Communication network security auditing method and system under multi-source heterogeneous data association

Through the security audit method of multi-source heterogeneous data association, network traffic, logs and signaling data are collected and analyzed in real time, and a multi-dimensional correlation model is built, which solves the fragmentation and lag problems of traditional security audits, and realizes intelligent security protection and efficient operation and maintenance of communication networks.

CN120455126APending Publication Date: 2025-08-08Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510726866.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

Traditional security audit methods rely on single-dimensional data analysis, resulting in fragmentation of detection and lagging response, insufficient correlation capabilities of multi-source heterogeneous data, making it difficult to deal with complex network security threats.

Method used

Through the multi-source heterogeneous data association method, network traffic data, log data and signaling data are collected and distinguished in real time, deep analysis and classification processing are carried out, multi-dimensional correlation analysis model is built, and a machine learning algorithm is used to mine the spatio-temporal and causal relationships between data to generate an adaptive security audit strategy.

Benefits of technology

It realizes all-round and intelligent security protection for the communication network, quickly identify complex threats, improves network stability and security, reduces operational risks, and improves operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455126A_ABST
    Figure CN120455126A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication network security, in particular to a communication network security auditing method and system under multi-source heterogeneous data association, and the method comprises the steps: collecting network flow data and log data in a communication network in real time; distinguishing non-service flow data and signaling data (also called service flow data) from the collected network flow data; performing deep analysis and classification processing on non-service flow data, performing unified analysis and association analysis on log data, and performing protocol decoding and content analysis on signaling data; constructing a multi-source heterogeneous data association relationship analysis model, integrating non-service flow data, signaling data and log data, mining space-time association and causal relationship among the data by applying a machine learning algorithm, and constructing a network security situation map; and based on a multi-dimensional analysis result, automatically generating a security audit strategy matched with the multi-dimensional analysis result. According to the invention, accurate detection, real-time blocking and risk early warning of communication network security threats are realized, and the network security protection capability and the operation and maintenance efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication network security technology, and in particular to a communication network security audit method and system under multi-source heterogeneous data association, which is used for endogenous security governance of communication networks, such as core network signaling fraud (SS7 / MAP / SIP / Diameter attacks, etc.) and internal threat detection (illegal operations), generating security audit reports and forming risk warnings for post-event tracing and compliance security audits. Background Art

[0002] Security audit technology usually refers to a key means of conducting comprehensive reviews and security assessments of various operations, data flows, network status changes, etc. on network equipment within the scope of information systems. It aims to ensure the security, compliance and stability of information systems, detect potential risks in a timely manner, and provide a strong basis for system security reinforcement and decision-making.

[0003] With the rapid development of network communication technologies, communication networks have become critical infrastructure supporting the functioning of society. Their security faces increasingly severe challenges, with security threats based on signaling protocols becoming a core challenge facing communication networks. Currently, the security situation in core networks is particularly severe. Signaling-layer threat logs are rampant, security incidents caused by unauthorized and illegal operations by insiders are increasing, and complex communication network security threats are becoming increasingly common. These security threats not only jeopardize the stable operation of communication networks but also have the potential to have serious social impacts.

[0004] Traditional security auditing technology mainly uses a single-dimensional detection method, which has obvious limitations. Specifically: (1) Network traffic monitoring equipment only focuses on abnormal fluctuations in traffic data, and detects potential threats through preset thresholds and pattern recognition; (2) Log audit systems mainly analyze device operation logs, including servers, network equipment, security equipment, etc., and identify security risks by tracking event records, operation behaviors, and status changes; (3) Signaling security detection equipment focuses on analyzing the compliance of signaling messages in communication networks to detect possible malicious tampering. These decentralized security audit methods are difficult to cope with the increasingly complex network security threats, resulting in many potential risks in communication networks. Summary of the Invention

[0005] The present invention aims to solve the problems of traditional security audit methods that rely on single-dimensional data analysis, and have the problems of detection fragmentation, response lag, and insufficient ability to associate multi-source heterogeneous data. The present invention proposes a communication network security audit method and system under multi-source heterogeneous data association. By deeply integrating non-business traffic data, log data and signaling message multi-dimensional data, establishing a correlation relationship analysis model between data, and constructing a comprehensive and intelligent security audit system, the present invention can effectively improve the security protection capability of the communication network and provide reliable protection for the stable operation of the communication network.

[0006] In order to achieve the above purpose, the technical solutions adopted are:

[0007] The present invention provides a communication network security audit method under multi-source heterogeneous data association, comprising:

[0008] Collect network traffic data and log data in the communication network in real time through diversified data collection methods;

[0009] Distinguish non-business traffic data and signaling data from the collected network traffic data;

[0010] Conduct in-depth analysis and classification of non-business traffic data, conduct unified analysis and correlation analysis of log data, and perform protocol decoding and content analysis of signaling data;

[0011] Build a multi-source heterogeneous data correlation analysis model, integrate non-business traffic data, signaling data, and log data, use machine learning algorithms to mine the spatiotemporal correlation and causal relationship between data, and build a network security situation map;

[0012] Based on the multi-dimensional analysis results, a suitable security audit strategy is automatically generated.

[0013] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, further, the collection of network traffic data includes: collecting and parsing data packets in the communication link through at least one of port mirroring technology, network probe deployment, SNMP protocol collection, NetFlow technology application and sFlow sampling analysis, analyzing its size, flow direction and rate characteristics, and marking abnormal traffic; the collection of log data includes: collecting device operation logs, system status logs, operation behavior logs and security alarm logs through automatic system log collection and / or shared directory access.

[0014] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, a further method for distinguishing non-business traffic data and signaling data is: using a deep learning model to analyze the protocol characteristics, source / destination addresses and port numbers of data packets to distinguish non-business traffic data and signaling data.

[0015] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, further in-depth analysis and classification processing of non-business traffic data includes:

[0016] Based on protocol feature recognition technology, it can distinguish the specific types of non-business traffic data, including normal non-business traffic data and abnormal non-business traffic data;

[0017] Block detected abnormal non-business traffic data in real time and simultaneously record attack characteristics;

[0018] Implement bandwidth monitoring and QoS policy optimization for normal non-business traffic data to ensure reasonable allocation of network resources.

[0019] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, further, unified parsing and association analysis of log data includes:

[0020] The equipment operation log, system status log, operation behavior log and security alarm log are formatted in a unified manner; time series analysis methods are used to establish temporal correlation relationships between log events; abnormal event logs and normal operation logs are automatically classified and labeled based on key field extraction and pattern recognition technology; a multi-dimensional log correlation model is constructed to identify correlated security events across devices and systems.

[0021] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, further, performing protocol decoding and content parsing on signaling data includes:

[0022] Use the protocol stack analysis engine to perform protocol decoding and multi-dimensional analysis on the collected signaling data to identify the signaling type, message format, message content and interaction process;

[0023] Based on the predefined security policy library, determine whether the signaling is abnormal signaling or normal signaling.

[0024] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, further, the construction of the multi-source heterogeneous data association relationship analysis model includes:

[0025] Establish a time series-based correlation analysis sub-model and calculate the correlation between different data sources in the time dimension using the Pearson correlation coefficient;

[0026] Establish a correlation analysis sub-model based on feature similarity and use the cosine similarity algorithm to quantify the matching degree between non-time series features;

[0027] Design a feature dimension reduction module based on principal component analysis (PCA) to extract features from multi-source data;

[0028] Linear regression model was used to establish the correlation between multivariate data.

[0029] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, a linear regression model is further used to establish the association relationship between multivariate data, and the expression is:

[0030] Y=α1N pca (t)+α2L pca (t)+α3S pca (t)+ε

[0031] Among them, α1, α2, α3 are regression coefficients, ε is the error term, N pca 、L pca 、S pca They are non-business traffic data, log data and signaling data, and Y represents the variable of the communication network security status.

[0032] According to the communication network security audit method under multi-source heterogeneous data association of the present invention, further, based on the multi-dimensional analysis results, automatically generating a security audit strategy adapted thereto specifically includes:

[0033] Based on the threat level assessment results, security audit policies are matched from the preset policy library, including traffic cleaning, signaling blocking, and permission control.

[0034] Furthermore, the present invention also provides a communication network security audit system under multi-source heterogeneous data association, which is used to implement the above-mentioned communication network security audit method under multi-source heterogeneous data association, including:

[0035] The data collection module is used to collect network traffic data and log data in the communication network in real time through diversified data collection methods;

[0036] Traffic diversion module, used to distinguish non-business traffic data and signaling data from the collected network traffic data;

[0037] The data processing module is used to perform in-depth analysis and classification of non-business traffic data, unified analysis and correlation analysis of log data, and protocol decoding and content analysis of signaling data;

[0038] The intelligent analysis module is used to build a multi-source heterogeneous data correlation analysis model, integrate non-business traffic data, signaling data, and log data, and use machine learning algorithms to mine the spatiotemporal correlation and causal relationship between data to build a network security situation map;

[0039] The security application module is used to automatically generate a security audit strategy that is adapted to the results of multi-dimensional analysis.

[0040] The beneficial effects achieved by adopting the above technical solution are:

[0041] (1) Multi-dimensional data fusion and analysis capabilities

[0042] This invention innovatively integrates multi-source heterogeneous data, such as non-business traffic data, log data, and network signaling messages, breaking through the limitations of traditional single-dimensional auditing. By constructing an analysis model for the correlation relationship between data, a comprehensive perception of the security situation of the communication network is achieved. Specifically: Network traffic analysis can monitor data transmission characteristics in real time, such as key parameters such as packet size, flow direction, and transmission rate, and effectively identify abnormal traffic patterns. Equipment log auditing can comprehensively track the operating status of equipment, including hardware indicators, resource usage, and operation records, providing a reliable basis for fault diagnosis.

[0043] (2) Multi-dimensional signaling feature analysis capabilities

[0044] The abnormal signaling detection of the core network of the communication network of the present invention is intended to identify fraudulent behaviors in the signaling protocol in real time (such as illegal positioning, billing tampering), block internal unauthorized operations, prevent risks such as user privacy leakage and roaming fraud, and ensure network reliability and operator business security. Specifically: real-time analysis of the core network signaling protocol, extraction of key features including abnormal call frequency, atypical routing paths, illegal parameter tampering, etc., and construction of a signaling behavior baseline model. Correlate signaling data, establish an end-to-end signaling tracking chain, and identify cross-protocol and cross-network element coordinated attacks. Integrate real-time blocking and policy linkage mechanisms to handle high-risk signaling, and automatically trigger network configuration reinforcement to form a closed-loop security protection and audit system of detection-blocking-repair.

[0045] (3) Intelligent data association analysis mechanism

[0046] This invention uses advanced correlation analysis methods to establish a dynamic correlation model between multi-source data. Through time series analysis, it accurately matches the temporal correlation between network traffic anomalies and device operations. It also uses feature extraction technology to identify the inherent connection between signaling anomalies and traffic fluctuations.

[0047] (4) Efficient real-time auditing capabilities

[0048] The security audit of the present invention has the following outstanding features: it adopts a distributed probe deployment solution to achieve real-time collection and pre-processing of data from the entire network, and provides a visual audit interface to intuitively display security status and threat intelligence.

[0049] (5) Powerful security protection function

[0050] This invention demonstrates excellent security protection capabilities in key scenarios such as the core network of communication networks: it can quickly identify complex threats such as DDoS attacks and signaling storms; support automated security policy generation and emergency response; and provide fine-grained access control and security reinforcement recommendations.

[0051] (6) Significant application value

[0052] The implementation of this invention will bring significant social and economic benefits: improving the security protection level of communication networks and reducing the incidence of security incidents; shortening troubleshooting time and improving operation and maintenance efficiency; meeting compliance requirements and reducing operational risks; and providing reliable guarantees for the stable operation of communication networks.

[0053] Through the above innovative design, the present invention effectively solves the problems of fragmentation and lag in traditional security auditing methods, provides strong technical support for the security operation of communication networks, and has broad application prospects and promotion value. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings of the embodiments of the present invention. The drawings are only used to illustrate some embodiments of the present invention, but not to limit all embodiments of the present invention thereto.

[0055] Figure 1 This is one of the flow diagrams of the communication network security audit method under multi-source heterogeneous data association according to an embodiment of the present invention;

[0056] Figure 2 This is the second flow chart of the communication network security audit method under multi-source heterogeneous data association according to an embodiment of the present invention. DETAILED DESCRIPTION

[0057] The following will be combined with the accompanying drawings of specific embodiments of the present invention to clearly and completely describe the exemplary embodiments of the present invention. Unless otherwise defined, technical or scientific terms used in the present invention should be given the common meanings understood by people with ordinary skills in the relevant field.

[0058] like Figure 1 and Figure 2 As shown, this embodiment discloses a communication network security audit method under multi-source heterogeneous data association, which adopts multi-source heterogeneous data association relationship processing technology and includes the following steps:

[0059] Step S101: Collect network traffic data and log data in the communication network in real time through diversified data collection methods.

[0060] This solution adopts a diversified data collection solution to ensure the comprehensiveness and real-time nature of data acquisition. For the extraction of network traffic data:

[0061] ① Port mirroring technology captures traffic by copying port data from a switch or router to a monitoring port; ② Network probe deployment uses a serial connection to directly capture link-layer traffic; ③ SNMP protocol collection receives traffic statistics proactively reported by network devices; ④ NetFlow technology is applied to collect flow characteristics output by routers and other devices; ⑤ sFlow sampling and analysis uses random sampling to obtain representative traffic data. These various data collection methods complement each other to ensure the integrity and reliability of the data source. These technologies collect network traffic data from communication links in real time, accurately capture and parse passing data packets, analyze key indicators such as size, direction, and rate, and automatically flag abnormal traffic.

[0062] Log data extraction: ① Automatically collect system logs and configure devices for standardized log output; ② Directly read device-stored log files through shared directory access. By collecting multi-source log data from devices, systems, and operational processes, we analyze log data to monitor operational status, parse system logs to assess overall health, organize operation logs to track manual operations, and integrate alarm logs to quickly locate abnormal events.

[0063] Step S102: Distinguish the collected network traffic data into non-business traffic data and signaling data.

[0064] Utilizing deep learning models (such as GNN, Transformer, and LSTM), we achieve precise traffic classification and targeted transmission. This model analyzes key information such as packet protocol characteristics, source / destination addresses, and port numbers, combined with traffic behavior pattern recognition technology (dynamic characteristics of traffic in time, space, and interactions), to accurately distinguish between non-business traffic data and signaling data (also known as business traffic data).

[0065] Based on pre-set traffic diversion strategies, different types of data are directed to dedicated processing channels: non-business traffic data is transmitted to the monitoring and analysis module, signaling data is sent to the signaling processing center, and log data is stored on distributed log servers. The system supports dynamic policy adjustment, automatically optimizing diversion rules based on network status to ensure processing efficiency.

[0066] Step S103: Perform in-depth analysis and classification processing on non-business traffic data.

[0067] Based on protocol feature recognition technology, it accurately distinguishes the specific types of non-business traffic data, including normal non-business traffic data (such as management traffic) and abnormal non-business traffic data (such as attack traffic: DDoS attacks, port scans, malware communications).

[0068] Implement bandwidth monitoring and QoS guarantee for normal non-business traffic data to optimize network resource allocation.

[0069] Abnormal non-business traffic data is blocked in real time, and attack signatures are simultaneously recorded to provide data support for security analysis. Specifically, by analyzing trace information in non-business traffic data, we deeply explore the behavioral characteristics of packets during attack stages such as penetration, implantation, persistence, lateral spread, theft, tampering, leakage, and illegal external connections. We also correlate and analyze location information, domain name characteristics, operational instructions, packet fingerprints, and other suspicious operations on the communication network. The system supports custom rules, allowing flexible adjustment of processing strategies based on business needs.

[0070] Step S104: performing unified parsing and correlation analysis on the log data.

[0071] The equipment operation log, system status log, operation behavior log and security alarm log are formatted in a unified manner.

[0072] The time series analysis method is used to establish the temporal correlation between log events.

[0073] The system automatically parses log formats, extracting key fields such as timestamp, event type, and operation object. Using pattern recognition technology, it distinguishes normal operation logs from abnormal event logs. Root cause analysis is performed on abnormal event logs, enabling rapid location and resolution. Normal operation logs are used for business statistics and trend analysis. The system provides log compression and archiving capabilities to optimize storage resource utilization.

[0074] Based on time-series correlation, a multi-dimensional log correlation model is established to identify cross-device and cross-system correlated security events, deeply explore potential risks and abnormal patterns, and automatically filter redundant data.

[0075] Step S105: perform protocol decoding and content analysis on the signaling data.

[0076] A protocol stack parsing engine is used to decode and parse collected signaling data (SS7, MAP, SIP, and Diameter protocols), accurately identifying signaling type, message format, message content, and interaction process, and establishing a signaling interaction trajectory. Based on a predefined security policy library, the system determines whether signaling is abnormal or normal. Abnormal signaling (such as illegal access and signaling storms) is reported and recorded in real time. Normal signaling is used for network performance analysis and troubleshooting. Processing results are stored in a distributed database, supporting rapid retrieval and correlation analysis.

[0077] Step S106: Construct a multi-source heterogeneous data correlation analysis model, integrating the processing results of steps S103, S104, and S105, integrating non-business traffic data, signaling data, and log data. Eliminate data silos through pre-processing such as data cleaning and format conversion. Apply machine learning algorithms (such as structural causal models (SCM)) to explore the spatiotemporal correlations and causal relationships between data, construct a complete network security situation map, and accurately identify potential threat chains. The analysis results are used in scenarios such as risk warning and attack tracing, providing data support for security decision-making.

[0078] By integrating the multi-dimensional correlation between non-business traffic data, log data, and network signaling messages, a mathematical model for analyzing the correlation between non-business traffic data, device operation logs, and network signaling data is constructed from the aspects of data representation, correlation measurement, feature extraction, and integration. The specific steps are as follows:

[0079] ①Data model

[0080] Non-business traffic data is N(t)=[n1(t),n2(t),...,n k (t)], N(t) is a vector containing characteristics such as packet size, flow direction, transmission rate, etc., n i (t) represents the value of the i-th non-business traffic characteristic time t.

[0081] The log data is L(t)=[l1(t),l2(t),...,l m (t)], L(t) is a vector containing features such as equipment logs, service logs, alarm logs, and operation logs of the communication network. j (t) represents the value of the jth log feature at time t.

[0082] The network signaling data is S(t)=[s1(t),s2(t),...,s m (t)], S(t) is a vector containing features such as signaling type, message content, interaction process, etc. k (t) represents the value of the kth log feature at time t.

[0083] ② Association measurement

[0084] The multi-dimensional correlation measurement between non-business traffic data, log data and network signaling messages is mainly used for correlation analysis from the two dimensions of time correlation and feature similarity.

[0085] Time correlation measurement: Pearson correlation coefficient is used to measure the correlation of different data sources in time series. For non-business traffic data N(t) and log data L(t), the time correlation coefficient r NL The expression is as follows:

[0086]

[0087] in, and are the mean values of N(t) and L(t) in the time interval [1, T].

[0088]

[0089] Feature similarity measurement: For non-time series features, cosine similarity is used to measure the similarity between features. A feature n of non-business traffic data N(t) i (t) and a certain feature s of the network signaling data S(t) k Cosine similarity between (t) where n i .s k is the vector n i and s k The dot product of ||n i || and ||s k || are their norms respectively.

[0090] ③ Feature extraction and integration

[0091] Principal Component Analysis (PCA): PCA is performed on non-business traffic data N(t), log L(t), and signaling data S(t) to reduce the data dimension and extract the main features. After PCA processing, the principal component of non-business traffic data is expressed as N pca (t), the principal component of the log data is represented by L pca (t), the principal component of the signaling data is represented by S pca (t).

[0092] Construct a comprehensive correlation matrix: Based on the time correlation and feature similarity measurement results, construct a comprehensive correlation matrix A, where A ij Indicates the degree of correlation between the i-th data source (non-business traffic, logs, network signaling) and the j-th data source.

[0093] ④ Association model

[0094] A linear regression model is used to establish the correlation between multi-source data. Let Y be a variable representing the security status of the communication network (such as risk level score), then: Y = α1N pca (t)+α2L pca (t)+α3P pca (t)+ε.

[0095] Where α1, α2, and α3 are regression coefficients, and ε is the error term. The regression coefficients are estimated by minimizing the sum of squared errors, thereby obtaining a quantitative correlation model between multi-source data and the security status of the communication network. The regression coefficients α1, α2, and α3 need to consider the correlation weights of each data source in the correlation matrix A. Strongly correlated data sources (such as A 12 High) may be assigned a higher weight in the model to reflect its significant impact on the security status Y.

[0096] To significantly enhance the system's computing power, this solution utilizes distributed computing and parallel processing technologies. Distributed computing breaks down large data processing tasks and distributes them to multiple computing nodes for collaborative execution. Parallel processing allows multiple tasks to proceed simultaneously, significantly reducing processing time and greatly improving the efficiency of data analysis and processing.

[0097] To ensure data quality, we introduced sophisticated data quality inspection and cleansing algorithms. Based on the business flow table records, we implemented a series of key data processing procedures. Denoising effectively filters out noise interference in the data, improving its accuracy and reliability. Interpolation technology appropriately fills in missing data to ensure data integrity. Through data fusion, heterogeneous data from different sources is integrated to explore potential connections between data. In the correlation relationship detection and analysis phase, we use chain detection methods to sort out the connectivity of heterogeneous data, clarify the interconnectedness between complex data, and lay a solid foundation for subsequent analysis.

[0098] Data mining techniques are used to conduct in-depth analysis of data. Through in-depth analysis and mining, various abnormal behaviors can be accurately identified. For example, unauthorized behavior detection prevents users from illegally accessing data beyond their authorized permissions; fragmented threat detection promptly detects scattered, abnormal data fragments that may pose a security threat; illegal external connection detection effectively blocks unauthorized external connections within the network; and abnormal signaling detection focuses on anomalies in communication signaling to ensure the normal operation of the communication network. These analysis results provide strong support for decision-making support systems, providing decision makers with comprehensive and accurate information to help them make scientific and reasonable decisions and ensure the secure, stable, and efficient operation of the communication network.

[0099] Step S107: Based on the multi-dimensional analysis results, automatically generate a security audit strategy that is adapted thereto.

[0100] Based on multi-dimensional analysis of non-business traffic characteristics, system log traces, and signaling behavior patterns, an intelligent policy engine dynamically generates adaptive security audit policies, including measures such as traffic cleaning, signaling blocking, and permission management. By assessing network security status in real time, combined with a predefined security rule base and machine learning models, audit policy parameters are automatically optimized to rapidly identify new threats and adapt policies, ensuring comprehensive and timely security audits.

[0101] Corresponding to the above method, this embodiment also discloses a communication network security audit system under multi-source heterogeneous data association, including:

[0102] The data collection module is used to collect network traffic data and log data in the communication network in real time through diversified data collection methods.

[0103] The traffic diversion module is used to distinguish non-business traffic data and signaling data from the collected network traffic data.

[0104] The data processing module is used to perform in-depth analysis and classification of non-business traffic data, unified analysis and correlation analysis of log data, and protocol decoding and content analysis of signaling data.

[0105] The intelligent analysis module is used to build a multi-source heterogeneous data correlation analysis model, integrate non-business traffic data, signaling data and log data, use machine learning algorithms to mine the spatiotemporal correlation and causal relationship between data, and build a network security situation map.

[0106] The security application module is used to automatically generate a security audit strategy that is adapted to the results of multi-dimensional analysis.

[0107] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the above-described embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-described embodiments within the technical scope disclosed by the present invention, or replace some of the technical features therein with equivalents. Such modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

Claims

1. A communication network security audit method under multi-source heterogeneous data association, characterized by: Include: Collect network traffic data and log data in the communication network in real time through diversified data collection methods; Distinguish non-business traffic data and signaling data from the collected network traffic data; Conduct in-depth analysis and classification of non-business traffic data, conduct unified analysis and correlation analysis of log data, and perform protocol decoding and content analysis of signaling data; Build a multi-source heterogeneous data correlation analysis model, integrate non-business traffic data, signaling data, and log data, use machine learning algorithms to mine the spatiotemporal correlation and causal relationship between data, and build a network security situation map; Based on the multi-dimensional analysis results, a suitable security audit strategy is automatically generated.

2. The communication network security audit method under multi-source heterogeneous data association according to claim 1 is characterized in that: The collection of network traffic data includes: collecting and parsing data packets in the communication link through at least one of port mirroring technology, network probe deployment, SNMP protocol collection, NetFlow technology application and sFlow sampling analysis, analyzing their size, flow direction and rate characteristics, and marking abnormal traffic; the collection of log data includes: collecting device operation logs, system status logs, operation behavior logs and security alarm logs through automatic system log collection and / or shared directory access.

3. The communication network security audit method under multi-source heterogeneous data association according to claim 1 is characterized in that: The method for distinguishing non-business traffic data from signaling data is to use a deep learning model to analyze the protocol characteristics, source / destination addresses and port numbers of data packets to distinguish non-business traffic data from signaling data.

4. The communication network security audit method under multi-source heterogeneous data association according to claim 1 is characterized in that: In-depth analysis and classification of non-business traffic data include: Based on protocol feature recognition technology, it can distinguish the specific types of non-business traffic data, including normal non-business traffic data and abnormal non-business traffic data; Block detected abnormal non-business traffic data in real time and simultaneously record attack characteristics; Implement bandwidth monitoring and QoS policy optimization for normal non-business traffic data to ensure reasonable allocation of network resources.

5. The communication network security audit method under multi-source heterogeneous data association according to claim 2 is characterized in that: Unified parsing and correlation analysis of log data includes: The equipment operation log, system status log, operation behavior log and security alarm log are formatted in a unified manner; time series analysis methods are used to establish temporal correlation relationships between log events; abnormal event logs and normal operation logs are automatically classified and labeled based on key field extraction and pattern recognition technology; a multi-dimensional log correlation model is constructed to identify correlated security events across devices and systems.

6. The communication network security audit method under multi-source heterogeneous data association according to claim 1 is characterized in that: Protocol decoding and content analysis of signaling data include: Use the protocol stack analysis engine to perform protocol decoding and multi-dimensional analysis on the collected signaling data to identify the signaling type, message format, message content and interaction process; Based on the predefined security policy library, determine whether the signaling is abnormal signaling or normal signaling.

7. The communication network security audit method under multi-source heterogeneous data association according to claim 1 is characterized in that: The construction of the multi-source heterogeneous data association relationship analysis model includes: Establish a time series-based correlation analysis sub-model and calculate the correlation between different data sources in the time dimension using the Pearson correlation coefficient; Establish a correlation analysis sub-model based on feature similarity and use the cosine similarity algorithm to quantify the matching degree between non-time series features; Design a feature dimension reduction module based on principal component analysis (PCA) to extract features from multi-source data; Linear regression model was used to establish the correlation between multivariate data.

8. The communication network security audit method under multi-source heterogeneous data association according to claim 7 is characterized in that: The linear regression model is used to establish the correlation between multivariate data, and the expression is: Y=α1N pca (t)+α2L pca (t)+α3S pca (t)+e Among them, α1, α2, α3 are regression coefficients, ε is the error term, N pca 、L pca 、S pca They are non-business traffic data, log data and signaling data, and Y represents the variable of the communication network security status.

9. The communication network security audit method under multi-source heterogeneous data association according to claim 1 is characterized in that: Based on the multi-dimensional analysis results, the automatically generated adaptive security audit strategy includes: Based on the threat level assessment results, security audit policies are matched from the preset policy library, including traffic cleaning, signaling blocking, and permission control.

10. A communication network security audit system under multi-source heterogeneous data association, characterized in that: A communication network security audit method for implementing multi-source heterogeneous data association according to any one of claims 1 to 9, comprising: The data collection module is used to collect network traffic data and log data in the communication network in real time through diversified data collection methods; Traffic diversion module, used to distinguish non-business traffic data and signaling data from the collected network traffic data; The data processing module is used to perform in-depth analysis and classification of non-business traffic data, unified analysis and correlation analysis of log data, and protocol decoding and content analysis of signaling data; The intelligent analysis module is used to build a multi-source heterogeneous data correlation analysis model, integrate non-business traffic data, signaling data, and log data, and use machine learning algorithms to mine the spatiotemporal correlation and causal relationship between data to build a network security situation map; The security application module is used to automatically generate a security audit strategy that is adapted to the results of multi-dimensional analysis.

Citation Information

Cited By

  • Safety audit and high-risk event mining method and system based on TDS protocol log and flow control

    CN121037110A

  • Security audit and high-risk event mining method and system based on TDS protocol log and flow control

    CN121037110B

  • A network security platform collaborative protection system and method

    CN122513205A