Network range data processing system and method, electronic equipment and storage medium

Through the network target range data processing system, data transmission plug-ins and collection agents are used for data collection, and the LSTM-Autoencoder model is used for analysis, which solves the problem of network target range data collection and analysis and realizes efficient and accurate data processing and real-time monitoring.

CN120692182AActive Publication Date: 2025-09-23CHINA ELECTRONICS CORP 6TH RES INST

Patent Information

Application Number
CN202510895867.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2025-09-23
Estimated Expiration
2045-06-30

AI Technical Summary

Technical Problem

Existing cyber range data collection tools lack specificity and are unable to meet the data collection needs of cyber ranges. In addition, they lack effective analysis methods to process the collected data.

Method used

A cyber range data processing system was designed, including a cyber range platform and a cyber range. Data collection and analysis were performed through data transmission plug-ins and collection agents. The collected data was processed using a network detection model, and the network operation status was detected in combination with the LSTM-Autoencoder model.

Benefits of technology

It realizes the targeted collection and analysis of network target range data, improves the efficiency and accuracy of data collection, can monitor the network operation status in real time, and supports large-scale data storage and rapid retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692182A_ABST
    Figure CN120692182A_ABST
Patent Text Reader

Abstract

The invention provides a network target range data processing system and method, electronic equipment and a storage medium. The system comprises a network target range platform and a network target range, the network target range platform comprises a first data transmission plug-in; the network target range comprises a second data transmission plug-in and an acquisition agent; each acquisition agent corresponds to one type of network nodes in the network target range; the network target range platform sends a data acquisition strategy to the second data transmission plug-in through the first data transmission plug-in; the second data transmission plug-in forwards the data to an acquisition agent; the collection agent collects network target range data of the network nodes according to the data collection strategy; sending the data to a data processing center; and the data processing center inputs all the network target range data into the network detection model to obtain the network running state of the network target range. According to the application, the network target range data of each network node can be collected in a targeted manner, the requirement of network target range data collection is met, and the network target range data can be analyzed and detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a system, method, electronic device and storage medium for processing network range data. Background Art

[0002] With the rapid development of information technology, the importance of network security has become increasingly prominent. Many organizations are using cyber ranges to simulate real-world network environments, improve their security protection capabilities, and test and train security personnel to respond to various threats.

[0003] However, because different targets in a cyber range require different data or collection methods, existing data collection tools lack specificity and are unable to meet the needs of cyber range data collection. Furthermore, there is currently a lack of effective analytical methods to process the collected cyber range data. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a network target range data processing system, method, electronic equipment and storage medium, which can collect network target range data of each network node in a targeted manner, meet the needs of network target range data collection, and analyze and detect network target range data.

[0005] In a first aspect, an embodiment of the present application provides a system for processing network range data, the system comprising: a network range platform and a network range; the network range platform comprising a first data transmission plug-in; the network range comprising a second data transmission plug-in and at least one type of collection agent; each collection agent corresponding to a network node in the network range;

[0006] The network range platform sends a data collection strategy to the second data collection strategy through the first data transmission plugin; the second data transmission plugin forwards the data collection strategy to the collection agent in the network range;

[0007] The acquisition agent acquires network range data of corresponding network nodes according to the data acquisition strategy; and sends the network range data to the data processing center;

[0008] The data processing center inputs all received network range data into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

[0009] In a possible implementation, before the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network range platform is further configured to:

[0010] Sending network simulation parameters to the second data transmission plug-in through the first data transmission plug-in; the network simulation parameters include target scenario parameters and operation control commands;

[0011] After receiving, through the first data transmission plug-in, network simulation parameter reception success information sent by the network range through the second data transmission plug-in, sending network simulation start status information to the second data transmission plug-in through the first data transmission plug-in, so that the network range performs corresponding operation based on the target scenario parameters and the operation control command;

[0012] When the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, it is specifically used to: after receiving the network simulation start and completion information sent by the network range through the second data transmission plug-in through the first data transmission plug-in, send the data collection strategy to the second data transmission plug-in through the first data transmission plug-in.

[0013] In a possible implementation, when the data processing center inputs all network range data into the network detection model to obtain the network operation status of the network range, the data processing center is specifically configured to:

[0014] Perform weighted fusion on all network range data to obtain network range fusion features;

[0015] The network range fusion features are input into a network detection model to obtain the network operation status of the network range.

[0016] In a possible implementation, before the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in,

[0017] The acquisition agent reports attribute information to the network range platform according to a preset reporting time interval by calling the agent status monitoring interface opened by the network range platform:

[0018] The network range platform updates the storage data corresponding to the acquisition agent in the monitoring database according to the attribute information reported by the acquisition agent; the monitoring database is used to store the attribute information of all acquisition agents.

[0019] In one possible implementation, the network range platform is further used to:

[0020] According to the latest storage time of the attribute information of each collection agent in the monitoring database, the non-update time corresponding to each collection agent is counted;

[0021] If the non-update time period corresponding to the acquisition agent exceeds a preset time period, the state of the acquisition agent is set to an offline state, and an offline warning is issued.

[0022] In a possible implementation manner, the data processing center is further configured to:

[0023] Visualizing network range data and / or network operation status of each network node using at least one visualization form;

[0024] The visualized network range data and / or network operation status are sent to the network range platform.

[0025] In a second aspect, an embodiment of the present application further provides a method for processing network range data, the method for processing network range data being applied to a data processing center in a network range data processing system as described in the first aspect, the system comprising a network range platform and a network range; the network range platform comprising a first data transmission plug-in; the network range comprising a second data transmission plug-in and at least one acquisition agent; each acquisition agent corresponding to a type of network node in the network range; the method comprising:

[0026] Receiving network range data sent by a collection agent of the network range;

[0027] The network range data is the network range data of the corresponding network nodes in the network range collected by the collection agent according to the data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and the second data transmission plug-in forwards the data collection strategy to the collection agent;

[0028] All network range data are input into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

[0029] In a third aspect, an embodiment of the present application further provides a device for processing network range data, the device comprising:

[0030] A receiving module, configured to receive network range data sent by a collection agent of the network range;

[0031] The network range data is the network range data of the corresponding network nodes in the network range collected by the collection agent according to the data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and the second data transmission plug-in forwards the data collection strategy to the collection agent;

[0032] The input module is used to input all network range data into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

[0033] In a fourth aspect, an embodiment of the present application further provides an electronic device comprising: a processor, a storage medium and a bus, wherein the storage medium stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to perform the steps of the method for processing network target range data as described in any one of the second aspects.

[0034] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method for processing network target range data as described in any one of the first aspects are executed.

[0035] The embodiment of the present application provides a network range data processing system, method, electronic device and storage medium, the system comprising: a network range platform and a network range; the network range platform comprising a first data transmission plug-in; the network range comprising a second data transmission plug-in and at least one collection agent; each collection agent corresponding to a type of network node in the network range; the network range platform sending a data collection strategy to the second data transmission plug-in via the first data transmission plug-in; the second data transmission plug-in forwarding the data collection strategy to the collection agent in the network range; the collection agent collecting network range data of the corresponding network node according to the data collection strategy; and sending the network range data to a data processing center; the data processing center inputting all received network range data into a network detection model to obtain the network operation status of the network range. The present application can carry out targeted collection of network range data of each network node, meet the needs of network range data collection, and can analyze and detect the network range data. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0037] Figure 1 A schematic diagram of the structure of a network range data processing system provided by an embodiment of the present application is shown;

[0038] Figure 2 A schematic diagram illustrating a process flow of a method for processing network range data provided by an embodiment of the present application is shown;

[0039] Figure 3 A schematic diagram showing the structure of a device for processing network range data provided by an embodiment of the present application is shown;

[0040] Figure 4 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0041] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of illustration and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowcharts can be implemented out of sequence, and steps without logical context can be reversed or implemented simultaneously. In addition, those skilled in the art, under the guidance of the contents of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart.

[0042] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application.

[0043] To enable those skilled in the art to utilize the contents of this application, the following implementation examples are provided in conjunction with a specific application scenario, "the field of network security technology." Those skilled in the art will appreciate that the general principles defined herein can be applied to other embodiments and application scenarios without departing from the spirit and scope of this application. Although this application is primarily described in the field of network security technology, it should be understood that this is merely an exemplary embodiment.

[0044] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0045] The following is a detailed description of a network range data processing system provided in an embodiment of the present application.

[0046] Reference Figure 1 As shown, it is a structural diagram of a network target range data processing system provided in an embodiment of the present application, the system including: a network target range platform 101 and a network target range 102; the network target range platform 101 includes a first data transmission plug-in 103; the network target range 102 includes a second data transmission plug-in 104 and at least one acquisition agent 105; each acquisition agent 105 corresponds to a type of network node 106 in the network target range 102.

[0047] Among them, the network range 102 is a virtual or physical environment that simulates a real network environment, which is used for network security testing, attack and defense drills, system testing, security product evaluation, and talent training. The network range platform 101 is a software or system used to manage and control the operation of the network range. The network nodes that collect network range data through the same data acquisition logic are the same type of network nodes (that is, network nodes that collect data through the same acquisition agent). The acquisition agent is a program that can collect data according to the preset data acquisition logic. The data acquisition logic corresponding to different acquisition agents can be the same or different. The network range data of multiple types of network nodes can be collected by acquisition agents corresponding to multiple data acquisition logics.

[0048] The network range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103; the second data transmission plug-in 104 forwards the data collection strategy to the collection agent 105 in the network range 102.

[0049] In the embodiment of the present application, data transmission between the network range platform 101 and the network range 102 is achieved through the first data transmission plug-in 103 in the network range platform 101 and the second data transmission plug-in 104 in the network range 102.

[0050] In addition, both the first data transmission plug-in 103 and the second data transmission plug-in 104 have open collection strategy delivery interfaces.

[0051] Specifically, the network target range platform 101 calls the collection strategy sending interface of the first data transmission plug-in 103 to send the data collection strategy to the first data transmission plug-in 103; the first data transmission plug-in 103 calls the collection strategy sending interface of the second data transmission plug-in 104 to send the data collection strategy to the second data transmission plug-in 104; the second data transmission plug-in 104 calls the collection strategy sending interface of each collection agent 105 to send the strategy information of the network node 106 corresponding to each collection agent 105 in the data collection strategy to each collection agent 105.

[0052] The collection agent 105 collects the network range data of the corresponding network node according to the data collection strategy; and sends the network range data to the data processing center 107.

[0053] In the embodiments of the present application, the collection agent 105 is a tool pre-deployed at at least one network node 106 in the network range 102 and used to collect network range data. It can be either a collection device or collection software. The collection agent 105 performs network range data collection tasks based on the network range data type and collection method corresponding to the network node 106 in the network range 102. The data collection policy includes policy information such as the required collection data source, collection method, collection frequency, data format and data quality requirements, storage method, data security and privacy protection, etc. for each network node 106, which is used to guide the collection agent 105 in collecting network range data.

[0054] Here, each acquisition agent 105 corresponds to a network node 106. This one-to-one mapping ensures the efficiency and accuracy of data acquisition. The acquisition agent 105 can interact directly with the corresponding network node 106, avoiding unnecessary data transmission and processing delays. The collaborative work between the first data transmission plug-in 103 and the second data transmission plug-in 104 ensures the accurate transmission of data acquisition strategies and the efficient return of collected data. This collaborative mechanism makes the data acquisition process more stable and reliable. By sending data acquisition strategies through the data transmission plug-in, the acquisition strategies can be dynamically adjusted according to the actual operation of the network target range 102.

[0055] The network nodes 106 include but are not limited to network inlets, outlets, core switches, key servers, etc. In addition, the collection agent 105 has an interface for issuing collection strategies.

[0056] Specifically, each collection agent 105 collects network range data of the corresponding network node 106 according to the received strategy information.

[0057] Here, this application uses a layered architecture consisting of a first data transmission plug-in 103, a second data transmission plug-in 104, and a collection agent 105 to separate the formulation of data collection strategies from the execution of specific collection tasks. This makes the entire collection process more flexible and customizable, achieving highly targeted collection. This layered design can be adjusted and optimized based on the actual needs of the network range 102.

[0058] The collection agent 105 collects the network range data of the corresponding network node 106 according to the data collection strategy; and sends the network range data to the data processing center 107.

[0059] Specifically, the collection agent 105 preprocesses the collected network range data and sends the preprocessed data to the second data transmission plug-in 104; the second data transmission plug-in 104 encapsulates the preprocessed network range data into messages, and sends the encapsulated messages to the message middleware (such as Kafka) to build a real-time data stream to ensure real-time transmission and processing of the network range data; the data processing center 107 pulls messages from the message middleware.

[0060] Among them, network target range data may include network traffic data (five-tuple) of each network node, system logs, user behavior data, target device status, and network traffic size of CPU, memory, I / O of general servers, PCs and other devices.

[0061] Taking network traffic data as an example, the collection agent 105 pre-processes the network traffic data, including: processing missing values ​​in the network traffic data (such as source IP / destination IP, port number, etc. in the network traffic data); detecting outliers in the network traffic data (such as verifying the port range, protocol field check, etc.), and deleting the detected abnormal network traffic data; correcting erroneous data in the network traffic data (such as using CIDR block matching to verify the validity of the IP address, using the ISO 8601 standardized unified timestamp format, etc.).

[0062] In addition, the data processing center 107 stores the cyber range data in a distributed database, such as Hadoop or Elasticsearch, to support storage and fast retrieval of large-scale data.

[0063] The data processing center 107 inputs all received network range data into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

[0064] In the implementation manner of the present application, all network range data are weightedly fused to obtain network range fusion features; the network range fusion features are input into the network detection model to obtain the network operation status of the network range 102.

[0065] Here, the cyber range data includes data with strong temporal sequences (e.g., continuous sequences of packets), such as network traffic data, and LSTM is effective in capturing long-term dependencies. Furthermore, the cyber range has far more samples of normal network operation than abnormal ones. The LSTM-Autoencoder can be trained solely on normal data, avoiding reliance on abnormal labels. Therefore, the LSTM-Autoencoder is used as the foundational model for the network detection model.

[0066] Specifically, all network target range data are weightedly fused, including: downgrading the dimensions of all network target range data through PCA (Principal Component Analysis); for each downgraded network target range data, extracting two-dimensional data features from all downgraded network target range data according to the characteristics of all the downgraded network target range data to obtain network target range data features; adjusting the fusion matrix using a dynamic weight algorithm, the fusion matrix includes the weight relationship between the network target range data; and fusing all network target range data features according to the fusion matrix.

[0067] Here, a certain downgraded network range data may include data of multiple dimensions. In order to reduce the computational workload and improve the analysis efficiency, data of two dimensions are extracted as features.

[0068] Optionally, before weighted fusion of all network range data, the data processing center 107 is also used to: count the traffic statistics (such as packet rate, number of bytes, connection duration, etc.) and protocol data corresponding to the network range data; and use the traffic statistics and protocol data as network range data.

[0069] The packet rate refers to the number of packets passing through the network per unit time. The byte count refers to the total number of bytes transmitted per unit time. The connection duration refers to the duration of a network connection. Protocol characteristics (such as the SYN / FIN flag) reflect the protocol behavior of network traffic and help identify specific types of network anomalies. The SYN / FIN flag is a flag in the TCP protocol. The SYN flag is used to establish a connection, and the FIN flag is used to close a connection.

[0070] In addition, the data processing center 107 trains the network detection model through the following steps: obtaining network target range sample data and the network operation status corresponding to the network target range sample data; wherein the network target range sample data includes real sample data in which the network operation status is a normal operation status, real sample data in which the network operation status is an abnormal operation status, and adversarial sample data in which the network operation status is an abnormal operation status; the adversarial sample data is real sample data close to the abnormal operation status of the network operation status generated by the adversarial generative network; the network detection model is trained using the network target range sample data as samples and the network operation status as labels.

[0071] Here, since the number of samples with normal network operation status in the network target range is far greater than that with abnormal network operation status, generating adversarial sample data can increase the number of samples with abnormal network operation status, balance the training data, and thus improve the generalization ability and detection accuracy of the model.

[0072] Furthermore, before the network range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103, the network range platform 101 is further configured to:

[0073] The network simulation parameters are sent to the second data transmission plug-in 104 via the first data transmission plug-in 103 ; the network simulation parameters include target scenario parameters and operation control commands.

[0074] In the embodiment of the present application, both the first data transmission plug-in 103 and the second data transmission plug-in 104 open the target scene parameter sending interface and the operation control command sending interface. The network target range platform 101 calls the target scene parameter sending interface of the first data transmission plug-in 103 to send the target scene parameters to the first data transmission plug-in 103; the first data transmission plug-in 103 calls the target scene parameter sending interface of the second data transmission plug-in 104 to send the target scene parameters to the second data transmission plug-in 104. The operation control command sending interface of the first data transmission plug-in 103 is called to send the operation control command to the first data transmission plug-in 103; the first data transmission plug-in 103 calls the operation control command sending interface of the second data transmission plug-in 104 to send the operation control command to the second data transmission plug-in 104.

[0075] Target scenario parameters are a set of parameters used to define and control target scenarios. Targets are objects within a cyber range for cyber attack and defense exercises. Operational control commands are commands used to control the operation of the cyber range, such as opening a gate.

[0076] After receiving the network simulation parameter reception success information sent by the network target range 102 through the second data transmission plug-in 104 through the first data transmission plug-in 103, the network simulation start status information is sent to the second data transmission plug-in 104 through the first data transmission plug-in, so that the network target range 102 performs corresponding operation operations based on the target scenario parameters and the operation control command.

[0077] In the embodiment of the present application, after receiving the network simulation parameters, the network range 102 calls the execution result reporting interface of the second data transmission plug-in 104 and sends the network simulation parameter reception success information to the second data transmission plug-in 104; the second data transmission plug-in 104 calls the execution result reporting interface of the first data transmission plug-in 103 and sends the network simulation parameter reception success information to the first data transmission plug-in 103. Then, after receiving the network simulation parameter reception success information, the network range platform 101 calls the execution status reporting interface of the first data transmission plug-in 103 and sends the network simulation start status information to the first data transmission plug-in 103; the first data transmission plug-in 103 calls the execution status reporting interface of the second data transmission plug-in 104 and sends the network simulation start status information to the second data transmission plug-in 104, so that the network range 102 performs the corresponding operation based on the target scenario parameters and the operation control command.

[0078] When the network range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in, it is specifically used to: after receiving the network simulation start and completion information sent by the network range 102 through the second data transmission plug-in 104 through the first data transmission plug-in 103, send the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103.

[0079] In an embodiment of the present application, after the network target range 102 starts to execute the corresponding operation based on the target scenario parameters and the operation control command, it calls the execution result reporting interface of the second data transmission plug-in 104 and sends the network simulation start completion information to the second data transmission plug-in 104; the second data transmission plug-in 104 calls the execution result reporting interface of the first data transmission plug-in 103 and sends the network simulation start completion information to the first data transmission plug-in 103; then, the data collection strategy is sent to the second data transmission plug-in 104 through the first data transmission plug-in 103.

[0080] The network simulation start and completion information includes the resource type of the target scenario parameters, the target scenario parameters, and the completion of the execution of the operation control command. The resource type of the target scenario parameters refers to the type of resources that are used to define and describe the various parameters of the target scenario when running the target scenario. It can be expressed by the name of the target scenario parameter (such as the opening and closing status of a gate) or by other means (such as hardware, software, etc.).

[0081] Furthermore, before the network target range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103, the collection agent 105 reports the attribute information to the network target range platform 101 according to the preset reporting time interval by calling the agent status monitoring interface opened by the network target range platform 101: the network target range platform 101 updates the storage data corresponding to the collection agent 105 in the monitoring database according to the attribute information reported by the collection agent 105; the monitoring database is used to store the attribute information of all collection agents.

[0082] The attribute information includes the IP address, port number, target type, etc. of the acquisition agent 105. The target type refers to the type of various target systems, devices, services, or scenarios used in the network target range to simulate a real network environment.

[0083] The network range platform 101 is also used to: count the non-updated time corresponding to each collection agent 105 according to the latest storage time of the attribute information of each collection agent 105 in the monitoring database; if the non-updated time corresponding to the collection agent 105 exceeds the preset time, the status of the collection agent 105 is set to offline and an offline warning is issued.

[0084] The preset duration is greater than the duration corresponding to the preset reporting time interval.

[0085] Here, this application can monitor the online status of network nodes by periodically reporting attribute information to ensure the data collection effect.

[0086] Furthermore, the data processing center 107 is further configured to: visualize the network range data and / or network operation status of each network node using at least one visualization form; and send the visualized network range data and / or network operation status to the network range platform 101. The visualization form may include charts, maps, etc.

[0087] Furthermore, before the network range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103 , the collection agent 105 registers service information with the network range platform 101 through the service registration interface opened by the network range platform 101 .

[0088] Here, during the collection process, the collection agent 105 and the network range platform 101 will improve the automation and efficiency of the collection from the aforementioned custom interface and design interface call logic, process orchestration, and system architecture optimization. The custom interface and call logic mainly realize on-demand and timely calls to the underlying target by adding time constraint modules and constraint call objects; process orchestration mainly improves the collection efficiency by determining the direction of the target business flow and the radiation range of the equipment, establishing dependencies, and building intelligent scheduling strategies such as dynamic sorting based on load resources; system architecture optimization mainly solves the problems of data congestion and low efficiency encountered in the actual collection process by manually intervening in the collection process according to the collection requirements and collection plan, adjusting and optimizing the collection time and objects. Finally, by establishing a heartbeat keep-alive interface, the device status is sensed to ensure that the collected data can be reported to the network range platform in real time without loss.

[0089] In addition, this system also provides a feedback mechanism to continuously optimize data collection strategies and network detection models based on feedback from security analysts, thereby improving the accuracy and efficiency of data collection and analysis.

[0090] Reference Figure 2 FIG. 1 is a flow chart of a method for processing network range data provided by an embodiment of the present application. The method for processing network range data is applied to a data processing center in a network range data processing system. The method includes:

[0091] S201. Receive network range data sent by a collection agent of the network range.

[0092] Among them, the network target range data is the network target range data of the corresponding network nodes in the network target range collected by the collection agent according to the data collection strategy; the data collection strategy is sent by the network target range platform to the second data transmission plug-in through the first data transmission plug-in, and the second data transmission plug-in forwards the data collection strategy to the collection agent.

[0093] S202. Input all network range data into the network detection model to obtain the network operation status of the network range.

[0094] Among them, the network detection model is trained based on network target range sample data and corresponding network operation status labels.

[0095] Based on the same inventive concept, an embodiment of the present application also provides a device for processing network target range data corresponding to the method for processing network target range data. Since the principle of solving the problem by the device in the embodiment of the present application is similar to the method for processing network target range data in the embodiment of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0096] Reference Figure 3FIG. 1 is a schematic diagram of a device for processing network range data according to an embodiment of the present application, the device comprising:

[0097] The receiving module 301 is used to receive network range data sent by a collection agent of the network range;

[0098] The network range data is the network range data of the corresponding network nodes in the network range collected by the collection agent according to the data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and the second data transmission plug-in forwards the data collection strategy to the collection agent;

[0099] The input module 302 is used to input all network range data into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

[0100] like Figure 4 As shown, an electronic device 400 provided in an embodiment of the present application includes: a processor 401, a memory 402 and a bus, wherein the memory 402 stores machine-readable instructions executable by the processor 401. When the electronic device is running, the processor 401 communicates with the memory 402 through the bus, and the processor 401 executes the machine-readable instructions to perform the steps of the above-mentioned method for processing network target range data.

[0101] Specifically, the above-mentioned memory 402 and processor 401 can be general-purpose memory and processor, which are not specifically limited here. When the processor 401 runs the computer program stored in the memory 402, it can execute the above-mentioned network target range data processing method.

[0102] Corresponding to the above-mentioned method for processing network range data, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the above-mentioned method for processing network range data are executed.

[0103] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0104] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed across multiple network elements. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0105] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0106] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the information processing method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0107] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A network range data processing system, characterized in that: The system includes: a network range platform and a network range; the network range platform includes a first data transmission plug-in; the network range includes a second data transmission plug-in and at least one acquisition agent; each acquisition agent corresponds to a type of network node in the network range; The network range platform sends a data collection strategy to the second data collection strategy through the first data transmission plugin; the second data transmission plugin forwards the data collection strategy to the collection agent in the network range; The acquisition agent acquires network range data of corresponding network nodes according to the data acquisition strategy; and sends the network range data to the data processing center; The data processing center inputs all received network range data into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

2. The network range data processing system according to claim 1, characterized in that: Before the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network range platform is further configured to: Sending network simulation parameters to the second data transmission plug-in through the first data transmission plug-in; the network simulation parameters include target scenario parameters and operation control commands; After receiving, through the first data transmission plug-in, network simulation parameter reception success information sent by the network range through the second data transmission plug-in, sending network simulation start status information to the second data transmission plug-in through the first data transmission plug-in, so that the network range performs corresponding operation based on the target scenario parameters and the operation control command; When the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, it is specifically used to: after receiving the network simulation start and completion information sent by the network range through the second data transmission plug-in through the first data transmission plug-in, send the data collection strategy to the second data transmission plug-in through the first data transmission plug-in.

3. The network range data processing system according to claim 1, characterized in that: When the data processing center inputs all network range data into the network detection model to obtain the network operation status of the network range, the data processing center is specifically used to: Perform weighted fusion on all network range data to obtain network range fusion features; The network range fusion features are input into a network detection model to obtain the network operation status of the network range.

4. The network range data processing system according to claim 1, characterized in that: Before the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, The acquisition agent reports attribute information to the network range platform according to a preset reporting time interval by calling the agent status monitoring interface opened by the network range platform: The network range platform updates the storage data corresponding to the acquisition agent in the monitoring database according to the attribute information reported by the acquisition agent; the monitoring database is used to store the attribute information of all acquisition agents.

5. The network range data processing system according to claim 4, characterized in that: The network range platform is also used to: According to the latest storage time of the attribute information of each collection agent in the monitoring database, the non-update time corresponding to each collection agent is counted; If the non-update time period corresponding to the acquisition agent exceeds a preset time period, the state of the acquisition agent is set to an offline state, and an offline warning is issued.

6. The network range data processing system according to any one of claims 1 to 5, characterized in that: The data processing center is also used for: Visualizing network range data and / or network operation status of each network node using at least one visualization form; The visualized network range data and / or network operation status are sent to the network range platform.

7. A method for processing network range data, characterized in that: The method for processing network range data is applied to a data processing center in a network range data processing system according to any one of claims 1 to 6, wherein the system comprises a network range platform and a network range; the network range platform comprises a first data transmission plug-in; the network range comprises a second data transmission plug-in and at least one acquisition agent; Each acquisition agent corresponds to a type of network node in the network target range; the method includes: Receiving network range data sent by a collection agent of the network range; The network range data is the network range data of the corresponding network nodes in the network range collected by the collection agent according to the data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and the second data transmission plug-in forwards the data collection strategy to the collection agent; All network range data are input into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

8. A network range data processing device, characterized in that: The device comprises: A receiving module, configured to receive network range data sent by a collection agent of the network range; The network range data is the network range data of the corresponding network nodes in the network range collected by the collection agent according to the data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and the second data transmission plug-in forwards the data collection strategy to the collection agent; The input module is used to input all network range data into the network detection model to obtain the network operation status of the network range; the network detection model is trained based on the network range sample data and the corresponding network operation status labels.

9. An electronic device, characterized in that: include: A processor, a storage medium and a bus, wherein the storage medium stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the storage medium communicate through the bus, and the processor executes the machine-readable instructions to perform the steps of the method for processing network range data as described in claim 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the method for processing network range data according to claim 7 are executed.

Citation Information

Patent Citations

  • Network security target range system and operation method thereof

    CN112153010A

  • Comprehensive auditing method and system for network target range

    CN114615013A

  • Test evaluation method, device and system based on parallel simulation

    CN116527536A

  • Network target range heterogeneous target configuration acquisition method and device, electronic equipment and storage medium

    CN117255021A

  • User traffic collection method and device based on network target range

    CN119071042A

Cited By

  • Network target range visual scene generation method and system based on model scenario

    CN121486206A