A network security dynamic early warning method and system based on a knowledge graph

By constructing a basic knowledge graph (KG) and analyzing potential attack paths through a knowledge graph-based dynamic early warning method for cybersecurity, this approach solves the problem of traditional methods being unable to connect cybersecurity events. It enables early identification and prediction of complex cyberattacks, reduces false negative and false positive rates, and enhances the proactiveness of cybersecurity protection.

CN120811768BActive Publication Date: 2025-11-11NANTONG SHIPPING COLLEGE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511270384.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-11-11
Estimated Expiration
2045-09-08

AI Technical Summary

Technical Problem

Existing technologies are ill-equipped to effectively address the high complexity, dynamism, and stealth of cyberattacks. They are unable to link fragmented cybersecurity incidents into a coherent attack intent, resulting in delayed warnings and a high false alarm rate. Security operations teams are overwhelmed by a massive amount of low-quality alerts and are unable to accurately identify lurking attacks.

Method used

A knowledge graph-based dynamic early warning method for cybersecurity is adopted. By constructing a basic knowledge graph (KG), the entity and interaction relationship of cybersecurity events are analyzed. A feature set (CE) is generated by combining behavioral feature algorithms, potential attack paths are analyzed, the threat index (ATI) is calculated, and an early warning report is generated. A closed-loop optimization mechanism is introduced.

Benefits of technology

It significantly improves the ability to identify and predict complex network attack chains at an early stage, reduces the false negative rate and false positive rate, realizes the transformation from passive defense to proactive early warning, and provides intuitive global attack chain analysis capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811768B_ABST
    Figure CN120811768B_ABST
Patent Text Reader

Abstract

The application discloses a kind of network security dynamic early warning method and system based on knowledge graph, it is related to network security early warning technical field, collects network security event original data Raw, analyzes core network entity and its interaction, constructs structured basic knowledge graph KG, constructs behavior characteristic algorithm based on core network entity and its interaction, generates behavior characteristic set CE, generates potential attack path set CP based on behavior characteristic set CE dynamic trigger point, in combination with candidate path propagation score pps High-threat path p_max is screened, and threat index ATI is calculated to generate early warning report AS, linkage response action and closed loop optimization.The present application correlates scattered events as attack chain through knowledge graph, dynamically quantifies risk and adaptively adjusts threshold, solves the problems of traditional method early warning lag, high false alarm rate and inability to associate multi-stage attack, significantly improves the early identification and blocking ability of complex threat.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security early warning technology, specifically to a network security dynamic early warning method and system based on knowledge graphs. Background Technology

[0002] Cybersecurity, as a core issue of the information age, has evolved from traditional perimeter protection and virus detection to proactive defense against complex and persistent threats. In the realm of proactive defense, cybersecurity early warning plays a crucial role, aiming to issue warnings before threats cause substantial damage, thus buying time for defense. However, cyberattacks are no longer isolated, single-point events, but rather exhibit multi-stage and dynamically evolving characteristics. Attackers first penetrate through a seemingly harmless entry point, then lurk and probe within the internal network, gradually escalating privileges and moving laterally, ultimately reaching the core target. The early stages of this chain-like attack are often characterized by weak and scattered features, making it difficult for traditional early warning mechanisms based on single-point events or simple rules to effectively capture and correlate them. Therefore, how to connect these seemingly scattered "points" into a "line," understand the attacker's intentions, predict their subsequent steps, and achieve truly dynamic early warning has become a key challenge that the cybersecurity field needs to overcome.

[0003] The shortcomings of existing technologies stem from their inability to effectively address the high complexity, dynamism, and stealth of cyberattacks. The diversity and heterogeneity of data sources make information integration difficult, hindering the construction of a comprehensive attack view. Over-reliance on static features and rules in analytical methods makes it impossible to keep pace with attackers' constantly evolving tactics, techniques, and processes. More importantly, there is a lack of a mechanism capable of deeply understanding the complex interactions between network entities, such as IPs, ports, protocols, users, and processes, and using this understanding to perform logical reasoning and risk propagation prediction. The resulting adverse effects are obvious: First, complex attacks are often only discovered after actual losses, such as data breaches or system crashes, significantly diminishing the value of early warnings. Second, security operations teams are overwhelmed by massive amounts of low-quality alerts, leading to "alert fatigue," where truly critical high-risk threat signals may be overlooked. Finally, while some statistical or machine learning-based anomaly detection methods can identify deviations from baseline behavior, they often lack sufficient contextual information to explain the nature and potential intent of the anomaly, making it difficult to distinguish benign anomalies from genuine attack precursors, and failing to clearly outline the complete path an attacker may be pursuing. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this invention provides a knowledge graph-based dynamic early warning method and system for network security, solving the problems mentioned in the background section.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a dynamic early warning method for network security based on knowledge graphs, comprising the following steps:

[0006] S1. Collect raw data of network security incidents through the network system, analyze the entity and interaction relationship of the collected raw data of network security incidents, and build a basic knowledge graph (KG).

[0007] S2. Based on the basic knowledge graph KG, combined with the latest cybersecurity events, the entities are mapped to the basic knowledge graph KG, and the context information of the interaction relationship between the entities related to the latest cybersecurity events is queried. A behavior feature algorithm is constructed, and a behavior feature set CE is generated.

[0008] Among them, the behavioral feature algorithms include connection frequency anomaly analysis algorithm, port-protocol singularity analysis algorithm and behavioral risk analysis algorithm;

[0009] The expression for the connection frequency anomaly analysis algorithm is as follows:

[0010] ;

[0011] In the formula, cfa represents the connection frequency anomaly, erf represents the Gaussian error function, log represents the logarithmic operation, frq_e represents the connection frequency of the source IP address, destination IP address, and destination port within the current time window in the current event, avg_sdp represents the moving average of the historical connection frequencies of the source IP address, destination IP address, and destination port recorded in the connection relationship, and avg_sdp represents the moving standard deviation of the historical connection frequencies of the source IP address, destination IP address, and destination port recorded in the connection relationship;

[0012] The expression for the port-protocol singularity analysis algorithm is as follows:

[0013] ;

[0014] In the formula, pus represents port-protocol singularity, count_sdpp represents the historical occurrence count of the combination of source IP address, destination IP address, destination port and protocol type recorded in the connection relationship, and count_sd represents the historical occurrence count of the combination of source IP address and destination IP address recorded in the connection relationship.

[0015] The behavioral risk analysis algorithm expression is as follows:

[0016] ;

[0017] In the formula, ibr represents the behavioral risk value, and tanh represents the hyperbolic tangent function. This indicates the session transmission rate of the current event. avg_sd represents the average rate of historical interactions between the source and destination IP addresses recorded in the transmission relationship. is_cmd represents the risk flag value of the host executing related commands recorded in the execution relationship. If the host executing related commands in the current event exists in the predefined known malicious commands table, the server log will map the risk flag value of the command according to the maliciousness level. The value range is [0, 1]. is_fid represents the risk flag value of the related file hash recorded in the transmission relationship. If the file hash in the current event exists in the predefined known malicious hash library, the server log will map the risk flag value of the file hash according to the maliciousness level. The value range is [0, 1].

[0018] S3. Based on the behavioral feature set CE as the trigger point, analyze the behavioral feature set CE and generate the potential attack path set CP, calculate the candidate path propagation score pps and generate the propagation score set PA;

[0019] S4. Based on the propagation score set PA, mark the path with the highest score as p_max, calculate the threat index ATI by combining the behavioral feature set CE of the event of the candidate path with the highest score p_max, compare the threat index ATI with the preset threat threshold ATI_G and generate a warning information report AS.

[0020] S5. Based on the content of the early warning information report AS, execute response actions through the API interface, record the execution results of the response actions to form the effect feedback dataset FL, perform closed-loop optimization based on the effect feedback dataset FL, and store the original network security event data Raw, the basic knowledge graph KG, and the early warning information report AS into the historical database His.

[0021] Preferably, S1 includes S11 and S12;

[0022] S11. Collect raw data of network security incidents from network security devices and server logs through the network system;

[0023] The raw data of a network security incident includes the source IP address (src), destination IP address (dst), destination port (prt), protocol type (pro), number of bytes transferred in the session (byt), session duration (dur), event timestamp (tms), the host command executed (cmd), and the hash of the relevant file (fid).

[0024] Preferably, in step S12, the raw data of the collected network security incidents is parsed to identify core network entities and their interaction relationships, and these entities and relationships are stored in a graph database to construct a basic knowledge graph (KG).

[0025] The core network entities include the source IP address src, the destination IP address dst, the destination port prt, the protocol type pro, the host execution command cmd, and the related file hash fid;

[0026] The interaction relationships of core network entities include connection relationship connect_to(src, dst, prt, pro, tms), execution relationship executes(src, cmd, tms), and transfer relationship transfers(src, dst, fid, tms).

[0027] Preferably, S2 includes S21;

[0028] S21. Based on the basic knowledge graph (KG) and combined with the latest cybersecurity events, entities are mapped to the basic knowledge graph KG. The context information of interaction relationships between entities related to the latest cybersecurity events is queried. A connection frequency anomaly analysis algorithm is constructed based on the connection relationship `connect_to(src, dst, prt, pro, tms)` to obtain the connection frequency anomaly score (CFA). A port-protocol singularity analysis algorithm is constructed based on the connection relationship `connect_to(src, dst, prt, pro, tms)` to obtain the port-protocol interaction singularity score (PUS). A behavioral risk analysis algorithm is constructed based on the execution relationship `executes(src, cmd, tms)` and the transfer relationship `transfers(src, dst, fid, tms)` to obtain the behavioral risk value (IBR). Combining the connection frequency anomaly score (CFA), the port-protocol interaction singularity score (PUS), and the behavioral risk value (IBR), a behavioral feature set (CE) is generated.

[0029] Preferably, S3 includes S31;

[0030] S31. Based on the behavioral feature set CE, dynamically determine the trigger point by statistically analyzing the distribution of connection frequency anomaly degree cfa, port-protocol interaction singularity pus and behavioral risk value ibr in the past week.

[0031] If the current event's connection frequency anomaly (CFA) is higher than the 95th percentile of all connection frequency anomalies (CFA) within a week, or the current event's port-protocol interaction singularity (PUS) is higher than the 98th percentile of all port-protocol interaction singularities (PUS) within a week, or the current event's behavioral risk value (IBR) is higher than the 90th percentile of all behavioral risk values ​​(IBR) within a week, then the trigger point requirement is met. Based on the event of the behavioral feature set (CE) that meets the trigger point requirement, the trigger point is used to retrieve the subgraph structure that matches the attack pattern fragment of the network behavior, generate the potential attack path set (CP), and assign a unique identifier CP={p_1, p_2, p_3, ..., p_m} to each candidate path, where m represents the total number of candidate paths. Based on the potential attack path set (CP), a candidate path propagation scoring algorithm is constructed and the candidate path propagation score (pps) is calculated to generate the propagation score set (PA).

[0032] The candidate path propagation scoring algorithm is expressed as follows:

[0033] ;

[0034] In the formula, p_i represents the candidate path with a unique identifier p_i in the potential attack path set CP, n(p_i) represents the total number of events on the candidate path p_i, cfa_(i,j) represents the connection frequency anomaly cfa of the j-th event on the candidate path p_i, pus_(i,j) represents the port-protocol interaction singularity pus of the j-th event on the candidate path p_i, ibr_(i,j) represents the behavioral risk value ibr of the j-th event on the candidate path p_i, exp represents the natural exponential function, hop_(i,j) represents the number of hops of the j-th event on the candidate path p_i, deg_(i,j) represents the number of connections of the j-th event in the basic knowledge graph KG, and α represents the preset attenuation factor.

[0035] Preferably, S4 includes S41 and S42;

[0036] S41. Based on the propagation score set PA, the path with the highest score is marked as p_max. Combine the behavioral feature set CE of the event of the candidate path with the highest score p_max to construct a threat index algorithm, calculate the threat index ATI, and compare the threat index ATI with the preset dynamic warning threshold ATI_G.

[0037] If the threat index ATI is less than the preset dynamic warning threshold ATI_G, it is determined to be a no-risk warning and a warning information report AS is generated.

[0038] If the threat index ATI is greater than or equal to the preset dynamic warning threshold ATI_G, then a risk warning is determined to exist and a warning information report AS is generated.

[0039] The early warning information report includes the following:

[0040] Risk warning assessment results, threat index (ATI), highest-scoring candidate path p_max, and core network entities involved in the highest-scoring candidate path p_max.

[0041] Preferably, in S42, the threat index algorithm expression is as follows:

[0042] ;

[0043] In the formula, PA(p_max) represents the propagation score of the candidate path p_max with the highest score in the propagation score set PA, avg_cfaG represents the average value of connection frequency anomaly (cfa) calculated by combining all raw data of network security events within the current time window W, avg_pusG represents the average value of port-protocol interaction singularity (pus) calculated by combining all raw data of network security events within the current time window W, β represents the preset weighting coefficient of the average global connection frequency anomaly (cfa), and γ represents the preset weighting coefficient of the average global port-protocol interaction singularity (pus).

[0044] Preferably, S5 includes S51;

[0045] S51. Based on the content of the early warning information report AS, a response action is executed through the API interface, and the relevant basic knowledge graph KG subgraph is retrieved on the visualization platform to display the following content:

[0046] The event nodes and relationships on the highest-scoring candidate path p_max are highlighted, along with the connection frequency anomaly score (cfa), port-protocol interaction singularity score (pus), and behavioral risk value (ibr) for each event on the highest-scoring candidate path p_max. The order of time occurrence is displayed with the event timestamp (tms) as the time axis coordinate.

[0047] The execution results of response actions and the analyst's confirmation of the correctness of the warning are recorded to form the effect feedback dataset FL. Based on the effect feedback dataset FL, the analyst dynamically adjusts the trigger point of the behavioral feature set CE and the influence factor α in the candidate path propagation scoring algorithm. The original network security event data Raw, the basic knowledge graph KG and the warning information report AS are stored in the historical database His.

[0048] A knowledge graph-based dynamic early warning system for cybersecurity includes a knowledge graph construction module, a behavioral feature quantification module, a propagation scoring module, an early warning generation module, and a visualization response and optimization module.

[0049] The knowledge graph construction module collects raw data of network security incidents through the network system, analyzes the entities and interaction relationships of the collected raw data, and constructs a basic knowledge graph (KG).

[0050] The behavioral feature quantification module maps entities in the basic knowledge graph (KG) to the latest cybersecurity events, queries the context information of the interaction relationships between entities related to the latest cybersecurity events, constructs a behavioral feature algorithm, and generates a behavioral feature set (CE).

[0051] Among them, the behavioral feature algorithms include connection frequency anomaly analysis algorithm, port-protocol singularity analysis algorithm and behavioral risk analysis algorithm;

[0052] The expression for the connection frequency anomaly analysis algorithm is as follows:

[0053] ;

[0054] In the formula, cfa represents the connection frequency anomaly, erf represents the Gaussian error function, log represents the logarithmic operation, frq_e represents the connection frequency of source IP address src, destination IP address dst, and destination port prt within the current time window W in the current event, avg_sdp represents the moving average of the historical connection frequencies of source IP address src, destination IP address dst, and destination port prt recorded in the connection relationship connect_to(src, dst, prt, pro, tms), and avg_sdp represents the moving standard deviation of the historical connection frequencies of source IP address src, destination IP address dst, and destination port prt recorded in the connection relationship connect_to(src, dst, prt, pro, tms).

[0055] The expression for the port-protocol singularity analysis algorithm is as follows:

[0056] ;

[0057] In the formula, pus represents port-protocol singularity, count_sdpp represents the historical occurrence count of the combination of source IP address src, destination IP address dst, destination port prt, and protocol type pro recorded in the connection relationship connect_to(src, dst, prt, pro, tms), and count_sd represents the historical occurrence count of the combination of source IP address src and destination IP address dst recorded in the connection relationship connect_to(src, dst, prt, pro, tms).

[0058] The behavioral risk analysis algorithm expression is as follows:

[0059] ;

[0060] In the formula, ibr represents the behavioral risk value, and tanh represents the hyperbolic tangent function. This indicates the session transfer rate of the current event. avg_sd represents the average historical rate of interaction between the source IP address src and the destination IP address dst, recorded in the transfers(src, dst, fid, tms) relationship. is_cmd represents the risk flag value of the host executing the relevant command cmd, recorded in the executes(src, cmd, tms) relationship. If the command cmd executed by the host in the current event exists in the predefined known malicious command table, the server log will map the risk flag value of the command according to the maliciousness level. The value range is [0, 1]. is_fid represents the risk flag value of the relevant file hash fid, recorded in the transfers(src, dst, fid, tms) relationship. If the file hash fid in the current event exists in the predefined known malicious hash library, the server log will map the risk flag value of the file hash according to the maliciousness level. The value range is [0, 1].

[0061] The propagation scoring module analyzes the behavioral feature set CE as the trigger point and generates a potential attack path set CP. It then calculates the candidate path propagation score pps and generates a propagation score set PA.

[0062] The early warning generation module marks the path with the highest score as p_max based on the propagation score set PA, calculates the threat index ATI by combining the behavioral feature set CE of the event of the candidate path with the highest score p_max, compares the threat index ATI with the preset threat threshold ATI_G, and generates an early warning information report AS.

[0063] The visualization response and optimization module executes response actions through API interfaces based on the content of the early warning information report (AS), records the execution results of the response actions to form an effect feedback dataset (FL), performs closed-loop optimization based on the effect feedback dataset (FL), and stores the original network security event data (Raw), the basic knowledge graph (KG), and the early warning information report (AS) in the historical database (His).

[0064] This invention provides a knowledge graph-based dynamic early warning method and system for network security, which has the following beneficial effects:

[0065] (1) By constructing a knowledge graph-based dynamic early warning system for network security, the early identification and prediction capabilities of complex network attack chains have been significantly improved. Traditional methods rely on single-point events or static rules, making it difficult to capture multi-stage and dynamically evolving attack behaviors, resulting in delayed early warnings and high false alarm rates. This method innovatively combines knowledge graph technology with behavioral feature quantification. By deeply analyzing network entities and their interaction relationships, it connects scattered events into logical attack paths and combines them with a risk propagation model to assess global threats. The system introduces a closed-loop optimization mechanism, using the effect feedback dataset FL to dynamically adjust algorithm parameters, adaptively responding to new attack methods and effectively reducing the false alarm and false alarm rates. In addition, the visualization platform highlights the candidate path p_max with the highest score and its associated events, providing intuitive decision support for the security team and realizing the transformation from passive defense to proactive early warning.

[0066] (2) By collecting raw data of network security incidents, analyzing entities and their interaction relationships, and constructing a structured basic knowledge graph (KG), the system transforms heterogeneous logs into a network behavior knowledge base with historical context, laying the foundation for subsequent analysis. Based on the basic knowledge graph (KG), the system calculates behavioral feature values ​​in conjunction with the latest events: connection frequency anomaly (CFA) quantifies the frequency deviation of the src-dst-prt combination from the historical baseline using a Gaussian error function; port-protocol interaction singularity (PUS) reflects the rarity of the prt-pro combination in a specific src-dst pair; and behavioral risk value (IBR) integrates session rate, command cmd, and file fid maliciousness markers to comprehensively assess event risk. These feature values ​​generate a behavioral feature set (CE), enabling the system to capture early anomalies with low frequency and weak features, such as covert penetration using legitimate protocols, filling the blind spots of traditional rule bases and significantly improving sensitivity to latent attacks.

[0067] (3) Based on the CE dataset, potential attack path analysis is triggered to generate a candidate path set CP, and the path threat is quantified by propagation score pps. The scoring algorithm comprehensively considers the behavioral characteristics of path events, hop count hop_j, and node connection count deg_j, and combines the attenuation factor α to suppress noise interference in deep paths, and selects high-threat paths p_max. The threat index ATI further integrates the global feature mean and weight coefficient, and dynamically compares the threshold ATI_G to generate a warning report AS. The response action is linked through the API interface, and the feedback data FL is recorded to optimize the model parameters and trigger conditions, forming a closed loop iteration. The visualization platform displays the p_max path details on the time axis tms, highlights abnormal nodes and interaction relationships, and helps analysts quickly locate key nodes in the attack chain. This method not only realizes the reasoning from single-point anomalies to global attack intent, but also improves the adaptability to new attack patterns through continuous learning, providing core technical support for building an intelligent and self-evolving network security protection system. Attached Figure Description

[0068] Figure 1 This is a schematic diagram illustrating the steps of a knowledge graph-based dynamic early warning method for network security according to the present invention.

[0069] Figure 2 This is a schematic diagram of a knowledge graph-based dynamic early warning system for network security according to the present invention.

[0070] Figure 3 This is a schematic diagram of the data structure relationship of the basic knowledge graph of this invention. Detailed Implementation

[0071] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0072] Example 1

[0073] This invention provides a knowledge graph-based dynamic early warning method for network security. Please refer to [link / reference]. Figure 1 This includes the following steps:

[0074] S1. Collect raw data of network security incidents through the network system, analyze the entity and interaction relationship of the collected raw data of network security incidents, and build a basic knowledge graph (KG).

[0075] S2. Based on the basic knowledge graph KG, combined with the latest cybersecurity events, the entities are mapped to the basic knowledge graph KG, and the context information of the interaction relationship between the entities related to the latest cybersecurity events is queried. A behavior feature algorithm is constructed, and a behavior feature set CE is generated.

[0076] Among them, the behavioral feature algorithms include connection frequency anomaly analysis algorithm, port-protocol singularity analysis algorithm and behavioral risk analysis algorithm;

[0077] The expression for the connection frequency anomaly analysis algorithm is as follows:

[0078] ;

[0079] In the formula, cfa represents the connection frequency anomaly, erf represents the Gaussian error function, log represents the logarithmic operation, frq_e represents the connection frequency of the source IP address, destination IP address, and destination port within the current time window in the current event, avg_sdp represents the moving average of the historical connection frequencies of the source IP address, destination IP address, and destination port recorded in the connection relationship, and avg_sdp represents the moving standard deviation of the historical connection frequencies of the source IP address, destination IP address, and destination port recorded in the connection relationship;

[0080] The expression for the port-protocol singularity analysis algorithm is as follows:

[0081] ;

[0082] In the formula, pus represents port-protocol singularity, count_sdpp represents the historical occurrence count of the combination of source IP address, destination IP address, destination port and protocol type recorded in the connection relationship, and count_sd represents the historical occurrence count of the combination of source IP address and destination IP address recorded in the connection relationship.

[0083] The behavioral risk analysis algorithm expression is as follows:

[0084] ;

[0085] In the formula, ibr represents the behavioral risk value, and tanh represents the hyperbolic tangent function. This indicates the session transmission rate of the current event. avg_sd represents the average rate of historical interactions between the source and destination IP addresses recorded in the transmission relationship. is_cmd represents the risk flag value of the host executing related commands recorded in the execution relationship. If the host executing related commands in the current event exists in the predefined known malicious commands table, the server log will map the risk flag value of the command according to the maliciousness level. The value range is [0, 1]. is_fid represents the risk flag value of the related file hash recorded in the transmission relationship. If the file hash in the current event exists in the predefined known malicious hash library, the server log will map the risk flag value of the file hash according to the maliciousness level. The value range is [0, 1].

[0086] S3. Based on the behavioral feature set CE as the trigger point, analyze the behavioral feature set CE and generate the potential attack path set CP, calculate the candidate path propagation score pps and generate the propagation score set PA;

[0087] S4. Based on the propagation score set PA, mark the path with the highest score as p_max, calculate the threat index ATI by combining the behavioral feature set CE of the event of the candidate path with the highest score p_max, compare the threat index ATI with the preset threat threshold ATI_G and generate a warning information report AS.

[0088] S5. Based on the content of the early warning information report AS, execute response actions through the API interface, record the execution results of the response actions to form the effect feedback dataset FL, perform closed-loop optimization based on the effect feedback dataset FL, and store the original network security event data Raw, the basic knowledge graph KG, and the early warning information report AS into the historical database His.

[0089] In this embodiment, raw data of network security incidents is collected, core network entities and their interactions are analyzed, and a structured basic knowledge graph (KG) is constructed. This transforms scattered logs into a global view with historical context, effectively integrating multi-source heterogeneous data and overcoming the problem of information silos in traditional methods. Based on the basic knowledge graph KG, a behavioral feature set (CE) is generated by calculating connection frequency anomaly degree (CFA), port-protocol interaction singularity (PUS), and behavioral risk value (IBR). This enables accurate capture of low-frequency, weak-feature anomalies, compensating for the insensitivity of static rule bases to early signals of multi-stage attacks. Furthermore, by analyzing the CE dataset, a potential attack path set (CP) is triggered. Combined with the candidate path propagation score (PPS), high-threat paths (p_max) are selected, and a warning report (AS) is dynamically generated based on the threat index (ATI), linking response actions and closed-loop optimization. This method not only fundamentally solves the problem that traditional technologies cannot connect "scattered events" into "attack intent," but also provides security teams with intuitive global attack chain analysis capabilities by highlighting the temporal relationship of the p_max path through a visualization platform, achieving a leapfrog improvement from passive response to dynamic prediction.

[0090] Example 2

[0091] This embodiment is an explanation based on Embodiment 1. Please refer to it. Figure 1 and Figure 3 Specifically: S1 includes S11 and S12;

[0092] S11. Collect raw data of network security incidents from network security devices and server logs through the network system;

[0093] The raw data of a network security incident includes the source IP address (src), destination IP address (dst), destination port (prt), protocol type (pro), number of bytes transferred in the session (byt), session duration (dur), timestamp of the event (tms), the command executed by the host (cmd), and the hash of the relevant file (fid).

[0094] S12. Parse the raw data of the collected network security incidents, identify the core network entities and their interaction relationships, store these entities and relationships in a graph database, and construct a basic knowledge graph (KG).

[0095] The core network entities include the source IP address src, the destination IP address dst, the destination port prt, the protocol type pro, the host execution command cmd, and the related file hash fid;

[0096] The interaction relationships of core network entities include connection relationship connect_to(src, dst, prt, pro, tms), execution relationship executes(src, cmd, tms), and transfer relationship transfers(src, dst, fid, tms).

[0097] S2 includes S21;

[0098] S21. Based on the basic knowledge graph KG and combined with the latest cybersecurity events, map the entities in the basic knowledge graph KG, and query the context information of the interaction relationships of the entities related to the latest cybersecurity events. Construct a connection frequency anomaly analysis algorithm based on the connection relationship connect_to(src, dst, prt, pro, tms) to obtain the connection frequency anomaly degree CFA. Construct a port-protocol singularity analysis algorithm based on the connection relationship connect_to(src, dst, prt, pro, tms) to obtain the port-protocol interaction singularity PuS. Construct a behavioral risk analysis algorithm based on the execution relationship executes(src, cmd, tms) and the transfer relationship transfers(src, dst, fid, tms) to obtain the behavioral risk value IBR. Combine the connection frequency anomaly degree CFA, the port-protocol interaction singularity PuS, and the behavioral risk value IBR to generate a behavioral feature set CE.

[0099] In this embodiment, the ability to accurately identify covert attacks is further enhanced by refining data collection, knowledge graph construction, and behavioral feature quantification methods. Specifically, by collecting raw data of network security incidents, the system is ensured to capture multi-dimensional interaction relationships, laying a data foundation for building a high-precision knowledge graph (KG). Furthermore, the core network entities and their interaction relationships in the raw data are analyzed, and a structured expression of dynamic relationships is achieved through graph database storage, solving the context loss problem caused by the discrete entity relationships in traditional methods. Building upon this foundation, a scientifically quantified behavioral feature algorithm is proposed: Connection Frequency Anomaly (CFA) uses a Gaussian error function to calculate the deviation of the connection frequencies of source IP address (src), destination IP address (dst), and destination port (prt) from the historical baseline, eliminating misjudgments of single high-frequency events. Port-Protocol Interaction Singularity (PUS) dynamically assesses the singularity of the combination of port prt and protocol type pro relative to the historical interactions between source IP address (src) and destination IP address (dst) based on historical occurrence counts, accurately identifying abnormal interactions disguised as legitimate protocols. Behavioral Risk Value (IBR) quantifies session rate anomalies using the hyperbolic tangent function (tanh) and is superimposed with predefined risk marker values ​​for command (cmd) and file hash (fid) to achieve multi-dimensional risk fusion. These methods not only improve the scientific rigor of feature calculation but also effectively address attacks launched by attackers using variant tools or unknown vulnerabilities by dynamically associating known malicious command tables and known malicious file hash libraries with real-time updates to risk markers. This compensates for the shortcomings of traditional static rule bases in responding to new threats with lag, providing reliable technical support for the early blocking of complex attack chains.

[0100] Example 3

[0101] This embodiment is an explanation based on Embodiment 2. Please refer to it. Figure 1 Specifically: S3 includes S31;

[0102] S31. Based on the behavioral feature set CE, dynamically determine the trigger point by statistically analyzing the distribution of connection frequency anomaly degree cfa, port-protocol interaction singularity pus and behavioral risk value ibr in the past week.

[0103] If the current event's connection frequency anomaly (CFA) is higher than the 95th percentile of all connection frequency anomalies (CFA) within a week, or the current event's port-protocol interaction singularity (PUS) is higher than the 98th percentile of all port-protocol interaction singularities (PUS) within a week, or the current event's behavioral risk value (IBR) is higher than the 90th percentile of all behavioral risk values ​​(IBR) within a week, then the trigger point requirement is met. Based on the event of the behavioral feature set (CE) that meets the trigger point requirement, the trigger point is used to retrieve the subgraph structure that matches the attack pattern fragment of the network behavior, generate the potential attack path set (CP), and assign a unique identifier CP={p_1, p_2, p_3, ..., p_m} to each candidate path, where m represents the total number of candidate paths. Based on the potential attack path set (CP), a candidate path propagation scoring algorithm is constructed and the candidate path propagation score (pps) is calculated to generate the propagation score set (PA).

[0104] The candidate path propagation scoring algorithm is expressed as follows:

[0105] ;

[0106] In the formula, p_i represents the candidate path with a unique identifier p_i in the potential attack path set CP, n(p_i) represents the total number of events on candidate path p_i, cfa_(i,j) represents the connection frequency anomaly cfa of the j-th event on candidate path p_i, pus_(i,j) represents the port-protocol interaction singularity pus of the j-th event on candidate path p_i, ibr_(i,j) represents the behavioral risk value ibr of the j-th event on candidate path p_i, exp represents the natural exponential function, hop_(i,j) represents the hop count of the j-th event on candidate path p_i, deg_(i,j) represents the number of connections of the j-th event on candidate path p_i in the basic knowledge graph KG, and α represents the preset attenuation factor.

[0107] A specific example of calculating the propagation score of a candidate path:

[0108] Current event: External IP 1.2.3.4 connects to port 80 of web server 192.168.1.100;

[0109] The current event connection frequency anomaly score (cfa) is 0.90, located at the 98th percentile within one week;

[0110] The current event port-protocol interaction singularity pus = 0.85, located at the 70th percentile within a week;

[0111] The current event behavior risk value (ibr) is 0.75, which is at the 85th percentile within one week.

[0112] In the current event, the connection frequency anomaly CFA is higher than the 95th percentile of all connection frequency anomalies CFA within a week, meeting the trigger point requirements. The current event is used as the trigger point to generate a potential attack path set CP with a decay factor α=0.1.

[0113] A candidate path p_i in the potential attack path set CP consists of three events, as follows:

[0114] Event 1: Web server 192.168.1.100 executed the command powershell -enc ABC;

[0115] The connection frequency anomaly of Event 1 is cfa_(i, 1) = 0.80;

[0116] Event 1 port-protocol interaction singularity pus_(i, 1) = 0.70;

[0117] The behavioral risk value for Event 1 is ibr_(i, 1) = 0.60;

[0118] The number of hops for event 1 on candidate path p_i is hop_(i, 1) = 1;

[0119] The number of connections in the basic knowledge graph KG for the first event on candidate path p_i is deg_(i,1) = 10;

[0120] Calculate the propagation score of event 1 in candidate path p_i:

[0121] ;

[0122] Event 2: External IP 1.2.3.4 connects to port 80 of web server 192.168.1.100;

[0123] The connection frequency anomaly of event 2 is cfa_(i,2) = 0.90;

[0124] Event 2 port-protocol interaction singularity pus_(i,2) = 0.85;

[0125] The behavioral risk value for event 2 is ibr_(i,2) = 0.75;

[0126] The number of hops on candidate path p_i for event 2 is hop_(i, 2) = 2;

[0127] The number of connections of the second event on candidate path p_i in the basic knowledge graph KG is deg_(i,2) = 5;

[0128] Calculate the event 2 propagation score in candidate path p_i:

[0129]

[0130] Event 3: Web service 192.168.1.100 connects to port 445 of internal server 192.168.1.50;

[0131] The connection frequency anomaly of event 3 is cfa_(i, 3) = 0.70;

[0132] Event 3 port-protocol interaction singularity pus_(i, 3) = 0.90;

[0133] The behavioral risk value for event 3 is ibr_(i,3) = 0.80;

[0134] The number of hops for event 3 on candidate path p_i is hop_(i, 3) = 3;

[0135] The number of connections of the 3rd event on candidate path p_i in the basic knowledge graph KG is deg_(i, 3) = 8;

[0136] Calculate the event 3 propagation score in candidate path p_i:

[0137] ;

[0138] Calculate the propagation score of candidate path p_i:

[0139] .

[0140] In this embodiment, a dynamic trigger point determination rule is introduced. Based on percentile thresholds for connection frequency anomaly (CFA), port-protocol interaction singularity (PUS), and behavioral risk value (IBR), the generation of the potential attack path set (CP) is triggered only when the event feature value trigger point is required, effectively avoiding the false triggering or missed detection problems caused by traditional fixed thresholds. Furthermore, a candidate path propagation scoring algorithm is proposed. This algorithm comprehensively considers the behavioral feature value of each event in the path, the hop count (hop_j) reflecting the attack chain depth, and the node connection count (deg_j) reflecting the network influence of the target node, and suppresses noise interference in deep paths through a decay factor α. This design not only quantifies the local anomalies of the attack path but also combines dynamic weight allocation of the network topology, making the scoring results more consistent with actual threat scenarios. For paths with a high hop count (hop_j) but a low node connection count (deg_j), the algorithm automatically reduces its propagation score through the denominator, thereby prioritizing attack paths of key hub nodes. Compared to the isolated analysis of single-point anomalies by traditional methods, scientifically modeling the propagation characteristics of attack paths can accurately identify high-risk paths for attackers to move laterally within the internal network, providing an interpretable basis for decision-making in blocking multi-stage attack chains.

[0141] Example 4

[0142] This embodiment is an explanation based on Embodiment 3. Please refer to it. Figure 1 Specifically: S4 includes S41 and S42;

[0143] S41. Based on the propagation score set PA, the path with the highest score is marked as p_max. Combine the behavioral feature set CE of the event of the candidate path with the highest score p_max to construct a threat index algorithm, calculate the threat index ATI, and compare the threat index ATI with the preset dynamic warning threshold ATI_G.

[0144] If the threat index ATI is less than the preset dynamic warning threshold ATI_G, it is determined to be a no-risk warning and a warning information report AS is generated.

[0145] If the threat index ATI is greater than or equal to the preset dynamic warning threshold ATI_G, then a risk warning is determined to exist and a warning information report AS is generated.

[0146] The early warning information report includes the following:

[0147] Risk warning assessment results, threat index (ATI), highest-scoring candidate path p_max, and core network entities involved in the highest-scoring candidate path p_max;

[0148] S42. The algorithm expression for the threat index is as follows:

[0149] ;

[0150] In the formula, PA(p_max) represents the propagation score of the candidate path p_max with the highest score in the propagation score set PA, avg_cfaG represents the average value of connection frequency anomaly cfa calculated in the current time window W by combining all network security event raw data Raw, avg_pusG represents the average value of port-protocol interaction singularity pus calculated in the current time window W by combining all network security event raw data Raw, β represents the preset weight coefficient of the global connection frequency anomaly cfa average value, and γ represents the preset weight coefficient of the global port-protocol interaction singularity pus average value.

[0151] S5 includes S51;

[0152] S51. Based on the content of the early warning information report AS, a response action is executed through the API interface, and the relevant basic knowledge graph KG subgraph is retrieved on the visualization platform to display the following content:

[0153] The event nodes and relationships on the highest-scoring candidate path p_max are highlighted, along with the connection frequency anomaly score (cfa), port-protocol interaction singularity score (pus), and behavioral risk value (ibr) for each event on the highest-scoring candidate path p_max. The order of time occurrence is displayed with the event timestamp (tms) as the time axis coordinate.

[0154] The execution results of response actions and the analyst's confirmation of the correctness of the warning are recorded to form the effect feedback dataset FL. Based on the effect feedback dataset FL, the analyst dynamically adjusts the trigger point of the behavioral feature set CE and the influence factor α in the candidate path propagation scoring algorithm. The original network security event data Raw, the basic knowledge graph KG and the warning information report AS are stored in the historical database His.

[0155] In this embodiment: the highest-scoring path p_max is selected based on the propagation score set PA, and the threat index ATI is calculated by combining its context event dataset CE. The path propagation score is dynamically fused with the average value of connection frequency anomaly (cfa) avg_cfaG and the average value of port-protocol interaction singularity (pus) avg_pusG within the current time window W. Weighting coefficients are introduced to balance local path threats with the overall network situation. Compared to traditional static thresholds, this method dynamically compares the threat index ATI with a preset threshold ATI_G, enabling it to adapt to the risk baseline of different network environments. For example, it automatically relaxes the threshold during peak business periods to reduce false alarms, or tightens the threshold during periods of high attack incidence to enhance sensitivity, significantly improving the flexibility of the early warning strategy. Furthermore, it uses an API interface to link automated responses and highlights the temporal relationship of the highest-scoring candidate path p_max on a visualization platform. Using the event occurrence timestamp (tms) as the axis, the behavioral characteristics of the event, and related subgraphs, it provides security analysts with a panoramic view of attack intent, path evolution, and key nodes, solving the decision-making blind spot problem caused by the fragmentation of traditional alarm information. Simultaneously, the system records the execution results of response actions and analyst feedback to form an effect feedback dataset FL. Through manual calibration and data accumulation in the historical database His, closed-loop optimization of model parameters is achieved. This mechanism not only overcomes the model rigidity defects caused by the lack of feedback in traditional methods, but also enhances the system's robustness by continuously learning new attack patterns, ultimately constructing an integrated dynamic defense system of "detection-response-optimization".

[0156] Example 5

[0157] A knowledge graph-based dynamic early warning system for cybersecurity; please refer to [reference needed]. Figure 2 Specifically, it includes a knowledge graph construction module, a behavioral feature quantification module, a propagation scoring module, an early warning generation module, and a visualization response and optimization module;

[0158] The knowledge graph construction module collects raw data of network security incidents through the network system, analyzes the entities and interaction relationships of the collected raw data, and constructs a basic knowledge graph (KG).

[0159] The behavioral feature quantification module maps entities in the basic knowledge graph (KG) to the latest cybersecurity events, queries the context information of the interaction relationships between entities related to the latest cybersecurity events, constructs a behavioral feature algorithm, and generates a behavioral feature set (CE).

[0160] Among them, the behavioral feature algorithms include connection frequency anomaly analysis algorithm, port-protocol singularity analysis algorithm and behavioral risk analysis algorithm;

[0161] The expression for the connection frequency anomaly analysis algorithm is as follows:

[0162] ;

[0163] In the formula, cfa represents the connection frequency anomaly, erf represents the Gaussian error function, log represents the logarithmic operation, frq_e represents the connection frequency of source IP address src, destination IP address dst, and destination port prt within the current time window W in the current event, avg_sdp represents the moving average of the historical connection frequencies of source IP address src, destination IP address dst, and destination port prt recorded in the connection relationship connect_to(src, dst, prt, pro, tms), and avg_sdp represents the moving standard deviation of the historical connection frequencies of source IP address src, destination IP address dst, and destination port prt recorded in the connection relationship connect_to(src, dst, prt, pro, tms).

[0164] The expression for the port-protocol singularity analysis algorithm is as follows:

[0165] ;

[0166] In the formula, pus represents port-protocol singularity, count_sdpp represents the historical occurrence count of the combination of source IP address src, destination IP address dst, destination port prt, and protocol type pro recorded in the connection relationship connect_to(src, dst, prt, pro, tms), and count_sd represents the historical occurrence count of the combination of source IP address src and destination IP address dst recorded in the connection relationship connect_to(src, dst, prt, pro, tms).

[0167] The behavioral risk analysis algorithm expression is as follows:

[0168] ;

[0169] In the formula, ibr represents the behavioral risk value, and tanh represents the hyperbolic tangent function. This indicates the session transfer rate of the current event. avg_sd represents the average historical rate of interaction between the source IP address src and the destination IP address dst, recorded in the transfers(src, dst, fid, tms) relationship. is_cmd represents the risk flag value of the host executing the relevant command cmd, recorded in the executes(src, cmd, tms) relationship. If the command cmd executed by the host in the current event exists in the predefined known malicious command table, the server log will map the risk flag value of the command according to the maliciousness level. The value range is [0, 1]. is_fid represents the risk flag value of the relevant file hash fid, recorded in the transfers(src, dst, fid, tms) relationship. If the file hash fid in the current event exists in the predefined known malicious hash library, the server log will map the risk flag value of the file hash according to the maliciousness level. The value range is [0, 1].

[0170] The propagation scoring module analyzes the behavioral feature set CE as the trigger point and generates a potential attack path set CP. It then calculates the candidate path propagation score pps and generates a propagation score set PA.

[0171] The early warning generation module marks the path with the highest score as p_max based on the propagation score set PA, calculates the threat index ATI by combining the behavioral feature set CE of the event of the candidate path with the highest score p_max, compares the threat index ATI with the preset threat threshold ATI_G, and generates an early warning information report AS.

[0172] The visualization response and optimization module executes response actions through API interfaces based on the content of the early warning information report (AS), records the execution results of the response actions to form an effect feedback dataset (FL), performs closed-loop optimization based on the effect feedback dataset (FL), and stores the original network security event data (Raw), the basic knowledge graph (KG), and the early warning information report (AS) in the historical database (His).

[0173] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A knowledge graph-based dynamic early warning method for network security, characterized in that: Includes the following steps: S1. Collect raw data of network security incidents through the network system, analyze the entity and interaction relationship of the collected raw data of network security incidents, and build a basic knowledge graph (KG); S2. Based on the basic knowledge graph KG, combined with the latest cybersecurity events, the entities are mapped to the basic knowledge graph KG, and the context information of the interaction relationship between the entities related to the latest cybersecurity events is queried. A behavior feature algorithm is constructed, and a behavior feature set CE is generated. Among them, the behavioral feature algorithms include connection frequency anomaly analysis algorithm, port-protocol singularity analysis algorithm and behavioral risk analysis algorithm; The expression for the connection frequency anomaly analysis algorithm is as follows: ; In the formula, cfa represents the connection frequency anomaly, erf represents the Gaussian error function, log represents the logarithmic operation, frq_e represents the connection frequency of the source IP address, destination IP address, and destination port within the current time window in the current event, avg_sdp represents the moving average of the historical connection frequencies of the source IP address, destination IP address, and destination port recorded in the connection relationship, and avg_sdp represents the moving standard deviation of the historical connection frequencies of the source IP address, destination IP address, and destination port recorded in the connection relationship; The expression for the port-protocol singularity analysis algorithm is as follows: ; In the formula, pus represents port-protocol singularity, count_sdpp represents the historical occurrence count of the combination of source IP address, destination IP address, destination port and protocol type recorded in the connection relationship, and count_sd represents the historical occurrence count of the combination of source IP address and destination IP address recorded in the connection relationship. The behavioral risk analysis algorithm expression is as follows: ; In the formula, ibr represents the behavioral risk value, and tanh represents the hyperbolic tangent function. This indicates the session transmission rate of the current event. avg_sd represents the average rate of historical interactions between the source and destination IP addresses recorded in the transmission relationship. is_cmd represents the risk flag value of the host executing related commands recorded in the execution relationship. If the host executing related commands in the current event exists in the predefined known malicious commands table, the server log will map the risk flag value of the command according to the maliciousness level. The value range is [0, 1]. is_fid represents the risk flag value of the related file hash recorded in the transmission relationship. If the file hash in the current event exists in the predefined known malicious hash library, the server log will map the risk flag value of the file hash according to the maliciousness level. The value range is [0, 1]. S3. Based on the behavioral feature set CE as the trigger point, analyze the behavioral feature set CE and generate the potential attack path set CP, calculate the candidate path propagation score pps and generate the propagation score set PA; S4. Based on the propagation score set PA, mark the path with the highest score as p_max, calculate the threat index ATI by combining the behavioral feature set CE of the event of the candidate path with the highest score p_max, compare the threat index ATI with the preset threat threshold ATI_G and generate a warning information report AS. S5. Based on the content of the early warning information report AS, execute response actions through the API interface, record the execution results of the response actions to form the effect feedback dataset FL, perform closed-loop optimization based on the effect feedback dataset FL, and store the original network security event data Raw, the basic knowledge graph KG, and the early warning information report AS into the historical database His.

2. The knowledge graph-based dynamic early warning method for network security according to claim 1, characterized in that: S1 includes S11 and S12; S11. Collect raw data of network security incidents from network security devices and server logs through the network security system; The raw data of a network security incident includes the source IP address (src), destination IP address (dst), destination port (prt), protocol type (pro), number of bytes transferred in the session (byt), session duration (dur), event timestamp (tms), the host command executed (cmd), and the hash of the relevant file (fid).

3. The knowledge graph-based dynamic early warning method for network security according to claim 2, characterized in that: S12. Parse the raw data of the collected network security incidents, identify the core network entities and their interaction relationships, store these entities and relationships in a graph database, and construct a basic knowledge graph (KG). The core network entities include the source IP address src, the destination IP address dst, the destination port prt, the protocol type pro, the host execution command cmd, and the related file hash fid; The interaction relationships of core network entities include connection relationship connect_to(src, dst, prt, pro, tms), execution relationship executes(src, cmd, tms), and transfer relationship transfers(src, dst, fid, tms).

4. The knowledge graph-based dynamic early warning method for network security according to claim 3, characterized in that: S2 includes S21; S21. Based on the basic knowledge graph KG and combined with the latest cybersecurity events, map the entities in the basic knowledge graph KG, and query the context information of the interaction relationships of the entities related to the latest cybersecurity events. Construct a connection frequency anomaly analysis algorithm based on the connection relationship connect_to(src, dst, prt, pro, tms) to obtain the connection frequency anomaly degree CFA. Construct a port-protocol singularity analysis algorithm based on the connection relationship connect_to(src, dst, prt, pro, tms) to obtain the port-protocol interaction singularity PuS. Construct a behavioral risk analysis algorithm based on the execution relationship executes(src, cmd, tms) and the transfer relationship transfers(src, dst, fid, tms) to obtain the behavioral risk value IBR. Combine the connection frequency anomaly degree CFA, the port-protocol interaction singularity PuS, and the behavioral risk value IBR to generate a behavioral feature set CE.

5. The knowledge graph-based dynamic early warning method for network security according to claim 4, characterized in that: S3 includes S31; S31. Based on the behavioral feature set CE, dynamically determine the trigger point by statistically analyzing the distribution of connection frequency anomaly degree cfa, port-protocol interaction singularity pus and behavioral risk value ibr in the past week. If the current event's connection frequency anomaly (CFA) is higher than the 95th percentile of all connection frequency anomalies (CFA) within a week, or the current event's port-protocol interaction singularity (PUS) is higher than the 98th percentile of all port-protocol interaction singularities (PUS) within a week, or the current event's behavioral risk value (IBR) is higher than the 90th percentile of all behavioral risk values ​​(IBR) within a week, then the trigger point requirement is met. Based on the event of the behavioral feature set (CE) that meets the trigger point requirement, the trigger point is used to retrieve the subgraph structure that matches the attack pattern fragment of the network behavior, generate the potential attack path set (CP), and assign a unique identifier CP={p_1, p_2, p_3, ..., p_m} to each candidate path, where m represents the total number of candidate paths. Based on the potential attack path set (CP), a candidate path propagation scoring algorithm is constructed and the candidate path propagation score (pps) is calculated to generate the propagation score set (PA). The candidate path propagation scoring algorithm is expressed as follows: ; In the formula, p_i represents the candidate path with a unique identifier p_i in the potential attack path set CP, n(p_i) represents the total number of events on the candidate path p_i, cfa_(i,j) represents the connection frequency anomaly cfa of the j-th event on the candidate path p_i, pus_(i,j) represents the port-protocol interaction singularity pus of the j-th event on the candidate path p_i, ibr_(i,j) represents the behavioral risk value ibr of the j-th event on the candidate path p_i, exp represents the natural exponential function, hop_(i,j) represents the number of hops of the j-th event on the candidate path p_i, deg_(i,j) represents the number of connections of the j-th event in the basic knowledge graph KG, and α represents the preset attenuation factor.

6. The knowledge graph-based dynamic early warning method for network security according to claim 5, characterized in that: S4 includes S41 and S42; S41. Based on the propagation score set PA, the path with the highest score is marked as p_max. Combine the behavioral feature set CE of the event of the candidate path with the highest score p_max to construct a threat index algorithm, calculate the threat index ATI, and compare the threat index ATI with the preset dynamic warning threshold ATI_G. If the threat index ATI is less than the preset dynamic warning threshold ATI_G, it is determined to be a no-risk warning. If the threat index ATI is greater than or equal to the preset dynamic warning threshold ATI_G, then a risk warning is determined to exist and a warning information report AS is generated. The early warning information report includes the following: Threat Index (ATI), highest-scoring candidate path p_max, and core network entities involved in the highest-scoring candidate path p_max.

7. The knowledge graph-based dynamic early warning method for network security according to claim 6, characterized in that: S42. The algorithm expression for the threat index is as follows: ; In the formula, PA(p_max) represents the propagation score of the candidate path p_max with the highest score in the propagation score set PA, avg_cfaG represents the average value of connection frequency anomaly (cfa) calculated by combining all raw data of network security events within the current time window W, avg_pusG represents the average value of port-protocol interaction singularity (pus) calculated by combining all raw data of network security events within the current time window W, β represents the preset weighting coefficient of the average global connection frequency anomaly (cfa), and γ represents the preset weighting coefficient of the average global port-protocol interaction singularity (pus).

8. The knowledge graph-based dynamic early warning method for network security according to claim 7, characterized in that: S5 includes S51; S51. Based on the content of the early warning information report AS, a response action is executed through the API interface, and the relevant basic knowledge graph KG subgraph is retrieved on the visualization platform to display the following content: The event nodes and relationships on the highest-scoring candidate path p_max are highlighted, along with the connection frequency anomaly score (cfa), port-protocol interaction singularity score (pus), and behavioral risk value (ibr) for each event on the highest-scoring candidate path p_max. The order of time occurrence is displayed with the event timestamp (tms) as the time axis coordinate. The execution results of response actions and the analyst's confirmation of the correctness of the warning are recorded to form the effect feedback dataset FL. Based on the effect feedback dataset FL, the analyst dynamically adjusts the trigger point of the behavioral feature set CE and the influence factor α in the candidate path propagation scoring algorithm. The original network security event data Raw, the basic knowledge graph KG and the warning information report AS are stored in the historical database His.

9. A knowledge graph-based dynamic early warning system for network security, applied to the knowledge graph-based dynamic early warning method for network security as described in any one of claims 1 to 8, characterized in that: It includes modules for knowledge graph construction, behavioral feature quantification, propagation scoring, early warning generation, and visualization response and optimization. The knowledge graph construction module collects raw data of network security incidents through the network system, analyzes the entities and interaction relationships of the collected raw data, and constructs a basic knowledge graph (KG). The behavioral feature quantification module maps entities in the basic knowledge graph (KG) to the latest cybersecurity events, queries the context information of the interaction relationships between entities related to the latest cybersecurity events, constructs a behavioral feature algorithm, and generates a behavioral feature set (CE). Among them, the behavioral feature algorithms include connection frequency anomaly analysis algorithm, port-protocol singularity analysis algorithm and behavioral risk analysis algorithm; The expression for the connection frequency anomaly analysis algorithm is as follows: ; In the formula, cfa represents the connection frequency anomaly, erf represents the Gaussian error function, log represents the logarithmic operation, frq_e represents the connection frequency of source IP address src, destination IP address dst, and destination port prt within the current time window W in the current event, avg_sdp represents the moving average of the historical connection frequencies of source IP address src, destination IP address dst, and destination port prt recorded in the connection relationship connect_to(src, dst, prt, pro, tms), and avg_sdp represents the moving standard deviation of the historical connection frequencies of source IP address src, destination IP address dst, and destination port prt recorded in the connection relationship connect_to(src, dst, prt, pro, tms). The expression for the port-protocol singularity analysis algorithm is as follows: ; In the formula, pus represents port-protocol singularity, count_sdpp represents the historical occurrence count of the combination of source IP address src, destination IP address dst, destination port prt, and protocol type pro recorded in the connection relationship connect_to(src, dst, prt, pro, tms), and count_sd represents the historical occurrence count of the combination of source IP address src and destination IP address dst recorded in the connection relationship connect_to(src, dst, prt, pro, tms). The behavioral risk analysis algorithm expression is as follows: ; In the formula, ibr represents the behavioral risk value, and tanh represents the hyperbolic tangent function. This indicates the session transfer rate of the current event. avg_sd represents the average historical rate of interaction between the source IP address src and the destination IP address dst, recorded in the transfers(src, dst, fid, tms) relationship. is_cmd represents the risk flag value of the host executing the relevant command cmd, recorded in the executes(src, cmd, tms) relationship. If the command cmd executed by the host in the current event exists in the predefined known malicious command table, the server log will map the risk flag value of the command according to the maliciousness level. The value range is [0, 1]. is_fid represents the risk flag value of the relevant file hash fid, recorded in the transfers(src, dst, fid, tms) relationship. If the file hash fid in the current event exists in the predefined known malicious hash library, the server log will map the risk flag value of the file hash according to the maliciousness level. The value range is [0, 1]. The propagation scoring module analyzes the behavioral feature set CE as the trigger point and generates a potential attack path set CP. It then calculates the candidate path propagation score pps and generates a propagation score set PA. The early warning generation module marks the path with the highest score as p_max based on the propagation score set PA, calculates the threat index ATI by combining the behavioral feature set CE of the event of the candidate path with the highest score p_max, compares the threat index ATI with the preset threat threshold ATI_G, and generates an early warning information report AS. The visualization response and optimization module executes response actions through API interfaces based on the content of the early warning information report (AS), records the execution results of the response actions to form an effect feedback dataset (FL), performs closed-loop optimization based on the effect feedback dataset (FL), and stores the original network security event data (Raw), the basic knowledge graph (KG), and the early warning information report (AS) in the historical database (His).

Citation Information

Patent Citations

  • Internet situation assessment method based on knowledge graph

    CN117692198A

  • Network attack link tracking and threat situation reasoning method based on knowledge graph

    CN119544327A