Network security situation awareness method and device, medium and equipment
By constructing and optimizing the initial decision tree model and using data distillation technology to process training samples, the accuracy of security event perception in the power optical transmission system is improved, solving the problem of low accuracy in existing technologies.
Patent Information
- Application Number
- CN202510742011.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-06-05
AI Technical Summary
The existing security event perception methods for power optical transmission systems have low accuracy, and when the model lacks training data or has deviations, the perception coverage performance is affected.
Build an initial decision tree model, obtain key features through optimization processing and data distillation technology, build an initial security perception model, and use the distilled training samples to train the model to improve the accuracy of the model.
It improves the accuracy of security event perception, avoids the problem of poor perception coverage performance caused by insufficient training data, and achieves more efficient security status judgment.
Smart Images

Figure CN120710705A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security situation awareness method, device, medium and equipment. Background Art
[0002] Optical communication networks have brought significant benefits to power systems. However, while improving network performance, they also pose new security risks. A growing number of sophisticated technologies and products are now capable of attacking and eavesdropping on the physical layer of optical networks. As attack methods continue to evolve, power optical transmission systems face unprecedented security threats. To prevent serious impacts on power grid security, it is crucial to be aware of security incidents within these systems.
[0003] The current method for sensing security events in power optical transmission systems is to collect various types of data during network data transmission, convert the raw data into features, input the features into a trained model, and use the trained model to calculate a safety value based on the features. The safety value is compared with the threshold to determine whether the status corresponding to the network data is safe.
[0004] The current security incident perception method for power optical transmission systems requires a large amount of training data to train the model. If the training data is insufficient or biased, it may affect the perception coverage performance of the method, resulting in a relatively low accuracy rate in security incident perception. At the same time, the model calculates a safety value and then determines whether it is safe by comparing the safety value with the threshold. The safety value only represents part of the network security status and cannot comprehensively represent the network security status. Therefore, the accuracy rate of the existing security incident perception method for power optical transmission systems is relatively low. Summary of the Invention
[0005] In view of this, the present invention provides a network security situation awareness method, the main purpose of which is to solve the problem of low accuracy of the existing security event perception method of the power optical transmission system.
[0006] According to one aspect of the present application, a network security situation awareness method is provided, the method comprising:
[0007] Obtaining key features related to network security in the power dispatch optical transmission monitoring system, constructing an initial decision tree model based on the first training sample, the key features and their corresponding feature attributes, and optimizing the initial decision tree model to obtain an initial security perception model;
[0008] Obtaining a second training sample, processing the second training sample using a data distillation method to obtain a distilled training sample, and training the initial security perception model based on the distilled sample to obtain a trained security perception model;
[0009] The operating data of the electric power dispatching optical transmission monitoring system under the current situation is obtained, and the operating data is input into the trained safety perception model to obtain the safety status of the electric power dispatching optical transmission monitoring system under the current situation.
[0010] Optionally, the optimizing the initial decision tree model to obtain an initial security perception model includes:
[0011] Selecting a plurality of optimized samples from the training samples, and performing feature recognition on the initial decision tree model using a back propagation method based on the optimized samples to obtain reverse features;
[0012] Only the nodes and branches corresponding to the reverse features are retained in the initial decision tree model to obtain an intermediate decision tree model;
[0013] Calculating the information gain corresponding to each node in the intermediate decision tree model, and deleting the nodes whose information gain is less than a gain threshold from the intermediate decision tree model;
[0014] Based on the intermediate decision tree model with the nodes deleted, the back propagation method is used again to identify features to obtain new reverse features. Based on the new reverse features, a new intermediate decision tree model is obtained. The nodes in the new decision tree model are deleted until the number of iterations is reached to obtain the initial security perception model.
[0015] Optionally, the performing feature recognition on the initial decision tree model based on the optimized sample using a back propagation method to obtain reverse features includes:
[0016] Calculate the decision target corresponding to the key feature corresponding to each node in the initial decision tree model based on a preset decision target formula;
[0017] Substituting the decision target corresponding to the key feature corresponding to each node into a preset relevant calculation formula to obtain a first correlation value between the key feature corresponding to each node and network security;
[0018] When the key feature corresponding to each node and the first correlation value of network security belong to a preset correlation range, the key feature corresponding to the node is a reverse feature.
[0019] Optionally, the information gain calculation formula is:
[0020]
[0021] Among them, p t is the tth feature x t The information gain of the corresponding node, C(x t ) is the t-th feature x t The first correlation value between it and network security, B is the correlation value between it and the t-th feature x t The number of optimized samples corresponding to the node matching; w c is the tth feature x t The number of node splits of the corresponding node, α e is the information entropy, v is the feature matrix, and β is the adjustment value.
[0022] Optionally, the adopting a data distillation method to process the second training sample to obtain a distilled training sample includes:
[0023] Dividing the second training samples into a plurality of sample groups, and writing the samples in each sample group into a plurality of modal data according to a preset format;
[0024] Using a pre-trained feature extraction model to extract semantic features and structural features from each of the modal data;
[0025] The semantic features and structural features in each modal data are fused across modal attention to obtain multiple distilled training samples.
[0026] Optionally, the following formula is used to perform cross-modal attention fusion on the semantic features and structural features in each modality data:
[0027]
[0028] Among them, W q , W k is a learnable parameter, d is the feature dimension, is a semantic feature, is the structural feature, m is the mth mode, and M is the number of modes.
[0029] Optionally, the acquiring of key features related to network security in the power dispatching optical transmission monitoring system includes:
[0030] Obtaining network communication characteristics, equipment operation characteristics, and service application characteristics in the power dispatch optical transmission monitoring system, wherein the network communication characteristics include network traffic data, port connection data, and communication protocol data; the equipment operation characteristics include optical power data, equipment temperature data, and equipment alarm data; and the service application characteristics include service transmission data and user operation behavior;
[0031] A second correlation value between each of the network communication feature, the device operation feature, and the service application feature and network security is calculated respectively, and a feature whose second correlation value is greater than a preset threshold is taken as a key feature.
[0032] According to another aspect of the present application, a network security situation awareness device is provided, comprising:
[0033] An initial model acquisition module is configured to acquire key features related to network security in the power dispatch optical transmission monitoring system, construct an initial decision tree model based on the first training sample, the key features, and their corresponding feature attributes, and optimize the initial decision tree model to obtain an initial security perception model;
[0034] a model training module, configured to obtain a second training sample, process the second training sample using a data distillation method to obtain a distilled training sample, and train the initial security perception model based on the distilled sample to obtain a trained security perception model;
[0035] The safety perception module is used to obtain the operating data of the power dispatching optical transmission monitoring system under the current situation, input the operating data into the trained safety perception model, and obtain the safety status of the power dispatching optical transmission monitoring system under the current situation.
[0036] Optionally, the initial model acquisition module is further used to:
[0037] Selecting a plurality of optimized samples from the training samples, and performing feature recognition on the initial decision tree model using a back propagation method based on the optimized samples to obtain reverse features;
[0038] Only the nodes and branches corresponding to the reverse features are retained in the initial decision tree model to obtain an intermediate decision tree model;
[0039] Calculating the information gain corresponding to each node in the intermediate decision tree model, and deleting the nodes whose information gain is less than a gain threshold from the intermediate decision tree model;
[0040] Based on the intermediate decision tree model with the nodes deleted, the back propagation method is used again to identify features to obtain new reverse features. Based on the new reverse features, a new intermediate decision tree model is obtained. The nodes in the new decision tree model are deleted until the number of iterations is reached to obtain the initial security perception model.
[0041] Optionally, the initial model acquisition module is further used to:
[0042] Calculate the decision target corresponding to the key feature corresponding to each node in the initial decision tree model based on a preset decision target formula;
[0043] Substituting the decision target corresponding to the key feature corresponding to each node into a preset relevant calculation formula to obtain a first correlation value between the key feature corresponding to each node and network security;
[0044] When the key feature corresponding to each node and the first correlation value of network security belong to a preset correlation range, the key feature corresponding to the node is a reverse feature.
[0045] Optionally, the information gain calculation formula is:
[0046]
[0047] Among them, p t is the tth feature x t The information gain of the corresponding node, C(x t ) is the t-th feature x t The first correlation value between it and network security, B is the correlation value between it and the t-th feature x t The number of optimized samples corresponding to the node matching; w c is the tth feature x t The number of node splits of the corresponding node, α e is the information entropy, v is the feature matrix, and β is the adjustment value.
[0048] Optionally, the model training module is further used to:
[0049] Dividing the second training samples into a plurality of sample groups, and writing the samples in each sample group into a plurality of modal data according to a preset format;
[0050] Using a pre-trained feature extraction model to extract semantic features and structural features from each of the modal data;
[0051] The semantic features and structural features in each modal data are fused across modal attention to obtain multiple distilled training samples.
[0052] Optionally, the following formula is used to perform cross-modal attention fusion on the semantic features and structural features in each modality data:
[0053]
[0054] Among them, W q , W k is a learnable parameter, d is the feature dimension, is a semantic feature, is the structural feature, m is the mth mode, and M is the number of modes.
[0055] Optionally, the initial model acquisition module is further used to:
[0056] Obtaining network communication characteristics, equipment operation characteristics, and service application characteristics in the power dispatch optical transmission monitoring system, wherein the network communication characteristics include network traffic data, port connection data, and communication protocol data; the equipment operation characteristics include optical power data, equipment temperature data, and equipment alarm data; and the service application characteristics include service transmission data and user operation behavior;
[0057] A second correlation value between each of the network communication feature, the device operation feature, and the service application feature and network security is calculated respectively, and a feature whose second correlation value is greater than a preset threshold is taken as a key feature.
[0058] According to another aspect of the present application, a storage medium is provided, in which at least one executable instruction is stored. The executable instruction enables a processor to perform operations corresponding to the above-mentioned network security situation awareness method.
[0059] According to another aspect of the present application, a computer device is provided, comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus;
[0060] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the above-mentioned network security situation awareness method.
[0061] By means of the above technical solution, the technical solution provided by the embodiment of the present invention has at least the following advantages:
[0062] The present application provides a network security situation awareness method, apparatus, medium and equipment. Based on a first training sample, key features related to network security in an electric power dispatching optical transmission monitoring system and their corresponding characteristic attributes, an initial decision tree model is constructed. To avoid model overfitting, the initial decision tree model is optimized, and non-compliant nodes are optimized to obtain an initial security perception model that achieves the expected goal. The second training sample is distilled using data distillation technology to fuse multi-level features. While retaining the key information of the original data, efficient data compression is achieved to obtain more valuable training samples. The initial security perception model is trained based on the distilled training samples. The operating data of the electric power dispatching optical transmission monitoring system under the current situation is input into the trained security perception model to obtain the security status of the electric power dispatching optical transmission monitoring system under the current situation. The security status is directly judged based on the operating data, thereby improving the accuracy of security event perception. Since the training samples are processed using data distillation technology, more valuable high-level concentrated samples are obtained, avoiding the problem of poor perception coverage performance due to insufficient training data, and also improving the accuracy of security event perception.
[0063] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0065] Figure 1 A flowchart of a network security situation awareness method provided by an embodiment of the present application is shown;
[0066] Figure 2 Another flow chart of a network security situation awareness method provided by an embodiment of the present application is shown;
[0067] Figure 3 Another flow chart of a network security situation awareness method provided by an embodiment of the present application is shown;
[0068] Figure 4 A structural block diagram of a network security situation awareness device provided by an embodiment of the present application is shown;
[0069] Figure 5A schematic structural diagram of a computer device provided by an embodiment of the present invention is shown.
[0070] in,
[0071] Figure 4 Middle: 402-initial model acquisition module; 404-model training module; 406-security perception module;
[0072] Figure 5 In the figure: 502 - processor; 504 - communication interface; 506 - memory; 508 - communication bus; 510 - program. DETAILED DESCRIPTION
[0073] The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, in the absence of conflict, the embodiments and features of the embodiments of the present invention can be combined with each other.
[0074] To further illustrate the technical means and effects employed by the present invention to achieve its intended objectives, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention is provided in conjunction with the accompanying drawings and preferred embodiments. In the following description, different references to "one embodiment" or "embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics of one or more embodiments may be combined in any suitable manner.
[0075] In order to solve the problem that the existing security event perception method of power optical transmission system has low accuracy, the embodiment of the present application provides a network security situation perception method, such as Figure 1 As shown, the method includes:
[0076] 102: Acquire key features related to network security in the power dispatch optical transmission monitoring system, construct an initial decision tree model based on the first training sample, the key features, and their corresponding feature attributes, and optimize the initial decision tree model to obtain an initial security perception model;
[0077] 104: Obtain a second training sample, process the second training sample using a data distillation method to obtain a distilled training sample, and train the initial security perception model based on the distilled sample to obtain a trained security perception model;
[0078] 106: Obtain operating data of the power dispatching optical transmission monitoring system under the current situation, input the operating data into the trained security perception model, and obtain the security status of the power dispatching optical transmission monitoring system under the current situation.
[0079] Specifically, network security is judged through network communication data, equipment operating status, and business application data in the power dispatching optical transmission monitoring system.
[0080] Network communication data includes: (1) Network traffic data: including the traffic size and traffic change rate of optical transmission links between different nodes in different time periods. An abnormal increase or decrease in traffic may indicate security incidents such as network attacks, equipment failures, or sudden changes in services. (2) Port connection data: information related to the connection status (connected / disconnected), connection frequency, connection duration, and specific IP addresses or devices connected to the ports of optical transmission equipment. Abnormal port connection behavior may be a sign of illegal device access or malicious scanning. (3) Communication protocol data: such as protocol-related parameters such as SDH (Synchronous Digital Hierarchy) and OTN (Optical Transport Network) used in the optical transmission process, including the format, content, error rate, etc. of protocol messages. Protocol anomalies may indicate the presence of protocol attacks or equipment communication failures.
[0081] The equipment operation status includes: (1) Optical power data: refers to the power intensity of the optical signal during the transmission process. Too high or too low optical power may affect the signal transmission quality, resulting in data loss or increased bit error rate. In severe cases, it may cause equipment failure. It is an important indicator of abnormal equipment operation status. (2) Temperature data: The temperature inside the optical transmission equipment. Long-term high-load operation of the equipment or failure of the cooling system may cause the temperature to rise. Excessive temperature will affect the performance of the equipment and even cause hardware damage. It can be used as a key feature of the health status of the equipment. (3) Equipment alarm data: Alarm information issued by the equipment itself when it detects an abnormality, such as hardware failure alarm, link interruption alarm, performance indicator over-limit alarm, etc. These alarms directly reflect the failure or potential risk of the equipment and are the key basis for the perception of security events.
[0082] Business application data includes: (1) Business data transmission characteristics: including the type of business data (such as control instructions, monitoring data, etc.), data volume, transmission frequency, and data integrity. Business data transmission anomalies (such as data loss, errors, sudden changes in transmission frequency, etc.) may affect the normal operation of power dispatching business and indicate the existence of security issues. (2) User operation behavior data: involving user operations on the power dispatching optical transmission monitoring system, such as login time, login location, operation instructions, operation frequency, etc. Abnormal user operations (such as abnormal logins during non-working hours, frequent attempts at sensitive operations, etc.) may be manifestations of illegal user intrusion or illegal operations by internal personnel.
[0083] Representative key features are selected through feature selection. Specifically, network communication data, equipment operating status and business application data in the power dispatching optical transmission monitoring system are obtained, and the correlation value between each type of network communication data, equipment operating status and business application data and network security is calculated respectively. Data with a correlation value greater than a preset correlation threshold is used as a key feature.
[0084] The key features are matched with a preset root node mapping table. The preset root node mapping table is a file generated based on expert experience to determine the key features that can be used as root nodes. It records the key features corresponding to the root node and determines the key features corresponding to the root node of the decision tree. Branches are constructed based on the attributes of the key features corresponding to the root node. The data of the first training sample can also be classified according to the root node. Multiple first-level branches are obtained based on the attributes or data classification results. The attributes of the key features of the root node or the data classification criteria are used as the first branch nodes. In each first-level branch, a second-level branch is constructed based on the attributes of the key features corresponding to the first-level branch nodes or the data classification of the sample. The attributes of the key features corresponding to the first-level branch nodes or the data classification criteria are used as the second branch nodes. According to the above method, multiple layers of branches are generated in sequence until a leaf node is generated, thereby obtaining an initial decision tree model. Avoid overfitting of the initial decision tree model and avoid the initial decision tree model from being too large. The nodes that do not meet the requirements in the initial decision tree model are optimized to obtain an initial security perception model that achieves the expected target results. Data distillation technology is applied to distill the sample data of the second training sample, and the features of the sample data are integrated together to obtain more valuable features. The initial security perception model is trained using the distilled training samples, and finally a trained security perception model is formed. The model is trained using the distilled training samples, which improves the training efficiency and accuracy of the model.
[0085] Obtain the operating data of the power dispatching optical transmission monitoring system under the current situation, input the operating data into the trained security perception model, and the security perception model judges the security status under the current situation and outputs the security status of the power dispatching optical transmission monitoring system under the current situation.
[0086] The present application provides a network security situation awareness method. Compared with the existing technology, an initial decision tree model is constructed based on a first training sample, key features related to network security in an electric power dispatching optical transmission monitoring system, and their corresponding characteristic attributes. To avoid model overfitting, the initial decision tree model is optimized, and non-compliant nodes are optimized to obtain an initial security perception model that achieves the expected goal. The second training sample is distilled using data distillation technology to fuse multi-level features. While retaining the key information of the original data, efficient compression of the data level is achieved to obtain more valuable training samples. The initial security perception model is trained based on the distilled training samples. The operating data of the electric power dispatching optical transmission monitoring system under the current situation is input into the trained security perception model to obtain the security status of the electric power dispatching optical transmission monitoring system under the current situation. The security status is directly judged based on the operating data, thereby improving the accuracy of security event perception. Since the training samples are processed using data distillation technology, more valuable high-level concentrated samples are obtained, which avoids the problem of poor perception coverage performance caused by insufficient training data and improves the accuracy of security event perception.
[0087] In one embodiment, Figure 2 As shown, the initial decision tree model is optimized to obtain the initial security perception model, including:
[0088] 202: Select multiple optimized samples from the training samples, and use the back propagation method to perform feature recognition on the initial decision tree model based on the optimized samples to obtain reverse features;
[0089] 204: Only the nodes and branches corresponding to the reverse features are retained in the initial decision tree model to obtain an intermediate decision tree model;
[0090] 206: Calculate the information gain corresponding to each node in the intermediate decision tree model, and delete the nodes whose information gain is less than the gain threshold from the intermediate decision tree model;
[0091] 208: Based on the intermediate decision tree model with the nodes deleted, the back propagation method is used again to identify features to obtain new reverse features. Based on the new reverse features, a new intermediate decision tree model is obtained. The nodes in the new decision tree model are deleted until the number of iterations is reached to obtain the initial security perception model.
[0092] Specifically, in the process of building the model, in order to avoid overfitting of the security perception model, the rationality of the characteristic value is deduced through the results of the decision-making target. The characteristics of the perception elements are identified based on the back propagation method, and the non-conforming features are removed.
[0093] Initially set the concept of "decision goal" of a decision tree, and set the decision goal as Z(X) formula as follows:
[0094]
[0095] Where c k represents the value of the kth key feature in an optimized sample; n represents the number of branch nodes in the decision tree; g i represents the decision rule of the decision tree, that is, the value of each branch node; d represents the size of the decision rule library, that is, the number of all feature values of the decision tree; t represents the number of training times.
[0096] Based on the preset decision target formula, calculate the decision target corresponding to the key feature of each node in the initial decision tree model; substitute the decision target corresponding to the key feature of each node into the preset relevant calculation formula to obtain the first correlation value between the key feature corresponding to each node and network security. The relevant calculation formula is as follows:
[0097]
[0098] Where k r Represents the uncertainty degree of the feature vector, E0 represents the hyperbolic tangent function, and A represents the number of layers of the decision tree.
[0099] When the key feature corresponding to each node and the first correlation value of network security belong to the preset correlation range corresponding to the key feature, the key feature is a reverse feature, and the key feature that does not belong to the preset correlation range is a feature that does not meet the requirements. The nodes and branches corresponding to the features that do not meet the requirements are deleted in the initial decision tree model. Therefore, only the nodes and branches corresponding to the reverse features are retained in the initial decision tree model, and finally an intermediate decision tree model is obtained.
[0100] By calculating the information gain of the key features corresponding to each node in the intermediate decision tree model, which describes the contribution of a feature to the decision outcome, the first iteration of the decision tree model is obtained by selecting the most important features. Nodes with information gain greater than or equal to the gain threshold are retained, while nodes with information gain less than the gain threshold are deleted. Based on the first iteration of the decision tree model, the next round of backpropagation feature recognition and information gain calculation is performed to obtain the second iteration of the decision tree model. This process is repeated until the required number of iterations is reached, resulting in the initial security perception model.
[0101] The information gain calculation formula is:
[0102]
[0103] Among them, p t is the tth feature x t The information gain of the corresponding node, C(x t ) is the t-th feature xt The first correlation value between it and network security, B is the correlation value between it and the t-th feature x t The number of optimized samples corresponding to the node matching; w c is the tth feature x t The number of node splits of the corresponding node, α e is the information entropy, v is the feature matrix, and β is the adjustment value.
[0104] In one embodiment, Figure 3 As shown, the second training sample is processed using a data distillation method to obtain a distilled training sample, including:
[0105] 302: Divide the second training sample into a plurality of sample groups, and write the samples in each sample group into a plurality of modal data according to a preset format;
[0106] 304: Use the pre-trained feature extraction model to extract semantic features and structural features from each modality data;
[0107] 306: Perform cross-modal attention fusion on the semantic features and structural features in each modal data to obtain multiple distilled training samples.
[0108] Specifically, with the improvement of destructive means, the judgment criteria for network security are changing. Therefore, only recent network operation data and security status are obtained as the second training samples. The number of second training samples is relatively small, so the second training samples are subjected to data distillation. Data distillation adopts multi-level feature fusion and adaptive importance sampling. While retaining the key information of the original data, it achieves efficient compression of the data level and obtains more valuable feature data. Then, the security perception model is trained with the distilled training samples, which can improve the training speed and accuracy of the model.
[0109] The specific method for performing data distillation on the second training sample is as follows:
[0110] First, the second training sample is divided into multiple sample groups, and the samples in each sample group are written into multiple modal data according to a preset format. in Indicates the mth modal text, y i For label.
[0111] Then, the pre-trained model (CLIP) is used to extract high-level semantic features and low-level structural features of each modality:
[0112] High-level semantic features: EM is the encoder of modality m (BERT).
[0113] Low-level structural features:
[0114] Finally, high-level semantic features and low-level structural features are fused through cross-modal attention, and the fused data is used as a distilled training sample. The above processing is performed on each sample group separately to obtain multiple distilled training samples.
[0115] The following formula is used to perform cross-modal attention fusion on the semantic features and structural features in each modality data:
[0116]
[0117] Among them, W q , W k is a learnable parameter, d is the feature dimension, is a semantic feature, is the structural feature, m is the mth mode, and M is the number of modes.
[0118] Furthermore, as a response to the above Figure 1 The embodiment of the present invention provides a network security situation awareness device, such as Figure 4 As shown, the device includes:
[0119] An initial model acquisition module 402 is configured to acquire key features related to network security in the power dispatch optical transmission monitoring system, construct an initial decision tree model based on the first training sample, the key features, and their corresponding feature attributes, and optimize the initial decision tree model to obtain an initial security perception model.
[0120] A model training module 404 is configured to obtain a second training sample, process the second training sample using a data distillation method to obtain a distilled training sample, and train the initial security perception model based on the distilled sample to obtain a trained security perception model;
[0121] The safety perception module 406 is used to obtain the operating data of the power dispatching optical transmission monitoring system under the current situation, input the operating data into the trained safety perception model, and obtain the safety status of the power dispatching optical transmission monitoring system under the current situation.
[0122] The present application provides a network security situation awareness device. Compared with the existing technology, an initial decision tree model is constructed based on a first training sample, key features related to network security in an electric power dispatching optical transmission monitoring system, and their corresponding characteristic attributes. To avoid model overfitting, the initial decision tree model is optimized, and non-compliant nodes are optimized to obtain an initial security perception model that achieves the expected goal. The second training sample is distilled using data distillation technology to fuse multi-level features. While retaining the key information of the original data, efficient compression of the data level is achieved to obtain more valuable training samples. The initial security perception model is trained based on the distilled training samples. The operating data of the electric power dispatching optical transmission monitoring system under the current situation is input into the trained security perception model to obtain the security status of the electric power dispatching optical transmission monitoring system under the current situation. The security status is directly judged based on the operating data, thereby improving the accuracy of security event perception. Since the training samples are processed using data distillation technology, more valuable high-level concentrated samples are obtained, which avoids the problem of poor perception coverage performance caused by insufficient training data and improves the accuracy of security event perception.
[0123] In one embodiment, the initial model acquisition module is further configured to:
[0124] Select multiple optimized samples from the training samples, and use the back propagation method to perform feature recognition on the initial decision tree model based on the optimized samples to obtain reverse features;
[0125] In the initial decision tree model, only the nodes and branches corresponding to the reverse features are retained to obtain the intermediate decision tree model;
[0126] Calculate the information gain corresponding to each node in the intermediate decision tree model, and delete the nodes whose information gain is less than the gain threshold from the intermediate decision tree model;
[0127] Based on the intermediate decision tree model with the nodes deleted, the back propagation method is used again to identify features to obtain new reverse features. Based on the new reverse features, a new intermediate decision tree model is obtained. The nodes in the new decision tree model are deleted until the number of iterations is reached to obtain the initial security perception model.
[0128] In one embodiment, the initial model acquisition module is further configured to:
[0129] Based on the preset decision target formula, calculate the decision target corresponding to the key feature of each node in the initial decision tree model;
[0130] Substituting the decision target corresponding to the key feature corresponding to each node into a preset relevant calculation formula to obtain a first correlation value between the key feature corresponding to each node and network security;
[0131] When the key feature corresponding to each node and the first correlation value of network security belong to a preset correlation range, the key feature corresponding to the node is a reverse feature.
[0132] In one embodiment, the information gain calculation formula is:
[0133]
[0134] Among them, p t is the tth feature x t The information gain of the corresponding node, C(x t ) is the t-th feature x t The first correlation value between it and network security, B is the correlation value between it and the t-th feature x t The number of optimized samples corresponding to the node matching; w c is the tth feature x t The number of node splits of the corresponding node, α e is the information entropy, v is the feature matrix, and β is the adjustment value.
[0135] In one embodiment, the model training module is further configured to:
[0136] Dividing the second training sample into a plurality of sample groups, and writing the samples in each sample group into a plurality of modal data according to a preset format;
[0137] Use pre-trained feature extraction models to extract semantic and structural features from each modality data;
[0138] The semantic features and structural features in each modal data are fused across modal attention to obtain multiple distilled training samples.
[0139] In one embodiment, the following formula is used to perform cross-modal attention fusion on the semantic features and structural features in each modality data:
[0140]
[0141] Among them, W q , W k is a learnable parameter, d is the feature dimension, is a semantic feature, is the structural feature, m is the mth mode, and M is the number of modes.
[0142] In one embodiment, the initial model acquisition module is further configured to:
[0143] Obtain network communication characteristics, equipment operation characteristics, and business application characteristics in the power dispatch optical transmission monitoring system. Network communication characteristics include network traffic data, port connection data, and communication protocol data; equipment operation characteristics include optical power data, equipment temperature data, and equipment alarm data; and business application characteristics include business transmission data and user operation behavior.
[0144] The second correlation value between each of the network communication feature, the device operation feature and the business application feature and the network security is calculated respectively, and the feature whose second correlation value is greater than a preset threshold is taken as the key feature.
[0145] According to one embodiment of the present invention, a storage medium is provided, which stores at least one executable instruction. The computer-executable instruction can execute the network security situation awareness method in any of the above method embodiments.
[0146] Figure 5 A schematic structural diagram of a computer device provided according to an embodiment of the present invention is shown. The specific embodiment of the present invention does not limit the specific implementation of the computer device.
[0147] like Figure 5 As shown, the computer device may include: a processor (processor) 502 , a communication interface (Communications Interface) 504 , a memory (memory) 506 , and a communication bus 508 .
[0148] The processor 502 , the communication interface 504 , and the memory 506 communicate with each other via a communication bus 508 .
[0149] The communication interface 504 is used to communicate with other devices such as clients or other servers.
[0150] The processor 502 is used to execute the program 510, and specifically can execute the relevant steps in the above-mentioned network security situation awareness method embodiment.
[0151] Specifically, the program 510 may include program codes, which include computer operation instructions.
[0152] Processor 502 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention. The one or more processors included in a computer device may be of the same type, such as one or more CPUs, or may be of different types, such as one or more CPUs and one or more ASICs.
[0153] The memory 506 is used to store the program 510. The memory 506 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0154] The program 510 may be specifically configured to enable the processor 502 to perform the following operations:
[0155] Obtaining key features related to network security in the power dispatch optical transmission monitoring system, constructing an initial decision tree model based on the first training sample, the key features, and their corresponding feature attributes, and optimizing the initial decision tree model to obtain an initial security perception model;
[0156] Obtaining a second training sample, processing the second training sample using a data distillation method to obtain a distilled training sample, and training the initial security perception model based on the distilled sample to obtain a trained security perception model;
[0157] The operating data of the power dispatching optical transmission monitoring system under the current situation is obtained, and the operating data is input into the trained security perception model to obtain the security status of the power dispatching optical transmission monitoring system under the current situation.
[0158] Obviously, those skilled in the art will appreciate that the various modules or steps of the present invention described above can be implemented using a general-purpose computing device, and can be centralized on a single computing device or distributed across a network of multiple computing devices. In one embodiment, they can be implemented using program code executable by a computing device, and thus, can be stored in a storage device and executed by the computing device. In some cases, the steps shown or described herein can be performed in a different order than that shown, or can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0159] The above embodiments are merely exemplary embodiments of the present application and are not intended to limit the scope of the present application. The scope of protection of the present application is defined by the claims. Those skilled in the art may make various modifications or equivalent substitutions to the present application within the essence and scope of protection of the present application, and such modifications or equivalent substitutions shall also be deemed to fall within the scope of protection of the present application.
Claims
1. A network security situation awareness method, characterized in that: include: Obtaining key features related to network security in the power dispatch optical transmission monitoring system, constructing an initial decision tree model based on the first training sample, the key features and their corresponding feature attributes, and optimizing the initial decision tree model to obtain an initial security perception model; Obtaining a second training sample, processing the second training sample using a data distillation method to obtain a distilled training sample, and training the initial security perception model based on the distilled sample to obtain a trained security perception model; The operating data of the electric power dispatching optical transmission monitoring system under the current situation is obtained, and the operating data is input into the trained safety perception model to obtain the safety status of the electric power dispatching optical transmission monitoring system under the current situation.
2. The network security situation awareness method according to claim 1, characterized in that: The optimizing process of the initial decision tree model to obtain an initial security perception model includes: Selecting a plurality of optimized samples from the training samples, and performing feature recognition on the initial decision tree model using a back propagation method based on the optimized samples to obtain reverse features; Only the nodes and branches corresponding to the reverse features are retained in the initial decision tree model to obtain an intermediate decision tree model; Calculating the information gain corresponding to each node in the intermediate decision tree model, and deleting the nodes whose information gain is less than a gain threshold from the intermediate decision tree model; Based on the intermediate decision tree model with the nodes deleted, the back propagation method is used again to identify features to obtain new reverse features. Based on the new reverse features, a new intermediate decision tree model is obtained. The nodes in the new decision tree model are deleted until the number of iterations is reached to obtain the initial security perception model.
3. The network security situation awareness method according to claim 2, characterized in that: The method of performing feature recognition on the initial decision tree model based on the optimized sample and obtaining reverse features by using a back propagation method includes: Calculate the decision target corresponding to the key feature corresponding to each node in the initial decision tree model based on a preset decision target formula; Substituting the decision target corresponding to the key feature corresponding to each node into a preset relevant calculation formula to obtain a first correlation value between the key feature corresponding to each node and network security; When the key feature corresponding to each node and the first correlation value of network security belong to a preset correlation range, the key feature corresponding to the node is a reverse feature.
4. The network security situation awareness method according to claim 2, characterized in that: The information gain calculation formula is: Among them, p t is the tth feature x t The information gain of the corresponding node, C(x t ) is the t-th feature x t The first correlation value between it and network security, B is the correlation value between it and the t-th feature x t The number of optimized samples corresponding to the node matching; w c is the tth feature x t The number of node splits of the corresponding node, α e is the information entropy, v is the feature matrix, and β is the adjustment value.
5. The network security situation awareness method according to claim 1, wherein: The step of processing the second training sample using a data distillation method to obtain a distilled training sample includes: Dividing the second training samples into a plurality of sample groups, and writing the samples in each sample group into a plurality of modal data according to a preset format; Using a pre-trained feature extraction model to extract semantic features and structural features from each of the modal data; The semantic features and structural features in each modal data are fused across modal attention to obtain multiple distilled training samples.
6. The network security situation awareness method according to claim 5, characterized in that: The following formula is used to perform cross-modal attention fusion on the semantic features and structural features in each modality data: Among them, W q , W k is a learnable parameter, d is the feature dimension, is a semantic feature, is the structural feature, m is the mth mode, and M is the number of modes.
7. The network security situation awareness method according to any one of claims 1 to 6, characterized in that: The key features related to network security in the power dispatch optical transmission monitoring system are obtained, including: Obtaining network communication characteristics, equipment operation characteristics, and service application characteristics in the power dispatch optical transmission monitoring system, wherein the network communication characteristics include network traffic data, port connection data, and communication protocol data; the equipment operation characteristics include optical power data, equipment temperature data, and equipment alarm data; and the service application characteristics include service transmission data and user operation behavior; A second correlation value between each of the network communication feature, the device operation feature, and the service application feature and network security is calculated respectively, and a feature whose second correlation value is greater than a preset threshold is taken as a key feature.
8. A network security situation awareness device, characterized in that: include: An initial model acquisition module is configured to acquire key features related to network security in the power dispatch optical transmission monitoring system, construct an initial decision tree model based on the first training sample, the key features, and their corresponding feature attributes, and optimize the initial decision tree model to obtain an initial security perception model; a model training module, configured to obtain a second training sample, process the second training sample using a data distillation method to obtain a distilled training sample, and train the initial security perception model based on the distilled sample to obtain a trained security perception model; The safety perception module is used to obtain the operating data of the power dispatching optical transmission monitoring system under the current situation, input the operating data into the trained safety perception model, and obtain the safety status of the power dispatching optical transmission monitoring system under the current situation.
9. A storage medium storing at least one executable instruction, wherein the executable instruction enables a processor to perform operations corresponding to the network security situation awareness method according to any one of claims 1 to 7.
10. A computer device comprising: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the network security situation awareness method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Network security monitoring method and device based on situation awareness, equipment and medium
CN111786950A
Training sample acquisition method and device, computer equipment and storage medium
CN114332567A
Training method and device of automatic driving perception model, equipment and medium
CN115879535A
Perception model training method and device, electronic equipment and storage medium
CN116861262A
Network security situation awareness method based on deep neural network
CN119484065A