Trusted situation defense method for university data centers based on virtual simulation trapping environment

By building a virtual simulation trapping environment in university data centers, using clustering and association rule mining technology and Markov chain modeling, and dynamically adjusting defense strategies, we solved the problem that traditional detection methods are difficult to identify complex network attacks, and achieved real-time situational defense and security and stability in university data centers.

CN120524436BActive Publication Date: 2025-09-16CHANGCHUN UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511013040.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-09-16
Estimated Expiration
2045-07-23

AI Technical Summary

Technical Problem

University data center networks are large and complex, and traditional detection methods are unable to accurately capture attack patterns, and cannot achieve efficient and accurate attack behavior identification and real-time situational awareness and defense.

Method used

Based on a virtual simulation trapping environment, clustering and association rule mining techniques are used to construct a training sample set. Combined with Markov chain modeling and risk assignment, the defense strategy is dynamically adjusted, and session information is collected in real time for quantitative evaluation.

Benefits of technology

It realizes real-time situational defense for university data centers, can quickly process and analyze network threats, and ensure safe and stable operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120524436B_ABST
    Figure CN120524436B_ABST
Patent Text Reader

Abstract

The present invention discloses a trusted situation defense method for university data centers based on a virtual simulation trapping environment, specifically relating to the field of simulation trapping technology. The method includes synchronously collecting normal session data in a real environment and known session data identified in a trapping environment, constructing a labeled training sample set, and using clustering and association rule mining techniques to collect behavioral information of the latest sessions. The method includes adopting the FP-Growth association rule mining algorithm to extract frequently occurring attack behavior features to form frequent item sets. The method also uses Markov chain modeling and risk assignment to collect risk information of the latest sessions. The method includes constructing a normal Markov model and an attack Markov model, analyzing the Markov model biased towards the latest session state sequence, fusing and quantitatively evaluating the behavioral information and risk information of the latest sessions, and dynamically adjusting the defense strategy. The present invention facilitates rapid session processing and real-time analysis, ensuring the safe and stable operation of university data centers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of simulation trapping, and more particularly to a trusted situation defense method for a university data center based on a virtual simulation trapping environment. Background Art

[0002] With the continuous advancement of informatization, university data centers are responsible for multiple critical tasks, including teaching, scientific research, and management, placing increasing demands on the security and stability of their network environments. University data center networks are large, with diverse services, complex business interactions, and a large amount of real-world access traffic from faculty and students. Traditional single-dimensional detection methods struggle to accurately capture the diverse, covert, and complex nature of network attacks, making it difficult to extract the frequent characteristics and complex sequence information of attack behaviors for efficient and accurate attack identification. Furthermore, they struggle to ensure real-time situational awareness and defensive response capabilities.

[0003] In order to solve the above-mentioned defects, a technical solution is now provided. Summary of the Invention

[0004] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a trusted situation defense method for a university data center based on a virtual simulation trapping environment to solve the problems raised in the above-mentioned background technology.

[0005] To achieve the above object, the present invention provides the following technical solutions:

[0006] The trusted situation defense method for university data centers based on a virtual simulation trapping environment specifically includes the following steps:

[0007] S1: Simulate the real network topology of a university data center, deploy typical business services, and simultaneously collect normal session data from the real environment and known session data identified in the trapping environment to construct a labeled training sample set.

[0008] S2: Use clustering and association rule mining techniques to collect behavioral information from recent sessions, including the FP-Growth association rule mining algorithm to extract frequently occurring attack behavior features and form frequent item sets.

[0009] S3: Use Markov chain modeling and risk assignment to collect risk information for the latest session. This includes constructing normal and attack Markov models, and analyzing the Markov model's bias toward the latest session state sequence.

[0010] S4: The behavioral information and risk information of the latest session are integrated and quantitatively evaluated. Based on risk signals of different levels, the defense strategy is dynamically adjusted to adapt to different levels of security threats.

[0011] In a preferred embodiment, the behavior information and risk information of the latest session include:

[0012] In the offline preparation phase, log data of normal conversations in the real environment and known conversations in the virtual simulation trapping environment are collected. The log data of known conversations are used as training data, and the latest conversations from the university data center are received in real time. The behavior information and risk information of the latest conversations are collected, and the behavior information of the latest conversations are represented by the attack importance index, and the risk information of the latest conversations are represented by the complexity risk coefficient and the data access risk coefficient. is the attack importance index of the latest session, is the complexity risk coefficient, is the data access risk factor.

[0013] In a preferred embodiment, the acquisition logic of the attack importance index is:

[0014] During the offline preparation phase, we collected log data from both normal conversations in a real-world environment and known attack conversations in a virtual simulation trapping environment. We labeled each conversation "normal" and "attack" and unified the timestamp. After data cleaning, we constructed a training set and extracted the attribute features of each conversation, including time, location, protocol type, and traffic volume. We then fused the time, location, and traffic features of each conversation and performed L2 normalization to generate a high-dimensional feature vector.

[0015] Based on the labels and silhouette coefficients of each conversation in the training set, the clustering results are evaluated to determine the optimal cluster model;

[0016] By using association rule mining technology, the discrete attributes of the attack sessions in each cluster are extracted. The FP-Growth algorithm is used to mine frequent itemsets in each cluster to determine the potential association relationships of the sessions in each cluster.

[0017] Determine the frequent itemsets in the session and calculate the support of the frequent itemsets in the session. The calculation formula is: ; Among them, ZCD is the support of the frequent itemset of the session, SL is the number of sessions with frequent itemsets in the attack session, and ZSL is the total number of attack sessions;

[0018] Based on the latest conversation received by the university data center during the online phase, the standardized high-dimensional feature vector of the latest conversation is determined, and the maximum similarity between the latest conversation and the attack conversation in the training set is calculated as the relevance of the latest conversation;

[0019] After dimensionality reduction using the t-SNE algorithm, the distance between the latest session and the cluster center of each attack session cluster in the offline preparation phase is calculated, and the minimum value is taken to obtain the security level of the latest session.

[0020] Based on the frequent itemsets in the offline preparation phase, determine the frequent itemsets in the latest session, calculate the support of the frequent itemsets in the latest session, and calculate the attack importance index using the formula. The calculation formula for the attack importance index is: ;in, is the relevance of the latest session, is the support of the latest session frequent itemset, For the security of the latest session, is a constant.

[0021] In a preferred embodiment, the logic for obtaining the complexity risk coefficient is:

[0022] According to the common session types and operations in university data centers, the key operations in the session are abstracted into a finite number of states based on known sessions. Each state represents a key interaction. The state set S is defined based on the session in the offline preparation phase. ,in, Different states are created, and the states in the session are arranged in chronological order, mapping each session into a state sequence;

[0023] In the offline preparation phase, the state sequence of the normal session and the state sequence of the attack session are determined. The number of occurrences of each pair of adjacent states in the state sequence set of all normal sessions is counted as the number of transitions in the normal session. The number of occurrences of each pair of adjacent states in the state sequence set of all attack sessions is counted as the number of transitions in the attack session. The conditional probability of state transition is obtained by normalizing the number of transitions. The transition probability matrices of the normal Markov model and the attack Markov model are constructed. The transition probability matrix of the normal Markov model is marked as: , mark the transition probability matrix of the attack Markov model as: , where i, j are the indices of the states in the state set, ranging from 1, 2, 3, ..., n;

[0024] Based on the transition probability matrices of the normal Markov model and the attack Markov model, the steady-state distributions of the normal Markov model and the attack Markov model are solved and marked as: H and ;

[0025] The entropy rates of the normal Markov model and the attack Markov model are calculated respectively. The entropy rate calculation formula of the normal Markov model is: , the entropy rate calculation formula of the attack Markov model is: ;in, is the entropy rate of the normal Markov model, is the steady-state probability of the ith state of the steady-state distribution of the normal Markov model, is the entropy rate of the attack Markov model, is the steady-state probability of the ith state of the steady-state distribution of the attack Markov model;

[0026] According to the latest session received by the university data center during the online phase, the state sequence of the latest session is determined and marked as: , where t is the number of the latest session, 1, 2, 3, ..., m is the state sequence number of different sessions;

[0027] Based on the normal Markov model determined in the offline preparation phase, the probability of each state transition in the state sequence of the latest session is obtained, and the cross entropy between the latest session and the normal Markov model is calculated. The calculation formula is: ;in, is the cross entropy between the latest session and the normal Markov model, g is the number of the state in the latest session state sequence, are all adjacent state pairs in the latest session state sequence, In the normal Markov model, Transfer to state The conditional probability of

[0028] Calculate the cross entropy between the latest session and the attack Markov model. The calculation formula is: ;in, is the cross entropy between the latest session and the attack Markov model, To attack the Markov model from the state Transfer to state The conditional probability of

[0029] Calculate the complexity risk coefficient using the following formula: .

[0030] In a preferred embodiment, the logic for obtaining the data access risk coefficient is:

[0031] During the offline preparation phase, we collect log data from both normal conversations in real environments and known conversations in a virtual simulation trapping environment. We then construct a training sample set, define the modal characteristics of the conversations, assign risk scores to the features of the known conversations in different modalities, standardize the features of each modality, and introduce modal weight parameters for different modalities. During the risk scoring process, we use a regression model to train a risk scoring function and output a risk score for each conversation based on each feature dimension.

[0032] Based on the latest conversations received by the university data center during the online phase, the corresponding eigenvalues ​​of the latest conversations in each modality are determined. Combined with the regression scoring function and modal weight parameters constructed during the offline phase, the risk scores of the latest conversations in each modality are assigned separately. The data access risk coefficient of the latest conversation is calculated according to the formula: ; Where k = 1, 2, 3, ..., K, K is a positive integer representing the total number of modes, k is the mode number, is the weight of the kth mode, and the weight satisfies the normalization constraint. Score the risk under the k-th mode.

[0033] In a preferred embodiment, the behavior information and risk information of the latest session are integrated and quantitatively evaluated, including:

[0034] Through comprehensive analysis of the latest session's behavioral information and risk information, the attack importance index, complexity risk coefficient, and data access risk coefficient of the latest session are weighted and summed to build a trustworthy situation assessment model and generate a trustworthy situation assessment coefficient. The calculation formula for the trustworthy situation assessment coefficient is: ;in, is the credible situation assessment coefficient, 、 、 are the proportional coefficients of attack importance index, complexity risk coefficient and data access risk coefficient, respectively. 、 、 Both are greater than 0.

[0035] In a preferred embodiment, the defense strategy is dynamically adjusted based on risk signals of different levels, including:

[0036] Setting a first trustworthy situation assessment coefficient threshold and a second trustworthy situation assessment coefficient threshold, where the first trustworthy situation assessment coefficient threshold is greater than the second trustworthy situation assessment coefficient threshold, collecting the latest conversations from the university data center in real time to obtain the trustworthy situation assessment coefficient of the latest conversation, comparing the trustworthy situation assessment coefficient of the latest conversation with the first trustworthy situation assessment coefficient threshold and the second trustworthy situation assessment coefficient threshold, and dynamically issuing a defense action;

[0037] If the trustworthiness assessment coefficient of the latest session is greater than the first trustworthiness assessment coefficient threshold, a high-risk signal is generated. The university data center will then perform defensive actions such as immediate interception, traffic blackhole introduction, and redirection to a honeypot environment to lure the attacker into revealing their behavior.

[0038] If the trustworthiness assessment coefficient of the latest session is less than the first trustworthiness assessment coefficient threshold, and the trustworthiness assessment coefficient of the latest session is greater than the second trustworthiness assessment coefficient threshold, a medium-risk signal is generated. The university data center performs defensive actions including initiating rate limiting measures, mirroring traffic to a simulation environment for in-depth behavioral analysis, and dynamically reporting to the security analysis engine.

[0039] If the trustworthy situation assessment coefficient of the latest session is less than the second trustworthy situation assessment coefficient threshold, a low-risk signal is generated. The defense actions performed by the university data center include logging, transparent release, and continuous background monitoring.

[0040] Technical effects and advantages of the present invention:

[0041] The present invention adopts a variety of data mining and modeling technologies. In the offline stage, cluster analysis, association rule mining and state sequence Markov chain model are used to build labeled training sample sets and attack behavior models. In the online stage, behavioral information and risk information of the latest sessions are collected in real time. Based on preset multi-level risk thresholds, the system can dynamically adjust defense strategies. The present invention facilitates rapid processing and real-time analysis of sessions, ensuring the safe and stable operation of university data centers. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings;

[0043] Figure 1 The figure is a flow chart of the trusted situation defense method of a university data center based on a virtual simulation trapping environment of the present invention. DETAILED DESCRIPTION

[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0045] Example 1

[0046] Figure 1 The flowchart of the trusted situation defense method of a university data center based on a virtual simulation trapping environment of the present invention specifically includes the following steps:

[0047] S1: Simulate the real network topology of a university data center, deploy typical business services, and simultaneously collect normal session data from the real environment and known session data identified in the trapping environment to construct a labeled training sample set.

[0048] S2: Use clustering and association rule mining techniques to collect behavioral information from recent sessions, including the FP-Growth association rule mining algorithm to extract frequently occurring attack behavior features and form frequent item sets.

[0049] S3: Use Markov chain modeling and risk assignment to collect risk information for the latest session. This includes constructing normal and attack Markov models, and analyzing the Markov model's bias toward the latest session state sequence.

[0050] S4: The behavioral information and risk information of the latest session are integrated and quantitatively evaluated. Based on risk signals of different levels, the defense strategy is dynamically adjusted to adapt to different levels of security threats.

[0051] In Docker containers and VMware virtual machines, we built the same network topology, operating system, and typical services (such as teaching platforms, databases, middleware, and file sharing) as those in real university data centers. Specifically, we divided the network topology of a real university data center into several typical business areas, including teaching service areas, office management areas, database storage areas, file sharing areas, and network egress areas. We also configured independent subnets for each business area and achieved interconnection through a virtual switching mechanism.

[0052] At the virtual machine level, VMware technology is used to build multiple virtual nodes, each with a different operating system. Actual service components, such as the online teaching platform, the academic affairs system, and the scientific research information system, run on these nodes to simulate a realistic teacher-student interaction environment. At the container level, various basic services, including database services, middleware services, and web services, are built based on Docker technology, using Docker Compose for service orchestration and lifecycle management.

[0053] In addition, several honeypots, such as interactive honeypot systems based on Cowrie or Dionaea, are deployed within the simulation environment to attract and record attack activity. Traffic collection tools (such as tcpdump, Zeek, or Suricata) are deployed on all nodes to collect real-time network and application layer logs. To improve the maintainability of the environment, automated configuration tools (such as Ansible) are introduced to enable batch deployment and updates of virtual nodes. A snapshot mechanism supports rollback and reuse of environment states.

[0054] The policy engine directs normal traffic and specially injected test traffic to the real environment and the simulated environment, respectively, ensuring that the decoy environment appears identical to the production system. To ensure the "realism" of the decoy environment, the simulated environment is built with a network structure, service port openness, protocol interaction logic, and response latency characteristics that are identical to those of the real environment. This ensures that when test traffic accesses the simulated environment, it sees the performance of the "real production system," unnoticed by attackers. Furthermore, the decoy environment supports in-depth recording of abnormal behavior, including system command execution, lateral movement, and privilege escalation attempts, enabling attack chain reconstruction and situational awareness analysis.

[0055] During the offline preparation phase, log data of normal sessions in a real environment and known sessions in a virtual simulation trapping environment are collected. The log data of known sessions are used as training data, and the latest sessions from the university data center are received in real time. The behavioral information and risk information of the latest sessions are collected, and the behavioral information of the latest sessions is represented by the attack importance index, and the risk information of the latest sessions is represented by the complexity risk coefficient and the data access risk coefficient.

[0056] The role and advantages of the attack importance index are:

[0057] The offline phase completes heavy clustering, rule mining, and parameter tuning, while the online phase only performs lightweight operations such as L2 normalization, t-SNE mapping, and vector distance / similarity calculations. This avoids the performance bottlenecks of online high-dimensional clustering and frequent itemset calculations, enables millisecond-level attack importance index assessment, and can smoothly support large-scale traffic loads of thousands or even tens of thousands of QPS. In university data centers, each session can be evaluated in real time.

[0058] After manual review, online false positives and missed negatives are returned to the offline module for retraining the clustering model and re-mining frequent item sets. The system has the ability to continuously learn and can be continuously updated according to the actual operating status of university data centers to resist "zero-day attacks" and "threat variants" and maintain the long-term effectiveness of the defense model.

[0059] The attack importance index is obtained by collecting log data of normal conversations in a real environment and known attack conversations in a virtual simulation trapping environment during the offline preparation phase. Each conversation is labeled "normal" and "attack" and timestamps are unified. After data cleaning, a training set is constructed to extract attribute features of each conversation, including time, location, protocol type, and traffic volume. The time features, location features, and traffic volume features of each conversation are fused and L2 normalized to generate a high-dimensional feature vector.

[0060] It should be noted that the time feature refers to the time period corresponding to the timestamp obtained based on the timestamp of the session. The time period can be divided into class time period, after-get out of class time period, night time period, etc.

[0061] The location feature refers to the geographical / network distance between the source IP-ASN location and the data center subnet. It is used to measure the "physical distance" or "network topological distance" between the IP address that initiates the request (the autonomous system ASN to which it belongs) and the accessed data center.

[0062] Traffic characteristics refer to the total amount of data transmitted during a session connection. The total amount of data transmitted during a session connection is standardized to reflect the relative size of the total amount of data transmitted in each session.

[0063] Based on the standardized high-dimensional feature vectors, after dimensionality reduction using the t-SNE algorithm, each conversation in the training set is clustered using the K-means clustering algorithm. The optimal number of clusters is automatically determined using the elbow method and silhouette coefficient, and the cluster center of each cluster is saved.

[0064] It should be noted that using t-SNE dimensionality reduction for attack session feature vectors will map similar attack behaviors to close locations in the low-dimensional space, enhancing the subsequent clustering algorithm's ability to perceive these "cluster" structures. Clustering is performed in a low-dimensional space, significantly reducing the amount of computation. Especially for large-scale traffic data, it can significantly shorten the clustering time, facilitating online or near-real-time analysis.

[0065] Based on the labels and silhouette coefficients of each conversation in the training set, the clustering results are evaluated to determine the optimal cluster model;

[0066] It should be noted that evaluating clustering results helps distinguish between normal and attack sessions. After selecting the optimal cluster model, the sessions within each cluster represent a "typical situation." Subsequent independent association rule mining for each cluster allows for more targeted extraction of attack chain features. Furthermore, through offline training, the standardized high-dimensional feature vectors of each new session are extracted in real time and t-SNE dimensionality reduction is performed. This helps quickly calculate the distance from each new session to all offline cluster centers and find the nearest cluster ID. This enables millisecond-level traffic session classification and drives real-time situational defense.

[0067] By using association rule mining technology, the discrete attributes of the attack sessions in each cluster are extracted. The FP-Growth algorithm is used to mine frequent itemsets in each cluster to determine the potential association relationships of the sessions in each cluster.

[0068] It should be noted that the discrete attributes of the attack session in each cluster include protocol type, target port, operation command, etc. The purpose of the FP-Growth algorithm is to find frequently occurring discrete attribute combinations. Frequent item sets often correspond to the attacker's typical methods or attack steps (for example, "SSH login + attempt to escalate privileges + lateral scanning"), helping security teams understand common attack routines.

[0069] Determine the frequent itemsets in the session and calculate the support of the frequent itemsets in the session. The calculation formula is: ; Among them, ZCD is the support of the frequent itemset of the session, SL is the number of sessions with frequent itemsets in the attack session, and ZSL is the total number of attack sessions;

[0070] Based on the latest conversation received by the university data center during the online phase, the standardized high-dimensional feature vector of the latest conversation is determined, and the maximum similarity between the latest conversation and the attack conversation in the training set is calculated as the relevance of the latest conversation;

[0071] It should be noted that the maximum similarity between the latest session and the attack session in the training set can be calculated using methods such as the Pearson correlation coefficient and cosine similarity. The greater the correlation, the more likely the latest session is an attack session and is considered highly consistent with known attacks. Conversely, the latest session is likely to be normal traffic.

[0072] After dimensionality reduction using the t-SNE algorithm, the distance between the latest session and the cluster center of each attack session cluster in the offline preparation phase is calculated, and the minimum value is taken to obtain the security level of the latest session.

[0073] It should be noted that the attack session cluster represents the division of clusters into two categories based on the optimal cluster model during the offline preparation phase: normal session clusters and attack session clusters. Normal session clusters include various types of clusters, such as database query clusters, file sharing clusters, and web access clusters. Attack session clusters also include various types of clusters, such as scanning and detection clusters, brute force login clusters, and data exfiltration clusters.

[0074] Based on the frequent itemsets in the offline preparation phase, determine the frequent itemsets in the latest session, calculate the support of the frequent itemsets in the latest session, and calculate the attack importance index using the formula. The calculation formula for the attack importance index is: ;in, is the attack importance index of the latest session, is the relevance of the latest session, is the support of the latest session frequent itemset, For the security of the latest session, is a constant.

[0075] As the formula shows, a larger attack importance index indicates that the latest session has triggered a typical attribute combination that is widely present in the attack cluster during the offline phase, which may be a common tactic used by the attacker. Furthermore, this means that the session is highly similar to existing real attack sessions in the training set in terms of multi-dimensional feature distribution, essentially replicating known intrusion trajectories and behavior patterns. Furthermore, it is clearly separated from normal business clusters, deviating from the normal access patterns of university data centers.

[0076] Among them, the advantages and functions of the complexity risk coefficient are:

[0077] The complexity risk factor not only considers static characteristics (traffic volume, protocol type, etc.), but also quantifies the degree of deviation from the normal process in the "operation sequence." Traditional rules often fail to detect low-frequency but complex attacks such as "slow funnel penetration" or "C2 heartbeat + covert pipeline." The complexity factor can precisely identify these "deep interactive" threats through sequence jump patterns.

[0078] By incorporating known attack sequences from honeypots into the attack model, the complexity coefficient can accurately identify real attack patterns verified in the simulation environment. Only a few online table lookups (transition probabilities) and simple logarithmic operations and multiplications are required, without the need for deep clustering or large-scale matrix decomposition, and the process can be completed in milliseconds. This fully meets the real-time defense needs of university data centers during peak final exam periods and high-concurrency scientific research scenarios.

[0079] The logic for obtaining the complexity risk coefficient is as follows: based on the common session types and operations in university data centers, the key operations in the session are abstracted into a finite number of states based on known sessions. Each state represents a key interaction. The state set S is defined based on the session in the offline preparation phase. ,in, Different states are created, and the states in the session are arranged in chronological order, mapping each session into a state sequence;

[0080] It should be noted that the session definition state set contains a finite number of states. The states represent key actions in the session, including web access, file interaction, system commands, and database operations. Each key action represents a state. The number of states in the state set should be sufficient to cover key behaviors. Additional states can be updated subsequently based on newly discovered attack methods to keep the model synchronized with the threat environment.

[0081] In the offline preparation phase, the state sequence of the normal session and the state sequence of the attack session are determined. The number of occurrences of each pair of adjacent states in the state sequence set of all normal sessions is counted as the number of transitions in the normal session. The number of occurrences of each pair of adjacent states in the state sequence set of all attack sessions is counted as the number of transitions in the attack session. The conditional probability of state transition is obtained by normalizing the number of transitions. The transition probability matrices of the normal Markov model and the attack Markov model are constructed. The transition probability matrix of the normal Markov model is marked as: , mark the transition probability matrix of the attack Markov model as: , where i, j are the indices of the states in the state set, ranging from 1, 2, 3, ..., n;

[0082] Based on the transition probability matrices of the normal Markov model and the attack Markov model, the steady-state distributions of the normal Markov model and the attack Markov model are solved and marked as: H and ;

[0083] The entropy rates of the normal Markov model and the attack Markov model are calculated respectively. The entropy rate calculation formula of the normal Markov model is: , the entropy rate calculation formula of the attack Markov model is: ;in, is the entropy rate of the normal Markov model, is the steady-state probability of the ith state of the steady-state distribution of the normal Markov model, is the entropy rate of the attack Markov model, is the steady-state probability of the ith state of the steady-state distribution of the attack Markov model;

[0084] It should be noted that the entropy rate is used to measure the average uncertainty of the state transition of the model in the long-term operation. The normal Markov model is used to characterize the "action flow" rules of all legitimate sessions in the university data center, reflecting the typical order and frequency of various business processes. The attack Markov model is used to characterize the "penetration chain" action sequence of known intruders, reflecting the sequential dependence and preferred path of typical attack methods.

[0085] According to the latest session received by the university data center during the online phase, the state sequence of the latest session is determined and marked as: , where t is the number of the latest session, 1, 2, 3, ..., m is the state sequence number of different sessions;

[0086] Based on the normal Markov model determined in the offline preparation phase, the probability of each state transition in the state sequence of the latest session is obtained, and the cross entropy between the latest session and the normal Markov model is calculated. The calculation formula is: ;in, is the cross entropy between the latest session and the normal Markov model, g is the number of the state in the latest session state sequence, are all adjacent state pairs in the latest session state sequence, In the normal Markov model, Transfer to state The conditional probability of

[0087] Calculate the cross entropy between the latest session and the attack Markov model. The calculation formula is: ;in, is the cross entropy between the latest session and the attack Markov model, To attack the Markov model from the state Transfer to state The conditional probability of

[0088] It should be noted that the larger the cross entropy between the latest session and the normal Markov model, the more uncommon the state transition of the latest session is in the normal Markov model. Similarly, the smaller the cross entropy between the latest session and the attack Markov model, the more common the state transition of the latest session is in the attack Markov model, indicating that the latest session is more likely to be an abnormal session or a malicious attack behavior.

[0089] Calculate the complexity risk coefficient using the following formula: ;in, is the complexity risk factor.

[0090] As can be seen from the formula, a larger complexity risk coefficient indicates that the latest session deviates more from the normal model than from the attack model, and is therefore more likely to be an attack. Conversely, a smaller complexity risk coefficient indicates that the latest session is more likely to be normal behavior. By calculating the cross-entropy deviation for each new session and comparing or calculating the deviation ratio, we can quantify whether the session is more likely to be "normal" or "attack," thereby implementing a trusted situation defense strategy for university data centers.

[0091] The role and advantages of the data access risk factor are:

[0092] The data access risk factor integrates behavioral characteristics across multiple modalities (such as time-sensitive behavior, access location, and identity reputation). Through cross-modal modeling, standardized scoring, and weighted calculations, it comprehensively measures the overall risk profile of a session. Compared to traditional single-dimensional rule-matching methods, it offers stronger recognition capabilities and lower false positive rates.

[0093] By combining expert scoring with offline training, we not only retain the understanding and constraint capabilities of domain experts on attack characteristics, but also achieve quantitative evaluation through regression models, ensuring that the model output is interpretable, making it easier for security analysts to trace, review, and optimize policies.

[0094] The logic for obtaining the data access risk coefficient is as follows: based on the offline preparation phase, log data of normal conversations in a real environment and known conversations in a virtual simulation trapping environment is collected, a training sample set is constructed, the modal characteristics of the conversations are defined, risk scores are assigned to the features of the known conversations under different modalities, each modal feature is standardized, and modal weight parameters are introduced for different modalities. In the risk scoring process, a regression model is used to train the risk scoring function and output the risk score of each conversation under each feature dimension.

[0095] It should be noted that different modalities include time-sensitive behavior modalities, access location modalities, identity reputation modalities, etc. Different features exist under different modalities. For example, the identity reputation modalities include IP reputation features and MFA flag features. The calculation basis of IP reputation features can be whether the IP hits known malicious blacklists / graylists, the number of abnormal accesses in the past period of time, the correlation with known attack events, geographical or ASN abnormal jumps, etc., and experts score different features under different modalities to obtain risk scores for the features under different modalities of known sessions.

[0096] Based on the latest conversations received by the university data center during the online phase, the corresponding eigenvalues ​​of the latest conversations in each modality are determined. Combined with the regression scoring function and modal weight parameters constructed during the offline phase, the risk scores of the latest conversations in each modality are assigned separately. The data access risk coefficient of the latest conversation is calculated according to the formula: ;in, is the data access risk coefficient, k=1, 2, 3, ..., K, K is a positive integer representing the total number of modes, k is the mode number, is the weight of the kth mode, and the weight satisfies the normalization constraint. Score the risk under the k-th mode.

[0097] As can be seen from the formula, the larger the data access risk coefficient, the more abnormal or attacking the current latest session is under multiple modal features, and its overall behavioral characteristics are highly similar to known high-risk sessions. Therefore, the higher the potential threat level, the security protection system should increase the defense level or trigger the response mechanism.

[0098] Through comprehensive analysis of the latest session's behavioral information and risk information, the attack importance index, complexity risk coefficient, and data access risk coefficient of the latest session are weighted and summed to build a trustworthy situation assessment model and generate a trustworthy situation assessment coefficient. The calculation formula for the trustworthy situation assessment coefficient is: ;in, is the credible situation assessment coefficient, 、 、 are the proportional coefficients of attack importance index, complexity risk coefficient and data access risk coefficient, respectively. 、 、 Both are greater than 0.

[0099] The formula shows that the greater the attack importance index, complexity risk coefficient, and data access risk coefficient of the latest session, the greater the trustworthy situation assessment coefficient. This indicates that the session exhibits high abnormality and risk in terms of behavioral characteristics, operation path complexity, and multimodal risk dimensions of access behavior. It can be comprehensively judged that this session has a high level of trustworthy risk situation faced by the current university data center.

[0100] It's important to note that the Trusted Situation Assessment Factor provides a multi-dimensional, integrated quantitative indicator that considers not only the attack behavior itself but also the degree of operational process anomalies and access risk context. It provides a comprehensive measure of the overall security threat level of the latest session. A higher value indicates a greater threat to the trusted operation of the university data center, posing a higher operational warning value and defense priority.

[0101] Setting a first trustworthy situation assessment coefficient threshold and a second trustworthy situation assessment coefficient threshold, where the first trustworthy situation assessment coefficient threshold is greater than the second trustworthy situation assessment coefficient threshold, collecting the latest conversations from the university data center in real time to obtain the trustworthy situation assessment coefficient of the latest conversation, comparing the trustworthy situation assessment coefficient of the latest conversation with the first trustworthy situation assessment coefficient threshold and the second trustworthy situation assessment coefficient threshold, and dynamically issuing a defense action;

[0102] If the trustworthiness assessment coefficient of the latest session is greater than the first trustworthiness assessment coefficient threshold, a high-risk signal is generated. The university data center will then perform defensive actions such as immediate interception, traffic blackhole introduction, and redirection to a honeypot environment to lure the attacker into revealing their behavior.

[0103] If the trustworthiness assessment coefficient of the latest session is less than the first trustworthiness assessment coefficient threshold, and the trustworthiness assessment coefficient of the latest session is greater than the second trustworthiness assessment coefficient threshold, a medium-risk signal is generated. The university data center performs defensive actions including initiating rate limiting measures, mirroring traffic to a simulation environment for in-depth behavioral analysis, and dynamically reporting to the security analysis engine.

[0104] If the trustworthy situation assessment coefficient of the latest session is less than the second trustworthy situation assessment coefficient threshold, a low-risk signal is generated. The defense actions performed by the university data center include logging, transparent release, and continuous background monitoring.

[0105] The present invention adopts a variety of data mining and modeling technologies. In the offline stage, cluster analysis, association rule mining and state sequence Markov chain model are used to build labeled training sample sets and attack behavior models. In the online stage, behavioral information and risk information of the latest sessions are collected in real time. Based on preset multi-level risk thresholds, the system can dynamically adjust defense strategies. The present invention facilitates rapid processing and real-time analysis of sessions, ensuring the safe and stable operation of university data centers.

[0106] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.

[0107] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0108] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0109] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0110] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0111] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0112] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A trusted situation defense method for university data centers based on a virtual simulation trapping environment, characterized in that: The specific steps include: S1: Simulate the real network topology of a university data center, deploy typical business services, and simultaneously collect normal session data from the real environment and known session data identified in the trapping environment to construct a labeled training sample set. S2: Use clustering and association rule mining techniques to collect behavioral information from recent sessions, including the FP-Growth association rule mining algorithm to extract frequently occurring attack behavior features and form frequent item sets. S3: Use Markov chain modeling and risk assignment to collect risk information for the latest session. This includes constructing normal and attack Markov models, and analyzing the Markov model's bias toward the latest session state sequence. S4: Fusion and quantitatively evaluate the behavioral information and risk information of the latest session. Based on different risk signals, the defense strategy is dynamically adjusted to adapt to different levels of security threats. Behavioral and risk information for the latest session, including: In the offline preparation phase, log data of normal conversations in the real environment and known conversations in the virtual simulation trapping environment are collected. The log data of known conversations are used as training data, and the latest conversations from the university data center are received in real time. The behavior information and risk information of the latest conversations are collected, and the behavior information of the latest conversations are represented by the attack importance index, and the risk information of the latest conversations are represented by the complexity risk coefficient and the data access risk coefficient. is the attack importance index of the latest session, is the complexity risk coefficient, is the data access risk factor.

2. The trusted situation defense method for university data centers based on a virtual simulation trapping environment according to claim 1 is characterized in that: The logic for obtaining the attack importance index is: During the offline preparation phase, we collected log data from both normal conversations in a real-world environment and known attack conversations in a virtual simulation trapping environment. We labeled each conversation "normal" and "attack" and unified the timestamp. After data cleaning, we constructed a training set and extracted the attribute features of each conversation, including time, location, protocol type, and traffic volume. We then fused the time, location, and traffic features of each conversation and performed L2 normalization to generate a high-dimensional feature vector. Based on the labels and silhouette coefficients of each conversation in the training set, the clustering results are evaluated to determine the optimal cluster model; By using association rule mining technology, the discrete attributes of the attack sessions in each cluster are extracted. The FP-Growth algorithm is used to mine frequent itemsets in each cluster to determine the potential association relationships of the sessions in each cluster. Determine the frequent itemsets in the session and calculate the support of the frequent itemsets in the session. The calculation formula is: ; Among them, ZCD is the support of the frequent itemset of the session, SL is the number of sessions with frequent itemsets in the attack session, and ZSL is the total number of attack sessions; Based on the latest conversation received by the university data center during the online phase, the standardized high-dimensional feature vector of the latest conversation is determined, and the maximum similarity between the latest conversation and the attack conversation in the training set is calculated as the relevance of the latest conversation; After dimensionality reduction using the t-SNE algorithm, the distance between the latest session and the cluster center of each attack session cluster in the offline preparation phase is calculated, and the minimum value is taken to obtain the security level of the latest session. Based on the frequent itemsets in the offline preparation phase, determine the frequent itemsets in the latest session, calculate the support of the frequent itemsets in the latest session, and calculate the attack importance index using the formula. The calculation formula for the attack importance index is: ;in, is the relevance of the latest session, is the support of the latest session frequent itemset, For the security of the latest session, is a constant.

3. The trusted situation defense method for university data centers based on a virtual simulation trapping environment according to claim 2 is characterized in that: The logic for obtaining the complexity risk coefficient is: According to the common session types and operations in university data centers, the key operations in the session are abstracted into a finite number of states based on known sessions. Each state represents a key interaction. The state set S is defined based on the session in the offline preparation phase. ,in, Different states are created, and the states in the session are arranged in chronological order, mapping each session into a state sequence; In the offline preparation phase, the state sequence of the normal session and the state sequence of the attack session are determined. The number of occurrences of each pair of adjacent states in the state sequence set of all normal sessions is counted as the number of transitions in the normal session. The number of occurrences of each pair of adjacent states in the state sequence set of all attack sessions is counted as the number of transitions in the attack session. The conditional probability of state transition is obtained by normalizing the number of transitions. The transition probability matrices of the normal Markov model and the attack Markov model are constructed. The transition probability matrix of the normal Markov model is marked as: , mark the transition probability matrix of the attack Markov model as: , where i, j are the indices of the states in the state set, ranging from 1, 2, 3, ..., n; Based on the transition probability matrices of the normal Markov model and the attack Markov model, the steady-state distributions of the normal Markov model and the attack Markov model are solved and marked as: and ; The entropy rates of the normal Markov model and the attack Markov model are calculated respectively. The entropy rate calculation formula of the normal Markov model is: , the entropy rate calculation formula of the attack Markov model is: ;in, is the entropy rate of the normal Markov model, is the steady-state probability of the ith state of the steady-state distribution of the normal Markov model, is the entropy rate of the attack Markov model, is the steady-state probability of the ith state of the steady-state distribution of the attack Markov model; According to the latest session received by the university data center during the online phase, the state sequence of the latest session is determined and marked as: , where t is the number of the latest session, 1, 2, 3, ..., m is the state sequence number of different sessions; Based on the normal Markov model determined in the offline preparation phase, the probability of each state transition in the state sequence of the latest session is obtained, and the cross entropy between the latest session and the normal Markov model is calculated. The calculation formula is: ;in, is the cross entropy between the latest session and the normal Markov model, g is the number of the state in the latest session state sequence, are all adjacent state pairs in the latest session state sequence, In the normal Markov model, Transfer to state The conditional probability of Calculate the cross entropy between the latest session and the attack Markov model. The calculation formula is: ;in, is the cross entropy between the latest session and the attack Markov model, To attack the Markov model from the state Transfer to state The conditional probability of Calculate the complexity risk coefficient using the following formula: .

4. The trusted situation defense method for university data centers based on a virtual simulation trapping environment according to claim 3 is characterized in that: The logic for obtaining the data access risk coefficient is: During the offline preparation phase, we collect log data from both normal conversations in real environments and known conversations in a virtual simulation trapping environment. We then construct a training sample set, define the modal characteristics of the conversations, assign risk scores to the features of the known conversations in different modalities, standardize the features of each modality, and introduce modal weight parameters for different modalities. During the risk scoring process, we use a regression model to train a risk scoring function and output a risk score for each conversation based on each feature dimension. Based on the latest conversations received by the university data center during the online phase, the corresponding eigenvalues ​​of the latest conversations in each modality are determined. Combined with the regression scoring function and modal weight parameters constructed during the offline phase, the risk scores of the latest conversations in each modality are assigned separately. The data access risk coefficient of the latest conversation is calculated according to the formula: ; Where k = 1, 2, 3, ..., K, K is a positive integer representing the total number of modes, k is the mode number, is the weight of the kth mode, and the weight satisfies the normalization constraint. Score the risk under the k-th mode.

5. The method for defending a university data center's trusted situation based on a virtual simulation trapping environment according to claim 4 is characterized in that: The latest conversation behavior information and risk information are integrated and quantitatively evaluated, including: Through comprehensive analysis of the latest session's behavioral information and risk information, the attack importance index, complexity risk coefficient, and data access risk coefficient of the latest session are weighted and summed to build a trustworthy situation assessment model and generate a trustworthy situation assessment coefficient. The calculation formula for the trustworthy situation assessment coefficient is: ;in, is the credible situation assessment coefficient, are the proportional coefficients of attack importance index, complexity risk coefficient and data access risk coefficient, respectively. Both are greater than 0.

6. The trusted situation defense method for university data centers based on a virtual simulation trapping environment according to claim 5 is characterized in that: Dynamically adjust defense strategies based on risk signals at different levels, including: Setting a first trustworthy situation assessment coefficient threshold and a second trustworthy situation assessment coefficient threshold, where the first trustworthy situation assessment coefficient threshold is greater than the second trustworthy situation assessment coefficient threshold, collecting the latest conversations from the university data center in real time to obtain the trustworthy situation assessment coefficient of the latest conversation, comparing the trustworthy situation assessment coefficient of the latest conversation with the first trustworthy situation assessment coefficient threshold and the second trustworthy situation assessment coefficient threshold, and dynamically issuing a defense action; If the trustworthiness assessment coefficient of the latest session is greater than the first trustworthiness assessment coefficient threshold, a high-risk signal is generated. The university data center will then perform defensive actions such as immediate interception, traffic blackhole introduction, and redirection to a honeypot environment to lure the attacker into revealing their behavior. If the trustworthiness assessment coefficient of the latest session is less than the first trustworthiness assessment coefficient threshold, and the trustworthiness assessment coefficient of the latest session is greater than the second trustworthiness assessment coefficient threshold, a medium-risk signal is generated. The university data center performs defensive actions including initiating rate limiting measures, mirroring traffic to a simulation environment for in-depth behavioral analysis, and dynamically reporting to the security analysis engine. If the trustworthy situation assessment coefficient of the latest session is less than the second trustworthy situation assessment coefficient threshold, a low-risk signal is generated. The defense actions performed by the university data center include logging, transparent release, and continuous background monitoring.

Citation Information

Patent Citations

  • Time sequence evolution network security early warning method for cloud platform

    CN110290120A

  • Security alarm driven attack scene reconstruction method, system and device and medium

    CN117596071A