Network information security analysis method and system based on big data
Through the network information security analysis method based on big data, comprehensive computing system, network and application feature indexes, and establishing an active monitoring mechanism, it solves the problem of difficulty in discovering hidden vulnerabilities in the existing technology, realizes real-time monitoring and early warning of network information security, and improves network security protection capabilities.
Patent Information
- Application Number
- CN202510476817.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-09-02
AI Technical Summary
The existing technology lacks an effective active monitoring mechanism, making it difficult to timely discover deep and untacked security vulnerabilities in the network system, resulting in frequent network security risks.
Using a network information security analysis method based on big data, through system monitoring, network monitoring, operation monitoring and application monitoring, the system feature index, network feature index, operation feature index and application feature index are calculated, the network information security index is comprehensively evaluated, the network information security index is established, and the potential security vulnerabilities are discovered in real time.
A comprehensive and objective assessment of network information security has been achieved, potential security risks are discovered in a timely manner, and protective measures have been taken in advance to improve network information security and reduce the risk of hackers exploiting vulnerabilities.
Smart Images

Figure CN120582804A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information security technology, and in particular to a network information security analysis method and system based on big data. Background Art
[0002] The Internet refers to a system that connects computers and devices in different locations through various communication methods to enable information sharing, data transmission, and resource utilization. The Internet is a crucial means of accessing information, acting as a vast repository of knowledge. People can easily access a wide range of knowledge through search engines, online libraries, and academic databases. Whether they're seeking to understand scientific principles, historical events, cultural knowledge, or learn skills like languages, art, or programming, a wealth of relevant information and learning materials are readily available, breaking down geographical boundaries and enabling people to connect with people around the world. Social platforms allow users to make new friends, find like-minded individuals, share their daily lives, and enrich their relationships. In both work and personal life, people can quickly share files, images, links, and other information online, improving collaboration and cooperation. While the Internet provides numerous conveniences for people's lives and work, it also has certain drawbacks.
[0003] At present, network information security vulnerabilities occur frequently. There are a large number of known and unknown security vulnerabilities in software such as operating systems and applications. Hackers can exploit these vulnerabilities to obtain system permissions and steal data. In many cases, security vulnerabilities are not discovered until they are exploited by hackers. At present, there is a lack of effective active monitoring mechanisms to monitor potential security vulnerabilities. Most systems will only start vulnerability detection when abnormal situations occur, such as system crashes or data leaks and other obvious symptoms. However, it is difficult to discover those vulnerabilities that are hidden deeply and have not yet been triggered in time, which leaves hidden dangers to network security. Summary of the Invention
[0004] (1) Technical problems solved
[0005] In response to the shortcomings of the existing technology, the present invention provides a network information security analysis method and system based on big data, which has the advantages of establishing a set of active monitoring mechanisms to monitor and warn of security vulnerabilities in the network system in real time, and can promptly discover security vulnerabilities that are hidden deeply and have not yet been triggered, so as to take corresponding protective measures before hackers exploit these vulnerabilities, effectively improving network information security and achieving comprehensive and objective reflection of the security status of network information.
[0006] (2) Technical solution
[0007] To achieve the above-mentioned purpose, the present invention provides the following technical solutions: a network information security analysis method based on big data, comprising the following steps;
[0008] Step 1: Conduct system monitoring, network monitoring, operation monitoring, and application monitoring of network information security;
[0009] Step 2: Obtain monitoring data and save it as system monitoring data set , network monitoring dataset , operation monitoring data set and application monitoring datasets ;
[0010] Step 3: Based on the system monitoring data set Calculate the system characteristic index , based on network monitoring dataset Calculate the network characteristic index , based on the operational monitoring data set Calculate the operating characteristic index , based on application monitoring dataset Calculate the application characteristic index ;
[0011] Step 4: Based on the system characteristic index , Network Characteristics Index , Operational Characteristics Index , Application Feature Index Calculation results are used to calculate the network information security index , and then according to the network information security index Conduct network information security analysis;
[0012] Step 5: Output and feedback the network information security analysis results.
[0013] Preferably, the system monitors the data set Including system utilization , system startup time , System running time , system call frequency , system abnormal file data
[0014] The network monitoring dataset Including abnormal protocol traffic bytes , source / destination IP address reputation score , encryption communication key length , number of network connections , disconnection frequency , Connection Duration , network equipment utilization rate , the proportion of encrypted communication traffic , System intrusion frequency .
[0015] Preferably, the system characteristic index The calculation formula is:
[0016]
[0017] In the calculation formula, 、 、 、 They represent the system usage rate, system startup time, system running time, and the theoretical minimum value of system call frequency. 、 、 、 They represent the system usage rate, system startup time, system running time, and the theoretical maximum value of system call frequency. Represents the total number of files, 、 、 、 、 Represents weight.
[0018] Preferably, the network characteristic index The calculation formula is:
[0019]
[0020] In the calculation formula, Represents the total traffic word count, 、 、 、 They represent the theoretical minimum values of the number of network connections, disconnection frequency, connection duration, and network device utilization, respectively. 、 、 、 They represent the theoretical maximum values of the number of network connections, disconnection frequency, connection duration, and network device utilization. The baseline proportion of traffic representing encrypted communications, Represents the maximum number of historical intrusion frequencies, 、 、 、 、 、 、 、 、 Represents weight.
[0021] Preferably, the operation monitoring data Includes the number of security audit log events , memory dump differences when running a crash , function call frequency , data interaction volume , data transmission error rate , abnormal frequency , trust score of data interaction objects ;
[0022] The application monitoring data Includes code integrity , application code update time , a hash of the application code , third-party library security factor , authentication failure frequency .
[0023] Preferably, the operating characteristic index The calculation formula is:
[0024]
[0025] In the calculation formula, Represents the maximum number of historical events, Represents the historical maximum memory dump difference, 、 Represents the minimum and maximum values of the function call frequency, 、 Represents the minimum and maximum values of data interaction. Represents the total amount of transmission, 、 Represents the minimum and maximum values of abnormal frequency, 、 、 、 、 、 、 Represent weights respectively.
[0026] Preferably, the application characteristic index The calculation formula is:
[0027]
[0028] In the calculation formula, stands for Maximum Code Integrity, represents the maximum application code update time, represents the initial hash value of the application code, The total number of authentications. 、 、 、 、 Represent weights respectively.
[0029] Preferably, the network information security index The calculation formula is:
[0030]
[0031] In the calculation formula, 、 、 、 Represent weights respectively.
[0032] Preferably, when the network information security index When the calculated value is greater than the network information security threshold, it means that the current network information is unsafe and an early warning signal is issued.
[0033] A network information security analysis system based on big data is applied to a network information security analysis method based on big data, comprising the following: a vulnerability monitoring module, a vulnerability analysis module, a vulnerability assessment module, and a vulnerability feedback module, wherein the vulnerability monitoring module, the vulnerability analysis module, the vulnerability assessment module, and the vulnerability feedback module are connected via a network;
[0034] The vulnerability monitoring module is used to perform system monitoring, network monitoring, operation monitoring and application monitoring of network information security, and obtain monitoring data for record keeping;
[0035] The vulnerability analysis module calculates the system characteristic index based on the data obtained by the vulnerability monitoring module , Network Characteristics Index , Operational Characteristics Index , Application Feature Index ;
[0036] The vulnerability assessment module calculates the network information security index based on the calculation results of the vulnerability analysis module , and then according to the network information security index Conduct network information security analysis and evaluate network information security status;
[0037] The vulnerability feedback module outputs and feeds back the network information security analysis results.
[0038] Compared with the existing technology, the present invention provides a network information security analysis method and system based on big data, which has the following beneficial effects:
[0039] 1. The present invention performs network information security analysis by comprehensively calculating the system characteristic index, network characteristic index, operation characteristic index and application characteristic index, which can comprehensively and objectively reflect the security status of network information, including the vulnerability of the system itself, the risk of the network environment, the stability during operation, and the security of the application program. This comprehensive assessment helps to identify potential security risks and weak links in the system, provide a basis for subsequent security reinforcement and protection measures, establish a set of active monitoring mechanisms, and conduct real-time monitoring and early warning of security vulnerabilities in the network system. It can timely discover those security vulnerabilities that are hidden deeply and have not yet been triggered, so that corresponding protection measures can be taken before hackers exploit these vulnerabilities, effectively improving network information security. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 It is a step diagram of the method of the present invention;
[0041] Figure 2 Schematic diagram of the system flow of the present invention. DETAILED DESCRIPTION
[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0043] See also Figure 1-2 ,A network information security analysis method based on big data, comprising the following steps;
[0044] Step 1: Conduct system monitoring, network monitoring, operation monitoring, and application monitoring of network information security;
[0045] Step 2: Obtain monitoring data and save it as system monitoring data set , network monitoring dataset , operation monitoring data set and application monitoring datasets ;
[0046] System monitoring data set Including system utilization , system startup time , System running time , system call frequency , system abnormal file data ;
[0047] Network monitoring dataset Including abnormal protocol traffic bytes , source / destination IP address reputation score , encryption communication key length , number of network connections , disconnection frequency , Connection Duration , network equipment utilization rate , the proportion of encrypted communication traffic , System intrusion frequency ;
[0048] Operation monitoring data Includes the number of security audit log events , memory dump differences when running a crash , function call frequency , data interaction volume , data transmission error rate , abnormal frequency , trust score of data interaction objects ;
[0049] Application monitoring data Includes code integrity , application code update time , a hash of the application code , third-party library security factor , authentication failure frequency ;
[0050] Step 3: Based on the system monitoring data set Calculate the system characteristic index , based on network monitoring dataset Calculate the network characteristic index , based on the operational monitoring data set Calculate the operating characteristic index , based on application monitoring dataset Calculate the application characteristic index ;
[0051] System characteristic index The calculation formula is:
[0052]
[0053] In the calculation formula, 、 、 、 They represent the system usage rate, system startup time, system running time, and the theoretical minimum value of system call frequency. 、 、 、 They represent the system usage rate, system startup time, system running time, and the theoretical maximum value of system call frequency. Represents the total number of files, 、 、 、 、 Represents weight;
[0054] By standardizing the data of key indicators of the real-time monitoring system and combining multiple parameters to comprehensively calculate the system characteristic index, potential security risks can be discovered in a timely manner to prevent loopholes from being exploited by hackers. The introduction of the system characteristic index enables the system to actively monitor its own health status and conduct real-time detection and analysis of abnormal behaviors. This active defense strategy can greatly enhance the security protection capabilities of the system and reduce the possibility of being attacked.
[0055] Network Characteristics Index The calculation formula is:
[0056]
[0057] In the calculation formula, Represents the total traffic word count, 、 、 、 They represent the theoretical minimum values of the number of network connections, disconnection frequency, connection duration, and network device utilization, respectively. 、 、 、 They represent the theoretical maximum values of the number of network connections, disconnection frequency, connection duration, and network device utilization. The baseline proportion of traffic representing encrypted communications, Represents the maximum number of historical intrusion frequencies, 、 、 、 、 、 、 、 、 Represents weight;
[0058] By collecting and analyzing network traffic, IP address reputation scores, encryption key lengths and other data in real time, abnormal network behavior can be discovered in a timely manner, enabling real-time monitoring of network security. Combining data from multiple dimensions can comprehensively assess the security status of network information, improve the accuracy of network information security testing, facilitate the implementation of preventive measures for information security, reduce potential security threats, identify key risk points in the network in advance, and ensure network information security.
[0059] Operational Characteristics Index The calculation formula is:
[0060]
[0061] In the calculation formula, Represents the maximum number of historical events, Represents the historical maximum memory dump difference, 、 Represents the minimum and maximum values of the function call frequency, 、 Represents the minimum and maximum values of data interaction. Represents the total amount of transmission, 、 Represents the minimum and maximum values of abnormal frequency, 、 、 、 、 、 、 Represent weights respectively;
[0062] Calculating the operational characteristic index through multiple operational parameter data helps to issue early warnings before potential risks become actual problems, thus improving the overall security of the system and reducing the possibility of attacks.
[0063] Application Feature Index The calculation formula is:
[0064]
[0065] In the calculation formula, stands for Maximum Code Integrity, represents the maximum application code update time, represents the initial hash value of the application code, The total number of authentications. 、 、 、 、 Represent weights respectively;
[0066] By comprehensively evaluating information from multiple dimensions of an application, we can gain a more comprehensive understanding of its security status, promptly identify potential security risks, and take effective protective measures to prevent malicious attacks and data leaks. We can also detect abnormal behavior and tampering in applications, ensuring the integrity and reliability of applications, protecting the interests of users and enterprises, improving information network security monitoring, and predicting network security risks in advance.
[0067] Step 4: Based on the system characteristic index , Network Characteristics Index , Operational Characteristics Index , Application Feature Index Calculation results are used to calculate the network information security index , and then according to the network information security index Conduct network information security analysis;
[0068] Network Information Security Index The calculation formula is:
[0069]
[0070] In the calculation formula, 、 、 、 Represent weights respectively;
[0071] By comprehensively calculating the system characteristic index, network characteristic index, operation characteristic index and application characteristic index to conduct network information security analysis, we can comprehensively and objectively reflect the security status of network information, including the vulnerability of the system itself, the risk of the network environment, the stability of the operation process and the security of the application program. This comprehensive assessment helps to identify potential security risks and weak links in the system, providing a basis for subsequent security reinforcement and protection measures. It also establishes a set of active monitoring mechanisms to conduct real-time monitoring and early warning of security vulnerabilities in the network system. It can timely discover those security vulnerabilities that are hidden deep and have not yet been triggered, so that corresponding protection measures can be taken before hackers exploit these vulnerabilities, effectively improving network information security.
[0072] When the network information security index If the calculated value is greater than the network information security threshold, it means that the current network information is unsafe and an early warning signal is issued;
[0073] Step 5: Output and feedback the network information security analysis results.
[0074] A network information security analysis system based on big data is applied to a network information security analysis method based on big data, including a vulnerability monitoring module, a vulnerability analysis module, a vulnerability assessment module and a vulnerability feedback module, wherein the vulnerability monitoring module, the vulnerability analysis module, the vulnerability assessment module and the vulnerability feedback module are connected via a network;
[0075] The vulnerability monitoring module is used to conduct system monitoring, network monitoring, operation monitoring and application monitoring of network information security, and obtain monitoring data for record keeping;
[0076] The vulnerability analysis module calculates the system characteristic index based on the data obtained by the vulnerability monitoring module , Network Characteristics Index , Operational Characteristics Index , Application Feature Index ;
[0077] The vulnerability assessment module calculates the network information security index based on the results of the vulnerability analysis module. , and then according to the network information security index Conduct network information security analysis and evaluate network information security status;
[0078] The vulnerability feedback module outputs and feeds back the results of network information security analysis.
[0079] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A network information security analysis method based on big data, characterized in that: The following steps are included: Step 1: Conduct system monitoring, network monitoring, operation monitoring, and application monitoring of network information security; Step 2: Obtain monitoring data and save it as system monitoring data set , network monitoring dataset , operation monitoring data set and application monitoring datasets ; Step 3: Based on the system monitoring data set Calculate the system characteristic index , based on network monitoring dataset Calculate the network characteristic index , based on the operational monitoring data set Calculate the operating characteristic index , based on application monitoring dataset Calculate the application characteristic index ; Step 4: Based on the system characteristic index , Network Characteristics Index , Operational Characteristics Index , Application Feature Index Calculation results are used to calculate the network information security index , and then according to the network information security index Conduct network information security analysis; Step 5: Output and feedback the network information security analysis results.
2. The method for analyzing network information security based on big data according to claim 1, characterized in that: System monitoring data set Including system utilization , system startup time , System running time , system call frequency , system abnormal file data ; The network monitoring dataset Including abnormal protocol traffic bytes , source / destination IP address reputation score , encryption communication key length , number of network connections , disconnection frequency , Connection Duration , network equipment utilization rate , the proportion of encrypted communication traffic , System intrusion frequency .
3. The method for analyzing network information security based on big data according to claim 2, characterized in that: The system characteristic index The calculation formula is: In the calculation formula, 、 、 、 They represent the system usage rate, system startup time, system running time, and the theoretical minimum value of system call frequency. 、 、 、 They represent the system usage rate, system startup time, system running time, and the theoretical maximum value of system call frequency. Represents the total number of files, 、 、 、 、 Represents weight.
4. The method for analyzing network information security based on big data according to claim 3, characterized in that: The network characteristic index The calculation formula is: In the calculation formula, Represents the total traffic word count, 、 、 、 They represent the theoretical minimum values of the number of network connections, disconnection frequency, connection duration, and network device utilization, respectively. 、 、 、 They represent the theoretical maximum values of the number of network connections, disconnection frequency, connection duration, and network device utilization. The baseline proportion of traffic representing encrypted communications, Represents the maximum number of historical intrusion frequencies, 、 、 、 、 、 、 、 、 Represents weight.
5. The method for analyzing network information security based on big data according to claim 4, characterized in that: The operation monitoring data Includes the number of security audit log events , memory dump differences when running a crash , function call frequency , data interaction volume , data transmission error rate , abnormal frequency , trust score of data interaction objects ; The application monitoring data Includes code integrity , application code update time , a hash of the application code , third-party library security factor , authentication failure frequency .
6. The method for analyzing network information security based on big data according to claim 5, characterized in that: The operational characteristic index The calculation formula is: In the calculation formula, Represents the maximum number of historical events, Represents the historical maximum memory dump difference, 、 Represents the minimum and maximum values of the function call frequency, 、 Represents the minimum and maximum values of data interaction. Represents the total amount of transmission, 、 Represents the minimum and maximum values of abnormal frequency, 、 、 、 、 、 、 Represent weights respectively.
7. The method for analyzing network information security based on big data according to claim 6, characterized in that: The application characteristic index The calculation formula is: In the calculation formula, stands for Maximum Code Integrity, represents the maximum application code update time, represents the initial hash value of the application code, The total number of authentications. 、 、 、 、 Represent weights respectively.
8. The network information security analysis method based on big data according to claim 7, characterized in that: The Network Information Security Index The calculation formula is: In the calculation formula, 、 、 、 Represent weights respectively.
9. The network information security analysis method based on big data according to claim 8, characterized in that: When describing the network information security index When the calculated value is greater than the network information security threshold, it means that the current network information is unsafe and an early warning signal is issued.
10. A network information security analysis system based on big data, based on the network information security analysis method based on big data according to any one of claims 1 to 9, characterized in that: It includes a vulnerability monitoring module, a vulnerability analysis module, a vulnerability assessment module and a vulnerability feedback module, wherein the vulnerability monitoring module, the vulnerability analysis module, the vulnerability assessment module and the vulnerability feedback module are connected via a network; The vulnerability monitoring module is used to perform system monitoring, network monitoring, operation monitoring and application monitoring of network information security, and obtain monitoring data for record keeping; The vulnerability analysis module calculates the system characteristic index based on the data obtained by the vulnerability monitoring module , Network Characteristics Index , Operational Characteristics Index , Application Feature Index ; The vulnerability assessment module calculates the network information security index based on the calculation results of the vulnerability analysis module , and then according to the network information security index Conduct network information security analysis and evaluate network information security status; The vulnerability feedback module outputs and feeds back the network information security analysis results.