Network target range data processing system, method, electronic device and storage medium

By designing a network range data processing system, utilizing data transmission plugins and acquisition agents for targeted data collection, and analyzing the data using network detection models, the system solves the challenges of network range data collection and analysis, achieving efficient and accurate data processing and security testing results.

CN120692182BActive Publication Date: 2026-02-06CHINA ELECTRONICS CORP 6TH RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510895867.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2026-02-06
Estimated Expiration
2045-06-30

AI Technical Summary

Technical Problem

Existing network range data acquisition tools lack specificity, making it difficult to meet the data acquisition needs of network ranges, and there is a lack of effective analysis methods to process the acquired data.

Method used

A network range data processing system was designed, comprising a network range platform and a network range. Through a data transmission plugin and a data acquisition agent, targeted data acquisition from network nodes is achieved, and the data is analyzed and detected using a network detection model. The system sends data acquisition strategies via the data transmission plugin, the acquisition agent collects data and sends it to the data processing center, and the network detection model is used for data analysis. Visualization and feedback mechanisms are incorporated to optimize data acquisition and analysis.

Benefits of technology

It enables efficient and accurate collection and analysis of network range data, meets the data collection needs of network ranges, and improves the efficiency and effectiveness of network security testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692182B_ABST
    Figure CN120692182B_ABST
Patent Text Reader

Abstract

The application provides a network target range data processing system, method, electronic equipment and storage medium. The system comprises a network target range platform and a network target range. The network target range platform comprises a first data transmission plug-in. The network target range comprises a second data transmission plug-in and a collection agent. Each collection agent corresponds to a type of network node in the network target range. The network target range platform sends a data collection strategy to the second data transmission plug-in through the first data transmission plug-in. The second data transmission plug-in forwards the data collection strategy to the collection agent. The collection agent collects network target range data of the network node according to the data collection strategy and sends the network target range data to a data processing center. The data processing center inputs all the network target range data into a network detection model to obtain a network operation state of the network target range. The application can collect network target range data of each network node, meet the demand of network target range data collection, and analyze and detect the network target range data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a network range data processing system and method, an electronic device and a storage medium. BACKGROUND

[0002] With the rapid development of information technology, the importance of network security is increasingly prominent. Many organizations have simulated real network environments by means of network ranges to improve their security protection capabilities and test and exercise the level of security personnel in responding to various threats.

[0003] However, since different targets in the network range correspond to different data or collection methods, existing data collection tools lack pertinence and are difficult to meet the needs of network range data collection. At the same time, there is currently a lack of effective analysis means to process the collected network range data. SUMMARY

[0004] Therefore, the purpose of the present application is to provide a network range data processing system and method, an electronic device and a storage medium, which can collect network range data of each network node pertinently, meet the needs of network range data collection, and analyze and detect network range data.

[0005] In a first aspect, the embodiments of the present application provide a network range data processing system, which comprises a network range platform and a network range; the network range platform comprises a first data transmission plug-in; the network range comprises a second data transmission plug-in and at least one type of collection agent; each collection agent corresponds to a network node in the network range;

[0006] The network range platform sends a data collection strategy to the second data transmission plug-in through the first data transmission plug-in; the second data transmission plug-in forwards the data collection strategy to the collection agent in the network range;

[0007] The collection agent collects network range data of the corresponding network node according to the data collection strategy; and sends the network range data to a data processing center;

[0008] The data processing center inputs all the received network range data into a network detection model to obtain the network running state of the network range; the network detection model is obtained by training based on network range sample data and corresponding network running state labels.

[0009] In a possible implementation, before the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network range platform is further configured to:

[0010] sending network simulation parameters to the second data transmission plug-in through the first data transmission plug-in; the network simulation parameters include target scene parameters and operation control commands;

[0011] After receiving the network simulation parameter sending success information sent by the network range through the second data transmission plug-in, the network range platform sends network simulation start state information to the second data transmission plug-in through the first data transmission plug-in, so that the network range executes corresponding operation operation based on the target scene parameters and the operation control commands.

[0012] When the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network range platform is specifically configured to send the data collection strategy to the second data transmission plug-in through the first data transmission plug-in after receiving the network simulation start completion information sent by the network range through the second data transmission plug-in through the first data transmission plug-in.

[0013] In a possible implementation, when the data processing center inputs all network range data into the network detection model to obtain the network operation state of the network range, the data processing center is specifically configured to:

[0014] perform weighted fusion on all network range data to obtain network range fusion features;

[0015] input the network range fusion features into the network detection model to obtain the network operation state of the network range.

[0016] In a possible implementation, before the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in,

[0017] The collection agent reports attribute information to the network range platform according to a preset reporting time interval by calling the agent state monitoring interface exposed by the network range platform.

[0018] The network range platform updates the storage data corresponding to the collection agent in the monitoring database according to the attribute information reported by the collection agent; the monitoring database is used to store attribute information of all collection agents.

[0019] In a possible implementation, the network range platform is further configured to:

[0020] According to the latest storage time of the attribute information of each collection agent in the monitoring database, the network range platform is further configured to:

[0021] If the non-updating duration corresponding to the collection agent exceeds a preset duration, the state of the collection agent is set to an offline state, and an offline warning is performed.

[0022] In a possible implementation, the data processing center is further configured to:

[0023] visualize the network range data and / or the network running state of each network node in at least one visualization form;

[0024] send the visualized network range data and / or the network running state to the network range platform.

[0025] In a second aspect, the embodiments of the present application further provide a network range data processing method, which is applied to a data processing center in a network range data processing system as described in the first aspect, the system comprising a network range platform and a network range; the network range platform comprising a first data transmission plug-in; the network range comprising a second data transmission plug-in and at least one collection agent; each collection agent corresponding to a type of network node in the network range; the method comprising:

[0026] receiving network range data sent by a collection agent of the network range;

[0027] The network range data is network range data of a corresponding network node in the network range collected by the collection agent according to a data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and then forwarded to the collection agent by the second data transmission plug-in.

[0028] inputting all the network range data into a network detection model to obtain a network running state of the network range; the network detection model is obtained by training based on network range sample data and corresponding network running state labels.

[0029] In a third aspect, the embodiments of the present application further provide a network range data processing device, comprising:

[0030] a receiving module configured to receive network range data sent by a collection agent of the network range;

[0031] The network range data is network range data of a corresponding network node in the network range collected by the collection agent according to a data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and then forwarded to the collection agent by the second data transmission plug-in.

[0032] The input module is configured to input all network range data into a network detection model to obtain a network running state of the network range, wherein the network detection model is obtained by training based on network range sample data and corresponding network running state labels.

[0033] In a fourth aspect, an electronic device is provided, which includes a processor, a storage medium, and a bus. The storage medium stores machine readable instructions executable by the processor. When the electronic device is running, the processor communicates with the storage medium through the bus. The processor executes the machine readable instructions to perform the steps of the network range data processing method according to any one of the second aspect.

[0034] In a fifth aspect, a computer readable storage medium is provided, which stores a computer program. When the computer program is run by a processor, the steps of the network range data processing method according to any one of the first aspect are performed.

[0035] The embodiments of the present application provide a network range data processing system, method, electronic device, and storage medium. The system includes a network range platform and a network range. The network range platform includes a first data transmission plug-in. The network range includes a second data transmission plug-in and at least one collection agent. Each collection agent corresponds to a type of network node in the network range. The network range platform sends a data collection strategy to the second data transmission plug-in through the first data transmission plug-in. The second data transmission plug-in forwards the data collection strategy to the collection agents in the network range. The collection agents collect network range data of the corresponding network nodes according to the data collection strategy and send the network range data to a data processing center. The data processing center inputs all received network range data into a network detection model to obtain a network running state of the network range. The embodiments of the present application can collect network range data of each network node in a targeted manner, meet the needs of network range data collection, and analyze and detect network range data. BRIEF DESCRIPTION OF DRAWINGS

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be considered as limiting the scope. For those skilled in the art, other related drawings can also be obtained without creative labor.

[0037] Figure 1 Fig. 1 shows a structural schematic diagram of a network range data processing system according to an embodiment of the present application;

[0038] Figure 2 A flowchart of a network range data processing method provided by an embodiment of the present application is shown;

[0039] Figure 3 A structural diagram of a network range data processing apparatus provided by an embodiment of the present application is shown;

[0040] Figure 4 A structural diagram of an electronic device provided by an embodiment of the present application is shown. DETAILED DESCRIPTION

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. It should be understood that the drawings in the present application serve only the purpose of description and illustration, and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn according to the actual proportions. The flowchart shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can not be implemented in sequence, and the steps without logical context relationship can be reversed in sequence or implemented simultaneously. In addition, one or more other operations can be added to the flowchart or removed from the flowchart by those skilled in the art under the guidance of the content of the present application.

[0042] In addition, the described embodiments are only some of the embodiments of the present application, not all the embodiments. The components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0043] In order to enable those skilled in the art to use the content of the present application, the following implementation is given in combination with a specific application scenario "network security technology field". Those skilled in the art can apply the general principles defined herein to other embodiments and application scenarios without departing from the spirit and scope of the present application. Although the present application is mainly described in relation to the "network security technology field", it should be understood that this is only an exemplary embodiment.

[0044] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.

[0045] A network target range data processing system provided by an embodiment of the present application is described in detail below.

[0046] Referring to Figure 1 FIG. 1 is a structural schematic diagram of a network target range data processing system provided by an embodiment of the present application. The system includes a network target range platform 101 and a network target range 102. The network target range platform 101 includes a first data transmission plug-in 103. The network target range 102 includes a second data transmission plug-in 104 and at least one collection agent 105. Each collection agent 105 corresponds to a type of network node 106 in the network target range 102.

[0047] The network target range 102 is a virtual or physical environment simulating a real network environment, which is used for network security testing, attack and defense drills, system testing, security product evaluation, and personnel training activities. The network target range platform 101 is a software or system used for managing and controlling the operation of the network target range. Network nodes that collect network target range data through the same data collection logic are network nodes of the same type (i.e., network nodes whose data is collected by the same collection agent). A collection agent is a program that can collect data according to a preset data collection logic. The data collection logic corresponding to different collection agents can be the same or different. Collection agents corresponding to multiple data collection logics can collect network target range data of multiple types of network nodes.

[0048] The network target range platform 101 sends a data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103. The second data transmission plug-in 104 forwards the data collection strategy to the collection agents 105 in the network target range 102.

[0049] In the present embodiment, the first data transmission plug-in 103 in the network target range platform 101 and the second data transmission plug-in 104 in the network target range 102 are used to realize data transmission between the network target range platform 101 and the network target range 102.

[0050] In addition, the first data transmission plug-in 103 and the second data transmission plug-in 104 both have a collection strategy issuing interface.

[0051] Specifically, the network target range platform 101 calls the collection strategy issuing interface of the first data transmission plug-in 103 to send a data collection strategy to the first data transmission plug-in 103. The first data transmission plug-in 103 calls the collection strategy issuing interface of the second data transmission plug-in 104 to send the data collection strategy to the second data transmission plug-in 104. The second data transmission plug-in 104 calls the collection strategy issuing interface of each collection agent 105 to send the policy information of the network nodes 106 corresponding to each collection agent 105 in the data collection strategy to each collection agent 105.

[0052] The collection agent 105 collects the network range data of the corresponding network node according to the data collection strategy; and sends the network range data to the data processing center 107.

[0053] In the embodiments of the present application, the collection agent 105 is a tool for collecting network range data, which is deployed in advance at at least one network node 106 of the network range 102, and can be a collection device or a collection software. The collection agent 105 performs the collection task of the network range data according to the type of the network range data of the corresponding network node 106 in the network range 102 and the collection method. The data collection strategy includes the required collection data source, collection method, collection frequency, data format and data quality requirement, storage method, data security and privacy protection and other strategy information of each network node 106, which is used to guide the collection agent 105 to collect the network range data.

[0054] Here, each collection agent 105 corresponds to one network node 106, and this one-to-one mapping relationship ensures the efficiency and accuracy of data collection. The collection agent 105 can directly interact with the corresponding network node 106, avoiding unnecessary data transmission and processing delay. The cooperative work between the first data transmission plug-in 103 and the second data transmission plug-in 104 ensures the accurate transmission of the data collection strategy and the efficient return of the collected data. This cooperative mechanism makes the data collection process more stable and reliable. By sending the data collection strategy through the data transmission plug-in, the collection strategy can be dynamically adjusted according to the actual operation of the network range 102.

[0055] Among them, the network node 106 includes but is not limited to network entrance, exit, core switch, key server and other positions. In addition, the collection agent 105 opens a collection strategy issuing interface.

[0056] Specifically, each collection agent 105 collects the network range data of the corresponding network node 106 according to the received strategy information.

[0057] Here, the present application separates the formulation of the data collection strategy from the execution of the specific collection task through the hierarchical architecture of the first data transmission plug-in 103, the second data transmission plug-in 104 and the collection agent 105, making the entire collection process more flexible and customizable, and achieving highly targeted collection. This hierarchical design can be adjusted and optimized according to the actual needs of the network range 102.

[0058] The collection agent 105 collects the network range data of the corresponding network node 106 according to the data collection strategy; and sends the network range data to the data processing center 107.

[0059] Specifically, the collection agent 105 pre-processes the collected network range data and sends the pre-processed data to the second data transmission plug-in 104; the second data transmission plug-in 104 encapsulates the pre-processed network range data into messages and sends the encapsulated messages to the message middleware (such as Kafka) to build a real-time data stream, ensuring real-time transmission and processing of the network range data; the data processing center 107 pulls the messages from the message middleware.

[0060] Among them, the network range data can include network traffic data (five tuples) of each network node, system logs, user behavior data, target equipment status, and network traffic size of CPU, memory, and I / O of general servers, PCs, and other devices.

[0061] Taking network traffic data as an example, the collection agent 105 pre-processes the network traffic data, including: performing missing value processing on the network traffic data (such as source IP / destination IP, port number, etc. in the network traffic data); performing outlier detection on the network traffic data (such as verifying the port range, protocol field checking, etc.), deleting the network traffic data detected as abnormal; performing error data correction on the network traffic data (such as using CIDR block matching to verify the effectiveness of the IP address, using ISO 8601 standardized unified timestamp format, etc.).

[0062] In addition, the data processing center 107 stores the network range data in a distributed database, such as Hadoop or Elasticsearch, to support large-scale data storage and fast retrieval.

[0063] The data processing center 107 inputs all the received network range data into the network detection model to obtain the network running state of the network range; the network detection model is trained based on network range sample data and corresponding network running state labels.

[0064] In the embodiments of the present application, all network range data is weighted and fused to obtain network range fusion features; the network range fusion features are input into the network detection model to obtain the network running state of the network range 102.

[0065] Here, since the network range data includes data with strong time sequence (such as continuous data packet sequence) (such as network traffic data), and LSTM can effectively capture long-term dependencies. In addition, the number of samples with normal network running state in the network range is much larger than the number of samples with abnormal network running state, and LSTM-Autoencoder can be trained only with normal data, avoiding dependence on abnormal labels. Therefore, LSTM-Autoencoder is used as the basic model of the network detection model.

[0066] Specifically, all network range data are weighted and fused, including: dimension reduction of all network range data by PCA (Principal Component Analysis); for each reduced network range data, two-dimensional data features are extracted from all reduced network range data according to the characteristics of all reduced network range data, to obtain network range data features; a dynamic weight algorithm is used to adjust a fusion matrix including weight relationships between network range data; and all network range data features are fused according to the fusion matrix.

[0067] Here, a certain reduced network range data may include multiple dimensions of data, and in order to reduce the calculation workload and improve the analysis efficiency, two dimensions of data are extracted as features.

[0068] Optionally, before the weighted fusion of all network range data, the data processing center 107 is further configured to: count traffic statistics data (such as packet rate, byte count, connection duration, etc.) and protocol data corresponding to the network range data; and take the traffic statistics data and the protocol data as the network range data.

[0069] Among them, the packet rate (Packet Rate) refers to the number of packets passing through the network per unit time. The byte count (Byte Count) refers to the total number of bytes transmitted per unit time. The connection duration (Connection Duration) refers to the duration of a network connection. The protocol feature (such as the SYN / FIN flag) is used to reflect the protocol behavior of network traffic, which helps to identify specific types of network anomalies. The SYN / FIN flag is a flag in the TCP protocol. The SYN flag is used to establish a connection, and the FIN flag is used to close a connection.

[0070] In addition, the data processing center 107 trains the network detection model by the following steps: obtaining network range sample data and network running states corresponding to the network range sample data; wherein the network range sample data includes real sample data with a normal network running state, real sample data with an abnormal network running state, and adversarial sample data with an abnormal network running state; the adversarial sample data is generated by an adversarial generation network to approach the real sample data with an abnormal network running state; and the network detection model is trained by taking the network range sample data as samples and the network running states as labels.

[0071] Here, since the number of samples of the normal running state is much larger than that of the abnormal running state in the network target field, the number of samples of the abnormal running state can be increased by generating the adversarial sample data, the training data is balanced, and thus the generalization ability and detection accuracy of the model are improved.

[0072] Further, before the network target field platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103, the network target field platform 101 is further configured to:

[0073] send the network simulation parameters to the second data transmission plug-in 104 through the first data transmission plug-in 103; the network simulation parameters include target scene parameters and running control commands.

[0074] In the embodiments of the present application, the first data transmission plug-in 103 and the second data transmission plug-in 104 both open a target scene parameter issuing interface and a running control command issuing interface. The network target field platform 101 calls the target scene parameter issuing interface of the first data transmission plug-in 103 to send the target scene parameters to the first data transmission plug-in 103; the first data transmission plug-in 103 calls the target scene parameter issuing interface of the second data transmission plug-in 104 to send the target scene parameters to the second data transmission plug-in 104. The running control command issuing interface of the first data transmission plug-in 103 is called to send the running control command to the first data transmission plug-in 103; the running control command issuing interface of the second data transmission plug-in 104 is called to send the running control command to the second data transmission plug-in 104.

[0075] The target scene parameters are a set of parameter collection for defining and controlling the target scene. The target refers to the object of network attack and defense drill in the network target field. The running control command refers to the command for controlling the running of the network target field, such as opening the gate, etc.

[0076] After receiving the network simulation parameter receiving success information sent by the network target field 102 through the second data transmission plug-in 104 through the first data transmission plug-in 103, the network simulation start state information is sent to the second data transmission plug-in 104 through the first data transmission plug-in, so that the network target field 102 performs corresponding running operation based on the target scene parameters and the running control command.

[0077] In the embodiment of the present application, after receiving the network simulation parameters, the network range 102 calls the execution result reporting interface of the second data transmission plug-in 104, and sends the network simulation parameter receiving success information to the second data transmission plug-in 104; the second data transmission plug-in 104 calls the execution result reporting interface of the first data transmission plug-in 103, and sends the network simulation parameter receiving success information to the first data transmission plug-in 103. Then, after receiving the network simulation parameter receiving success information, the network range platform 101 calls the execution state reporting interface of the first data transmission plug-in 103, and sends the network simulation start state information to the first data transmission plug-in 103; the first data transmission plug-in 103 calls the execution state reporting interface of the second data transmission plug-in 104, and sends the network simulation start state information to the second data transmission plug-in 104, so that the network range 102 executes the corresponding operation based on the target scene parameters and the operation control command.

[0078] When the network range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in, it is specifically used for: after receiving the network simulation start completion information sent by the network range 102 through the second data transmission plug-in 104 through the first data transmission plug-in 103, sending the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103.

[0079] In the embodiment of the present application, after the network range 102 starts to execute the corresponding operation based on the target scene parameters and the operation control command, the execution result reporting interface of the second data transmission plug-in 104 is called, and the network simulation start completion information is sent to the second data transmission plug-in 104; the execution result reporting interface of the first data transmission plug-in 103 is called, and the network simulation start completion information is sent to the first data transmission plug-in 103; then, the data collection strategy is sent to the second data transmission plug-in 104 through the first data transmission plug-in 103.

[0080] In the embodiment of the present application, after the network range 102 starts to execute the corresponding operation based on the target scene parameters and the operation control command, the execution result reporting interface of the second data transmission plug-in 104 is called, and the network simulation start completion information is sent to the second data transmission plug-in 104; the execution result reporting interface of the first data transmission plug-in 103 is called, and the network simulation start completion information is sent to the first data transmission plug-in 103; then, the data collection strategy is sent to the second data transmission plug-in 104 through the first data transmission plug-in 103.

[0081] Further, before the network range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103, the collection agent 105 reports attribute information to the network range platform 101 at a preset reporting time interval by calling an agent state monitoring interface exposed by the network range platform 101; the network range platform 101 updates the stored data corresponding to the collection agent 105 in the monitoring database according to the attribute information reported by the collection agent 105; and the monitoring database is used to store attribute information of all collection agents.

[0082] The attribute information includes an IP address, a port number, a target type and the like of the collection agent 105. The target type refers to a type of various target systems, devices, services or scenes in a real network environment simulated in the network range.

[0083] The network range platform 101 is further configured to: according to the latest storage time of the attribute information of each collection agent 105 in the monitoring database, count an un-updated duration corresponding to each collection agent 105; and if the un-updated duration corresponding to the collection agent 105 exceeds a preset duration, set a state of the collection agent 105 as an offline state and perform offline warning.

[0084] The preset duration is greater than a duration corresponding to the preset reporting time interval.

[0085] Here, the attribute information is periodically reported, so that the online state of the network node can be monitored, and the data collection effect is ensured.

[0086] Further, the data processing center 107 is further configured to: visualize the network range data and / or the network running state of each network node in at least one visual form; and send the visualized network range data and / or the network running state to the network range platform 101. The visual form can include a chart, a map and the like.

[0087] Further, before the network range platform 101 sends the data collection strategy to the second data transmission plug-in 104 through the first data transmission plug-in 103, the collection agent 105 registers service information to the network range platform 101 through a service registration interface exposed by the network range platform 101.

[0088] Here, the collection agent 105 in the collection process, the network target field platform 101 will be from the foregoing custom interface and design interface call logic, process orchestration and system architecture optimization three aspects to improve the automation and efficiency of collection. Custom interface and call logic mainly through the increase of time constraint module and constraint call object to realize the on-demand and on-time call of the underlying target; process orchestration mainly through judging the target business flow direction and device radiation range to establish the dependency relationship, construct the dynamic sorting based on load resources Intelligent scheduling strategy to improve the collection efficiency; system architecture optimization mainly through manual intervention according to the collection demand and collection scheme in the collection process, adjusting and optimizing the collection time and object conditions to solve the collection data congestion and low efficiency encountered in the actual collection process. Finally, through the establishment of the heartbeat keep-alive interface, the device state is perceived, and it is ensured that the collection data can be reported to the network target field platform in real time without loss.

[0089] In addition, the system also provides a feedback mechanism, according to the feedback of the security analyst, the data collection strategy and the network detection model are continuously optimized, and the accuracy and efficiency of data collection and analysis are improved.

[0090] Referring to Figure 2 As shown in the flowchart of the network target field data processing method provided by the embodiment of the application, the network target field data processing method is applied to the data processing center in the network target field data processing system, and the method comprises:

[0091] S201, receiving the network target field data sent by the collection agent of the network target field.

[0092] Among them, the network target field data is the network target field data of the corresponding network node in the network target field collected by the collection agent according to the data collection strategy; the data collection strategy is sent by the network target field platform through the first data transmission plug-in to the second data transmission plug-in, and then the second data transmission plug-in forwards the data collection strategy to the collection agent.

[0093] S202, input all the network target field data into the network detection model to obtain the network running state of the network target field.

[0094] Among them, the network detection model is obtained based on the training of the network target field sample data and the corresponding network running state label.

[0095] Based on the same inventive concept, the network target field data processing device corresponding to the network target field data processing method is also provided in the embodiment of the application. Since the principle of solving problems in the device of the embodiment of the application is similar to the network target field data processing method of the above-mentioned embodiment of the application, the implementation of the device can be referred to the implementation of the method, and the repeated parts will not be described here.

[0096] Referring to Figure 3As shown in the structural schematic diagram of the network range data processing device provided by the embodiment of the present application, the device comprises:

[0097] The receiving module 301 is configured to receive the network range data sent by the collection agent of the network range.

[0098] The network range data is the network range data of the corresponding network node in the network range collected by the collection agent according to a data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and then the second data transmission plug-in forwards the data collection strategy to the collection agent.

[0099] The input module 302 is configured to input all the network range data into a network detection model to obtain the network running state of the network range; the network detection model is obtained by training based on network range sample data and corresponding network running state labels.

[0100] As shown in the structural schematic diagram of the network range data processing device provided by the embodiment of the present application, the device comprises: Figure 4 The electronic device 400 provided by the embodiment of the present application comprises a processor 401, a memory 402 and a bus, the memory 402 stores machine readable instructions executable by the processor 401, when the electronic device is running, the processor 401 and the memory 402 communicate through the bus, and the processor 401 executes the machine readable instructions to perform the steps of the network range data processing method as described above.

[0101] Specifically, the memory 402 and the processor 401 can be general memory and processor, which are not specifically limited here, and when the processor 401 runs the computer program stored in the memory 402, the network range data processing method can be executed.

[0102] Corresponding to the network range data processing method, the embodiment of the present application further provides a computer readable storage medium, the computer readable storage medium stores a computer program, and the computer program is executed by the processor to perform the steps of the network range data processing method.

[0103] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the system and the device described above can refer to the corresponding process in the method embodiment, and will not be repeated in the present application. In the several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented by other means. The above-described device embodiments are only schematic, for example, the division of the modules is only a logical function division, and the actual implementation can have another division manner, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed mutual elements can be indirect coupling or communication connection through some communication interface, device or module, which can be electrical, mechanical or other forms.

[0104] The modules described as separate components can or can not be physically separated, and the components shown as modules can or can not be physical units, i.e. can be located in one place or distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0105] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0106] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer readable storage medium executable by a processor. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the information processing method described in each embodiment of the present application. The foregoing storage medium includes: U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, and various storage program codes.

[0107] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A processing system for network range data, characterized by, The system comprises a network target platform and a network target; the network target platform comprises a first data transmission plug-in; the network target comprises a second data transmission plug-in and at least one collection agent; each collection agent corresponds to a type of network node in the network target; The network target platform sends a data collection strategy to the second data transmission plug-in through the first data transmission plug-in; the second data transmission plug-in forwards the data collection strategy to the collection agent in the network target; The collection agent collects network target data of the corresponding network node according to the data collection strategy, and sends the network target data to a data processing center; The data processing center inputs all the received network target data into a network detection model to obtain the network running state of the network target; the network detection model is obtained by training based on network target sample data and corresponding network running state labels; Before the network target platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network target platform is further configured to send network simulation parameters to the second data transmission plug-in through the first data transmission plug-in; the network simulation parameters comprise target scene parameters and operation control commands; after receiving successful information of receiving the network simulation parameters sent by the network target through the second data transmission plug-in through the first data transmission plug-in, the network target platform sends network simulation start state information to the second data transmission plug-in through the first data transmission plug-in, so that the network target executes corresponding operation based on the target scene parameters and the operation control commands; when the network target platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network target platform is specifically configured to: after receiving network simulation start completion information sent by the network target through the second data transmission plug-in through the first data transmission plug-in, the network target platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in.

2. The processing system of network range data according to claim 1, wherein, When the data processing center inputs all the network target data into the network detection model to obtain the network running state of the network target, the data processing center is specifically configured to: perform weighted fusion on all the network target data to obtain network target fusion features; input the network target fusion features into the network detection model to obtain the network running state of the network target.

3. The processing system of networked range data according to claim 1, wherein, Before the network target platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, The collection agent reports attribute information to the network target platform at a preset reporting time interval by calling an agent state monitoring interface opened by the network target platform: The network target platform updates the storage data of the collection agent in a monitoring database according to the attribute information reported by the collection agent; the monitoring database is used to store attribute information of all collection agents.

4. The processing system of network range data according to claim 3, wherein, The network target platform is further configured to: According to the latest storage time of attribute information of each collection agent in the monitoring database, the non-updating duration corresponding to each collection agent is counted; If the non-updating duration corresponding to the collection agent exceeds a preset duration, the state of the collection agent is set to an offline state, and an offline warning is performed.

5. The processing system of network range data according to any one of claims 1 to 4, characterized in that, The data processing center is further configured to: visualize the network range data and / or the network running state of each network node in at least one visualization form; send the visualized network range data and / or the network running state to the network range platform.

6. A method of processing network range data, characterized by, The network range data processing method is applied to a data processing center in a network range data processing system according to any one of claims 1 to 5, the system comprising a network range platform and a network range; the network range platform comprises a first data transmission plug-in; the network range comprises a second data transmission plug-in and at least one collection agent; Each collection agent corresponds to a type of network node in the network range; the method comprises: receiving network range data sent by a collection agent of the network range; The network range data is network range data of a corresponding network node in the network range collected by the collection agent according to a data collection strategy; the data collection strategy is sent by the network range platform to the second data transmission plug-in through the first data transmission plug-in, and then forwarded to the collection agent by the second data transmission plug-in; before the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network range platform sends network simulation parameters to the second data transmission plug-in through the first data transmission plug-in; the network simulation parameters comprise target scene parameters and running control commands; after the network range platform receives successful information of the network simulation parameters sent by the network range through the second data transmission plug-in through the first data transmission plug-in, the network range platform sends network simulation start state information to the second data transmission plug-in through the first data transmission plug-in, so that the network range performs corresponding running operations based on the target scene parameters and the running control commands; after the network range platform receives network simulation start completion information sent by the network range through the second data transmission plug-in through the first data transmission plug-in, the network range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in; All network range data is input into a network detection model to obtain the network running state of the network range; the network detection model is obtained by training based on network range sample data and corresponding network running state labels.

7. A network range data processing apparatus, characterized by, The apparatus comprises: a receiving module configured to receive network range data sent by a collection agent of a network range; The network target range data is network target range data of a corresponding network node in the network target range collected by the collection agent according to a data collection strategy; the data collection strategy is sent by a network target range platform to a second data transmission plug-in through a first data transmission plug-in, and then the second data transmission plug-in forwards the data collection strategy to the collection agent; before the network target range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in, the network target range platform sends network simulation parameters to the second data transmission plug-in through the first data transmission plug-in; the network simulation parameters include target scene parameters and operation control commands; after the network target range platform receives successful information that the network simulation parameters sent by the network target range through the second data transmission plug-in are received through the first data transmission plug-in, the network target range platform sends network simulation start state information to the second data transmission plug-in through the first data transmission plug-in, so that the network target range executes corresponding operation operations based on the target scene parameters and the operation control commands; after the network target range platform receives network simulation start completion information sent by the network target range through the second data transmission plug-in through the first data transmission plug-in, the network target range platform sends the data collection strategy to the second data transmission plug-in through the first data transmission plug-in. The input module is used for inputting all network target range data into a network detection model to obtain a network operation state of the network target range; the network detection model is obtained by training based on network target range sample data and corresponding network operation state labels.

8. An electronic device, comprising: The processor, the storage medium and the bus, the storage medium stores machine readable instructions executable by the processor, when the electronic device runs, the processor and the storage medium communicate through the bus, the processor executes the machine readable instructions, to execute the steps of the network target range data processing method of claim 6. The computer readable storage medium stores a computer program, and the computer program is executed by the processor to execute the steps of the network target range data processing method of claim 6.

9. A computer-readable storage medium, characterized in that, ​

Citation Information

Patent Citations

  • Network target range heterogeneous target configuration acquisition method and device, electronic equipment and storage medium

    CN117255021A

  • Network target range task evaluation method and device, equipment and storage medium

    CN119728393A