A multi-dimensional based network security situation awareness system and method

By using a multi-dimensional network security situational awareness system and a support vector machine algorithm to establish a traffic anomaly detection model, the problem of insufficient adaptability and self-optimization in existing technologies for anomaly traffic detection is solved, and efficient and flexible anomaly traffic detection and security response are achieved.

CN120750680BActive Publication Date: 2025-11-07NANTONG SHIPPING COLLEGE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511270556.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-11-07
Estimated Expiration
2045-09-08

AI Technical Summary

Technical Problem

Existing machine learning-based anomaly traffic detection technologies are less adaptable to handling high-dimensional and diverse network data, unable to respond to network attacks in a timely manner, and lack self-learning and optimization mechanisms, resulting in system lag and vulnerabilities.

Method used

A multi-dimensional network security situation awareness system is adopted, including modules for data acquisition and preprocessing, feature extraction and multi-dimensional analysis, anomaly detection model training, real-time traffic monitoring and anomaly detection, anomaly traffic assessment and priority ranking, feedback and model optimization. The traffic anomaly detection model is established using the support vector machine algorithm, and the model is optimized through multi-dimensional feature fusion and real-time updates.

Benefits of technology

It improves the accuracy and flexibility of abnormal traffic detection, reduces false alarm and false negative rates, enhances the real-time performance and response speed of the system, can adapt to new attack methods and network environments, and improves security response efficiency and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750680B_ABST
    Figure CN120750680B_ABST
Patent Text Reader

Abstract

The application discloses a kind of network security situation awareness system and method based on multidimension, it is related to network security situation awareness technical field, by abnormal flow comprehensive score calculation unit, in combination with abnormal score Sy, risk index Ry, data packet influence factor Iy and duration factor Dy, system can calculate accurate priority Py for each abnormal flow.This kind of comprehensive evaluation method makes system be able to consider the abnormal degree of flow, potential threat to system and duration comprehensively, improves the accuracy of abnormal flow detection.Through abnormal flow sequencing and security response triggering unit, system carries out descending order sequencing to the flow priority Py calculated, and classifies flow event according to priority threshold TPth.Through flow event according to priority sequencing, system can preferentially process the most urgent security threat, ensure that security personnel can respond to the most important event in time, improve response efficiency and processing timeliness.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security situation awareness, in particular to a network security situation awareness system and method based on multiple dimensions. BACKGROUND

[0002] Network security is a major issue that has been increasingly concerned, covering multiple aspects such as computer networks, information technology, and data security. In the context of continuous development of informatization and digitization, network security is not only related to data protection, but also an important cornerstone for safeguarding national, enterprise, and personal security. With the popularization of emerging technologies such as the Internet of Things, big data, and cloud computing, the threat of network security is increasing, and more and more systems rely on machine learning technology to analyze network traffic in real time, thereby improving the intelligent level of security protection.

[0003] Although existing machine learning-based abnormal traffic detection technology has achieved certain results, it still faces many challenges in dealing with high-dimensional and diversified network data. First, traditional anomaly detection methods often rely on manually defined features and rules, which makes the system less adaptable to new attack patterns and unable to respond to the variability of network attacks in a timely manner. Second, most existing machine learning models rely heavily on data quality and are difficult to continuously optimize and learn without increasing hardware resources.

[0004] These existing problems and deficiencies often result from two aspects. On the one hand, traditional abnormal traffic detection systems usually rely on manually designed features and cannot cope with dynamically changing network environments and evolving attack methods. On the other hand, the lack of a self-learning and self-optimizing mechanism leads to a certain lag in existing systems when encountering new network attacks. In this case, attackers can exploit the inherent weaknesses of the system to bypass security protection using new attack methods, causing system vulnerabilities. These problems not only lead to an increase in the frequency of security incidents, but in some cases, due to the existence of false positives and false negatives, the trustworthiness of the protection system is affected, resulting in a decrease in the response efficiency of network security management personnel, ultimately posing a serious threat to the normal operation of business systems. SUMMARY

[0005] In view of the deficiencies of the prior art, the present application provides a network security situation awareness system and method based on multiple dimensions, which solves the problems mentioned in the background art.

[0006] To achieve the above object, the application is implemented by the following technical solutions: a network security situation awareness system based on multi-dimension, comprising a data acquisition and preprocessing module, a feature extraction and multi-dimension analysis module, an abnormality detection model training module, a real-time traffic monitoring and abnormality detection module, an abnormality traffic evaluation and priority sorting module, and a feedback and model optimization module;

[0007] The data acquisition and preprocessing module acquires network traffic data from the firewall, IDS and IPS in the network in real time, fits the original data set DM, and performs preprocessing to obtain the network data set DW;

[0008] The feature extraction and multi-dimension analysis module performs feature extraction on the obtained network data set DW, and performs multi-dimension analysis on the extracted features to form the structured feature data set DF;

[0009] The abnormality detection model training module trains the feature data set DF by using the support vector machine algorithm to establish the traffic abnormality detection model MTR;

[0010] The real-time traffic monitoring and abnormality detection module performs abnormality detection on the real-time traffic data by using the traffic abnormality detection model MTR, judges whether there is abnormal traffic, and obtains the abnormality score Sy and the risk index Ry;

[0011] The abnormality traffic evaluation and priority sorting module calculates the abnormality traffic priority Py according to the obtained abnormality score Sy and risk index Ry;

[0012] The feedback and model optimization module updates the traffic abnormality detection model MTR according to the obtained abnormality traffic priority Py to obtain the updated traffic abnormality detection model nMTR.

[0013] Preferably, the data acquisition and preprocessing module comprises a multi-source network data acquisition unit and a data preprocessing unit;

[0014] The multi-source network data acquisition unit acquires network traffic data through the firewall, NetFlow device, sFlow device, network probe, port mirroring and packet capture tool, and system-level packet capture tool in the network, including source IP address IPs, target IP address IPm, source port number PDs, target port number PDm, protocol type XY, packet size SΩ and time stamp ST, and fits the original data set DM;

[0015] The source IP address IPs and target IP address IPm are acquired by the network probe and NetFlow device:

[0016] The source port number PDs and target port number PDm are acquired by the sFlow device and network probe;

[0017] Protocol type XY is acquired through firewall and network probe collection;

[0018] Packet size SΩ is acquired through port mirroring and packet capture tool collection;

[0019] Timestamp ST is acquired through system-level packet capture tool and network probe collection;

[0020] The data preprocessing unit preprocesses the acquired original data set DM, including abnormal field cleaning and field normalization processing, to obtain a network data set DW;

[0021] Abnormal field cleaning includes address filtering, protocol missing processing and abnormal point elimination on the original data set DM;

[0022] Address filtering uses format legality verification to verify whether it is a legal IPv4 and IPv6 address;

[0023] Protocol missing processing eliminates the protocol in the original data set DM through a reverse backtracking method;

[0024] Abnormal point elimination eliminates non-monotonic increasing timestamps ST in the original data set DM through an anomaly detection algorithm;

[0025] Field normalization processing includes port field normalization processing and packet size field normalization processing on the original data set DM;

[0026] Port field normalization processing unifies the numerical scale under the same dimensionless through numerical range verification;

[0027] Packet size field normalization processing normalizes the network data set DW using the min-max normalization method.

[0028] Preferably, the feature extraction and multi-dimensional analysis module includes a network behavior feature extraction unit and a multi-dimensional feature correlation analysis unit;

[0029] The network behavior feature extraction unit extracts features from the network data set DW, including traffic statistical features F1, time features F2, host behavior features F3, communication directionality features F4 and session density features F5;

[0030] Traffic statistical features F1, total flow sum, are acquired through the following formula:

[0031]

[0032] In the formula, F1(k) represents the total flow within the sliding window k, k represents the starting index of the sliding window, L represents the length of the sliding window, i.e. the number of records contained in the window, SΩ j ​Data packet size of the jth data;

[0033] Time feature F2, data packet arrival frequency, number of data packets per unit time, obtained by the following formula:

[0034] ;

[0035] In the formula, F2(T) represents the data packet arrival frequency in the time window T, T represents the length of the time window, STj represents the time stamp of the jth data, STn represents the time stamp corresponding to the current index n, and {j |...} represents a set of data records satisfying the time condition;

[0036] Host behavior feature F3, access session density index, obtained by the following formula:

[0037] ;

[0038] In the formula, F3IPs(T) represents the connection frequency density of the source IP address IPs in the time window T, IPSj represents the source IP address of the jth data, and IPSn represents the source IP address corresponding to the current index n;

[0039] Communication directionality feature F4, communication directionality ratio, obtained by the following formula:

[0040] ;

[0041] In the formula, F4(IPo) represents the communication proportion of the host IPo, IPo represents the analyzed host IP address, c represents a positive number (used to avoid division by zero error) represents the total number of inbound traffic bytes of all targets for IPo represents the total number of outbound traffic bytes from IPo;

[0042] Session density feature F5, burst traffic change rate, obtained by the following formula:

[0043] ;

[0044] In the formula, F5(k) represents the traffic change rate of the sliding window k, and μF(k) represents the average traffic;

[0045] The multi-dimensional feature correlation analysis unit constructs a composite feature FH by multiplying and interacting different types of features;

[0046] The composite feature FH is obtained by the following formula:

[0047] ;

[0048] In the formula, FH (F5, F4) represents a composite feature considering the communication direction and the session density, and B represents a neutral offset value, specifically 0.5;

[0049] The obtained traffic statistical feature F1, time feature F2, host behavior feature F3, communication direction feature F4, session density feature F5 and composite feature FH are integrated to obtain a feature data set DF.

[0050] Preferably, the anomaly detection model training module comprises a training sample construction unit and a support vector machine training unit.

[0051] The training sample construction unit selects and manually labels the training samples from the obtained feature data set DF, determines the normal label and the abnormal label of each record, and constructs a training set for sample training.

[0052] The feature data set DF is set as:

[0053] ;

[0054] In the formula, Fi represents the ith feature in the feature data set DF, and N represents the total number of features.

[0055] The label Y corresponding to the feature data set DF is:

[0056] ;

[0057] In the formula, yi represents the classification label, yi=+1 represents that the ith feature is normal traffic, and yi=-1 represents that the ith feature is abnormal traffic.

[0058] The support vector machine training unit trains the training set by using a support vector machine algorithm to obtain a generalizable traffic anomaly detection model MTR.

[0059] The obtaining steps of the traffic anomaly detection model MTR are:

[0060] S1, find a set of parameters (w, b) to construct a hyperplane formula:

[0061] ;

[0062] ;

[0063] In the formula, w represents a weight vector, represents a direction vector of the classification hyperplane in the feature space, and has the same dimension as the feature vector; b represents a bias term, which is obtained by training and learning.

[0064] S2, for the parameters (w, b), use the constraint condition to maximize the classification interval, and the formula is as follows:

[0065] , constraints: ;

[0066] wherein min represents a minimization operation, and represents that the constraint is true for all samples;

[0067] S3, the i-th feature Fi in the feature dataset DF is mapped to a high-dimensional space, and a kernel function is used to realize the nonlinear classification ability, and the formula is as follows:

[0068] ;

[0069] wherein KS() represents a kernel function, Fa represents the a-th feature in the feature dataset DF, exp() represents an exponential function, and γ represents a kernel function parameter;

[0070] S4, finally output the traffic anomaly detection model MTR:

[0071] MTR= (w, b, KS()).

[0072] Preferably, the real-time traffic monitoring and anomaly detection module detects the traffic data in the network dataset DW through the traffic anomaly detection model MTR, obtains an anomaly score Sy, and compares the anomaly score Sy with a preset anomaly threshold TSY to determine the abnormal state of the traffic;

[0073] The anomaly score Sy is obtained by the following formula:

[0074] ;

[0075] wherein Nks represents the number of support vectors, represents the i-th feature in the feature dataset DF, represents the weight coefficient of the i-th feature support vector, represents the feature vector constructed in the network dataset DW;

[0076] According to the obtained anomaly score Sy, the traffic is judged;

[0077] When sign(Sy)=+1, it is judged that the traffic is normal traffic;

[0078] When sign(Sy)=-1, it is judged that the traffic is abnormal traffic;

[0079] The abnormal state of the traffic is obtained by matching the following way:

[0080] When the anomaly score Sy is less than or equal to the anomaly threshold TSY, it indicates that the determination result of the traffic is inaccurate;

[0081] When the abnormal score Sy is greater than the abnormal threshold TSY, it indicates that the determination result of the traffic is accurate;

[0082] The abnormal score Sy is calculated by using the confidence function ASy, the risk index Ry is obtained, and the risk degree is determined by the risk index Ry;

[0083] The risk index Ry is obtained by the following formula:

[0084] ;

[0085] In the formula, exp represents the exponential function, Co represents the risk index expansion factor, Indicates the indicator function, which is only effective for abnormal traffic, and is effective when sign (Sy) =-1;

[0086] The risk degree of abnormal traffic is matched by the following way

[0087] When 0

[0088] When 0.5

[0089] Preferably, the abnormal traffic evaluation and priority sorting module includes an abnormal traffic comprehensive score calculation unit and an abnormal traffic sorting and security response triggering unit;

[0090] The abnormal traffic comprehensive score calculation unit calculates the abnormal traffic priority Py according to the obtained abnormal score Sy and risk index Ry, and combines the data packet influence factor Iy and the duration factor Dy;

[0091] The abnormal traffic priority Py is obtained by the following formula:

[0092] ;

[0093] In the formula, Respectively represent the preset weight values of the abnormal score Sy, the risk index Ry, the data packet influence factor Iy and the duration factor Dy, and ;

[0094] The data packet influence factor Iy reflects the potential influence degree of the traffic data packet on the system security, and the importance of the data packet is evaluated according to the data packet size SΩ;

[0095] The data packet influence factor Iy is obtained by the following formula:

[0096] ;

[0097] In the formula, maxSΩ represents the set maximum packet size;

[0098] The duration factor Dy measures the duration of network traffic anomaly, and the long duration of abnormal traffic acquisition system causes threat;

[0099] The duration factor Dy is obtained by the following formula:

[0100] ;

[0101] In the formula, STs represents the time stamp of the start of the traffic anomaly event, and STmax represents the maximum allowed time stamp.

[0102] Preferably, the abnormal traffic ranking and security response triggering unit ranks the acquired abnormal traffic priority Py;

[0103] The ranking process adopts descending order ranking, and the abnormal traffic with higher priority will be processed first;

[0104] The ranking formula is as follows:

[0105] ;

[0106] In the formula, Sort (Py) represents the ranking order;

[0107] After ranking, the countermeasures are triggered based on the abnormal traffic priority Py;

[0108] The countermeasures are classified according to the preset priority threshold TPth:

[0109] The classification level is matched and obtained by the following way:

[0110] When the abnormal traffic priority Py is greater than or equal to 2 times the priority threshold TPth, it represents the first priority, high priority, triggers isolation and alarm, disconnects the flow and notifies the security personnel;

[0111] When the abnormal traffic priority Py is greater than or equal to 1.5 times the priority threshold TPth, it represents the second priority, medium priority, triggers access restriction, and access control is performed on the affected traffic

[0112] When the abnormal traffic priority Py is greater than or equal to the priority threshold TPth, it represents the third priority, low priority, triggers monitoring and analysis, and observes and collects data on the flow.

[0113] Preferably, the feedback and model optimization module includes an abnormal traffic feedback and sample re-labeling unit and a model updating and optimization unit;

[0114] The abnormal flow feedback and sample re-labeling unit re-labels the detected abnormal flow based on the abnormal flow priority Py, adjusts the sample label, and obtains a new label nyi of the feedback sample;

[0115] The new label nyi of the feedback sample is obtained by matching in the following way:

[0116] ;

[0117] In the formula, flow is normal indicates normal flow, flow is abnormal indicates abnormal flow, and flow is uncertain and needs further analysis indicates uncertain flow and needs further analysis.

[0118] Preferably, the model updating and optimization unit updates the flow anomaly detection model MTR according to the obtained abnormal flow priority Py and the new label nyi, and obtains an updated flow anomaly detection model nMTR;

[0119] The updated flow anomaly detection model nMTR is obtained by the following formula:

[0120] ;

[0121] In the formula, Train represents a model training function, and Dfe represents a network data set DW and a new label nyi.

[0122] A multi-dimensional network security situation awareness method, comprising the following steps:

[0123] Step one: the data acquisition and preprocessing module acquires network flow data from the firewall, IDS and IPS in the network in real time, fits into an original data set DM, and pre-processes to obtain a network data set DW;

[0124] Step two: the feature extraction and multi-dimensional analysis module extracts features from the obtained network data set DW, and performs multi-dimensional analysis on the extracted features to form a structured feature data set DF;

[0125] Step three: the abnormal detection model training module trains the feature data set DF by using a support vector machine algorithm, and establishes a flow anomaly detection model MTR;

[0126] Step four: the real-time flow monitoring and abnormal detection module detects abnormal flow by using the flow anomaly detection model MTR, judges whether there is abnormal flow, and obtains an abnormal score Sy and a risk index Ry;

[0127] Step five: the abnormal traffic evaluation and priority sorting module calculates the abnormal traffic priority Py according to the obtained abnormal score Sy and risk index Ry;

[0128] Step six: the feedback and model optimization module updates the traffic anomaly detection model MTR according to the obtained abnormal traffic priority Py, and obtains the updated traffic anomaly detection model nMTR.

[0129] The application provides a network security situation awareness system and method based on multiple dimensions, which has the following beneficial effects:

[0130] (1) When the system is running, the abnormal field cleaning and abnormal point elimination module effectively eliminates invalid information in the collected data. Address filtering, protocol missing processing and abnormal point elimination ensure the reliability of data quality and avoid the interference of invalid or error data on subsequent processing and analysis. This can greatly reduce the false positive rate and false negative rate, improve the accuracy and reliability of system detection. Through field normalization processing, including normalization of port number and packet size SΩ, this module converts data of different sources and units into a unified standard format, thereby eliminating the inconsistency problem caused by different data scales. This not only improves the comparability of data, but also provides uniform and standardized data input for machine learning model training, helping to improve the stability and prediction accuracy of the model.

[0131] (2) Through feature fusion, all-round analysis and decision can be made according to multiple dimensional features, reducing the limitations and deviations caused by single feature or single model, and enhancing the robustness and flexibility of detection. Through real-time feature extraction and window mechanism, the system can respond to the change of network traffic in an instant and capture possible abnormal behavior in time. Since the sliding window and dynamic analysis method are adopted, the system can continuously evaluate real-time traffic without waiting for a large amount of data accumulation, which greatly improves the real-time performance and response speed of the system.

[0132] Through the integration of multiple dimensional features, this module provides a high-quality input data set DF for subsequent anomaly detection models, thereby improving the training effect and accuracy of the model. Since the integrated feature data set is more comprehensive and standardized, subsequent anomaly detection, model training and optimization can obtain more stable and reliable results.

[0133] (3) Through the training sample construction unit, the system can select and manually label the training samples based on the feature data set DF, thereby providing accurate training data for the support vector machine model. This combination of manual labeling and automatic learning enables the system to accurately distinguish between normal traffic and abnormal traffic, and to build a more accurate traffic anomaly detection model on this basis. Through the support vector machine training unit, the traffic anomaly detection model MTR is trained using the support vector machine algorithm, which can effectively distinguish between normal and abnormal traffic by maximizing the classification interval. With the introduction of high-dimensional mapping and kernel functions, SVM has the ability to non-linearly separate, enabling the system to identify more complex and diverse attack patterns. The trained model has strong generalization ability and can adapt to new attack methods and network environments.

[0134] (4) Through the abnormal traffic comprehensive score calculation unit, the system can calculate the accurate priority Py for each abnormal traffic by combining the abnormal score Sy, the risk index Ry, the data packet influence factor Iy, and the duration factor Dy. This comprehensive evaluation method enables the system to comprehensively consider the abnormality degree of traffic, the potential threat to the system, and the duration, thereby ensuring that the risk assessment of each traffic is fully considered and the accuracy of abnormal traffic detection is improved.

[0135] Through the abnormal traffic ranking and security response triggering unit, the system sorts the calculated traffic priority Py in descending order and classifies the traffic events according to the preset priority threshold TPth. By ranking the traffic events according to priority, the system can prioritize the most urgent security threats, ensuring that security personnel can respond to the most important events in a timely manner, improving response efficiency and timeliness. According to the traffic priority, the system can intelligently trigger different levels of response measures, such as isolation and alarm, access restriction, monitoring and analysis, etc. This hierarchical response mechanism ensures that the system can take appropriate response measures when facing abnormal traffic of different threat levels, avoiding excessive response or lack of timely response, improving the security and flexibility of the system. BRIEF DESCRIPTION OF DRAWINGS

[0136] Figure 1 A flowchart of the system block diagram of the present application based on multi-dimensional network security situation awareness;

[0137] Figure 2 A flowchart of the method steps of the present application based on multi-dimensional network security situation awareness;

[0138] Figure 3 A flowchart of the traffic anomaly model construction of the present application;

[0139] Figure 4 An abnormal traffic priority line graph of the present application. DETAILED DESCRIPTION

[0140] The technical solutions in the embodiments of the present application will be apparently and completely described in connection with the drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments of the present application, all the other embodiments obtained by a person of ordinary skill in the art without any creative work fall within the protection scope of the present application.

[0141] Embodiment 1

[0142] The present application provides a network security situation awareness system based on multi-dimension, please refer to Figures 1 to 4 , comprising a data acquisition and preprocessing module, a feature extraction and multi-dimension analysis module, an abnormal detection model training module, a real-time traffic monitoring and abnormal detection module, an abnormal traffic evaluation and priority sorting module and a feedback and model optimization module.

[0143] The data acquisition and preprocessing module acquires network traffic data from the firewall, IDS and IPS in the network in real time, fits into an original data set DM, and performs preprocessing to obtain a network data set DW.

[0144] The feature extraction and multi-dimension analysis module performs feature extraction on the obtained network data set DW, and performs multi-dimension analysis on the extracted features to form a structured feature data set DF.

[0145] The abnormal detection model training module trains the feature data set DF by using a support vector machine algorithm to establish a traffic anomaly detection model MTR.

[0146] The real-time traffic monitoring and abnormal detection module performs abnormal detection on real-time traffic data by using the traffic anomaly detection model MTR, judges whether there is abnormal traffic, and obtains an abnormal score Sy and a risk index Ry.

[0147] The abnormal traffic evaluation and priority sorting module calculates an abnormal traffic priority Py according to the obtained abnormal score Sy and risk index Ry.

[0148] The feedback and model optimization module updates the traffic anomaly detection model MTR according to the obtained abnormal traffic priority Py to obtain an updated traffic anomaly detection model nMTR.

[0149] In this embodiment, through the feature extraction and multi-dimensional analysis module, the system can extract multi-dimensional features from real-time collected traffic data and conduct comprehensive analysis. This approach avoids the shortcomings of traditional methods that rely on single features, enabling the system to more comprehensively understand the behavior patterns of network traffic, thereby enhancing the ability to identify complex and unknown attacks. The real-time traffic monitoring and anomaly detection module combined with the support vector machine learning algorithm can automatically analyze and determine whether real-time traffic is abnormal. The system's automated detection capability reduces the need for human intervention and enables rapid response when attacks occur, allowing timely alarm processing and preventing the spread of attacks.

[0150] Through the feedback and model optimization module, the system can update and optimize the traffic anomaly detection model in real time according to the priority and risk index of abnormal traffic. This feedback mechanism ensures that the model can continuously adapt to new attack patterns and traffic characteristics, thereby maintaining high-precision detection capabilities and improving the long-term stability of the system.

[0151] The abnormal traffic evaluation and priority sorting module can assign reasonable priorities to each traffic event by integrating abnormal score Sy and risk index Ry and other key factors, and present high-priority events to security personnel first. This function enhances the intelligent response capability of the system, enabling security personnel to more efficiently handle the most urgent security threats and avoiding the over-alarming or neglecting of potential threats in traditional systems.

[0152] Through incremental learning and adaptive adjustment, the system can continuously optimize detection accuracy without increasing hardware resources. This feature effectively reduces the system's operational costs while improving the model's flexibility, adapting to the needs of large-scale network environments. The system's self-learning ability through continuous acquisition of new traffic data and real-time optimization enables the multi-dimensional network security situation awareness system to evolve and possess high robustness and accuracy when facing increasingly complex network attacks. This continuous learning capability is unmatched by traditional static rule detection systems.

[0153] Embodiment 2

[0154] This embodiment is an explanation and description in Embodiment 1, please refer to Figure 1 , specifically: the data acquisition and preprocessing module includes a multi-source network data acquisition unit and a data preprocessing unit;

[0155] The multi-source network data acquisition unit collects network traffic data through a firewall, a NetFlow device, an sFlow device, a network probe, a port mirror and a packet capture tool and a system-level packet capture tool in the network, including source IP address IPs, target IP address IPm, source port number PDs, target port number PDm, protocol type XY, packet size SΩ and timestamp ST, and fits the original data set DM;

[0156] Among them, the source IP address IPs and the target IP address IPm are collected and obtained through the network probe and the NetFlow device:

[0157] The source port number PDs and the target port number PDm are collected and obtained through the sFlow device and the network probe;

[0158] The protocol type XY is collected and obtained through the firewall and the network probe;

[0159] The packet size SΩ is collected and obtained through the port mirror and the packet capture tool;

[0160] The timestamp ST is collected and obtained through the system-level packet capture tool and the network probe;

[0161] The data preprocessing unit pre-processes the obtained original data set DM, including abnormal field cleaning and field normalization processing, to obtain the network data set DW;

[0162] The abnormal field cleaning includes address filtering, protocol missing processing and abnormal point elimination on the original data set DM;

[0163] The address filtering is verified by using format legality verification to check whether it is a legal IPv4 and IPv6 address;

[0164] The protocol missing processing eliminates the protocol in the original data set DM through a reverse back-propagation method;

[0165] The abnormal point elimination eliminates the non-monotonic increasing timestamp ST in the original data set DM through an abnormal detection algorithm;

[0166] The field normalization processing includes port field normalization processing and packet size field normalization processing on the original data set DM;

[0167] The port field normalization processing unifies the numerical scale under the same dimensionless through numerical range verification;

[0168] The packet size field normalization processing normalizes the network data set DW by using the minimum-maximum normalization method.

[0169] In this embodiment, through abnormal field cleaning and abnormal point elimination, the module effectively eliminates the useless information in the collected data. Address filtering, protocol missing processing and abnormal point elimination ensure the reliability of data quality, avoiding the interference of invalid or error data on subsequent processing and analysis. This can greatly reduce the false positive rate and false negative rate, and improve the accuracy and reliability of system detection. Through field normalization processing, including the normalization of port number and packet size SΩ, the module converts data of different sources and units into a unified standard format, thereby eliminating the inconsistency problem caused by different data scales. This not only improves the comparability of data, but also provides uniform and standardized data input for machine learning model training, helping to improve the stability and prediction accuracy of the model.

[0170] Through automated abnormal field cleaning and data normalization, the need for manual intervention is reduced, and the efficiency of data processing is improved. The introduction of automated processing not only saves a lot of manual cost, but also improves the real-time response capability of the system, ensuring the efficiency and real-time performance of data preprocessing, especially suitable for large-scale and high-frequency traffic data processing scenarios. By introducing flexible cleaning and preprocessing methods, the module can be optimized for different types of network environments, enhancing the adaptability of the system. Whether it is facing traditional network traffic data or new protocols or data of different network structures, the system can quickly adjust to continuously provide effective input data for subsequent modules.

[0171] Embodiment 3

[0172] This embodiment is an explanation and description in embodiment 2, please refer to Figure 1 and Figure 3 , specifically: the feature extraction and multi-dimensional analysis module includes a network behavior feature extraction unit and a multi-dimensional feature correlation analysis unit;

[0173] The network behavior feature extraction unit extracts features from the network data set DW, including traffic statistical features F1, time features F2, host behavior features F3, communication directionality features F4, and session density features F5.

[0174] Traffic statistical features F1 are obtained by the following formula:

[0175] ;

[0176] In the formula, F1(k) represents the total traffic in the sliding window k, k represents the starting index of the sliding window, L represents the length of the sliding window, SΩ j represents the packet size of the jth data;

[0177] Time features F2 are obtained by the following formula:

[0178] ;

[0179] In the formula, F2(T) represents the data packet arrival frequency in the time window T, T represents the time window length, STj represents the time stamp of the jth data, STn represents the time stamp corresponding to the current index n, and {j |...} represents a data record set satisfying the time condition;

[0180] The host behavior feature F3 is obtained by the following formula:

[0181] ;

[0182] In the formula, F3IPs(T) represents the connection frequency density of the source IP address IPs in the time window T, IPSj represents the source IP address of the jth data, and IPSn represents the source IP address corresponding to the current index n;

[0183] The communication direction feature F4 is obtained by the following formula:

[0184] ;

[0185] In the formula, F4(IPo) represents the communication proportion of the host IPo, IPo represents the analyzed host IP address, c represents a positive number, represents the total number of inbound traffic bytes of all targets for IPo represents the total number of outbound traffic bytes from IPo;

[0186] The session density feature F5 is obtained by the following formula:

[0187] ;

[0188] In the formula, F5(k) represents the traffic change rate of the sliding window k, and μF(k) represents the average traffic;

[0189] The multi-dimensional feature correlation analysis unit constructs a composite feature FH by multiplying and interacting different types of features;

[0190] The composite feature FH is obtained by the following formula:

[0191] ;

[0192] In the formula, FH(F5, F4) represents the composite feature considering the communication direction and the session density, and B represents a neutral offset value, specifically 0.5;

[0193] The obtained traffic statistical feature F1, time feature F2, host behavior feature F3, communication direction feature F4, session density feature F5, and composite feature FH are integrated to obtain a feature data set DF.

[0194] In this embodiment, the system extracts various features including traffic statistics, time, host behavior, communication directionality, and session density from the network traffic dataset through the network behavior feature extraction unit. This multi-dimensional feature extraction method enables the system to comprehensively understand the behavior patterns of network traffic, rather than relying solely on single feature information. In this way, the system's detection capability for various complex and unknown attack patterns is significantly enhanced, improving the recognition rate of new attacks.

[0195] The network behavior feature extraction unit performs real-time statistical analysis of traffic through a sliding window, which can reflect the trend of network traffic changes and sudden events. This time window-based and real-time updating analysis method enables the system to dynamically adapt to different network behavior patterns, especially when facing large-scale data traffic, it can continuously monitor the changes in traffic and timely capture potential abnormal activities. This adaptive modeling approach greatly improves the sensitivity of traffic in different network environments. Through correlation analysis of multi-dimensional features, this module can construct composite features through product interaction, thereby enhancing the correlation between features. This approach can combine information from multiple dimensions to identify complex abnormal behaviors that conventional detection methods cannot capture.

[0196] Through feature fusion, comprehensive analysis and decision-making can be performed based on multi-dimensional features, reducing the limitations and biases caused by single features or single models, and enhancing the robustness and flexibility of detection. Through real-time feature extraction and window mechanism, the system can respond to changes in network traffic in an instant, capturing possible abnormal behavior in a timely manner. Due to the use of sliding window and dynamic analysis method, the system can continuously evaluate real-time traffic without waiting for a large amount of data to accumulate, which greatly improves the real-time performance and response speed of the system.

[0197] Through the integration of multiple dimensional features, this module provides a high-quality input dataset DF for subsequent anomaly detection models, thereby improving the training effect and accuracy of the model. Since the integrated feature dataset is more comprehensive and standardized, subsequent anomaly detection, model training and optimization can obtain more stable and reliable results.

[0198] Embodiment 4

[0199] This embodiment is an explanation and description in Embodiment 3, please refer to Figure 1 and Figure 3 , in particular: the anomaly detection model training module includes a training sample construction unit and a support vector machine training unit;

[0200] The training sample construction unit selects and manually labels the training sample of the obtained feature dataset DF, determines the normal label and abnormal label of each record, and constructs the training set for sample training.

[0201] The feature data set DF is set as:

[0202] ;

[0203] In the formula, Fi represents the i-th feature in the feature data set DF, and N represents the total number of features;

[0204] The label Y corresponding to the feature data set DF is:

[0205] ;

[0206] In the formula, yi represents a classification label, yi=+1 represents that the i-th feature is normal traffic, and yi=-1 represents that the i-th feature is abnormal traffic;

[0207] The support vector machine training unit trains the training set by using a support vector machine algorithm to obtain a generalizable traffic anomaly detection model MTR;

[0208] The obtaining step of the traffic anomaly detection model MTR is:

[0209] S1, find a set of parameters (w, b) to construct a hyperplane formula:

[0210] ;

[0211] ;

[0212] In the formula, w represents a weight vector, and b represents a bias term;

[0213] S2, for the parameters (w, b), use the constraint condition to maximize the classification interval, and the formula is as follows:

[0214] The constraint condition is: ;

[0215] In the formula, min represents a minimization operation, and ∀i represents that the constraint condition is true for all samples;

[0216] S3, map the i-th feature Fi in the feature data set DF to a high-dimensional space, and use a kernel function to realize a nonlinear classification capability, and the formula is as follows:

[0217] ;

[0218] In the formula, KS() represents a kernel function, Fa represents the a-th feature in the feature data set DF, exp() represents an exponential function, and γ represents a kernel function parameter;

[0219] S4, finally output the traffic anomaly detection model MTR:

[0220] MTR = (w, b, KS()).

[0221] The real-time traffic monitoring and anomaly detection module detects the traffic data in the network data set DW through the traffic anomaly detection model MTR, obtains an anomaly score Sy, and compares the anomaly score Sy with a preset anomaly threshold TSY to determine the abnormal state of the traffic.

[0222] The anomaly score Sy is obtained by the following formula:

[0223]

[0224] In the formula, Nks represents the number of support vectors, represents the i-th feature in the feature data set DF, represents the weight coefficient of the i-th feature, represents the feature vector constructed in the network data set DW;

[0225] The traffic is determined according to the obtained anomaly score Sy.

[0226] When sign(Sy) = +1, the traffic is determined to be normal traffic.

[0227] When sign(Sy) = -1, the traffic is determined to be abnormal traffic.

[0228] The abnormal state of the traffic is matched and obtained in the following way:

[0229] When the anomaly score Sy is less than or equal to the anomaly threshold TSY, it indicates that the determination result of the traffic is inaccurate.

[0230] When the anomaly score Sy is greater than the anomaly threshold TSY, it indicates that the determination result of the traffic is accurate.

[0231] The risk index Ry is obtained by using the confidence function ASy to calculate the anomaly score Sy, and the risk degree is determined by the risk index Ry.

[0232] The risk index Ry is obtained by the following formula:

[0233]

[0234] In the formula, exp represents the exponential function, Co represents the risk index expansion factor, represents the indicator function, which is only effective for abnormal traffic.

[0235] The risk degree of the abnormal traffic is matched and obtained in the following way:

[0236] ​​When 0 < risk index Ry≤ 0.5, it means that the abnormality degree is within the normal range, and there is no danger.

[0237] When 0.5 < risk index Ry< 1, it means that the abnormality degree is not within the normal range, and there is danger.

[0238] In this embodiment, the system can select and manually label training samples based on the feature data set DF through the training sample construction unit, thereby providing accurate training data for the support vector machine model. This combination of manual labeling and automatic learning enables the system to accurately distinguish between normal and abnormal traffic, and to build a more accurate traffic anomaly detection model based on this. Through the support vector machine training unit, the traffic anomaly detection model MTR is trained using the support vector machine algorithm, which can effectively distinguish between normal and abnormal traffic by maximizing the classification interval. With the introduction of high-dimensional mapping and kernel functions, SVM has the ability to non-linearly separate, enabling the system to recognize more complex and diverse attack patterns. The trained model has strong generalization ability and can adapt to new attack methods and network environments.

[0239] Through the real-time traffic monitoring and anomaly detection module, the model can detect anomalies in real-time network data and determine the abnormal state of the traffic based on the comparison of the anomaly score Sy and the anomaly threshold TSY. The determination of abnormal traffic is more accurate and real-time, and the risk index Ry calculated by the confidence function can further help determine the risk level of abnormal traffic. This method effectively reduces false positives and false negatives, improving the accuracy of anomaly detection.

[0240] Through comprehensive analysis of the anomaly score Sy and the risk index Ry, the system can assign different risk levels to each traffic event, guiding security personnel to prioritize high-risk traffic events. The introduction of the risk index enables the system not only to accurately determine whether the traffic is abnormal, but also to determine the risk level of abnormal traffic, helping security personnel make more effective response decisions.

[0241] The training and updating mechanism of the support vector machine model ensures that the system can continuously adapt to changes in network traffic, especially when faced with new attacks, the model can continuously improve detection accuracy through real-time learning and optimization. This adaptive learning ability makes the system long-term effective, avoiding the problem of decreased detection ability when facing changes in network environment. Through efficient training and real-time monitoring of the traffic anomaly detection model MTR, the system can achieve low resource consumption while analyzing large-scale network traffic in real time. This optimization ensures that the system can operate efficiently while ensuring detection accuracy, and adapt to complex large-scale network environments.

[0242] Embodiment 5

[0243] This embodiment is an explanation and illustration in embodiment 4, please refer to Figure 1 and Figure 4 , specifically: abnormal flow evaluation and priority sorting module includes abnormal flow comprehensive score calculation unit and abnormal flow sorting and security response triggering unit;

[0244] Abnormal flow comprehensive score calculation unit calculates abnormal flow priority Py according to the obtained abnormal score Sy and risk index Ry, combined with data packet influence factor Iy and duration factor Dy; as shown in table 1:

[0245] Abnormal flow priority Py is obtained by the following formula:

[0246] ;

[0247] In the formula, respectively represent the preset weight value of abnormal score Sy, risk index Ry, data packet influence factor Iy and duration factor Dy, and ;

[0248] Specific examples:

[0249] The preset weight value of the preset abnormal score Sy, risk index Ry, data packet influence factor Iy and duration factor Dy is 0.3, 0.25, 0.2 and 0.25 respectively;

[0250] Obtain abnormal score Sy=0.8;

[0251] Risk index Ry=0.7;

[0252] Data packet influence factor Iy=0.75;

[0253] Duration factor Dy=0.9;

[0254] Calculate the abnormal flow priority Py:

[0255] ;

[0256] Table 1 abnormal flow priority calculation table:

[0257]

[0258] Data packet influence factor Iy reflects the potential influence degree of flow data packet on system security, and the importance of data packet is evaluated according to data packet size SΩ;

[0259] Data packet influence factor Iy is obtained by the following formula:

[0260] ;

[0261] In the formula, maxSΩ represents the maximum data packet size set;

[0262] The duration factor Dy measures the duration of network traffic anomalies, and long-duration abnormal traffic poses a threat to the system;

[0263] The duration factor Dy is obtained by the following formula:

[0264]

[0265] In the formula, STs represents the timestamp of the start of the traffic anomaly event, and STmax represents the maximum allowed timestamp.

[0266] The abnormal traffic ranking and security response triggering unit ranks the obtained abnormal traffic priority Py;

[0267] The ranking process adopts descending order ranking, and the abnormal traffic with higher priority will be processed first;

[0268] The ranking formula is as follows:

[0269]

[0270] In the formula, Sort(Py) represents the ranking order;

[0271] After ranking is completed, countermeasures are triggered based on the abnormal traffic priority Py;

[0272] The countermeasures are classified according to the preset priority threshold TPth:

[0273] The classification level is matched and obtained by the following method:

[0274] When the abnormal traffic priority Py is greater than or equal to 2 times the priority threshold TPth, it represents the first priority, triggering isolation and alarm, disconnecting the traffic and notifying the security personnel;

[0275] When the abnormal traffic priority Py is greater than or equal to 1.5 times the priority threshold TPth, it represents the second priority, triggering access restriction, and performing access control on the affected traffic;

[0276] When the abnormal traffic priority Py is greater than or equal to the priority threshold TPth, it represents the third priority, triggering monitoring and analysis, observing the traffic and collecting data.

[0277] The feedback and model optimization module includes an abnormal traffic feedback and sample re-labeling unit and a model updating and optimization unit;

[0278] ​​The abnormal flow feedback and sample re-labeling unit re-labels the detected abnormal flow based on the abnormal flow priority Py, adjusts the sample label, and obtains a new label nyi of the feedback sample;

[0279] The new label nyi of the feedback sample is obtained by matching in the following way:

[0280] ;

[0281] In the formula, flow is normal indicates normal flow, flow is abnormal indicates abnormal flow, and flow is uncertain and needs further analysis indicates uncertain flow and needs further analysis.

[0282] The model updating and optimization unit updates the flow anomaly detection model MTR according to the obtained abnormal flow priority Py and the new label nyi, and obtains an updated flow anomaly detection model nMTR;

[0283] The updated flow anomaly detection model nMTR is obtained by the following formula:

[0284] ;

[0285] In the formula, Train represents a model training function, and Dfe represents a network dataset DW and a new label nyi.

[0286] In this embodiment, the abnormal flow comprehensive score calculation unit combines the abnormal score Sy, the risk index Ry, the data packet influence factor Iy, and the duration factor Dy to calculate an accurate priority Py for each abnormal flow. This comprehensive evaluation method enables the system to comprehensively consider the abnormality degree of the flow, the potential threat to the system, and the duration, thereby ensuring that the risk assessment of each flow is fully considered and improving the accuracy of abnormal flow detection.

[0287] Through the abnormal flow ranking and security response triggering unit, the system sorts the calculated flow priority Py in descending order and classifies the flow events according to the preset priority threshold TPth. By sorting the flow events according to the priority, the system can prioritize the most urgent security threats, ensuring that security personnel can respond to the most important events in a timely manner, improving response efficiency and timeliness. According to the flow priority, the system can intelligently trigger different levels of response measures, such as isolation and alarm, access restriction, monitoring and analysis, etc. This hierarchical response mechanism ensures that the system can take appropriate response measures when facing abnormal flows of different threat levels, avoiding excessive response or lack of timely response, improving the security and flexibility of the system.

[0288] Through the feedback and model optimization module, the system recalibrates the sample according to the detected abnormal traffic and priority Py, and updates the traffic anomaly detection model MTR through the new label nyi. This priority-based feedback mechanism enables the model to self-optimize and continuously learn in actual operation, calmly cope with new attack patterns and traffic characteristics, and enhances the adaptive ability and intelligent level of the system.

[0289] Through incremental learning and self-feedback, the updated traffic anomaly detection model nMTR can continuously optimize with the changes of traffic data, ensuring that the model still maintains high detection accuracy when facing new traffic patterns or attack methods. The optimization ability of the system not only improves the robustness of detection, but also reduces the need for human intervention and reduces maintenance costs.

[0290] Embodiment 6

[0291] A multi-dimensional network security situation awareness method, please refer to Figure 2 , Specifically: including the following steps:

[0292] Step one: the data acquisition and preprocessing module collects network traffic data from the firewall, IDS and IPS in the network in real time, fits into the original data set DM, and performs preprocessing to obtain the network data set DW;

[0293] Step two: the feature extraction and multi-dimensional analysis module extracts features from the obtained network data set DW, and performs multi-dimensional analysis on the extracted features to form a structured feature data set DF;

[0294] Step three: the abnormal detection model training module trains the feature data set DF by using the support vector machine algorithm to establish the traffic anomaly detection model MTR;

[0295] Step four: the real-time traffic monitoring and anomaly detection module uses the traffic anomaly detection model MTR to detect abnormal traffic in real-time traffic data, judges whether there is abnormal traffic, and obtains the abnormal score Sy and the risk index Ry;

[0296] Step five: the abnormal traffic evaluation and priority sorting module calculates the abnormal traffic priority Py according to the obtained abnormal score Sy and risk index Ry;

[0297] Step six: the feedback and model optimization module updates the traffic anomaly detection model MTR according to the obtained abnormal traffic priority Py, and obtains the updated traffic anomaly detection model nMTR.

[0298] In this embodiment, through the data acquisition and preprocessing module, the method collects network traffic data in real time from various devices such as firewalls, IDS, and IPS in the network, and performs preprocessing. This multi-source data acquisition method ensures the comprehensiveness and high quality of network traffic data, thereby providing accurate basic data for subsequent feature extraction and analysis. Through cleaning and formatting, the system can remove redundant data, filter outliers, improve data quality, and ensure the efficiency and accuracy of subsequent processing.

[0299] Through the feature extraction and multi-dimensional analysis module, the method can extract multi-dimensional features including traffic statistics, time, host behavior, communication directionality, etc. from the original traffic data and perform in-depth analysis. This multi-dimensional feature extraction method not only improves the system's comprehensive understanding of network behavior, but also enhances the model's ability to identify complex network attacks. The introduction of this module significantly improves the response capability to new attack behaviors, and can analyze data from multiple dimensions to accurately identify potential abnormal traffic.

[0300] Through the feedback and model optimization module, the method realizes the continuous optimization and adaptive learning of the model. After detecting abnormal traffic each time, the system will feedback according to the priority of abnormal traffic, adjust the sample label and update the model. Through this feedback mechanism, the system can dynamically adjust and optimize the detection model according to the new network environment and attack mode, ensuring that it can still maintain high identification ability when facing new attacks. The updated traffic anomaly detection model nMTR can continuously improve accuracy and response speed, reduce false positives and false negatives. By integrating data acquisition, feature extraction, anomaly detection, priority evaluation, and model optimization modules, this method provides a comprehensive, real-time, and intelligent network security situation awareness system. The system can monitor traffic in real time, accurately identify potential attacks, and automatically respond according to threat levels, improving the overall network security protection capability. Through continuous optimization and self-learning, the system can adapt to the changing network security environment and maintain efficient monitoring and defense capabilities.

[0301] Although embodiments of the present application have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made therein without departing from the principles and spirit of the application, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A multi-dimensional based cyber security situation awareness system, characterized in that: The system comprises a data collection and preprocessing module, a feature extraction and multi-dimensional analysis module, an anomaly detection model training module, a real-time traffic monitoring and anomaly detection module, an abnormal traffic evaluation and priority sorting module, and a feedback and model optimization module. The data collection and preprocessing module collects network traffic data from firewalls, IDSs and IPSs in the network in real time, fits the data into an original data set DM, and pre-processes the data to obtain a network data set DW. The feature extraction and multi-dimensional analysis module extracts features from the obtained network data set DW, and performs multi-dimensional analysis on the extracted features to form a structured feature data set DF. The feature extraction and multi-dimensional analysis module comprises a network behavior feature extraction unit and a multi-dimensional feature correlation analysis unit. The network behavior feature extraction unit extracts features from the network data set DW, including traffic statistical features F1, time features F2, host behavior features F3, communication directionality features F4, and session density features F5. The traffic statistical features F1 are obtained by the following formula: ; In the formula, F1(k) represents the total flow within the sliding window k, k represents the starting index of the sliding window, L represents the length of the sliding window, SΩ j represents the data packet size of the jth data; The time features F2 are obtained by the following formula: ; In the formula, F2(T) represents the data packet arrival frequency within a time window T, T represents the time window length, STj represents the timestamp of the jth data, STn represents the timestamp corresponding to the current index n, and {j|...} represents a set of data records satisfying the time condition. The host behavior features F3 are obtained by the following formula: ; In the formula, F3IPs(T) represents the connection frequency density of the source IP address IPs within a time window T, IPSj represents the source IP address of the jth data, and IPsn represents the source IP address corresponding to the current index n. The communication directionality features F4 are obtained by the following formula: ; where F4(IP0) represents the fraction of traffic from host IP0, IP0 represents the host IP address being analyzed, and c represents a positive number, represents the total number of bytes of inbound traffic destined for IP0 represents the total number of bytes of outbound traffic originating from IP0; The session density features F5 are obtained by the following formula: ; In the formula, F5(k) represents the traffic change rate of a sliding window k, and μF(k) represents the average traffic. The multi-dimensional feature correlation analysis unit constructs a composite feature FH by multiplying and interacting different types of features. The composite feature FH is obtained by the following formula: ; In the formula, FH(F5, F4) represents a composite feature considering communication direction and session density, and B represents a neutral offset value. The obtained traffic statistical features F1, time features F2, host behavior features F3, communication directionality features F4, session density features F5, and composite features FH are integrated to obtain the feature data set DF. The anomaly detection model training module trains the feature data set DF using a support vector machine algorithm to establish a traffic anomaly detection model MTR. The real-time traffic monitoring and anomaly detection module uses the traffic anomaly detection model MTR to detect anomalies in real-time traffic data, determines whether there is abnormal traffic, and obtains an abnormal score Sy and a risk index Ry. The abnormal traffic evaluation and priority sorting module calculates the abnormal traffic priority Py based on the obtained abnormal score Sy and risk index Ry. The feedback and model optimization module updates the traffic anomaly detection model MTR based on the obtained abnormal traffic priority Py to obtain an updated traffic anomaly detection model nMTR.

2. The multi-dimensional based cyber security situation awareness system of claim 1, wherein: The data acquisition and preprocessing module comprises a multi-source network data acquisition unit and a data preprocessing unit. The multi-source network data acquisition unit acquires network traffic data through a firewall, a NetFlow device, an sFlow device, a network probe, a port mirror and a packet capture tool and a system-level packet capture tool, including source IP addresses IPs, target IP addresses IPm, source port numbers PDs, target port numbers PDm, protocol types XY, packet sizes SΩ and timestamps ST, and fitting an original data set DM; The source IP addresses IPs and the target IP addresses IPm are acquired through the network probe and the NetFlow device; The source port numbers PDs and the target port numbers PDm are acquired through the sFlow device and the network probe; The protocol types XY are acquired through the firewall and the network probe; The packet sizes SΩ are acquired through the port mirror and the packet capture tool; The timestamps ST are acquired through the system-level packet capture tool and the network probe; The data preprocessing unit preprocesses the acquired original data set DM, including abnormal field cleaning and field normalization processing, to obtain a network data set DW; The abnormal field cleaning comprises address filtering, protocol missing processing and abnormal point elimination on the original data set DM; The address filtering uses format legality verification to check whether it is a legal IPv4 and IPv6 address; The protocol missing processing eliminates the protocol in the original data set DM through a reverse back-propagation method; The abnormal point elimination eliminates the non-monotonic increasing timestamp ST in the original data set DM through an anomaly detection algorithm; The field normalization processing comprises port field normalization processing and packet size field normalization processing on the original data set DM; The port field normalization processing unifies the numerical scale under the same dimensionless through numerical range verification; The packet size field normalization processing normalizes the network data set DW through the minimum-maximum normalization method.

3. The multi-dimensional based cyber security situation awareness system of claim 1, wherein: The anomaly detection model training module comprises a training sample construction unit and a support vector machine training unit; The training sample construction unit selects and manually labels training samples from the acquired feature data set DF, determines the normal label and the abnormal label of each record, and constructs a training set for sample training; The feature data set DF is set as: ; wherein Fi represents the ith feature in the feature data set DF, and N represents the total number of features; The label Y corresponding to the feature data set DF is: ; wherein yi represents the classification label, yi=+1 represents that the ith feature is normal traffic, and yi=-1 represents that the ith feature is abnormal traffic; The support vector machine training unit trains the training set using a support vector machine algorithm to obtain a generalizable traffic anomaly detection model MTR; The steps for obtaining the traffic anomaly detection model MTR are: S1, find a set of parameters (w, b) to construct a hyperplane formula: ; ; wherein w represents the weight vector, and b represents the bias term; S2, for the parameters (w, b), use the constraint condition to maximize the classification interval, and the formula is as follows: , constraints: ; wherein min represents the minimum operation, and ∀i represents that the constraint condition is true for all samples. S3, mapping the i-th feature Fi in the feature dataset DF to a high-dimensional space and using a kernel function to realize nonlinear classification capability, as follows: ; In the formula, KS() represents the kernel function, Fa represents the a-th feature in the feature dataset DF, exp() represents the exponential function, and γ represents the kernel function parameter; S4, finally outputting the traffic anomaly detection model MTR: MTR=(w, b, KS()).

4. The multi-dimensional based cyber security situation awareness system of claim 3, wherein: The real-time traffic monitoring and anomaly detection module performs anomaly detection on the traffic data in the network dataset DW through the traffic anomaly detection model MTR, obtains an anomaly score Sy, and compares the anomaly score Sy with a preset anomaly threshold TSY to determine the abnormal state of the traffic; The anomaly score Sy is obtained by the following formula: ; where Nks represents the number of support vectors, represents the support vector of the i-th feature in the feature dataset DF, represents the weight coefficient of the support vector of the i-th feature, represents the constructed feature vector in the network dataset DW; According to the obtained anomaly score Sy, the traffic is determined; When sign(Sy)=+1, it is determined that the traffic is normal traffic; When sign(Sy)=-1, it is determined that the traffic is abnormal traffic; The abnormal state of the traffic is matched and obtained in the following way: When the anomaly score Sy is less than or equal to the anomaly threshold TSY, it indicates that the determination result of the traffic is inaccurate; When the anomaly score Sy is greater than the anomaly threshold TSY, it indicates that the determination result of the traffic is accurate; The risk index Ry is obtained by using the confidence function ASy to calculate the anomaly score Sy, and the risk degree is determined by the risk index Ry; The risk index Ry is obtained by the following formula: ; where exp denotes the exponential function, Co denotes the risk index expansion factor, denotes the indicator function, which only takes effect for abnormal traffic; The risk degree of abnormal traffic is matched and obtained in the following way: When 0 The abnormal traffic evaluation and priority sorting module includes an abnormal traffic comprehensive score calculation unit and an abnormal traffic sorting and security response triggering unit; 5. The multi-dimensional based cyber security situation awareness system of claim 1, wherein: The abnormal traffic comprehensive score calculation unit calculates and obtains the abnormal traffic priority Py according to the obtained anomaly score Sy and risk index Ry, and in combination with the data packet influence factor Iy and the duration factor Dy; The abnormal traffic priority Py is obtained by the following formula: The data packet influence factor Iy reflects the potential influence degree of the traffic data packet on the system security, and the importance of the data packet is evaluated according to the data packet size SΩ; ; wherein, respectively represent preset weight values of the abnormal score Sy, the risk index Ry, the data packet influence factor Iy, and the duration factor Dy, and ; The data packet influence factor Iy is obtained by the following formula: In the formula, maxSΩ represents the maximum data packet size set; ; The duration factor Dy measures the duration of network traffic anomaly, and the abnormal traffic that lasts for a long time poses a threat to the system; The duration factor Dy is obtained by the following formula: In the formula, STs represents the time stamp of the start of the traffic anomaly event, and STmax represents the maximum time stamp allowed. ; The abnormal traffic sorting and security response triggering unit sorts the obtained abnormal traffic priority Py; 6. The multi-dimensional based cyber security situation awareness system of claim 5, wherein: The sorting process adopts descending order sorting, and the abnormal traffic with higher priority will be processed first; The sorting formula is as follows: In the formula, Sort(Py) represents the sorting order; ; After sorting, countermeasures are triggered based on the abnormal traffic priority Py; The countermeasures are classified according to the preset priority threshold TPth: The classification level is matched and obtained in the following way: ​ When the abnormal traffic priority Py is greater than or equal to 2 times the priority threshold TPth, it indicates the first priority, triggers isolation and alarm, disconnects the traffic and notifies the security personnel; When the abnormal traffic priority Py is greater than or equal to 1.5 times the priority threshold TPth, it indicates the second priority, triggers access restriction, and performs access control on the affected traffic; When the abnormal traffic priority Py is greater than or equal to the priority threshold TPth, it indicates the third priority, triggers monitoring and analysis, and performs observation and data collection on the traffic.

7. The multi-dimensional based cyber security situation awareness system of claim 6, wherein: The feedback and model optimization module includes an abnormal traffic feedback and sample re-labeling unit and a model updating and optimization unit; The abnormal traffic feedback and sample re-labeling unit re-labels the detected abnormal traffic based on the abnormal traffic priority Py, adjusts the sample label, and obtains the new label nyi of the feedback sample; The new label nyi of the feedback sample is obtained by matching in the following way: ; Where, flow is normal indicates normal traffic, flow is abnormal indicates abnormal traffic, and flow is uncertain and needs further analysis indicates uncertain traffic that needs further analysis.

8. The multi-dimensional based cyber security situation awareness system of claim 7, wherein: The model updating and optimization unit updates the traffic anomaly detection model MTR according to the obtained abnormal traffic priority Py and new label nyi, and obtains the updated traffic anomaly detection model nMTR; The updated traffic anomaly detection model nMTR is obtained by the following formula: ; Where, Train represents the model training function, and Dfe represents the network dataset DW and the new label nyi. 9.A method for multi-dimensional cyber security situation awareness, applied to the multi-dimensional cyber security situation awareness system of any one of claims 1-8. The method includes the following steps: Step one: the data acquisition and preprocessing module collects network traffic data in real time from the firewall, IDS and IPS in the network, fits the original data set DM, and performs preprocessing to obtain the network dataset DW; Step two: the feature extraction and multi-dimensional analysis module extracts features from the obtained network dataset DW, and performs multi-dimensional analysis on the extracted features to form a structured feature dataset DF; Step three: the abnormal detection model training module trains the feature dataset DF using a support vector machine algorithm to establish a traffic anomaly detection model MTR; Step four: the real-time traffic monitoring and anomaly detection module uses the traffic anomaly detection model MTR to detect anomalies in real-time traffic data, determines whether there is abnormal traffic, and obtains the abnormal score Sy and risk index Ry; Step five: the abnormal traffic evaluation and priority sorting module calculates the abnormal traffic priority Py according to the obtained abnormal score Sy and risk index Ry; Step six: the feedback and model optimization module updates the traffic anomaly detection model MTR according to the obtained abnormal traffic priority Py, and obtains the updated traffic anomaly detection model nMTR.

Citation Information

Patent Citations

  • Network security situation awareness method and device based on abnormal flow detection

    CN110769007A

  • Network security situation generation method based on multi-view monitoring

    CN119583219A