Network security threat monitoring and early warning method and system

By building a threat monitoring model and collecting and processing multi-source data, security threat classification and level warning response are carried out, which solves the problem of the inability to respond at a graded level in existing technologies and realizes efficient and accurate network security threat monitoring and warning.

CN120768569APending Publication Date: 2025-10-10NAVAL UNIV OF ENG PLA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510683668.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

In the existing technology, network security threat monitoring and early warning methods are unable to classify security threats, resulting in the inability to provide different early warning responses according to different security threat levels, making it difficult to meet the efficiency, accuracy and flexibility requirements of modern network security protection.

Method used

By acquiring historical threat data to build a threat monitoring model, multi-source data collection and preprocessing are performed on the target network, standard collection data is generated and imported into the threat monitoring model, threat monitoring results are output, security threat classification and level warning response are performed, threat warning records are generated and shared, and the threat sharing database is updated.

Benefits of technology

It realizes different early warning responses according to different security threat levels, meeting the efficiency, accuracy and flexibility requirements of modern network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768569A_ABST
    Figure CN120768569A_ABST
Patent Text Reader

Abstract

The invention relates to a network security threat monitoring and early warning method and system, and the method comprises the steps: obtaining historical threat data, and constructing and deploying a threat monitoring model; carrying out multi-source data acquisition on the target network to obtain multi-source acquisition data, and carrying out data preprocessing to generate standard acquisition data; importing the standard collection data into the threat monitoring model, and outputting a threat monitoring result; according to a threat monitoring result, performing security threat grading, determining a threat early warning grade, and performing grade early warning response; and generating and sharing a threat early warning record, and updating the threat shared database. According to the system, multi-source data acquisition and processing can be carried out, threat monitoring results are output through the threat monitoring model, threat early warning levels are determined, and level early warning responses are carried out, so that different early warning responses can be carried out according to different security threat levels, and the high-standard requirements of modern network security protection on high efficiency, accuracy and flexibility can be met.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a network security threat monitoring and early warning method and system. BACKGROUND

[0002] In the network security technology, the security threat monitoring is mainly based on the attack chain to construct external attack monitoring, and through multi-level association to locate and track, and finally to realize defense through linkage and defense. The internal state early warning model is constructed based on statistical analysis to timely find abnormal trend changes and produce early warning.

[0003] In the prior art, the traditional network security threat monitoring and early warning is often limited to following the preset and fixed process to perform the threat monitoring task, and cannot perform security threat grading, different early warning responses according to different security threat levels, and cannot meet the high standard requirements of modern network security protection for efficiency, accuracy and flexibility. SUMMARY

[0004] The present application provides a network security threat monitoring and early warning method and system to solve the technical problems in the prior art.

[0005] The technical solution of the present application to solve the above technical problems is as follows: a network security threat monitoring and early warning method, the method comprising the following steps: acquiring historical threat data, constructing and deploying a threat monitoring model; performing multi-source data collection on a target network, acquiring multi-source collection data, and performing data preprocessing to generate standard collection data; importing the standard collection data into the threat monitoring model to output threat monitoring results; performing security threat grading according to the threat monitoring results, determining threat early warning levels, and performing level early warning responses; generating and sharing threat early warning records, and updating a threat sharing database. As a further limitation of the technical scheme of the present application, the acquiring historical threat data, constructing and deploying a threat monitoring model specifically comprises the following steps: acquiring historical threat data; performing data division processing on the historical threat data according to a preset division ratio to obtain a training set and a test set; performing model training and testing through the training set and the test set to construct a threat monitoring model; deploying the threat monitoring model.

[0006] As a further limitation of the technical solution of the embodiment of the present invention, the step of collecting multi-source data on the target network, obtaining the multi-source collected data, and performing data preprocessing to generate standard collected data specifically includes the following steps: Collect multi-source data on the target network, including traffic, logs, assets, and vulnerability data; Deduplication processing is performed on the multi-source collected data to generate deduplication collected data; Eliminating invalid data from the deduplicated collected data to generate valid collected data; The effective collected data is standardized to generate standard collected data.

[0007] As a further limitation of the technical solution of the embodiment of the present invention, the security threat classification, determination of the threat warning level, and level warning response based on the threat monitoring results specifically include the following steps: Identify the threat monitoring results and extract key danger information; Based on the key risk information, security threat classification is performed to determine the threat warning level; Conducting level-linked defense according to the threat warning level; A threat level warning is issued according to the threat warning level.

[0008] As a further limitation of the technical solution of the embodiment of the present invention, generating and sharing threat warning records and updating the threat sharing database specifically include the following steps: Generate threat warning records; Sharing the threat warning record according to a preset shared address; Based on the threat warning record, the threat sharing database is updated.

[0009] A network security threat monitoring and early warning system, comprising a monitoring model building unit, a multi-source data acquisition unit, a monitoring result output unit, a graded early warning response unit, and a shared database update unit, wherein: A monitoring model building unit, used to obtain historical threat data, build and deploy threat monitoring models; The multi-source data acquisition unit is used to collect multi-source data from the target network, obtain the multi-source collected data, perform data preprocessing, and generate standard collected data; A monitoring result output unit, configured to import the standard collected data into the threat monitoring model and output threat monitoring results; A level warning response unit is used to classify security threats, determine threat warning levels, and respond to level warnings based on the threat monitoring results; The shared database update unit is used to generate and share threat warning records and update the threat sharing database.

[0010] As a further limitation of the technical solution of the embodiment of the present invention, the monitoring model building unit specifically includes: Data acquisition module, used to obtain historical threat data; A data partitioning module is used to perform data partitioning processing on the historical threat data according to a preset partitioning ratio to obtain a training set and a test set; A model building module is used to perform model training and testing using the training set and the test set to build a threat monitoring model; A model deployment module is used to deploy the threat monitoring model.

[0011] As a further limitation of the technical solution of the embodiment of the present invention, the multi-source data acquisition unit specifically includes: The data collection module is used to collect multi-source data on the target network and obtain multi-source collected data including traffic, logs, assets and vulnerability data; A deduplication processing module, configured to perform deduplication processing on the multi-source collected data to generate deduplication collected data; An invalid elimination module, used for eliminating invalid data from the deduplicated collected data to generate valid collected data; The standardization processing module is used to perform standardization processing on the effective collected data to generate standard collected data.

[0012] As a further limitation of the technical solution of the embodiment of the present invention, the level warning response unit specifically includes: An information extraction module, used to identify the threat monitoring results and extract key danger information; A threat classification module is used to classify security threats and determine threat warning levels based on the key risk information; A linkage defense module, configured to perform level-linked defense according to the threat warning level; The level warning module is used to issue a threat level warning according to the threat warning level.

[0013] As a further limitation of the technical solution of the embodiment of the present invention, the shared database updating unit specifically includes: A record generation module is used to generate threat warning records; A sharing processing module, configured to share the threat warning record according to a preset sharing address; The database updating module is used to update the threat sharing database based on the threat warning record.

[0014] The beneficial effects of the present invention are as follows: by acquiring historical threat data, a threat monitoring model is constructed and deployed; multi-source data is collected on the target network, multi-source collected data is obtained, and data preprocessing is performed to generate standard collected data; the standard collected data is imported into the threat monitoring model and threat monitoring results are output; based on the threat monitoring results, security threats are graded, threat warning levels are determined, and graded warning responses are performed; threat warning records are generated and shared, and a threat sharing database is updated. The system is capable of performing multi-source data collection and processing, outputting threat monitoring results through the threat monitoring model, determining threat warning levels, and performing graded warning responses, thereby enabling different warning responses to be performed according to different security threat levels, and meeting the high standards of efficiency, accuracy, and flexibility required for modern network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 A flowchart of a method provided by an embodiment of the present invention; Figure 2 A flowchart of constructing a threat monitoring model in the method provided in an embodiment of the present invention; Figure 3 A flowchart of multi-source data acquisition and processing in the method provided in an embodiment of the present invention; Figure 4 A flowchart of performing a graded warning response in the method provided in an embodiment of the present invention; Figure 5 A flowchart of updating a threat sharing database in a method provided in an embodiment of the present invention; Figure 6 An application architecture diagram of the system provided by an embodiment of the present invention; Figure 7 A structural block diagram of a monitoring model building unit in a system provided by an embodiment of the present invention; Figure 8 A structural block diagram of a multi-source data acquisition unit in a system provided by an embodiment of the present invention; Figure 9 A structural block diagram of a high-level warning response unit in a system provided by an embodiment of the present invention; Figure 10 This is a structural block diagram of a shared database update unit in a system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0016] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.

[0017] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the described features. In the description of this application, "plurality" means two or more, unless otherwise specifically specified.

[0018] In the description of this application, the term "for example" is used to mean "used as an example, illustration or explanation". Any embodiment described as "for example" in this application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is given to enable any person skilled in the art to implement and use the present invention. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art will recognize that the present invention can be implemented without using these specific details. In other examples, well-known structures and processes will not be elaborated in detail to avoid obscuring the description of the present invention with unnecessary details. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed in this application.

[0019] Example 1 Figure 1 A flow chart of a method provided by an embodiment of the present invention is shown.

[0020] Specifically, a network security threat monitoring and early warning method includes the following steps: Step S101: Acquire historical threat data, build and deploy a threat monitoring model.

[0021] In an embodiment of the present invention, historical threat data related to network security threat monitoring and early warning is obtained, and data division processing is performed on the historical threat data according to a preset division ratio to obtain a training set and a test set. The model is then trained and tested using the training set and the test set to construct a threat monitoring model, and the threat monitoring model is deployed. Specifically, the threat monitoring model is an internal state early warning model constructed based on statistical analysis, which can process data and discover abnormal trend changes.

[0022] Specifically, Figure 2 This is a flowchart of constructing a threat monitoring model in the method provided in an embodiment of the present invention.

[0023] In a preferred embodiment of the present invention, the steps of obtaining historical threat data and constructing and deploying a threat monitoring model specifically include the following steps: Step S1011: Acquire historical threat data; Step S1012, data partition processing is performed on the historical threat data according to a preset partition ratio, to obtain a training set and a test set; Step S1013, model training and testing are performed through the training set and the test set, to construct a threat monitoring model; Step S1014, the threat monitoring model is deployed.

[0024] Further, the network security threat monitoring and early warning method further includes the following steps: Step S102, multi-source data acquisition is performed on a target network, multi-source acquisition data is acquired, data preprocessing is performed, and standard acquisition data is generated.

[0025] In the embodiment of the application, multi-source data acquisition is performed on the target network, multi-source acquisition data including traffic, logs, asset and vulnerability data, etc. (in the multi-source acquisition data, assets, processes, data and security resources are effectively integrated together to realize security management process integration) is acquired, and operating system level monitoring is performed on external attack sniffing behavior, internal abnormal behavior, and self security protection configuration short board, etc. to acquire comprehensive terminal side threat perception basic data. Then, the multi-source acquisition data and the terminal side threat perception basic data are de-duplicated to generate de-duplicated acquisition data. Then, the de-duplicated acquisition data is invalidly eliminated to generate valid acquisition data, and the valid acquisition data is standardized to generate standard acquisition data.

[0026] Specifically, Figure 3 A flowchart of multi-source data acquisition and processing in the method provided in the embodiment of the application.

[0027] In the preferred embodiment provided in the application, the multi-source data acquisition on the target network, the acquisition of the multi-source acquisition data, and the data preprocessing to generate the standard acquisition data specifically include the following steps: Step S1021, multi-source data acquisition is performed on the target network to acquire multi-source acquisition data including traffic, logs, asset and vulnerability data; Step S1022, de-duplication processing is performed on the multi-source acquisition data to generate de-duplicated acquisition data; Step S1023, invalid elimination is performed on the de-duplicated acquisition data to generate valid acquisition data; Step S1024, standardization processing is performed on the valid acquisition data to generate standard acquisition data.

[0028] Further, the network security threat monitoring and early warning method further includes the following steps: Step S103, the standard acquisition data is imported into the threat monitoring model, and a threat monitoring result is output.

[0029] In the embodiment of the present invention, the standard collected data is imported into the threat monitoring model, the standard collected data is processed by the threat monitoring model, and the threat monitoring result is output.

[0030] Step S104: Based on the threat monitoring results, security threats are classified, threat warning levels are determined, and level warning responses are performed.

[0031] In an embodiment of the present invention, by identifying the threat monitoring results, extracting key risk information from the threat monitoring results, and then performing security threat classification based on the key risk information, determining the threat warning level, and then performing corresponding level linkage defense based on the threat warning level, and generating a level warning signal to perform threat level warning; different level linkage defenses are based on the corresponding threat warning level, and perform multi-level linkage coordination that meets the level, and perform automated response disposal for programmable response scenarios, including terminal isolation, file deletion / restore, port blocking, process termination and other blocking methods, to provide different levels of security defense; when an external network intrusion occurs, the target network will first be in the deployed virtual-real network boundary protection network, security threat trapping audit system, etc. When an alarm condition is triggered in the Tonghe industrial control security gateway system and the target network is subjected to a violent intrusion, the wireless signal accesses the information flow network boundary or reaches the edge computing platform, and is captured by the industrial control security gateway system, the edge trusted system and the host protection system, thereby triggering the alarm condition and blocking the intrusion path within the policy; when an internal malicious program steals data and controls the device, it will be identified and discovered by the deployed edge trusted system, triggering the alarm condition; the deployed industrial control security gateway system will also be monitored and blocked; when it reaches the server or host terminal, it will be intercepted by the deployed host protection system and trigger an alarm. Once a system triggers an alarm, the entire system will synchronize the message, determine the level of warning response, and collaboratively complete the handling and recording of security incidents based on security threat classification.

[0032] Specifically, Figure 4 This is a flowchart of performing a graded warning response in the method provided in an embodiment of the present invention.

[0033] Among them, in the preferred embodiment provided by the present invention, the security threat classification based on the threat monitoring results, the determination of the threat warning level, and the level warning response specifically include the following steps: Step S1041: Identify the threat monitoring results and extract key danger information; Step S1042: perform security threat classification based on the key risk information and determine the threat warning level; Step S1043: Perform level-linked defense according to the threat warning level; Step S1044: Issue a threat level warning based on the threat warning level.

[0034] Furthermore, the network security threat monitoring and early warning method further includes the following steps: Step S105: Generate and share threat warning records, and update the threat sharing database.

[0035] In an embodiment of the present invention, by investigating and tracing the detected threats or monitored alarm events, a traceability analysis is performed on security events related to the specified attack source, destination IP and attack type in the form of a customized tracing task, and the attacker portrait information, victim information and attack process topology are visualized by integrating third-party clue information to restore the cause and occurrence process of the entire security incident, and analyze the impact caused, complete the attacker's IP address, attack time, attack method and event record, and finally restore the attack chain, confirm the attack chain, attacker, attacked device and other information, generate a threat warning record, and then share the threat warning record according to the preset shared address, and then update the threat sharing database based on the threat warning record. Specifically, Figure 5 This is a flowchart of updating the threat sharing database in the method provided in an embodiment of the present invention.

[0036] In a preferred embodiment of the present invention, generating and sharing threat warning records and updating the threat sharing database specifically include the following steps: Step S1051: Generate a threat warning record; Step S1052: Sharing the threat warning record according to a preset shared address; Step S1053: Update the threat sharing database based on the threat warning record.

[0037] Example 2 See also Figure 6 , Figure 6 This is an application architecture diagram of the system provided by the embodiment of the present invention. Figure 3 As shown, the embodiment of the present invention provides a network security threat monitoring and early warning system, including: The monitoring model building unit 101 is used to obtain historical threat data, build and deploy a threat monitoring model.

[0038] In an embodiment of the present invention, the monitoring model construction unit 101 obtains historical threat data related to network security threat monitoring and early warning, and performs data division processing on the historical threat data according to a preset division ratio to obtain a training set and a test set, and then performs model training and testing on the training set and the test set to construct a threat monitoring model and deploy the threat monitoring model. Specifically, the threat monitoring model is an internal state early warning model constructed based on statistical analysis, which can process data and discover abnormal trend changes.

[0039] Specifically, Figure 7 This is a structural block diagram of the monitoring model building unit 101 in the system provided by an embodiment of the present invention.

[0040] In a preferred embodiment of the present invention, the monitoring model building unit 101 specifically includes: Data acquisition module 1011, used to acquire historical threat data; A data partitioning module 1012 is configured to partition the historical threat data according to a preset partitioning ratio to obtain a training set and a test set; A model building module 1013 is configured to perform model training and testing using the training set and the test set to build a threat monitoring model; The model deployment module 1014 is used to deploy the threat monitoring model.

[0041] Furthermore, the network security threat monitoring and early warning system also includes: The multi-source data collection unit 102 is used to collect multi-source data from the target network, obtain multi-source collected data, and perform data preprocessing to generate standard collected data.

[0042] In an embodiment of the present invention, the multi-source data collection unit 102 performs multi-source data collection on the target network to obtain multi-source collected data including traffic, logs, assets and vulnerability data (in the multi-source collected data, assets, processes, data, and security resources are also effectively integrated to realize the integration of security management processes), and performs operating system-level monitoring and tracking of external attack sniffing behaviors, internal abnormal behaviors, and shortcomings in its own security protection configuration to obtain comprehensive terminal-side threat perception basic data, and then deduplicates the multi-source collected data and the terminal-side threat perception basic data to generate deduplicated collected data. Afterwards, invalid deduplication is eliminated from the deduplicated collected data to generate valid collected data, and the valid collected data is standardized to generate standard collected data.

[0043] Specifically, Figure 8 This is a structural block diagram of the multi-source data acquisition unit 102 in the system provided by an embodiment of the present invention.

[0044] In the preferred embodiments provided by the present application, the multi-source data collection unit 102 specifically comprises: a data collection module 1021, configured to collect multi-source data of a target network, and acquire multi-source collection data including traffic, log, asset and vulnerability data; a deduplication processing module 1022, configured to perform deduplication processing on the multi-source collection data, and generate deduplicated collection data; an invalid elimination module 1023, configured to perform invalid elimination on the deduplicated collection data, and generate valid collection data; a standardization processing module 1024, configured to perform standardization processing on the valid collection data, and generate standard collection data.

[0045] Further, the network security threat monitoring and early warning system further comprises: a monitoring result output unit 103, configured to import the standard collection data into the threat monitoring model, and output a threat monitoring result.

[0046] In the embodiments of the present application, the monitoring result output unit 103 imports the standard collection data into the threat monitoring model, processes the standard collection data through the threat monitoring model, and outputs a threat monitoring result.

[0047] a level early warning response unit 104, configured to perform security threat grading according to the threat monitoring result, determine a threat early warning level, and perform level early warning response.

[0048] In an embodiment of the present invention, the level warning response unit 104 identifies the threat monitoring results, extracts key risk information from the threat monitoring results, and then performs security threat classification based on the key risk information to determine the threat warning level. Then, according to the threat warning level, corresponding level linkage defense is performed, and a level warning signal is generated to perform threat level warning. Different level linkage defenses are based on the corresponding threat warning level. Multi-level linkage coordination that meets the level is performed, and automated response disposal is performed for programmable response scenarios, including terminal isolation, file deletion / restore, port blocking, process termination and other blocking methods to provide different levels of security defense. When an external network intrusion occurs, the target network will first be in the deployed virtual and real combined network boundary protection network, security threat Alarm conditions are triggered in the trapping audit system and the industrial control security gateway system. When the target network is subjected to violent intrusion, the wireless signal accesses the information flow network boundary or reaches the edge computing platform, and is captured by the industrial control security gateway system, the edge trusted system and the host protection system, thereby triggering the alarm condition and blocking the intrusion path within the policy; when an internal malicious program steals data and controls the device, it will be identified and discovered by the deployed edge trusted system, triggering the alarm condition; the deployed industrial control security gateway system will also be monitored and blocked; when it reaches the server or host terminal, it will be intercepted by the deployed host protection system and trigger an alarm. Once a system triggers an alarm, the entire system will synchronize the message, determine the level of warning response, and collaboratively complete the handling and recording of security incidents based on security threat classification.

[0049] Specifically, Figure 9 This is a structural block diagram of the medium-level warning response unit 104 in the system provided by an embodiment of the present invention.

[0050] In a preferred embodiment of the present invention, the level warning response unit 104 specifically includes: Information extraction module 1041, used to identify the threat monitoring results and extract key danger information; A threat classification module 1042 is configured to classify security threats based on the key risk information and determine a threat warning level; A linkage defense module 1043 is configured to perform level-linked defense according to the threat warning level; The level warning module 1044 is used to issue a threat level warning according to the threat warning level.

[0051] Furthermore, the network security threat monitoring and early warning system also includes: The shared database updating unit 105 is configured to generate and share threat warning records and update the threat sharing database.

[0052] In an embodiment of the present invention, the shared database update unit 105 investigates and traces the detected threats or monitored alarm events, and traces the source of security events related to the specified attack source, destination IP and attack type in the form of customized tracing tasks, and visually displays the attacker portrait information, victim information and attack process topology diagram based on third-party clue information, restores the cause and occurrence process of the entire security incident, and analyzes the impact caused, completes the attacker's IP address, attack time, attack method and event records, and finally restores the attack chain, confirms the attack chain, attacker, attacked device and other information, generates threat warning records, and then shares the threat warning records according to the preset shared address, and then updates the threat sharing database based on the threat warning records.

[0053] Specifically, Figure 10 This is a structural block diagram of the shared database updating unit 105 in the system provided by an embodiment of the present invention.

[0054] In a preferred embodiment of the present invention, the shared database updating unit 105 specifically includes: Record generation module 1051, used to generate threat warning records; A sharing processing module 1052 is used to share the threat warning record according to a preset sharing address; The database updating module 1053 is configured to update the threat sharing database based on the threat warning record.

[0055] It should be noted that, in the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0056] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0057] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0058] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0059] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0060] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0061] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A network security threat monitoring and early warning method, characterized in that: The method comprises the following steps: Obtain historical threat data, build and deploy threat monitoring models; Collect multi-source data from the target network, obtain multi-source collected data, perform data preprocessing, and generate standard collected data; Importing the standard collected data into the threat monitoring model and outputting threat monitoring results; Based on the threat monitoring results, security threat classification is performed, threat warning levels are determined, and level warning responses are implemented; Generate and share threat warning records and update the threat sharing database.

2. The network security threat monitoring and early warning method according to claim 1 is characterized in that: The acquisition of historical threat data and the construction and deployment of a threat monitoring model specifically include the following steps: Obtain historical threat data; Performing data partitioning processing on the historical threat data according to a preset partitioning ratio to obtain a training set and a test set; Performing model training and testing using the training set and the test set to build a threat monitoring model; Deploy the threat monitoring model.

3. The network security threat monitoring and early warning method according to claim 1 is characterized in that: The method of collecting multi-source data from the target network, obtaining the multi-source collected data, and performing data preprocessing to generate standard collected data specifically includes the following steps: Collect multi-source data on the target network, including traffic, logs, assets, and vulnerability data; Deduplication processing is performed on the multi-source collected data to generate deduplication collected data; Eliminating invalid data from the deduplicated collected data to generate valid collected data; The effective collected data is standardized to generate standard collected data.

4. The network security threat monitoring and early warning method according to claim 1 is characterized in that: The security threat classification, threat warning level determination, and level warning response based on the threat monitoring results specifically include the following steps: Identify the threat monitoring results and extract key danger information; Based on the key risk information, security threat classification is performed to determine the threat warning level; Conducting level-linked defense according to the threat warning level; A threat level warning is issued according to the threat warning level.

5. The network security threat monitoring and early warning method according to claim 1 is characterized in that: Generating and sharing threat warning records and updating the threat sharing database specifically include the following steps: Generate threat warning records; Sharing the threat warning record according to a preset shared address; Based on the threat warning record, the threat sharing database is updated.

6. Network security threat monitoring and early warning system, characterized by: The system includes a monitoring model building unit, a multi-source data acquisition unit, a monitoring result output unit, a graded warning response unit, and a shared database update unit, wherein: A monitoring model building unit, used to obtain historical threat data, build and deploy threat monitoring models; The multi-source data acquisition unit is used to collect multi-source data from the target network, obtain the multi-source collected data, perform data preprocessing, and generate standard collected data; A monitoring result output unit, configured to import the standard collected data into the threat monitoring model and output threat monitoring results; A level warning response unit is used to classify security threats, determine threat warning levels, and respond to level warnings based on the threat monitoring results; The shared database update unit is used to generate and share threat warning records and update the threat sharing database.

7. The network security threat monitoring and early warning system according to claim 6, characterized in that: The monitoring model building unit specifically includes: Data acquisition module, used to obtain historical threat data; A data partitioning module is used to perform data partitioning processing on the historical threat data according to a preset partitioning ratio to obtain a training set and a test set; A model building module is used to perform model training and testing using the training set and the test set to build a threat monitoring model; A model deployment module is used to deploy the threat monitoring model.

8. The network security threat monitoring and early warning system according to claim 6, characterized in that: The multi-source data acquisition unit specifically includes: The data collection module is used to collect multi-source data on the target network and obtain multi-source collected data including traffic, logs, assets and vulnerability data; A deduplication processing module, configured to perform deduplication processing on the multi-source collected data to generate deduplication collected data; An invalid elimination module, used for eliminating invalid data from the deduplicated collected data to generate valid collected data; The standardization processing module is used to perform standardization processing on the effective collected data to generate standard collected data.

9. The network security threat monitoring and early warning system according to claim 6, characterized in that: The level warning response unit specifically includes: An information extraction module, used to identify the threat monitoring results and extract key danger information; A threat classification module is used to classify security threats and determine threat warning levels based on the key risk information; A linkage defense module, configured to perform level-linked defense according to the threat warning level; The level warning module is used to issue a threat level warning according to the threat warning level.

10. The network security threat monitoring and early warning system according to claim 6, characterized in that: The shared database updating unit specifically includes: A record generation module is used to generate threat warning records; A sharing processing module, configured to share the threat warning record according to a preset sharing address; The database updating module is used to update the threat sharing database based on the threat warning record.