A network security situation prediction method based on big data
By dynamically adjusting the security prediction cycle and method based on the ratio of structured to unstructured data and the sensitivity status of network communication data, the problem of poor security situation awareness in existing technologies is solved, and more efficient and accurate network security situation prediction is achieved.
Patent Information
- Application Number
- CN202511248656.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-09-03
AI Technical Summary
Existing technologies with single data processing methods cannot effectively meet the needs of dynamic data transmission processes, resulting in poor security situation awareness.
The data structure status is determined by the ratio of structured to unstructured data in the target network communication data. A baseline or dynamic security prediction cycle is set, and different security prediction methods are selected in combination with the data sensitivity status, including user operation behavior prediction analysis and data association hazard prediction analysis. The frequency of data transmission paths is adjusted to improve the accuracy and efficiency of security situation awareness.
It enables flexible setting of security prediction cycles, improves the efficiency and accuracy of security situation awareness, adapts to the needs of different data transmission scenarios, and enhances the real-time monitoring capabilities of network security.
Smart Images

Figure CN120729655B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security, and in particular to a network security situation prediction method based on big data. BACKGROUND
[0002] With the development of information technology, the application of computer network is becoming more and more popular, and the network security problem has gradually become the concern of people. Network security technology is the core technology to ensure user information security and network operation stability. Especially for network data transmission process, as one of the most common network technologies, it is also a very critical technology link of network security. Therefore, how to effectively perceive, predict and even warn for network information transmission security is a very important problem for those skilled in the art.
[0003] Chinese patent publication No. CN110650155A discloses a network security situation awareness platform for rapid transmission of security risk information. The method comprises the following steps: preprocessing, optimizing and setting transmission rules for all obtained current network security risk information, and batch processing and transmission to improve the transmission efficiency of security risk information and achieve near real-time information transmission effect. The network security risk information of the present application is filtered by matching the supervision object and the security risk type of the warning and early warning information, and the same type of security risk information is aggregated and simplified. The information transmission method is a whole-to-part information transmission method, which can improve the information transmission efficiency, so that the user can see the data before T time every time the platform opens the warning and early warning module page, and can improve the user experience and the warning and early warning efficiency, so that the user can always see the security risk information immediately when opening the warning and early warning module. The network security risk information transmission efficiency is high, and the network security index can be further improved. It can be seen that the above technical scheme has the following problems: the single data processing method cannot effectively meet the dynamic data transmission process, and different security analysis strategies cannot be selected according to the characteristics of the actual transmission data, resulting in poor security situation awareness effect. SUMMARY
[0004] Therefore, the present application provides a network security situation prediction method based on big data to overcome the problem that the single security analysis method in the prior art cannot meet the dynamic data transmission scene, thereby resulting in poor security situation awareness prediction effect.
[0005] To achieve the above-mentioned purpose, the present application provides a network security situation prediction method based on big data, comprising:
[0006] determining the data structure state according to the data proportion ratio of the structured data and the unstructured data of the target network communication data;
[0007] The safety prediction period is set as a reference safety prediction period or a dynamic safety prediction period according to the data structure state;
[0008] The data sensitive state is determined according to the sensitive characteristic value and the sensitive fluctuation value of the target network communication data, and the safety prediction mode is determined according to the data sensitive state;
[0009] When the safety prediction mode is user operation behavior prediction analysis, the information extraction frequency and the information extraction concentration of each operation user are detected to determine the information extraction state, and whether the operation user has dangerous behavior is determined according to the information extraction state;
[0010] When the safety prediction mode is data correlation dangerous prediction analysis, the comparison result of the data dependency corresponding to a plurality of safety prediction periods and the preset data dependency is determined to adjust the data transmission path replacement frequency or send a sensitive data risk prompt to the user.
[0011] Further, the data structure state of the target network communication data is periodically detected, and the safety prediction period is determined according to the data structure state;
[0012] If the data structure state is a first data structure state, the safety prediction period is set as a reference safety prediction period;
[0013] If the data structure state is a second data structure state, the safety prediction period is set as a dynamic safety prediction period.
[0014] Further, the data structure state is determined according to the data proportion ratio of the structured data and the unstructured data of the target network communication data, and the data structure state includes:
[0015] If the data proportion ratio is greater than a preset data proportion ratio, the data structure state is a first data structure state;
[0016] If the data proportion ratio is less than or equal to the preset data proportion ratio, the data structure state is a second data structure state.
[0017] Further, under the period adjustment condition, the time length of the dynamic safety prediction period is determined according to the unstructured data difference value;
[0018] The time length of the dynamic safety prediction period and the unstructured data difference value are in a negative correlation relationship;
[0019] The period adjustment condition is that the data structure state is determined as a second data structure state, and the time length of the dynamic safety prediction period is less than the time length of the reference safety prediction period.
[0020] Further, under the pre-analysis condition, the safety prediction mode is determined according to the data sensitive state;
[0021] If the data sensitivity state is the first data sensitivity state, the security prediction mode is user operation behavior prediction analysis;
[0022] If the data sensitivity state is the second data sensitivity state, the security prediction mode is data correlation risk prediction analysis;
[0023] The pre-analysis condition is the end of a single security prediction cycle.
[0024] Further, the data sensitivity state is determined according to a sensitive characteristic value and a sensitive fluctuation value of the target network communication data, and the data sensitivity state includes:
[0025] The first data sensitivity state in which the sensitive characteristic value is less than a preset sensitive characteristic value and the sensitive fluctuation value is less than a preset sensitive fluctuation value;
[0026] The second data sensitivity state in which the sensitive characteristic value is greater than or equal to the preset sensitive characteristic value or the sensitive fluctuation value is greater than or equal to the preset sensitive fluctuation value.
[0027] Further, under the first analysis condition, the information extraction frequency and the information extraction concentration of each operation user are detected to determine the information extraction state, and whether the operation user has dangerous behavior is determined according to the information extraction state;
[0028] If the information extraction state is that the information extraction frequency is greater than a preset information extraction frequency or the information extraction concentration is greater than a preset information extraction concentration, the operation user has dangerous behavior.
[0029] If the information extraction state is that the information extraction frequency is less than or equal to the preset information extraction frequency and the information extraction concentration is less than or equal to the preset information extraction concentration, the operation user does not have dangerous behavior.
[0030] The first analysis condition is that the data sensitivity state is the first data sensitivity state.
[0031] Further, under the second analysis condition, the data dependency corresponding to a plurality of security prediction cycles closest to the current time is detected;
[0032] If the data dependency is greater than a preset data dependency, it is determined that there is a data correlation risk, and the data transmission path alternation frequency is adjusted.
[0033] If the data dependency is less than or equal to the preset data dependency, it is determined that there is no data correlation risk, and a sensitive data risk prompt is sent to the user.
[0034] The second analysis condition is that the data sensitivity state is the second data sensitivity state.
[0035] Further, the data transmission path alternation frequency is adjusted, including:
[0036] The dependency difference value corresponding to the detection data dependency and the preset data dependency;
[0037] According to the dependency difference value, the data transmission path alternation frequency is adjusted to increase;
[0038] The increase value of the data transmission path alternation frequency and the dependency difference value are in a positive correlation relationship.
[0039] Compared with the prior art, the beneficial effects of the present application are that in the technical scheme of the present application, the data structure state is determined according to the data proportion ratio of the structured data and the unstructured data of the target network communication data, and then the complexity of the target network communication data is reflected, and different security prediction periods are selected correspondingly, so that the setting of the security prediction period is more in line with the actual application scene, and then the subsequent analysis can be more timely, avoiding the problem of poor data analysis effect caused by the single period monitoring mode, and then the security situation awareness prediction efficiency of the present application is improved.
[0040] Further, in the technical scheme of the present application, the length of the dynamic security prediction period is determined according to the unstructured data difference value, so that the length of the dynamic security prediction period is set according to the actual scene, and is not a fixed single value, and the setting precision of the length of the dynamic security prediction period is improved.
[0041] Further, in the technical scheme of the present application, the data sensitive state is determined according to the sensitive characteristic value and the sensitive fluctuation value of the target network communication data, the content sensitivity of the target network communication data is effectively reflected through the data sensitive state, and different security prediction modes are adaptively selected, so that the security prediction mode is dynamic and targeted, and the security situation prediction efficiency and accuracy of the present application are further improved. BRIEF DESCRIPTION OF DRAWINGS
[0042] Fig. 1 It is a schematic diagram of the network security situation prediction method based on big data of the present application;
[0043] Fig. 2 It is a flow chart of determining the security prediction period according to the data structure state of the present application;
[0044] Fig. 3 It is a flow chart of determining the security prediction mode according to the data sensitive state of the present application. DETAILED DESCRIPTION
[0045] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described, obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.
[0046] Please refer to Figs. 1 to 3 As shown in the drawings, the present application provides a network security situation prediction method based on big data, comprising:
[0047] According to the data proportion ratio of the structured data and the unstructured data of the target network communication data, the data structure state is determined;
[0048] According to the data structure state, the security prediction cycle is set as a reference security prediction cycle or a dynamic security prediction cycle;
[0049] According to the sensitive characteristic value and the sensitive fluctuation value of the target network communication data, the data sensitive state is determined, and according to the data sensitive state, the security prediction mode is determined;
[0050] When the security prediction mode is user operation behavior prediction analysis, the information extraction frequency and the information extraction concentration degree of each operation user are detected to determine the information extraction state, and whether the operation user has dangerous behavior is determined according to the information extraction state;
[0051] When the security prediction mode is data correlation dangerous prediction analysis, according to the comparison result of the data dependence degree corresponding to a plurality of security prediction cycles and the preset data dependence degree, the data transmission path replacement frequency is adjusted or the sensitive data risk prompt is sent to the user.
[0052] The present application is applied to the network security situation prediction warning in the process of communication network data transmission, the present application is applied to a target platform, the target platform is provided with a database, an operation user sends a data request to the target platform, the target platform sends the data request to the corresponding database, and transmits the data corresponding to the data request to the user, and the management personnel are technical personnel for security management of the target platform; the present application should have a plurality of historical records, a single historical record at least records data proportion ratio, sensitive characteristic value, sensitive fluctuation value, information extraction frequency, information extraction concentration degree and data dependence degree, and the historical record is provided with a qualified mark, the qualified mark represents whether the historical record meets the demand of the management personnel, it can be understood that the self-set security operation index is used to determine whether the platform meets the operation safety demand of the management personnel in a period of time, which is the content mastered by those skilled in the art, and will not be repeated here.
[0053] The application applies detection values, including data proportion ratio, sensitive representation value, sensitive fluctuation value, information extraction frequency, information extraction concentration, and data dependency, and each detection value is correspondingly provided with a preset threshold, including a preset data proportion ratio, a preset sensitive representation value, a preset sensitive fluctuation value, a preset information extraction frequency, a preset information extraction concentration, and a preset data dependency. For any preset threshold, the value method is to detect the detection value of the historical record meeting the operator's demand corresponding to the preset threshold, remove the abnormal value of the detection value, and calculate the average value of the detection value after removing the abnormal value, which is recorded as the value of the preset threshold. The method for removing abnormal values includes but is not limited to 3σ criterion method or IQR method.
[0054] Specifically, the data structure state of the target network communication data is periodically detected, and the safety prediction period is determined according to the data structure state;
[0055] If the data structure state is the first data structure state, the safety prediction period is set as the reference safety prediction period;
[0056] If the data structure state is the second data structure state, the safety prediction period is set as the dynamic safety prediction period.
[0057] The target network communication data is the data transmitted in the last safety prediction period.
[0058] Specifically, the data structure state is determined according to the data proportion ratio of the structured data and the unstructured data of the target network communication data, and the data structure state includes:
[0059] If the data proportion ratio is greater than the preset data proportion ratio, the data structure state is the first data structure state;
[0060] If the data proportion ratio is less than or equal to the preset data proportion ratio, the data structure state is the second data structure state.
[0061] The structured data is data presented in the form of a table, the unstructured data is data in the form of a table, the preset data proportion ratio = data amount of structured data / data amount of unstructured data, and the unit of data amount is bit;
[0062] The reference safety prediction period is a period of time set by the manager, and the manager can set the reference safety prediction period according to actual needs. The greater the manager's demand for data analysis and timeliness, the shorter the length of the reference safety prediction period.
[0063] Specifically, under the period adjustment condition, the length of the dynamic safety prediction period is determined according to the unstructured data difference value;
[0064] The length of the dynamic security prediction period is negatively correlated with the unstructured data difference value;
[0065] The period adjustment condition is that the data structure state is the second data structure state, and the length of the dynamic security prediction period is less than the length of the reference security prediction period.
[0066] The length of the dynamic security prediction period = the length of the reference security prediction period + k * the unstructured data difference value, the unstructured data difference value = the data amount of the unstructured data - the data amount of the structured data, k is a conversion coefficient, and the value of k is set by the manager; the greater the sensitivity of the manager to the unstructured data, the greater the value of k.
[0067] Specifically, under the pre-analysis condition, the security prediction mode is determined according to the data sensitivity state;
[0068] If the data sensitivity state is the first data sensitivity state, the security prediction mode is user operation behavior prediction analysis;
[0069] If the data sensitivity state is the second data sensitivity state, the security prediction mode is data correlation risk prediction analysis;
[0070] The pre-analysis condition is that a single security prediction period ends.
[0071] Specifically, the data sensitivity state is determined according to the sensitive characteristic value and the sensitive fluctuation value of the target network communication data, and the data sensitivity state includes:
[0072] The first data sensitivity state that the sensitive characteristic value is less than a preset sensitive characteristic value and the sensitive fluctuation value is less than a preset sensitive fluctuation value;
[0073] The second data sensitivity state that the sensitive characteristic value is greater than or equal to the preset sensitive characteristic value or the sensitive fluctuation value is greater than or equal to the preset sensitive fluctuation value.
[0074] In the present application, each data item is marked with a security mark, and the security mark shows that the data item is sensitive data or non-sensitive data, which is set by the manager in advance according to the actual importance of the data. The sensitive characteristic value = the number of requests that exist sensitive data in all data requests corresponding to the latest security prediction period / the number of all data requests, and the sensitive fluctuation value is the maximum value of the sensitive characteristic value corresponding to the latest security prediction period minus the sensitive characteristic value corresponding to the latest three security prediction periods before the latest security prediction period.
[0075] Specifically, under the first analysis condition, the information extraction frequency and the information extraction concentration of each operation user are detected to determine the information extraction state, and whether the operation user has dangerous behavior is determined according to the information extraction state;
[0076] If the information extraction state is that the information extraction frequency is greater than the preset information extraction frequency or the information extraction concentration is greater than the preset information extraction concentration, the operation user has dangerous behavior;
[0077] If the information extraction state is that the information extraction frequency is less than or equal to the preset information extraction frequency and the information extraction concentration is less than or equal to the preset information extraction concentration, the operation user does not have dangerous behavior.
[0078] The first analysis condition is that the data sensitive state is the first data sensitive state.
[0079] The confirmation manner of the information extraction frequency of the operation user is to detect the number of information requests in the last one safety prediction period of the operation user, which is recorded as the information extraction frequency.
[0080] The confirmation manner of the information extraction concentration of the operation user is to detect the database corresponding to each information request in the last one safety prediction period of the operation user, and the information extraction concentration = the number of databases with repeated requests / the total number of databases corresponding to each information request. The database with repeated requests is that the databases corresponding to at least two information requests are the same database, and the database is the database with repeated requests.
[0081] Specifically, under the second analysis condition, the data dependency degree corresponding to the last several safety prediction periods from the current time is detected.
[0082] If the data dependency degree is greater than the preset data dependency degree, it is determined that there is a data association danger, and the data transmission path alternation frequency is adjusted.
[0083] If the data dependency degree is less than or equal to the preset data dependency degree, it is determined that there is no data association danger, and a sensitive data risk prompt is sent to the user.
[0084] The second analysis condition is that the data sensitive state is the second data sensitive state.
[0085] The confirmation manner of the data dependency degree is to detect the target network communication data with a dependent relationship in the last one safety prediction period, and record the data amount of the target network communication data with a dependent relationship / the total data amount of the target network communication data in the last one safety prediction period as the data dependency degree. For any two target network communication data, if the upload IP corresponding to the two target network communication data is the same IP, the two target network communication data have a dependent relationship. It can be understood that obtaining the IP of the data upload user corresponding to the database is a content mastered by those skilled in the art, and will not be repeated here.
[0086] Specifically, the data transmission path alternation frequency is adjusted, including:
[0087] The dependency difference value corresponding to the detection data dependency and the preset data dependency;
[0088] The dependency difference value is used to increase the data transmission path replacement frequency;
[0089] The increase value of the data transmission path replacement frequency and the dependency difference value are in a positive correlation relationship.
[0090] In the present application, the data transmission path is different after a certain period of time, and the data transmission path replacement frequency is the number of data transmission path replacements in a fixed time.
[0091] The above examples are only used to illustrate the technical method of the present application and are not limited. Although the present application has been described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical method of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical method of the present application.
Claims
1. A method for predicting network security situation based on big data, characterized in that, include: The data structure status is determined based on the ratio of structured to unstructured data in the target network communication data; The security prediction period is determined based on the data structure status and set as either the baseline security prediction period or the dynamic security prediction period. The data sensitivity status is determined based on the sensitive characterization value and sensitive fluctuation value of the target network communication data, and the security prediction method is determined based on the data sensitivity status. The safety prediction method involves detecting the frequency and concentration of information extraction by each user during user operation behavior prediction and analysis to determine the information extraction status and to determine whether the user is engaging in dangerous behavior based on the information extraction status. When the security prediction method is data-related risk prediction analysis, the frequency of data transmission path changes is adjusted or sensitive data risk warnings are sent to users based on the comparison results of data dependence corresponding to several security prediction cycles and preset data dependence.
2. The network security situation prediction method based on big data according to claim 1, characterized in that, Periodically detect the data structure status of the target network communication data, and determine the security prediction period based on the data structure status; If the data structure state is the first data structure state, then the security prediction period is set to the baseline security prediction period. If the data structure state is the second data structure state, then the security prediction period is set to the dynamic security prediction period.
3. The network security situation prediction method based on big data according to claim 2, characterized in that, The data structure state is determined based on the ratio of structured to unstructured data in the target network communication data. The data structure state includes: If the data proportion is greater than the preset data proportion, the data structure state is the first data structure state; If the data proportion is less than or equal to the preset data proportion, the data structure state is the second data structure state.
4. The network security situation prediction method based on big data according to claim 3, characterized in that, Under periodic adjustment conditions, the duration of the dynamic security prediction period is determined based on the difference in unstructured data; The duration of the dynamic security prediction period is negatively correlated with the difference in unstructured data. The period adjustment condition is that the data structure state is determined to be the second data structure state, and the duration of the dynamic security prediction period is less than the duration of the baseline security prediction period.
5. The network security situation prediction method based on big data according to claim 4, characterized in that, Under pre-analysis conditions, the security prediction method is determined based on the data sensitivity status; If the data sensitivity status is the first data sensitivity status, then the security prediction method is user operation behavior prediction analysis; If the data sensitivity status is the second data sensitivity status, then the security prediction method is data association hazard prediction analysis; The pre-analysis condition is the end of a single security prediction cycle.
6. The network security situation prediction method based on big data according to claim 5, characterized in that, The data sensitivity state is determined based on the sensitivity characterization value and sensitivity fluctuation value of the target network communication data, and the data sensitivity state includes: The first data sensitivity state is characterized by both the sensitivity characterization value being less than the preset sensitivity characterization value and the sensitivity fluctuation value being less than the preset sensitivity fluctuation value. A second data sensitivity state where the sensitive characterization value is greater than or equal to a preset sensitive characterization value or the sensitive fluctuation value is greater than or equal to a preset sensitive fluctuation value.
7. The network security situation prediction method based on big data according to claim 6, characterized in that, Under the first analysis condition, the frequency and concentration of information extraction by each user are detected to determine the information extraction status, and the user is determined to have any dangerous behavior based on the information extraction status. If the information extraction frequency is greater than the preset information extraction frequency or the information extraction concentration is greater than the preset information extraction concentration, then the user is engaging in dangerous behavior. If the information extraction status is that the information extraction frequency is less than or equal to the preset information extraction frequency and the information extraction concentration is less than or equal to the preset information extraction concentration, then the user is not engaging in dangerous behavior. The first analysis condition is the data-sensitive state, which is the first data-sensitive state.
8. The network security situation prediction method based on big data according to claim 7, characterized in that, Under the second analysis condition, the data dependency corresponding to the most recent security prediction periods is detected; If the data dependency is greater than the preset data dependency, it is determined that there is a risk of data association, and the frequency of data transmission path changes is adjusted. If the data dependency is less than or equal to the preset data dependency, it is determined that there is no risk of data association, and a sensitive data risk warning is sent to the user. The second analysis condition is a data-sensitive state.
9. The network security situation prediction method based on big data according to claim 8, characterized in that, The adjustment of the frequency of data transmission path changes includes: The difference between the detected data dependency and the preset data dependency; Adjust the frequency of data transmission path changes based on the dependency difference; The increase in the frequency of data transmission path changes is positively correlated with the difference in dependency.
Citation Information
Patent Citations
Method for quickly transmitting potential safety hazard information in network security situation awareness platform
CN110650155A
Network security situation awareness method, device and system
CN115001954A
AI-based network security situation analysis and prediction method and system
CN119094194A