Big data analysis driven multi-modal network security operation and maintenance method and system

By integrating device operating status and network traffic behavior data, constructing a three-dimensional vector and performing adaptive learning, the problem of insufficient multimodal data fusion analysis in existing technologies is solved, enabling accurate identification of complex threats and dynamic policy adjustment, and improving the level of intelligence in network security operation and maintenance.

CN120811770BActive Publication Date: 2026-01-09CHINA TOWER CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511275099.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2026-01-09
Estimated Expiration
2045-09-08

AI Technical Summary

Technical Problem

Existing network security operation and maintenance technologies are insufficient in terms of multimodal data fusion analysis, dynamic policy adjustment capabilities, and adaptive learning mechanisms, resulting in inadequate identification of complex network threats and slow response speed.

Method used

By acquiring device operating status data and network traffic behavior data, calculating the average fluctuation and frequency of abnormal distribution, generating a comprehensive trigger signal, performing abnormal boundary scanning, identifying behavioral feature segments, constructing a three-dimensional vector and performing cluster analysis, the system achieves adaptive learning and dynamic adjustment of the multimodal behavior vector set.

Benefits of technology

It enhances the intelligence level of network security operations and maintenance, enabling more accurate identification of complex threats and dynamic policy adjustments, thereby improving the stability and identification rate of network security operations and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811770B_ABST
    Figure CN120811770B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network security operation and maintenance, in particular to a multi-modal network security operation and maintenance method and system driven by big data analysis, which comprises obtaining running state and network traffic data to generate a comprehensive trigger signal, dividing a behavior characteristic section set, extracting a main behavior characteristic area, constructing a multi-modal behavior vector set and performing clustering analysis, and outputting a classification result. Through steps such as double-feature screening, mutation point division, weighted fusion and similarity screening, the present application improves data filtering precision and boundary recognition ability, enhances significant area extraction and cross-modal consistency expression, realizes adaptive aggregation and accurate classification of threat attributes in complex scenarios, and guarantees the stability and recognition rate of network security operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security operation and maintenance, and particularly relates to a multi-modal network security operation and maintenance method and system driven by big data analysis. BACKGROUND

[0002] With the rapid development of information technology, enterprises and organizations have increasingly high requirements for network security. Traditional operation and maintenance methods mainly rely on manual operation, which has problems such as low efficiency, slow response speed, and high misjudgment rate. In addition, due to the lack of intelligent analysis means, traditional operation and maintenance has certain lag in discovering potential security threats and equipment failures, which may affect business continuity. Although some existing intelligent operation and maintenance systems can realize partial automation functions, there is still room for improvement in data analysis depth, accuracy of abnormal behavior identification, and decision support capability. Therefore, there is an urgent need for a more efficient and intelligent network security operation and maintenance solution.

[0003] After searching, a network security operation and maintenance management method and system based on data analysis (CN117040912B) is disclosed, which obtains server security configuration data, combines the attack intrusion, initial state, and post-state feature data processing of multiple time nodes in a time period to obtain an effectiveness evaluation index, and evaluates the recovery evaluation index obtained from the monitoring data of the initial state and the terminal recovery state, so as to adjust and verify the operation and maintenance state of the server. However, this technical solution mainly focuses on single-dimensional data analysis and fails to fully integrate multi-modal data (such as network traffic, user behavior, and device performance) for comprehensive evaluation, which may affect the identification ability of complex network security threats. In addition, this solution lacks flexibility in dynamic adjustment strategy generation and needs to be strengthened in the ability to adapt to rapidly changing network environments.

[0004] After searching, a network information security early warning platform based on big data analysis (CN114157463B) is disclosed, which realizes effective monitoring and analysis of security risks in the network through the cooperative work of multiple modules such as data collection units, operation and maintenance units, transmission units, and data processing units, and establishes a network and information security event early warning working mechanism. However, this technical solution has certain limitations in the integration and processing ability of multi-source heterogeneous data, and fails to fully utilize the complementarity of multi-modal data for in-depth analysis, which may affect the accuracy and timeliness of the early warning. In addition, this solution mainly relies on preset rules and thresholds for abnormal behavior identification, lacks self-adaptive learning ability, and may not perform well in the face of new threats or complex attack scenarios.

[0005] The above problems show that the existing network security operation and maintenance technology and early warning platform still need to be improved in terms of multi-modal data fusion analysis, dynamic strategy adjustment capability and self-adaptive learning mechanism. Therefore, the present application provides a multi-modal network security operation and maintenance method and system driven by big data analysis, aiming to improve the intelligent level of network security operation and maintenance and the ability to cope with complex threats by fusing multi-modal data, introducing an adaptive learning algorithm and optimizing a dynamic adjustment strategy, so as to meet the needs of modern enterprises for efficient and intelligent network security operation and maintenance. SUMMARY

[0006] In order to solve the technical problems existing in the prior art, the embodiments of the present application provide a multi-modal network security operation and maintenance method and system driven by big data analysis. The technical solution is as follows:

[0007] The multi-modal network security operation and maintenance method driven by big data analysis comprises the following steps:

[0008] S1: Obtain front-end device running state data and network traffic behavior data, calculate the fluctuation mean value of the running state data and the abnormal distribution frequency of the network traffic behavior data respectively, judge whether the fluctuation mean value is lower than the stable threshold and whether the abnormal distribution frequency is higher than the risk threshold, and generate a comprehensive trigger signal;

[0009] S2: Based on the comprehensive trigger signal, perform an abnormal boundary scanning operation on the fusion data stream, calculate the behavior characteristic change difference in the continuous time sequence, identify the mutation point to divide the behavior section, and generate a behavior characteristic section set;

[0010] S3: According to the behavior characteristic section set, calculate the behavior intensity value of each section, weight and combine the corresponding time gradient value, sort and filter the behavior section with the maximum weight value, and generate a main behavior characteristic region;

[0011] S4: Based on the main behavior characteristic region, extract the behavior correlation matrix feature of the corresponding region running state data and the dynamic distribution field of the network traffic behavior data, construct a three-dimensional vector and compare the cosine similarity between the vector groups, and generate a multi-modal behavior vector set.

[0012] S5: According to the multi-modal behavior vector set, perform clustering analysis on all vector groups, count the proportion of each group and identify the maximum class attribution relationship, map the corresponding class attribution to the current data stream region, and obtain the network security operation and maintenance classification result.

[0013] As a further scheme of the present application, the comprehensive trigger signal comprises a timestamp number, an activation state mark, a trigger signal type, the behavior characteristic section set comprises a behavior mutation point, a time interval, a behavior section number, the main behavior characteristic region comprises a behavior section index, a data flow region coordinate, a behavior intensity level, and the multi-modal behavior vector set comprises a behavior correlation matrix characteristic vector, a dynamic distribution field vector, and a characteristic similarity value.

[0014] As a further scheme of the present application, the comprehensive trigger signal comprises a timestamp number, an activation state mark, a trigger signal type, the behavior characteristic section set comprises a behavior mutation point, a time interval, a behavior section number, the main behavior characteristic region comprises a behavior section index, a data flow region coordinate, a behavior intensity level, and the multi-modal behavior vector set comprises a behavior correlation matrix characteristic vector, a dynamic distribution field vector, and a characteristic similarity value.

[0015] S111: behavior characteristic values are extracted row by row based on the running state data, a fluctuation sequence is formed in time sequence, a behavior characteristic difference value between every two adjacent time points in the fluctuation sequence is obtained, a behavior characteristic difference value set mean value is calculated by traversing the entire sequence, and a fluctuation mean value is generated;

[0016] S112: an abnormal distribution frequency value in a specified time period of network traffic behavior data is obtained, a frequency sequence is formed in time collection order, a standard deviation calculation operation is performed on the frequency sequence in combination with the fluctuation mean value, a coupling degree between a response amplitude and a stability degree of the abnormal distribution under fluctuation change is judged, and an abnormal fluctuation compound difference intensity value is obtained.

[0017]

[0018] As a further scheme of the present application, the behavior characteristic section set comprises a behavior mutation point, a time interval, a behavior section number, the main behavior characteristic region comprises a behavior section index, a data flow region coordinate, a behavior intensity level, and the multi-modal behavior vector set comprises a behavior correlation matrix characteristic vector, a dynamic distribution field vector, and a characteristic similarity value.

[0019] S211: based on the comprehensive trigger signal, an abnormal boundary scanning operation is performed on the corresponding fusion data flow, an abnormal boundary detection standard value is set, behavior characteristic values at each time point are detected and compared with a set threshold value, and an abnormal boundary mask graph is obtained.

[0020] S212: according to the abnormal boundary mask graph, a corresponding behavior characteristic sequence is extracted in time sequence from the marked abnormal points in the data flow, a change in behavior characteristic values in continuous time is recorded, a time gradient response intensity is calculated, a change trend of the gradient response intensity on the time continuous position is determined, a position where the behavior characteristic difference value is greater than an abnormal boundary detection threshold value is identified as a mutation point, and a mutation point time sequence is obtained.

[0021] S213: according to the mutation point time sequence, the data flow is segmented and divided according to the interval distribution between adjacent mutation points, the starting point and the ending point time of each segment are recorded, and a behavior characteristic section set is generated.​

[0022] As a further scheme of the present application, the step of acquiring the main behavior feature region is specifically:

[0023] S311: According to the behavior feature segment set, the time point coordinates covered in each behavior segment are acquired, and a behavior correlation matrix is constructed in the corresponding data stream region. The co-occurrence frequency of each behavior pair combination is sequentially counted, and the behavior intensity value is calculated to obtain a behavior intensity value sequence;

[0024] S312: Based on the behavior intensity value sequence and the time gradient value of each segment in the behavior feature segment set, the time gradient value of each segment is calculated as the absolute value average of the behavior change rate of adjacent time points in the segment. Each behavior intensity value is weighted and fused with the corresponding time gradient value to calculate the fused behavior gradient weight value of the behavior segment, and a fused behavior gradient weight value sequence is obtained;

[0025] S313: According to the fused behavior gradient weight value sequence, all behavior segments are sorted from high to low according to the weight value, the behavior segment with the maximum weight value is selected, the corresponding data stream region time range is extracted, and the time point index of the corresponding segment is recorded. The main behavior feature region is generated.

[0026] As a further scheme of the present application, the step of acquiring the multi-modal behavior vector set is specifically:

[0027] S411: Based on the main behavior feature region, the running state data at the corresponding position is extracted, all time point behavior feature values in the region are intercepted, and a behavior correlation matrix is constructed. The occurrence frequency of adjacent time point behavior combination is counted pair by pair to fill the correlation matrix, and a behavior correlation feature vector group is obtained;

[0028] S412: According to the behavior correlation feature vector group and the corresponding network traffic behavior data region, a dynamic distribution field is constructed, a dynamic vector field sequence is constructed, each pair of behavior correlation feature vectors and dynamic distribution vectors are combined to form a three-dimensional feature vector, the cosine similarity between three-dimensional feature vectors is calculated, all vector pairs with similarity greater than the feature consistency threshold are retained, and a high-similarity vector combination set is obtained;

[0029] S413: Based on the high-similarity vector combination set, the vector contents in each pair of vector combinations that meet the feature consistency condition are integrated to establish a multi-modal behavior vector set.

[0030] As a further scheme of the present application, the step of acquiring the network security operation classification result is specifically:

[0031] S511: According to the multi-modal behavior vector set, the feature point time of each vector is extracted, the corresponding timestamp number and data stream time are constructed to form an index structure, the behavior feature dimension is uniformly mapped, and the vector numbers are sorted and arranged to obtain a multi-modal behavior distribution point set.

[0032] S512: According to the multi-modal behavior distribution point set, the density characteristics of all vector points are judged, the core points are determined, the core points are taken as the starting points to form a class cluster structure, the number of members of each class is counted, and the proportion in the whole vector set is calculated, the class with the maximum number of vectors is identified, and a clustering result number set is obtained.

[0033] S513: According to the vector number marked as the maximum class in the clustering result number set and the corresponding timestamp number and data stream time position, the data stream time points are extracted one by one, the corresponding class is marked as a threat type, and is uniformly recorded to establish a network security operation classification result.

[0034] The multi-modal network security operation system driven by big data analysis comprises:

[0035] The comprehensive signal extraction module is used for obtaining running state data and network traffic behavior data frames, extracting fluctuation and frequency sequences, calculating stable mean value and risk distribution frequency, judging double threshold condition, and obtaining comprehensive trigger signal.

[0036] The behavior region identification module is used for extracting behavior feature difference and judging mutation condition based on the comprehensive trigger signal frame, dividing behavior section and recording time, and obtaining a behavior feature section set.

[0037] The main behavior feature extraction module is used for calculating behavior intensity and time gradient based on the behavior feature section set, screening the maximum value section after weighted fusion, and obtaining a main behavior feature region.

[0038] The multi-modal behavior construction module is used for extracting behavior correlation matrix features and dynamic distribution field based on the main behavior feature region, constructing three-dimensional vectors, and screening combinations with similarity greater than feature consistency threshold to obtain a multi-modal behavior vector set.

[0039] The clustering identification attribution module is used for performing clustering analysis according to the multi-modal behavior vector set time, counting the proportion of each group, mapping the maximum group timestamp number and time, and obtaining a network security operation classification result.

[0040] The technical scheme provided by the embodiment of the application has at least the following beneficial effects:

[0041] In the application, a precise triggering mechanism is established by screening the dual characteristics of running state fluctuation and network traffic anomaly, the initial data filtering accuracy is improved, the behavior mutation point division strengthens the boundary recognition sensitivity, the data stream segmentation has more physical difference basis, the weighted fusion of behavior intensity and time gradient enhances the significant region extraction capability, the three-dimensional vector construction combines the similarity screening to construct the cross-modal consistency feature group, the recognition expression integrity is improved, the vector distribution clustering replaces the static threshold classification, has the self-adaptive aggregation ability, realizes the accurate mapping and classification decision of threat attributes in the complex scene, cooperates and optimizes each link from key frame screening to feature attribution output, guarantees the stability and recognition rate of network security operation and maintenance results. BRIEF DESCRIPTION OF DRAWINGS

[0042] Figure 1 is a method flowchart of the application;

[0043] Figure 2 is a flowchart of the acquisition of the comprehensive trigger signal of the application;

[0044] Figure 3 is a flowchart of the acquisition of the behavior feature region set of the application;

[0045] Figure 4 is a flowchart of the acquisition of the main behavior feature region of the application;

[0046] Figure 5 is a flowchart of the acquisition of the multi-modal behavior vector set of the application;

[0047] Figure 6 is a flowchart of the acquisition of the network security operation and maintenance classification result of the application. DETAILED DESCRIPTION

[0048] The technical solutions in the application will be described below with reference to the drawings.

[0049] In the embodiments of the application, the words such as “example”, “for example” are used to represent an example, illustration or description. Any embodiment or design scheme described as “example” in the application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word “example” is intended to present the concept in a specific manner. In addition, in the embodiments of the application, the meaning expressed by “and / or” can be both, or can be one of the two.

[0050] In order to make the technical problems, technical solutions and advantages of the application more clear, the following will be described in detail with reference to the drawings and specific embodiments.

[0051] Please refer to Figure 1 The application provides a technical solution: a multi-modal network security operation and maintenance method driven by big data analysis, comprising the following steps:

[0052] S1: Obtain front-end device running state data and network traffic behavior data, respectively calculate the fluctuation mean of the running state data and the abnormal distribution frequency of the network traffic behavior data, judge whether the fluctuation mean is lower than the stability threshold and whether the abnormal distribution frequency is higher than the risk threshold, and generate a comprehensive trigger signal;

[0053] S2: Based on the comprehensive trigger signal, perform an abnormal boundary scanning operation on the fusion data stream, calculate the behavior characteristic change difference in the continuous time sequence, identify the mutation point to divide the behavior section, and generate a behavior characteristic section set;

[0054] S3: According to the behavior characteristic section set, calculate the behavior intensity value of each section, weight and merge with the corresponding time gradient value, sort and filter the behavior section with the maximum weight value, and generate a main behavior characteristic region;

[0055] S4: Based on the main behavior characteristic region, extract the behavior correlation matrix feature of the corresponding region running state data and the dynamic distribution field of the network traffic behavior data, construct a three-dimensional vector and compare the cosine similarity between vector groups, and generate a multi-modal behavior vector set;

[0056] S5: According to the multi-modal behavior vector set, perform clustering analysis on all vector groups, count the proportion of each group and identify the maximum class attribution relationship, map the corresponding class attribution to the current data stream region, and obtain the network security operation classification result.

[0057] The comprehensive trigger signal includes timestamp number, activation state mark, trigger signal type, the behavior characteristic section set includes behavior mutation point, time interval, behavior section number, the main behavior characteristic region includes behavior segment index, data stream region coordinate, behavior intensity level, the multi-modal behavior vector set includes behavior correlation matrix feature vector, dynamic distribution field vector, and feature similarity value, and the network security operation classification result includes data stream region class label, identification timestamp number, and corresponding time position.

[0058] Please refer to Figure 2 , the acquisition step of the comprehensive trigger signal is specifically:

[0059] S111: Based on the running state data, extract the behavior characteristic value row by row, and form a fluctuation sequence in time sequence, obtain the behavior characteristic difference value of each two adjacent time points in the fluctuation sequence, traverse the entire sequence to calculate the behavior characteristic difference value set mean, and generate the fluctuation mean;

[0060] Based on the running state data, the behavior characteristic value is extracted row by row. First, from the log storage unit of the firewall device (model: H3C SecPath F5000-AI-75) deployed at the front-end network boundary, the CPU utilization and memory utilization of the device at 10 time points (T1 to T10) are continuously acquired at an acquisition cycle of 1 second. The acquired original running state data is shown in Table 1.

[0061] Table 1: Original data table of front-end device running state

[0062]

[0063] As shown in Table 1, the table records the key performance indicators of the device in the continuous monitoring period. For calculating the behavior characteristic value, the weight coefficient of CPU utilization is set to 0.6, and the weight coefficient of memory utilization is set to 0.4. The weight coefficient value is determined based on the principal component analysis of more than 500 known benign and malicious network attack event sample libraries. The analysis result shows that the change of CPU utilization contributes about 60% to the indication of abnormal behavior. The setting process of the weight coefficient excludes human preset, ensuring its objectivity. The behavior characteristic value of T1 time point is calculated as follows: According to this method, the behavior characteristic values of T2 to T10 time points are calculated in turn, and the following values are obtained respectively: These behavior characteristic values are arranged in time sequence to form a fluctuation sequence Then, the behavior characteristic difference values of every two adjacent time points in the fluctuation sequence are obtained, and the first difference value is calculated as follows: The subsequent difference values are as follows: A behavior characteristic difference value set is formed Finally, the mean value of the behavior characteristic difference value set is calculated by traversing the entire sequence, and the calculation process is as follows: The fluctuation mean value is generated.

[0064] ​​​​​​​​​​​​​​​​​​S112: Obtain the abnormal distribution frequency value of the network traffic behavior data in the specified time period, form a frequency sequence according to the time collection order, combine the fluctuation mean value, and perform a standard deviation calculation operation on the frequency sequence to judge the coupling degree between the response amplitude and stability of the abnormal distribution under fluctuation change, and obtain the abnormal fluctuation composite difference intensity value;

[0065] Obtain the abnormal distribution frequency value of the network traffic behavior data in the same time period (T1 to T10) as the running state data. The abnormal distribution frequency value here refers to the number of data packets identified by the network traffic monitoring system (for example, IDS integrated with Snort rule set) per second that meet the "suspicious TCP connection request" rule, with the unit of pps (packets per second). The collected frequency sequence is Combine the fluctuation mean value calculated in S111 Perform a standard deviation calculation operation on the frequency sequence First, calculate the mean value of the frequency sequence , Then calculate the square of the difference between each frequency value and the mean value to obtain , , , , , , , , , Sum the square difference values to obtain , divide by the number of data points 10 to obtain the variance , and take the square root to obtain the standard deviation of the frequency sequence In order to judge the coupling degree between the response amplitude and stability of the abnormal distribution under fluctuation change, a coupling coefficient is introduced here, which is defined as the ratio of the fluctuation mean value to the historical stable state fluctuation mean value reference. The historical reference value is set as This reference value is the fluctuation mean value obtained by performing the same calculation on the data collected during the normal business period of the device without any security alarm for 7 consecutive days. Therefore, the coupling coefficient is Multiply this coefficient with the calculated standard deviation to obtain the final intensity value, the calculation process is , and obtain the abnormal fluctuation composite difference intensity value.

[0066] S113: Based on the fluctuation mean value and the abnormal fluctuation composite difference intensity value, respectively judge the stable threshold and the risk threshold. If the fluctuation mean value is lower than the set stable threshold and the abnormal fluctuation composite difference intensity value is higher than the frequency standard deviation threshold, record the corresponding timestamp number and activate the data marking state, generate a comprehensive trigger signal.

[0067] based on fluctuation mean abnormal fluctuation compound difference intensity measure , respectively, with stable threshold and frequency standard deviation threshold are judged, the stable threshold is set by referring to the fluctuation mean distribution of the equipment during normal operation for 30 consecutive working days. Through statistical analysis of 30 daily fluctuation means (ranging from 0.5 to 1.5), after removing the extreme values of the highest 5% and the lowest 5%, the 95th percentile of the distribution is taken as the threshold. Specifically, after sorting the 27 effective data points observed, the value of the 26th position is selected, which is 2.5, so the stable threshold is set to 2.5. The frequency standard deviation threshold is set based on the statistics of the frequency standard deviation of the corresponding traffic when the same type of attack (for example, a confirmed SYN Flood attack) occurs. 20 attack samples are selected, and the standard deviation ranges from 350 to 600, taking the average value as the reference, that is, the judgment logic is executed. First, it is judged whether the fluctuation mean is higher than the stable threshold . This condition is met ( ), then it is judged whether the abnormal fluctuation compound difference intensity measure is higher than the frequency standard deviation threshold . This condition is also met ( ), since both judgment conditions are met, the corresponding timestamp number T10 is recorded at the time point when this judgment is triggered, that is, T10 (as the end point of the current analysis period), and the data marking state is activated as "to be analyzed", and a comprehensive trigger signal is generated.

[0068] Please refer to Figure 3 , the acquisition step of the behavior characteristic segment set is specifically:

[0069] S211: Based on the comprehensive trigger signal, an abnormal boundary scanning operation is performed on the corresponding fusion data stream. Set the abnormal boundary detection standard value, detect the behavior characteristic value at each time point and compare it with the set threshold value, and obtain the abnormal boundary mask graph;

[0070] The fusion data stream corresponding to the trigger time T10, that is, the set of running state data and network traffic behavior data containing the T1 to T10 time period, is executed. The abnormal boundary scanning operation is set, and the abnormal boundary detection standard value is set. The basis for setting this standard value is that in the historical normal data set, the behavior characteristic value The distribution mean value is 21.5, and the standard deviation is 0.5. According to the statistical principle, the detection standard value is set to be the mean value plus three times the standard deviation to cover 99.7% of the normal fluctuation. The calculation process is Subsequently, the behavior characteristic value at each of the time points T1 to T10 (calculated in S111) is detected and compared with the set threshold value The behavior characteristic value at T1 is , which is lower than , and is marked as 0. The behavior characteristic value at T2 is , which is lower than , and is marked as 0. The behavior characteristic value at T3 is , which is lower than , and is marked as 0. The behavior characteristic value at T4 is , which is higher than , and is marked as 1. The behavior characteristic value at T5 is , which is higher than , and is marked as 1. The behavior characteristic value at T6 is , which is higher than , and is marked as 1. The behavior characteristic value at T7 is , which is higher than , and is marked as 1. The behavior characteristic value at T8 is , which is lower than , and is marked as 0. The behavior characteristic value at T9 is , which is lower than , and is marked as 0. The behavior characteristic value at T10 is , which is lower than , and is marked as 0. The series of binary marks are combined in time sequence to obtain an abnormal boundary mask map.

[0071] S212: According to the abnormal boundary mask map, the corresponding behavior characteristic sequence of the marked abnormal points in the data stream is extracted in time sequence, the change of the behavior characteristic value in continuous time is recorded, the time gradient response strength is calculated, the change trend of the gradient response strength in the time continuous position is determined, the position where the behavior characteristic difference value is greater than the abnormal boundary detection threshold is identified as a mutation point, and a mutation point time sequence is obtained;

[0072] According to the abnormal boundary mask map , the behavior characteristic sequence corresponding to the abnormal points marked as 1 in the data stream, i.e., T4, T5, T6, and T7, is extracted in time sequence , the change of the behavior characteristic value in this continuous time is recorded, and the time gradient response strength is calculated. The response degree is defined as the change rate of the behavior characteristic value at the continuous time points, i.e., the absolute value of the difference. The first change is , the second change is , and the third change is . The change trend of the gradient response strength in the time continuous position is determined through these change values. On this basis, the position where the behavior characteristic difference value is greater than the abnormal boundary detection threshold set in S211 is identified as a mutation point. The position of T3 is the mutation point, and a separate mutation point judgment threshold is needed. The mutation point threshold is set to 75% of the value of T3, that is, T3*0.75. The proportion is an empirical value obtained by analyzing the change amplitude of attack injection points and attack decay points in historical data. Now the original complete behavior feature difference set is judged. Non-mutation point, Non-mutation point, is a mutation point occurring between T3 and T4, denoted as T3*0.75. (time point T3), Non-mutation point, Non-mutation point, is a mutation point occurring between T6 and T7, denoted as T3*0.75. (time point T6), is a mutation point occurring between T7 and T8, denoted as T3*0.75. (time point T7), Non-mutation point, Non-mutation point, obtain the mutation point time sequence.

[0073] S213: According to the mutation point time sequence, the data stream is segmented and divided according to the interval distribution between adjacent mutation points, and the starting point and ending point time of each segment are recorded to generate a behavior feature segment set.

[0074] According to the obtained mutation point time sequence , the data stream from T1 to T10 is segmented and divided according to the interval distribution between adjacent mutation points. The first segment starts from the starting time T1 which is not marked as a mutation point, and ends at the first mutation point , so the first segment is [T1, T3]. The second segment starts from the next time point T4 of the first mutation point , and ends at the second mutation point , so the second segment is [T4, T6]. The third segment starts from the next time point T7 of the second mutation point , and ends at the third mutation point , so the third segment is [T7, T7]. The fourth segment starts from the next time point T8 of the third mutation point , and ends at the end of the data stream T10, so the fourth segment is [T8, T10]. The starting point and ending point time of each segment are recorded as [T1, T3], [T4, T6], [T7, T7] and [T8, T10] respectively, and a behavior feature segment set is generated. ​​​

[0075] Referring to Figure 4 , the obtaining step of the main behavior feature region is specifically:

[0076] S311: According to the behavior feature segment set, the time point coordinates covered in each behavior segment are obtained, and a behavior correlation matrix is constructed in the corresponding data stream region. The co-occurrence frequency of each behavior on the combination is sequentially counted, and the behavior intensity value is calculated to obtain the behavior intensity value sequence;

[0077] According to the behavior feature segment set , the time point coordinates covered in each behavior segment are obtained, and a behavior correlation matrix is constructed in the corresponding data stream region. For constructing the matrix, the behavior feature value calculated in S111 is divided into three states according to its numerical range: state L (low) corresponds to , state M (medium) corresponds to , and state H (high) corresponds to . Based on this rule, the behavior state sequence of T1-T10 is . Now calculate the second segment [T4, T6]. The state sequence covered by this segment is , and the state transition is twice. In the behavior correlation matrix (with L, M, and H as rows and columns) of this segment, only position 2 is 2, and the rest are 0. The behavior intensity value is defined as the sum of all non-diagonal elements in the matrix, which is used to measure the degree of state change. Therefore, the behavior intensity value of segment two is . Similarly, the state sequence of segment one [T1, T3] is , and the transition is twice. The behavior intensity value is . Segment three [T7, T7] has only one time point, and the state is M, with no state transition. The behavior intensity value is . The state sequence of segment four [T8, T10] is , and the transition is twice. The behavior intensity value is . This result cannot distinguish between segments, so the behavior intensity value is redefined as the average of the behavior feature values within the segment. The feature value sequence in segment one [T1, T3] is , and the behavior intensity value is . The feature value sequence in segment two [T4, T6] is , and the behavior intensity value is . The feature value sequence in segment three [T7, T7] is , and the behavior intensity value is . The feature value sequence in segment four [T8, T10] is the behavior intensity value , and obtaining a behavior intensity value sequence.

[0078] S312: Based on the behavior intensity value sequence and the time gradient value of each segment in the behavior feature segment set, the time gradient value of each segment is calculated as the absolute value average of the behavior change rate of adjacent time points in the segment, and each behavior intensity value is weighted and fused with the corresponding time gradient value to calculate the fused behavior gradient weight value of the behavior segment, and a fused behavior gradient weight value sequence is obtained;

[0079] Based on the behavior intensity value sequence and the time gradient value of each segment in the behavior feature segment set, the time gradient value of each segment is calculated as the absolute value average of the behavior change rate of adjacent time points in the segment, for segment one [T1, T3], the internal behavior feature difference is , the time gradient value , for segment two [T4, T6], the internal behavior feature difference is , the time gradient value , for segment three [T7, T7], because there is only one point, the time gradient value , for segment four [T8, T10], the internal behavior feature difference is , the time gradient value , each behavior intensity value is weighted and fused with the corresponding time gradient value , the weight of the behavior intensity value is set to , the weight of the time gradient value is set to , the setting of these two weight values is based on the fact that in a large number of safety event reviews, the amplitude (intensity) of abnormal behavior is the main basis for judgment, and the internal change rate (gradient) is the secondary auxiliary basis, so the intensity value is given a higher weight, and the fused behavior gradient weight value of segment one is calculated , the weight value of segment two is , the weight value of segment three is , and the weight value of segment four is , and a fused behavior gradient weight value sequence is obtained.

[0080] S313: According to the fused behavior gradient weight value sequence, all behavior segments are sorted in descending order of weight value, the behavior segment with the largest weight value is selected, the corresponding data stream region time range is extracted, and the time point index of the corresponding segment is recorded, and a main behavior feature region is generated.

[0081] The behavior intensity value, the time gradient value and the fused behavior gradient weight value are summarized, and the specific data is shown in Table 2.

[0082] Table 2: Behavior segment weight calculation and sorting table

[0083]

[0084] As shown in Table 2, which summarizes the key calculation indicators of each behavior section, according to the fusion behavior gradient weight value sequence, all behavior sections are sorted in descending order of weight value, and the sorting result is section two (65.392), section three (37.152), section one (17.326), and section four (17.288). The behavior section with the largest weight value, i.e. section two, is selected, the corresponding data flow region time range is extracted, the range is [T4, T6], and the corresponding time point index {T4, T5, T6} is recorded, and the main behavior feature region is generated.

[0085] Please refer to Figure 5 , the acquisition step of the multi-modal behavior vector set is specifically:

[0086] S411: Based on the main behavior feature region, the running state data at the corresponding position is extracted, all time point behavior feature values in the region are intercepted, and a behavior correlation matrix is constructed. The occurrence frequency of adjacent time point behavior combination is counted pair by pair to fill the correlation matrix, and a behavior correlation feature vector group is obtained;

[0087] Based on the main behavior feature region [T4, T6], the running state data at the corresponding position is extracted, i.e. the CPU utilization (%) and the memory utilization (%) at T4, T5 and T6, the data is , , , all time point behavior feature values in the region are intercepted, and a behavior correlation matrix is constructed. In order to improve the resolution, the running state data is divided into more fine levels, CPU utilization below 20% is C1, 20-80% is C2, and above 80% is C3. Memory utilization below 40% is M1, 40-70% is M2, and above 70% is M3. Thus, the state of T4 is (C3, M3), the state of T5 is (C3, M3), and the state of T6 is (C3, M3). The transition from T4 to T5 is (C3, M3)→(C3, M3), and the transition from T5 to T6 is (C3, M3)→(C3, M3). A 9x9 behavior correlation matrix is constructed, and the rows and columns are C1M1, C1M2, …, C3M3, etc. In this example, only the transition from state (C3, M3) to itself occurs twice, so the cell value corresponding to (C3, M3)→(C3, M3) in the matrix is 2, and the remaining 80 cell values are 0. The matrix is expanded by row to form an 81-dimensional vector . In order to simplify the representation, dimension reduction is adopted here, only the state transition of CPU and memory is considered, the CPU state sequence is , and the transition matrix is , wherein , the rest is 0, the memory state sequence is , the transition matrix is , wherein , the rest is 0, and the two matrices are expanded and spliced to obtain a vector of length Since there is only one behavior pattern in the region, only one vector is generated, and to construct the vector group, the [T4, T6] region can be further divided into [T4, T5] and [T5, T6] two sub-regions, and vectors are calculated respectively to obtain two vectors with the same content, and the behavior correlation feature vector group is obtained.

[0088] S412: Construct a dynamic distribution field according to the behavior correlation feature vector group and the corresponding network traffic behavior data region, construct a dynamic vector field sequence, combine each pair of behavior correlation feature vectors and dynamic distribution vectors to form a three-dimensional feature vector, calculate the cosine similarity between the three-dimensional feature vectors, retain all vector pairs with a similarity greater than a feature consistency threshold, and obtain a high-similarity vector combination set;

[0089] According to the behavior correlation feature vector group (simplified as a single vector ) and the corresponding network traffic behavior data region [T4, T6], a dynamic distribution field is constructed, the network traffic frequency of the region is , and the dynamic distribution field is defined as a vector describing the traffic statistical characteristics, the dimension includes mean, standard deviation and change trend (last item minus first item), the mean is , the standard deviation is , and the change trend is , then , combine each pair of behavior correlation feature vectors and dynamic distribution vectors to form a three-dimensional feature vector expression, which is specifically implemented as splicing the two vectors to form a dimensional feature vector , assuming that a vector for comparison is also calculated in the previous time period [T1, T3], the running state is L→L, the traffic is , the calculated vector is , and the cosine similarity between the two three-dimensional feature vectors (i.e. the spliced high-dimensional vector) is calculated, the formula is , since the two state vectors are orthogonal, the dot product of the state part is 0, and the dot product of the traffic part is , the norm multiplication result is a very large number, and the final similarity is close to 0, and the feature consistency threshold is set to ​, the value is set by comparing the similarity distribution of 100 groups of known homologous attacks (such as DDoS attacks from the same C2 server) pairwise, taking the 10th percentile to ensure high-precision matching, if another attack B also produces a vector , the calculated cosine similarity is 0.92, because , the vector pair is retained.

[0090] S413: Based on the high-similarity vector combination set, the vector contents in each vector combination that meets the feature consistency condition are integrated to establish a multi-modal behavior vector set.

[0091] Based on the high-similarity vector combination set, the set contains the attack vector of the last period and the vector of the current main behavior feature area, the vector pair of each vector combination that meets the feature consistency condition, that is , the vector contents are integrated, the integration method is to perform weighted average on each dimension of the vector, the weight is determined according to the fusion behavior gradient weight value of each corresponding section, assuming the corresponding weight value is , the weight of the current vector is , then the first element of the integrated new vector is calculated as , and so on, the calculation of 21 dimensions is completed, in this way, similar attack behavior vectors are fused into a more representative central vector, each such central vector represents a similar attack behavior mode, assuming that all high-similarity vector pairs are processed by this method, a set containing several central vectors is finally generated, and a multi-modal behavior vector set is established.

[0092] Please refer to Figure 6 , the steps of obtaining the network security operation classification result are as follows:

[0093] S511: According to the multi-modal behavior vector set, the feature point time of each vector is extracted, the corresponding timestamp number and data flow time are constructed to build an index structure, the behavior feature dimension is uniformly mapped, and the vectors are sorted and arranged according to the vector number to obtain a multi-modal behavior distribution point set.

[0094] The multi-modal behavior vector set currently contains a vector integrated from and , and assuming that there are two other dissimilar vectors and , extract the feature point time of each vector, i.e. the center time point of the main behavior feature region it represents, and , the timestamp can be recorded as T5, extract the corresponding timestamp number T5 and data stream time to construct an index structure, such as key-value pair {‘T5: }, unify the mapping of behavior feature dimensions, since all vectors have formed a unified 21-dimensional structure through splicing in step S412, this step does not require additional operations, and directly sorts and arranges according to vector numbers (such as Vec_01, Vec_02, Vec_03) to form a list containing indexes and vector contents, and obtain a multi-modal behavior distribution point set.

[0095] S512: According to the multi-modal behavior distribution point set, the density characteristics of all vector points are judged to determine the core points, and the core points are taken as the starting point to expand their neighborhoods to form a class cluster structure. The number of members of each class is counted, and the proportion in the whole vector set is calculated. The class with the largest number of vectors is identified to obtain a set of clustering result numbers.

[0096] Suppose that after a period of accumulation in the current data set, there are 100 such multi-modal vector points. The density characteristics of all vector points are judged. This process is performed in reference to the core idea of the DBSCAN algorithm. The neighborhood radius is set to 0.15, which is based on the feature consistency threshold set in S412, i.e. , the minimum number of points in the neighborhood required to form a core point MinPts is set to 4, which is determined by testing the clustering effect of known attack samples. When MinPts=4, different types of attacks can be best distinguished and the false positives are minimized. All 100 points are traversed. For each point, the number of points in its neighborhood (cosine distance less than 0.15) is calculated. If the number of points in the neighborhood of a point is greater than or equal to 4, the point is marked as a core point. Taking a core point as the starting point, all points in its neighborhood (including other core points and non-core points) are included in the same class cluster. The neighborhood of the newly added core point is recursively expanded until no new point can be added to the class cluster. A class cluster structure is formed. After all class clusters are constructed, the number of members of each class is counted. Suppose that finally three class clusters are formed: class cluster 1 has 70 vectors, class cluster 2 has 20 vectors, and class cluster 3 has 8 vectors. The remaining 2 are noise points. The proportion of each class cluster in the whole vector set is calculated. The proportion of class cluster 1 is , the proportion of class cluster 2 is , and the proportion of class cluster 3 is , the class cluster 1 with the maximum number of vectors is identified as the cluster result number set.

[0097] S513: According to the vector number marked as the maximum class in the cluster result number set, the corresponding timestamp number and data stream time position, the data stream time points are extracted one by one, the corresponding class is marked as a threat type, and unified recording is performed to establish a network security operation classification result;

[0098] According to the vector number marked as the maximum class in the cluster result number set, that is, the number of 70 vectors belonging to class cluster 1, and the corresponding timestamp number and data stream time position, the data stream time points associated with these vectors are extracted one by one, for example, the vector (numbered Vec_01) is divided into class cluster 1 through clustering analysis, and its corresponding timestamp is T5. Then, T5 is extracted as a time point. A pre-defined threat type library is mapped with the class cluster. The mapping relationship is obtained by introducing known attack samples for training and learning. For example, after 10 different DDoS attack samples are vectorized, it is found that they all fall into class cluster 1, while 5 port scanning attack samples all fall into class cluster 2. Therefore, the mapping relationship is established: class cluster 1→“DDoS attack”, and class cluster 2→“port scanning”. Therefore, the class label “DDoS attack” is assigned to the T5 time point. The same operation is performed on the other 69 vectors in class cluster 1 to extract their respective time points and assign the label “DDoS attack”. All these label results are recorded in a security event log, and the content is shown in Table 3.

[0099] Table 3: Network security operation classification result example table

[0100]

[0101] As shown in Table 3, part of the network security operation classification result is listed, and the final network security operation classification result is established through the table.

[0102] A multi-modal network security operation system driven by big data analysis, the system comprises:

[0103] The comprehensive signal extraction module is used to obtain the running state data and network traffic behavior data frame, extract the fluctuation and frequency sequence, calculate the stable mean value and risk distribution frequency, judge the double threshold condition, and obtain the comprehensive trigger signal;

[0104] The behavior region identification module is used to extract the behavior feature difference value and judge the mutation condition based on the comprehensive trigger signal frame, divide the behavior section and record the time, and obtain the behavior feature section set;

[0105] A main behavior feature extraction module is configured to calculate a behavior intensity and a time gradient based on a behavior feature section set, filter a maximum value section after weighted fusion, and obtain a main behavior feature region;

[0106] A multi-modal behavior construction module is configured to extract a behavior correlation matrix feature and a dynamic distribution field based on the main behavior feature region, construct a three-dimensional vector, filter combinations with a similarity greater than a feature consistency threshold, and obtain a multi-modal behavior vector set;

[0107] A clustering recognition attribution module is configured to perform clustering analysis according to the multi-modal behavior vector set, count a proportion of each group, map a maximum group timestamp number and a time, and obtain a network security operation and maintenance classification result.

[0108] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A multimodal network security operation and maintenance method driven by big data analytics, characterized in that: Includes the following steps: S1: Obtain front-end device operating status data and network traffic behavior data, calculate the average fluctuation value of the operating status data and the frequency of abnormal distribution of the network traffic behavior data respectively, determine whether the average fluctuation value is lower than the stability threshold and whether the frequency of abnormal distribution is higher than the risk threshold, and generate a comprehensive trigger signal. The comprehensive trigger signal includes a timestamp number, an activation status marker, and a trigger signal type. S2: Based on the comprehensive trigger signal, perform an anomaly boundary scanning operation on the fused data stream, calculate the difference in behavioral feature changes in the continuous time series, identify abrupt change points to divide behavioral segments, and generate a set of behavioral feature segments; the set of behavioral feature segments includes behavioral abrupt change points, time intervals, and behavioral segment numbers; S3: Based on the set of behavioral feature segments, calculate the behavioral intensity value of each segment, perform weighted merging with the corresponding time gradient value, sort and filter the behavioral segments with the largest weight value, and generate the main behavioral feature region. The main behavioral feature region includes the behavioral segment index, data flow region coordinates, and behavioral intensity level. S4: Based on the main behavior feature region, extract the behavior correlation matrix features of the corresponding region's operating status data and the dynamic distribution field of the network traffic behavior data, construct a three-dimensional vector, and compare the cosine similarity between vector groups pairwise to generate a multimodal behavior vector set. The multimodal behavior vector set includes behavior correlation matrix feature vectors, dynamic distribution field vectors, and feature similarity values. The specific steps for obtaining the multimodal behavior vector set are as follows: S411: Based on the main behavior feature region, extract the running status data of the corresponding position, extract the behavior feature values ​​of all time points in the region and construct a behavior association matrix, and fill the association matrix by statistically analyzing the occurrence frequency of behavior combinations of adjacent time points to obtain a behavior association feature vector group. S412: Construct a dynamic distribution field based on the behavior-related feature vector group and the corresponding network traffic behavior data region, construct a dynamic vector field sequence, combine each pair of behavior-related feature vectors with the dynamic distribution vector to form a three-dimensional feature vector, calculate the cosine similarity between the three-dimensional feature vectors, retain all vector pairs with similarity greater than the feature consistency threshold, and obtain a set of highly similar vector combinations. S413: Based on the set of highly similar vector combinations, integrate the vector content in each pair of vector combinations that meet the feature consistency condition to establish a multimodal behavior vector set; S5: Based on the multimodal behavior vector set, perform cluster analysis on all vector groups, count the proportion of each group and identify the largest category affiliation relationship, map the corresponding category affiliation to the current data flow region, and obtain the network security operation and maintenance classification results.

2. The big data analytics-driven multimodal network security operation and maintenance method according to claim 1, characterized in that, The specific steps for obtaining the integrated trigger signal are as follows: S111: Extract behavioral feature values ​​line by line based on the running status data, form a fluctuation sequence in time order, obtain the behavioral feature difference between every two adjacent time points in the fluctuation sequence, traverse the entire sequence to calculate the mean of the behavioral feature difference set, and generate the fluctuation mean. S112: Obtain the frequency value of abnormal distribution in network traffic behavior data within a specified time period, form a frequency sequence according to the time collection order, combine the fluctuation mean and perform standard deviation calculation on the frequency sequence, determine the coupling degree between the response amplitude and stability of abnormal distribution under fluctuation changes, and obtain the intensity of abnormal fluctuation composite difference. S113: Based on the mean fluctuation and the intensity of the composite difference of abnormal fluctuations, a judgment is made against the stability threshold and the risk threshold respectively. If the mean fluctuation is lower than the set stability threshold and the intensity of the composite difference of abnormal fluctuations is higher than the frequency standard deviation threshold, the corresponding timestamp number is recorded and the data marking state is activated to generate a comprehensive trigger signal.

3. The big data analytics-driven multimodal network security operation and maintenance method according to claim 1, characterized in that, The specific steps for obtaining the set of behavioral feature segments are as follows: S211: Based on the comprehensive trigger signal, perform an anomaly boundary scanning operation on the corresponding fused data stream, set an anomaly boundary detection standard value, detect the behavioral feature value at each time point and compare it with the set threshold to obtain an anomaly boundary mask image; S212: Based on the abnormal boundary mask map, extract the corresponding behavioral feature sequence of the marked abnormal points in the data stream in chronological order, record the changes in behavioral feature values ​​over continuous time, calculate the temporal gradient response intensity, determine the changing trend of the gradient response intensity at continuous time positions, identify the positions where the behavioral feature difference is greater than the abnormal boundary detection threshold as mutation points, and obtain the mutation point time series. S213: Based on the time series of the mutation points, the data stream is segmented according to the interval distribution between adjacent mutation points, and the start and end times of each segment are recorded to generate a set of behavioral feature segments.

4. The big data analytics-driven multimodal network security operation and maintenance method according to claim 1, characterized in that, The specific steps for obtaining the main behavioral feature region are as follows: S311: Based on the set of behavioral feature segments, obtain the time point coordinates covered in each behavioral segment, construct a behavioral correlation matrix in the corresponding data stream area, sequentially count the co-occurrence frequency of each behavioral pair combination, calculate the behavioral intensity value, and obtain the behavioral intensity value sequence. S312: Based on the behavior intensity value sequence and the time gradient value of each segment in the behavior feature segment set, calculate the absolute average of the behavior change rate at adjacent time points within the segment as the time gradient value of each segment, weight and fuse each behavior intensity value with the corresponding time gradient value, calculate the fused behavior gradient weight value of the behavior segment, and obtain the fused behavior gradient weight value sequence. S313: Based on the fusion behavior gradient weight value sequence, sort all behavior segments from high to low according to their weight values, select the behavior segment with the largest weight value, extract the corresponding data stream region time range, record the time point index of the corresponding segment, and generate the main behavior feature region.

5. The big data analytics-driven multimodal network security operation and maintenance method according to claim 1, characterized in that, The specific steps for obtaining the network security operation and maintenance classification results are as follows: S511: Based on the multimodal behavior vector set, extract the feature point time of each vector, extract the corresponding timestamp number and data stream time to construct an index structure, uniformly map the behavior feature dimensions, and sort and organize them according to the vector number to obtain the multimodal behavior distribution point set; S512: Based on the multimodal behavior distribution point set, perform density characteristic judgment on all vector points, determine the core point, expand from the core point to its neighborhood to form a cluster structure, count the number of member vectors of each class, calculate the proportion in the overall vector set, identify the class with the largest number of vectors, and obtain the clustering result number set. S513: Based on the vector number marked as the largest category in the clustering result number set, the corresponding timestamp number, and the data stream time position, extract the data stream time points item by item, mark the corresponding category as threat type, record them uniformly, and establish network security operation and maintenance classification results.

6. A multimodal network security operation and maintenance system driven by big data analytics, characterized in that: The system is used to implement the big data analysis-driven multimodal network security operation and maintenance method according to any one of claims 1-5, and the system includes: The integrated signal extraction module is used to acquire operational status data and network traffic behavior data frames, extract fluctuation and frequency sequences, calculate stable mean and risk distribution frequency, determine dual threshold conditions, and acquire integrated trigger signals; the integrated trigger signals include timestamp numbers, activation status markers, and trigger signal types. The behavior region identification module is used to extract behavior feature differences and determine abrupt change conditions based on the comprehensive trigger signal frame, divide behavior segments and record time, and obtain a set of behavior feature segments, wherein the set of behavior feature segments includes behavior abrupt change points, time intervals and behavior segment numbers. The main behavior feature extraction module is used to calculate the behavior intensity and temporal gradient based on the set of behavior feature segments, and after weighted fusion, filter the segment with the maximum value to obtain the main behavior feature region. The main behavior feature region includes the behavior segment index, data flow region coordinates, and behavior intensity level. A multimodal behavior construction module is used to extract behavior association matrix features and dynamic distribution fields based on the main behavior feature region, construct three-dimensional vectors, and filter combinations with similarity greater than the feature consistency threshold to obtain a multimodal behavior vector set. The multimodal behavior vector set includes behavior association matrix feature vectors, dynamic distribution field vectors, and feature similarity values. The specific steps for obtaining the multimodal behavior vector set are as follows: Based on the main behavioral feature region, the running status data of the corresponding position is extracted, the behavioral feature values ​​of all time points in the region are extracted and a behavioral correlation matrix is ​​constructed, and the frequency of occurrence of behavioral combinations of adjacent time points is statistically analyzed to fill the correlation matrix and obtain the behavioral correlation feature vector group. A dynamic distribution field is constructed based on the behavior-related feature vector group and the corresponding network traffic behavior data region. A dynamic vector field sequence is constructed. Each pair of behavior-related feature vectors and dynamic distribution vectors are combined to form a three-dimensional feature vector. The cosine similarity between the three-dimensional feature vectors is calculated. All vector pairs with similarity greater than the feature consistency threshold are retained to obtain a set of highly similar vector combinations. Based on the set of highly similar vector combinations, the vector content in each pair of vector combinations that meet the feature consistency condition is integrated to establish a multimodal behavior vector set; The clustering identification and attribution module is used to perform clustering analysis based on the time of the multimodal behavior vector set, count the proportion of each group, map the timestamp number of the largest group to the time, and obtain the network security operation and maintenance classification results.

Citation Information

Patent Citations

  • Network information security early warning platform based on big data analysis

    CN114157463B

  • A network security operation and maintenance management method and system based on data analysis

    CN117040912B

  • Network traffic anomaly detection algorithm based on multi-modal feature fusion

    CN118353660A

  • Method and system for collecting network security threat information

    CN119743335A