Network security situation prediction method based on big data

By adjusting the security prediction cycle and method according to the ratio of structured and unstructured data in network communication data, the problem of poor security situation awareness in existing technologies is solved, and more efficient and accurate security prediction is achieved.

CN120729655AActive Publication Date: 2025-09-30BEIJING JINGNENG GAOANTUN GAS THERMAL POWER CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511248656.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-03
Publication Date
2025-09-30
Estimated Expiration
2045-09-03

AI Technical Summary

Technical Problem

The single data processing method in the existing technology cannot effectively meet the dynamic data transmission process, resulting in poor security situation awareness.

Method used

Determine the data structure status based on the ratio of structured data to unstructured data in the target network communication data, set a benchmark or dynamic security prediction cycle, and determine the security prediction method through sensitive characterization values ​​and sensitive fluctuation values, detect user behavior and data association risks, and adjust the data transmission path to improve security prediction efficiency.

Benefits of technology

It realizes the dynamic adjustment of the security prediction cycle, improves the efficiency and accuracy of security situation awareness, adapts to security analysis strategies with different data characteristics, and improves the real-time and accuracy of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729655A_ABST
    Figure CN120729655A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network security, in particular to a big data-based network security situation prediction method, which comprises the following steps of: determining a data structure state according to a data proportion of structured data and unstructured data of target network communication data; determining a safety prediction period according to the data structure state, and setting the safety prediction period as a reference safety prediction period or a dynamic safety prediction period; determining a data sensitive state according to the sensitive representation value and the sensitive fluctuation value of the target network communication data, and determining a security prediction mode according to the data sensitive state; the problem that in the prior art, a single security analysis mode is difficult to meet a dynamic data transmission scene, and consequently the security situation perception prediction effect is poor is solved, and the security situation prediction efficiency and accuracy are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a network security situation prediction method based on big data. Background Art

[0002] With the development of information technology, the application of computer networks has become more and more popular. As a result, network security issues have gradually become a concern of people. Network security technology is the core technology to ensure user information security and stable network operation. Especially for the network data transmission process, as one of the most common network technologies, it is also a very critical technical link in network security. Therefore, how to effectively perceive, predict and even warn of network information transmission security is an issue that technicians in this field attach great importance to.

[0003] Chinese Patent Publication No. CN110650155A discloses a method for quickly transmitting security risk information in a network security situation awareness platform. After pre-processing, optimizing, and setting transmission rules for all currently untransmitted network security risk information, batch processing and transmission are carried out to improve the efficiency of security risk information transmission and achieve a near-real-time information transmission effect. The network security risk information of the present invention is filtered by matching the supervision object and the security risk type of notification and warning. The same type of security risk information is aggregated and simplified. The information transmission method of the whole into parts is transmitted in a time-sharing manner. This can not only improve the efficiency of information transmission, so that each time the user opens the notification and warning module page of the platform, they will see data before T time. It can also improve the user experience and notification and warning efficiency, so that the user can always see the security risk information immediately when opening the notification and warning module. The network security risk information transmission efficiency is high, which can further improve the network security index. It can be seen that the above technical solution has the following problems: a single data processing method cannot effectively meet the dynamic data transmission process, and cannot select different security analysis strategies according to the characteristics of the actual transmitted data, resulting in poor security situation awareness effect. Summary of the Invention

[0004] To this end, the present invention provides a network security situation prediction method based on big data to overcome the problem that a single security analysis method in the prior art is difficult to meet the dynamic data transmission scenarios, resulting in poor security situation perception and prediction effects.

[0005] To achieve the above objectives, the present invention provides a network security situation prediction method based on big data, comprising: Determine the data structure status based on the ratio of structured data to unstructured data in the target network communication data; Determine, based on the data structure state, whether the security prediction period is set as a baseline security prediction period or a dynamic security prediction period; Determine the data sensitivity status based on the sensitive characterization value and sensitive fluctuation value of the target network communication data and determine the security prediction method based on the data sensitivity status; When the security prediction method is user operation behavior prediction analysis, the frequency and concentration of information extraction of each operating user are detected to determine the information extraction status and determine whether the operating user has dangerous behavior based on the information extraction status; When the security prediction method is data-related risk prediction analysis, the frequency of data transmission path changes is adjusted or sensitive data risk warnings are sent to users based on the comparison results of the data dependencies corresponding to several security prediction cycles and the preset data dependencies.

[0006] Furthermore, the data structure status of the target network communication data is periodically detected, and a security prediction period is determined based on the data structure status; If the data structure state is the first data structure state, the security prediction period is set to the baseline security prediction period; If the data structure state is the second data structure state, the security prediction period is set to the dynamic security prediction period.

[0007] Furthermore, the data structure state is determined based on the data ratio of structured data to unstructured data in the target network communication data. The data structure state includes: If the data proportion is greater than the preset data proportion, the data structure state is the first data structure state; If the data proportion is less than or equal to the preset data proportion, the data structure state is the second data structure state.

[0008] Furthermore, under the period adjustment condition, the duration of the dynamic security prediction period is determined based on the difference in unstructured data; The duration of the dynamic security prediction cycle is negatively correlated with the difference in unstructured data; The period adjustment condition is to determine that the data structure state is the second data structure state, and the duration of the dynamic security prediction period is less than the duration of the baseline security prediction period.

[0009] Furthermore, under pre-analysis conditions, a security prediction method is determined based on the data sensitivity status; If the data sensitivity status is the first data sensitivity status, the security prediction method is user operation behavior prediction analysis; If the data sensitivity state is the second data sensitivity state, the security prediction method is data association risk prediction analysis; The pre-analysis condition is the end of a single safety prediction cycle.

[0010] Furthermore, the data sensitivity status is determined based on the sensitivity characterization value and sensitivity fluctuation value of the target network communication data. The data sensitivity status includes: A first data sensitive state in which the sensitivity characterization value is less than a preset sensitivity characterization value and the sensitivity fluctuation value is less than a preset sensitivity fluctuation value; A second data sensitive state in which the sensitivity characterization value is greater than or equal to a preset sensitivity characterization value or the sensitivity fluctuation value is greater than or equal to a preset sensitivity fluctuation value.

[0011] Furthermore, under the first analysis condition, the information extraction frequency and information extraction concentration of each operating user are detected to determine the information extraction state, and whether the operating user has engaged in dangerous behavior is determined based on the information extraction state; If the information extraction status is that the information extraction frequency is greater than the preset information extraction frequency or the information extraction concentration is greater than the preset information extraction concentration, then the operating user has engaged in dangerous behavior; If the information extraction status is that the information extraction frequency is less than or equal to the preset information extraction frequency and the information extraction concentration is less than or equal to the preset information extraction concentration, then the operating user does not have any dangerous behavior; The first analysis condition is that the data sensitivity state is the first data sensitivity state.

[0012] Furthermore, under the second analysis condition, the data dependencies corresponding to several security prediction cycles closest to the current moment are detected; If the data dependency is greater than the preset data dependency, it is determined that there is a data association risk, and the frequency of data transmission path changes is adjusted; If the data dependency is less than or equal to the preset data dependency, it is determined that there is no data association risk and a sensitive data risk warning is sent to the user; The second analysis condition is that the data sensitivity state is the second data sensitivity state.

[0013] Furthermore, the frequency of data transmission path changes is adjusted, including: Detecting the difference between the data dependency and the dependency corresponding to the preset data dependency; Increase and adjust the frequency of data transmission path changes based on the dependency difference; The increase in the frequency of data transmission path changes is positively correlated with the difference in dependence.

[0014] Compared with the prior art, the beneficial effect of the present invention lies in that the technical solution of the present invention determines the data structure state according to the data proportion ratio of structured data and unstructured data of the target network communication data, thereby reflecting the complexity of the target network communication data, and correspondingly selects different security prediction cycles, so that the setting of the security prediction cycle is more in line with the actual application scenario, thereby making subsequent analysis more timely, avoiding the problem of poor data analysis effect caused by a single periodic monitoring method, and thereby improving the security situation awareness prediction efficiency of the present invention.

[0015] Furthermore, in the technical solution of the present invention, the duration of the dynamic security prediction period is determined based on the difference in unstructured data, so that the duration of the dynamic security prediction period is set according to the actual scenario, rather than a fixed single value, thereby improving the setting accuracy of the duration of the dynamic security prediction period.

[0016] Furthermore, in the technical solution of the present invention, the data sensitivity status is determined based on the sensitive characterization value and sensitive fluctuation value of the target network communication data. The data sensitivity status effectively reflects the sensitivity of the content of the target network communication data, and adaptively selects different security prediction methods, so that the security prediction method is dynamic and targeted, which further improves the prediction efficiency and accuracy of the security situation of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 Schematic diagram of the network security situation prediction method based on big data of the present invention; Figure 2 This is a flow chart of the present invention for determining a security prediction period according to a data structure state; Figure 3 This is a flow chart of the present invention for determining a security prediction method based on data sensitivity status. DETAILED DESCRIPTION

[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0019] See also Figures 1 to 3 As shown, the present invention provides a network security situation prediction method based on big data, comprising: Determine the data structure status based on the ratio of structured data to unstructured data in the target network communication data; Determine, based on the data structure state, whether the security prediction period is set as a baseline security prediction period or a dynamic security prediction period; Determine the data sensitivity status based on the sensitive characterization value and sensitive fluctuation value of the target network communication data and determine the security prediction method based on the data sensitivity status; When the security prediction method is user operation behavior prediction analysis, the frequency and concentration of information extraction of each operating user are detected to determine the information extraction status and determine whether the operating user has dangerous behavior based on the information extraction status; When the security prediction method is data-related risk prediction analysis, the frequency of data transmission path changes is adjusted or sensitive data risk warnings are sent to users based on the comparison results of the data dependencies corresponding to several security prediction cycles and the preset data dependencies.

[0020] The present invention is applied to network security situation prediction and warning during data transmission in a communication network. The present invention is applied to a target platform, which is provided with a database. The operating user sends a data request to the target platform. The target platform sends the data request to the corresponding database and transmits the data corresponding to the data request to the user. The manager is a technician who performs security management on the target platform. The present invention should have several historical records, and a single historical record at least records the data proportion, sensitive characterization value, sensitive fluctuation value, information extraction frequency, information extraction concentration and data dependence, and the historical record is provided with a qualified mark. The qualified mark indicates whether the historical record meets the needs of the manager. It can be understood that setting up a safe operation indicator to determine whether the platform meets the operational safety needs of the manager within a period of time is content that has been mastered by those skilled in the art and will not be elaborated here.

[0021] The present invention uses detection values, including data proportion, sensitive characterization value, sensitive fluctuation value, information extraction frequency, information extraction concentration and data dependence, and each detection value is correspondingly set with a preset threshold, including a preset data proportion, a preset sensitive characterization value, a preset sensitive fluctuation value, a preset information extraction frequency, a preset information extraction concentration and a preset data dependence. For any preset threshold, the value-taking method is to detect the detection value of the historical record that meets the operator's needs corresponding to the preset threshold, remove the outliers from the detection value, and calculate the average value of the detection value after removing the outliers, which is recorded as the value of the preset threshold. Among them, the method of removing outliers includes but is not limited to the 3σ criterion method or the IQR method.

[0022] Specifically, the data structure status of the target network communication data is periodically detected, and a security prediction period is determined according to the data structure status; If the data structure state is the first data structure state, the security prediction period is set to the baseline security prediction period; If the data structure state is the second data structure state, the security prediction period is set to the dynamic security prediction period.

[0023] The target network communication data is the data transmitted in the most recent security prediction cycle.

[0024] Specifically, the data structure status is determined based on the ratio of structured data to unstructured data in the target network communication data. The data structure status includes: If the data proportion is greater than the preset data proportion, the data structure state is the first data structure state; If the data proportion is less than or equal to the preset data proportion, the data structure state is the second data structure state.

[0025] Structured data refers to data presented in a tabular format, and unstructured data refers to data in a non-tabular format. The preset data ratio = the amount of structured data / the amount of unstructured data. The unit of data volume is bits. The baseline security prediction cycle is a cycle duration set by the administrator. The administrator can set the baseline security prediction cycle according to actual needs. The greater the administrator's demand for timeliness of data analysis, the shorter the baseline security prediction cycle.

[0026] Specifically, under the period adjustment condition, the duration of the dynamic security prediction cycle is determined based on the difference in unstructured data; The duration of the dynamic security prediction cycle is negatively correlated with the difference in unstructured data; The period adjustment condition is to determine that the data structure state is the second data structure state, and the duration of the dynamic security prediction period is less than the duration of the baseline security prediction period.

[0027] The duration of the dynamic security prediction cycle = the duration of the baseline security prediction cycle + k × unstructured data difference, the unstructured data difference = the amount of unstructured data - the amount of structured data, k is the conversion coefficient, and the value of k is set by the management personnel. The more sensitive the management personnel are to unstructured data, the larger the value of k.

[0028] Specifically, under pre-analysis conditions, a security prediction method is determined based on the data sensitivity status; If the data sensitivity status is the first data sensitivity status, the security prediction method is user operation behavior prediction analysis; If the data sensitivity state is the second data sensitivity state, the security prediction method is data association risk prediction analysis; The pre-analysis condition is the end of a single safety prediction cycle.

[0029] Specifically, the data sensitivity status is determined based on the sensitivity characterization value and sensitivity fluctuation value of the target network communication data. The data sensitivity status includes: A first data sensitive state in which the sensitivity characterization value is less than a preset sensitivity characterization value and the sensitivity fluctuation value is less than a preset sensitivity fluctuation value; A second data sensitive state in which the sensitivity characterization value is greater than or equal to a preset sensitivity characterization value or the sensitivity fluctuation value is greater than or equal to a preset sensitivity fluctuation value.

[0030] In the present invention, each data item is marked with a security tag, which shows whether the data item is sensitive data or non-sensitive data. This is set in advance by the management personnel based on the actual importance of the data. The sensitive characterization value = the number of requests with sensitive data in all data requests corresponding to the most recent security prediction cycle / the total number of data requests. The sensitive fluctuation value is the sensitive characterization value corresponding to the most recent security prediction cycle minus the maximum value of the sensitive characterization values ​​corresponding to the three most recent security prediction cycles before the most recent security prediction cycle.

[0031] Specifically, under the first analysis condition, the information extraction frequency and information extraction concentration of each operating user are detected to determine the information extraction state, and whether the operating user has dangerous behavior is determined according to the information extraction state; If the information extraction status is that the information extraction frequency is greater than the preset information extraction frequency or the information extraction concentration is greater than the preset information extraction concentration, then the operating user has engaged in dangerous behavior; If the information extraction status is that the information extraction frequency is less than or equal to the preset information extraction frequency and the information extraction concentration is less than or equal to the preset information extraction concentration, then the operating user does not have any dangerous behavior; The first analysis condition is that the data sensitivity state is the first data sensitivity state.

[0032] The method for confirming the frequency of information extraction of the operating user is to detect the number of information requests of the operating user in the most recent security prediction cycle, and record it as the frequency of information extraction; The method for confirming the information extraction concentration of the operating user is to detect the databases corresponding to each information request of the operating user in the most recent security prediction cycle. Information extraction concentration = the number of databases with repeated requests / the total number of databases corresponding to each information request. If there is a database with repeated requests, that is, the database corresponding to at least two information requests is the same database, then this database is a database with repeated requests.

[0033] Specifically, under the second analysis condition, the data dependencies corresponding to several security prediction cycles closest to the current moment are detected; If the data dependency is greater than the preset data dependency, it is determined that there is a data association risk, and the frequency of data transmission path changes is adjusted; If the data dependency is less than or equal to the preset data dependency, it is determined that there is no data association risk and a sensitive data risk warning is sent to the user; The second analysis condition is that the data sensitivity state is the second data sensitivity state.

[0034] The method for confirming data dependency is to detect the target network communication data with dependency in the most recent security prediction cycle, and record the data volume of the target network communication data with dependency / the total data volume of the target network communication data in the most recent security prediction cycle as the data dependency. For any two target network communication data, if the upload IPs corresponding to the two target network communication data are the same IP, then the two target network communication data have a dependency relationship. It can be understood that obtaining the IP of the data upload user corresponding to the database is content that technicians in this field have already mastered and will not elaborate on it here.

[0035] Specifically, the frequency of data transmission path changes is adjusted, including: Detecting the difference between the data dependency and the dependency corresponding to the preset data dependency; Increase and adjust the frequency of data transmission path changes based on the dependency difference; The increase in the frequency of data transmission path changes is positively correlated with the difference in dependence.

[0036] In the present invention, the data transmission path of the data request is different after a certain period of time, and the frequency of data transmission path change is the number of times the data transmission path is changed within a fixed time.

[0037] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A network security situation prediction method based on big data, characterized in that: include: Determine the data structure status based on the ratio of structured data to unstructured data in the target network communication data; Determine, based on the data structure state, whether the security prediction period is set as a baseline security prediction period or a dynamic security prediction period; Determine the data sensitivity status based on the sensitive characterization value and sensitive fluctuation value of the target network communication data and determine the security prediction method based on the data sensitivity status; When the security prediction method is user operation behavior prediction analysis, the frequency and concentration of information extraction of each operating user are detected to determine the information extraction status and determine whether the operating user has dangerous behavior based on the information extraction status; When the security prediction method is data-related risk prediction analysis, the frequency of data transmission path changes is adjusted or sensitive data risk warnings are sent to users based on the comparison results of the data dependencies corresponding to several security prediction cycles and the preset data dependencies.

2. The network security situation prediction method based on big data according to claim 1 is characterized in that: Periodically detect the data structure status of target network communication data and determine the security prediction period based on the data structure status; If the data structure state is the first data structure state, the security prediction period is set to the baseline security prediction period; If the data structure state is the second data structure state, the security prediction period is set to the dynamic security prediction period.

3. The network security situation prediction method based on big data according to claim 2 is characterized in that: The data structure status is determined based on the ratio of structured data to unstructured data in the target network communication data. The data structure status includes: If the data proportion is greater than the preset data proportion, the data structure state is the first data structure state; If the data proportion is less than or equal to the preset data proportion, the data structure state is the second data structure state.

4. The network security situation prediction method based on big data according to claim 3 is characterized in that: Under the period adjustment condition, the duration of the dynamic security prediction cycle is determined based on the difference in unstructured data; The duration of the dynamic security prediction cycle is negatively correlated with the difference in unstructured data; The period adjustment condition is to determine that the data structure state is the second data structure state, and the duration of the dynamic security prediction period is less than the duration of the baseline security prediction period.

5. The network security situation prediction method based on big data according to claim 4 is characterized in that: Under pre-analysis conditions, determine the security prediction method based on the data sensitivity status; If the data sensitivity status is the first data sensitivity status, the security prediction method is user operation behavior prediction analysis; If the data sensitivity state is the second data sensitivity state, the security prediction method is data association risk prediction analysis; The pre-analysis condition is the end of a single safety prediction cycle.

6. The network security situation prediction method based on big data according to claim 5 is characterized in that: The data sensitivity status is determined based on the sensitivity characterization value and sensitivity fluctuation value of the target network communication data. The data sensitivity status includes: A first data sensitive state in which the sensitivity characterization value is less than a preset sensitivity characterization value and the sensitivity fluctuation value is less than a preset sensitivity fluctuation value; A second data sensitive state in which the sensitivity characterization value is greater than or equal to a preset sensitivity characterization value or the sensitivity fluctuation value is greater than or equal to a preset sensitivity fluctuation value.

7. The network security situation prediction method based on big data according to claim 6 is characterized in that: Under the first analysis condition, the frequency and concentration of information extraction of each operating user are detected to determine the information extraction status, and whether the operating user has dangerous behavior is determined according to the information extraction status; If the information extraction status is that the information extraction frequency is greater than the preset information extraction frequency or the information extraction concentration is greater than the preset information extraction concentration, then the operating user has engaged in dangerous behavior; If the information extraction status is that the information extraction frequency is less than or equal to the preset information extraction frequency and the information extraction concentration is less than or equal to the preset information extraction concentration, then the operating user does not have any dangerous behavior; The first analysis condition is that the data sensitive state is the first data sensitive state.

8. The network security situation prediction method based on big data according to claim 7 is characterized in that: Under the second analysis condition, the data dependency corresponding to several security prediction cycles closest to the current moment is detected; If the data dependency is greater than the preset data dependency, it is determined that there is a data association risk, and the frequency of data transmission path changes is adjusted; If the data dependency is less than or equal to the preset data dependency, it is determined that there is no data association risk and a sensitive data risk warning is sent to the user; The second analysis condition is that the data sensitive state is the second data sensitive state.

9. The network security situation prediction method based on big data according to claim 8 is characterized in that: The adjusting the frequency of data transmission path alternation includes: Detecting the difference between the data dependency and the dependency corresponding to the preset data dependency; Increase and adjust the frequency of data transmission path changes based on the dependency difference; The increase in the frequency of data transmission path changes is positively correlated with the difference in dependence.

Citation Information

Patent Citations

  • Network security monitoring method and device based on situation awareness, equipment and medium

    CN111786950A

  • Network security situation awareness method, device and system

    CN115001954A

  • AI-based network security situation analysis and prediction method and system

    CN119094194A

  • Network security situation awareness and early warning system and method based on artificial intelligence

    CN119276529A

  • Network security situation awareness method based on adaptive algorithm

    CN119966658A