Network security information processing method and device and storage medium

Through the three-level architecture of "preliminary analysis-behavioral analysis-intelligent management and control" and the time decay model, the problems of correlation mining and dynamic adaptability in network security analysis in existing technologies are solved, the accurate capture and real-time response to network threats are achieved, and the systematicness and flexibility of network security are improved.

CN120710786AActive Publication Date: 2025-09-26YANGZHOU QINGYAN SOFTWARE TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202511060709.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-09-26
Estimated Expiration
2045-07-30

AI Technical Summary

Technical Problem

Existing network security analysis technologies have difficulty effectively exploring the correlation between potential threats and distinguishing between legitimate internal employee access and abnormal behavior. Traditional detection is unable to cope with multi-stage attacks. Massive network data leads to analysis delays, and rigid models are difficult to adapt to new threats, reducing the security of network information.

Method used

A three-level architecture of "preliminary analysis-behavioral analysis-intelligent control" is adopted. The data preliminary analysis module is used to build a control reference set, and the behavioral analysis module is combined to generate a behavioral reference set. Finally, the intelligent control module makes a comprehensive decision, introduces a time decay model and multi-indicator evaluation, and constructs a comprehensive behavioral anomaly index to achieve dynamic risk assessment and differentiated control.

Benefits of technology

It achieves accurate capture and real-time response to network threats, supports differentiated management and control of internal/external IPs, forms a closed-loop protection system, adapts to different attack scenarios, and improves the systematicness and flexibility of network security analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120710786A_ABST
    Figure CN120710786A_ABST
Patent Text Reader

Abstract

The invention discloses a network security information processing method and device and a storage medium, and relates to the field of network security information.The network security information processing device comprises a data preliminary analysis module, a behavior analysis module and an intelligent network management and control module, through a multi-dimensional data analysis and intelligent decision-making mechanism, the accuracy and management and control efficiency of network threat detection are remarkably improved, and the network security information processing efficiency is improved. According to the method, an internal and external network IP differentiation analysis system is constructed, a connection anomaly coefficient model is established by combining working time period characteristics, accurate identification of abnormal behaviors of internal personnel and unauthorized external access is realized, an abnormal behavior analysis model of a time decay mechanism is introduced, historical behavior characteristics are reserved, recent behavior weights are enhanced, and the accuracy of the abnormal behaviors is improved. The discovery capability of a novel attack mode is effectively improved, and multi-dimensional quantitative evaluation of security threats is realized through weighted fusion of a danger rating coefficient and a behavior anomaly index.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security information, and in particular to a method, device and storage medium for processing network security information. Background Art

[0002] Cybersecurity information is crucial for protecting core assets. In the digital age, sensitive information such as business secrets and customer data is stored online. Cyberattacks, such as data leaks, can not only lead to significant financial losses but also damage a company's reputation and even threaten its survival. Cybersecurity information can help companies promptly identify potential threats, such as hacker intrusion attempts and the spread of malware. This allows them to proactively take preventative measures, optimize security strategies, and strengthen their digital defenses.

[0003] Existing technologies, such as traditional network analysis, typically process connection logs and behavioral data in isolation, making it difficult to uncover correlations between potential threats (such as the linkage between abnormal logins and data leaks). It is also difficult to distinguish between legitimate internal employee access and abnormal behavior (such as data theft). Traditional rule-based detection struggles to cope with multi-stage attacks or compliance violations (such as access to unauthorized data types). Massive amounts of network data can easily lead to analysis delays, and rigid models make it difficult to adapt to new threats, reducing the security of network information. Summary of the Invention

[0004] The object of the present invention is to provide a method, device and storage medium for processing network security information to solve the problems raised in the above background technology.

[0005] To achieve the above object, the present invention provides the following technical solution: a device for network security information, comprising:

[0006] Data preliminary analysis module: used to obtain the historical connection data corresponding to the target network, and perform preliminary analysis on the historical connection data corresponding to the target network to obtain the control reference set corresponding to the target network;

[0007] Behavior analysis module: used to perform behavior analysis based on the historical connection data corresponding to the target network and obtain the behavior reference set corresponding to the target network;

[0008] Intelligent network control module: used to perform data analysis based on the control reference set and behavior reference set corresponding to the target network, and obtain the network control results corresponding to the target network.

[0009] In the preferred embodiment of this solution, the specific implementation method of the data preliminary analysis module is as follows:

[0010] Establish a data extraction relationship between the data preliminary analysis module and the database to extract historical connection data stored in the database. The historical connection data refers to the network behavior corresponding to each connected network connection IP, each disconnected network connection IP, and each connected network connection IP at each historical time point;

[0011] Extract each internal IP and the corresponding working time period stored in the database;

[0012] According to each internal IP, the connection IP of each connected network, the connection IP of each disconnected network, and the connection IP of each connected network corresponding to each historical time point are divided, and the internal IP and external IP corresponding to the connected network at each historical time point are obtained, and the internal IP and external IP corresponding to the disconnected network at each historical time point are obtained. Each connection IP that does not belong to the internal IP is recorded as an external IP;

[0013] Obtain a preset reference time period and a corresponding reference duration for the target network, divide the historical connection data according to the preset reference time period and the corresponding reference duration for the target network, obtain each historical reference time period corresponding to the target network, perform statistics based on each internal IP and each external IP that accessed and disconnected the network at each historical time point in each historical reference time period, obtain each connection time period, the duration of each connection time period, the connection frequency, and the number of connections corresponding to each internal IP and each external IP in each historical reference time period, perform data calculation based on each connection time period, the duration of each connection time period, the connection frequency, and the number of connections corresponding to each internal IP and each external IP, and obtain the average connection duration of the connection time period corresponding to each internal IP and each external IP, and the total connection duration of the connection time period;

[0014] Reverse screening is performed on each internal IP and each external IP in each historical reference time period to obtain each historical reference time period corresponding to each internal IP and each external IP, the average connection duration of the connection time period corresponding to each historical reference time period, the total connection duration of the connection time period, the connection frequency and the number of connections. A preliminary analysis model is established based on each historical reference time period corresponding to each internal IP and each external IP, the average connection duration of the connection time period corresponding to each historical reference time period, the total connection duration of the connection time period, the connection frequency and the number of connections. Analysis is performed through the preliminary analysis model to obtain the control reference set corresponding to the target network.

[0015] In the preferred embodiment of this solution, the specific implementation of the data behavior analysis module is as follows:

[0016] Obtain the network behavior corresponding to each internal IP and each external IP at each historical time point, filter and obtain the network behavior set corresponding to each internal IP and each external IP for each historical reference time period, perform data extraction on the network behavior set, and obtain the corresponding data download behavior and data access behavior in the network behavior set. The data download behavior refers to the data download frequency and the total amount of data transmission, and the data access behavior refers to the various data access types and the number of data access categories.

[0017] An abnormal behavior analysis model is established based on the network behavior set of each internal IP and each external IP corresponding to each historical reference time period. Data analysis is performed through the abnormal behavior analysis model to obtain the comprehensive behavior anomaly index corresponding to each internal IP and each external IP. The comprehensive behavior anomaly index corresponding to each internal IP and each external IP is recorded as the behavior reference set corresponding to the target network.

[0018] In the preferred embodiment of this solution, the specific implementation of the intelligent network control module is as follows:

[0019] Establish a data extraction relationship between the intelligent network control module and the database, extract the standard risk rating coefficients and standard comprehensive behavior anomaly indexes corresponding to internal IPs and external IPs stored in the database, extract the influence weights of the risk rating coefficients and comprehensive behavior anomaly indexes stored in the database on the IP warning index, establish an IP control model based on the comprehensive behavior anomaly indexes and risk rating coefficients corresponding to each internal IP and each external IP, analyze based on the IP control model, and obtain the network control results corresponding to the target network.

[0020] To achieve the above object, the present invention further provides the following technical solution: a method for processing network security information, comprising the following steps:

[0021] Obtain the historical connection data corresponding to the target network, perform preliminary analysis on the historical connection data corresponding to the target network, and obtain the control reference set corresponding to the target network;

[0022] Perform behavioral analysis based on the historical connection data corresponding to the target network to obtain a behavioral reference set corresponding to the target network;

[0023] Data analysis is performed based on the control reference set corresponding to the target network and the behavior reference set corresponding to the target network, and the network control results corresponding to the target network are obtained.

[0024] To achieve the above-mentioned purpose, the present invention also provides the following technical solution: a storage medium for network security information, on which network security information readable instructions are stored, and when the network security information readable instructions are executed by a processor, a device for implementing a network security information described in any one of the embodiments of the present invention.

[0025] Compared with the prior art, the present invention has the following beneficial effects:

[0026] This invention adopts a three-tiered architecture: preliminary analysis, behavioral analysis, and intelligent management and control. The preliminary data analysis module constructs a control reference set, which is then combined with the behavioral analysis module to generate a behavioral reference set. Ultimately, the intelligent management and control module makes comprehensive decisions. This layered design organically combines basic data statistics, behavioral feature extraction, and dynamic risk assessment, ensuring systematic data processing while avoiding the limitations of single-dimensional analysis.

[0027] This invention introduces a time decay model to dynamically weight historical behaviors, making anomaly detection closer to real-time status. It also combines multiple indicators such as data download volume and access type compliance to construct a comprehensive behavior anomaly index, which can accurately capture complex attacks such as data leakage and malicious access.

[0028] The intelligent control module integrates the dual characteristics of connection anomalies and behavioral anomalies through the IP warning index, and uses standardized coefficient comparison (e.g., (actual value - standard value) / standard value) to achieve quantitative assessment. This design not only supports differentiated control of internal and external IP addresses (e.g., internal anomalies trigger warnings, external anomalies are directly blocked), but also adapts to different attack scenarios through dynamic weight allocation, forming a closed-loop protection system of "prevention-identification-action".

[0029] By establishing a preliminary analysis model, an abnormal behavior analysis model, and an IP control model, the system transforms expert experience into configurable weighting parameters (such as the impact weight of the anomaly coefficient and the time decay coefficient). This ensures the rigor of the analysis logic and provides an interface for subsequent algorithm optimization. For example, by adjusting the standard value for work hours or the anomaly weight, the system can quickly adapt to the network environments of different industries and enterprises. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] The present invention is further described with reference to the accompanying drawings. However, the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other drawings based on the following drawings without creative effort.

[0031] Figure 1 This is a schematic diagram of module connections according to an embodiment of the present invention.

[0032] Figure 2 This is a schematic diagram of the connection steps of an embodiment of the present invention. DETAILED DESCRIPTION

[0033] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0034] See also Figure 1 ,The present invention provides a device for network security information, which includes a data preliminary analysis module, a behavior analysis module and an intelligent network management and control module;

[0035] The data preliminary analysis module is connected to the behavior analysis module, and the behavior analysis module is connected to the intelligent network control module;

[0036] The data preliminary analysis module is used to obtain the historical connection data corresponding to the target network, and perform preliminary analysis on the historical connection data corresponding to the target network to obtain the control reference set corresponding to the target network;

[0037] Furthermore, the specific execution method of the data preliminary analysis module is as follows:

[0038] Establish a data extraction relationship between the data preliminary analysis module and the database to extract historical connection data stored in the database. The historical connection data refers to the network behavior corresponding to each connected network connection IP, each disconnected network connection IP, and each connected network connection IP at each historical time point;

[0039] Extract each internal IP and the corresponding working time period stored in the database;

[0040] According to each internal IP, the connection IP of each connected network, the connection IP of each disconnected network, and the connection IP of each connected network corresponding to each historical time point are divided, and the internal IP and external IP corresponding to the connected network at each historical time point are obtained, and the internal IP and external IP corresponding to the disconnected network at each historical time point are obtained. Each connection IP that does not belong to the internal IP is recorded as an external IP;

[0041] Obtain a preset reference time period and a corresponding reference duration for the target network, divide the historical connection data according to the preset reference time period and the corresponding reference duration for the target network, obtain each historical reference time period corresponding to the target network, perform statistics based on each internal IP and each external IP that accessed and disconnected the network at each historical time point in each historical reference time period, obtain each connection time period, the duration of each connection time period, the connection frequency, and the number of connections corresponding to each internal IP and each external IP in each historical reference time period, perform data calculation based on each connection time period, the duration of each connection time period, the connection frequency, and the number of connections corresponding to each internal IP and each external IP, and obtain the average connection duration of the connection time period corresponding to each internal IP and each external IP, and the total connection duration of the connection time period;

[0042] Reverse screening is performed on each internal IP and each external IP in each historical reference time period to obtain each historical reference time period corresponding to each internal IP and each external IP, the average connection duration of the connection time period corresponding to each historical reference time period, the total connection duration of the connection time period, the connection frequency and the number of connections. A preliminary analysis model is established based on each historical reference time period corresponding to each internal IP and each external IP, the average connection duration of the connection time period corresponding to each historical reference time period, the total connection duration of the connection time period, the connection frequency and the number of connections. Analysis is performed through the preliminary analysis model to obtain the control reference set corresponding to the target network.

[0043] It should be noted that: Through the preliminary analysis model, the specific analysis method for obtaining the control reference set corresponding to the target network is as follows:

[0044] Obtain the initial connection time point and the termination connection time point corresponding to each historical reference time period;

[0045] Match the initial connection time point and the termination connection time point corresponding to each historical reference time period with the working time period corresponding to each internal IP, and obtain each working matching historical reference time period and each non-working matching historical reference time period corresponding to each internal IP;

[0046] Take a single internal IP corresponding to a single job matching historical reference time period as an example;

[0047] Filter and obtain the work matching history corresponding to the internal IP, and refer to the total connection duration, connection frequency, and number of connections in the corresponding connection time period;

[0048] Extract the standard total connection duration, standard connection frequency, and standard number of connections of the internal IP in the connection time period corresponding to the working time period stored in the preliminary analysis model;

[0049] Extract the influence weights of the total connection duration, connection frequency, and number of connections of the internal IP preset in the preliminary analysis model on the connection anomaly coefficient during the connection time period corresponding to the working time period and mark them as a, b, and c respectively;

[0050] By calculating the formula , calculate the connection anomaly coefficient corresponding to the historical reference time period of the internal IP corresponding to the work matching , where A, B, and C represent the total connection duration, connection frequency, and number of connections in the connection time period, respectively; A1, B1, and C1 represent the standard total connection duration, standard connection frequency, and standard number of connections in the connection time period corresponding to the working time period, respectively;

[0051] Take a single internal IP address corresponding to a single non-working matching history reference time period as an example;

[0052] Extract the influence weights of the total connection duration, connection frequency, and number of connections of the internal IP preset in the preliminary analysis model on the connection anomaly coefficient during the non-working time period and mark them as a2, b2, and c2 respectively;

[0053] By calculating the formula , calculate the connection anomaly coefficient corresponding to the non-working matching historical reference time period of the internal IP , A2, B2, and C2 represent the standard total connection duration, standard connection frequency, and standard number of connections of the connection time period corresponding to the non-working time period, respectively;

[0054] Obtain statistics on the connection anomaly coefficients for each working matching historical reference time period and each non-working matching historical reference time period corresponding to each internal IP;

[0055] The connection anomaly coefficient curves of each working matching historical reference time period and each non-working matching historical reference time period are plotted by corresponding initial connection time points and termination connection time points of each historical reference time period, and the connection anomaly coefficient curves of the working period and non-working period corresponding to each internal IP are obtained. The connection anomaly coefficient curves of the working period and non-working period corresponding to each internal IP are extracted data, and the peak number and peak average value of the connection anomaly coefficient curves of the working period and non-working period corresponding to each internal IP are obtained;

[0056] The peak average value refers to the average value of each peak value;

[0057] Extract the influence weights of the peak number and peak average value preset in the preliminary analysis model on the preliminary rating coefficient, and extract the influence weights of the risk rating coefficient corresponding to the working period and non-working period;

[0058] Extract the standard peak number and standard peak average corresponding to the internal IP preset in the preliminary analysis model;

[0059] Take a single internal IP as an example;

[0060] The preliminary rating coefficient corresponding to working hours and non-working hours = (peak number ÷ standard peak number) × the influence weight of the peak number on the preliminary rating coefficient + (peak average value ÷ standard peak average value) × the influence weight of the peak average value on the preliminary rating coefficient;

[0061] Risk rating coefficient = preliminary rating coefficient of working hours × impact weight of risk rating coefficient corresponding to working hours + preliminary rating coefficient corresponding to non-working hours × impact weight of risk rating coefficient corresponding to non-working hours;

[0062] Filter and obtain the risk rating coefficient corresponding to each internal IP;

[0063] Take a single external IP address corresponding to a single historical reference time period as an example;

[0064] Extract the standard total connection duration, standard connection frequency, and standard number of connections for the connection time period corresponding to the external IP address preset in the preliminary analysis model, and mark them as A3, B3, and C3 respectively;

[0065] Extract the influence weights of the standard total connection duration, standard connection frequency, and standard number of connections on the connection anomaly coefficient for the connection time period corresponding to the external IP preset in the preliminary analysis model and mark them as a3, b3, and c3 respectively;

[0066] By calculating the formula , calculate the connection anomaly coefficient corresponding to the historical reference time period of the external IP ;

[0067] Filter and obtain the connection anomaly coefficient corresponding to each external IP and each historical reference time period;

[0068] Connect the connection anomaly coefficients of each external IP corresponding to each historical reference time period by the initial connection time point and the termination connection time point corresponding to each historical reference time period, obtain the connection anomaly coefficient curve corresponding to each external IP, and obtain the peak number, peak average value and peak frequency in the connection anomaly coefficient curve;

[0069] Extract the influence weights of the peak number, peak average and peak frequency preset in the preliminary analysis model on the risk rating coefficient;

[0070] Extract the standard peak number, standard peak average and standard peak frequency corresponding to the external IP preset in the preliminary analysis model;

[0071] Take a single external IP as an example;

[0072] Risk rating coefficient = (peak number ÷ standard peak number) × the influence weight of the peak number on the risk rating coefficient + (peak average value ÷ standard peak average value) × the influence weight of the peak average value on the risk rating coefficient + (peak frequency ÷ standard peak frequency) × the influence weight of the peak frequency on the risk rating coefficient;

[0073] Filter and obtain the risk rating coefficient corresponding to each external IP, and record the risk rating coefficient corresponding to each external IP and the risk rating coefficient corresponding to each internal IP as the control reference set corresponding to the target network;

[0074] The behavior analysis module is used to perform behavior analysis based on the historical connection data corresponding to the target network to obtain a behavior reference set corresponding to the target network;

[0075] Furthermore, the specific execution method of the data behavior analysis module is as follows:

[0076] Obtain the network behavior corresponding to each internal IP and each external IP at each historical time point, filter and obtain the network behavior set corresponding to each internal IP and each external IP for each historical reference time period, perform data extraction on the network behavior set, and obtain the corresponding data download behavior and data access behavior in the network behavior set. The data download behavior refers to the data download frequency and the total amount of data transmission, and the data access behavior refers to the various data access types and the number of data access categories.

[0077] An abnormal behavior analysis model is established based on the network behavior set of each internal IP and each external IP corresponding to each historical reference time period. Data analysis is performed through the abnormal behavior analysis model to obtain the comprehensive behavior anomaly index corresponding to each internal IP and each external IP. The comprehensive behavior anomaly index corresponding to each internal IP and each external IP is recorded as the behavior reference set corresponding to the target network.

[0078] It should be noted that the specific analysis method for analyzing data through the abnormal behavior analysis model to obtain the behavioral anomaly index corresponding to each internal IP and each external IP is as follows:

[0079] Extract the standard data download frequency and standard data transmission volume corresponding to the internal IP and external IP stored in the abnormal behavior analysis model;

[0080] Take a single internal IP or a single external IP corresponding to a single historical reference time period as an example;

[0081] Internal IP or external IP data download anomaly index = (internal IP or external IP data download frequency ÷ standard data download frequency corresponding to the internal IP or external IP) + (total data transmission volume of the internal IP or external IP ÷ standard data transmission volume corresponding to the internal IP or external IP);

[0082] Obtain statistical data download anomaly index for each internal IP and each external IP corresponding to each historical reference time period;

[0083] Extract the allowed data access types corresponding to the internal IP and the allowed data access types corresponding to the external IP preset by the abnormal behavior analysis model;

[0084] Compare and match the allowed data access types corresponding to the internal IP and the allowed data access types corresponding to the external IP with the data access types corresponding to each historical reference time period for each internal IP and each external IP, obtain the types of the prohibited access data corresponding to each historical reference time period for each internal IP and each external IP, and obtain the types of the prohibited access data types;

[0085] Abnormal data access coefficient = type of data that is not allowed to be accessed / number of data access types;

[0086] Filter and obtain the abnormal data access coefficients of each internal IP and each external IP corresponding to each historical reference time period;

[0087] Extract the influence weight of the abnormal data access coefficient and data download abnormality index preset in the abnormal behavior analysis model on the behavior abnormality index;

[0088] Behavior anomaly index = abnormal data access coefficient × the influence weight of abnormal data access coefficient on behavior anomaly index + data download anomaly index × the influence weight of data download anomaly index on behavior anomaly index;

[0089] Obtain statistically the behavioral anomaly index of each internal IP and each external IP corresponding to each historical reference time period;

[0090] Introducing a time decay model, where the time decay model refers to an impact weight distribution set corresponding to different time interval combinations, and the impact weight distribution set refers to the data impact weights corresponding to different time intervals, where the sum of the data impact weights is 1;

[0091] Based on the initial connection time point and the termination connection time point corresponding to each historical reference time period, the time interval of each internal IP and each external IP corresponding to each historical reference time period is obtained. Based on the time interval of each internal IP and each external IP corresponding to each historical reference time period, the data influence weight of each internal IP and each external IP corresponding to each historical reference time period is obtained.

[0092] The comprehensive behavior anomaly index corresponding to each internal IP and each external IP = the sum of the data impact weight of each internal IP and each external IP corresponding to each historical reference time period and the product of the behavior anomaly index of each internal IP and each external IP corresponding to each historical reference time period.

[0093] The intelligent network control module is used to perform data analysis based on the control reference set corresponding to the target network and the behavior reference set corresponding to the target network, and obtain the network control results corresponding to the target network.

[0094] Furthermore, the specific implementation of the intelligent network control module is as follows:

[0095] Establish a data extraction relationship between the intelligent network control module and the database, extract the standard risk rating coefficients and standard comprehensive behavior anomaly indexes corresponding to internal IPs and external IPs stored in the database, extract the influence weights of the risk rating coefficients and comprehensive behavior anomaly indexes stored in the database on the IP warning index, establish an IP control model based on the comprehensive behavior anomaly indexes and risk rating coefficients corresponding to each internal IP and each external IP, analyze based on the IP control model, and obtain the network control results corresponding to the target network.

[0096] It should be noted that the specific analysis process for obtaining the network control results corresponding to the target network based on the IP control model is as follows:

[0097] IP warning index = (risk rating coefficient - standard risk rating coefficient) ÷ standard risk rating coefficient × the influence weight of the risk rating coefficient on the IP warning index + (comprehensive behavior abnormality index - standard comprehensive behavior abnormality index) ÷ standard comprehensive behavior abnormality index × the influence weight of the comprehensive behavior abnormality index on the IP warning index;

[0098] Filter and obtain the IP warning index corresponding to each internal IP and each external IP;

[0099] The IP warning index corresponding to each internal IP and each external IP is compared with the preset IP warning index threshold. If the IP warning index is less than the IP warning index threshold, it means that the normal access of the IP has no security threat. If the IP warning index is greater than or equal to the IP warning index threshold, it means that the abnormal access of the IP has a security threat. Statistically obtain each IP without security threat and each IP with security threat in the internal IP corresponding to the target network, obtain each IP without security threat and each IP with security threat in the external IP corresponding to the target network, issue a security reminder for each IP with security threat in the internal IP corresponding to the target network, and deny connection control for each IP with security threat in the external IP corresponding to the target network. Issue a security reminder for each IP with security threat in the internal IP corresponding to the target network, and deny connection control for each IP with security threat in the external IP corresponding to the target network as the network management and control result corresponding to the target network.

[0100] See also Figure 2 To achieve the above purpose, the present invention also provides the following technical solution: a method for processing network security information, comprising the following steps:

[0101] Obtain the historical connection data corresponding to the target network, perform preliminary analysis on the historical connection data corresponding to the target network, and obtain the control reference set corresponding to the target network;

[0102] Perform behavioral analysis based on the historical connection data corresponding to the target network to obtain a behavioral reference set corresponding to the target network;

[0103] Data analysis is performed based on the control reference set corresponding to the target network and the behavior reference set corresponding to the target network, and the network control results corresponding to the target network are obtained.

[0104] To achieve the above-mentioned purpose, the present invention also provides the following technical solution: a storage medium for network security information, on which network security information readable instructions are stored, and when the network security information readable instructions are executed by a processor, a device for implementing a network security information described in any one of the embodiments of the present invention.

[0105] The above are all preferred embodiments of the present application, and are not intended to limit the scope of protection of the present application. Therefore, any equivalent changes made based on the structure, shape, and principle of the present application should be included in the scope of protection of the present application.

Claims

1. A device for network information security, characterized by: include: Data preliminary analysis module: used to obtain the historical connection data corresponding to the target network, and perform preliminary analysis on the historical connection data corresponding to the target network to obtain the control reference set corresponding to the target network; Behavior analysis module: used to perform behavior analysis based on the historical connection data corresponding to the target network and obtain the behavior reference set corresponding to the target network; Intelligent network control module: used to perform data analysis based on the control reference set and behavior reference set corresponding to the target network, and obtain the network control results corresponding to the target network.

2. The network information security device according to claim 1, characterized in that: The specific execution method of the data preliminary analysis module is as follows: Establish a data extraction relationship between the data preliminary analysis module and the database to extract historical connection data stored in the database. The historical connection data refers to the network behavior corresponding to each connected network connection IP, each disconnected network connection IP, and each connected network connection IP at each historical time point; Extract each internal IP and the corresponding working time period stored in the database; According to each internal IP, the connection IP of each connected network, the connection IP of each disconnected network, and the connection IP of each connected network corresponding to each historical time point are divided, and the internal IP and external IP corresponding to the connected network at each historical time point are obtained, and the internal IP and external IP corresponding to the disconnected network at each historical time point are obtained. Each connection IP that does not belong to the internal IP is recorded as an external IP; Obtain a preset reference time period and a corresponding reference duration for the target network, divide the historical connection data according to the preset reference time period and the corresponding reference duration for the target network, obtain each historical reference time period corresponding to the target network, perform statistics based on each internal IP and each external IP that accessed and disconnected the network at each historical time point in each historical reference time period, obtain each connection time period, the duration of each connection time period, the connection frequency, and the number of connections corresponding to each internal IP and each external IP in each historical reference time period, perform data calculation based on each connection time period, the duration of each connection time period, the connection frequency, and the number of connections corresponding to each internal IP and each external IP, and obtain the average connection duration of the connection time period corresponding to each internal IP and each external IP, and the total connection duration of the connection time period; Reverse screening is performed on each internal IP and each external IP in each historical reference time period to obtain each historical reference time period corresponding to each internal IP and each external IP, the average connection duration of the connection time period corresponding to each historical reference time period, the total connection duration of the connection time period, the connection frequency and the number of connections. A preliminary analysis model is established based on each historical reference time period corresponding to each internal IP and each external IP, the average connection duration of the connection time period corresponding to each historical reference time period, the total connection duration of the connection time period, the connection frequency and the number of connections. Analysis is performed through the preliminary analysis model to obtain the control reference set corresponding to the target network.

3. The network information security device according to claim 1, characterized in that: The specific execution method of the data behavior analysis module is as follows: Obtain the network behavior corresponding to each internal IP and each external IP at each historical time point, filter and obtain the network behavior set corresponding to each internal IP and each external IP for each historical reference time period, perform data extraction on the network behavior set, and obtain the corresponding data download behavior and data access behavior in the network behavior set. The data download behavior refers to the data download frequency and the total amount of data transmission, and the data access behavior refers to the various data access types and the number of data access categories. An abnormal behavior analysis model is established based on the network behavior set of each internal IP and each external IP corresponding to each historical reference time period. Data analysis is performed through the abnormal behavior analysis model to obtain the comprehensive behavior anomaly index corresponding to each internal IP and each external IP. The comprehensive behavior anomaly index corresponding to each internal IP and each external IP is recorded as the behavior reference set corresponding to the target network.

4. A network information security device according to claim 3, characterized in that: The specific implementation of the intelligent network control module is as follows: Establish a data extraction relationship between the intelligent network control module and the database, extract the standard risk rating coefficients and standard comprehensive behavior anomaly indexes corresponding to internal IPs and external IPs stored in the database, extract the influence weights of the risk rating coefficients and comprehensive behavior anomaly indexes stored in the database on the IP warning index, establish an IP control model based on the comprehensive behavior anomaly indexes and risk rating coefficients corresponding to each internal IP and each external IP, analyze based on the IP control model, and obtain the network control results corresponding to the target network.

5. A method for processing network security information, applied to a network security information device according to any one of claims 1 to 4, characterized in that: include: Obtain the historical connection data corresponding to the target network, perform preliminary analysis on the historical connection data corresponding to the target network, and obtain the control reference set corresponding to the target network; Perform behavioral analysis based on the historical connection data corresponding to the target network to obtain a behavioral reference set corresponding to the target network; Data analysis is performed based on the control reference set corresponding to the target network and the behavior reference set corresponding to the target network, and the network control results corresponding to the target network are obtained.

6. A storage medium for network security information, characterized in that: The network security information storage medium stores network security information readable instructions, which, when executed by a processor, implement a network security information device according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Abnormal network connection detection method based on deep learning

    CN108809948A

  • Computer information security monitoring method and system and storage medium

    CN116488939A

  • Network perception anomaly detection system and method based on big data

    CN117395076A

  • Network security detection system based on data visualization

    CN117997586A

  • Network security analysis system based on big data

    CN118041673A