Method and system for dynamically evaluating damage degree of network attack

By acquiring resource and threat data through edge nodes, dynamically adjusting device strategies and coordinating detection, the problems of unstable resource load and rigid model updates are solved, achieving system stability and accurate assessment under high load and providing targeted remediation strategies.

CN120896870APending Publication Date: 2025-11-04HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511006210.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

In existing technologies, resource load cannot be dynamically adjusted, and crashes are prone to occur under high load. Rigid edge model updates lead to delays in critical business operations, and attack damage assessments rely on static indicators, causing scores to deviate from the actual business impact.

Method used

By acquiring resource metrics and threat traffic data through edge nodes, generating resource status reports, dynamically adjusting device grouping and polling strategies, triggering threat monitoring modes, collaboratively detecting and performing threat identification, generating edge model update requirements, and calculating network attack damage scores based on weighted fusion algorithms.

Benefits of technology

It achieves system stability under high load, improves detection accuracy, ensures timely model updates, quantifies the dynamic damage of attacks to resources, provides targeted remediation strategies, and solves the problems of assessment lag and protection disconnect in high-concurrency scenarios of traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120896870A_ABST
    Figure CN120896870A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a dynamic evaluation method and system for the damage degree of a network attack, and belongs to the technical field of network attack damage degree evaluation. The method comprises the following steps: acquiring resource index data and threat flow metadata screened through an edge model from an edge node, and generating a resource state report; triggering a threat monitoring mode when any resource index continuously exceeds a set threshold for multiple times; executing threat identification through collaborative detection, and generating an edge model updating demand; issuing a grading increment updating instruction of the edge model; monitoring resource flow data of the equipment, and calculating a network attack damage degree score by using a weighted fusion algorithm; and generating a network attack damage degree evaluation report. According to the method, the threat data compressed and transmitted by the edge model are received, and the monitoring mode is dynamically triggered in combination with the resource state, so that the high-load stability of the system is guaranteed, and the problems of evaluation lag and protection disjunction of a traditional method in a high-concurrency scene are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network attack damage degree evaluation, and particularly relates to a network attack damage degree dynamic evaluation method and system. BACKGROUND

[0002] With the rapid development of industrial internet and edge computing, the complexity and destructiveness of network attacks have significantly increased. Traditional network attack evaluation methods mainly rely on centralized analysis architecture, which collects full traffic data to the cloud for deep packet inspection (DPI) and behavior analysis. In recent years, dynamic evaluation techniques based on machine learning have been gradually applied in this field, such as using random forest models to identify known attack patterns, or using LSTM networks to detect time series anomalies. In resource-constrained edge side, lightweight model deployment has become a research hotspot. In addition, existing technologies attempt to optimize system load through resource monitoring and polling strategies, such as dynamically adjusting device grouping size based on CPU / memory threshold, or processing threat alerts according to business weight classification. However, these solutions still center on the central node, and the edge side only undertakes the task of basic data filtering, lacking a collaborative mechanism for model updating and resource scheduling. SUMMARY

[0003] The purpose of the present application is to provide a network attack damage degree dynamic evaluation method and system for dynamically sensing resource state and attack behavior changes, and quickly evaluating the damage degree of network attacks on different priority business systems.

[0004] To achieve the above purpose, the present application provides a network attack damage degree dynamic evaluation method, comprising: obtaining resource index data and threat flow metadata filtered by an edge model from an edge node, and generating a resource state report; dynamically adjusting a device grouping polling strategy according to the resource state report, and triggering a threat monitoring mode when any resource index exceeds a set threshold for multiple times in succession; when in the threat monitoring mode, performing threat identification through collaborative detection, and generating an edge model update requirement; issuing a hierarchical incremental update instruction of the edge model according to the edge model update requirement and a central node load state; when detecting that the edge model incremental update is completed, monitoring resource flow data of the device, calculating a network attack damage degree score using a weighted fusion algorithm; and generating a network attack damage degree evaluation report based on the network attack damage degree score.

[0005] Optionally, the obtaining of the resource index data and the threat flow metadata filtered by the edge model from the edge node, and the generation of the resource state report, comprises: obtaining the resource index data preprocessed by the edge node and the threat flow metadata filtered by the edge model; parsing and verifying the threat flow metadata, and aggregating resource indexes to generate the resource state report.

[0006] Optionally, the obtaining of the resource index data preprocessed by the edge node and the threat traffic metadata filtered by the edge model comprises: monitoring the execution of inference by the edge node, wherein the inference comprises extracting network traffic features of the edge device, constructing the extracted network traffic features of the edge device into a feature vector of fixed dimensions, and inputting the feature vector into an edge model, and the edge model traverses decision tree nodes according to a preset attack rule library; and when the features match threat rules, a threat traffic filtering result is output.

[0007] Optionally, the dynamically adjusting of the device grouping polling strategy according to the resource state report comprises: performing device grouping based on a preset initial device grouping polling strategy; dynamically optimizing the grouping scale according to a comprehensive health index in a device group on a regular basis, increasing the number of devices in the group when the comprehensive health index in the group increases, and reducing the number of devices in the group when the comprehensive health index in the group decreases; and monitoring resource usage indexes of the device group while dynamically optimizing the grouping scale, and triggering a threat monitoring mode when resource loads of the device group in continuous multiple samplings exceed a preset upper threshold, and prolonging a polling response period of the device group.

[0008] Optionally, the threat identification by cooperative detection and the generation of the edge model update requirement when in the threat monitoring mode comprise: performing full-amount feature analysis on a list of edge-filtered network traffic data transmitted by the edge node, verifying the validity of threats by a random forest model, and outputting a threat determination result; sampling original device network traffic data, comparing detection results of the edge model and a center model, and calculating a false negative rate of the edge model; and when the false negative rate continuously exceeds a preset false negative rate threshold for multiple times, generating an edge model update requirement including a target node ID, a false negative feature sample, and a priority label.

[0009] Optionally, the issuing of the edge model hierarchical incremental update instruction according to the edge model update requirement and the load state of the center node comprises: distributing the edge model update requirement to a corresponding update queue according to a priority label of the edge model update requirement; the priority label comprises a high-priority requirement, a medium-priority requirement, and a low-priority requirement; distributing the high-priority requirement to a parallel update channel, distributing the medium-priority requirement to a to-be-scheduled queue, and distributing the low-priority requirement to a resource-aware waiting queue.

[0010] Optionally, the issuing of the edge model hierarchical incremental update instruction according to the edge model update demand and the center node load state further comprises: monitoring a center node resource index, if a resource load in the center node resource index exceeds a preset load threshold, suspending a high-priority demand and a low-priority demand queue task; triggering a batch compensation task in an off-peak period, and preferentially processing an overdue node that is not updated.

[0011] Optionally, the monitoring of the resource flow data of the device after detecting that the edge model incremental update is completed, and the calculation of the network attack damage degree score using a weighted fusion algorithm comprises: monitoring resource flow data of the attacked device; performing weighted summation according to a preset weight coefficient through a weighted fusion algorithm; introducing a time decay function to calculate the network attack damage degree score.

[0012] Optionally, the generation of the network attack damage degree evaluation report based on the network attack damage degree score comprises: mapping the network attack damage degree score to a risk level; mapping the network attack damage degree score value, the attack type, the resource impact peak value and the business interruption index to corresponding fields of the network attack damage degree evaluation report; matching a repair scheme corresponding to the network attack event according to the risk level, and generating a visual report containing the risk level and the repair scheme.

[0013] In another aspect, the present application provides a network attack damage degree dynamic evaluation system for implementing the network attack damage degree dynamic evaluation method, which comprises a control module, the control module comprising a memory, a processor and a computer program stored on the memory and executable on the processor, and the processor executes the computer program to implement the network attack damage degree dynamic evaluation method.

[0014] The above technical solution receives threat data compressed and transmitted by an edge model, dynamically triggers a monitoring mode in combination with a resource state, guarantees system high-load stability, improves detection accuracy based on edge and center model collaborative verification, generates model update demands according to a false negative rate, adopts a multi-level queue and a delay compensation mechanism to ensure timely response, uses a business priority weighted fusion time decay function to accurately quantify the dynamic damage degree of attacks on resources, and finally outputs a targeted repair strategy in association with attack characteristics, effectively solving the problems of evaluation lag and protection disconnection in a high-concurrency scene in traditional methods.

[0015] Other features and advantages of the present application will be described in detail in the following specific embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0016] The accompanying drawings are included to provide a further understanding of the present application, and constitute a part of the specification, and are used together with the following specific embodiments to explain the present application, but do not constitute a limitation on the present application. In the drawings: Figure 1 is a network attack damage degree dynamic evaluation flowchart.

[0017] Figure 2 is an edge model incremental update flowchart. DETAILED DESCRIPTION

[0018] The following description will be made in conjunction with the accompanying drawings as follows: Figure 1 - the accompanying drawings Figure 2 The specific implementation of the embodiments of the present application is described in detail. It should be understood that the specific implementation described herein is only used to illustrate and explain the embodiments of the present application, and is not used to limit the embodiments of the present application.

[0019] It should be noted that the acquisition, transmission, storage, use, processing, etc. of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations. In the embodiments of the present application, some existing industry solutions may be mentioned, such as software, components, models, etc. They should be considered as exemplary, and their purpose is only to illustrate the feasibility of the implementation of the technical solutions of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0020] The present inventors found in the process of implementing the present application that the prior art has the defects that the resource load cannot dynamically adjust the polling strategy, and is easy to crash under high load; the edge model update is rigid, which causes delay of key business, and the attack damage evaluation only relies on static indicators, which causes the score to deviate from the actual business impact.

[0021] Embodiment 1 Reference Figures 1-2 As the first embodiment of the present application, the embodiment provides a network attack damage degree dynamic evaluation method, comprising: S100: Obtain resource index data and threat flow metadata filtered by an edge model from an edge node, and generate a resource state report.

[0022] Further, the resource index data preprocessed by the edge node and the threat flow metadata filtered by the edge model are obtained; the threat flow metadata is parsed and verified, and the resource index is aggregated to generate a resource state report.

[0023] Further, the edge node performs reasoning, which includes extracting edge device network flow features, constructing the extracted edge device network flow features into a fixed-dimension feature vector, and inputting the feature vector into an edge model, the edge model traverses decision tree nodes according to a pre-set attack rule library; when the features match threat rules, output a threat flow filtering result.

[0024] Specifically, network traffic feature extraction is performed by a lightweight model (such as a lightweight decision tree model optimized by a tensor real-time inference engine) deployed on an edge device (such as a router / firewall) supporting eBPF (extended Berkeley Packet Filter), and specific features such as five-tuple, protocol type, packet size distribution, and TLS fingerprint are collected, and the extracted features are constructed into a fixed-dimension feature vector. The feature vector is input into the lightweight decision tree model for real-time inference. The lightweight decision tree model traverses the preset attack rule library, and when the feature vector hits a threat rule for three consecutive times (subject to a buffer count threshold), a threat traffic screening result is output. Only the metadata (such as IP address, port number, protocol type, timestamp, and feature label) marked as threat traffic is compressed and transmitted to the central node, which performs NetFlow (network traffic flow) full analysis and session reconstruction verification on the metadata, and aggregates resource indicators such as CPU, memory, bandwidth, and process number of the edge device to generate a report containing a verified threat list and comprehensive resource status.

[0025] Further, the threat list includes IP address, port number, protocol type, timestamp, and the like; and the comprehensive resource status includes CPU utilization, memory utilization, network bandwidth occupancy, and the like.

[0026] Preferably, the above scheme significantly reduces the bandwidth and processing pressure of the central node. By using a lightweight decision tree model deployed on an edge device (such as a router / firewall) supporting eBPF, network traffic features are extracted in real time at the data source and preliminary threat screening is performed, and only compressed metadata marked as threats is transmitted to the center, thereby reducing the bandwidth and processing pressure of the central node.

[0027] S200: According to the resource status report, dynamically adjust the device grouping polling strategy, and trigger the threat monitoring mode when any resource indicator exceeds the set threshold for multiple times in a row.

[0028] Further, the devices are grouped based on a preset initial device grouping polling strategy; the grouping size is dynamically optimized based on the comprehensive health indicators of the device group at regular intervals, and when the comprehensive health indicators of the group increase, the number of devices in the group is increased, and when the comprehensive health indicators of the group decrease, the number of devices in the group is decreased; while dynamically optimizing the grouping size, the resource usage indicators of the device group are monitored, and when the resource load of the device group exceeds the preset upper threshold for multiple times in a row, the threat monitoring mode is triggered, and the polling response period of the device group is extended.

[0029] Specifically, based on the preset initial device grouping strategy (default 50 devices / group), first, the device grouping is established according to the proximity of the device and the business importance, and the grouping rule is to group according to the business importance (such as core infrastructure control, non-core auxiliary facility operation, etc.) first, and then group according to the proximity of the device (the physical location or network topology of the devices in the same group is similar); every 10 minutes, the group size is dynamically adjusted according to the comprehensive health index (CPU health score + memory health score) in the group. CPU health score = (1-CPU actual utilization rate / 100) x CPU weight coefficient, memory health score = (1-memory actual utilization rate / 100) x memory weight coefficient (CPU actual utilization rate and memory actual utilization rate are not 0). The CPU weight coefficient and the memory weight coefficient are set according to the business type, such as the CPU weight coefficient of the computing-intensive business is set to 0.7, and the memory weight coefficient is set to 0.3, the CPU weight coefficient of the memory-intensive business is set to 0.3, and the memory weight coefficient is set to 0.7.

[0030] Further, when the health index increases (device load decreases), the number of devices in the group is increased (maximum +12%), and when the health index decreases (load increases), the number of devices is reduced (minimum-12%).

[0031] Preferably, the CPU, memory and other resource indicators of each group are continuously monitored, and if any resource indicator (such as CPU>70% or memory>75%) exceeds the preset upper threshold value for 3 consecutive samplings, the threat monitoring mode is triggered for the device group, and the polling response period is extended, such as from normal 5 seconds to 30 seconds; the low-load recovery mechanism is simultaneously enabled, and when the resource indicator is lower than the lower threshold value (such as CPU<60%) for 3 consecutive times, it is returned to the normal period of 5 seconds.

[0032] Preferably, the above scheme is based on the business importance and proximity of the device for initial grouping, and the group size is adjusted regularly according to the dynamically calculated comprehensive health index in the group, which optimizes the overall resource utilization and efficiency of the polling system. Secondly, through continuous sampling monitoring of the key resource indicators of the device group, potential overload or attacked node groups can be accurately identified. Extending the polling response period can provide an overload relief buffer period for the group to reduce the monitoring burden, avoid collapse under high load, and gain time for in-depth analysis.

[0033] S300: When in threat monitoring mode, threat identification is performed through cooperative detection, and edge model update demand is generated.

[0034] Further, the received edge node transmitted edge screening network traffic data list is subjected to full-amount feature analysis, the effectiveness of the threat is verified through a random forest model, and a threat determination result is output; sample original device network traffic data, compare the detection results of the edge model and the center model, and calculate the false negative rate of the edge model; when the false negative rate exceeds the set false negative rate threshold for multiple times in succession, an edge model update requirement containing the target node ID, the false negative feature sample, and the priority label is generated.

[0035] Specifically, when the center node enters the threat monitoring mode, a three-stage cooperative detection process is performed. First, through a NetFlow full-amount analyzer, based on the screening network traffic data metadata transmitted by the edge node, the original traffic mirror pool is reversely searched, and the original network traffic saved through an independent mirror mechanism is extracted; then a protocol session reconstruction engine is enabled, TCP / UDP session streams are recombined, and application layer protocols are deconstructed, and a 72-dimensional full-amount feature vector is generated; the feature vector is input into the random forest model deployed in the center (using the complete feature set) to perform deep verification on the screened threat traffic, including NetFlow packet reconstruction, protocol session reconstruction, and load content analysis, and output the final threat determination result.

[0036] Further, 50 original network traffics are sampled per hour according to the business importance, and the detection results of the edge model and the center model (the random forest model deployed in the center) are compared respectively, and the false negative rate of the edge model (the percentage of the number of false negative samples to the total number of real threat samples) is calculated; when the false negative rate exceeds the preset threshold continuously, i.e. the false negative rate of the high-priority edge node (such as the core control device) is greater than 3% and exceeds the threshold for 2 times continuously, the false negative rate of the medium-priority edge node (such as the environmental monitoring device) is greater than 5% and exceeds the threshold for 3 times continuously, and the false negative rate of the low-priority edge node (such as the sensor) is greater than 7% and exceeds the threshold for 5 times continuously, a structured edge model update requirement is generated, which contains three core elements: target edge node ID identification, specific false negative feature sample, such as unidentified TLS (Transport Layer Security) abnormal handshake fingerprint or SQL (Structured Query Language) injection feature fragment, and priority label (high-priority requirement / medium-priority requirement / low-priority requirement) marked according to the business importance of the node, so as to trigger subsequent edge model incremental update.

[0037] Preferably, the above scheme performs deep analysis through the random forest model deployed by the center node, verifies the edge preliminary screening result with high precision, and significantly reduces the false alarm and missed alarm risk. By strictly comparing the detection results of the edge model and the center model, the missed alarm rate of the edge model is obtained. According to the continuous over-standard threshold set by different priority nodes, a structured edge model update requirement is generated, which accurately points out the target node ID, the specific missed feature samples and the priority label based on the node importance, and provides timely, targeted and reasonably resource-allocated basis for subsequent edge model update.

[0038] S400: According to the edge model update requirement and the center node load state, the edge model hierarchical incremental update instruction is issued.

[0039] Further, according to the priority label of the edge model update requirement, the edge model update requirement is allocated to the corresponding update queue; the priority label includes high priority requirement, medium priority requirement and low priority requirement; the high priority requirement is distributed to the parallel update channel, the medium priority requirement is distributed to the to-be-scheduled queue, and the low priority requirement is distributed to the resource-aware waiting queue.

[0040] Further, the center node resource index is monitored, and if the resource load in the center node resource index exceeds the preset load threshold, the medium priority requirement and the low priority requirement queue task are suspended; a batch compensation task is triggered in the off-peak period, and the nodes that are not updated in time are preferentially processed.

[0041] Specifically, according to the edge model update requirement containing the priority label and the monitored real-time load state (CPU utilization, memory utilization, network bandwidth occupation, etc.) of the center node, the center node issues a hierarchical incremental update instruction, which is generated according to the priority label. The hierarchical incremental update instruction contains priority label (high priority requirement, medium priority requirement and low priority requirement), update window period (such as 30-minute update window for high priority requirement, 1-hour update window for medium priority requirement, and 2-hour update window for low priority requirement), change parameter set (such as edge model feature increment, decision tree structure adjustment parameter, etc.), execution condition (such as time window, network state, etc.), consistency verification instruction (such as feature library hash verification, business rule verification, etc.), digital signature (such as signature algorithm, signature object), etc.

[0042] Further, the update requirements are assigned to corresponding priority queues. High-priority requirements (such as core database intrusion events) are directly entered into the parallel update channel, such as the high-priority model update task quantity limit set to 100 for the support center node to handle at the same time, and the timeout retry number is set to 3 times; medium-priority requirements (such as ordinary service interruption events) are entered into the to-be-scheduled queue, the medium-priority model update task quantity limit set to 50 for the center node to handle at the same time, but when the CPU utilization of the center node is > 80% or the bandwidth occupancy is > 90%, the queue tasks will be suspended; low-priority requirements (such as non-core Internet of Things device abnormalities) are assigned to the resource-aware waiting queue, whose execution is strictly limited, and only when the center CPU utilization is < 40% and the bandwidth is idle, the low-priority model update task quantity limit set to 20 for the support center node to handle at the same time is activated.

[0043] Preferably, the update is executed when the resources allow and the idle condition is met. The center node resource indicators are continuously monitored, and if the load indicators (such as CPU or bandwidth) exceed the preset threshold, the tasks of the medium- and low-priority queues will be suspended immediately, and only the execution of high-priority urgent tasks is guaranteed; after the resource load is continuously sampled for 3 times below the set threshold (CPU utilization < 80% or bandwidth occupancy < 90%), the queue task execution is restored in the order of priority (high-priority requirements -> medium-priority requirements -> low-priority requirements). For low-priority nodes whose update is delayed due to resource limitations, if they do not complete the update for more than 3 hours, the center node generates an "update delay alarm". Batch compensation tasks are automatically triggered during off-peak periods (such as 2:00-5:00) when the center load is below 30%, and these tasks are executed in priority to regular updates; at the same time, these edge nodes in the waiting or delayed state enable the conservative mode (only detecting high-risk threats in the preset attack rule library) to ensure basic security until the update is completed.

[0044] Preferably, the center node outputs the update task report (including compensation task progress, priority label, etc.) and generates the edge-center consistency verification log, which ensures consistency by comparing the inconsistent detection results (such as a false negative rate > 5% triggering an alarm) of the same threats between the edge node lightweight model and the center node model, and records all update delay alarms and compensation results.

[0045] Preferably, the above scheme automatically suspends the medium- and low-priority queue tasks when the resources are tight, and only guarantees the execution of high-priority tasks to avoid center overload. At the same time, the conservative mode is enabled for low-priority nodes whose update is delayed due to resource limitations to ensure basic security. During resource idle or off-peak periods, low-priority queues are automatically activated and batch compensation tasks that have not been updated for a long time are executed in priority. The entire update process relies on hierarchical instructions (including window period, change parameter, execution condition, consistency verification) to ensure reliability and consistency, and the timeliness of key updates is guaranteed.

[0046] S500: When detecting that the edge model incremental update is completed, monitoring the resource flow data of the device, and using a weighted fusion algorithm to calculate a network attack damage degree score.

[0047] Further, the resource flow data of the attacked device is monitored; a weighted sum is performed according to a preset weight coefficient through a weighted fusion algorithm; a time decay function is introduced to calculate the network attack damage degree score.

[0048] Specifically, the dynamic resource flow data of the attacked device is collected through the edge node, including CPU utilization, memory occupation, network bandwidth fluctuation, I / O abnormal frequency, process abnormal number, etc. Through a preset weighted fusion algorithm, a differential weight coefficient table based on historical data is loaded according to the priority label, and the resource anomaly of the core infrastructure is given a higher impact weight, and the non-critical device anomaly is reduced in weight proportion. The multi-dimensional indicators are weighted and aggregated, the weight coefficients are normalized, and the basic score is generated. The basic score calculation formula is as follows:

[0049] Wherein, n is the total number of resource index categories, i is an index variable, represents the i-th resource index value, represents the preset weight of the i-th resource under the current device business type.

[0050] Further, the decay function and dynamic business compensation are introduced on the basis of the basic score to obtain the network attack damage degree score. The calculation formula of the network attack damage degree score is as follows:

[0051] Wherein, represents the attack type decay coefficient (set by historical attack data), represents the attack duration, and C represents the business compensation coefficient (set according to the priority label, the high-priority requirement is 1.5, the medium-priority requirement is 1.2, and the low-priority requirement is 1.0).

[0052] Preferably, the above scheme adopts a weighted fusion algorithm, combines a differential weight coefficient table preset based on the device business type, and performs weighted aggregation on each index to generate a basic score. The time dynamic factor and business impact factor are introduced on the basis of the basic score, and the overall damage degree score that can scientifically reflect the actual impact of the attack on the key business is finally calculated. This makes the score not only based on multi-dimensional real-time indicators, but also considers the differences such as the persistence of the attack.

[0053] S600: Based on the network attack damage degree score, a network attack damage degree evaluation report is generated.

[0054] Further, the network attack damage degree score is mapped to a risk level; the network attack damage degree score, attack type, resource impact peak value, and business interruption index are mapped to corresponding fields of a network attack damage degree assessment report; a repair scheme corresponding to the network attack event is matched according to the risk level, and a visual report containing the risk level and the repair scheme is generated.

[0055] Specifically, the network attack damage degree score is dynamically mapped to a four-level risk level, for example, the network attack damage degree score > 10 is serious (red, core business paralysis level risk), 10 < network attack damage degree score ≤ 6 is high risk (orange, key function damage level risk), 6 < network attack damage degree score ≤ 3 is medium risk (yellow, local impact level risk), and network attack damage degree score < 3 is low risk (green, negligible level risk). The attack type is associated with a depth analysis label, the resource impact peak value extracts the historical maximum value of the CPU / memory / bandwidth index of the attacked device during the attack, and the business interruption index is obtained by the formula (number of attacked devices / business group size) × business impact range.

[0056] Preferably, a preset repair scheme library is matched according to the risk level and the attack type (for example, device isolation + traffic cleaning triggered by a serious level distributed denial of service attack). The risk level is distinguished by color coding, the resource peak value and the threshold value line are displayed by a time sequence line chart, the attack path is restored by a topology graph, and automatic response is executed in conjunction with an alarm system (serious events automatically isolate devices, and high-risk events trigger manual confirmation countdown). All data is synchronized and archived to edge-center consistency verification logs for audit tracking, forming a closed-loop defense chain of monitoring, assessment, and disposal.

[0057] Preferably, the above scheme dynamically maps the calculated network attack damage degree score to an intuitive four-level risk level and is supplemented by color coding. The report integrates key information and automatically matches a preset repair scheme library, directly driving automated response or assisting manual decision-making. The resource peak value and the threshold value are compared by a time sequence line chart, the attack path is restored by a topology graph, and visualization is achieved. All assessment results, response operations, and related logs are archived to edge-center consistency verification logs, ensuring complete audit tracking and achieving full-chain closed-loop defense from monitoring, assessment to disposal.

[0058] The application also provides a network attack damage degree dynamic assessment system for implementing the network attack damage degree dynamic assessment method, which comprises a control module, the control module comprises a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the computer program to implement the network attack damage degree dynamic assessment method.

[0059] The embodiment of the present application provides a storage medium, which stores a program, and the program is executed by a processor to realize the network attack damage degree dynamic evaluation method.

[0060] The embodiment of the present application provides a processor, which is used for running a program, wherein the program is executed to perform the network attack damage degree dynamic evaluation method.

[0061] The embodiment of the present application provides a device, which comprises a processor, a memory, and a program stored in the memory and capable of running on the processor, and the processor performs the program to realize the network attack damage degree dynamic evaluation method. The device herein can be a server, a PC, a PAD, a mobile phone, or the like.

[0062] The present application also provides a computer program product, which is suitable for performing the network attack damage degree dynamic evaluation method when executed on a data processing device.

[0063] Those skilled in the art should understand that the embodiments of the present application can provide methods, systems, or computer program products. Therefore, the present application can adopt a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt a computer program product in the form of being implemented on one or more computer usable storage media containing computer usable program codes (including but not limited to disk storage, CD-ROM, optical storage, etc.).

[0064] The present application is described with reference to flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The means for implementing the functions of one or more flows and / or blocks Figure 1 The means for implementing the functions of one or more flows and / or blocks

[0065] These computer program instructions can also be stored in a computer readable storage medium capable of guiding a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer readable storage medium produce a product including instruction means, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The means for implementing the functions of one or more flows and / or blocks Figure 1 The means for implementing the functions of one or more flows and / or blocks

[0066] These computer program instructions can also be loaded into a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 Figure 1

[0067] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0068] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) about which the processor can execute instructions. The memory can also include non-volatile memory, such as read only memory (ROM), electrically programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), flash memory, or other memory technologies, about which the processor can execute instructions. The memory is an example of computer readable media.

[0069] Computer readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically programmable read only memory (EEPROM), flash memory or other memory technologies, compact disc read only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to computing devices. According to the definition herein, computer readable media does not include transitory media, such as modulated data signals and carrier waves.

[0070] It should also be noted that the terms "comprising", "including", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not include only those elements recited, but can also include other elements not expressly listed or inherent to such process, method, article or apparatus. Without further limitation, an element preceded by "comprises a" does not, without more constraints, foreclose the existence of additional identical elements in the process, method, article or apparatus that includes the element.

[0071] ​​The above merely provides an example of the present application, and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application should be included in the scope of claims of the present application.

Claims

1. A method for dynamically assessing the extent of damage caused by network attacks, characterized in that, include: Resource metric data and threat traffic metadata filtered by the edge model are obtained from edge nodes, and a resource status report is generated. Based on the resource status report, the device grouping polling strategy is dynamically adjusted, and the threat monitoring mode is triggered when any resource indicator exceeds the set threshold multiple times in a row. When in threat monitoring mode, threat identification is performed through collaborative detection, and edge model update requirements are generated. Based on the edge model update requirements and the central node load status, the edge model hierarchical incremental update command is issued; Once the edge model incremental update is detected, the resource flow data of the monitoring device is used to calculate the network attack damage score using a weighted fusion algorithm. Based on the network attack damage severity score, a network attack damage severity assessment report is generated.

2. The method for dynamically assessing the degree of damage caused by network attacks according to claim 1, characterized in that, The process of acquiring resource indicator data from edge nodes and threat traffic metadata filtered through the edge model, and generating a resource status report, includes: Acquire preprocessed resource metrics data from edge nodes and threat traffic metadata filtered by the edge model; The threat traffic metadata is parsed and verified, and resource metrics are aggregated to generate a resource status report.

3. The method for dynamically assessing the degree of damage caused by network attacks according to claim 2, characterized in that, The acquisition of preprocessed resource indicator data from edge nodes and threat traffic metadata filtered through the edge model includes: The monitoring edge nodes perform inference, which includes extracting network traffic features of edge devices, constructing the extracted network traffic features of edge devices into a fixed-dimensional feature vector, and inputting the feature vector into the edge model. The edge model traverses decision tree nodes according to a preset attack rule base. When the feature matches a threat rule, the threat traffic filtering result is output.

4. The method for dynamically assessing the degree of damage caused by network attacks according to claim 1, characterized in that, The step of dynamically adjusting the device grouping polling strategy based on the resource status report, and triggering a threat monitoring mode when any resource indicator exceeds a set threshold multiple times consecutively, includes: Devices are grouped based on a preset initial device grouping polling strategy; The group size is dynamically optimized periodically based on the comprehensive health index within the group of equipment. When the comprehensive health index within the group increases, the number of equipment in the group is increased; when the comprehensive health index within the group decreases, the number of equipment in the group is decreased. While dynamically optimizing the group size, the resource usage indicators of the monitoring device group are monitored. When the resource load of the device group exceeds the preset upper limit threshold in multiple consecutive samplings, the threat monitoring mode is triggered to extend the polling response cycle of the device group.

5. The method for dynamically assessing the degree of damage caused by network attacks according to claim 1, characterized in that, When in threat monitoring mode, the process of performing threat identification through collaborative detection and generating edge model update requirements includes: The received edge-filtered network traffic data list transmitted by edge nodes is subjected to full feature analysis. The effectiveness of the threat is verified by a random forest model, and the threat determination result is output. Sample raw device network traffic data, compare the detection results of the edge model and the center model, and calculate the false negative rate of the edge model; When the false negative rate exceeds the set false negative rate threshold multiple times consecutively, an edge model update request containing the target node ID, false negative feature samples, and priority labels is generated.

6. The method for dynamically assessing the degree of damage caused by network attacks according to claim 1, characterized in that, The step of issuing hierarchical incremental update instructions for the edge model based on the edge model update requirements and the load status of the central node includes: Based on the priority label of the edge model update request, the edge model update request is assigned to the corresponding update queue; The priority labels include high-priority requirements, medium-priority requirements, and low-priority requirements; The high-priority requests are distributed to the parallel update channel, the medium-priority requests are distributed to the scheduling queue, and the low-priority requests are distributed to the resource-aware waiting queue.

7. The method for dynamically assessing the degree of damage caused by network attacks according to claim 1, characterized in that, The step of issuing the edge model hierarchical incremental update instruction based on the edge model update requirements and the central node load status also includes: Monitor the resource indicators of the central node. If the resource load in the central node resource indicators exceeds the preset load threshold, then suspend the medium-priority and low-priority demand queue tasks. During off-peak hours, trigger batch compensation tasks and prioritize processing nodes that have not been updated due to timeout.

8. The method for dynamically assessing the degree of damage caused by network attacks according to claim 1, characterized in that, Once the edge model incremental update is detected, the resource flow data of the monitoring device is used to calculate the network attack damage severity score using a weighted fusion algorithm, including: Monitor the resource flow data of the attacked device; The weighted fusion algorithm is used to perform weighted summation according to preset weight coefficients; A time decay function is introduced to calculate the score of the damage caused by a network attack.

9. The method for dynamically assessing the degree of damage caused by network attacks according to claim 1, characterized in that, The process of generating a network attack damage assessment report based on the network attack damage severity score includes: Map the severity of cyberattacks to risk levels; Map the network attack damage score, attack type, peak resource impact, and service interruption index to the corresponding fields in the network attack damage assessment report; Match the remediation plan to the network attack incident based on the risk level, and generate a visual report that includes the risk level and the remediation plan.

10. A dynamic assessment system for the degree of damage caused by network attacks, characterized in that, The system includes a control module, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the dynamic assessment method for the degree of damage caused by network attacks according to any one of claims 1-9.