Threat information collection method and system based on network security

By constructing a multi-dimensional heterogeneous network security threat information graph and improving the Transformer algorithm, the problems of insufficient heterogeneous information processing and dynamic adaptability in network security threat information aggregation technology are solved, efficient integration and dynamic tracking of network security threats are achieved, and the timeliness and effectiveness of network security protection are improved.

CN120639489AInactive Publication Date: 2025-09-12HEFEI JINGHEYUAN TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511024415.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-09-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing network security threat information aggregation technologies are unable to effectively handle the complex correlations of heterogeneous information and adapt to dynamically changing network security threats. They are unable to quickly and accurately integrate multi-source heterogeneous threat information, and traditional methods are unable to adaptively capture the evolution of threat characteristics.

Method used

Based on the network security threat information aggregation method, a multi-dimensional heterogeneous network security threat information graph is constructed. The optimized graph neural network is used for feature extraction and reinforcement learning. The improved Transformer algorithm is combined for feature sequence processing. The multi-head attention mechanism is used for weighted aggregation and cluster analysis to establish an association index between threat information clusters and network nodes and timestamps.

Benefits of technology

It achieves efficient integration and dynamic tracking of network security threat information, improves the timeliness and effectiveness of network security protection, can quickly respond to changes in network security threats, and provides efficient threat information query and analysis tools.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639489A_ABST
    Figure CN120639489A_ABST
Patent Text Reader

Abstract

The invention discloses a network security threat information collection method and system, and the method comprises the steps: constructing a multi-dimensional heterogeneous network security threat information graph, extracting graph structure features through employing an optimized graph neural network, processing feature sequence fragments through employing an improved Transform algorithm in combination with parameters such as a risk level and an attack frequency, and carrying out the collection of the network security threat information graph. And after the clustering analysis is completed, the threat information cluster is stored and an index is established. The system comprises a topology construction unit, a graph feature extraction unit, a sequence division unit, a Transform processing unit, a clustering analysis unit and a storage index unit which work cooperatively in sequence. According to the method, the problems that in the prior art, heterogeneous information association processing is insufficient, and dynamic threat changes are difficult to adapt are effectively solved, efficient integration, deep analysis and rapid storage retrieval of network security threat information are achieved through an innovative algorithm and system architecture design, and powerful support is provided for network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a method and system for collecting network security threat information. Background Art

[0002] As digitalization deepens, the scale and complexity of cyberspace are growing exponentially. The widespread use of IoT devices, cloud computing services, and distributed systems is making network architectures increasingly large and complex. At the same time, cyberattack methods are constantly evolving, with new threats such as ransomware and supply chain attacks emerging frequently. Efficiently collecting cybersecurity threat information has become a critical component of risk prevention and cybersecurity assurance. How to quickly and accurately integrate multi-source, heterogeneous threat information and deeply analyze threat characteristics and correlations has become a pressing challenge.

[0003] Existing cybersecurity threat information aggregation technologies have significant shortcomings. For one thing, traditional methods struggle to effectively handle the complex relationships between heterogeneous information. As the claim addresses in constructing a multi-dimensional, heterogeneous cybersecurity threat information graph, traditional aggregation technologies lack the ability to model the complex relationships between device nodes, vulnerability nodes, and attack behavior nodes. They are unable to enhance inter-node association learning through multi-layer graph convolution and attention mechanisms, as optimized graph neural networks do. This makes it difficult to tease out a complete threat context from massive amounts of fragmented information, hindering overall threat assessment.

[0004] On the other hand, existing technologies lack adaptability to dynamically changing cybersecurity threats. Parameters such as the risk level and attack frequency of cybersecurity threats are constantly changing. Traditional aggregation techniques cannot dynamically adjust their attention calculations based on real-time threat parameters, as the improved Transformer algorithm does. This makes it difficult to adaptively capture evolving threat signatures. When new threats emerge or attack patterns change, traditional technologies are unable to respond promptly, making it difficult to meet the timeliness and accuracy requirements of cybersecurity protection. Summary of the Invention

[0005] In order to overcome the shortcomings and deficiencies of the prior art, the present invention provides a method and system for collecting network security threat information.

[0006] The technical solution adopted by the present invention is based on a network security threat information collection method, comprising the following steps:

[0007] Step S1: Construct a multi-dimensional heterogeneous network security threat information graph based on the network topology structure, classify the nodes in the network according to device type, network layer, and security domain attributes, and construct the edges between nodes based on network connection relationships, data interaction relationships, and security policy relationships to form an initial graph structure containing device nodes, service nodes, vulnerability nodes, and attack behavior nodes;

[0008] Step S2: Using an optimized graph neural network to extract features from the initial graph structure, and by designing a multi-layer graph convolution operation and combining it with an attention mechanism to perform reinforcement learning on the association relationship between different types of nodes, a preliminary feature set including node feature vectors and edge feature vectors is obtained;

[0009] Step S3: Divide the preliminary feature set according to the time series to form multiple feature sequence segments, each feature sequence segment contains network security threat features within a certain time window;

[0010] Step S4: Using the improved Transformer algorithm to process the feature sequence fragments, by redesigning the attention calculation method in the multi-head attention mechanism and combining the risk level, impact range, and attack frequency parameters of the network security threat, the key features in the feature sequence fragments are weighted and aggregated to obtain a feature vector sequence containing contextual association information;

[0011] Step S5: performing cluster analysis on the feature vector sequence, and classifying feature vectors with similar characteristics into one category based on similar characteristic attributes of network security threats, thereby forming multiple threat information clusters;

[0012] Step S6: number and identify each threat information cluster, store it in a preset threat information database, and establish an association index between the threat information cluster, the network node, and the timestamp.

[0013] Furthermore, in the optimized graph neural network, the node feature update model formula is designed as follows:

[0014]

[0015] in, represents the updated feature vector of the i-th node in the l+1th layer; Represents the feature vector of the jth node adjacent to node i in the lth layer; N(i) is the set of neighboring nodes of node i; α ij is the attention weight between node i and node j, which is calculated by the similarity of network security threat types and attack path dependency between nodes; W l and W′ l is the learnable weight matrix of layer l; σ is the activation function.

[0016] Furthermore, in the improved Transformer algorithm, a new attention calculation model formula is designed as follows:

[0017]

[0018] Among them, Q, K, and V are query matrix, key matrix, and value matrix respectively; dk is the dimension of the key matrix; β is the weighted coefficient matrix, whose element values ​​are dynamically adjusted according to the urgency parameter of the network security threat, the credibility parameter of the attack source, and the defense difficulty parameter; ⊙ represents the multiplication of the corresponding elements of the matrix; A(Q, K, V) is the calculated attention result.

[0019] Furthermore, in step S3, the length of the time window is adaptively adjusted according to the historical frequency parameter of network security threats and the network traffic fluctuation parameter, and the adjustment formula is:

[0020]

[0021] Among them, T w is the time window length; f i is the number of network security threats in the i-th historical time period; n is the number of historical time periods; F is the historical network traffic set; γ is the preset adjustment coefficient.

[0022] Furthermore, in step S4, when the improved Transformer algorithm is used to process the feature sequence fragments, the importance of each feature vector in the feature vector sequence is scored in combination with the asset value parameter and the attack path depth parameter of the network security threat. The scoring formula is:

[0023]

[0024] Among them, S i Score the importance of the i-th eigenvector; is the network asset value parameter corresponding to the i-th eigenvector; is the attack path depth parameter corresponding to the i-th eigenvector; w1 and w2 are weight coefficients set according to the network security policy.

[0025] Furthermore, in step S5, the cluster analysis adopts a density clustering algorithm based on the network security threat propagation speed parameter and the impact range parameter. During the clustering process, the neighborhood density formula is defined as:

[0026]

[0027] Among them, ρ i is the neighborhood density of the i-th eigenvector; d ij is the distance between the i-th eigenvector and the h-th eigenvector, calculated by the Euclidean distance of the network security threat feature vector; ∈ is the preset distance threshold; χ is the indicator function, when d ij When <∈, the value of χ is 1, otherwise it is 0.

[0028] Furthermore, in step S6, when establishing the association index between the threat information cluster and the network node and timestamp, the traceability difficulty parameter and the repair time parameter of the network security threat are introduced, and the index association strength model formula is constructed as follows:

[0029]

[0030] Among them, I s is the index association strength; T r D is the difficulty parameter for tracing the source of network security threats; t is the repair time parameter for network security threats; w3 and w4 are weight coefficients set according to network security management requirements.

[0031] Furthermore, in step S2, when using the optimized graph neural network for feature extraction, differentiated feature extraction weight matrices are designed for different types of network security threat nodes. The parameters of the weight matrix are dynamically updated according to the threat level parameter and attack frequency parameter of the node. The update formula is:

[0032]

[0033] Among them, W t is the weight matrix after the tth update; W t-1 is the weight matrix of the previous time; η is the learning rate; R t is the threat level parameter of the current node; R max is the preset maximum threat level; F t is the attack frequency parameter of the current node; F max is the preset maximum attack frequency; ΔW is the weight update step size.

[0034] Furthermore, in step S4, when the improved Transformer algorithm is used to process the feature sequence fragments, the attention heads in the multi-head attention mechanism are grouped and managed in combination with the horizontal diffusion parameter and vertical penetration parameter of the network security threat. The grouping formula is:

[0035] G k =mod(sum(P h ), M)

[0036] Among them, G k is the group to which the kth attention head belongs; P h is the vector consisting of the horizontal diffusion parameter and vertical penetration parameter of the network security threat corresponding to the h-th attention head; sum(P h ) is the vector P h The sum of all elements; M is the preset number of groups; mod is the modulo operation.

[0037] Based on the network security threat information collection system, the system includes:

[0038] A multi-dimensional heterogeneous threat information graph construction unit, which is used to classify nodes in the network according to device type, network hierarchy, and security domain attributes based on the network topology structure, and to construct edges between nodes based on network connection relationships, data interaction relationships, and security policy relationships, forming an initial multi-dimensional heterogeneous network security threat information graph structure that includes device nodes, service nodes, vulnerability nodes, and attack behavior nodes;

[0039] A graph structure feature extraction and reinforcement learning unit is connected to the multi-dimensional heterogeneous threat information graph construction unit. This unit utilizes an optimized graph neural network, designs multi-layer graph convolution operations, and combines an attention mechanism to perform reinforcement learning on the association relationships between different types of nodes, thereby extracting a preliminary feature set including node feature vectors and edge feature vectors from the initial graph structure.

[0040] A feature set fragmentation unit, connected to the graph structure feature extraction and reinforcement learning unit, is used to divide the preliminary feature set into time series, and form a plurality of feature sequence fragments containing network security threat features within a specific time window based on the relevant characteristics of the network security threat;

[0041] A feature sequence context association processing unit is connected to the feature set fragmentation unit, and uses an improved Transformer algorithm to redesign the attention calculation method in the multi-head attention mechanism, combining the risk level, impact range, and attack frequency parameters of network security threats to perform weighted aggregation on the key features in the feature sequence fragments, thereby obtaining a feature vector sequence containing context association information;

[0042] a cluster analysis and cluster generation unit connected to the feature sequence context association processing unit, which performs cluster analysis on the feature vector sequence and classifies feature vectors with similar characteristics into one category based on similar feature attributes of network security threats, thereby forming multiple threat information clusters;

[0043] The threat information cluster identification storage and multidimensional index construction unit is connected to the cluster analysis and cluster generation unit, and is used to number and identify each threat information cluster and store it in a preset threat information database. At the same time, it establishes an associated index between the threat information cluster and the network node and time stamp, completing the collection, storage and index construction of network security threat information.

[0044] Beneficial Effects: This invention proposes a method and system for aggregating network security threat information. The invention constructs a multi-dimensional, heterogeneous network security threat information graph, integrating different types of nodes, such as devices, services, vulnerabilities, and attack behaviors, and the connections between them, into a unified framework. Leveraging an optimized graph neural network, multi-layer graph convolution operations and an attention mechanism deeply explore potential connections between nodes, accurately extracting feature vectors of nodes and edges, and efficiently integrating fragmented information to present a complete threat picture. Addressing the shortcomings of traditional technologies in adapting to dynamically changing threats, the system utilizes an improved Transformer algorithm and redesigns the computational logic of the multi-head attention mechanism. Combining real-time parameters such as risk level, attack frequency, and impact range, the system performs weighted aggregation of key information in the feature sequence to dynamically capture the evolving trends of threat characteristics. Furthermore, the system adaptively adjusts the time window based on parameters such as the historical frequency of threats and network traffic fluctuations, and assigns importance scores to feature vectors based on parameters such as asset value and attack path depth, further enhancing the ability to respond to dynamic threats. At the information processing backend, cluster analysis and index association are performed by introducing parameters such as threat propagation speed and traceability difficulty, enabling orderly storage and rapid retrieval of threat information. The present invention forms a complete and efficient threat information collection system from information modeling, feature extraction, sequence processing to storage indexing, significantly enhancing the timeliness and effectiveness of network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is a flow chart of the method steps of the present invention;

[0046] Figure 2 It is a diagram of the system unit composition of the present invention. DETAILED DESCRIPTION

[0047] It should be noted that, unless there is a conflict, the embodiments in this application and the features described in the embodiments can be combined with each other. The application is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0048] like Figure 1 As shown, the network security threat information collection method and system includes the following steps:

[0049] Step S1: Construct a multi-dimensional heterogeneous network security threat information graph based on the network topology structure, classify the nodes in the network according to attributes such as device type, network layer, and security domain, and construct the edges between nodes based on network connection relationships, data interaction relationships, and security policy relationships to form an initial graph structure including device nodes, service nodes, vulnerability nodes, and attack behavior nodes;

[0050] Specifically, when constructing a multi-dimensional, heterogeneous network security threat information graph based on the network topology, the nodes in the network must be strictly classified according to attributes such as device type, network layer, and security domain. Device types include servers, terminal devices, and network switches; network layers include the core layer, aggregation layer, and access layer; and security domains are divided into different areas based on security protection requirements. Edges between nodes are constructed based on network connectivity relationships, data interaction relationships, and security policy relationships. Network connectivity relationships clarify the physical or logical connections between devices; data interaction relationships reflect the flow and frequency of data between nodes; and security policy relationships reflect the access control and protection rules between nodes. In this way, an initial graph structure is formed that includes device nodes, service nodes, vulnerability nodes, and attack behavior nodes, providing a structured data foundation for subsequent threat information analysis.

[0051] Integrate various types of information related to network security threats in the form of a graph structure, so that the relationships between originally scattered and isolated information can be clearly presented. In terms of implementation, it is first necessary to conduct a comprehensive scan of the network environment to obtain basic information such as the network device list, network connection configuration, and service operation status. Use professional network topology discovery tools to automatically identify nodes and connection relationships in the network. For vulnerable nodes and attack behavior nodes, use security monitoring equipment and log analysis systems to collect relevant data and map them to corresponding locations in the graph structure. During the construction process, it is necessary to ensure the accuracy and completeness of the information, and to annotate the attributes of the nodes and edges in detail so that subsequent steps can conduct in-depth analysis based on this.

[0052] Step S2: Using an optimized graph neural network to extract features from the initial graph structure, and by designing a multi-layer graph convolution operation and combining it with an attention mechanism to perform reinforcement learning on the association relationship between different types of nodes, a preliminary feature set including node feature vectors and edge feature vectors is obtained;

[0053] Specifically, step S2 uses an optimized graph neural network to extract features from the initial graph structure generated in step S1. The optimized graph neural network is designed with multi-layer graph convolution operations, which can aggregate and update node features on the graph structure. At the same time, combined with the attention mechanism, its role is to strengthen learning of the associations between different types of nodes. In network security threat scenarios, the degree of association between different types of nodes, such as device nodes and vulnerability nodes, and attack behavior nodes, is of great value in threat analysis. Through the attention mechanism, different weights can be assigned to these associations, highlighting the characteristics of key nodes and important connections, thereby obtaining a preliminary feature set containing node feature vectors and edge feature vectors.

[0054] Extracting representative and discriminative features from complex graph structures provides more refined and effective data for subsequent threat analysis. During implementation, the number of layers in the graph neural network and the dimensions of the node feature vectors must be determined, appropriately configured based on the network scale and the complexity of the threat information. During graph convolution, features are aggregated based on the node's neighboring node information, and node features are updated through multiple iterations. The attention mechanism calculates based on node attributes and connectivity, dynamically adjusting weights by calculating the similarity or dependency between nodes. During training, the graph neural network is supervised using labeled historical threat data, and model parameters are continuously optimized to improve the accuracy and effectiveness of feature extraction.

[0055] Step S3: Divide the preliminary feature set according to the time series to form multiple feature sequence segments, each feature sequence segment contains network security threat features within a certain time window;

[0056] Specifically, step S3 divides the preliminary feature set obtained in step S2 into time series segments, forming multiple feature sequence segments. The time series segmentation is based on the temporal dynamics of network security threats. Each feature sequence segment contains network security threat characteristics within a specific time window. The size of the time window is not a fixed value; it is related to the occurrence patterns of network security threats and changes in network traffic. Properly dividing the time series segments can cut continuous threat feature data into easily processable units, facilitating subsequent analysis of threat trends and patterns over different time periods.

[0057] Continuous threat signature data is structured to reflect the temporal characteristics of cybersecurity threats, facilitating subsequent in-depth analysis using time series analysis or sequence-based machine learning algorithms. The implementation method first determines the initial size of the time window. An appropriate time length can be selected based on statistical analysis of historical threat data. The initial feature set is then partitioned into segments at fixed time intervals. Each segment contains the feature vectors of all nodes and edges within that time window. During the partitioning process, a certain amount of overlap between adjacent segments is ensured to avoid missing information and ensure that the continuous changes in threat signatures are captured.

[0058] Step S4: Using the improved Transformer algorithm to process the feature sequence fragments, by redesigning the attention calculation method in the multi-head attention mechanism and combining parameters such as the risk level, impact range, and attack frequency of network security threats, the key features in the feature sequence fragments are weighted and aggregated to obtain a feature vector sequence containing contextual association information;

[0059] Specifically, step S4 uses the improved Transformer algorithm to process the feature sequence fragments generated in step S3. The improved Transformer algorithm redesigns the attention calculation method in the multi-head attention mechanism, combining parameters such as the risk level, impact range, and attack frequency of the network security threat to perform weighted aggregation of key features in the feature sequence fragments. In network security scenarios, different threat features have different degrees of impact on the overall threat situation. By introducing these parameters, it is possible to specifically highlight important features and suppress secondary features based on the actual threat situation, thereby obtaining a feature vector sequence containing contextual information.

[0060] Mining contextual information within feature sequence segments enhances understanding and analysis of cybersecurity threats. Implementation begins with configuring the structure of the improved Transformer algorithm, determining parameters such as the number of heads in the multi-head attention mechanism and the dimension of the feature vector. When calculating attention weights, various cybersecurity threat parameters are incorporated into the calculation process. Using specific computational logic, weights are assigned to different features based on their parameter values. Then, using weighted aggregation, features within the feature sequence segments are combined to generate a feature vector sequence containing contextual information. When training the algorithm model, a large amount of cybersecurity threat sequence data is used, and model parameters are adjusted to better adapt to the characteristics of cybersecurity threat data and accurately extract key features and contextual information.

[0061] Step S5: performing cluster analysis on the feature vector sequence, and classifying feature vectors with similar characteristics into one category based on similar characteristic attributes of network security threats, thereby forming multiple threat information clusters;

[0062] Specifically, step S5 performs cluster analysis on the feature vector sequence obtained in step S4. Cluster analysis is performed based on the similar characteristic attributes of network security threats. Its purpose is to group feature vectors with similar characteristics into one category, forming multiple threat information clusters. In the field of network security, similar threats often have similar characteristics such as attack methods, impact ranges, or propagation paths. Through cluster analysis, massive feature vectors can be classified and organized, so that data with similar threat characteristics are aggregated, facilitating subsequent centralized analysis and processing of threats of the same category.

[0063] Classify and summarize network security threat information to simplify the management and analysis of threat information. In terms of implementation, the first step is to select an appropriate clustering algorithm that can adapt to the characteristics of network security threat feature vectors. During the clustering process, the similarity between feature vectors is calculated based on a pre-set similarity metric. The similarity metric can be based on indicators such as the distance and angle between feature vectors. When the similarity between feature vectors meets a certain threshold, they are classified into the same category, forming a threat information cluster. During the clustering process, clustering parameters such as the number of cluster centers and the similarity threshold must be continuously adjusted to ensure that the clustering results can accurately reflect the actual classification of network security threats and improve the accuracy and effectiveness of clustering.

[0064] Step S6: number and identify each threat information cluster, store it in a preset threat information database, and establish an association index between the threat information cluster, the network node, and the timestamp.

[0065] Specifically, step S6 assigns a number to each threat information cluster generated in step S5 and stores it in a pre-set threat information database. Simultaneously, an association index is established, linking the threat information cluster with the network node and timestamp. The numbering uniquely identifies each threat information cluster, facilitating subsequent querying and management. Storing the threat information cluster in the database ensures persistent storage of threat information. Establishing the association index links the threat information cluster with the network node generating the threat and the time of the threat occurrence, providing clear source and time attributes for the threat information and facilitating subsequent tracing and analysis.

[0066] Build a complete network security threat information storage and retrieval system to provide network security managers with efficient and convenient threat information query and analysis tools. In terms of implementation, we must first design a reasonable numbering rule to ensure that the number of each threat information cluster is unique and readable. When storing threat information clusters, the characteristic vectors, related attributes and other information within the cluster are formatted and stored according to the database storage structure. When establishing an associated index, the number of the threat information cluster is associated with the corresponding network node identifier and timestamp through the database indexing mechanism. During the index establishment process, the balance between index performance and storage space must be considered, the index structure must be optimized, and the query efficiency of threat information must be improved so that when a network security incident occurs, relevant threat information can be retrieved quickly and accurately to provide support for security decision-making.

[0067] Preferably, in the optimized graph neural network, the node feature update model formula is designed as follows:

[0068]

[0069] in, represents the updated feature vector of the i-th node in the l+1th layer; Represents the feature vector of the jth node adjacent to node i in the lth layer; N(i) is the set of neighboring nodes of node i; α ij is the attention weight between node i and node j, which is calculated by the similarity of network security threat types and attack path dependency between nodes; W l and W′ l is the learnable weight matrix of layer l; σ is the activation function.

[0070] Specifically, during the optimized graph neural network processing, a specific node feature update mechanism was designed to more accurately update node features. This mechanism considers the feature information of the node itself and its neighboring nodes, and dynamically adjusts the contribution of different node features to the target node update by introducing attention weights calculated based on the similarity of network security threat types and attack path dependencies between nodes. A learnable weight matrix is ​​used to perform linear transformations on node features, and in conjunction with an activation function, completes the nonlinear transformation of features. The significance of this mechanism lies in its ability to strengthen associative learning between nodes, highlight key node features, and enhance the graph neural network's feature extraction capabilities for network security threat information graphs. During implementation, relevant data such as the node's threat type and attack path must first be collected to calculate the attention weights. The learnable weight matrix is ​​then optimized using training data, and the model parameters are continuously adjusted to achieve the best feature update effect.

[0071] Preferably, in the improved Transformer algorithm, a new attention calculation model formula is designed as follows:

[0072]

[0073] Among them, Q, K, and V are query matrix, key matrix, and value matrix respectively; d k is the dimension of the key matrix; β is the weighted coefficient matrix, whose element values ​​are dynamically adjusted according to the urgency parameter of the network security threat, the credibility parameter of the attack source, and the defense difficulty parameter; ⊙ represents the multiplication of the corresponding elements of the matrix; A(Q, K, V) is the calculated attention result.

[0074] Specifically, the improved Transformer algorithm redesigns the attention calculation method to combine the characteristics of network security threats and more effectively capture key information in feature sequences. The introduced weighting coefficient matrix is ​​dynamically generated based on parameters such as the urgency of the network security threat, the credibility of the attack source, and the difficulty of defense. These parameters reflect the different attributes and importance of the threat. When calculating attention, the weighting coefficient matrix is ​​combined with the conventional attention calculation process to adjust the attention weights of different features, allowing the algorithm to focus on more important threat features and enhance the ability to extract contextual information from feature sequences. During implementation, it is necessary to obtain various threat parameters in real time, dynamically update the weighting coefficient matrix according to parameter changes, and integrate it into the attention calculation process of the Transformer algorithm to ensure that the algorithm can adapt to different threat scenarios.

[0075] Preferably, in step S3, the length of the time window is adaptively adjusted according to a historical frequency parameter of network security threats and a network traffic fluctuation parameter, and the adjustment formula is:

[0076]

[0077] Among them, T w is the time window length; f i is the number of network security threats in the i-th historical time period; n is the number of historical time periods; F is the historical network traffic set; γ is the preset adjustment coefficient.

[0078] Specifically, the adaptive adjustment mechanism for the time window length in step S3 is designed to better match the dynamic characteristics of network security threats. This mechanism comprehensively considers the historical frequency of network security threats and network traffic fluctuations. The historical frequency reflects the regularity of threat emergence, while network traffic fluctuations reflect the dynamic changes in the network environment. Through specific calculation logic, these two factors are quantified and used to adjust the length of the time window, so that the time window can not only cover sufficient threat information but also adapt to the rhythm of threat changes in a timely manner. During implementation, it is necessary to first continuously collect and count the historical frequency data of threats and network traffic data, and then calculate and adjust the time window length in real time according to the established calculation method to ensure that the divided feature sequence segments can accurately reflect the characteristic changes of threats in different time periods.

[0079] Preferably, in step S4, when the improved Transformer algorithm is used to process the feature sequence fragment, the importance of each feature vector in the feature vector sequence is scored in combination with the asset value parameter and the attack path depth parameter of the network security threat. The scoring formula is:

[0080]

[0081] Among them, S i Score the importance of the i-th eigenvector; is the network asset value parameter corresponding to the i-th eigenvector; is the attack path depth parameter corresponding to the i-th eigenvector; w1 and w2 are weight coefficients set according to the network security policy.

[0082] Specifically, when the improved Transformer algorithm processes feature sequence fragments, a scoring mechanism based on network asset value and attack path depth is introduced to evaluate the importance of each feature vector. The network asset value parameter measures the importance of the assets affected by the threat, while the attack path depth parameter reflects the complexity and potential harm of the threat propagation. By linearly combining these two parameters according to certain weights, an importance score for each feature vector is obtained. This score is used for subsequent screening and weighted processing of feature vectors, allowing the algorithm to focus more on features with a greater impact on network security. During implementation, it is necessary to first determine the value assessment criteria for network assets and the calculation method for attack path depth. Then, for the threat scenario corresponding to each feature vector, the corresponding asset value and attack path depth parameters are obtained, and the importance score is calculated to provide a basis for feature processing.

[0083] Preferably, in step S5, the cluster analysis adopts a density clustering algorithm based on network security threat propagation speed parameters and impact range parameters. During the clustering process, the neighborhood density formula is defined as:

[0084]

[0085] Among them, ρ i is the neighborhood density of the i-th eigenvector; d ij is the distance between the i-th eigenvector and the j-th eigenvector, calculated by the Euclidean distance of the network security threat feature vector; ∈ is the preset distance threshold; χ is the indicator function, when d ij When <∈, the value of χ is 1, otherwise it is 0.

[0086] Specifically, the cluster analysis in step S5 adopts a density clustering algorithm based on the propagation speed and impact range of network security threats. The propagation speed parameter describes how fast the threat spreads in the network, and the impact range parameter reflects the breadth of the threat. These two parameters can effectively reflect the similarity and degree of aggregation of the threat. In the clustering process, the neighborhood density of each eigenvector is determined by calculating the number of other eigenvectors that meet a certain distance threshold in the neighborhood of the eigenvector. When the neighborhood density reaches a certain level, these eigenvectors are classified into the same category to form a threat information cluster. During implementation, a suitable distance threshold should be set first, and then the propagation speed and impact range data of the threat should be obtained in real time, the neighborhood density of the eigenvector should be calculated, and clustering operations should be performed based on the density to achieve effective classification of threat information.

[0087] Preferably, in step S6, when establishing the association index between the threat information cluster and the network node and the timestamp, the traceability difficulty parameter and the repair time parameter of the network security threat are introduced, and the index association strength model formula is constructed as follows:

[0088]

[0089] Among them, I s is the index association strength; T r D is the difficulty parameter for tracing the source of network security threats; t is the repair time parameter for network security threats; w3 and w4 are weight coefficients set according to network security management requirements.

[0090] Specifically, when establishing the association index between the threat information cluster and the network node and timestamp in step S6, the index association strength model introduced takes into account the difficulty of tracing the source and the repair time parameters of the network security threat. The difficulty of tracing the source reflects the difficulty of tracing the source of the threat, and the repair time parameter reflects the time required to eliminate the impact of the threat. These two parameters are of great significance for evaluating the importance and degree of association of threat information. By combining the reciprocals of these two parameters according to certain weights, the index association strength is obtained, which is used to determine the degree of association between the threat information cluster and the network node and timestamp. During implementation, it is necessary to first determine the evaluation method of the difficulty of tracing the source and the repair time, and then obtain the corresponding parameters for each threat information cluster and calculate the index association strength. According to the strength results, an efficient association index is established to facilitate rapid retrieval and analysis of threat information.

[0091] Preferably, in step S2, when the optimized graph neural network is used for feature extraction, differentiated feature extraction weight matrices are designed for different types of network security threat nodes. The parameters of the weight matrix are dynamically updated according to the threat level parameters and attack frequency parameters of the nodes. The update formula is:

[0092]

[0093] Among them, W t is the weight matrix after the tth update; W t-1 is the weight matrix of the previous time; η is the learning rate; R t is the threat level parameter of the current node; R max is the preset maximum threat level; F t is the attack frequency parameter of the current node; F max is the preset maximum attack frequency; ΔW is the weight update step size.

[0094] Specifically, the differentiated feature extraction for different types of network security threat nodes in step S2 is achieved by designing a dynamically updateable weight matrix. The update of the weight matrix depends on the threat level and attack frequency parameters of the node. The threat level reflects the severity of the threat faced by the node, and the attack frequency reflects the frequency of the node being attacked. By comparing these two parameters with the preset maximum threat level and maximum attack frequency, combined with the learning rate and weight update step size, the weight matrix is ​​iteratively updated. In this way, when using graph neural networks to extract features, the focus of feature extraction can be dynamically adjusted according to the actual threat situation of the node, thereby improving the pertinence and effectiveness of feature extraction. During implementation, it is necessary to monitor the threat level and attack frequency of the node in real time, and update the weight matrix regularly according to the update formula to ensure that the model can adapt to the feature extraction requirements of different types of threat nodes.

[0095] Preferably, in step S4, when the improved Transformer algorithm is used to process the feature sequence fragments, the attention heads in the multi-head attention mechanism are grouped and managed in combination with the horizontal diffusion parameter and the vertical penetration parameter of the network security threat. The grouping is based on the formula:

[0096] G k =mod(sum(P h ), M)

[0097] Among them, G k is the group to which the kth attention head belongs; P h is the vector consisting of the horizontal diffusion parameter and vertical penetration parameter of the network security threat corresponding to the h-th attention head; sum(P h ) is the vector P h The sum of all elements; M is the preset number of groups; mod is the modulo operation.

[0098] Specifically, in step S4, the multi-head attention mechanism of the improved Transformer algorithm is grouped and managed according to the lateral diffusion and vertical penetration parameters of network security threats. The lateral diffusion parameter describes the propagation of threats within the same network layer or region, and the vertical penetration parameter reflects the ability of threats to cross different network layers or security domains. These two parameters can reflect the propagation mode and complexity of the threat. By calculating the sum of the elements of the threat lateral diffusion and vertical penetration parameter vectors corresponding to each attention head, and taking the modulus of the preset number of groups, the attention heads are assigned to different groups. Different groups can be specially processed for threats with different propagation modes, thereby improving the algorithm's ability to extract complex threat features. During implementation, it is necessary to obtain the lateral diffusion and vertical penetration data of the threat in real time, calculate the parameter vector and perform grouping operations. During the operation of the Transformer algorithm, the attention heads are managed and features are extracted according to the grouping situation.

[0099] like Figure 2 As shown, based on the network security threat information collection system, the system includes:

[0100] A multi-dimensional heterogeneous threat information graph construction unit, which is used to classify nodes in the network according to attributes such as device type, network layer, and security domain based on the network topology structure, and to construct edges between nodes based on network connection relationships, data interaction relationships, and security policy relationships, forming an initial multi-dimensional heterogeneous network security threat information graph structure that includes device nodes, service nodes, vulnerability nodes, and attack behavior nodes;

[0101] A graph structure feature extraction and reinforcement learning unit is connected to the multi-dimensional heterogeneous threat information graph construction unit. This unit utilizes an optimized graph neural network, designs multi-layer graph convolution operations, and combines an attention mechanism to perform reinforcement learning on the association relationships between different types of nodes, thereby extracting a preliminary feature set including node feature vectors and edge feature vectors from the initial graph structure.

[0102] A feature set fragmentation unit, connected to the graph structure feature extraction and reinforcement learning unit, is used to divide the preliminary feature set into time series, and form a plurality of feature sequence fragments containing network security threat features within a specific time window based on the relevant characteristics of the network security threat;

[0103] A feature sequence context association processing unit is connected to the feature set fragmentation unit, and uses an improved Transformer algorithm to redesign the attention calculation method in the multi-head attention mechanism, combining parameters such as the risk level, impact range, and attack frequency of network security threats to perform weighted aggregation on the key features in the feature sequence fragments, thereby obtaining a feature vector sequence containing context association information;

[0104] a cluster analysis and cluster generation unit connected to the feature sequence context association processing unit, which performs cluster analysis on the feature vector sequence and classifies feature vectors with similar characteristics into one category based on similar feature attributes of network security threats, thereby forming multiple threat information clusters;

[0105] The threat information cluster identification storage and multidimensional index construction unit is connected to the cluster analysis and cluster generation unit, and is used to number and identify each threat information cluster and store it in a preset threat information database. At the same time, it establishes an associated index between the threat information cluster and the network node and time stamp, completing the collection, storage and index construction of network security threat information.

[0106] This paper proposes a method and system for aggregating network security threat information. This system constructs a multidimensional, heterogeneous network security threat information graph, structuring edges between various nodes, such as devices, services, vulnerabilities, and attack behaviors, based on network connections, data interactions, and security policy relationships, to form a unified graph structure model. Leveraging an optimized graph neural network, multi-layer graph convolution operations and an attention mechanism, this method performs reinforcement learning on the relationships between different types of nodes. It deeply mines the feature vectors of nodes and edges, organically integrating previously fragmented information to present a comprehensive picture and context of the threat. This addresses the difficulty traditional methods have in handling the complex relationships between heterogeneous information.

[0107] To address the shortcomings of traditional technologies in adapting poorly to dynamically changing cybersecurity threats, the system uses an improved Transformer algorithm and redesigns the calculation method of the multi-head attention mechanism. Combining real-time cybersecurity threat parameters such as risk level, attack frequency, and impact range, it performs weighted aggregation of key features in feature sequence fragments to achieve dynamic tracking of threat feature evolution. At the same time, the system adaptively adjusts the time window based on parameters such as the historical frequency of threats and network traffic fluctuations, and scores the importance of feature vectors based on parameters such as asset value and attack path depth. This enables the system to quickly respond to threat changes, greatly improving the ability to identify and aggregate new or mutated threats, and overcoming the shortcomings of traditional technologies in terms of timeliness and effectiveness.

[0108] In terms of subsequent information processing and management, the system introduces parameters such as threat propagation speed, tracing difficulty, and repair time to perform cluster analysis and index association. Feature vector sequences are clustered using a density-based clustering algorithm to form multiple threat information clusters. Each cluster is numbered and identified, and an associated index with network nodes and timestamps is established. At the same time, differentiated feature extraction weight matrices are designed for different types of threat nodes. These are dynamically updated based on parameters such as the node threat level and attack frequency. Attention heads are grouped and managed in combination with threat horizontal diffusion and vertical penetration parameters. This optimizes the organization, storage, and retrieval efficiency of threat information, further enhancing the system's processing capabilities and robustness for complex threat information, and providing solid and powerful support for network security protection.

[0109] In the description of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," "connected," and "fixed" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; they may refer to mechanical connections or electrical connections; they may refer to direct connections or indirect connections through an intermediate medium; and they may refer to internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0110] While embodiments of the present invention have been shown and described, it will be understood by those skilled in the art that various equivalent changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. Based on the network security threat information collection method, it is characterized by: The following steps are involved: Step S1: Construct a multi-dimensional heterogeneous network security threat information graph based on the network topology structure, classify the nodes in the network according to device type, network layer, and security domain attributes, and construct the edges between nodes based on network connection relationships, data interaction relationships, and security policy relationships to form an initial graph structure containing device nodes, service nodes, vulnerability nodes, and attack behavior nodes; Step S2: Using an optimized graph neural network to extract features from the initial graph structure, and by designing a multi-layer graph convolution operation and combining it with an attention mechanism to perform reinforcement learning on the association relationship between different types of nodes, a preliminary feature set including node feature vectors and edge feature vectors is obtained; Step S3: Divide the preliminary feature set according to the time series to form multiple feature sequence segments, each feature sequence segment contains network security threat features within a certain time window; Step S4: Using the improved Transformer algorithm to process the feature sequence fragments, by redesigning the attention calculation method in the multi-head attention mechanism and combining the risk level, impact range, and attack frequency parameters of the network security threat, the key features in the feature sequence fragments are weighted and aggregated to obtain a feature vector sequence containing contextual association information; Step S5: performing cluster analysis on the feature vector sequence, and classifying feature vectors with similar characteristics into one category based on similar characteristic attributes of network security threats, thereby forming multiple threat information clusters; Step S6: number and identify each threat information cluster, store it in a preset threat information database, and establish an association index between the threat information cluster, the network node, and the timestamp.

2. The method for collecting network security threat information according to claim 1, characterized in that: The optimized graph neural network designs a node feature update model formula as follows: in, represents the updated feature vector of the i-th node in the l+1th layer; Represents the feature vector of the jth node adjacent to node i in the lth layer; N(i) is the set of neighboring nodes of node i; α ij is the attention weight between node i and node j, which is calculated by the similarity of network security threat types and attack path dependency between nodes; W l and W′ l is the learnable weight matrix of layer l; σ is the activation function.

3. The method for collecting network security threat information according to claim 1, characterized in that: The improved Transformer algorithm designs a new attention calculation model formula: Among them, Q, K, and V are query matrix, key matrix, and value matrix respectively; d k is the dimension of the key matrix; β is the weighted coefficient matrix, whose element values ​​are dynamically adjusted according to the urgency parameter of the network security threat, the credibility parameter of the attack source, and the defense difficulty parameter; ⊙ represents the multiplication of the corresponding elements of the matrix; A(Q, K, V) is the calculated attention result.

4. The method for collecting network security threat information according to claim 1, characterized in that: In step S3, the length of the time window is adaptively adjusted according to the historical frequency parameter of network security threats and the network traffic fluctuation parameter, and the adjustment formula is: Among them, T w is the time window length; f i is the number of network security threats in the i-th historical time period; n is the number of historical time periods; F is the historical network traffic set; γ is the preset adjustment coefficient.

5. The method for collecting network security threat information according to claim 1, characterized in that: In step S4, when the improved Transformer algorithm is used to process the feature sequence fragments, the importance of each feature vector in the feature vector sequence is scored in combination with the asset value parameter and the attack path depth parameter of the network security threat. The scoring formula is: Among them, S i Score the importance of the i-th eigenvector; is the network asset value parameter corresponding to the i-th eigenvector; is the attack path depth parameter corresponding to the i-th eigenvector; w1 and w2 are weight coefficients set according to the network security policy.

6. The method for collecting network security threat information according to claim 1, characterized in that: In step S5, cluster analysis uses a density clustering algorithm based on the network security threat propagation speed parameter and the impact range parameter. During the clustering process, the neighborhood density formula is defined as: Among them, ρ i is the neighborhood density of the i-th eigenvector; d ij is the distance between the i-th eigenvector and the j-th eigenvector, calculated by the Euclidean distance of the network security threat feature vector; ∈ is the preset distance threshold; χ is the indicator function, when d ij When <∈, the value of χ is 1, otherwise it is 0.

7. The method for collecting network security threat information according to claim 1, characterized in that: In step S6, when establishing the association index between the threat information cluster, the network node, and the timestamp, the traceability difficulty parameter and the repair time parameter of the network security threat are introduced, and the index association strength model formula is constructed as follows: Among them, I s is the index association strength; T r D is the difficulty parameter for tracing the source of network security threats; t is the repair time parameter for network security threats; w3 and w4 are weight coefficients set according to network security management requirements.

8. The method for collecting network security threat information according to claim 1, characterized in that: In step S2, when using the optimized graph neural network for feature extraction, differentiated feature extraction weight matrices are designed for different types of network security threat nodes. The parameters of the weight matrix are dynamically updated according to the node threat level parameter and the attack frequency parameter. The update formula is: Among them, W t is the weight matrix after the tth update; W t-1 is the weight matrix of the previous time; η is the learning rate; R t is the threat level parameter of the current node; R max is the preset maximum threat level; F t is the attack frequency parameter of the current node; F max is the preset maximum attack frequency; ΔW is the weight update step size.

9. The method for collecting network security threat information according to claim 1, characterized in that: In step S4, when the improved Transformer algorithm is used to process the feature sequence fragments, the attention heads in the multi-head attention mechanism are grouped and managed in combination with the horizontal diffusion parameter and the vertical penetration parameter of the network security threat. The grouping is based on the formula: G k =mod(sum(P h ),M) Among them, G k is the group to which the kth attention head belongs; P h is the vector consisting of the horizontal diffusion parameter and vertical penetration parameter of the network security threat corresponding to the h-th attention head; sum(P h ) is the vector P h The sum of all elements; M is the preset number of groups; mod is the modulo operation.

10. Based on the network security threat information collection system, it is characterized by: The system includes: A multi-dimensional heterogeneous threat information graph construction unit, which is used to classify nodes in the network according to device type, network hierarchy, and security domain attributes based on the network topology structure, and to construct edges between nodes based on network connection relationships, data interaction relationships, and security policy relationships, forming an initial multi-dimensional heterogeneous network security threat information graph structure that includes device nodes, service nodes, vulnerability nodes, and attack behavior nodes; A graph structure feature extraction and reinforcement learning unit is connected to the multi-dimensional heterogeneous threat information graph construction unit. This unit utilizes an optimized graph neural network, designs multi-layer graph convolution operations, and combines an attention mechanism to perform reinforcement learning on the association relationships between different types of nodes, thereby extracting a preliminary feature set including node feature vectors and edge feature vectors from the initial graph structure. A feature set fragmentation unit, connected to the graph structure feature extraction and reinforcement learning unit, is used to divide the preliminary feature set into time series, and form a plurality of feature sequence fragments containing network security threat features within a specific time window based on the relevant characteristics of the network security threat; A feature sequence context association processing unit is connected to the feature set fragmentation unit, and uses an improved Transformer algorithm to redesign the attention calculation method in the multi-head attention mechanism, combining the risk level, impact range, and attack frequency parameters of network security threats to perform weighted aggregation on the key features in the feature sequence fragments, thereby obtaining a feature vector sequence containing context association information; a cluster analysis and cluster generation unit connected to the feature sequence context association processing unit, which performs cluster analysis on the feature vector sequence and classifies feature vectors with similar characteristics into one category based on similar feature attributes of network security threats, thereby forming multiple threat information clusters; The threat information cluster identification storage and multidimensional index construction unit is connected to the cluster analysis and cluster generation unit, and is used to number and identify each threat information cluster and store it in a preset threat information database. At the same time, it establishes an associated index between the threat information cluster and the network node and time stamp, completing the collection, storage and index construction of network security threat information.

Citation Information

Cited By

  • Firewall interception information clustering identification method and system based on network security

    CN121530624A