A risk assessment method and system based on topology analysis

By constructing a multipath propagation topology model and combining node status and path interaction characteristics, risk convergence nodes are identified, solving the problem of risk underestimation in existing technologies and achieving accurate identification and dynamic updating of network risks.

CN120880939BActive Publication Date: 2025-12-23XUANCHENG POWER SUPPLY OF ANHUI ELECTRIC POWER CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511396120.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2025-12-23
Estimated Expiration
2045-09-28

AI Technical Summary

Technical Problem

In existing technologies, network risk assessment methods are mostly based on single dominant path analysis, ignoring multi-path effects. This leads to an underestimation of risk and a lack of real-time performance and accuracy, making it difficult to support risk warning and control for highly reliable systems.

Method used

By constructing a multi-path propagation topology model, combining node operating status and path interaction characteristics, risk convergence nodes are identified and comprehensively quantified to generate network risk distribution.

Benefits of technology

It enables accurate identification and quantification of multi-path risks, avoids the problem of risk underestimation, and provides dynamic updates of network risks and reliable risk warning basis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880939B_ABST
    Figure CN120880939B_ABST
Patent Text Reader

Abstract

The application discloses a kind of risk assessment method and system based on topology analysis, it is related to risk assessment technical field, including the following steps: analysis interconnection between nodes, extract the multiple propagation paths between any two nodes, form path set;Based on risk transmission direction and path attribute, map path set, construct multi-path propagation relationship graph;Based on multi-path propagation relationship graph, identify the risk convergence node with multi-path risk input, and fuse the comprehensive risk value of the node by calculating multi-path attribute;Based on comprehensive risk value and combined with operating state data, generate network risk distribution.The application constructs multi-path propagation topology model, and combines node operating state and path interaction characteristics, to solve the problem of underestimating network overall risk in prior art by only relying on single dominant path, to carry out convergence analysis and comprehensive quantification on the risk on multiple paths.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of risk assessment, more particularly, the present application relates to a risk assessment method and system based on topology analysis. BACKGROUND

[0002] In power, communication and complex network operation management, risk assessment is an important link to ensure system security and stability. In the prior art, network risk analysis methods are mostly based on the shortest path or a single dominant path for transmission calculation, and the node or network overall risk is evaluated through a single path propagation model. However, in actual networks, there may be multiple parallel propagation paths between nodes, and risks may accumulate or interact between different paths. Single path analysis cannot reflect this multi-path effect, which may lead to underestimation of the risk of critical nodes. In addition, traditional methods usually ignore the dynamic changes of node state and the interaction logic between paths, so that the risk assessment results lack real-time and accuracy, and it is difficult to support risk warning, control and optimal scheduling of high reliability systems.

[0003] The above disclosed technical solutions have at least the following technical problems: existing methods are mostly based on the shortest path or a single dominant path analysis, but in actual networks, risks may propagate in parallel through multiple paths, and the strength is superimposed. Ignoring the multi-path effect will underestimate the global risk.

[0004] To solve the above problems, the present application provides a solution. SUMMARY

[0005] In order to overcome the above-mentioned defects of the prior art, the embodiments of the present application provide a risk assessment method and system based on topology analysis, which builds a multi-path propagation topology model, and combines node operating state and path interaction characteristics to conduct convergence analysis and comprehensive quantification of risks on multiple paths, so as to solve the problem of underestimating the overall network risk in the prior art by relying only on a single dominant path.

[0006] To achieve the above-mentioned purposes, the present application provides the following technical solutions:

[0007] On the one hand, a risk assessment method based on topology analysis includes the following steps: analyzing the connection relationship between nodes, extracting multiple propagation paths between any two nodes to form a path set; mapping the path set based on risk transmission direction and path attribute, and constructing a multi-path propagation relationship graph; based on the multi-path propagation relationship graph, identifying a risk convergence node with multiple path risk input, and calculating the comprehensive risk value of the node by fusing the multi-path attribute; based on the comprehensive risk value and combined with the operating state data, generating network risk distribution.

[0008] In a preferred embodiment, the inter-node connectivity relationship is analyzed by establishing a topological description model, and the specific construction steps of the topological description model are as follows: collecting topological structure data and running state data of the target network, and establishing an initial adjacency matrix; performing multi-path compression coding on the initial adjacency matrix to generate a path distribution vector between any two nodes, the path distribution vector including a path probability weight and a path entropy value; and based on the path distribution vector, applying a risk energy conservation constraint rule to establish a topological description model.

[0009] In a preferred embodiment, the initial adjacency matrix is compressed and coded by a multi-path to generate a path distribution vector between any two nodes, and the specific steps are as follows: enumerating all feasible propagation paths between the source node and the target node by a breadth-first search method; extracting a path feature vector of each path, the feature vector including a path length, a number of passed nodes, an edge weight, and a node running state label; calculating a propagation probability weight of the path based on the path feature vector, normalizing all weights, and calculating an entropy value of the path distribution; integrating the normalized probability weight and the entropy value into a path distribution vector, and compressing and storing the multi-path information by the vector.

[0010] In a preferred embodiment, the inter-node connectivity relationship is analyzed by extracting a plurality of propagation paths between any two nodes to form a path set, and the specific steps are as follows: reversely decoding an initial path list based on the pre-stored path distribution vector and the associated node and edge identifiers; obtaining real-time running state data of the target network, and dynamically screening the initial path list based on the running state data to obtain effective paths that currently have propagation conditions; supplementing real-time attribute information to the screened effective paths to form structured path data; and classifying the structured path data according to the start point-end point node pairs to form an effective propagation path set of the multi-node pairs.

[0011] In a preferred embodiment, the path set is mapped based on the risk transmission direction and the path attribute to construct a multi-path propagation relationship graph, and the specific steps are as follows: mapping the effective propagation paths of the multi-node pairs to the graph to construct an initial multi-path propagation relationship graph, taking nodes as vertices and paths as edges; labeling the interaction relationship between the paths based on the paths sharing nodes or edges in the relationship graph, and determining the priority transmission path and the potential inhibition path of the risk flow at the node; dividing the paths according to the propagation probability weight of the priority transmission path and the potential inhibition path and the multi-path interaction logic; and dynamically adjusting the multi-path propagation relationship graph based on the division result and the real-time running state of the target network.

[0012] In a preferred embodiment, the multi-path propagation relationship graph is used to identify a risk convergence node with multi-path risk input, specifically: in the multi-path propagation relationship graph, a candidate node located at the intersection of multiple high-weight paths is identified, and directional superposition of input risk flow is performed based on path interaction logic; a risk convergence gain factor representing the risk amplification effect of multiple paths is constructed based on the propagation probability weight and distribution entropy of each path; the intrinsic risk response value of the candidate node is combined with the risk convergence gain factor to determine the risk convergence node and its comprehensive risk level.

[0013] In a preferred embodiment, the candidate node located at the intersection of multiple high-weight paths is identified in the multi-path propagation relationship graph, specifically: the propagation probability weight is sorted in the multi-path propagation relationship graph, and a weight threshold is set to filter out high-weight paths; the frequency of each node in the high-weight path is counted to obtain the path intersection degree index of the node; the path intersection degree index is compared with a preset threshold to determine the risk convergence candidate node.

[0014] In a preferred embodiment, the directional superposition of input risk flow based on path interaction logic is performed, specifically: the directional relationship of all incoming and outgoing paths of the candidate node is extracted, and a risk flow superposition operator is constructed based on path interaction logic.

[0015] In a preferred embodiment, the network risk distribution is generated based on the comprehensive risk value and combined with the running state data, including: obtaining real-time state information of the risk convergence node and generating a node dynamic attribute set; calculating the actual risk energy output value of each risk convergence node under the current network state based on the comprehensive risk value and dynamic attribute set of the node; mapping the actual risk energy output value of each node to the network topology structure to form a node-risk matrix; filtering the dominant path set based on the node-risk matrix, and eliminating infeasible paths caused by node abnormalities or path failures; outputting the risk convergence node, actual risk energy output value and filtered dominant path set in a structured form.

[0016] On the other hand, a risk assessment system based on topology analysis includes the following modules: a path extraction module for analyzing the connectivity between nodes and extracting multiple propagation paths between any two nodes to form a path set; a multi-path graph construction module for mapping the path set based on risk transmission direction and path attributes to construct a multi-path propagation relationship graph; a risk convergence identification module for identifying a risk convergence node with multi-path risk input based on the multi-path propagation relationship graph, and calculating the comprehensive risk value of the node by combining multi-path attributes; a risk distribution output module for generating a network risk distribution based on the comprehensive risk value and combined with the running state data.

[0017] The technical effects and advantages of the risk assessment method and system based on topology analysis are as follows:

[0018] 1. The present application realizes quantitative analysis of the multi-path parallel propagation of risks in the network by constructing a multi-path propagation relationship graph, combining path propagation probability weight, path entropy value and directionality superposition operator, so as to accurately identify risk convergence nodes and their comprehensive risk levels, and effectively avoid the risk underestimation problem caused by traditional single-path calculation.

[0019] 2. The present application couples the comprehensive risk level of the risk convergence node with the real-time running state of the network to generate the actual risk energy output of the node, and determines the dominant risk diffusion path in combination with the multi-path propagation relationship graph, realizes dynamic update and structured output of the network risk distribution, and provides a reliable basis for risk early warning, control and network vulnerability analysis. BRIEF DESCRIPTION OF DRAWINGS

[0020] Figure 1 The figure is a flowchart of the risk assessment method based on topology analysis of the present application.

[0021] Figure 2 The figure is a structural diagram of the risk assessment system based on topology analysis of the present application. DETAILED DESCRIPTION

[0022] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0023] Embodiment 1, Figure 1 The risk assessment method based on topology analysis of the present application is given, including the following steps:

[0024] S1, analyze the connection relationship between nodes, extract multiple propagation paths between any two nodes to form a path set;

[0025] The connection relationship between nodes is analyzed by establishing a topology description model, and the specific construction steps of the topology description model are as follows:

[0026] Collect the topology structure data and running state data of the target network to establish an initial adjacency matrix. In this embodiment, the topology structure data includes node information and connection information, and the running state data includes node state.

[0027] The initial adjacency matrix is compressed and encoded by multiple paths, and multiple propagation paths between any two nodes are stored in the form of path distribution vectors, the path distribution vectors including path probability weights and path entropy values, used for representing the intensity and uncertainty of multiple path parallel propagation;

[0028] Based on the path distribution vector, a risk energy conservation constraint rule is established, so that the risk of the source node satisfies the total conservation when diffusing to multiple paths, and a topology description model considering the multiple path characteristics and risk energy rationality is obtained.

[0029] The initial adjacency matrix is compressed and encoded by multiple paths, and multiple propagation paths between any two nodes are stored in the form of path distribution vectors, and the specific steps are as follows:

[0030] The breadth-first search method is used to enumerate the feasible propagation paths of any two nodes, and the path length, the number of nodes passed, the edge weight and the node running state label of each path are extracted to form a path feature vector;

[0031] The propagation probability weight of the path is calculated based on the path feature vector, wherein the shorter the path and the more fragile the node state, the greater the propagation probability;

[0032] The propagation probability weights of all paths are normalized, and the path distribution entropy value is calculated, used for representing the dispersion and uncertainty of the risk among multiple paths;

[0033] The probability weight and the entropy value of the path set are integrated to form a path distribution vector, which is stored in the topology description model in a compressed form, replacing the traditional redundant path storage method, thereby reducing the storage complexity and improving the calculability of risk propagation.

[0034] The propagation probability weight is calculated according to the following formula:

[0035]

[0036]

[0037]

[0038] The path distribution entropy value is calculated according to the following formula:

[0039]

[0040] wherein, is the propagation probability weight, is the vulnerability coefficient of the node v on the path, the larger the value, the easier the node transmits the risk, is the path length attenuation function, is the total number of paths in the set, actual capacity of node v, maximum capacity in the network, length of the path ,preset attenuation factor,path distribution entropy value, the greater the entropy value, the more uniform the risk distribution among multiple paths and the higher the uncertainty, and the smaller the entropy value, the risk is mainly concentrated along a small number of paths, which can assist in identifying the dominant path set. In this embodiment, the risk energy conservation constraint rule is specifically:

[0041] In this embodiment, the risk energy conservation constraint rule is specifically:

[0042]

[0043] wherein, risk energy flowing into node v is obtained by superimposing the risk amounts of all incoming edge paths, risk energy emitted by node v is distributed to different downstream paths, risk energy consumed inside node v. Through the risk energy conservation constraint rule:

[0044] Avoids the risk amount distortion problem caused by multi-path convergence;

[0045] Guarantees the closure of risk value calculation in the whole network range, so that the output risk distribution result is more in line with the network physical and logical rules;

[0046] Improves the stability and interpretability of risk propagation analysis, and provides a reliable basis for subsequent risk control and dominant path identification.

[0047] In this embodiment, the multiple propagation paths between any two nodes are extracted to form a path set, which is specifically:

[0048] From the multi-path compression encoding result of the topology description model, the original feasible propagation paths are decoded reversely according to the path distribution vector and the associated node or edge identifier to form an initial path list;

[0049] In combination with the real-time running state data of the target network, the initial path list is screened to eliminate paths containing offline nodes, faulty edges or load rates exceeding the threshold, and to retain effective paths currently having propagation conditions;

[0050]

[0051] Real-time attribute information is supplemented for the screened effective paths, including actual propagation hop count, path real-time risk carrying capacity and real-time risk coupling coefficient of the path associated node, to form structured path data; ​​

[0052] Classify the structured path data according to start-end node pairs, each node pair corresponding to an independent path subset, all subsets integrated to form a final multi-node pair effective propagation path set, providing a standardized input for subsequent construction of a multi-path propagation relationship graph.

[0053] S2, mapping the path set based on the risk transmission direction and path attribute, and constructing a multi-path propagation relationship graph;

[0054] The mapping of the path set based on the risk transmission direction and path attribute, and the construction of the multi-path propagation relationship graph, specifically are:

[0055] Map each path in the multi-node pair effective propagation path set to the graph, with nodes as vertices and paths as edges, to form an initial multi-path propagation relationship graph;

[0056] Based on the direction information of each path in the graph, identify potential transmission center nodes and diffusion order (statistically calculate the "in-degree", "out-degree" and propagation probability of all nodes in the path, and the node with a greater out-degree weight than the in-degree weight is considered as a potential diffusion center);

[0057] For paths sharing nodes or edges, mark the path interaction relationship in the graph, and determine the priority transmission path and potential suppression path of the risk flow at the node;

[0058] According to the propagation probability weight and multi-path interaction logic of the priority transmission path and potential suppression path, the path is divided into a dominant layer, an auxiliary layer and a low-risk layer, which are used to identify core diffusion paths and alternative paths;

[0059] Combine the real-time running state of the target network to analyze the impact of path failure or node anomaly on the graph, and dynamically adjust the structure of the multi-path propagation relationship graph;

[0060] Save the final multi-path propagation relationship graph in a structured form for subsequent risk convergence node identification and dominant path decision analysis.

[0061] S3, based on the multi-path propagation relationship graph, identify risk convergence nodes with multi-path risk input, and calculate the comprehensive risk value of the node by integrating multi-path attributes;

[0062] In this embodiment, the multi-path propagation relationship graph is used to identify risk convergence nodes with multi-path risk input, specifically:

[0063] In the multi-path propagation relationship graph, identify candidate nodes that are simultaneously located at the intersection of multiple high-weight paths, and perform directional superposition on the risk flow based on the path interaction logic recorded in the graph;

[0064] A risk convergence gain factor is constructed by combining the propagation probability weight of each path and the distribution entropy, and is used to represent the risk amplification effect of the node under the parallel action of multiple paths.

[0065] The risk response value of the candidate node is combined with the risk convergence gain factor to determine the risk convergence node and the comprehensive risk level, thereby avoiding the risk underestimation problem caused by the traditional single-path calculation.

[0066] In the multi-path propagation relationship graph, the candidate node that is simultaneously at the intersection of multiple high-weight paths is identified, specifically:

[0067] In the multi-path propagation relationship graph, the propagation probability weights of all paths are sorted, and a weight threshold is set, and only high-weight paths with a propagation probability weight greater than the threshold are retained;

[0068] The number of occurrences of each node in the high-weight path is counted to obtain the path intersection degree index of the node;

[0069] When the path intersection degree index of the node is greater than a preset threshold, the node is determined as a risk convergence candidate node.

[0070] The risk flow is directionally superimposed based on the path interaction logic recorded in the graph, specifically:

[0071] The directional relationship of all incoming paths and outgoing paths of the candidate node is extracted, and a risk flow superposition operator is constructed based on the path interaction logic, wherein the path interaction logic includes:

[0072] When the risk directions of multiple incoming paths are consistent, the risk amount is superimposed in a linear cumulative manner;

[0073] When the risk directions of the incoming paths are opposite or there is a mutual cancellation relationship, the risk amount is differentially superimposed according to the path probability weight, so as to reflect the risk weakening effect;

[0074] When multiple paths compete for the same outgoing path at the candidate node, a path priority factor is introduced, the main transmission direction is determined according to the propagation probability weight and the path entropy value, and a decay coefficient is applied to the risk amount of the secondary path;

[0075] Through the above directional superposition, the risk response value of the candidate node not only reflects the numerical accumulation of the risk amount, but also reflects the amplification, cancellation and preferential transmission effect under the interaction of multiple paths, so as to obtain a risk convergence representation that is more in line with the actual propagation mechanism.

[0076] The risk flow superposition operator, specifically:

[0077]

[0078]

[0079] the risk aggregation gain factor, specifically:

[0080]

[0081] the comprehensive risk level, specifically:

[0082]

[0083] wherein, is a risk flow superposition operator, is a path directionality coefficient, if the risk direction is consistent with the main transmission direction, then , if it is opposite, then , is a path propagation probability weight, is a high-weight path set, is a path priority factor, is a preset proportion coefficient, is the length of path i, is the vulnerability coefficient of a node on the path, is a risk aggregation gain factor, is a preset gain adjustment coefficient, is a path distribution entropy value, is a comprehensive risk level.

[0084] S4, based on the comprehensive risk value and in combination with the operating state data, generating a network risk distribution.

[0085] In this embodiment, the generating of the network risk distribution based on the comprehensive risk value and in combination with the operating state data is specifically:

[0086] Real-time load, voltage, availability and edge state information associated with the risk aggregation node are obtained, and a dynamic attribute set of the node is generated;

[0087] Based on the comprehensive risk level, in combination with the dynamic attributes of the node, the actual risk energy output of each risk aggregation node under the current network state is calculated;

[0088] The actual risk energy output of all risk aggregation nodes is mapped into the network topology structure to form a node-risk matrix, and a weighted superposition is performed in combination with a multi-path propagation relationship graph to reflect the diffusion distribution of the risk along different paths;

[0089] Based on the node-risk matrix, paths with high risk propagation probability weight and low path entropy are screened to form a dominant path set, and infeasible paths affected by node abnormalities or path failures are eliminated;

[0090] The risk aggregation node, the actual risk energy output and the dominant path set are output in a structured form, and are used for subsequent risk early warning, control and network vulnerability analysis.

[0091] The actual risk energy output is specifically:

[0092]

[0093]

[0094]

[0095] Wherein, is the actual risk energy output, is the comprehensive risk level, is the node real-time operation state coupling coefficient, is the node availability coefficient, online is 1, offline or failure is (0, 1), is the load adjustment coefficient, is the node current load, is the node maximum tolerance load.

[0096] Embodiment 2, Figure 2 The application provides a risk assessment system based on topology analysis, comprising the following modules:

[0097] The path extraction module is used for analyzing the connection relationship between nodes, extracting multiple propagation paths between any two nodes, and forming a path set.

[0098] The multi-path atlas construction module is used for mapping the path set based on the risk transmission direction and the path attribute, and constructing a multi-path propagation relationship atlas.

[0099] The risk aggregation identification module is used for identifying the risk aggregation node with multiple path risk inputs based on the multi-path propagation relationship atlas, and calculating the comprehensive risk value of the node by fusing the multi-path attribute.

[0100] The risk distribution output module is used for generating the network risk distribution based on the comprehensive risk value and in combination with the operation state data.

[0101] The above formulas are all dimensionless numerical calculations, the formulas are obtained by collecting a large amount of data to simulate a formula of the nearest real situation, and the preset parameters in the formula are set by the person skilled in the art according to the actual situation.

[0102] The above embodiments can be realized by software, hardware, firmware or any combination thereof in whole or in part. When realized by software, the above embodiments can be realized in the form of a computer program product in whole or in part.

[0103] Those skilled in the art can understand that the modules and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0104] In addition, each functional module in each embodiment of the present application can be integrated in one processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.

[0105] The above is merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0106] Finally: the above is only the preferred embodiment of the present application, and is not used to limit the present application, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.

Claims

1. A risk assessment method based on topology analysis, characterized in that, Includes the following steps: Analyze the connectivity between nodes, extract multiple propagation paths between any two nodes, and form a path set; Mapping the path set based on the risk transmission direction and path attributes, and constructing a multi-path propagation relationship graph; Based on the multi-path propagation relationship graph, risk convergence nodes with multi-path risk inputs are identified, and the comprehensive risk value of the node is calculated by integrating multi-path attributes. Specifically, in the multi-path propagation relationship graph, candidate nodes located at the intersection of multiple high-weight paths are identified, and the input risk flows are directionally superimposed based on path interaction logic; combining the propagation probability weights and distribution entropy of each path, a risk convergence gain factor characterizing the multi-path risk amplification effect is constructed, thereby determining the risk convergence node and its comprehensive risk level. The input risk flow is directionally superimposed based on path interaction logic. Specifically, the directional relationship between all inbound and outbound paths of candidate nodes is extracted, and a risk flow superposition operator is constructed based on the path interaction logic. Based on the comprehensive risk value and combined with operational status data, a network risk distribution is generated; The risk flow superposition operator is specifically: The risk convergence gain factor is specifically: The overall risk level is as follows: in, For risk flow superposition operators, This is the path directionality coefficient; if the risk direction is consistent with the main transmission direction, then... If the opposite is true, then , For path propagation probability weights, For the set of high-weight paths, For path priority factors, This is a preset proportional coefficient. Let i be the length of path i. Vulnerability coefficient of nodes on the path The actual capacity of node i. The maximum capacity in the network. As a risk convergence gain factor, The preset gain adjustment coefficient, The path distribution entropy value. To assess the overall risk level.

2. The risk assessment method based on topology analysis according to claim 1, characterized in that, The analysis of connectivity relationships between nodes is performed by establishing a topology description model. The specific steps for constructing the topology description model are as follows: Collect the topology and operational status data of the target network and establish an initial adjacency matrix; The initial adjacency matrix is ​​subjected to multipath compression encoding to generate a path distribution vector between any two nodes. The path distribution vector includes path probability weights and path entropy values. A topological description model is established based on the path distribution vector and the risk energy conservation constraint rule.

3. The risk assessment method based on topology analysis according to claim 2, characterized in that, The process of performing multi-path compression encoding on the initial adjacency matrix to generate a path distribution vector between any two nodes is as follows: Enumerate all feasible propagation paths between the source node and the target node using a breadth-first search method; Extract the path feature vector for each path, the feature vector including path length, number of nodes passed through, edge weight and node running status label; The propagation probability weights of the path are calculated based on the path feature vectors, all weights are normalized, and the entropy value of the path distribution is calculated. The normalized probability weights and entropy values ​​are integrated into a path distribution vector, and multi-path information is compressed and stored using this vector.

4. The risk assessment method based on topology analysis according to claim 3, characterized in that, The analysis of connectivity between nodes involves extracting multiple propagation paths between any two nodes to form a path set, specifically: Based on the pre-stored path distribution vector and its associated node and edge identifiers, the initial path list is generated by reverse decoding. Obtain real-time operational status data of the target network, and dynamically filter the initial path list based on the operational status data to obtain the effective paths that currently have the conditions for propagation; Real-time attribute information is added to the filtered valid paths to form structured path data; The structured path data is categorized according to the origin-end node to form a set of effective propagation paths with multiple node pairs.

5. The risk assessment method based on topology analysis according to claim 4, characterized in that, The mapping of path sets based on risk transmission direction and path attributes to construct a multi-path propagation relationship graph is as follows: The effective propagation paths of multiple node pairs are mapped to the graph, with nodes as vertices and paths as edges, to construct an initial multi-path propagation relationship graph; Based on the paths of shared nodes or shared edges in the relationship graph, the interaction relationships between paths are marked, and the priority transmission paths and potential suppression paths of risk flows at the nodes are determined. The paths are divided according to the propagation probability weights of the preferred transmission paths and potential suppression paths, as well as the multi-path interaction logic; Based on the partitioning results and the real-time operating status of the target network, the multipath propagation relationship graph is dynamically adjusted.

6. The risk assessment method based on topology analysis according to claim 5, characterized in that, The process of identifying candidate nodes located at the intersection of multiple high-weight paths in the multi-path propagation graph specifically involves: In the multipath propagation relationship graph, the propagation probability weights are sorted and weight thresholds are set to filter out high-weight paths. The frequency of each node's occurrence in high-weight paths is counted to obtain the path intersection index of the nodes; The path convergence index is compared with a preset threshold to determine candidate nodes for risk convergence.

7. The risk assessment method based on topology analysis according to claim 6, characterized in that, The generation of network risk distribution based on comprehensive risk value and combined with operational status data includes: Obtain real-time status information of risk aggregation nodes and generate a set of dynamic node attributes; Based on the comprehensive risk value and dynamic attribute set of the nodes, calculate the actual risk energy output value of each risk convergence node under the current network state; The actual risk energy output value of each node is mapped to the network topology to form a node-risk matrix; The dominant path set is selected based on the node-risk matrix, and infeasible paths caused by node anomalies or path failures are removed. Output risk convergence nodes, actual risk energy output values, and the set of selected dominant paths in a structured form.

8. A system using a risk assessment method based on topology analysis as described in any one of claims 1-7, characterized in that, Includes the following modules: Path extraction module: used to analyze the connectivity between nodes, extract multiple propagation paths between any two nodes, and form a path set; Multi-path graph construction module: used to map path sets based on risk transmission direction and path attributes to construct a multi-path propagation relationship graph; Risk convergence identification module: Based on the multi-path propagation relationship graph, it identifies risk convergence nodes with multi-path risk inputs and calculates the comprehensive risk value of the node by integrating multi-path attributes; Risk distribution output module: Used to generate network risk distribution based on comprehensive risk value and combined with operational status data.

Citation Information

Patent Citations

  • Network risk assessment method and device, electronic equipment and storage medium

    CN110557393A

  • Credit risk early warning method and device

    CN113516553A