Double-graph fusion network security regulation and control method, apparatus and device, and medium

By constructing anomaly behavior graphs and operation and maintenance topology graphs, generating node mapping relationship tables, and using dynamic Bayesian networks for anomaly propagation analysis, the problem of low accuracy in existing network security protection technologies is solved, achieving accuracy, timeliness, and effectiveness in network security protection and response.

CN120934870APending Publication Date: 2025-11-11CHINA PING AN PROPERTY INSURANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511210091.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing network security protection technologies suffer from problems such as inconsistent representation of anomalies and assets, reliance on a large number of labeled samples, and implicit association reasoning processes. These issues result in poor generalization ability, difficulty in adapting to complex network environments, inability to effectively utilize the correlation between abnormal behavior and business assets, and low accuracy.

Method used

By acquiring multi-source heterogeneous data, anomaly behavior graphs and operation and maintenance topology graphs are constructed, node mapping relationship tables are generated, anomaly propagation analysis is performed using dynamic Bayesian networks, hierarchical response strategies are generated, and the anomaly behavior graphs, operation and maintenance topology graphs, business impact data, and business status feedback data are merged and rendered into a network security situation map to execute network protection and control operations.

Benefits of technology

It enables precise binding of security incidents to network assets, improving the accuracy of network security protection and the timeliness and effectiveness of response, ensuring that analysis results are closely related to core business, dynamically optimizing response measures, and enhancing the intuitiveness of security decisions and the accuracy of operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934870A_ABST
    Figure CN120934870A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent decision making, can be applied to business system platforms of financial science and technology, medical health and the like, and discloses a double-graph fused network security regulation and control method, device and equipment and a medium, and the method comprises the following steps: constructing an abnormal behavior graph and an operation and maintenance topological graph based on multi-source heterogeneous data; performing association matching on the abnormal behavior nodes and asset nodes to generate a node mapping relation table; constructing a dynamic Bayesian network according to the node mapping relation table, and performing abnormal diffusion analysis on the associated nodes by using the dynamic Bayesian network to obtain service influence data; generating a hierarchical response strategy based on the service influence data, and obtaining service state feedback data in an execution process of the hierarchical response strategy; and fusing and rendering the abnormal behavior graph, the operation and maintenance topological graph, the service influence data and the service state feedback data into a network security situation graph, and executing network protection regulation and control operation on the target network by utilizing a regulation and control instruction. The accuracy of network security protection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent decision-making technology, and in particular to a network security control method, apparatus, device, and medium for dual-graph fusion. Background Technology

[0002] Network security protection is a system that uses static rules or single-dimensional threat detection technology to independently analyze abnormal logs and network device status in order to monitor and protect network security status. It can identify abnormal behaviors in the network and take corresponding protective measures for the identified situations.

[0003] In the healthcare field, network security protection systems monitor access logs of the electronic medical record system on the hospital's intranet using preset static rules. When an unauthorized IP address attempts to log in, the system triggers account locking protection measures.

[0004] In the fintech business, the cybersecurity protection system uses single-dimensional threat detection technology to screen online banking transaction logs. When it finds that the transaction amount or location does not match the user's historical habits, it initiates the SMS verification protection process. At the same time, it separately analyzes the access records of the core database and issues alerts for operations that frequently query sensitive information.

[0005] In summary, while existing network security protection technologies have made progress, they still suffer from problems such as inconsistent representation of anomalies and assets, reliance on a large number of labeled samples, and implicit association reasoning processes. These issues result in poor generalization capabilities, making it difficult to adapt to complex network environments and unable to effectively utilize the correlation between abnormal behavior and business assets.

[0006] Therefore, improving the accuracy of cybersecurity protection has become an urgent problem to be solved. Summary of the Invention

[0007] This invention provides a network security control method, apparatus, device, and medium based on dual-image fusion to solve the technical problem of low accuracy in network security protection.

[0008] Firstly, a network security control method based on dual-graph fusion is provided, including: Acquire multi-source heterogeneous data in the target network, and construct an abnormal behavior graph and operation and maintenance topology graph of the target network based on the multi-source heterogeneous data; The abnormal behavior nodes in the abnormal behavior graph are associated and matched with the asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network. Based on the node mapping relationship table, a dynamic Bayesian network of associated nodes in the target service is constructed, and the dynamic Bayesian network is used to perform anomaly diffusion analysis on the associated nodes of the target service in the node mapping relationship table to obtain the business impact data corresponding to the target service. Based on the business impact data, a tiered response strategy for the target business is generated, and business status feedback data is obtained during the execution of the tiered response strategy. The abnormal behavior graph, the operation and maintenance topology graph, the service impact data, and the service status feedback data are merged and rendered into a network security situation map. The control instructions in the network security situation map are used to perform network protection control operations on the target network.

[0009] Secondly, a network security control device with dual-graph fusion is provided, comprising: The dual-graph construction module is used to acquire multi-source heterogeneous data in the target network and construct an abnormal behavior graph and an operation and maintenance topology graph of the target network based on the multi-source heterogeneous data. The node mapping relationship generation module is used to associate and match the abnormal behavior nodes in the abnormal behavior graph with the asset nodes in the operation and maintenance topology graph to generate a node mapping relationship table in the target network. The business impact data analysis module is used to construct a dynamic Bayesian network of related nodes in the target business based on the node mapping relationship table, and to use the dynamic Bayesian network to perform anomaly diffusion analysis on the related nodes of the target business in the node mapping relationship table to obtain the business impact data corresponding to the target business. The business status feedback data acquisition module is used to generate a hierarchical response strategy for the target business based on the business impact data, and to acquire business status feedback data during the execution of the hierarchical response strategy. The network security situation map control module is used to fuse and render the abnormal behavior map, the operation and maintenance topology map, the service impact data, and the service status feedback data into a network security situation map, and to perform network protection control operations on the target network using the control instructions in the network security situation map.

[0010] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the aforementioned dual-graph fusion network security control method.

[0011] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the aforementioned dual-graph fusion network security control method.

[0012] In the aforementioned scheme implemented by the dual-graph fusion network security control method, device, equipment, and medium, multi-source heterogeneous data in the target network can be obtained through a client. An abnormal behavior graph and an operation and maintenance topology graph of the target network are constructed based on this data. Abnormal behavior nodes in the abnormal behavior graph are associated and matched with asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network. A dynamic Bayesian network of associated nodes in the target service is constructed based on the node mapping table, and the dynamic Bayesian network is used to perform abnormal diffusion analysis on the associated nodes of the target service in the node mapping table to obtain service impact data corresponding to the target service. A tiered response strategy for the target service is generated based on the service impact data, and service status feedback data is obtained during the execution of the tiered response strategy. The abnormal behavior graph, the operation and maintenance topology graph, the service impact data, and the service status feedback data are fused and rendered into a network security situation map. Control commands in the network security situation map are used to perform network protection control operations on the target network. The results of the control operations are fed back to the client. In this invention, by acquiring multi-source heterogeneous data and constructing anomaly behavior graphs and operation and maintenance topology graphs, the security status and operational architecture of the target network can be comprehensively captured. A mapping relationship table is generated by associating anomaly behavior nodes with asset nodes, realizing the precise binding of security events and network assets. Based on this table, a dynamic Bayesian network is constructed and anomaly propagation analysis is performed focusing on target business-related nodes. The degree of business impact can be assessed in a targeted manner, ensuring that the analysis results are closely related to the core business. Based on the business impact data, a graded response strategy is generated and combined with status feedback data, which can dynamically optimize the response measures and improve the timeliness and effectiveness of the response. Finally, multiple types of data are integrated to render a network security situation map and execute protection and control, making security decisions more intuitive and operations more precise, thus improving the accuracy of network security protection. Attached Figure Description

[0013] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0014] Figure 1 This is a schematic diagram of an application environment for a network security control method based on dual-image fusion in one embodiment of the present invention; Figure 2 This is a flowchart illustrating a network security control method based on dual-image fusion in one embodiment of the present invention; Figure 3 yes Figure 2 A flowchart illustrating a specific implementation method of step S2; Figure 4 yes Figure 2 A flowchart illustrating a specific implementation of step S4; Figure 5 This is a schematic diagram of a network security control device with dual-image fusion in one embodiment of the present invention; Figure 6 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 7 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation

[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0016] The dual-image fusion network security control method provided in this invention can be applied to, for example... Figure 1In this application environment, the client communicates with the server via a network. The server can obtain multi-source heterogeneous data from the target network through the client, and construct an abnormal behavior graph and an operation and maintenance topology graph of the target network based on the multi-source heterogeneous data; it associates and matches the abnormal behavior nodes in the abnormal behavior graph with the asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network; it constructs a dynamic Bayesian network of associated nodes in the target service based on the node mapping table, and uses the dynamic Bayesian network to perform anomaly diffusion analysis on the associated nodes of the target service in the node mapping table to obtain the service impact data corresponding to the target service; it generates a hierarchical response strategy for the target service based on the service impact data, and obtains service status feedback data during the execution of the hierarchical response strategy; it merges and renders the abnormal behavior graph, the operation and maintenance topology graph, the service impact data, and the service status feedback data into a network security situation map, and uses the control instructions in the network security situation map to perform network protection control operations on the target network. The results of the control operations are fed back to the client. In this invention, by acquiring multi-source heterogeneous data and constructing anomaly behavior graphs and operation and maintenance topology graphs, the security status and operational architecture of the target network can be comprehensively captured. A mapping table is generated by associating anomaly behavior nodes with asset nodes, achieving precise binding of security events and network assets. Based on this table, a dynamic Bayesian network is constructed, focusing on target business-related nodes for anomaly propagation analysis. This allows for targeted assessment of the degree of business impact, ensuring that the analysis results are closely related to the core business. Based on the business impact data, a tiered response strategy is generated, and combined with status feedback data, dynamic optimization of response measures can be achieved, improving the timeliness and effectiveness of the response. Finally, multiple types of data are integrated to render a network security situation map and execute protection and control measures, making security decisions more intuitive and operations more precise, thus improving the accuracy of network security protection. The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster composed of multiple servers. The invention will be described in detail below through specific embodiments.

[0017] Please see Figure 2 As shown, Figure 2 A flowchart illustrating the dual-graph fusion network security control method provided in this embodiment of the invention includes the following steps: S1. Obtain multi-source heterogeneous data in the target network, and construct an abnormal behavior diagram and operation and maintenance topology diagram of the target network based on the multi-source heterogeneous data.

[0018] In this embodiment of the invention, the multi-source heterogeneous data refers to a collection of data from different sources with diverse formats and structures. These data have significant differences in terms of type, storage method, and collection frequency, such as security device logs (firewall logs), terminal event records (terminal protection events), asset management system information (IT asset management system), and network scan logs.

[0019] In detail, a lightweight data collection agent is deployed at key network nodes of the target network to capture network traffic data through traffic mirroring. It also aggregates security device logs such as firewall logs and endpoint protection event logs with a log forwarding mechanism, and obtains asset management system information by connecting to the IT asset management system via API.

[0020] In this embodiment of the invention, the abnormal behavior graph is a graph structure used to describe network security attack behavior. It consists of attack entities (such as IP addresses, vulnerabilities, and attack tools) and their interrelationships (such as scanning, attack, and penetration). The nodes and edges quantify the attributes of the attack behavior through features such as attack strength, timestamp, and attack path probability.

[0021] In this embodiment of the invention, the operation and maintenance topology diagram is a graph structure that describes the system operation and maintenance architecture. It includes operation and maintenance entities (such as servers, switches, and applications) and their interrelationships (such as dependencies, communication, and hosting). The system's operating status and the relationships between components are reflected through node attributes (such as asset level and service status) and edge attributes (such as traffic baseline and dependency strength).

[0022] In this embodiment of the invention, the construction of the abnormal behavior graph and operation and maintenance topology graph of the target network based on the multi-source heterogeneous data includes: Data cleaning is performed on the multi-source heterogeneous data to obtain standard data in the target network; Anomaly windows are aggregated from the security device logs and terminal event records in the standard data to obtain anomaly event sequences in the target network. The abnormal event sequence is identified based on a preset state machine model to obtain an initial abnormal behavior graph in the target network; By performing topological association between the asset management system information and network scan logs in the standard data, an initial operation and maintenance topology map of the target network is obtained. The initial abnormal behavior graph and the initial operation and maintenance topology graph are transformed to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network.

[0023] In detail, the system traverses multi-source heterogeneous data sources, including firewall logs, endpoint protection events, and IT asset management system data. It identifies and filters content that clearly does not conform to normal network data formats. For time fields, it converts different time information formats to a standard format using string processing functions, based on a unified timestamp format. For network identification data such as IP addresses and port numbers, it uses network data verification algorithms to check whether they conform to the standardized network address format, correcting any non-standard expressions caused by input errors or transmission errors. Finally, it outputs standard data that conforms to the target network data specifications and can be used for subsequent processing.

[0024] Specifically, security device logs (such as attack IPs and ports recorded by firewalls) and terminal event records (such as vulnerability exploitation events reported by terminals) are extracted from standard data. These records are aggregated according to a preset 5-minute sliding window. Alarm events related to the same attack source within the same time window are grouped together to form a sequence of attack-related abnormal events.

[0025] For example, in the fintech field, by aggregating malicious IP access blocked by firewalls and vulnerability exploitation events detected by terminal EDR, an abnormal event sequence targeting the core trading system is generated, APT attack chains are identified in real time, and automatic fund flow monitoring and account freezing are triggered.

[0026] For example, in the fintech field, banks use a 5-minute window to aggregate multiple port scan logs of the same attacking IP against the online banking system and abnormal login events reported by the terminal, forming an abnormal sequence targeting the payment system and quickly intercepting fraudulent transactions.

[0027] For example, in the healthcare field, based on the illegal medical device connection requests blocked by the firewall and the medical data leakage events reported by the terminal, an attack sequence targeting medical IoT devices is generated, the ransomware propagation path is quickly located, and infected devices are isolated in conjunction to ensure patient data security.

[0028] The state machine model is a set of preset logical frameworks used to describe the laws governing changes in system states. It defines the judgment conditions for different attack stages (such as scanning, vulnerability exploitation, and other behavioral characteristics) and the transition rules between states (such as entering the intrusion stage if vulnerability exploitation occurs after scanning). It achieves modeling and detection of the evolution process of abnormal behavior by standardizing the identification process of event sequences.

[0029] Next, the sequence of abnormal events is traversed chronologically, extracting the time, source IP, target asset, and behavior type for each record. The first event matching the "initial attack" condition (such as port scanning) is marked as the starting point, the source IP is set as the attacker node, and the target asset is set as the first victim node. The state machine strategy is used to determine whether subsequent events meet the stage transition conditions (e.g., cross-device access after intrusion is considered lateral movement). If they do, a new victim node is added, and the relevant nodes are connected with edges containing attack type and timestamp. After the traversal is complete, all nodes (including IP and service type attributes) and edges (including attack type and timestamp attributes) are integrated to generate the initial abnormal behavior graph of the target network.

[0030] Furthermore, asset management system information (asset ID, type, etc.) and network scan logs (active ports, protocols, etc.) are extracted from standard data. A mapping table with asset ID as the unique identifier is established to associate two types of data of the same asset. An adjacency table is constructed according to network connection relationship to record connection information such as protocols and ports between devices to determine the dependency relationship. Then, with assets as nodes (including metadata such as type and IP) and connection relationship as edges (including attributes such as protocol and traffic), an initial operation and maintenance topology diagram of the target network containing all asset nodes and connection relationships is generated.

[0031] In this embodiment of the invention, the step of performing data transformation on the initial abnormal behavior graph and the initial operation and maintenance topology graph to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network includes: The node and edge attributes in the initial abnormal behavior graph and the initial operation and maintenance topology graph are standardized in format to obtain the updated node and updated edge attributes. Extract the topological features of the updated node and the updated edge attributes, and aggregate the topological features into a feature set; Based on the feature set, calculate the node similarity and edge class consistency of the updated node and the updated edge attributes, respectively; Based on the node similarity and the edge class consistency, the updated node and the updated edge attributes are merged to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network.

[0032] In detail, node attributes (such as IP and device type) and edge attributes (such as protocol and access time) are extracted from the initial abnormal behavior graph and the initial operation and maintenance topology graph. A predefined format conversion script is called to unify IPs of different formats into the format "xxx.xxx.xxx.xxx" through operations such as string truncation and regular expression matching. Protocol names such as "TCP" and "Transmission Control Protocol" are uniformly mapped to "TCP". After removing redundant fields, standardized updated nodes and updated edge attributes with consistent attribute field names and formats are output.

[0033] Next, the standardized update nodes and edge attributes are traversed to extract node topology features, read attributes such as IP and port, count the number of edges connected to each node (in-degree / out-degree), and record information such as the network segment to which the node belongs. For edge attributes, protocol type, access frequency, and connection duration are extracted. These features are then categorized and organized by node ID and edge identifier, and stored in an array as key-value pairs (e.g., node ID → [IP, in-degree, network segment], edge identifier → [protocol, frequency, duration]), forming a set containing node and edge topology features.

[0034] Specifically, for node features in the feature set (such as IP network segment, service type, in-degree / out-degree), a node similarity score is obtained through string comparison (such as determining whether the IPs are in the same network segment) and numerical difference calculation (such as in-degree difference rate); for edge features (such as protocol, port, access frequency range), edge class consistency (yes / no) is obtained through complete matching (if the protocol and port are the same, they are determined to be of the same type) and threshold judgment (if the frequency is in the same range).

[0035] Furthermore, based on a preset threshold (e.g., node similarity ≥ 0.8), similar nodes are merged into a single master node, retaining core attributes (e.g., master IP, device type) and integrating associated edges; for edges determined to be of the same type, duplicate connections are merged, and feature values ​​such as access frequency are accumulated; by adjusting the graph structure and deleting redundant nodes and edges, a concise and accurate target network abnormal behavior graph and operation and maintenance topology graph are finally generated.

[0036] In this embodiment of the invention, by fusing multi-source heterogeneous data to construct a dual-graph model, the attack path (abnormal behavior graph) and asset dependency relationship (operation and maintenance topology graph) can be accurately restored, thereby enhancing the comprehensiveness and response speed of network defense.

[0037] S2. Associate and match the abnormal behavior nodes in the abnormal behavior graph with the asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network.

[0038] In this embodiment of the invention, the node mapping relationship table is a two-dimensional data table that stores the association between abnormal behavior nodes and asset nodes in a structured manner. Its fields include: abnormal behavior node ID, asset node ID, time alignment status, topology path details, and metadata such as timestamp and data source.

[0039] In the embodiments of the present invention, see Figure 3 As shown, the step of associating and matching abnormal behavior nodes in the abnormal behavior graph with asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network includes: S31. By using a sliding time window, the timestamps of the abnormal behavior nodes in the abnormal behavior graph and the asset nodes in the operation and maintenance topology graph are time-aligned to obtain the first node pair of time synchronization. S32. Perform topological connectivity verification on the first node pair to obtain the topological connectivity verification result, and generate a topologically connected second node pair based on the topological connectivity verification result; S33. Calculate the association confidence of the second node pair; S34. Summarize the first node pair, the second node pair, and the association confidence into a node mapping relationship table.

[0040] In detail, by using a preset sliding time window size (e.g., 5 minutes), the timestamp set of abnormal behavior nodes in the abnormal behavior graph and the timestamp set of asset nodes in the operation and maintenance topology graph are traversed. For each abnormal behavior node's timestamp t1, all records in the asset node's timestamp t2 that satisfy t1 - window size ≤ t2 ≤ t1 + window size are retrieved. Abnormal behavior nodes and asset nodes falling within this time interval are paired to form candidate node pairs. After deduplication, the first set of time-synchronized node pairs is finally generated.

[0041] Specifically, the network connection relationships of all asset nodes are extracted from the operation and maintenance topology diagram to construct topology data containing node and link information. For each abnormal behavior node and asset node in the first node pair, based on the topology data, the transmission process of data packets from the network location corresponding to the abnormal behavior node to the asset node is simulated. It is checked whether there is a complete path connected by network devices (switches, routers, etc.) that conforms to network access rules to determine whether the two are connected. Abnormal behavior nodes and asset nodes that pass the connectivity check are combined to form a new node pair. After summarizing, a second set of node pairs that can be associated with the topology is obtained.

[0042] Furthermore, for each abnormal behavior node and asset node in the second node pair, the association confidence score is calculated according to preset rules: the smaller the timestamp alignment deviation (e.g., deviation ≤ 1 minute, 0.4 points), the fewer the number of path hops (e.g., hops ≤ 2, 0.4 points), and the more successful historical associations (e.g., ≥ 3 times, 0.2 points). The sum of the three scores is the association confidence score of the node pair (maximum score 1 point).

[0043] Next, a structured table is created, in which the time synchronization record of the first node pair, the topology reachability identifier of the second node pair (such as "yes" or "no"), and the corresponding association confidence value are entered in sequence. By deduplicating and retaining high confidence records, a node mapping relationship table containing fields such as abnormal behavior node ID, asset node ID, time alignment deviation, path hop count, and association confidence is finally generated.

[0044] In this embodiment of the invention, the abnormal behavior nodes in the abnormal behavior graph are associated and matched with the asset nodes in the operation and maintenance topology graph to generate a node mapping relationship table. This can connect security events with physical assets, clarify the specific devices or services corresponding to abnormal events, and provide accurate basis for locating the source of threats and assessing the scope of impact.

[0045] For example, in the fintech field, banks use this table to associate abnormal transaction IPs with core transaction servers, quickly identifying and blocking attacked payment nodes.

[0046] For example, in the healthcare field, hospitals can promptly detect compromised doctor workstations by matching abnormal access records of the medical record system with terminal devices in order to protect patient data.

[0047] S3. Construct a dynamic Bayesian network of associated nodes in the target service based on the node mapping relationship table, and use the dynamic Bayesian network to perform anomaly diffusion analysis on the associated nodes of the target service in the node mapping relationship table to obtain the service impact data corresponding to the target service.

[0048] In this embodiment of the invention, the dynamic Bayesian network is a probabilistic graphical model consisting of nodes representing IT assets with attributes such as vulnerability scores and service criticality, as well as nodes observing abnormal events, and attack propagation paths (directed edges) whose edge weights are dynamically calculated based on operational topology dependencies and path confidence.

[0049] In this embodiment of the invention, constructing a dynamic Bayesian network of associated nodes in the target service based on the node mapping relationship table includes: Map the abnormal behavior nodes and asset nodes corresponding to the associated nodes in the node mapping table to observation nodes and status nodes, respectively. Directed edges are constructed based on the dependencies in the aforementioned operation and maintenance topology graph; The edge weights of the directed edges are calculated based on the path characteristics in the node mapping table. A dynamic Bayesian network of associated nodes in the target service is constructed based on the observation nodes, the state nodes, the directed edges, and the edge weights.

[0050] In detail, the node mapping table is traversed to extract the feature information of nodes with abnormal behavior (such as attack type, trigger time, source IP, etc.), and a unique identifier is assigned to each node with abnormal behavior and marked as an observation node. At the same time, the attribute information of asset nodes (such as device type, business unit to which they belong, IP address, etc.) is extracted, and a unique identifier is assigned to each asset node and marked as a status node.

[0051] Next, the operation and maintenance topology diagram is analyzed to extract information such as service dependencies and data flow between asset nodes. For each pair of asset nodes with dependencies, if the operation of asset node X depends on the services or data provided by asset node Y, a directed edge is created from Y to X. Simultaneously, based on the association between abnormal behavior nodes and asset nodes in the node mapping table, if an abnormal behavior node can affect an asset node through a specific path, a directed edge will also be constructed between the corresponding associated asset nodes.

[0052] Specifically, when calculating the edge weight of a directed edge based on the node mapping table, path-related features are extracted from the table, such as the vulnerability score of asset nodes on the path (read from the recorded vulnerability assessment value in the corresponding storage location), service criticality (obtained based on the criticality indicator according to business configuration information), and attack frequency associated with nodes exhibiting abnormal behavior. Then, according to a pre-defined calculation formula, edge weight = α * vulnerability score + β * service criticality + γ * attack frequency, where α, β, and γ are coefficients adjusted according to the actual scenario. These parameters are typically taken as (α = 0.6, β = 0.8, γ = 0.5). By calling arithmetic operation instructions, the extracted feature data is substituted into the rules for numerical calculation, and the calculated result is assigned to the weight attribute of the corresponding directed edge to obtain the corresponding edge weight.

[0053] Furthermore, a dynamic Bayesian network model framework is created. Labeled observation nodes and state nodes are imported into the model using unique identifiers and allocated storage locations. Based on the constructed list of directed edges, a pointing relationship is established for each pair of nodes with dependencies in the model. The quantized edge weights are associated with the corresponding directed edges as probabilistic parameters for the influence of node states. Finally, a time-slice update mechanism is set for the network (e.g., updating node states every 5 minutes). Nodes, directed edges, weights, and time update rules are integrated into a runnable probabilistic graphical model, thus completing the construction of the dynamic Bayesian network.

[0054] In this embodiment of the invention, the business impact data is a set of quantitative indicators that are structured records of the impact of network security incidents on the target business system, including the following core fields: business unit name (such as "payment gateway"), interruption anomaly, affected business unit, cost of handling action, and path confidence.

[0055] In this embodiment of the invention, the abnormal diffusion analysis of the associated nodes of the target service in the node mapping table is performed using the dynamic Bayesian network to obtain the service impact data corresponding to the target service, including: Obtain the asset dependency list of the target business system, and establish an association table between the business units in the asset dependency list and the asset nodes in the node mapping relationship table based on the asset dependency list; The anomaly probability of associated nodes in the node mapping table is calculated using the forward propagation algorithm in the dynamic Bayesian network. Calculate the business impact score of the target business based on the service criticality weights in the association table and the anomaly probability; Obtain a historical case library of business interruptions, and map the business impact score to business impact data based on the case library.

[0056] In detail, the asset dependency list is obtained from the configuration management database of the target business system. This list contains asset information such as business units (e.g., payment module, login module) and their dependent hardware devices and software services.

[0057] Next, extract the asset identifier (such as device IP, service name) corresponding to each business unit in the list and match it with the asset node identifier in the node mapping table (such as by precise comparison through IP address or device unique number). For successfully matched business units and asset nodes, create an association table containing business unit ID, business unit name, corresponding asset node ID, asset type and dependency description.

[0058] Specifically, the system uses a pre-set monitoring program to scan the state changes of observation nodes in the dynamic Bayesian network in real time. When an observation node (corresponding to an abnormal behavior node) triggers an alarm (such as detecting an attack), the forward propagation algorithm is immediately started. Starting from the alarming observation node, the algorithm transmits the abnormal state to the associated state nodes (corresponding to asset nodes) according to the direction and weight of the directed edges in the network. Specifically, the abnormal probability value of each associated node is updated sequentially by calculating "current node abnormal probability = previous node abnormal probability × edge weight + its own basic abnormal probability". After each round of calculation, the abnormal probability field of the corresponding asset node in the node mapping table is updated to the latest value, realizing the dynamic calculation and synchronization of the abnormal probability of associated nodes.

[0059] Next, the association table is traversed to extract the service criticality weights (e.g., core assets are weighted at 0.8, and non-core assets at 0.3) and the anomaly probabilities (values ​​between 0 and 1) obtained through the forward propagation algorithm for each business unit's associated asset nodes. For each business unit, the impact score of all associated asset nodes is calculated using the formula "single asset impact score = service criticality weight × anomaly probability". These scores are then summed to obtain the total impact score for the business unit. Finally, the total impact score is normalized to the range of 0-100 (e.g., the business unit with the highest total score corresponds to 100 points, and others are proportionally converted), and this score is used as the business impact score for that business unit. This completes the calculation from service criticality weights and anomaly probabilities to the business impact score.

[0060] Furthermore, a historical business interruption case library is retrieved through a database query interface. This case library contains records linking historical business impact scores with corresponding business interruption duration, economic losses, and the number of affected users. The historical scores in the case library are divided into intervals (e.g., 0-30 points for low impact, 31-70 points for medium impact, and 71-100 points for high impact), and the average value of various business impact data within each interval is calculated (e.g., the average interruption duration in the high impact interval is 2 hours, and the average loss is 500,000 yuan). The current business impact score is assigned to the corresponding interval, and the average data of that interval is directly used as the base value. Then, it is fine-tuned according to the similarity between the current business and the business type of historical cases (e.g., the similarity of financial transaction business is set to 1.0, and other types are adjusted proportionally). Finally, business impact data containing information such as interruption duration, economic losses, and the scope of impact is generated.

[0061] In this embodiment of the invention, by constructing node mapping relationships through a dynamic Bayesian network and performing anomaly propagation analysis, the probability of anomalies propagating between network nodes can be dynamically quantified, and the scope and extent of the impact can be accurately predicted.

[0062] For example, in the fintech field, banks use this network to analyze the propagation path of abnormal transaction nodes, identify the probability of core payment systems being affected in advance, and reduce abnormal fund losses.

[0063] For example, in the healthcare field, hospitals use their tracking systems to detect abnormal transmissions of medical records, quickly assess the impact on their medical services, and ensure patient data security and service continuity.

[0064] S4. Generate a tiered response strategy for the target business based on the business impact data, and obtain business status feedback data during the execution of the tiered response strategy.

[0065] In this embodiment of the invention, the business status feedback data is a set of structured indicators that record the execution effect of the hierarchical response strategy, including strategy trigger time, type of execution action (such as blocking, rate limiting, repair), completion status of each action (success / failure), attack blocking rate (number of blocked attack packets / total number of attack packets), false alarm rate (number of normal traffic blocked / total number of blocked traffic), changes in business indicators (such as transaction success rate, response time, system load), business interruption duration, and number of user complaints.

[0066] In the embodiments of the present invention, see Figure 4 As shown, the hierarchical response strategy for generating target services based on the business impact data includes: S41. Construct an anomaly scoring matrix for the target service based on the path confidence, service impact unit, and interruption anomaly in the service impact data. S42. Identify the basic response actions corresponding to the rating levels of the business impact units in the anomaly rating matrix; S43. Identify the dependencies between the business-influencing units, and adjust the basic response actions according to the dependencies to obtain a set of linked response actions for the target business; S44. Arrange the set of linked response actions according to the preset time sequence and operation priority to obtain the hierarchical response strategy of the target service.

[0067] In detail, path confidence (a value between 0 and 1), criticality weight of business impact units (e.g., core business 0.8, non-core 0.3) and interruption outliers (0-100 points mapped by historical cases) are extracted from the business impact data, and these three indicators are used as the row dimensions of the matrix.

[0068] Next, using the affected business units as column dimensions, an empty matrix is ​​created. Then, for each business unit, a score is calculated using the formula: "Anomaly Score = Path Confidence × 0.4 + Business Unit Criticality Weight × 0.3 + Interruption Anomaly Value / 100 × 0.3" (normalized to 0-1), and the result is filled into the corresponding position in the matrix. Finally, all scores in the matrix are divided into three levels—low, medium, and high—with thresholds of 0.3 and 0.6, and labeled in the corresponding cells, completing the construction of the anomaly score matrix.

[0069] Specifically, a preset policy rule base is invoked, which stores the correspondence between the rating levels of the anomaly rating matrix and the response policies (e.g., low level corresponds to "continuous monitoring + logging", medium level corresponds to "traffic limiting + vulnerability scanning", and high level corresponds to "emergency blocking + business switching"). The anomaly rating matrix is ​​traversed to identify the rating level corresponding to each business unit, and the basic response action is matched according to the rule base.

[0070] Next, the dependencies between business units are checked (e.g., if A depends on B, then they need to be handled in conjunction). Response actions for related business units are merged (e.g., if B is at a high level, A, even if at a medium level, is upgraded to a high-level strategy). Finally, the action sequence is organized according to time order (immediate execution, execution within 10 minutes) and operation priority (blocking > rate limiting > scanning), generating a hierarchical response strategy that includes the execution object, action type, triggering condition, and completion time limit, and stored in the strategy execution queue.

[0071] Furthermore, monitoring points are deployed at each stage of the tiered response strategy execution. Network probes are used to capture the operation logs of the strategy execution objects (such as servers and switches) in real time (recording the execution time and results of blocking, rate limiting, and other actions). Performance monitoring tools are used to collect business metrics (such as transaction success rate, response time, and CPU utilization). At the same time, log analysis tools are used to statistically analyze changes in attack events (such as the number of attack packets and the frequency of alarms).

[0072] Next, these data are linked to the corresponding response strategy steps by timestamp, and organized into structured records in the format of "Execution Action ID + Business Unit Name + Metric Name + Value + Collection Time," which are then stored in the feedback database. Newly collected data is aggregated every preset time interval (e.g., 1 minute), and the difference in metrics before and after strategy execution (e.g., the percentage decrease in attack packets after blocking) is calculated, forming business status feedback data that includes the effectiveness of the action and the degree of business impact.

[0073] In this embodiment of the invention, generating a graded response strategy based on business impact data can achieve a precise balance between anomalies and handling costs, while business status feedback data verifies the effectiveness of the strategy and continuously optimizes the response mechanism through quantitative indicators (blockage rate, business recovery time, etc.), forming a closed loop of security protection.

[0074] For example, in the fintech field, a tiered strategy is generated for anomalies in high-frequency trading systems based on business impact data. The strategy is then optimized by feedback on attack blocking rate, false alarm rate, etc., to intercept attacks and control the duration of trading interruptions.

[0075] For example, in the healthcare field, hospitals develop tiered responses to system anomalies based on business impact data, and adjust strategies in conjunction with feedback on treatment response time, registration success rate, etc., to ensure the continuous operation of outpatient services while blocking attacks.

[0076] S5. The abnormal behavior diagram, the operation and maintenance topology diagram, the service impact data, and the service status feedback data are merged and rendered into a network security situation diagram. The control instructions in the network security situation diagram are used to perform network protection control operations on the target network.

[0077] In this embodiment of the invention, the network security situation map is a comprehensive view that uses visualization technology to integrate and render abnormal nodes in the abnormal behavior map, asset connection relationships in the operation and maintenance topology map, the degree of impact in the business impact data, and the policy execution effect in the business status feedback data. It graphically and intuitively displays the target network security status, abnormal propagation path, business abnormality level, and protection policy effect, and includes control commands that can trigger network protection control operations.

[0078] For example, in the fintech field, a bank's cybersecurity situational awareness map integrates abnormal transaction nodes, payment system topology connections, the impact level of core businesses, and the effectiveness of blocking strategies. It uses dynamic graphics to intuitively display the spread path of transfer attacks and the interception rate of risk control strategies, and operations and maintenance personnel can directly trigger suspicious IP blocking commands.

[0079] For example, in the healthcare field, a hospital's situational awareness map integrates abnormal access nodes of the medical record system, system topology, abnormal levels of patient data leakage, and the effectiveness of rate limiting strategies. It graphically presents the attack spread trajectory and protection effects, enabling medical staff to quickly trigger terminal isolation and control to ensure the security of medical data and the continuity of services.

[0080] In this embodiment of the invention, the step of fusing and rendering the abnormal behavior graph, the operation and maintenance topology graph, the business impact data, and the business status feedback data into a network security situation graph includes: Render the abnormal paths in the abnormal behavior graph as dynamic abnormal trajectories on a time axis. The asset nodes in the operation and maintenance topology diagram are overlaid with the dynamic anomaly trajectory of the time axis by color to obtain the updated dynamic anomaly trajectory of the time axis. The business impact data and the business status feedback data are labeled onto the asset nodes in the dynamic anomaly trajectory of the update time axis to obtain a network security situation map.

[0081] In detail, the node sequence of the abnormal path (e.g., "Node A → Node B → Node C") and features such as timestamps and anomaly types (e.g., scanning, intrusion, data theft) for each stage are extracted from the abnormal behavior graph. A timeline is created with time as the horizontal axis, and the occurrence time of each abnormal node is marked on the axis in chronological order of timestamps. Different colored lines (e.g., red for intrusion, yellow for scanning) are used to connect the nodes to form the path trajectory. At the same time, stage characteristics (e.g., "10:05 Node A initiates port scan" "10:12 Node B detects intrusion behavior") are marked next to the trajectory. The anomaly propagation process is dynamically demonstrated through animation effects (e.g., node blinking, path gradual display). When the mouse hovers over a trajectory node, a pop-up window displays detailed anomaly information for that node (e.g., source IP, attack payload), thus completing the rendering of the dynamic abnormal trajectory on the timeline.

[0082] Next, the operation and maintenance topology diagram is analyzed to extract the unique identifiers and corresponding network location information of all asset nodes, establishing a mapping relationship between asset nodes and abnormal path nodes in the abnormal behavior diagram (matching by IP address or device number). Then, based on the degree of impact of asset nodes in the business impact data (e.g., red for high anomalies, yellow for medium anomalies, and green for low anomalies), a preset color coding rule is established. On the rendering layer of the dynamic anomaly trajectory on the timeline, the location of the asset node associated with the abnormal path node is found, and the corresponding color block is overlaid on it according to the color coding rule. Simultaneously, as the anomaly trajectory dynamically updates over time, the color of the associated asset node is updated in real time (e.g., the color changes from yellow to red as the anomaly level increases), ensuring that the color status of the asset node remains consistent with the current stage of the anomaly trajectory, thus completing the color overlay process.

[0083] Specifically, information such as the affected business unit, interruption anomaly value, and estimated loss corresponding to each asset node is extracted from the business impact data. The execution status of the response strategy associated with the node (such as "blocked" or "rate limiting") and the indicator change value (such as response time increasing by 20ms) are extracted from the business status feedback data. In the rendering interface of the dynamic anomaly trajectory on the time axis, the graphic position of the corresponding asset node is located, and a floating text box is generated next to the node through programming, and the information is filled in the format of "Business Impact: [Unit Name] Anomaly [Value]; Feedback: [Strategy Status] [Indicator Change]".

[0084] Next, set the display rules for the text boxes (such as displaying complete information when the node is clicked, and displaying abnormal values ​​and policy status by default), and associate these labels with the color status of asset nodes and the timeline of abnormal trajectories to ensure that the information is dynamically updated over time (such as refreshing the feedback content in real time after adding a response action), and finally form a network security situation map that includes abnormal trajectories, asset status, business impact and feedback information.

[0085] Furthermore, the control commands associated with asset nodes in the network security situation map (such as "block port 80 of node A" and "restart the service of node B") are analyzed to extract the operation object (node ​​ID), operation type (blocking / restarting, etc.), and parameters (port number / time) from the commands. These commands are converted into configuration commands (such as firewall ACL rules and server SSH commands) recognizable by the target devices through the network management interface. The commands are then sent to the corresponding devices according to their priority (e.g., emergency blocking takes precedence over regular restarting). The execution results of the commands are monitored in real time (e.g., returning "success" or "fail"). If successful, the status identifier of the corresponding node in the situation map is updated (e.g., a "blocked" label is added). If it fails, a retry mechanism is triggered (up to 3 retries), and an operation log is recorded (including command content, execution time, and result). This completes the protection and control of the target network.

[0086] In this embodiment of the invention, abnormal behavior graphs, operation and maintenance topology graphs, business impact data, and business status feedback data are integrated and rendered into a network security situational graph. The control commands within the graph are used to execute protection operations. This method can intuitively integrate multi-dimensional information, allowing operation and maintenance personnel to quickly grasp the security situation, anomaly propagation, and strategy effectiveness. One-click control enables precise protection and reduces decision-making delays.

[0087] For example, in the fintech field, banks use situational maps to discover abnormal propagation paths in payment systems and quickly block the source of attacks through control commands.

[0088] For example, in the healthcare field, hospitals use situational maps to identify abnormal transmissions in medical record systems and use control commands to isolate infected terminals, ensuring the security of medical data and the continuity of services.

[0089] As can be seen, the above solution constructs anomaly behavior graphs and operation and maintenance topology graphs by fusing multi-source heterogeneous data, achieving accurate mapping between network threats and asset entities. By leveraging dynamic Bayesian networks to conduct anomaly propagation analysis on target business-related nodes, the impact of attacks on core businesses can be quantitatively assessed. Based on the hierarchical response strategy generated from the impact data, differentiated protection measures (such as low-risk monitoring and high-risk blocking) can be automatically triggered for different risk levels. Finally, the situation map dynamically visualizes multiple types of data and executes protection and control measures, making security decisions more intuitive and efficient. This forms a closed loop from threat perception and impact assessment to dynamic protection, enhancing the accuracy of network security protection.

[0090] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0091] In one embodiment, a network security control device for dual-image fusion is provided, which corresponds one-to-one with the network security control method for dual-image fusion described in the above embodiments. For example... Figure 5 As shown, the network security control device with dual-map fusion includes a dual-map construction module 101, a node mapping relationship generation module 102, a business impact data analysis module 103, a business status feedback data acquisition module 104, and a network security situation map control module 105. Detailed descriptions of each functional module are as follows: The dual-graph construction module 101 is used to acquire multi-source heterogeneous data in the target network and construct an abnormal behavior graph and an operation and maintenance topology graph of the target network based on the multi-source heterogeneous data. The node mapping relationship generation module 102 is used to associate and match the abnormal behavior nodes in the abnormal behavior graph with the asset nodes in the operation and maintenance topology graph to generate a node mapping relationship table in the target network. The business impact data analysis module 103 is used to construct a dynamic Bayesian network of related nodes in the target business based on the node mapping relationship table, and to use the dynamic Bayesian network to perform anomaly diffusion analysis on the related nodes of the target business in the node mapping relationship table to obtain the business impact data corresponding to the target business. The business status feedback data acquisition module 104 is used to generate a hierarchical response strategy for the target business based on the business impact data, and to acquire business status feedback data during the execution of the hierarchical response strategy. The network security situation map control module 105 is used to fuse and render the abnormal behavior map, the operation and maintenance topology map, the service impact data and the service status feedback data into a network security situation map, and to perform network protection control operations on the target network using the control instructions in the network security situation map.

[0092] In one embodiment, the dual-graph construction module 101, when executing the construction of an anomaly behavior graph and an operation and maintenance topology graph of the target network based on the multi-source heterogeneous data, is used to: Data cleaning is performed on the multi-source heterogeneous data to obtain standard data in the target network; Anomaly windows are aggregated from the security device logs and terminal event records in the standard data to obtain anomaly event sequences in the target network. The abnormal event sequence is identified based on a preset state machine model to obtain an initial abnormal behavior graph in the target network; By performing topological association between the asset management system information and network scan logs in the standard data, an initial operation and maintenance topology map of the target network is obtained. The initial abnormal behavior graph and the initial operation and maintenance topology graph are transformed to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network.

[0093] In one embodiment, the dual-graph construction module 101, when performing data transformation on the initial abnormal behavior graph and the initial operation and maintenance topology graph to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network, is used to: The node and edge attributes in the initial abnormal behavior graph and the initial operation and maintenance topology graph are standardized in format to obtain the updated node and updated edge attributes. Extract the topological features of the updated node and the updated edge attributes, and aggregate the topological features into a feature set; Based on the feature set, calculate the node similarity and edge class consistency of the updated node and the updated edge attributes, respectively; Based on the node similarity and the edge class consistency, the updated node and the updated edge attributes are merged to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network.

[0094] In one embodiment, the node mapping relationship generation module 102, when performing the process of associating and matching abnormal behavior nodes in the abnormal behavior graph with asset nodes in the operation and maintenance topology graph to generate a node mapping relationship table in the target network, is used to: By using a sliding time window, the timestamps of the abnormal behavior nodes in the abnormal behavior graph and the asset nodes in the operation and maintenance topology graph are time-aligned to obtain the first node pair for time synchronization. Perform a topology connectivity check on the first node pair to obtain the topology connectivity check result, and generate a topology-connected second node pair based on the topology connectivity check result; Calculate the association confidence of the second node pair; The first node pair, the second node pair, and the association confidence are summarized into a node mapping relationship table.

[0095] In one embodiment, the business impact data analysis module 103, when executing the construction of a dynamic Bayesian network of associated nodes in the target business based on the node mapping relationship table, is used to: Map the abnormal behavior nodes and asset nodes corresponding to the associated nodes in the node mapping table to observation nodes and status nodes, respectively. Directed edges are constructed based on the dependencies in the aforementioned operation and maintenance topology graph; The edge weights of the directed edges are calculated based on the path characteristics in the node mapping table. A dynamic Bayesian network of associated nodes in the target service is constructed based on the observation nodes, the state nodes, the directed edges, and the edge weights.

[0096] In one embodiment, the business impact data analysis module 103, when performing anomaly diffusion analysis on the associated nodes of the target business in the node mapping table using the dynamic Bayesian network to obtain the business impact data corresponding to the target business, is used to: Obtain the asset dependency list of the target business system, and establish an association table between the business units in the asset dependency list and the asset nodes in the node mapping relationship table based on the asset dependency list; The anomaly probability of associated nodes in the node mapping table is calculated using the forward propagation algorithm in the dynamic Bayesian network. Calculate the business impact score of the target business based on the service criticality weights in the association table and the anomaly probability; Obtain a historical case library of business interruptions, and map the business impact score to business impact data based on the case library.

[0097] In one embodiment, the service status feedback data acquisition module 104, when executing the generation of a hierarchical response strategy for the target service based on the service impact data, is used to: Construct an anomaly scoring matrix for the target service based on the path confidence, service impact unit, and interruption anomaly in the service impact data; Identify the basic response actions corresponding to the rating levels of the business impact units in the anomaly rating matrix; Identify the dependencies between the business-affecting units, and adjust the basic response actions according to the dependencies to obtain a set of linked response actions for the target business; The set of linked response actions is arranged according to a preset time sequence and operation priority to obtain a hierarchical response strategy for the target service.

[0098] In one embodiment, the network security situation map control module 105, when performing the fusion and rendering of the abnormal behavior map, the operation and maintenance topology map, the service impact data, and the service status feedback data into a network security situation map, is used to: Render the abnormal paths in the abnormal behavior graph as dynamic abnormal trajectories on a time axis. The asset nodes in the operation and maintenance topology diagram are overlaid with the dynamic anomaly trajectory of the time axis by color to obtain the updated dynamic anomaly trajectory of the time axis. The business impact data and the business status feedback data are labeled onto the asset nodes in the dynamic anomaly trajectory of the update time axis to obtain a network security situation map.

[0099] This invention provides a dual-graph fusion network security control device. By fusing multi-source heterogeneous data, it constructs an abnormal behavior graph and an operation and maintenance topology graph, achieving accurate mapping between network threats and asset entities. Utilizing a dynamic Bayesian network, it conducts abnormal propagation analysis on target business-related nodes, quantifying the impact of attacks on core businesses. Based on the hierarchical response strategy generated from the impact data, it automatically triggers differentiated protection measures (such as low-risk monitoring and high-risk blocking) for different risk levels. Finally, it dynamically visualizes various types of data through a situational graph and executes protection controls, making security decisions more intuitive and efficient. This forms a closed loop from threat perception and impact assessment to dynamic protection, enhancing the accuracy of network security protection.

[0100] Specific limitations regarding the network security control device for dual-image fusion can be found in the limitations of the network security control method for dual-image fusion described above, and will not be repeated here. Each module in the aforementioned network security control device for dual-image fusion can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0101] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a dual-graph fusion network security control method on the server side.

[0102] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements the client-side functions or steps of a dual-graph fusion network security control method.

[0103] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: Acquire multi-source heterogeneous data in the target network, and construct an abnormal behavior graph and operation and maintenance topology graph of the target network based on the multi-source heterogeneous data; The abnormal behavior nodes in the abnormal behavior graph are associated and matched with the asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network. Based on the node mapping relationship table, a dynamic Bayesian network of associated nodes in the target service is constructed, and the dynamic Bayesian network is used to perform anomaly diffusion analysis on the associated nodes of the target service in the node mapping relationship table to obtain the business impact data corresponding to the target service. Based on the business impact data, a tiered response strategy for the target business is generated, and business status feedback data is obtained during the execution of the tiered response strategy. The abnormal behavior graph, the operation and maintenance topology graph, the service impact data, and the service status feedback data are merged and rendered into a network security situation map. The control instructions in the network security situation map are used to perform network protection control operations on the target network.

[0104] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor: Acquire multi-source heterogeneous data in the target network, and construct an abnormal behavior graph and operation and maintenance topology graph of the target network based on the multi-source heterogeneous data; The abnormal behavior nodes in the abnormal behavior graph are associated and matched with the asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network. Based on the node mapping relationship table, a dynamic Bayesian network of associated nodes in the target service is constructed, and the dynamic Bayesian network is used to perform anomaly diffusion analysis on the associated nodes of the target service in the node mapping relationship table to obtain the business impact data corresponding to the target service. Based on the business impact data, a tiered response strategy for the target business is generated, and business status feedback data is obtained during the execution of the tiered response strategy. The abnormal behavior graph, the operation and maintenance topology graph, the service impact data, and the service status feedback data are merged and rendered into a network security situation map. The control instructions in the network security situation map are used to perform network protection control operations on the target network.

[0105] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0106] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0107] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0108] It should be noted that if any software tools or components not belonging to our company appear in the embodiments of this application, they are merely for illustrative purposes and do not represent actual use.

[0109] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A network security control method based on dual-graph fusion, characterized in that, include: Acquire multi-source heterogeneous data in the target network, and construct an abnormal behavior graph and operation and maintenance topology graph of the target network based on the multi-source heterogeneous data; The abnormal behavior nodes in the abnormal behavior graph are associated and matched with the asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network. Based on the node mapping relationship table, a dynamic Bayesian network of associated nodes in the target service is constructed, and the dynamic Bayesian network is used to perform anomaly diffusion analysis on the associated nodes of the target service in the node mapping relationship table to obtain the business impact data corresponding to the target service. Based on the business impact data, a tiered response strategy for the target business is generated, and business status feedback data is obtained during the execution of the tiered response strategy. The abnormal behavior graph, the operation and maintenance topology graph, the service impact data, and the service status feedback data are merged and rendered into a network security situation map. The control instructions in the network security situation map are used to perform network protection control operations on the target network.

2. The network security control method based on dual-graph fusion as described in claim 1, characterized in that, The construction of the abnormal behavior graph and operation and maintenance topology graph of the target network based on the multi-source heterogeneous data includes: Data cleaning is performed on the multi-source heterogeneous data to obtain standard data in the target network; Anomaly windows are aggregated from the security device logs and terminal event records in the standard data to obtain anomaly event sequences in the target network. The abnormal event sequence is identified based on a preset state machine model to obtain an initial abnormal behavior graph in the target network; By performing topological association between the asset management system information and network scan logs in the standard data, an initial operation and maintenance topology map of the target network is obtained. The initial abnormal behavior graph and the initial operation and maintenance topology graph are transformed to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network.

3. The network security control method based on dual-graph fusion as described in claim 2, characterized in that, The step of transforming the initial abnormal behavior graph and the initial operation and maintenance topology graph to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network includes: The node and edge attributes in the initial abnormal behavior graph and the initial operation and maintenance topology graph are standardized in format to obtain the updated node and updated edge attributes. Extract the topological features of the updated node and the updated edge attributes, and aggregate the topological features into a feature set; Based on the feature set, calculate the node similarity and edge class consistency of the updated node and the updated edge attributes, respectively; Based on the node similarity and the edge class consistency, the updated node and the updated edge attributes are merged to obtain the abnormal behavior graph and operation and maintenance topology graph of the target network.

4. The network security control method based on dual-graph fusion as described in claim 1, characterized in that, The step of associating and matching abnormal behavior nodes in the abnormal behavior graph with asset nodes in the operation and maintenance topology graph to generate a node mapping table in the target network includes: By using a sliding time window, the timestamps of the abnormal behavior nodes in the abnormal behavior graph and the asset nodes in the operation and maintenance topology graph are time-aligned to obtain the first node pair for time synchronization. Perform a topology connectivity check on the first node pair to obtain the topology connectivity check result, and generate a topology-connected second node pair based on the topology connectivity check result; Calculate the association confidence of the second node pair; The first node pair, the second node pair, and the association confidence are summarized into a node mapping relationship table.

5. The network security control method based on dual-graph fusion as described in claim 1, characterized in that, The step of constructing a dynamic Bayesian network of associated nodes in the target service based on the node mapping table includes: Map the abnormal behavior nodes and asset nodes corresponding to the associated nodes in the node mapping table to observation nodes and status nodes, respectively. Directed edges are constructed based on the dependencies in the aforementioned operation and maintenance topology graph; The edge weight of the directed edge is calculated based on the path characteristics in the node mapping table. A dynamic Bayesian network of associated nodes in the target service is constructed based on the observation nodes, the state nodes, the directed edges, and the edge weights.

6. The network security control method based on dual-graph fusion as described in claim 1, characterized in that, The hierarchical response strategy for generating target services based on the business impact data includes: Construct an anomaly scoring matrix for the target service based on the path confidence, service impact unit, and interruption anomaly in the service impact data; Identify the basic response actions corresponding to the rating levels of the business impact units in the anomaly rating matrix; Identify the dependencies between the business-affecting units, and adjust the basic response actions according to the dependencies to obtain a set of linked response actions for the target business; The set of linked response actions is arranged according to a preset time sequence and operation priority to obtain a hierarchical response strategy for the target service.

7. The network security control method based on dual-graph fusion as described in claim 1, characterized in that, The process of fusing and rendering the abnormal behavior graph, the operation and maintenance topology graph, the business impact data, and the business status feedback data into a network security situational awareness graph includes: Render the abnormal paths in the abnormal behavior graph as dynamic abnormal trajectories on the time axis. The asset nodes in the operation and maintenance topology diagram are overlaid with the dynamic anomaly trajectory of the time axis by color to obtain the updated dynamic anomaly trajectory of the time axis. The business impact data and the business status feedback data are labeled onto the asset nodes in the dynamic anomaly trajectory of the update time axis to obtain a network security situation map.

8. A network security control device with dual-image fusion, characterized in that, include: The dual-graph construction module is used to acquire multi-source heterogeneous data in the target network and construct an abnormal behavior graph and an operation and maintenance topology graph of the target network based on the multi-source heterogeneous data. The node mapping relationship generation module is used to associate and match the abnormal behavior nodes in the abnormal behavior graph with the asset nodes in the operation and maintenance topology graph to generate a node mapping relationship table in the target network. The business impact data analysis module is used to construct a dynamic Bayesian network of related nodes in the target business based on the node mapping relationship table, and to use the dynamic Bayesian network to perform anomaly diffusion analysis on the related nodes of the target business in the node mapping relationship table to obtain the business impact data corresponding to the target business. The business status feedback data acquisition module is used to generate a hierarchical response strategy for the target business based on the business impact data, and to acquire business status feedback data during the execution of the hierarchical response strategy. The network security situation map control module is used to fuse and render the abnormal behavior map, the operation and maintenance topology map, the service impact data, and the service status feedback data into a network security situation map, and to perform network protection control operations on the target network using the control instructions in the network security situation map.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the network security control method of dual-graph fusion as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the network security control method of dual-graph fusion as described in any one of claims 1 to 7.