Method and device for automatically constructing network topology scene library
By combining focused crawlers, deep learning visual models, and multimodal large models, we solved the problems of difficulty in acquiring network topology scene libraries and low efficiency in automatic recognition, built an efficient network topology scene library, and provided support for cyberspace security.
Patent Information
- Application Number
- CN202510855878.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-10-10
AI Technical Summary
It is difficult to obtain massive network topology scenarios, automatic identification efficiency is low, and existing technologies make it difficult to effectively build a network topology scenario library.
A focused crawler method based on keyword construction and image reverse search is used to obtain a set of candidate topology maps. A deep learning visual model is used to screen real topology maps. A multimodal large model is combined for topology recognition. A recognition dataset is generated through a topology map description template, and finally a network topology scenario library is constructed.
It has achieved efficient and automated network topology map acquisition and identification, built a high-quality network topology scenario library, and provided strong technical support for cyberspace security technology experiments.
Smart Images

Figure CN120768765A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of computer network technology and artificial intelligence technology, and in particular to a method and device for automatically constructing a network topology scenario library. Background Art
[0002] Cyberspace security technology experiments rely on various real network topology scenario libraries, including the global Internet, backbone networks, and local area networks. However, it is extremely difficult to obtain massive network topology scenarios. This application notes that there are a large number of valuable network topology map resources on the World Wide Web, including local area network topology maps, submarine optical cable topology maps, and backbone network topology maps. With the rapid development of network information, there are about 2 billion active websites on the World Wide Web. Efficiently discovering network topology maps in such a huge amount of data has become a huge challenge. Even if these network topology maps are found, only by automatically identifying the nodes, connection relationships, and semantic information they contain can the automated construction of the network topology scenario library be truly realized to serve cyberspace security technology experiments. However, there are many ways to draw network topology maps, the shapes of nodes are different, and the expression of connection relationships varies greatly, which brings great difficulties to automatic identification.
[0003] Among related technologies, focused crawler technology provides an efficient and feasible path for acquiring massive amounts of network topology maps. By targeting specific search engines with appropriate search terms and crawling resources, it is possible to automatically collect a large amount of network topology resources from the internet, ensuring the relevance and efficiency of data resource acquisition. Meanwhile, mainstream search engines are increasingly mature in reverse image search technology. This technology can be used to perform similarity-based extended searches on already captured topology resources, further acquiring dozens of times more new topology data.
[0004] However, candidate topology maps are not necessarily network topology maps, and may also be mixed with other irrelevant content. It is necessary to further design an image classification algorithm based on deep learning to effectively screen out the true network topology map from the candidate topology maps; after obtaining the true network topology map, it is necessary to further design a fine-tuning technology based on a multimodal large model to effectively extract the nodes, connection relationships and semantic information in the network topology map to improve the efficiency and accuracy of recognition; and finally form a massive network topology scene snapshot library with a unified description template and display form, providing strong technical support for cyberspace security technology experiments. Summary of the Invention
[0005] The present application provides a method and device for automatically constructing a network topology scenario library to solve the problems of difficulty in obtaining topology maps and low automatic recognition efficiency in related technologies.
[0006] The first embodiment of the present application provides a method for automatically constructing a network topology scenario library, comprising the following steps:
[0007] A crawler method based on keyword construction and image reverse search is used to obtain a candidate network topology atlas;
[0008] Based on a preset deep learning visual model, the network topology maps in the candidate network topology atlas that meet the preset real conditions are screened to obtain a real network topology atlas;
[0009] Based on a preset multimodal large model and a preset topology map description template, perform network topology recognition on the real network topology maps in the real network topology map set, generate a topology recognition result for each real network topology map, and generate a network topology map recognition dataset based on each real network topology map and the topology recognition result of each real network topology map;
[0010] Based on the network topology map, a data set is identified, network topology JSON data is loaded, and a graphical network topology map is created based on the loading result, and the network topology scenario library is constructed according to the graphical network topology map.
[0011] Optionally, the focused crawler method based on keyword construction and image reverse search, to obtain a candidate network topology graph, includes:
[0012] Determining the type of the network topology map to be obtained, and constructing effective search terms to obtain high-quality candidate network topology maps, wherein the type of the network topology map to be obtained includes at least one of a local area network topology map, a critical infrastructure network topology map, and a backbone network topology map;
[0013] The network topology map is crawled according to the search keyword to obtain a network topology image file to form the candidate network topology map set.
[0014] Optionally, after obtaining the real network topology atlas, the method further includes:
[0015] For the real network topology atlas, image reverse search is used to perform similarity expansion retrieval, and the candidate network topology atlas is expanded according to the expansion retrieval.
[0016] Optionally, before screening the network topology maps in the candidate network topology map set that meet preset real conditions based on the preset deep learning visual model, the method further includes:
[0017] Obtaining a training data set, wherein the training data set includes a first preset number of real network topology maps as positive samples and a second preset number of non-network topology maps as negative samples, and the first preset number and the second preset number are in a preset ratio;
[0018] Based on a preset division ratio, the training data set is divided into a training set and a test set, and based on a preset composite loss function, a preset deep learning network is trained using the training set to obtain an optimized deep learning vision model;
[0019] The optimized deep learning vision model is tested using the test set, and when the test result meets the preset test condition, the optimized deep learning vision model is used as the preset deep learning vision model.
[0020] Optionally, before performing network topology recognition on the real network topology maps in the real network topology map set based on the preset topology map description template, the method further includes:
[0021] Based on the JSON format file description of the topological structure and information of the network topology map, the preset topology map description template is obtained, wherein,
[0022] The file in JSON format includes a node set and a connection relationship set.
[0023] Optionally, before performing network topology recognition on the real network topology maps in the real network topology map set based on the preset multimodal large model and the preset topology map description template, the method further includes:
[0024] Acquire a training data set, wherein the training data set includes network topology diagram annotation information generated based on a multimodal large model and manually verified and corrected;
[0025] The preset multimodal large model is fine-tuned based on the training data set, wherein the preset multimodal large model is optimized using a composite loss function including text semantic similarity loss and graph edit distance loss.
[0026] A second embodiment of the present application provides a device for automatically constructing a network topology scenario library, including:
[0027] The acquisition module is used to obtain the candidate network topology atlas using a focused crawler method based on keyword construction and image reverse search;
[0028] A screening module is used to screen the network topology maps in the candidate network topology atlas that meet preset real conditions based on a preset deep learning visual model to obtain a real network topology atlas;
[0029] a generation module, configured to perform network topology recognition on the real network topology maps in the real network topology map set based on a preset multimodal large model and a preset topology map description template, generate a topology recognition result for each real network topology map, and generate a network topology map recognition dataset based on each real network topology map and the topology recognition result of each real network topology map;
[0030] A visualization module is used to identify a data set based on the network topology map, load the network topology JSON data, create a graphical network topology map based on the loading result, and build the network topology scenario library based on the graphical network topology map.
[0031] Optionally, the acquisition module is specifically configured to:
[0032] Determining the type of the network topology map to be obtained, and constructing effective search terms to obtain high-quality candidate network topology maps, wherein the type of the network topology map to be obtained includes at least one of a local area network topology map, a critical infrastructure network topology map, and a backbone network topology map;
[0033] The network topology map is crawled according to the search keyword to obtain a network topology image file to form the candidate network topology map set.
[0034] Optionally, after obtaining the real network topology atlas, the acquisition module is further configured to:
[0035] Performing similarity extension retrieval on the real network topology atlas using image reverse search, and expanding the candidate network topology atlas based on the extension retrieval;
[0036] Before screening the network topology maps that meet the preset real conditions in the candidate network topology map set based on the preset deep learning visual model, the screening module is further used to:
[0037] Obtaining a training data set, wherein the training data set includes a first preset number of real network topology maps as positive samples and a second preset number of non-network topology maps as negative samples, and the first preset number and the second preset number are in a preset ratio;
[0038] Based on a preset division ratio, the training data set is divided into a training set and a test set, and based on a preset composite loss function, a preset deep learning network is trained using the training set to obtain an optimized deep learning vision model;
[0039] The optimized deep learning vision model is tested using the test set, and when the test result meets the preset test condition, the optimized deep learning vision model is used as the preset deep learning vision model.
[0040] Optionally, before performing network topology recognition on the real network topology maps in the real network topology map set based on the preset topology map description template, the generating module is further configured to:
[0041] Describing the topological structure and information of the network topology graph based on a file in JSON format to obtain the preset topology graph description template, wherein the file in JSON format includes a node set and a connection relationship set;
[0042] Acquire a training data set, wherein the training data set includes network topology diagram annotation information generated based on a multimodal large model and manually verified and corrected;
[0043] The preset multimodal large model is fine-tuned based on the training data set, wherein the preset multimodal large model is optimized using a composite loss function including text semantic similarity loss and graph edit distance loss.
[0044] Therefore, the embodiment of the present application is based on a focused crawler method based on keyword construction and image reverse search to obtain a candidate network topology atlas, and based on a preset deep learning visual model, screen the network topology maps in the candidate network topology atlas that meet the preset real conditions to obtain a real network topology atlas; based on a preset multimodal large model and a preset topology description template, perform network topology recognition on the real network topology maps in the real network topology atlas, generate a topology recognition result for each real network topology map, and generate a network topology map recognition data set based on each real network topology map and the topology recognition result of each real network topology map; based on the network topology map recognition data set, load the network topology JSON data, and create a graphical network topology map based on the loading result, and build a network topology scenario library based on the graphical network topology map. Thus, the problems of difficulty in obtaining topology maps and low efficiency of automatic recognition in related technologies are solved, providing support for cyberspace security technology experiments.
[0045] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0047] Figure 1 A flowchart of a method for automatically constructing a network topology scenario library according to an embodiment of the present application;
[0048] Figure 2 A schematic diagram of a model structure of a network topology diagram classification method for automatically constructing a network topology scenario library according to an embodiment of the present application;
[0049] Figure 3 A schematic diagram of a model structure of network topology map recognition for a method for automatically constructing a network topology scenario library according to one embodiment of the present application;
[0050] Figure 4 A flowchart of network topology graph acquisition, screening, identification, and visualization of a network topology scenario library automatic construction method according to an embodiment of the present application;
[0051] Figure 5 A schematic diagram of a network topology scenario library automatic construction device according to an embodiment of the present application. DETAILED DESCRIPTION
[0052] Embodiments of the present application are described in detail below, examples of which are shown in the accompanying drawings, in which the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the accompanying drawings are exemplary and are intended to explain the present application, and cannot be understood as limiting the present application.
[0053] The network topology scenario library automatic construction method and device of the embodiments of the present application are described below with reference to the accompanying drawings. In view of the problems of difficult topology graph acquisition and low automatic identification efficiency in the related technologies mentioned in the background art, the present application provides a network topology scenario library automatic construction method, in which, based on the focused crawler method of keyword construction and image reverse search, a candidate network topology graph set is acquired, and based on a preset deep learning vision model, a network topology graph in the candidate network topology graph set that meets a preset reality condition is screened to obtain a real network topology graph set. Based on a preset multi-modal large model and a preset topology graph description template, network topology identification is performed on the real network topology graphs in the real network topology graph set to generate a topology identification result for each real network topology graph, and a network topology graph identification data set is generated based on each real network topology graph and the topology identification result of each real network topology graph. Based on the network topology graph identification data set, network topology JSON data is loaded, and based on the loading result, a graphical network topology graph is created, and a network topology scenario library is constructed according to the graphical network topology graph. Thus, the problems of difficult topology graph acquisition and low automatic identification efficiency in the related technologies are solved, and support is provided for network space security technology tests.
[0054] Specifically, Figure 1 A flowchart of a network topology scenario library automatic construction method according to an embodiment of the present application.
[0055] As Figure 1 shown, the network topology scenario library automatic construction method includes the following steps:
[0056] In step S101, based on the focused crawler method of keyword construction and image reverse search, a candidate network topology graph set is acquired.
[0057] The candidate network topology atlas refers to a collection of images that are initially collected from the Internet and may contain network topology structures.
[0058] Optionally, in some embodiments, obtaining candidate network topology maps includes determining the type of network topology map to be obtained, constructing effective search terms to obtain high-quality candidate network topology maps, wherein the type of network topology map to be obtained includes at least one of a local area network topology map, a critical infrastructure network topology map, and a backbone network topology; crawling the network topology map according to the search keywords, obtaining a network topology image file, and forming a candidate network topology map set.
[0059] Optionally, in some embodiments, after obtaining the real network topology atlas, the method further includes: performing similarity extension retrieval on the real network topology atlas using image reverse search, and expanding the candidate network topology atlas based on the extension retrieval.
[0060] Specifically, with respect to the crawling stage, the embodiment of the present application provides an efficient search method based on search term guidance, which is used to find as many high-quality candidate network topology maps as possible in the massive World Wide Web resources, thereby avoiding a large amount of resource overhead consumed on irrelevant web pages and improving the efficiency of the focused crawler method. Considering that search engines (such as Google, Bing, and Baidu) have deployed powerful crawler infrastructure for regularly crawling massive web pages in the World Wide Web and providing mature search functions, the embodiment of the present application uses a search engine to help implement an efficient network topology map search method, by inputting search keywords into the search engine, so as to obtain a large number of search results related to the network topology map, and use them as candidate network topology maps. Subsequently, based on the network topology map that meets the preset real conditions, image reverse search is used to perform similarity expansion retrieval to further expand the set of candidate network topology maps; this process can be iterated multiple times. The embodiment of the present application designs different efficient search terms for different types of network topology maps, so that it can obtain a large number of rich network topology maps while avoiding the resource overhead consumed on irrelevant web pages.
[0061] Furthermore, for local area network topology diagrams, embodiments of the present application use Chinese or English words such as "LAN network topology diagram," "local area network topology diagram," "campus network topology diagram," "LAN_network_topology," and "campus_network_topology" as keywords entered into a search engine, automatically crawling and returning search results, including image files, image descriptions, image URLs, and other information. For critical infrastructure network topology diagrams, embodiments of the present application use Chinese or English words such as "power grid topology diagram," "financial network topology diagram," "transportation network topology diagram," and "energy grid topology diagram" as keywords entered into a search engine, automatically crawling and returning search results, including image files, image descriptions, image URLs, and other information. Regarding the backbone network topology, given that large operators with high rankings usually publish their backbone network topologies separately on their own websites, the embodiment of the present application first obtains the name of the operator with high ASRank ranking, and then merges it with the network map as a keyword and inputs it into the search engine. For example, the name of the operator ranked first in ASRank is Level 3Parent, LLC, and the keyword construction is Level3Parent, LLC network map. Then, the most relevant search results are automatically crawled and returned, including image files, image descriptions, image URLs and other information; finally, the network topology image file is obtained.
[0062] In addition, as far as the crawling stage is concerned, the embodiment of the present application also provides a network topology image reverse search method based on dynamic web crawler technology, which performs image similarity search based on the subsequent acquisition of network topology image files that meet preset real conditions, so as to solve the problem of limited number of network topology images obtained by traditional keyword search, thereby efficiently building a large-scale network topology scene library. First, the network topology image files are read in batches, and each image is processed. The search engine website is automatically opened using Selenium WebDriver, and the upload button is simulated to upload the image; then, the system waits for the search result page to load, parses the page content, and extracts the image file and image description, image URL and other information of the relevant image; for each extracted image link, the system sends an HTTP request to download and save the original image locally, and records relevant metadata, such as the image URL, description information and source page link. In order to improve the stability and fault tolerance of the system, the embodiment of the present application also introduces a retry mechanism and an intermediate result preservation mechanism to ensure that the acquired data can be retained to the greatest extent even if an exception occurs during the processing process; ultimately, a set of candidate network topology maps is obtained, and the automated and batch acquisition of network topology maps is realized, which significantly improves the efficiency and scale of data collection and is particularly suitable for building a network topology scenario library of more than 10,000 levels.
[0063] In step S102, based on a preset deep learning visual model, network topology maps that meet preset real conditions in the candidate network topology atlas are screened to obtain a real network topology atlas.
[0064] Specifically, a preset deep learning visual model such as ResNet is used as the basis. The preset deep learning visual model needs to be fine-tuned in advance to adapt to a specific task, that is, the ability to distinguish network topology maps from other image types; the candidate network topology atlas is input into the deep learning model; the model classifies each image according to the features learned during its training process to determine whether it is a real network topology map; for the results output by the model, real conditions can be preset to determine which images are real network topology maps, forming a real network topology atlas for subsequent analysis, research, or construction of a network topology scenario library.
[0065] In step S103, based on the preset multimodal large model and the preset topology map description template, network topology recognition is performed on the real network topology maps in the real network topology map set, and a topology recognition result for each real network topology map is generated. A network topology map recognition data set is generated based on each real network topology map and the topology recognition result of each real network topology map.
[0066] Specifically, the embodiment of the present application utilizes a preset multimodal large model combined with a preset topology description template to perform structured recognition and annotation of real network topology maps, automatically generating a high-quality network topology recognition data set, and providing basic support for subsequent automated understanding and modeling of network topology.
[0067] In step S104, a data set is identified based on the network topology map, network topology JSON data is loaded, a graphical network topology map is created based on the loading result, and a network topology scenario library is constructed according to the graphical network topology map.
[0068] Specifically, based on the topological node position information extracted in the image recognition stage, this embodiment adopts a static coordinate mapping strategy to achieve high-fidelity restoration of the topological structure. The system first parses the aspect ratio of the original topological map, and based on the pixel position of each node in the image, calculates its normalized coordinates relative to the width and height of the entire image (the range is limited to between 0 and 1, accurate to four decimal places). In the topological map generation stage, the system maps the relative coordinates of the nodes to the standard canvas to ensure that the graphic proportions and structural distribution are highly consistent with the original image layout, thereby improving the restoration accuracy and visual consistency.
[0069] Optionally, in some embodiments, before screening the network topology maps that meet preset real conditions in the candidate network topology map set based on the preset deep learning visual model, it also includes: obtaining a training data set, wherein the training data set includes a first preset number of real network topology maps as positive samples and a second preset number of non-network topology maps as negative samples, and the first preset number and the second preset number are a preset ratio; based on a preset division ratio, the training data set is divided into a training set and a test set, and based on a preset composite loss function, the preset deep learning network is trained with the training set to obtain an optimized deep learning visual model; the optimized deep learning visual model is tested with the test set, and when the test result meets the preset test condition, the optimized deep learning visual model is used as the preset deep learning visual model.
[0070] Among them, the first preset number, the second preset number, and the preset ratio can be thresholds set in advance by the user, can be thresholds obtained through a limited number of experiments, or can be thresholds obtained through a limited number of computer simulations, and are not specifically limited here.
[0071] It is understandable that if Figure 2 As shown, Figure 2 This is a schematic diagram of the model structure of network topology diagram classification of a method for automatically constructing a network topology scenario library in an embodiment of the present application. The embodiment of the present application filters out the true network topology diagram from the candidate network topology diagrams, thereby avoiding the subsequent recognition algorithm from wasting computing resources to identify the crawled non-network topology diagrams, and improving the purity of the crawled network topology diagrams.
[0072] Specifically, considering that ResNet has a large number of mature applications in the binary image classification task, a traditional supervised fine-tuning method was used to construct a deep learning visual model with the ability to classify network topology images. The training data set of the embodiment of this application is derived from the candidate topology maps obtained in the focus crawler stage. 800 real network topology maps were manually identified and screened as positive samples, and 200 non-network topology maps were screened as negative samples. The entire data set was divided into training and test sets in a ratio of eight to two to ensure the objectivity of the model evaluation. The network model uses ResNet50 as the basic feature extractor. The input images are uniformly scaled to 224×224 pixels and support formats such as PNG, JPG, and WEBP. After the images are normalized (mean 0.485, 0.456, 0.406, standard deviation 0.229, 0.224, 0.225), preliminary features are first obtained through a 7×7 convolutional layer with a stride of 2, and the feature map size is compressed through a maximum pooling layer. Subsequently, the network extracts deep features through four residual block groups, each containing 3, 4, 6, and 3 Bottleneck units, respectively, with corresponding output channel numbers of 256, 512, 1024, and 2048. For the classification decision maker part, the embodiment of the present application improves the design of the original ResNet50 classification layer; first, a global average pooling layer is used to convert the feature map of 2048 channels into a feature vector; secondly, feature dimensionality reduction is performed through a fully connected layer with 512 neurons, and the ReLU activation function is used to increase the nonlinear expression ability; then, a Dropout layer with a dropout rate of 0.5 is set to prevent the model from overfitting; finally, a fully connected layer with 2 neurons is used to output the final classification result.
[0073] Furthermore, the training data set is optimized using a preset composite loss function, which mainly includes cross entropy loss, which is used to calculate the difference between the predicted label and the true label; and feature consistency loss, which is used to measure the similarity between feature representations of different layers; these two losses are combined in a weight ratio of 7:3 to form a total loss function. The embodiment of the present application adopts a transfer learning strategy and a parameter freezing technology, which only retains the parameters of the last 30 layers for training, thereby retaining the basic feature extraction capability and reducing the amount of training parameters. In terms of optimizer selection, the Adam algorithm is adopted, the initial learning rate is set to 0.001, and the learning rate is dynamically adjusted in combination with the ReduceLROnPlateau strategy. The embodiment of the present application is based on a preset deep learning visual model and a real web crawler data set for training, and has extremely high practicality in application scenarios; it supports a variety of common image formats as input, adopts a composite loss function design and an efficient transfer learning strategy, and shows important practical value in the field of intelligent classification of network topology maps, thereby improving the classification accuracy of the model.
[0074] Optionally, in some embodiments, before performing network topology identification on a real network topology map in a real network topology map collection based on a preset multimodal large model and a preset topology map description template, it also includes: describing the topological structure and information of the network topology map based on a file in JSON format to obtain a preset topology map description template, wherein the file in JSON format includes a node set and a connection relationship set.
[0075] like Figure 3 As shown, Figure 3 This is a schematic diagram of the network topology map recognition model structure in the method for automatically building a network topology scenario library in one embodiment of the present application. In this embodiment, a unified topology map description template is defined, and the network topology structure and its key attributes are structured and encoded in JSON format. The template mainly consists of two core parts: the "nodes" node set and the "edges" connection relationship set. In the "nodes" section, each node is assigned a globally unique identifier through the "id" field, and a unified naming convention of "device type + numeric suffix" (such as "web_server1", "web_server2") is adopted to support the distinction and indexing of devices of the same type. Device type information is expressed through the "type" field (or "label"), covering standard network role classifications such as "server", "firewall", "switch", etc., to ensure the standardization and consistency of topology semantics. In the "edges" section, the connection relationship establishes a directed logical link between nodes through the "source" and "target" fields (also compatible with "from" and "to" naming), fully expressing the communication path of the network architecture. To further refine the connection semantics, two extended fields, "type" and "label", are added to each edge: the "type" field is used to define the link connection method, including categories such as "wired", "wireless", "bus", and "multipath"; the "label" field is used to record link technical details, such as link protocol / media (such as "Ethernet", "Fiber", and "Wi-Fi") and link rate (such as "1Gbps", "10Gbps", and "40GbE"), etc., to facilitate semantic enhancement and fine-grained management of topology diagrams in visualization, network simulation, and structural verification. The node naming rules and type classification system ensure the consistency of device identification, while the explicit definition and extended attributes of the connection edges fully express the communication logic of the network architecture, provide structured support for modeling the technical characteristics of network links, and provide a structured data foundation for automated topology generation and verification. The following is an example of a topology diagram description template:
[0076]
[0077]
[0078] Furthermore, for the collected network topology diagram, the embodiments of the present application aim to automatically understand and recognize it and convert it into a unified topology diagram description template format, facilitating automatic configuration of network scenario libraries by administrators. The embodiments of the present application identify nodes, connection relationships, and corresponding semantic information from the topology diagram, leveraging the powerful visual and semantic understanding capabilities of the multimodal large model to achieve end-to-end understanding of the network topology diagram. Considering the large number of model parameters in the open-source multimodal large model and the high computational resource consumption of traditional full-parameter fine-tuning, the embodiments of the present application adopt a parameter-efficient fine-tuning (PEFT) approach to update only a small number of model parameters, thereby enhancing the multimodal large model's capabilities in network topology image classification tasks. A dataset is constructed using the network topology diagrams batch-output by the classification module. First, the multimodal large model is fed with the prompt "Identify the device nodes and connection relationships in the diagram, describe them in JSON format, and only output JSON" and the network topology diagram to generate preliminary annotations for each network topology diagram. The device names, types, and connection relationships are then manually verified and corrected, ultimately forming a network topology diagram recognition dataset containing the original images and corresponding precise JSON tags. JSON tags strictly follow the structured expression specifications of device ID, device type, and connection relationship. The storage directory and JSON tags of all images are aggregated into a JSON file to form a data set. A data entry is presented in the following format:
[0079]
[0080]
[0081] Furthermore, the embodiment of the present application proposes a multimodal large model training method based on the LLaMA-Factory framework, which is specially designed for network topology map recognition tasks. It combines efficient parameter fine-tuning strategies with innovative loss function design to achieve efficient and accurate understanding and analysis of network topology maps. In order to improve the performance of the model in network topology map recognition tasks, the loss function designed in the embodiment of the present application mainly combines the graph edit distance similarity between the topology map of the recognition result and the topology map structure annotated by the label, while taking into account the similarity of text semantics, forming a dual-objective optimization architecture. The graph edit distance quantifies structural similarity by calculating the minimum number of editing operations required to convert from one graph to another (such as node addition / deletion, edge addition / deletion, node / edge attribute modification). In the embodiment of the present application, by inheriting and rewriting the compute_loss method in trainer.py, the loss function is defined as:
[0082] L = α·L_GED + β·L_Sem;
[0083] Among them, L_GED represents the structural loss based on graph edit distance, L_Sem represents the text semantic similarity loss, and α and β are adjustable weight coefficients.
[0084] Specifically, L_GED no longer directly calculates the graph edit distance between the original structures of the predicted and annotated graphs. Instead, it introduces an enhanced structural alignment mechanism: First, a matching cost matrix is constructed for each pair of graphs, taking into account node type, connectivity, and neighbor type distribution. Subsequently, the Hungarian algorithm is used to find the one-to-one matching relationship with the minimum total cost, aligning the node names of the predicted graph to those of the annotated graph. Only after structural alignment is the edge set compared, and the normalized graph edit distance is calculated based on this comparison. This method significantly improves the robustness and rationality of structural matching, particularly in graphs with isomorphic nodes but confusing naming and strong structural symmetry. L_Sem, based on text embeddings extracted from a pretrained language model, calculates the cosine similarity between the generated and reference texts, reflecting the degree of semantic similarity. Training begins with the weights of a pretrained open-source multimodal large model, employing a "selective freezing" strategy, freezing the language model and only unfreezing the visual encoder and multimodal connector. The LoRA technology (rank 8) implemented by the PEFT library adds a lightweight adaptation module between the original model layers, so that fine-tuning can be performed without changing the original parameters, significantly reducing the amount of trainable parameters. In terms of training configuration, the global batch size is set to 16, and the AdamW optimizer and weight decay of 0.1 are used to perform language modeling training in conjunction with the cross-entropy loss function. In addition, the embodiment of the present application implements a hierarchical learning rate strategy (main body 1e-4, vision 2e-6, connector 1e-5) and a cosine decay strategy, and sets a warm-up ratio of 0.03 to ensure stable convergence. In terms of performance optimization, DeepSpeed's ZeRO-3 is combined for distributed training, BitsAndBytes is used to implement model quantization, Flash Attention 2 accelerates attention calculation, gradient checkpoints save memory, and mixed precision accelerates training. Data processing adopts reasonable image size restrictions and lazy preprocessing methods, regularly saves checkpoints, and ultimately saves only lightweight LoRA weights for deployment. This fully optimized fine-tuning method effectively enhances the multimodal capabilities of the model through a small amount of directional parameter updates while balancing resource consumption.
[0085] Therefore, the embodiment of the present application realizes the structured expression of the topology map by defining a standardized topology map description template; based on the open source multimodal large model, a multimodal large model fine-tuning optimization loss function that is more suitable for the topology map recognition task is reconstructed, and combined with PEFT technology and full-process training optimization strategy, while significantly reducing the training overhead, the model's multimodal understanding and automatic recognition capabilities of the network topology map are enhanced, providing an efficient and accurate technical means for the automatic construction of the network scenario library.
[0086] Optionally, in some embodiments, before identifying a data set based on the network topology map, loading the network topology JSON data, and creating a graphical network topology map based on the loading result, it also includes: obtaining a training data set, the training data set containing network topology map annotation information generated based on the multimodal big model and manually checked and corrected; fine-tuning the preset multimodal big model based on the training data set, wherein a composite loss function including text semantic similarity loss and graph edit distance loss is used to optimize the preset multimodal big model.
[0087] It is understandable that LLM generation significantly reduces manual labeling time, covers rare topological structures, and avoids model overfitting; the composite loss function design optimizes semantic understanding and structural recognition capabilities; through LLM enhanced data and composite loss joint optimization, "structural-semantic" dual-optimal topology recognition is achieved, providing a reliable foundation for network automation management.
[0088] It should be noted that the embodiment of the present application constructs a standardized visual system including 12 types of common network devices (cloud platforms, routers, switches, wireless access points, firewalls, load balancers, servers, controllers, databases, storage devices, clients, and printers) through the Matplotlib drawing interface. Each type of device is equipped with an icon of a uniform size and adopts a low-saturation color coding scheme with a unified design style; it also supports an interactive topology fine-tuning mechanism. Users can select key nodes through the graphical interface and drag to adjust their spatial position. The system updates the node coordinates in real time and synchronously stretches the connected edges to maintain the consistency of the topological structure. The connection relationship supports manual addition and deletion and target node redirection, allowing manual correction of recognition errors or completion of topological logic. The system converts JSON text to graphical recognition results, and the graphical recognition results to JSON bidirectional correction, operation undo and redo mechanism, version snapshot recording and recovery function, supports the refined editing of node and connection information during the topology editing process, and forms a verifiable and traceable graphical editing closed loop.
[0089] To facilitate those skilled in the art to further understand the method for automatically constructing a network topology scenario library in the embodiment of the present application, the following is a Figure 4 The illustrated embodiment is described in detail.
[0090] Specifically, if Figure 4 As shown, Figure 4 This is a flowchart illustrating the acquisition, screening, recognition, and visualization of network topology maps for a method for automatically constructing a network topology scenario library according to one embodiment of the present application. In the acquisition phase, focused crawler technology is used to construct effective keywords and retrieve candidate topology maps through a search engine. Furthermore, based on the subsequent collection of network topology maps that meet preset real-world conditions, dynamic network crawler technology is used to perform image reverse search to further enrich the candidate topology map resources. In the screening phase, the residual network in the deep learning visual model extracts image features and encodes them into feature vectors. The MLP fully connected network then classifies these feature vectors to select the true network topology map. In the recognition phase, a multimodal large model-based approach is applied, in which a Vision Transformer extracts visual features, an MLP fully connected network maps them into a semantic space, and finally, an open-source large language model decodes the recognition results and generates a topology structure description in JSON format. In the visualization phase, an intelligent layout engine, combined with multi-dimensional visual encoding technology, converts the recognition results into standardized network topology maps with a unified style and regular layout. Finally, in the storage phase, all processed network topology maps and their related information are integrated into the network topology scenario library, forming a comprehensive and easily searchable resource collection. The entire process is iteratively optimized to ensure the accuracy and practicality of the network topology scenario library.
[0091] Furthermore, the embodiment of the present application designs a method for automatically constructing a network topology scene library, including a method for automatically acquiring a network topology map and a method for automatically identifying a network topology map, and based on these methods, designs a device for automatically constructing a network topology scene library: including a network topology map automatic search module, a network topology map classification module, a network topology map automatic identification module, and a massive network topology scene library storage, retrieval and display module. The embodiment of the present application designs a method for automatically acquiring a network topology map based on a focused crawler, aiming to efficiently discover network topology map resources in massive World Wide Web resources; crawl as many resources related to the network topology map as possible, and then further determine whether it is indeed a network topology map. The embodiment of the present application designs a method for searching a network topology map based on search term guidance, aiming to crawl as many resources related to the network topology map as possible; for a specific search engine, design appropriate search terms to carry out targeted crawling of network topology map resources, and the collected resources are called candidate topology maps. The embodiment of the present application designs an automatic image reverse search method for network topology maps based on dynamic web crawler technology, which aims to efficiently download network topology maps from massive network resources; by simulating the interactive behavior of browser-side users, automatically batch uploads and subsequently obtains network topology image files that meet preset real conditions for reverse image search, deeply mines similar image resources, and simultaneously extracts metadata such as image descriptions and URLs in related web pages, thereby achieving a substantial increase in the size of the candidate topology map resource library. The embodiment of the present application designs a candidate network topology map classification method based on deep learning, which aims to accurately determine whether the crawled image is a real network topology map; using the ResNet deep learning model, by annotating and training a large amount of crawled network topology map data, the real network topology map in the candidate image is screened. The embodiment of the present application designs a topology map recognition method based on a multimodal large model, which aims to identify the topological structure and semantic information in the network topology map as accurately as possible; based on the open source multimodal large model, by manually annotating the topology map and the corresponding JSON file describing the topological structure and semantic information, a data set is constructed for PEFT training to enhance the model's structural and semantic recognition capabilities in network topology map recognition scenarios. This embodiment of the application designs a new loss function that combines the graph edit distance similarity between the topology of the recognition result and the labeled topology structure, while also considering the similarity of textual semantics. In the process of fine-tuning a large multimodal model suitable for topology recognition tasks, the model can simultaneously optimize the loss values of graph edit distance and textual semantic similarity, ensuring that the model can efficiently and accurately understand and analyze network topology maps in practical applications.The embodiment of the present application designs a topology diagram description template to support the storage and visualization of the scenario library; the description template standardizes the specific representation of different types and numbers of device nodes (such as servers, switches, firewalls, clients, etc.) and the connection relationships between them, and represents the nodes and edges of the network in JSON format to facilitate the formation of a network topology scenario library with the same format. The embodiment of the present application designs a network topology scenario library visualization method for loading network topology JSON data and creating a graphical network topology diagram, which displays the nodes of different types of devices and the connection relationships between them through different color labels; and uses a layout algorithm to make the structure more intuitively visualized, while providing legends and labels to clearly display the network structure.
[0092] Therefore, the embodiment of the present application integrates advanced technologies such as focus and dynamic web crawler technology, deep learning visual models and multimodal large models, and realizes a full-process automation system from search, classification, recognition to storage and visualization, reflecting a high level of technical integration and automation, and providing strong support for the research and application of network topology.
[0093] According to the method for automatically constructing a network topology scenario library proposed in the embodiment of the present application, the embodiment of the present application obtains a candidate network topology atlas, and based on a preset deep learning visual model, screens the network topology maps in the candidate network topology atlas that meet the preset real conditions to obtain a real network topology atlas; based on a preset multimodal large model and a preset topology description template, performs network topology recognition on the real network topology maps in the real network topology atlas, generates a topology recognition result for each real network topology map, and generates a network topology map recognition data set based on each real network topology map and the topology recognition result of each real network topology map; based on the network topology map recognition data set, loads the network topology JSON data, and creates a graphical network topology map based on the loading result, and constructs a network topology scenario library based on the graphical network topology map. Thus, the problems of difficulty in obtaining topology maps and low efficiency of automatic recognition in related technologies are solved, providing support for cyberspace security technology experiments.
[0094] Next, a device for automatically constructing a network topology scenario library according to an embodiment of the present application will be described with reference to the accompanying drawings.
[0095] Figure 5 It is a block diagram of the network topology scenario library automatic construction device according to an embodiment of the present application.
[0096] like Figure 5 As shown, the network topology scenario library automatic construction device 10 includes: an acquisition module 100, a screening module 200, a generation module 300 and a visualization module 400.
[0097] The acquisition module 100 acquires a candidate network topology atlas based on a focused crawler method of keyword construction and image reverse search;
[0098] A screening module 200 is configured to screen the network topology maps in the candidate network topology atlas that meet preset real conditions based on a preset deep learning visual model to obtain a real network topology atlas;
[0099] A generation module 300 is configured to perform network topology recognition on real network topology maps in a real network topology map set based on a preset multimodal large model and a preset topology map description template, generate a topology recognition result for each real network topology map, and generate a network topology map recognition dataset based on each real network topology map and the topology recognition result of each real network topology map;
[0100] The visualization module 400 is used to identify a data set based on the network topology map, load the network topology JSON data, create a graphical network topology map based on the loading result, and build a network topology scenario library based on the graphical network topology map.
[0101] Optionally, the acquisition module 100 is specifically used to: determine the type of network topology map to be obtained, construct effective search terms to obtain high-quality candidate network topology maps, wherein the type of network topology map to be obtained includes at least one of a local area network topology map, a critical infrastructure network topology map and a backbone network topology; crawl the network topology map according to the search keywords, obtain the network topology image file, and form a candidate network topology map set.
[0102] Optionally, before screening the network topology maps that meet preset real conditions in the candidate network topology atlas based on the preset deep learning visual model, the screening module 200 is also used to: obtain a training data set, wherein the training data set includes a first preset number of real network topology maps as positive samples and a second preset number of non-network topology maps as negative samples, and the first preset number and the second preset number are a preset ratio; based on the preset division ratio, the training data set is divided into a training set and a test set, and based on a preset composite loss function, the preset deep learning network is trained with the training set to obtain an optimized deep learning visual model; the optimized deep learning visual model is tested with the test set, and when the test result meets the preset test condition, the optimized deep learning visual model is used as the preset deep learning visual model; after obtaining the real network topology atlas, it is also used to: perform similarity extension retrieval on the real network topology atlas using image reverse search, and expand the candidate network topology atlas based on the extended retrieval.
[0103] Optionally, before performing network topology recognition on the real network topology maps in the real network topology map collection based on the preset multimodal big model and the preset topology map description template, the generation module 300 is also used to: describe the topological structure and information of the network topology map based on a JSON format file to obtain a preset topology map description template, wherein the JSON format file includes a node set and a connection relationship set; obtain a training data set, the training data set contains network topology map annotation information generated based on the multimodal big model and manually checked and corrected; fine-tune the preset multimodal big model based on the training data set, wherein a composite loss function including text semantic similarity loss and graph edit distance loss is used to optimize the preset multimodal big model.
[0104] It should be noted that the aforementioned explanation of the embodiment of the method for automatically constructing a network topology scenario library is also applicable to the device for automatically constructing a network topology scenario library of this embodiment, and will not be repeated here.
[0105] According to the automatic construction device of the network topology scene library proposed in the embodiment of the present application, the embodiment of the present application obtains a candidate network topology atlas, and based on a preset deep learning visual model, screens the network topology maps in the candidate network topology atlas that meet the preset real conditions to obtain a real network topology atlas; based on a preset multimodal large model and a preset topology description template, performs network topology recognition on the real network topology maps in the real network topology atlas, generates a topology recognition result for each real network topology map, and generates a network topology map recognition data set based on each real network topology map and the topology recognition result of each real network topology map; based on the network topology map recognition data set, loads the network topology JSON data, and creates a graphical network topology map based on the loading result, and constructs a network topology scene library based on the graphical network topology map. In this way, the problems of difficulty in obtaining topology maps and low efficiency of automatic recognition in related technologies are solved, providing support for cyberspace security technology experiments.
[0106] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.
[0107] Furthermore, the terms "first", "second", third", etc. are used herein for purposes of description and are in no way intended to refer to or imply relative importance or to imply a particular order of execution unless specifically defined by the context of this application. Thus, a feature defined to be a "first" feature can implicitly or explicitly include at least one of the feature.
[0108] Any process or method descriptions or blocks in flow charts described herein and elsewhere can represent modules, segments, or portions of code which include one or more executable instructions for implementing specific logical functions or steps in the process. Alternate implementations are included within the scope of the preferred embodiments of this application in which additional functionality can be added or where functions can be performed in differing orders or in different manners without departing from the spirit or scope of the application.
Claims
1. A method for automatically constructing a network topology scenario library, characterized in that: The following steps are involved: A focused crawler method based on keyword construction and image reverse search to obtain a candidate network topology atlas; Based on a preset deep learning visual model, the network topology maps in the candidate network topology atlas that meet the preset real conditions are screened to obtain a real network topology atlas; Based on a preset multimodal large model and a preset topology map description template, perform network topology recognition on the real network topology maps in the real network topology map set, generate a topology recognition result for each real network topology map, and generate a network topology map recognition dataset based on each real network topology map and the topology recognition result of each real network topology map; Based on the network topology map, a data set is identified, network topology JSON data is loaded, and a graphical network topology map is created based on the loading result, and the network topology scenario library is constructed according to the graphical network topology map.
2. The method according to claim 1, characterized in that The focused crawler method based on keyword construction and image reverse search obtains a candidate network topology graph, including: Determining the type of the network topology map to be obtained, and constructing effective search terms to obtain high-quality candidate network topology maps, wherein the type of the network topology map to be obtained includes at least one of a local area network topology map, a critical infrastructure network topology map, and a backbone network topology map; The network topology map is crawled according to the search keyword to obtain a network topology image file to form the candidate network topology map set.
3. The method according to claim 1, characterized in that After obtaining the real network topology atlas, the method further includes: For the real network topology atlas, image reverse search is used to perform similarity expansion retrieval, and the candidate network topology atlas is expanded according to the expansion retrieval.
4. The method according to claim 1, wherein Before screening the network topology maps that meet the preset real conditions in the candidate network topology map set based on the preset deep learning visual model, the method further includes: Obtaining a training data set, wherein the training data set includes a first preset number of real network topology maps as positive samples and a second preset number of non-network topology maps as negative samples, and the first preset number and the second preset number are in a preset ratio; Based on a preset division ratio, the training data set is divided into a training set and a test set, and based on a preset composite loss function, a preset deep learning network is trained using the training set to obtain an optimized deep learning vision model; The optimized deep learning vision model is tested using the test set, and when the test result meets the preset test condition, the optimized deep learning vision model is used as the preset deep learning vision model.
5. The method according to claim 1, characterized in that Before performing network topology recognition on the real network topology graph in the real network topology graph set based on the preset multimodal large model and the preset topology graph description template, the method further includes: Based on the JSON format file description of the topological structure and information of the network topology map, the preset topology map description template is obtained, wherein, The file in JSON format includes a node set and a connection relationship set.
6. The method according to claim 1, characterized in that Before performing network topology recognition on the real network topology graph in the real network topology graph set based on the preset multimodal large model and the preset topology graph description template, the method further includes: Acquire a training data set, wherein the training data set includes network topology diagram annotation information generated based on a large language model and manually verified and corrected; The preset multimodal large model is fine-tuned based on the training data set, wherein the preset multimodal large model is optimized using a composite loss function including text semantic similarity loss and graph edit distance loss.
7. A device for automatically constructing a network topology scenario library, characterized in that: include: The acquisition module uses a focused crawler method based on keyword construction and image reverse search to obtain a set of candidate network topology graphs; A screening module is used to screen the network topology maps in the candidate network topology atlas that meet preset real conditions based on a preset deep learning visual model to obtain a real network topology atlas; a generation module, configured to perform network topology recognition on the real network topology maps in the real network topology map set based on a preset multimodal large model and a preset topology map description template, generate a topology recognition result for each real network topology map, and generate a network topology map recognition dataset based on each real network topology map and the topology recognition result of each real network topology map; A visualization module is used to identify a data set based on the network topology map, load the network topology JSON data, create a graphical network topology map based on the loading result, and build the network topology scenario library based on the graphical network topology map.
8. The device according to claim 7, characterized in that The acquisition module is specifically used to: Determining the type of the network topology map to be obtained, and constructing effective search terms to obtain high-quality candidate network topology maps, wherein the type of the network topology map to be obtained includes at least one of a local area network topology map, a critical infrastructure network topology map, and a backbone network topology map; The network topology map is crawled according to the search keyword to obtain a network topology image file to form the candidate network topology map set.
9. The device according to claim 7, characterized in that After obtaining the real network topology atlas, the acquisition module is further configured to: Performing similarity extension retrieval on the real network topology atlas using image reverse search, and expanding the candidate network topology atlas based on the extension retrieval; Before screening the network topology maps that meet the preset real conditions in the candidate network topology map set based on the preset deep learning visual model, the screening module is further used to: Obtaining a training data set, wherein the training data set includes a first preset number of real network topology maps as positive samples and a second preset number of non-network topology maps as negative samples, and the first preset number and the second preset number are in a preset ratio; Based on a preset division ratio, the training data set is divided into a training set and a test set, and based on a preset composite loss function, a preset deep learning network is trained using the training set to obtain an optimized deep learning vision model; The optimized deep learning vision model is tested using the test set, and when the test result meets the preset test condition, the optimized deep learning vision model is used as the preset deep learning vision model.
10. The device according to claim 7, characterized in that Before performing network topology recognition on the real network topology graph in the real network topology graph set based on the preset multimodal large model and the preset topology graph description template, the generating module is further configured to: Describing the topological structure and information of the network topology graph based on a file in JSON format to obtain the preset topology graph description template, wherein the file in JSON format includes a node set and a connection relationship set; Acquire a training data set, wherein the training data set includes network topology diagram annotation information generated based on a multimodal large model and manually verified and corrected; The preset multimodal large model is fine-tuned based on the training data set, wherein the preset multimodal large model is optimized using a composite loss function including text semantic similarity loss and graph edit distance loss.