By acquiring network device data in various formats, performing structured processing and classification, constructing a device knowledge graph, and combining risk assessment with logical and spatial relationships, a comprehensive identification and risk analysis of ship network assets can be achieved.

Benefits of technology

It improves the comprehensiveness of ship network asset identification and the accuracy of threat analysis, and realizes the standardization of valuation and the automation of risk assessment, thus solving the limitations and reliability problems of traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120450449B_ABST
    Figure CN120450449B_ABST
Patent Text Reader

Abstract

The application provides a ship network asset identification and risk analysis method, device and equipment, the method comprises the following steps: acquiring network equipment data of a plurality of different data formats of a ship network; performing structured processing on the network equipment data of a plurality of different data formats to obtain target data; classifying network equipment according to the target data to obtain equipment classification results; performing risk assessment on network equipment according to the equipment classification results to obtain a risk level; processing the relationship between network equipment according to the equipment classification results to obtain an equipment knowledge graph; and performing risk analysis processing on the network equipment assets of the ship according to the equipment knowledge graph and the risk level to obtain a risk analysis processing result. The scheme can improve the comprehensiveness of ship network asset identification and the accuracy of threat analysis, and realize the standardization of assignment evaluation and the automation of risk assessment.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information processing, in particular to a ship network asset identification and risk analysis method, device and equipment. BACKGROUND

[0002] With the improvement of the intelligence and informatization of ships, the ship network system (such as ship automation system, satellite communication system, navigation system, etc.) is increasingly complex, and the security management of network assets (including hardware, software, data, etc.) becomes the key to ensure the safe operation of the ship. However, the existing technology lacks asset identification and risk analysis schemes for the special nature of the ship network environment (such as mobility, heterogeneous network integration, off-shore communication restrictions, etc.), which leads to the inability to accurately identify dynamically changing network assets, making it difficult to comprehensively assess the security risks of the ship network, and there is a great security risk.

[0003] With the deep integration of ship intelligence and informatization, the ship network architecture is becoming increasingly complex, with a large number of electronic devices, control systems and communication systems interwoven. Ship network security has become a key factor in ensuring the safe operation of the ship, and once subjected to network attacks, it is likely to cause catastrophic consequences such as navigation system failure and power system failure. Accurate identification of network assets and scientific assessment of their risks are the basis and core of building a ship network security protection system. However, the diversity and dynamic nature of ship network assets pose a huge challenge to traditional asset identification methods. At the same time, the types and means of network threats are increasingly diverse, and it is urgent to use professional security products to monitor network attack behavior in real time. SUMMARY

[0004] The technical problem to be solved by the present application is to provide a ship network asset identification and risk analysis method, device and equipment. It can improve the comprehensiveness of ship network asset identification and the accuracy of threat analysis, and realize the standardization of assignment evaluation and the automation of risk assessment.

[0005] To solve the above technical problems, the technical solutions of the present application are as follows:

[0006] A ship network asset identification and risk analysis method, comprising:

[0007] Obtaining network device data of multiple different data formats of the ship network;

[0008] Structurally processing the network device data of multiple different data formats to obtain target data;

[0009] Classifying network devices according to the target data to obtain device classification results;

[0010] Risk assessment of network devices according to the device classification results to obtain risk levels;

[0011] According to the device classification result, the relationship between network devices is processed to obtain a device knowledge graph;

[0012] According to the device knowledge graph and the risk level, risk analysis and processing of ship network device assets are performed to obtain a risk analysis and processing result.

[0013] Optionally, the network device data in multiple different data formats is structured to obtain target data, including:

[0014] The network device data is cleaned to obtain intermediate data;

[0015] The intermediate data is converted in format to obtain the target data.

[0016] Optionally, according to the target data, the network devices are classified to obtain a device classification result, including:

[0017] Label information of the devices is extracted from the target data;

[0018] According to the label information, basic probability assignments of each classification result are obtained;

[0019] The basic probability assignments are fused to obtain the device classification result.

[0020] Optionally, according to the device classification result, risk assessment of the network devices is performed to obtain a risk level, including:

[0021] According to the device classification result, evaluation indexes of various network devices are assigned to obtain an index assignment result;

[0022] According to the index assignment result and a network threat occurrence probability, the risk level is obtained.

[0023] Optionally, according to the device classification result, the relationship between network devices is processed to obtain a device knowledge graph, including:

[0024] According to the device classification result, a dependent relationship existing between network devices is determined to obtain a logical relationship graph;

[0025] According to the device classification result, a geographic location code of the network devices is determined to obtain a spatial relationship graph;

[0026] According to the device classification result, a component composition of the network devices is determined to obtain a hierarchical relationship graph.

[0027] Optionally, according to the device classification result, a dependent relationship existing between network devices is determined to obtain a logical relationship graph, including:

[0028] According to the device classification result, device function service data is obtained;

[0029] According to the device function service data, device dependency probability is obtained by using device-dependent likelihood probability, prior probability and marginal probability;

[0030] According to the device dependency probability, a logical relationship graph is obtained.

[0031] Optionally, according to the device classification result, the geographical position code of the network device is determined to obtain a spatial relationship graph, comprising:

[0032] According to the device classification result, the coordinates of the network device in the ship space are determined to obtain device three-dimensional coordinate data;

[0033] The device three-dimensional coordinate data is mapped to a two-dimensional plane to obtain two-dimensional coordinate data;

[0034] According to the two-dimensional coordinate data, the geographical position code of the network device is determined to obtain a spatial relationship graph.

[0035] Optionally, according to the device classification result, the relationship between network devices is processed to obtain a device knowledge graph, further comprising:

[0036] When the device state changes, the influence range of the device state change on the relationship between devices is dynamically calculated;

[0037] According to the influence range, the device knowledge graph is updated to obtain an updated device knowledge graph.

[0038] Embodiments of the present application also provide a ship network asset identification and risk analysis device, comprising:

[0039] The acquisition module is configured to acquire network device data of multiple different data formats of the ship network;

[0040] The processing module is configured to perform structured processing on the network device data of multiple different data formats to obtain target data; according to the target data, the network device is classified to obtain a device classification result; according to the device classification result, the network device is risk evaluated to obtain a risk level; according to the device classification result, the relationship between network devices is processed to obtain a device knowledge graph; and according to the device knowledge graph and the risk level, the ship network device asset is risk analyzed and processed to obtain a risk analysis processing result.

[0041] Embodiments of the present application also provide a computing device, comprising: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, so that the one or more processors implement the ship network asset identification and risk analysis method described in the present application.

[0042] The above technical solutions of the present application have at least the following technical effects:

[0043] The above ship network asset identification and risk analysis method of the present application, by acquiring network equipment data of multiple different data formats of a ship network; structuring the network equipment data of multiple different data formats to obtain target data; classifying network equipment according to the target data to obtain equipment classification results; risk assessment of network equipment according to the equipment classification results to obtain risk levels; processing the relationship between network equipment according to the equipment classification results to obtain equipment knowledge graphs; risk analysis and processing of ship network equipment assets according to the equipment knowledge graphs and risk levels to obtain risk analysis and processing results. The above ship network asset identification and risk analysis method of the present application solves the problems of limitations, disconnection between threats and assets, lack of evaluation standards, and insufficient reliability of risk analysis results in the prior art, and can improve the comprehensiveness of ship network asset identification and the accuracy of threat analysis, and realize the standardization of evaluation and the automation of risk assessment. BRIEF DESCRIPTION OF DRAWINGS

[0044] Figure 1 is a flowchart of the ship network asset identification and risk analysis method of the present application;

[0045] Figure 2 is a schematic diagram of the ship network asset identification and risk analysis device of the present application. DETAILED DESCRIPTION

[0046] Exemplary embodiments of the present application will be described in greater detail below with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be accurately conveyed to those skilled in the art.

[0047] As shown in Figure 1 , embodiments of the present application propose a ship network asset identification and risk analysis method, comprising:

[0048] Step S1, acquiring network equipment data of multiple different data formats of a ship network;

[0049] Step S2, structuring the network equipment data in multiple different data formats to obtain target data;

[0050] Step S3, classifying the network equipment according to the target data to obtain equipment classification results;

[0051] Step S4, risk assessment of the network equipment according to the equipment classification results to obtain a risk level;

[0052] Step S5, processing the relationship between the network equipment according to the equipment classification results to obtain a device knowledge graph;

[0053] Step S6, risk analysis and processing of the ship network equipment assets according to the device knowledge graph and the risk level to obtain a risk analysis and processing result.

[0054] In this embodiment, as Figure 1As shown, in the ship network asset identification and risk analysis method, first, the data of network equipment is collected through various ways and network protocols, the collected network equipment data includes static data and dynamic data, the static data includes equipment model, manufacturer, deployment location and other data, the dynamic data includes ship network equipment communication data collected through simple network management protocol (SNMP), CAN bus, log message protocol (Syslog), transmission control protocol / Internet protocol (TCP / IP protocol) and other heterogeneous network protocols; the data of ship automatic identification system (AIS) is collected through simple network management protocol (SNMP), SNMP is a network management protocol, which can be used to monitor and obtain the state information of network equipment, and the required monitoring parameters such as CPU utilization, memory usage, hard disk space can also be configured, the server data collected through SNMP can monitor the performance and health status of the server, and potential problems can be found and solved in time, at the same time, regular analysis of server data can also help to optimize resource use and plan system upgrade and expansion; the data of ship switch and router is collected through log message protocol (Syslog), Syslog is a standard protocol for storing system logs, which not only defines how to record events, but also specifies how these events should be transmitted over the network, Syslog has the advantages of unified storage, simplified monitoring, universal protocol, consistency, flexible configuration, distributed architecture and the like; the data of ship satellite communication terminal and network flow collection probe is collected through transmission control protocol / Internet protocol (TCP / IP protocol), TCP / IP protocol is the most basic communication protocol in network use, TCP / IP transmission protocol specifies the standard and method of communication between various parts in the Internet, which has wide compatibility, good expansibility and stable reliability; the data of ship environmental sensor is collected through modular communication protocol (Modbus protocol), Modbus protocol is a protocol for communication between master device and slave device, which has the characteristics of openness, simplicity and reliability, and is widely used in programmable logic controller, sensor, instrument and other fields; the data of manual input is collected through electronic spreadsheet (Excel);

[0055] Then, the obtained network equipment data is subjected to structured processing such as data cleaning and format conversion to obtain target data convenient for processing; secondly, the network equipment is classified according to the target data to obtain equipment classification results; thirdly, the relationship between the network equipment is processed to obtain a device knowledge graph, and finally, the ship network equipment asset is subjected to risk analysis processing according to the device knowledge graph and a risk level to obtain a risk analysis processing result, thereby realizing the structured management of the ship network equipment asset; specifically, the network system performs a full-network scan once every 15 minutes, the passive listening module captures traffic data in real time, and the asset database is dynamically updated; the IDS alarm is received in real time, the affected assets are matched through an IP-asset mapping table, and a threat-asset correlation log is generated; the assignment data is updated according to the asset changes and the vulnerability scanning results every month; the risk level is calculated based on the real-time data, and the preset risk level threshold is triggered to push the early warning to the security management platform.

[0056] The scheme of the present application breaks through the isolated management mode of the traditional static account book by constructing a three-dimensional dynamic knowledge graph of the fusion space position, logical dependence and hierarchical relationship of the ship network equipment, realizing real-time self-adaptive adjustment of the asset structure by using incremental update and dynamic weight through a dynamic self-optimization algorithm, and embedding ship field knowledge and intelligent analysis models.

[0057] In an optional embodiment of the present application, in step S2, the network equipment data in multiple different data formats is subjected to structured processing to obtain target data, including:

[0058] In step S21, the network equipment data is subjected to data cleaning to obtain intermediate data.

[0059] In step S22, the intermediate data is subjected to format conversion to obtain target data.

[0060] In the present embodiment, the network equipment data is subjected to structured processing, first, according to the type of the network equipment data, a reasonable threshold range of each parameter data is set, data exceeding the reasonable threshold range is discarded as an abnormal value to prevent the influence of data fluctuation on subsequent data processing, then repeated values and missing values in the network equipment data are found and invalid data such as repeated values and missing values are removed to obtain intermediate data; secondly, the intermediate data is subjected to format conversion, for example, the network rate is 85.62 megabits / second, which is composed of two original data (85 and 62) representing the integer part and the decimal part of the network rate, the system converts the data according to a preset rule, and the value 85.62 is reported to obtain target data.

[0061] In an optional embodiment of the present application, in step S3, the network equipment is classified according to the target data to obtain equipment classification results, including:

[0062] Step S31, extracting the label information of the device from the target data;

[0063] Step S32, obtaining the basic probability assignment of each classification result according to the label information;

[0064] Step S33, fusing the basic probability assignments to obtain the classification result of the device.

[0065] In the embodiment, in the process of classifying the device, multiple device label information is extracted from target data from different sources, including the function label (such as navigation device, communication device, etc.), protocol label (such as TCP / IP, NMEA0183 of marine electronic device format, etc.), location label, manufacturer label, etc. of the device;

[0066] Then, according to the set of all possible label information, an evidence body is constructed for each label, and the label information is converted into the basic probability assignment of the network device belonging to different classification results; for example, for the function label of the device, according to the information such as the instruction manual and operation log of the device, the probability distribution of the device belonging to different function categories is determined; assuming that the probability of a device being judged as a navigation device is 0.8 and the probability of being a communication device is 0.2, an evidence body can be constructed to represent the function classification of the device.

[0067] Finally, the evidence bodies of different labels are fused according to the basic probability assignment, and the fusion formula is:

[0068] wherein m(A) is the fused basic probability distribution, K is the conflict coefficient, representing the conflict degree of two different evidence bodies; B and C represent possible device classification results, and A represents the fused device classification result; the intersection of the characteristics of B and C is A; the basic probability distribution of result B is m(B), the basic probability distribution of result C is m(C);

[0069] Through multiple iterations of fusing the evidence bodies of different labels, the final comprehensive evidence body is obtained; according to the fused comprehensive evidence body, the final classification result of the device is determined; the maximum probability principle can be used, that is, the class with the maximum probability after fusion is selected as the classification result of the device; or a threshold value can be set according to actual needs, and when the probability of a certain class exceeds the threshold value, the device is classified into that class. With the operation of the device and the update of data, new label information is continuously collected, and the classification result of the device is updated and optimized to adapt to the changes of the device state.

[0070] In an optional embodiment of the present application, in step S4, risk assessment is performed on the network device according to the device classification result, and a risk level is obtained, including:

[0071] In step S41, the evaluation indexes of each type of network device are valued according to the device classification result, and an index valuation result is obtained.

[0072] In step S42, a risk level is obtained according to the index valuation result and the network threat occurrence probability.

[0073] In this embodiment, the original threat data (attack type, source / target IP, timestamp, etc.) is obtained through the intrusion detection system (IDS) component built in the network, and the specific assets attacked are located through the IP-asset mapping table (such as "target IP: 192.168.1.10" corresponding to "pilot navigation server").

[0074] The risk level is adjusted based on the asset attribute and asset category, and the attack risk of the III type system is automatically increased by 50%, and the II type is increased by 30%. For example, the DoS attack on the III type propulsion system is marked as "extremely high risk".

[0075] The standardized asset valuation method establishes a valuation index system according to the requirements of ship network security:

[0076] Importance valuation (I): according to the classification of system categories, III is valued as 5 levels, II is valued as 3 levels, and I is valued as 1 level, using the difference value of an arithmetic sequence (tolerance is 2), which is suitable for representing the "equidistant difference" between levels. For example, the host control system (III) is assigned a value of 5, and the cabin lighting (II) is assigned a value of 2.

[0077] Vulnerability valuation (V): combined with the Common Vulnerabilities and Exposures (CVE) vulnerability level (high risk = 5 levels, medium risk = 3 levels, low risk = 1 level), such as assigning a value of 5 to a device with a CVE-2023-1234 high-risk vulnerability.

[0078] Data sensitivity valuation (D): data is classified according to low, medium and high sensitivity, and is valued at 1, 3 and 5 respectively.

[0079] The risk analysis adopts a three-dimensional risk calculation model:

[0080] R = P x (I x V x D)

[0081] Where R is the risk level, P is the threat occurrence probability, I is the importance, V is the vulnerability, and D is the data sensitivity.

[0082] The threat occurrence probability (P) is based on statistical analysis of historical IDS data (such as the frequency of a certain type of attack in the past 30 days).

[0083] Classification criteria: high probability: attacks occur frequently (such as ≥ 15 times in the past 30 days); medium probability: attacks occur occasionally (2-14 times in 30 days); low probability: attacks occur rarely (≤ 1 time in 30 days). High probability P=0.8, medium probability P=0.5, low probability P=0.3, using the difference of arithmetic sequence (tolerance is 0.3), which is suitable for representing the "equidistant difference" between grades.

[0084] Output the visual risk report, mark the high-risk asset list, threat hotspot area and protection priority suggestion.

[0085] In an optional embodiment of the present application, in step S5, according to the device classification result, the relationship between network devices is processed to obtain a device knowledge graph, including:

[0086] Step S51, according to the device classification result, determine the dependency relationship between network devices, and obtain a logical relationship graph;

[0087] Step S52, according to the device classification result, determine the geographic location code of the network device, and obtain a spatial relationship graph;

[0088] Step S53, according to the device classification result, determine the component composition of the network device, and obtain a hierarchical relationship graph.

[0089] In this embodiment, when constructing the knowledge graph of the network device of the ship, the logical relationship graph between devices is obtained through the link layer discovery protocol (LLDP protocol) and the network reasoning model. The LLDP protocol is a protocol that enables devices in the network to discover and advertise state, interaction information; by constructing the ship space network, the device space association is realized based on the geographic location code, and the spatial relationship graph is obtained; by the device function tree level, the component composition of the device is determined, and the hierarchical relationship graph is obtained; the device knowledge graph is constructed in the form of resource description framework (RDF triple), such as (device A, relationship type, device B), and stored in the graph database.

[0090] In an optional embodiment of the present application, in step S51, according to the device classification result, determine the dependency relationship between network devices, and obtain a logical relationship graph, including:

[0091] Step S511, according to the device classification result, obtain device function service data;

[0092] Step S512, according to the device function service data, using the likelihood probability, prior probability and marginal probability of device dependency, obtain the device dependency probability;

[0093] Step S513, according to the device dependency probability, obtain the logical relationship graph.

[0094] In this embodiment, when constructing the logical relationship graph of the ship equipment room, first, according to the target data and the equipment classification result, the running data, log information, configuration information and the like of the equipment are extracted, and these data contain the interaction relationship and the dependency information between the equipment; then, according to the function and the business logic of the equipment, the dependency relationship that may exist between the equipment is preliminarily determined, the topology structure of the network is constructed, and expert knowledge, data mining and the like are used to determine the network structure, for example, according to the design document and experience of the ship network, the connection relationship between the satellite terminal and the switch and the server is determined; the parameter of the network structure is learned using the structured processed data, the conditional probability distribution of each node is calculated, the parameter learning can be performed by using the maximum likelihood estimation, the Bayesian estimation and the like, and the probability of the dependency relationship between the equipment is estimated through a large amount of historical data; when new equipment running data or events occur, the learned network topology is used for dependency reasoning, and the probability change of the dependency relationship between the equipment is calculated; the parameter and the structure of the network are updated according to the reasoning result, so as to adapt to the dynamic change of the equipment state, for example, when a certain switch fails, the dependency relationship probability of the related equipment is updated.

[0095] Specifically, according to the equipment function business data, the likelihood probability of the equipment dependency is obtained, and is represented by P (X|D), wherein P represents the probability, X represents the vector of the feature data, and D is the dependency relationship between the equipment.

[0096] The state data distribution of the dependency relationship between the equipment is a normal distribution, the mean value of the state data is μ, and the variance is σ 2 , wherein, ;

[0097] P (D) is used to represent the prior probability of the dependency relationship.

[0098] P (X) represents the marginal probability of the feature data.

[0099] The probability P (D|X) of the dependency relationship between the equipment is obtained through the formula P (D|X) = P (X|D) P (D) / P (X).

[0100] According to the maximum value of the equipment dependency probability, the dependency relationship between the equipment is determined, and the logical relationship graph is obtained.

[0101] In an optional embodiment of the present application, in step S52, according to the equipment classification result, the geographical position code of the network equipment is determined, and the spatial relationship graph is obtained, including:

[0102] In step S521, according to the equipment classification result, the coordinates of the network equipment in the ship space are determined, and the three-dimensional coordinate data of the equipment is obtained.

[0103] Step S522, mapping the device three-dimensional coordinate data to a two-dimensional plane to obtain two-dimensional coordinate data;

[0104] Step S523, determining the geographic location code of the network device according to the two-dimensional coordinate data to obtain a spatial relationship graph.

[0105] In this embodiment, when constructing the spatial relationship graph of the ship equipment, the ship overall space is first divided into layers according to decks, cabins, cabinets, etc., to construct a hierarchical spatial structure. Specifically, a ship space network of full ship→deck→cabin→cabinet→equipment is constructed.

[0106] For example, the ship is divided into multiple deck layers, each deck layer is further subdivided into several cabins, and each cabin contains multiple cabinets; each hierarchical space unit is assigned a unique identifier, such as deck number, cabin number, cabinet number, etc.

[0107] Then, the precise coordinates of each device in the ship space are determined to obtain three-dimensional coordinate information of the device.

[0108] Secondly, the device three-dimensional coordinate data is mapped to a two-dimensional plane to obtain two-dimensional coordinate data.

[0109] Thirdly, Hilbert curve is used for space coding, and the Hilbert code corresponding to the device on the two-dimensional plane is calculated according to the coordinates of the device on the two-dimensional plane, and the calculation formula is as follows:

[0110] S=

[0111] Wherein, n is the order of Hilbert curve, E j The jth sub-region number is determined by the direction state and the binary bit.

[0112] The traversal order of each hierarchical sub-region is determined by the direction state of the parent region. In this embodiment, a U-shaped direction state rule is adopted to arrange the sub-regions in a clockwise rotation.

[0113] The hierarchical information of the ship space is integrated into the Hilbert code, for example, the deck number, cabin number, etc. information is added as a prefix or suffix to the Hilbert code to form a unique string code, such as “H3_Deck02_R05_03”, wherein “H3” can represent the deck number, “Deck02” represents the second deck, “R05” represents the 5th cabin, and “03” represents the specific position in the cabin. The improved Hilbert code of the device is stored in the graph database as the spatial identifier of the device; an index is established for the Hilbert code to quickly query and locate the position of the device in the ship space, and the spatial query efficiency is improved.

[0114] In an optional embodiment of the present application, step S53, determining the component composition of the network device according to the device classification result, obtaining a hierarchical relationship graph, can include:

[0115] The component composition of the device is determined through the device function tree level (such as: navigation system -> AIS -> antenna), and a hierarchical relationship graph is obtained. The device knowledge graph is constructed in the form of a resource description framework (RDF triple), such as (device A, relationship type, device B), and stored in a graph database.

[0116] In an optional embodiment of the present application, in step S5, according to the device classification result, the relationship between network devices is processed to obtain a device knowledge graph, which further includes:

[0117] Step S54, when the device state changes, dynamically calculating the influence range of the device state change on the relationship between devices;

[0118] Step S55, updating the device knowledge graph according to the influence range to obtain an updated device knowledge graph.

[0119] In this embodiment, when the device state changes, such as device addition, deletion, or attribute change, first calculate the influence range of the device change on the knowledge graph, specify the changed device as the starting node, initialize its shortest path distance to 0 in the graph database, and set the distance attribute of all other nodes to infinity. Add a predecessor node attribute to each node to record the predecessor node on the current shortest path. Initially, only the predecessor node of the starting node points to itself, and the predecessor nodes of other nodes are empty. Use the traversal interface of the graph database to select the node with the smallest distance value from all nodes that have not been marked as "visited" as the current processing node, and mark it as "visited". Traverse all adjacent nodes of the current node, and calculate the total weight of the path through the current node to these adjacent nodes (i.e. the distance of the current node plus the edge weight). If the value is less than the existing distance value of the adjacent node, update the distance and predecessor node attribute of the adjacent node. Repeat this process until all nodes are marked as "visited" or the distance of the target node (such as the business system node affected by the change) no longer changes.

[0120] After the change is executed, the edge weight is updated according to the real-time monitoring data (such as the actual load of the link and the configuration effective state), and the shortest path is recalculated to verify whether the influence range exceeds the expectation, thereby achieving dynamic evaluation. In this process, a dynamic weight algorithm (combined with device importance and change frequency) is used to update the asset structure priority, and the specific formula is as follows: W = α × T + β × F + γ × G;

[0121] Wherein, W represents weight, T represents running time, F represents failure times, G represents associated device number, a is time coefficient, b is failure coefficient, g is association coefficient, and a+b+g=1.

[0122] In an optional embodiment of the application, in step S6, the ship network device asset is subjected to risk analysis processing according to the device knowledge graph and the risk level, and a risk analysis processing result is obtained, including:

[0123] The risk analysis module calculates the risk level based on real-time data and pushes a warning to the safety management platform when a preset risk level threshold is triggered. The risk analysis adjusts the risk level based on asset attributes and asset categories, and the risk of a III-class system attack is automatically increased by 50%, and the risk of a II-class attack is increased by 30%. For example, a DoS attack on a III-class propulsion system is marked as “extremely high risk”. A visual risk report is output, and a high-risk asset list, a threat hotspot area, and a protection priority suggestion are marked.

[0124] The scheme of the application realizes real-time updating of device attributes through automatic collection of multi-source data. The dynamic updating module combines an incremental updating algorithm, calculates the influence range in combination with local refreshing of the graph, and greatly reduces the data updating delay. Multiple labels are fused to realize complex classification, the knowledge graph constructs spatial, logical, and hierarchical relationships, supports fault propagation path analysis (such as switch failure→disruption of 7 terminal devices connected in cascade), and gives the correlation analysis capability. The built-in network flow collection probe collects real-time flow logs through a mirror port, and configures an intrusion detection system rule library to detect flow information in real time, resist fake attacks, and detect abnormal behaviors (graph relationship mutation warning) to locate security events from the network layer to the device level (such as IP→device, ID→cabin), and greatly improve the security response speed. Through the graph database, a dynamic topology (device online→relationship automatically constructed) is automatically generated, the shortest path algorithm is used to calculate the fault influence range in real time, the logical relationship modeling is fused with business data flow (satellite terminal→switch→server), the dynamic weight algorithm is combined to optimize resource scheduling (high-weight devices are preferentially protected), and the topology updating delay is reduced from several hours or days to several minutes.

[0125] The scheme of the application constructs a three-dimensional dynamic knowledge graph of ship network devices (fusing spatial position, logical dependency, and hierarchical relationship), realizes real-time adaptive adjustment of asset structure through a dynamic self-optimization algorithm (incremental updating and dynamic weight), and embeds ship field knowledge and intelligent analysis models to break through the isolated management mode of traditional static accounts.

[0126] The application applies a multi-dimensional structured modeling method of Hilbert space coding fusion network dependent reasoning; adopts a dynamic updating mechanism combined with an incremental updating algorithm and a configurable weight formula; utilizes intelligent application enhanced by domain knowledge; and constructs a ship-specific system architecture of multi-protocol adaptation and security asset linkage. Through four-dimensional protection of methods, systems, data models and scenario-based applications, the fundamental defects of the prior art, such as staticity, isolation and artificial dependence, are solved, and the application is suitable for global ship digitalization demand scenarios.

[0127] As Figure 2 shown, the embodiment of the application also provides a ship network asset identification and risk analysis device 20, comprising:

[0128] An acquisition module 21 is configured to acquire network equipment data in multiple different data formats of a ship network.

[0129] A processing module 22 is configured to perform structured processing on the network equipment data in multiple different data formats to obtain target data; classify network equipment according to the target data to obtain equipment classification results; perform risk assessment on network equipment according to the equipment classification results to obtain a risk level; process the relationship between network equipment according to the equipment classification results to obtain an equipment knowledge graph; and perform risk analysis processing on ship network equipment assets according to the equipment knowledge graph and the risk level to obtain a risk analysis processing result.

[0130] Optionally, the structured processing on the network equipment data in multiple different data formats to obtain target data comprises:

[0131] Data cleaning is performed on the network equipment data to obtain intermediate data.

[0132] Format conversion is performed on the intermediate data to obtain target data.

[0133] Optionally, the classification of network equipment according to the target data to obtain equipment classification results comprises:

[0134] Label information of equipment is extracted from the target data.

[0135] Basic probability assignments of each classification result are obtained according to the label information.

[0136] The basic probability assignments are fused to obtain equipment classification results.

[0137] Optionally, the risk assessment on network equipment according to the equipment classification results to obtain a risk level comprises:

[0138] Evaluation indexes of various network equipment are valued according to the equipment classification results to obtain an index valuation result.

[0139] According to the index assignment result and the network threat occurrence probability, a risk level is obtained.

[0140] Optionally, according to the device classification result, a relationship between network devices is processed to obtain a device knowledge graph, including:

[0141] According to the device classification result, a dependency relationship existing between network devices is determined to obtain a logical relationship graph;

[0142] According to the device classification result, a geographic location code of the network device is determined to obtain a spatial relationship graph;

[0143] According to the device classification result, a component composition of the network device is determined to obtain a hierarchical relationship graph.

[0144] Optionally, according to the device classification result, a dependency relationship existing between network devices is determined to obtain a logical relationship graph, including:

[0145] According to the device classification result, device function service data is obtained;

[0146] According to the device function service data, a device dependency probability is obtained by using a likelihood probability, a prior probability, and a marginal probability of device dependency;

[0147] According to the device dependency probability, a logical relationship graph is obtained.

[0148] Optionally, according to the device classification result, a geographic location code of the network device is determined to obtain a spatial relationship graph, including:

[0149] According to the device classification result, a coordinate of the network device in a ship space is determined to obtain device three-dimensional coordinate data;

[0150] The device three-dimensional coordinate data is mapped to a two-dimensional plane to obtain two-dimensional coordinate data;

[0151] According to the two-dimensional coordinate data, a geographic location code of the network device is determined to obtain a spatial relationship graph.

[0152] Optionally, according to the device classification result, a relationship between network devices is processed to obtain a device knowledge graph, further including:

[0153] When a device state changes, an influence range of the device state change on a relationship between devices is dynamically calculated;

[0154] According to the influence range, the device knowledge graph is updated to obtain an updated device knowledge graph.

[0155] All implementation manners in the method embodiments are applicable to the device embodiments, and the same technical effects can be achieved.

[0156] Embodiments of the present application also provide a computing device, comprising: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the ship network asset identification and risk analysis method described in the present application. All implementation manners in the method embodiments are applicable to the computing device embodiments, and the same technical effects can be achieved.

[0157] Those skilled in the art can understand that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0158] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0159] In the embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented by other ways. For example, the device embodiments described above are only schematic, and the division of units is only a logical function division, and there can be another division way in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different parts can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0160] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0161] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.

[0162] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, and various program code storage media.

[0163] In addition, it should be noted that in the device and method of the present application, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombination should be considered as equivalent solutions of the present application. Moreover, the steps of performing the above series of processes can naturally be executed in time sequence according to the order of description, but do not necessarily have to be executed in time sequence, and some steps can be executed in parallel or independently of each other. It can be understood by those skilled in the art that all or any steps or components of the method and device of the present application can be implemented in hardware, firmware, software or a combination thereof in any computing device (including processors, storage media, etc.) or network of computing devices, which can be implemented by those skilled in the art using their basic programming skills after reading the description of the present application.

[0164] Therefore, the object of the present application can also be achieved by running a program or a set of programs on any computing device. The computing device can be a commonly known general-purpose device. Therefore, the object of the present application can also be achieved by providing a program product containing program code for implementing the method or device. That is, such a program product also constitutes the present application, and a storage medium storing such a program product also constitutes the present application. Obviously, the storage medium can be any commonly known storage medium or any storage medium developed in the future. It should be noted that in the device and method of the present application, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombination should be considered as equivalent solutions of the present application. Moreover, the steps of performing the above series of processes can naturally be executed in time sequence according to the order of description, but do not necessarily have to be executed in time sequence. Some steps can be executed in parallel or independently of each other.

[0165] The above is the preferred embodiment of the present application. It should be noted that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should also be considered within the scope of protection of the present application.

Claims

1. A method of ship network asset identification and risk analysis, characterized by, The method comprises the following steps: acquiring network device data of a plurality of different data formats of a ship network; performing structured processing on the network device data of a plurality of different data formats to obtain target data; classifying network devices according to the target data to obtain a device classification result; performing risk assessment on the network devices according to the device classification result to obtain a risk level; processing the relationship between the network devices according to the device classification result to obtain a device knowledge graph; performing risk analysis processing on the ship network device assets according to the device knowledge graph and the risk level to obtain a risk analysis processing result; wherein the classification of the network devices according to the target data to obtain the device classification result comprises: extracting label information of the devices from the target data; obtaining basic probability assignments of each classification result according to the label information; fusing the basic probability assignments to obtain the device classification result; the fusion formula is: Wherein, m(A) is the basic probability assignment after fusion, K is the conflict coefficient, indicating the conflict degree of two different evidence bodies; B and C represent the possible device classification results, and A represents the device classification result after fusion; The intersection of the features of B and C is A; The basic probability assignment of result B is m(B); The basic probability assignment of result C is m(C). wherein the risk assessment on the network devices according to the device classification result to obtain the risk level comprises: assigning values to evaluation indexes of various network devices according to the device classification result to obtain an index assignment result; obtaining the risk level according to the index assignment result and a network threat occurrence probability; the risk level calculation formula is: R = P x (I x V x D) wherein R is the risk level, P is the threat occurrence probability, I is the importance, V is the vulnerability, and D is the data sensitivity; wherein the processing of the relationship between the network devices according to the device classification result to obtain the device knowledge graph comprises: determining the dependency relationship between the network devices according to the device classification result to obtain a logical relationship graph; determining the geographic location code of the network devices according to the device classification result to obtain a spatial relationship graph; determining the component composition of the network devices according to the device classification result to obtain a hierarchical relationship graph; wherein the determination of the dependency relationship between the network devices according to the device classification result to obtain the logical relationship graph comprises: obtaining device function service data according to the device classification result; obtaining device dependency probability by using the likelihood probability, the prior probability and the marginal probability of device dependency according to the device function service data; obtaining the logical relationship graph according to the device dependency probability; wherein the determination of the geographic location code of the network devices according to the device classification result to obtain the spatial relationship graph comprises: determining the coordinates of the network devices in the ship space to obtain device three-dimensional coordinate data according to the device classification result; mapping the device three-dimensional coordinate data to a two-dimensional plane to obtain two-dimensional coordinate data; determining the geographic location code of the network devices according to the two-dimensional coordinate data to obtain the spatial relationship graph.

2. The method of claim 1, wherein, The structured processing on the network device data of a plurality of different data formats to obtain the target data comprises: performing data cleaning on the network device data to obtain intermediate data; performing format conversion on the intermediate data to obtain the target data.

3. The method of claim 1, wherein, The processing of the relationship between the network devices according to the device classification result to obtain the device knowledge graph further comprises: When the device state changes, the influence range of the device state change on the relationship between devices is dynamically calculated; According to the influence range, the device knowledge graph is updated to obtain an updated device knowledge graph.

4. A marine network asset identification and risk analysis apparatus, characterized by, Comprise: The acquisition module is used for acquiring network device data of multiple different data formats of the ship network; The processing module is used for structuring the network device data of multiple different data formats to obtain target data; According to the target data, the network device is classified to obtain a device classification result; According to the device classification result, the risk of the network device is evaluated to obtain a risk level; According to the device classification result, the relationship between the network devices is processed to obtain a device knowledge graph; according to the device knowledge graph and the risk level, the risk analysis and processing of the ship network device assets are carried out to obtain a risk analysis and processing result; According to the target data, the network device is classified to obtain a device classification result, comprising: From the target data, the label information of the device is extracted; According to the label information, the basic probability assignment of each classification result is obtained; The basic probability assignment is fused to obtain the device classification result; the fusion formula is: wherein m(A) is the basic probability assignment after fusion, K is the conflict coefficient, indicating the conflict degree of two different evidence bodies; B and C represent the possible device classification results, and A represents the device classification result after fusion; the intersection of the features of B and C is A; the basic probability assignment of result B is m(B); the basic probability assignment of result C is m(C). According to the device classification result, the risk of the network device is evaluated to obtain a risk level, comprising: According to the device classification result, the evaluation indexes of various network devices are valued to obtain an index valuation result; According to the index valuation result and the network threat occurrence probability, the risk level is obtained; the risk level calculation formula is: R=P×(I×V×D) Wherein, R is the risk level, P is the threat occurrence probability, I is the importance, V is the vulnerability, and D is the data sensitivity; According to the device classification result, the relationship between the network devices is processed to obtain a device knowledge graph, comprising: According to the device classification result, the dependency relationship existing between the network devices is determined to obtain a logical relationship graph; According to the device classification result, the geographic location code of the network device is determined to obtain a spatial relationship graph; According to the device classification result, the component composition of the network device is determined to obtain a hierarchical relationship graph; According to the device classification result, the dependency relationship existing between the network devices is determined to obtain a logical relationship graph, comprising: According to the device classification result, device function service data is obtained; According to the device function service data, the device dependency probability is obtained by using the likelihood probability, the prior probability and the marginal probability of device dependency; According to the device dependency probability, the logical relationship graph is obtained; According to the device classification result, the geographic location code of the network device is determined to obtain a spatial relationship graph, comprising: According to the device classification result, the coordinates of the network device in the ship space are determined to obtain device three-dimensional coordinate data; The device three-dimensional coordinate data is mapped to a two-dimensional plane to obtain two-dimensional coordinate data; According to the two-dimensional coordinate data, the geographic location code of the network device is determined to obtain a spatial relationship graph.

5. A computing device, comprising: Comprise: One or more processors; a storage device for storing one or more programs, when executed by the one or more processors, cause the one or more processors to implement a method recited in any of claims 1 to 3.

Citation Information

Patent Citations

  • Ocean wave disaster defensive area demarcation optimization method based on ship AIS data

    CN119379006A

  • Shipping risk assessment method

    CN119863116A

  • Multi-source data-based power grid knowledge graph construction method

    CN119886298A