A network information security online monitoring and analyzing method
By collecting data on the spread of online information, generating temporal changes in discussion volume and the spread of negative sentiment, and combining this with the potential influence and credibility of the disseminating entity, the shortcomings of dissemination trend prediction and risk assessment in online information security monitoring are addressed, achieving accurate risk identification and efficient security monitoring.
Patent Information
- Application Number
- CN202510832096.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2045-06-20
AI Technical Summary
Existing technologies in network information security monitoring have failed to deeply analyze the temporal changes and potential impacts of information dissemination, resulting in insufficient accuracy in predicting dissemination trends and a lack of targeted risk control measures, thus reducing monitoring efficiency and effectiveness.
By collecting data on the spread of target network information, the system generates the temporal variation of discussion volume and the spread of negative sentiment. Combined with the potential influence score of the disseminating entity and the credibility of the account, it generates a spread security level and triggers risk alerts.
It enables accurate prediction of information dissemination trends and scientific risk assessment, accurately identifies key dissemination nodes, and enhances the reliability of assessment results and the efficiency of monitoring and early warning.
Smart Images

Figure CN120639642B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network information security monitoring, and relates to a network information security online monitoring and analyzing method. BACKGROUND
[0002] With the popularity of the Internet, network information security problems are increasingly prominent, and the rapid spread and diffusion of information may lead to serious consequences. Online monitoring and analysis of network information security is of great significance to social stability and the protection of personal and corporate rights. At present, network information security monitoring methods mainly focus on the auditing and filtering of information content, but the dynamic monitoring and risk assessment of the information dissemination process are not perfect enough.
[0003] For example, a public opinion analysis method and system based on a social network platform in Chinese patent publication No. CN116522013A, by obtaining the occurrence frequency and spatial position distribution of the comment text in the network public opinion information, extracting public opinion features and determining public opinion themes by combining a combination clustering algorithm, and finally determining the diffusion degree by information entropy and emotional polarity, it provides a certain reference for public opinion analysis.
[0004] However, the prior art has the following problems: 1. The prior art only analyzes from the perspective of public opinion features and emotional attributes, without in-depth analysis of the time sequence variation law in the information dissemination process, making it difficult to accurately capture the periodic fluctuations and decay trend of information dissemination, resulting in insufficient prediction accuracy of the dissemination trend.
[0005] 2. The prior art only focuses on the occurrence frequency and spatial position distribution of the comment text, and cannot comprehensively evaluate the potential impact of the dissemination subject on information diffusion, making it impossible to quickly locate the dissemination subject that plays a leading role in risk dissemination, resulting in a lack of targeted risk control measures and reducing the efficiency and effectiveness of network information security monitoring. SUMMARY
[0006] The purpose of the present application is to provide a network information security online monitoring and analyzing method, which collects the dissemination data of target network information, analyzes the dissemination trend, the potential impact of the dissemination subject and the account credibility, generates a diffusion security level and triggers a risk alarm, effectively solving the problems existing in the prior art.
[0007] To achieve the above purpose, the present application adopts the following technical solution: a network information security online monitoring and analyzing method, comprising: S1, collecting the original dissemination data of target network information, generating a discussion quantity time sequence variation degree of a set dissemination period, and analyzing the follow-up data stream corresponding to the target network information in the original dissemination data, and forming a negative emotional tendency diffusion degree by analyzing the emotional tendency of the follow-up data stream.
[0008] S2, the discussion time sequence change degree and negative emotional tendency diffusion degree and the set corresponding influence factor generate network information propagation trend change degree.
[0009] S3, by parallel acquisition network platform all propagation main body network information propagation time sequence flow, the network information propagation time sequence flow is integrated and analyzed to get information propagation efficiency index, combined with its in social network propagation center degree, generate each propagation main body to information diffusion potential influence score.
[0010] S4, verify all propagation main body's account credibility score, it is with potential influence score and network information propagation trend change degree multidimensional data fusion analysis, generate target network information diffusion security level.
[0011] S5, according to target network information diffusion security level trigger corresponding level risk visualization alarm.
[0012] Compared with the prior art, the present application has the following beneficial effects: (1) the present application generates short period, medium period and long period discussion time sequence change degree by collecting the original copy propagation data of the target network information, and forms negative emotional tendency diffusion degree by combining sentiment tendency analysis and geographic location distribution density of follow-up data flow, realizes the overall quantification of information propagation periodicity characteristics and negative emotional space diffusion, improves the accuracy of information propagation trend prediction and the scientific nature of negative risk assessment.
[0013] (2) the present application integrates and analyzes the propagation rate to get information propagation efficiency index by parallel acquisition of all propagation main body information propagation time sequence flow in network platform, generates the potential influence score of each propagation main body by combining social network propagation center degree, realizes the multidimensional evaluation of the influence of propagation main body, and can accurately identify the propagation node which plays a key role in information diffusion.
[0014] (3) the present application verifies the account credibility score by obtaining the fan scale quantity and authentication label of the propagation main body, and carries out multidimensional data fusion analysis on the potential influence score, network information propagation trend change degree, to generate the target network information diffusion security level, so that the security level determination fully considers the credibility of the propagation main body, and enhances the reliability and rationality of the evaluation result.
[0015] (4) the present application triggers the risk visualization alarm of corresponding level according to the target network information diffusion security level, realizes the real-time response and intuitive display of network information security risk, facilitates relevant personnel to take timely countermeasures, and improves the early warning efficiency and disposal timeliness of network information security monitoring. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the description of the embodiments. Obviously, the drawings in the following description only some of the embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0017] Figure 1 The method steps of the present application are shown in the flow chart.
[0018] Figure 2 The S1 step of the present application is shown in the flow chart.
[0019] Figure 3 The S3 step of the present application is shown in the flow chart.
[0020] Figure 4 The S4 step of the present application is shown in the flow chart. DETAILED DESCRIPTION
[0021] Various exemplary embodiments of the present application will now be described in detail below with reference to the accompanying drawings. Note that the relative arrangement, numerical expressions, and numerical values of the components and steps set forth in these embodiments are not limiting to the scope of the present application unless otherwise specifically stated. Also, it should be understood that the sizes of the various parts shown in the drawings are not drawn to scale for the convenience of description.
[0022] The following description of at least one example embodiment is merely illustrative in nature and is in no way limiting to the scope of the application and its applications or uses. Techniques, methods, and devices known to those of ordinary skill in the relevant art can not be discussed in detail, but should be considered part of the specification, where appropriate.
[0023] In all examples shown and discussed herein, any specific values should be interpreted as merely illustrative and not as a limitation. Thus, other examples of the example embodiments can have different values.
[0024] Please refer to Figure 1 As shown, the present application provides a network information security online monitoring and analysis method, comprising: S1, collecting original manuscript propagation data of target network information, generating discussion amount time sequence change degree of set propagation period, and analyzing the corresponding follow-up data stream of the target network information in the original manuscript propagation data, and forming a negative emotional tendency diffusion degree by performing emotional tendency analysis on the follow-up data stream.
[0025] As Figure 2As shown, the step content of S1 is specifically as follows: S11, extracting discussion quantity time sequence features from the collected target network information in the manuscript dissemination data of the manuscript dissemination platform, and statistically analyzing short-period discussion quantity fluctuation features, medium-period discussion quantity trend features, and long-period discussion quantity decay features.
[0026] S12, fusing and analyzing the short-period discussion quantity fluctuation features, the medium-period discussion quantity trend features, and the long-period discussion quantity decay features to generate a discussion quantity time sequence change degree.
[0027] Further, the specific content of the step S12 is as follows: extracting the discussion quantity of each unit time in the short period, the medium period, and the long period from the discussion quantity time sequence features.
[0028] constructing a short-period discussion quantity change curve from the discussion quantity of each unit time in the short period, extracting a maximum propagation growth rate; obtaining a smoothed value of each unit time by exponential smoothing from the discussion quantity of each unit time in the medium period, and obtaining a discussion quantity persistence index based on the ratio of the mean value of the smoothed value to the standard deviation of the smoothed value; and obtaining a decay rate by linear regression analysis of the discussion quantity of each unit time in the long period through the least square method.
[0029] normalizing the maximum propagation growth rate, the discussion quantity persistence index, and the decay rate, and generating a discussion quantity time sequence change degree by linear weighting of the normalized data.
[0030] The weight setting mode of the maximum propagation growth rate, the discussion quantity persistence index, and the decay rate is to collect a large amount of historical discussion quantity data and determine the weight by using a statistical analysis method. For example, principal component analysis is performed on the collected historical data, and it is found through PCA analysis that the principal component of the maximum propagation growth rate can explain 40% of the data variance, the discussion quantity persistence index can explain 30% of the data variance, and the decay rate can explain 30% of the data variance. Therefore, the weights can be set according to this proportion, which are 0.4, 0.3, and 0.3, respectively.
[0031] In one specific embodiment, the short-period discussion quantity fluctuation features are the dynamic changes of the discussion quantity in minute unit time; the medium-period discussion quantity trend features are the persistence of discussion heat in hour unit time; and the long-period discussion quantity decay features are the decay of the discussion quantity with time in day unit time.
[0032] The maximum propagation growth rate is the maximum value selected from the propagation growth rates of each minute, wherein the propagation growth rate is the growth rate of the discussion quantity in the adjacent minute to the discussion quantity of the previous minute.
[0033] The discussion quantity persistence index is to aggregate the discussion quantity of each minute by hour, which is to sum the discussion quantity of all minutes in each hour to obtain the discussion quantity of each hour, and the smoothed value of each hour is obtained by the exponential smoothing formula wherein a and b are the smoothed values of the first hour and the second hour, and respectively, a and b are the smoothed values of the first hour and the second hour, is a set smoothing coefficient, and the value is between 0 and 1, for example, 0.4, is the discussion quantity of the first hour, and the smoothed value mean and the smoothed value standard deviation are obtained according to the smoothed value of each hour, and the ratio of the smoothed value mean to the smoothed value standard deviation is obtained to obtain the discussion quantity persistence index.
[0034] The decay rate is to count the discussion quantity of each day, to construct a linear regression equation with the day number as the independent variable and the discussion quantity as the dependent variable, to fit the data by the least square method, and to obtain the slope of the regression equation as the decay rate.
[0035] S13, obtaining the comment text, comment time and geographic location of each follow-up user from the follow-up data stream, dividing the follow-up users into different time periods based on the comment time of each follow-up user, and counting the follow-up users in different time periods.
[0036] S14, performing sentiment tendency analysis on the comment text of each follow-up user in different time periods to obtain a negative sentiment tendency growth acceleration rate, and screening the geographic locations of all follow-up users with negative sentiment tendency in different time periods.
[0037] S15, based on the geographic location, the geographic area is circled, based on the circled geographic area, the follow-up user distribution density is analyzed, and the follow-up user distribution density and the negative sentiment tendency growth acceleration rate are fused and analyzed to form a negative sentiment tendency diffusion degree.
[0038] Further, the analysis process of the negative sentiment tendency diffusion degree is: preprocessing the comment text of each follow-up user in different time periods, and marking the sentiment polarity of all words by substituting the preprocessed comment text into a set general sentiment dictionary, wherein the sentiment polarity includes positive sentiment words, neutral sentiment words and negative sentiment words.
[0039] Based on the sentiment polarity of all words, the sentiment tendency of the comment text is judged, the number of follow-up users with negative sentiment tendency and the geographic location of each follow-up user in different time periods are counted.
[0040] Comparative analysis is performed on the number of follow-up users with negative sentiment tendency in different time periods and adjacent time periods to generate a negative sentiment tendency growth acceleration rate.
[0041] The geographical location of each follow-up user with a negative emotional tendency in different time periods is geographically circled, and the distribution density of the follow-up users in the circled geographical area is analyzed.
[0042] The negative emotional tendency growth acceleration rate and the follow-up user distribution density are standardized, and the standardized data is subjected to nonlinear synergistic effect analysis to obtain the negative emotional tendency diffusion degree.
[0043] The nonlinear synergistic effect analysis can be a product operation, because the negative emotional tendency growth acceleration rate and the follow-up user distribution density have a coupling effect on the diffusion degree, that is, the change of the negative emotional tendency growth rate in a high user density area will amplify the diffusion effect in the form of product. For example, if the follow-up user distribution density in a geographical area is concentrated, and the negative emotional growth rate in the geographical area suddenly accelerates, the product result will significantly increase, reflecting the risk of accelerated diffusion of network information.
[0044] In a specific embodiment, the preprocessing of the comment text includes removing garbled characters, special symbols and redundant repeated content, and using a word segmentation tool for word segmentation, filtering general stop words such as "de" and "le", and retaining negative words with emotional tendencies such as "bu" and "meiyou", and outputting all processed words.
[0045] In a specific embodiment, the emotional tendency judgment method of the comment text is to count the number of positive emotional words and the number of negative emotional words in the comment text, and when the number of positive emotional words is more than the number of negative emotional words, the emotional tendency of the comment text is positive emotional tendency, and vice versa.
[0046] The negative emotional tendency growth acceleration rate generation method is to obtain the difference between the number of follow-up users of the negative emotional tendency in different time periods and the number of follow-up users of the negative emotional tendency in adjacent time periods, and take the ratio of the difference to the number of follow-up users of the negative emotional tendency in the adjacent time period as the negative emotional tendency growth rate, and take the average of the negative emotional tendency growth rates in different time periods to obtain the negative emotional tendency growth acceleration rate.
[0047] The present application generates the discussion amount time sequence change degree of short, medium and long periods by collecting the original document propagation data of the target network information, and combines the emotional tendency analysis and geographical location distribution density of the follow-up data stream to form the negative emotional tendency diffusion degree, realizes the comprehensive quantification of the periodic characteristics of information propagation and the spatial diffusion of negative emotions, and improves the accuracy of information propagation trend prediction and the scientificity of negative risk assessment.
[0048] S2, generate network information propagation trend change degree from the discussion amount time sequence change degree and the negative emotional tendency diffusion degree and the corresponding influence factor set.
[0049] Further, the discussion quantity time series variation degree and the negative sentiment tendency diffusion degree and the corresponding influence factor are set as follows: a large amount of historical network information of the same or similar topic and platform as the target network information is collected, the actual values of the discussion quantity time series variation degree and the negative sentiment tendency diffusion degree are calculated according to the large amount of historical network information, the final propagation trend variation degree is recorded, the prediction influence values of the discussion quantity time series variation degree and the negative sentiment tendency diffusion degree on the propagation trend variation degree are quantified by using multiple linear regression analysis, and the corresponding influence factor is determined according to the proportion of the prediction influence values.
[0050] S3, the network information propagation time series flow of all propagation subjects in the network platform is collected in parallel, the information propagation efficiency index is obtained by performing propagation rate integration analysis on the network information propagation time series flow, and the potential influence score of each propagation subject on information diffusion is generated in combination with the social network propagation center degree.
[0051] As shown in Figure 3 , the step content of S3 is specifically as follows: S31, an information propagation flow curve is constructed according to the information propagation time series flow of all propagation subjects in the network platform, and the burst duration, peak flow and half-life time are identified from the information propagation flow curve.
[0052] The burst duration is the duration from the publication of the target network information to the peak propagation flow, the peak flow is the maximum propagation flow in the information propagation flow curve, and the half-life time is the time required for the target network information propagation flow to decay to half of the peak value.
[0053] S32, the burst duration, peak flow and half-life time are subjected to propagation rate integration analysis to obtain the information propagation efficiency index.
[0054] Further, the content of the information propagation efficiency index is specifically as follows: based on the half-life flow corresponding to the half-life time and the interval duration between the half-life time and the burst time obtained from the information propagation flow curve, the ratio of the difference between the peak flow and the half-life flow to the interval duration is taken as the half-life rate, and the decay level corresponding to the half-life rate is matched.
[0055] The ratio of the peak flow to the burst duration is analyzed to obtain the burst rate, and the burst level corresponding to the burst rate is matched.
[0056] The decay level and the burst level are subjected to grade combination analysis to determine the information propagation efficiency index.
[0057] In a specific embodiment, each decay level includes a high decay level, a medium decay level and a low decay level, and each decay level is set to correspond to a half-life rate range, for example, the high decay level represents extremely fast decay, the medium decay level represents medium decay, and the low decay level represents slow decay. , low decay level represents slow decay, such as .
[0058] Each burst level includes high burst level, medium burst level and low burst level, and each burst level is set to correspond to a burst rate range, for example, high burst level represents instantaneous burst, such as , medium burst level represents rapid rise, such as , low burst level represents slow rise, such as .
[0059] The level combination analysis of the information propagation efficiency index is based on the preset level combination rule, for example: if the burst level of a certain propagation subject is high burst level and the decay level is low decay level, the information propagation efficiency index of the propagation subject is the highest value, wherein the range of the information propagation efficiency index is set to , and the highest value is 0.9; if the burst level is high burst level and the decay level is medium decay level, the information propagation efficiency index of the propagation subject is 0.8; indicating that the propagation subject can well trigger rapid information propagation and ensure that the information has a long lasting influence.
[0060] If the burst level is medium burst level and the decay level is low decay level, the information propagation efficiency index of the propagation subject is 0.7; if the burst level is medium burst level and the decay level is medium decay level, the information propagation efficiency index of the propagation subject is 0.6; if the burst level is high burst level and the decay level is high decay level, the information propagation efficiency index of the propagation subject is 0.5; if the burst level is medium burst level and the decay level is high decay level, the information propagation efficiency index of the propagation subject is 0.4; if the burst level is low burst level and the decay level is low decay level, the information propagation efficiency index of the propagation subject is 0.3, indicating that the performance of the propagation subject in the two key propagation stages is general, and the propagation efficiency is at a medium level.
[0061] If the burst level is low burst level and the decay level is medium decay level, the information propagation efficiency index of the propagation subject is 0.2; if the burst level is low burst level and the decay level is high decay level, the information propagation efficiency index of the propagation subject is 0.1, indicating that the propagation subject is poor in triggering rapid information propagation and maintaining information lasting heat.
[0062] S33, obtains the forwarding level of the target network information corresponding to each propagation subject and the key user participation amount of each level from the network platform, and obtains the social network propagation center degree based on the node weight of each level.
[0063] Further, the specific content of the step S33 includes: counting all participating users of each forwarding level of the target network information corresponding to each propagation subject, screening out machine forwarding users to obtain the total amount of participating users after screening, and performing ratio on the key user participation amount of each level and the corresponding total amount of participating users to obtain the key user participation degree.
[0064] The product operation result of each level key user participation degree and the node weight of the corresponding level is fused to obtain the social network propagation centrality. For example, the social network propagation centrality is the sum of the product operation results of each level and the node weight of the corresponding level.
[0065] The account registration information of the machine forwarding user may have problems. For example, the registration time is short but the forwarding amount is extremely large, or there is an abnormal difference between the registration place and the active place. Many machine forwarding accounts are registered in batches by automatic programs, and their registration information may contain false identity information. Screening out machine forwarding users can ensure that the data of the total amount of participating users is more accurate. If the machine forwarding users are included, the number of participating users will be overestimated. For example, when evaluating the effect of network information propagation, the existence of a large number of machine forwarding users will make the propagation range seem very wide, but in fact there are not so many real users participating. By removing these machine forwarding users, the propagation scale and influence of the target network information in real users can be more truly reflected.
[0066] In a specific embodiment, the levels can be a first forwarding level, a second forwarding level, a third forwarding level, etc. Network information in social network forwarding usually increases with the level, and the influence naturally decays. For example, the first forwarding level: the information propagation node based on the propagation subject directly propagates, determines the network information starting potential energy, and the weight is set to 0.5.
[0067] The second forwarding level: it can reach the fans or followers of the first forwarding level, but the propagation range is limited by the influence of the first node, and the weight is set to 0.25, which is 50% attenuation compared with the first forwarding level, reflecting the energy loss in diffusion.
[0068] The third forwarding level: it relies on the second forwarding level for further diffusion, the propagation link is longer, and the information loss is more, and the weight is set to 0.125. In this way, the weight of the subsequent level can be decreased by 50% per level, which is consistent with the actual propagation decay speed.
[0069] S34, the information propagation efficiency index and the social network propagation centrality are synergistically combined and analyzed to generate a potential influence score of each propagation subject on information diffusion.
[0070] Further, the specific content of the step S34 includes: sorting the information propagation efficiency index of each propagation subject and the social network propagation centrality according to the order from large to small in value to obtain the sequence number of each propagation subject in the information propagation efficiency index sequence and the social network propagation centrality sequence, and obtaining the potential influence score of each propagation subject on information diffusion based on the sequence number corresponding influence score of the information propagation efficiency index sequence and the social network propagation centrality sequence. Wherein the potential influence score is the average of the influence score corresponding to the sequence number of the information propagation efficiency index sequence and the influence score corresponding to the sequence number of the social network propagation centrality sequence.
[0071] Wherein the sequence number represents the ranking of the propagation subject in the two dimensions of information propagation efficiency index and social network propagation centrality, and the influence score is the value weight given to the ranking position. The earlier the sequence number is, the stronger the influence of the propagation subject in this dimension is, and the higher the score should be. The influence score corresponding to each sequence number is analyzed by using exponential scoring method, for example, according to the fixed attenuation coefficient 0.8, the influence score of the first ranking is the highest basic score, the influence score of the second ranking is the highest basic score multiplied by 0.8, and so on, highlighting that the first value is much higher than the subsequent propagation characteristics.
[0072] The present application obtains the information propagation efficiency index by collecting the information propagation time sequence flow of all propagation subjects in the network platform in parallel, integrating and analyzing the propagation rate, and combining the social network propagation centrality to generate the potential influence score of each propagation subject, thereby realizing the multi-dimensional evaluation of the influence of the propagation subject and accurately identifying the propagation node that plays a key role in information diffusion.
[0073] S4, verifying the account credibility score of all propagation subjects, and performing multi-dimensional data fusion analysis on the potential influence score and the network information propagation trend change degree to generate a target network information diffusion security level.
[0074] As shown in Figure 4 The specific content of the step S4 is as follows: S41, obtaining the fan scale quantity and authentication label of each propagation subject, matching the fan scale level based on the fan scale quantity of each propagation subject, and verifying the account credibility score of each propagation subject according to the credibility score corresponding to the fan scale level and the authentication label.
[0075] The verification method of the account credibility score is: comparing the matched fan scale level with the credibility score corresponding to each set fan scale level to obtain the credibility score corresponding to the matched fan scale level, and similarly obtaining the credibility score corresponding to the authentication label, and performing mean analysis on the credibility score corresponding to the matched fan scale level to obtain the account credibility score.
[0076] The credibility score corresponding to each fan scale level and each authentication label can be achieved through the following standardization process: based on platform official statistical data, the fan base is divided into intervals, and the accounts in the head, middle and tail are scored according to the actual influence, such as 9 points for more than 1 million, 7 points for 10-100 million, etc.; at the same time, a label scoring system is established according to the authority of each authentication type, such as 10 points for official authentication, 8 points for expert authentication, 6 points for personal gold V authentication, and 3 points for ordinary authentication; finally, the initial score is calibrated through expert review combined with historical account trustworthy behavior data, including content violation rate and false information dissemination record, to ensure that the score strictly corresponds to the actual credibility.
[0077] S42, according to the account credibility score and the potential influence score of each propagation subject, determine the account state label according to the set account state label rule, and screen the number of high-risk labeled accounts and the proportion of suspicious labeled accounts.
[0078] In a specific embodiment, the account state label rule is set as follows: if the account credibility score is greater than the set credibility score threshold and the potential influence score is greater than the set influence score threshold, the account state is a high credibility labeled account; if the account credibility score is greater than the set credibility score threshold and the potential influence score is less than or equal to the set influence score threshold, the account state is a general labeled account; if the account credibility score is less than or equal to the set credibility score threshold and the potential influence score is greater than the set influence score threshold, the account state is a high-risk labeled account; if the account credibility score is less than or equal to the set credibility score threshold and the potential influence score is less than or equal to the set influence score threshold, the account state is a suspicious labeled account.
[0079] S43, input the network information propagation trend change degree, the number of high-risk labeled accounts and the proportion of suspicious labeled accounts into the diffusion security decision rule, and output the target network information diffusion security level.
[0080] In a specific embodiment, the diffusion security decision rule is as follows: when the network information propagation trend change degree is greater than the preset change degree threshold, the number of high-risk labeled accounts is greater than the set high-risk account number threshold or the proportion of suspicious labeled accounts is greater than the set suspicious account proportion threshold, then the network information diffusion security level is high risk level, otherwise the network information diffusion security level is low risk level.
[0081] When the network information propagation trend change degree is less than or equal to the preset change degree threshold, the number of high-risk labeled accounts is greater than the set high-risk account number threshold or the proportion of suspicious labeled accounts is greater than the set suspicious account proportion threshold, then the network information diffusion security level is medium risk level, otherwise the network information diffusion security level is low risk level.
[0082] The application verifies the account credibility score by acquiring the fan scale quantity and authentication label of the propagation subject, and performs multi-dimensional data fusion analysis on the potential influence score and network information propagation trend change degree, and generates a target network information diffusion security level, so that the security level determination fully considers the credibility of the propagation subject, and the reliability and rationality of the evaluation result are enhanced.
[0083] S5, triggering a risk visualization alarm of a corresponding level according to the target network information diffusion security level.
[0084] According to the target network information diffusion security level, the application triggers a risk visualization alarm of a corresponding level, realizes real-time response and intuitive display of network information security risks, facilitates relevant personnel to take timely response measures, and improves the early warning efficiency and disposal timeliness of network information security monitoring.
[0085] The above formulas are all dimensionless numerical calculations, the formulas are obtained by software simulation of a large amount of data to obtain a formula of the latest real situation, and the preset parameters in the formula are set by a person skilled in the art according to the actual situation.
[0086] The above embodiments can be realized by software, hardware, firmware or any combination thereof, in whole or in part. When realized by software, the above embodiments can be realized in the form of a computer program product in whole or in part.
[0087] Those skilled in the art can realize that the modules and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0088] In addition, the functional modules in each embodiment of the present application can be integrated in one processing module, or each module can exist physically, or two or more modules can be integrated in one module.
[0089] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any skilled person in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0090] Finally, the above only is the preferred embodiment of the present application, and is not used to limit the present application, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A method for online monitoring and analysis of network information security, characterized in that, include: S1. Collect the original dissemination data of the target network information, generate the discussion volume time-series change degree for the set dissemination period, and analyze the follow-up comment data stream corresponding to the target network information in the original dissemination data. Perform sentiment analysis on the follow-up comment data stream to form the negative sentiment diffusion degree. S11. Extract the discussion volume time sequence characteristics from the original text dissemination data of the collected target network information on the original text dissemination platform, and statistically analyze the short-cycle discussion volume fluctuation characteristics, medium-cycle discussion volume trend characteristics, and long-cycle discussion volume decay characteristics to obtain the maximum dissemination growth rate, discussion volume persistence index, and decay rate, respectively. S12. Normalize the maximum propagation growth rate, the discussion volume persistence index, and the decay rate, and then perform linear weighting on the normalized data to generate the discussion volume time-series change degree. S13. Obtain the comment text, comment time and geographical location of each commenting user from the comment data stream, divide the commenting user into different time periods based on the comment time of each commenting user, and count each commenting user in different time periods; S14. Perform sentiment analysis on the comment texts of each commenter in different time periods to obtain the negative sentiment growth acceleration rate, and filter the geographical locations of all commenters with negative sentiment in different time periods. S15. Delineate geographical regions based on geographic location, analyze the distribution density of commenting users based on the delineated geographical regions, standardize the growth rate of negative sentiment and the distribution density of commenting users, and perform nonlinear synergy effect analysis on the standardized data to obtain the diffusion degree of negative sentiment. S2. The degree of change in the discussion volume over time and the degree of diffusion of negative sentiment are compared with the corresponding set influencing factors to generate the degree of change in the trend of network information dissemination. S3. By collecting the network information propagation time-series traffic of all propagation entities in the network platform in parallel, the propagation time-series traffic of network information propagation is integrated and analyzed to obtain the information propagation efficiency index. Combined with its propagation centrality in the social network, the potential impact score of each propagation entity on information diffusion is generated. S31. Construct an information propagation flow curve based on the information propagation time sequence flow of all propagation entities in the network platform, and identify the burst duration, peak flow and half-life from the information propagation flow curve; S32. The information dissemination efficiency index is obtained by integrating the burst duration, peak flow and half-life with the propagation rate analysis. S33. Obtain the forwarding level of the target network information corresponding to all propagation subjects from the network platform and the participation of key users at each level, and obtain the social network propagation centrality based on the node weights at each level. S34. Sort the information dissemination effectiveness index and social network dissemination centrality of each dissemination subject in descending order of value to obtain the sequence number of each dissemination subject in the information dissemination effectiveness index sequence and social network dissemination centrality sequence. Based on the influence score corresponding to the sequence number of the information dissemination effectiveness index sequence and social network dissemination centrality sequence, obtain the potential influence score of each dissemination subject on information diffusion. S4. Verify the account credibility scores of all dissemination entities, and perform multi-dimensional data fusion analysis with the potential impact score and the degree of change in the trend of network information dissemination to generate the target network information diffusion security level; S5. Trigger corresponding level of risk visualization alarm based on the target network information dissemination security level.
2. The method for online monitoring and analysis of network information security according to claim 1, characterized in that: The specific content of step S11 is as follows: Extract the discussion volume per unit time within the short, medium, and long periods from the temporal characteristics of the discussion volume; To construct a short-cycle discussion volume change curve, the maximum propagation growth rate is extracted by considering the discussion volume per unit time within the short cycle. Within the medium cycle, the discussion volume per unit time is smoothed exponentially to obtain smoothed values for each unit time. The persistence index of discussion volume is obtained based on the ratio of the mean of the smoothed values to the standard deviation of the smoothed values. Within the long cycle, the discussion volume per unit time is analyzed using linear regression with the least squares method to obtain the decay rate.
3. The method for online monitoring and analysis of network information security according to claim 1, characterized in that: The analysis process for the distribution density of the commenting users is as follows: The comment texts of each user who commented within different time periods were preprocessed, and the preprocessed comment texts were substituted into a general sentiment dictionary to mark the sentiment polarity of all words. The sentiment tendency of the comment text is judged based on the sentiment polarity of all words, and the number of users with negative sentiment tendencies and the geographical location of each user are counted in different time periods. By comparing and analyzing the number of users commenting with negative sentiment in different time periods and their adjacent time periods, the growth rate of negative sentiment can be generated. The geographical locations of users who left comments with negative sentiment tendencies at different time periods were defined, and the distribution density of users leaving comments within the defined geographical areas was analyzed.
4. The method for online monitoring and analysis of network information security according to claim 1, characterized in that: The specific content of the information dissemination effectiveness index is as follows: Based on the information propagation flow curve, the half-life flow corresponding to the half-life time and the interval between the half-life time and the burst time are obtained. The ratio of the difference between the peak flow and the half-life flow to the interval is used as the half-life rate, and the decay level corresponding to the half-life rate is matched. The burst rate is obtained by analyzing the ratio of peak flow to burst duration, and the burst level is matched with the burst rate. The information dissemination effectiveness index is determined by combining the attenuation level and the outbreak level.
5. The method for online monitoring and analysis of network information security according to claim 1, characterized in that: The specific content of step S33 includes: The total number of participating users at each forwarding level of the target network information corresponding to each dissemination entity is obtained by counting all participating users at each forwarding level and filtering out machine forwarding users. The participation rate of key users at each level is compared with the total number of participating users to obtain the participation rate of key users. The social network propagation centrality is obtained by multiplying the key user engagement at each level with the node weight at the corresponding level, and then combining the product result with the node weight at each level.
6. The method for online monitoring and analysis of network information security according to claim 1, characterized in that: The specific content of step S4 is as follows: S41. Obtain the number of followers and certification tags of each dissemination entity, match the follower scale level based on the number of followers of each dissemination entity, and verify the account credibility score of each dissemination entity according to the credibility score corresponding to the follower scale level and certification tag. S42. Based on the account credibility score and potential impact score of each dissemination entity, determine the account status label according to the set account status labeling rules, and filter the number of high-risk labeled accounts and the proportion of suspicious labeled accounts; S43. Input the degree of change in the trend of network information dissemination, the number of high-risk marked accounts, and the proportion of suspicious marked accounts into the diffusion security decision rules, and output the target network information diffusion security level.
7. The online monitoring and analysis method for network information security according to claim 6, characterized in that: The verification method for the account credibility score is as follows: The matching fan size level is compared with the credibility score corresponding to each set fan size level to obtain the credibility score corresponding to the matching fan size level. Similarly, the credibility score corresponding to the certification tag is obtained. The average of these scores and the credibility scores corresponding to the matching fan size level is then analyzed to obtain the account credibility score.
Citation Information
Patent Citations
Public opinion analysis method and system based on social network platform
CN116522013A
Cross-platform dissemination trend evaluation and grading method based on specific events
CN111949848A
Social network topic discussion influence detection method and system
CN117332161A