Attack and defense element collecting and processing method and system based on multi-source data
By establishing multiple data monitoring points in the network system and dynamically adjusting the preprocessing model and initial acquisition frequency, combined with multi-level early warning strategies and correlation models, the problem of collaborative acquisition of multi-dimensional heterogeneous data was solved, and the efficiency of acquisition and analysis of offensive and defensive elements was improved.
Patent Information
- Application Number
- CN202510905228.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-11-21
AI Technical Summary
Existing technologies lack the ability to collaboratively collect multi-dimensional heterogeneous data, resulting in blind spots in threat perception. Elements at each stage of the attack chain are not effectively linked, making it difficult to form a systematic knowledge graph that can guide proactive defense.
Multiple data monitoring points are established in the network system. The preprocessing model and initial acquisition frequency are dynamically adjusted according to the historical characteristics of each data monitoring point. A multi-level early warning strategy and correlation model are constructed to achieve collaborative acquisition of multi-dimensional heterogeneous data.
It improves the efficiency of data collection and analysis for offensive and defensive elements, reduces the operational load, provides timely early warning of fluctuations in data monitoring points, and enables collaborative collection of multi-dimensional heterogeneous data.
Smart Images

Figure CN121000408A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of network attack and defense elements, in particular to a method and system for collecting and processing attack and defense elements based on multi-source data. BACKGROUND
[0002] With the increasing complexity of network attack means and the frequent occurrence of advanced persistent threats, the network security defense system urgently needs to shift from passive response to active prediction and coordinated protection. Dynamic collection and efficient processing of attack and defense elements (such as attack characteristics, vulnerability information, threat intelligence, and defense strategies) have become the core foundation of building intelligent security defense capabilities.
[0003] Existing technologies mostly rely on a single data source, such as a log system, a single honeypot, or a public vulnerability database, and lack the ability to cooperatively collect multi-dimensional heterogeneous data such as dark web forums, open source intelligence, terminal behavior data, and cloud platform traffic, resulting in blind spots in threat perception. The elements of each link in the attack chain are not effectively associated, making it difficult to form a systematic knowledge graph that can guide active defense from fragmented information. SUMMARY
[0004] The purpose of the present application is to solve the above technical problems, and the present application provides a method and system for collecting and processing attack and defense elements based on multi-source data, aiming to improve the collection efficiency of attack and defense element data and improve the overall linkage analysis efficiency of attack chains.
[0005] In some embodiments of the present application, multiple data monitoring points are established in the network system according to the characteristics of attack and defense elements, and the preprocessing model and initial collection frequency of each data monitoring point are dynamically adjusted according to the historical characteristics of each data monitoring point, reducing the overall running load and improving the collection and analysis efficiency of attack and defense elements in the network system.
[0006] In some embodiments of the present application, a multi-level early warning strategy for each data monitoring point is established to timely warn of the fluctuation state of attack and defense elements in each data monitoring point, improve the collection efficiency of attack and defense elements, and at the same time, by constructing an association model, the collection strategy of the associated monitoring points is adjusted in time when data collection is performed at the target monitoring point, thereby realizing the cooperative collection of multi-dimensional heterogeneous data and improving the collection and analysis efficiency of attack and defense elements in the network system.
[0007] In some embodiments of the present application, a method for collecting and processing attack and defense elements based on multi-source data is provided, comprising: Constructing multiple data monitoring points based on network system parameters; Generating a collection evaluation value for each data monitoring point, and setting the initial collection frequency of each data monitoring point according to all collection evaluation values; Acquire monitoring data packets from each monitoring point, and determine whether to generate a primary acquisition instruction for each monitoring point based on all monitoring data packets; When constructing multiple data monitoring points, the following are included: Establish a data monitoring point sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let be the i-th data monitoring point; n is the number of data monitoring points.
[0008] In some embodiments of this application, the generation of the collection evaluation values for each data monitoring point includes: Based on the data monitoring point sequence A, a is set sequentially. i Monitoring points to be evaluated; Generate correlation values between the monitoring points to be evaluated and each data monitoring point based on a preset correlation model; Based on all correlation values, establish a sequence of correlation monitoring points P, P=(p1, p2…p…). i …p n1 ), where n1 is the number of associated monitoring points of the monitoring point to be evaluated; p i Let i be the i-th associated monitoring point of the monitoring point to be evaluated; Obtain historical data packets for the monitoring points to be evaluated; Generate the collected evaluation value b of the monitoring point to be evaluated based on the associated monitoring point sequence P and historical data packets; The collected evaluation values for each data monitoring point are generated sequentially; Establish a sequence of collected evaluation values B, B=(b1, b2, ..., bb2) i …b n ), where b i Let be the evaluation value collected at the i-th data monitoring point.
[0009] In some embodiments of this application, generating the collected evaluation value b of the monitoring point to be evaluated includes: b=e1*Q1*[ β i *v i ]+e2*Q2*[ η i *s i ]; Where e1 is the preset first fixed coefficient; e2 is the preset second fixed coefficient; Q1 is the preset first fixed coefficient; Q2 is the preset second fixed coefficient; θ1 is the number of historical evaluation indicators; β i v is the influence factor of the i-th historical evaluation indicator; i To generate a reference value for the i-th historical evaluation indicator based on historical data packets; n1 is the number of associated monitoring points of the monitoring point to be evaluated; ηi is an influence factor of the ith associated monitoring point of the monitoring point to be evaluated; s i is an auxiliary evaluation value of the ith associated monitoring point of the monitoring point to be evaluated.
[0010] In some embodiments of the present application, when the monitoring data packet of each data monitoring point is acquired, the following steps are included: According to the data monitoring point sequence A, a i is a target monitoring point; According to the initial collection frequency of the target monitoring point, a collection time axis of the target monitoring point is established, and the collection time axis includes a plurality of collection time nodes; A preprocessing model of the target monitoring point is established; The original data of the target monitoring point at the current collection time node is acquired; According to the preprocessing model and the original data, a monitoring data packet of the target monitoring point at the current collection time node is generated; According to the monitoring data packet, an abnormal risk value c of the target monitoring point is generated; According to the abnormal risk value c, a first-level collection instruction of the target monitoring point is generated; Whether each data monitoring point generates a first-level collection instruction is sequentially determined.
[0011] In some embodiments of the present application, when the abnormal risk value c of the target monitoring point is generated, the following steps are included: Based on the monitoring data packet, an initial abnormal value d1 of the target monitoring point is generated; d1=[ μ i *j i ]; Wherein, θ2 is the number of characteristic indexes of the target monitoring point; μ i is an influence factor of the ith characteristic index; j i is a matching value of the ith characteristic index based on the monitoring data packet; A preset initial abnormal value threshold D is set; If d1>D, the abnormal risk value c of the target monitoring point is set as the initial abnormal value d1, that is, c=d1; If d1<D, a second-level abnormal value d2 is generated; According to the initial abnormal value d1 and the second-level abnormal value d2, the abnormal risk value c is generated, c=e3*d1+e4*d2; Wherein, e3 is a preset third weight coefficient; e4 is a preset fourth weight coefficient.
[0012] In some embodiments of the present application, when the second-level abnormal value d2 is generated, the following steps are included: d2=[ λ i *(w i-w' i ) 2 ]; wherein θ3 is the number of abnormal indexes of the target monitoring point; λ i is the influence factor of the i-th abnormal index of the target monitoring point; w i is the real-time reference value of the i-th abnormal index of the target monitoring point; w i is the standard reference value of the i-th abnormal index of the target monitoring point.
[0013] 7. The attack-defense element collection processing method based on multi-source data according to claim 4, wherein when determining whether to generate a first collection instruction of the target monitoring point according to the abnormal risk value c, the method comprises: setting an abnormal risk value threshold C1; if c < C1, the target monitoring point does not generate a first collection instruction; if c > C1, the target monitoring point generates a first collection instruction.
[0014] In some embodiments of the application, the first collection instruction comprises: setting a first collection strategy of the target monitoring point according to the abnormal risk value c, and obtaining a first feedback data packet of the target monitoring point according to the first collection strategy; establishing a sequence A2 of associated monitoring points of the target monitoring point, A2 = (a 21 ,a 22 …a 2i …a 2n2 ), wherein a 2i is the number of the i-th associated monitoring point of the target monitoring point; and n2 is the number of associated monitoring points of the target monitoring point; setting an auxiliary collection strategy of each associated monitoring point; obtaining a second feedback data packet of each associated monitoring point according to all auxiliary collection strategies; determining whether to generate a warning instruction of each associated monitoring point according to the second feedback data packet; generating a data packet to be analyzed of the target monitoring point according to the first feedback data packet and all second feedback data packets.
[0015] In some embodiments of the application, a system for collecting and processing attack-defense elements based on multi-source data is provided, comprising: a central control module configured to construct a plurality of data monitoring points based on network system parameters; a first processing module configured to generate a collection evaluation value of each data monitoring point; a second processing module configured to set an initial collection frequency of each data monitoring point according to all collection evaluation values; The third processing module is configured to acquire monitoring data packets of each data monitoring point, and determine whether to generate a first-level collection instruction of each monitoring point according to all the monitoring data packets. The central control module is further configured to establish a data monitoring point sequence A, A=(a1, a2,..., ai,..., an), where ai is the ith data monitoring point, and n is the number of data monitoring points.
[0016] In some embodiments of the present application, the first processing module is further configured to: According to the data monitoring point sequence A, ai is sequentially set as a i to be evaluated; generate an association value between the to-be-evaluated monitoring point and each data monitoring point based on a preset association model; establish an associated monitoring point sequence P of the to-be-evaluated monitoring point based on all the association values, P=(p1, p2,..., pi,..., pn1), where n1 is the number of associated monitoring points of the to-be-evaluated monitoring point, and pi is the ith associated monitoring point of the to-be-evaluated monitoring point. i …p n1 i i …b n ), where bi is the ith data monitoring point. i acquire historical data packets of the to-be-evaluated monitoring point; generate a collection evaluation value b of the to-be-evaluated monitoring point based on the associated monitoring point sequence P and the historical data packets; generate collection evaluation values of each data monitoring point in sequence; establish a collection evaluation value sequence B, B=(b1, b2,..., bi,..., bn), where n is the number of data monitoring points, and bi is the collection evaluation value of the ith data monitoring point. i …b n ), where bi is the ith data monitoring point. i
[0017] Compared with the prior art, the method and system for collecting and processing attack and defense elements based on multi-source data have the following advantages: According to the characteristics of attack and defense elements, multiple data monitoring points are established in a network system, and the preprocessing model and initial collection frequency of each data monitoring point are dynamically adjusted according to the historical characteristics of each data monitoring point, thereby reducing the overall operation load and improving the collection and analysis efficiency of attack and defense elements of the network system.
[0018] By establishing a multi-level early warning strategy for each data monitoring point, the fluctuation state of attack and defense elements of each data monitoring point is timely warned, the collection efficiency of attack and defense elements is improved, and by constructing an association model, the collection strategy of the associated monitoring point of the target monitoring point is timely adjusted when data is collected at the target monitoring point, thereby realizing the cooperative collection of multi-dimensional heterogeneous data and improving the collection and analysis efficiency of attack and defense elements of the network system. BRIEF DESCRIPTION OF DRAWINGS
[0019] Figure 1This is a flowchart illustrating a preferred embodiment of the present application's method for collecting and processing attack and defense elements based on multi-source data. Detailed Implementation
[0020] The specific embodiments of this application will be described in further detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate this application, but are not intended to limit the scope of this application.
[0021] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.
[0022] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0023] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0024] like Figure 1 As shown, a preferred embodiment of this application provides a method for collecting and processing attack and defense elements based on multi-source data, including: S101: Construct multiple data monitoring points based on network system parameters; S102: Generate the collection evaluation value of each data monitoring point, and set the initial collection frequency of each data monitoring point based on all collection evaluation values; S103: Obtain the monitoring data packets of each data monitoring point, and determine whether to generate a first-level acquisition instruction for each monitoring point based on all monitoring data packets; When constructing multiple data monitoring points, the following are included: Establish a data monitoring point sequence A, A=(a1, a2, ..., a... i …an ), where a i Let be the i-th data monitoring point; n is the number of data monitoring points.
[0025] Specifically, multiple data monitoring points are set according to the types of offensive and defensive elements and the network system structure. Each data monitoring point represents a node that collects data on offensive and defensive elements, including but not limited to terminal nodes, network nodes, cloud nodes, IoT nodes, and application nodes in the network system. Specifically, when generating the collection evaluation values for each data monitoring point, the following are included: Based on the data monitoring point sequence A, a is set sequentially. i Monitoring points to be evaluated; Generate correlation values between the monitoring points to be evaluated and each data monitoring point based on a preset correlation model; Based on all correlation values, establish a sequence of correlation monitoring points P, P=(p1, p2…p…). i …p n1 ), where n1 is the number of associated monitoring points of the monitoring point to be evaluated; p i Let i be the i-th associated monitoring point of the monitoring point to be evaluated; Obtain historical data packets for the monitoring points to be evaluated; Generate the collected evaluation value b of the monitoring point to be evaluated based on the associated monitoring point sequence P and historical data packets; The collected evaluation values for each data monitoring point are generated sequentially; Establish a sequence of collected evaluation values B, B=(b1, b2, ..., bb2) i …b n ), where b i Let be the evaluation value collected at the i-th data monitoring point.
[0026] Specifically, the correlation value is generated based on the correlation between the monitoring point to be evaluated and the data within each data monitoring point.
[0027] Specifically, based on the amount of data interaction between the monitoring point to be evaluated and each data monitoring point, the correlation value is generated based on the correlation between the attack and defense elements to be collected by the monitoring point to be evaluated and each data monitoring point. For example, if the monitoring point to be evaluated needs to collect attack elements, then when the attack element changes, if it is necessary to analyze the state of the defense elements of a single data monitoring point, then the correlation value between the data monitoring point and the monitoring point to be evaluated is relatively large. The specific rules for the correlation value can be set according to the actual historical monitoring parameters of the network system.
[0028] Specifically, a correlation threshold is set based on historical parameters. If the correlation value of a single data monitoring point exceeds the threshold, that data monitoring point is designated as a related monitoring point to be evaluated. When the attack and defense element status of the monitoring point to be evaluated fluctuates, the likelihood of fluctuations in the attack and defense element status of the related monitoring points increases. Relevant attack and defense element data from the related monitoring points should be collected promptly for risk analysis.
[0029] Specifically, generating the collected evaluation value b for the monitoring point to be evaluated includes: b=e1*Q1*[ β i *v i ]+e2*Q2*[ η i *s i ]; Where e1 is the preset first fixed coefficient; e2 is the preset second fixed coefficient; Q1 is the preset first fixed coefficient; Q2 is the preset second fixed coefficient; θ1 is the number of historical evaluation indicators; β i v is the influence factor of the i-th historical evaluation indicator; i To generate a reference value for the i-th historical evaluation indicator based on historical data packets; n1 is the number of associated monitoring points of the monitoring point to be evaluated; η i s is the influence factor of the i-th associated monitoring point of the monitoring point to be evaluated; i This is the auxiliary evaluation value of the i-th associated monitoring point of the monitoring point to be evaluated.
[0030] Specifically, historical evaluation indicators include, but are not limited to, the probability of fluctuations in the offensive and defensive elements of the monitoring point under evaluation, the probability of the emergence of new data, the historical false alarm rate of the monitoring point under evaluation, and credit rating, among other parameters. By quantifying each historical evaluation indicator, accurate analysis of the monitoring point under evaluation can be achieved.
[0031] Specifically, the higher the evaluation value, the greater the likelihood that the attack and defense elements corresponding to the monitoring point to be evaluated will experience state fluctuations.
[0032] Specifically, the influence factor of each associated monitoring point can be set according to its association value; the larger the association value, the larger the corresponding influence factor.
[0033] Specifically, the influencing factors of each historical evaluation indicator can be set based on historical parameters.
[0034] Specifically, the auxiliary evaluation value of a related monitoring point is the weighted sum of the real-time reference values of all historical evaluation indicators for that related monitoring point. That is, the [...] of the related monitoring point. β i *v i ]part.
[0035] Specifically, by presetting a first fixed coefficient and a second fixed coefficient, all parameters in the model are normalized, so that all parameters in the model are within the same range of values.
[0036] It is understandable that in the above embodiments, multiple data monitoring points are established in the network system based on the characteristics of the attack and defense elements, and the preprocessing model and initial acquisition frequency of each data monitoring point are dynamically adjusted according to the historical characteristics of each data monitoring point, thereby reducing the overall operating load and improving the efficiency of collecting and analyzing the attack and defense elements of the network system.
[0037] In a preferred embodiment of this application, obtaining the monitoring data packets for each data monitoring point includes: Based on the data monitoring point sequence A, a is set sequentially. i For target monitoring points; Establish a timeline for the target monitoring points based on their initial acquisition frequency. The timeline includes multiple acquisition time nodes. Establish a preprocessing model for the target monitoring points; Obtain the raw data of the target monitoring point at the current data collection time point; Generate the target monitoring point in the current monitoring data packet based on the preprocessing model and raw data; Generate the abnormal risk value c of the target monitoring point based on the monitoring data packet; Determine whether a primary data collection instruction for a production target monitoring point is required based on the abnormal risk value c. Check each data monitoring point sequentially to see if a first-level acquisition command has been generated.
[0038] Specifically, the larger the abnormal risk value c, the faster the corresponding initial collection frequency, that is, the shorter the time interval between adjacent collection time nodes of the target monitoring point.
[0039] Specifically, by dynamically adjusting the initial acquisition frequency of the target monitoring points, timely warnings can be issued for abnormal fluctuations in offensive and defensive elements within the target monitoring points, thereby reducing the overall data acquisition load and false alarm rate.
[0040] Specifically, generating the abnormal risk value c for the target monitoring point includes: Generate the initial anomaly value d1 of the target monitoring point based on the monitoring data packet; d1=[ μ i *j i ]; Where θ2 is the number of characteristic indicators of the target monitoring point; μ i Let j be the influence factor of the i-th characteristic indicator; i To generate a matching value for the i-th feature indicator based on the monitoring data packet; Preset an initial outlier threshold D; If d1 > D, set the abnormal risk value c of the target monitoring point as the initial outlier d1, that is, c = d1; If d1 < D, generate a secondary outlier d2; Generate an abnormal risk value c according to the initial outlier d1 and the secondary outlier d2, c = e3 * d1 + e4 * d2; Where, e3 is a preset third weight coefficient; e4 is a preset fourth weight coefficient.
[0041] Specifically, when generating the secondary outlier d2, it includes: d2 = λ i * (w i - w' i ) 2 ; Where, θ3 is the number of abnormal indicators of the target monitoring point; λ i is the influence factor of the i-th abnormal indicator of the target monitoring point; w i is the real-time reference value of the i-th abnormal indicator of the target monitoring point; w' i is the standard reference value of the i-th abnormal indicator of the target monitoring point.
[0042] Specifically, according to the type of attack and defense elements to be collected at the target monitoring point, set its corresponding characteristic indicators, and its attack and defense element categories include but are not limited to: firewall parameters, IDS / IPS parameters, file integrity monitoring parameters, network probe parameters, malicious apps, system vulnerability parameters, protocol vulnerability parameters, malicious processes, sensitive files, fileless attack parameters, configuration vulnerabilities, vulnerability exploitation packages, etc. Specifically, according to the category of attack and defense elements to be monitored at the target monitoring point, set its corresponding characteristic indicators. For example, when it comes to vulnerability exploitation packages, multiple groups of Shellcode characteristic byte sequences can be set. By analyzing the matching degree of real-time characteristic indicators, it is judged whether the attack and defense elements at the target monitoring point fluctuate.
[0043] Specifically, the specific values of the third weight coefficient and the fourth weight coefficient can be set according to historical parameters, and e3 + e4 = 1.
[0044] Specifically, set its abnormal indicators according to the type of attack and defense elements to be collected at the target monitoring point. For example, at the node where attack elements need to be collected, set parameters such as data traffic fluctuation and data entropy value as abnormal indicators to timely warn of potential attack risks that may occur at the target monitoring point and timely collect relevant attack elements for analysis.
[0045] Specifically, the influence factors of each outlier can be set according to historical parameters.
[0046] It can be understood that in the above embodiments, by establishing a multi-level early warning strategy for each data monitoring point, the fluctuation state of the attack and defense elements of each data monitoring point is timely warned, and the acquisition efficiency of the attack and defense elements is improved.
[0047] In the preferred embodiment of the embodiment of the present application, when judging whether to generate a first-level acquisition instruction for the target monitoring point according to the abnormal risk value c, it includes: Preprocessing the abnormal risk value threshold C1; If c < C1, the target monitoring point does not generate a first-level acquisition instruction; If c > C1, the target monitoring point generates a first-level acquisition instruction.
[0048] Specifically, the first-level acquisition instruction includes: Setting the first-level acquisition strategy of the target monitoring point according to the abnormal risk value c, and obtaining the first-level feedback data packet of the target monitoring point according to the first-level acquisition strategy; Establishing the associated monitoring point sequence A2 of the target monitoring point, A2 = (a 21 , a 22 … a 2i … a 2n2 ), where a 2i is the quantity of the i-th associated monitoring point of the target monitoring point; n2 is the number of associated monitoring points of the target monitoring point; Setting the auxiliary acquisition strategies of each associated monitoring point; Obtaining the second-level feedback data packets of each associated monitoring point according to all the auxiliary acquisition strategies; Judging whether to generate a warning instruction for each associated monitoring point according to the second-level feedback data packet; Generating the to-be-analyzed data packet of the target monitoring point according to the first-level feedback data packet and all the second-level feedback data packets.
[0049] Specifically, the larger the abnormal risk value is, the greater the fluctuation amount of the attack and defense elements of the target monitoring point is, and it needs to be analyzed in time.
[0050] Specifically, the feedback data packet is the real-time data parameter of each data monitoring point. The first-level feedback data packet and each second-level feedback data packet are fused to generate the to-be-analyzed data packet, and the to-be-analyzed data packet is stored in the sub-storage library corresponding to the target monitoring point, so as to realize the collaborative acquisition of multi-dimensional heterogeneous data and improve the acquisition and analysis efficiency of the attack and defense elements of the network system.
[0051] Specifically, the first-level acquisition strategy refers to setting the continuous acquisition duration of the target monitoring point according to the abnormal risk value of the target monitoring point. The larger the abnormal risk value is, the longer the corresponding continuous acquisition duration is.
[0052] Specifically, the secondary acquisition strategy refers to setting the corresponding acquisition duration based on the correlation value between the associated monitoring point and the target monitoring point, and analyzing the abnormal risk value of the associated monitoring point based on the acquired secondary feedback data packets. If the abnormal risk value exceeds the abnormal risk value threshold, a primary acquisition instruction for the associated monitoring point is generated, and the corresponding analysis data packet is obtained.
[0053] It is understandable that, in the above embodiments, by constructing an association model, the collection strategy of the associated monitoring points is adjusted in a timely manner when data is collected at the target monitoring point, thereby realizing the collaborative collection of multi-dimensional heterogeneous data and improving the efficiency of collecting and analyzing attack and defense elements of the network system.
[0054] In another preferred embodiment of the attack and defense element acquisition and processing method based on multi-source data according to any of the above preferred embodiments, this preferred embodiment provides an attack and defense element acquisition and processing system based on multi-source data, including: The central control module is used to construct multiple data monitoring points based on network system parameters; The first processing module is used to generate the collection evaluation values for each data monitoring point; The second processing module is used to set the initial collection frequency of each data monitoring point based on all collected evaluation values. The third processing module is used to acquire monitoring data packets from each data monitoring point and determine whether to generate a first-level acquisition instruction for each monitoring point based on all monitoring data packets. The central control module is also used to establish a data monitoring point sequence A, A=(a1, a2…ai…an), where ai is the i-th data monitoring point and n is the number of data monitoring points.
[0055] Specifically, the first processing module is also used for: Based on the data monitoring point sequence A, a is set sequentially. i Monitoring points to be evaluated; Generate correlation values between the monitoring points to be evaluated and each data monitoring point based on a preset correlation model; Based on all correlation values, establish a sequence of correlation monitoring points P, P=(p1, p2…p…). i …p n1 ), where n1 is the number of associated monitoring points of the monitoring point to be evaluated; p i Let i be the i-th associated monitoring point of the monitoring point to be evaluated; Obtain historical data packets for the monitoring points to be evaluated; Generate the collected evaluation value b of the monitoring point to be evaluated based on the associated monitoring point sequence P and historical data packets; The collected evaluation values for each data monitoring point are generated sequentially; Establish a sequence of collected evaluation values B, B=(b1, b2, ..., bb2)i …b n ), where b i Let be the evaluation value collected at the i-th data monitoring point.
[0056] Based on the first concept of this application, multiple data monitoring points are established in the network system according to the characteristics of offensive and defensive elements. The preprocessing model and initial acquisition frequency of each data monitoring point are dynamically adjusted based on its historical characteristics, thereby reducing the overall operational load and improving the efficiency of data collection and analysis of offensive and defensive elements in the network system.
[0057] According to the second concept of this application, by establishing a multi-level early warning strategy for each data monitoring point, the fluctuation status of attack and defense elements at each data monitoring point can be warned in a timely manner, thereby improving the collection efficiency of attack and defense elements. At the same time, by constructing an association model, when data is collected at the target monitoring point, the collection strategy of its associated monitoring points can be adjusted in a timely manner, thereby realizing the collaborative collection of multi-dimensional heterogeneous data and improving the collection and analysis efficiency of attack and defense elements of the network system.
[0058] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and substitutions can be made without departing from the technical principles of this application, and these improvements and substitutions should also be considered within the scope of protection of this application.
Claims
1. A method for acquiring and processing attack and defense elements based on multi-source data, characterized in that, including: Constructing multiple data monitoring points based on network system parameters; Generating the acquisition evaluation value of each data monitoring point, and setting the initial acquisition frequency of each data monitoring point according to all the acquisition evaluation values; Obtaining the monitoring data packets of each data monitoring point, and judging whether to generate the first-level acquisition instruction of each monitoring point according to all the monitoring data packets; Among them, when constructing multiple data monitoring points, it includes: Establish a data monitoring point sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let be the i-th data monitoring point; n is the number of data monitoring points.
2. The attack and defense element acquisition and processing method based on multi-source data as described in claim 1, characterized in that, When generating the acquisition evaluation value of each data monitoring point, it includes: Based on the data monitoring point sequence A, a is set sequentially. i Monitoring points to be evaluated; Generating the correlation value between the monitoring point to be evaluated and each data monitoring point based on a preset correlation model; Based on all correlation values, establish a sequence of correlation monitoring points P, P=(p1, p2…p…). i …p n1 ), where n1 is the number of associated monitoring points of the monitoring point to be evaluated; p i Let i be the i-th associated monitoring point of the monitoring point to be evaluated; Obtaining the historical data packet of the monitoring point to be evaluated; Generating the acquisition evaluation value b of the monitoring point to be evaluated according to the correlation monitoring point sequence P and the historical data packet; Generating the acquisition evaluation value of each data monitoring point in turn; Establish a sequence of collected evaluation values B, B=(b1, b2, ..., bb2) i …b n ), where b i Let be the evaluation value collected at the i-th data monitoring point.
3. The attack and defense element acquisition and processing method based on multi-source data as described in claim 2, characterized in that, When generating the acquisition evaluation value b of the monitoring point to be evaluated, it includes: b=e1*Q1*[ b i *v i ]+e2*Q2*[ or i *s i ]; Where e1 is the preset first fixed coefficient; e2 is the preset second fixed coefficient; Q1 is the preset first fixed coefficient; Q2 is the preset second fixed coefficient; θ1 is the number of historical evaluation indicators; β i v is the influence factor of the i-th historical evaluation indicator; i To generate a reference value for the i-th historical evaluation indicator based on historical data packets; n1 is the number of associated monitoring points of the monitoring point to be evaluated; η i s is the influence factor of the i-th associated monitoring point of the monitoring point to be evaluated; i This is the auxiliary evaluation value of the i-th associated monitoring point of the monitoring point to be evaluated.
4. The attack and defense element acquisition and processing method based on multi-source data as described in claim 2, characterized in that, When obtaining the monitoring data packets of each data monitoring point, it includes: Based on the data monitoring point sequence A, a is set sequentially. i For target monitoring points; Establishing the acquisition time axis of the target monitoring point according to the initial acquisition frequency of the target monitoring point, and the acquisition time axis includes multiple acquisition time nodes; Establishing the preprocessing model of the target monitoring point; Obtaining the original data of the target monitoring point at the current acquisition time node; Generating the monitoring data packet of the target monitoring point at the current time according to the preprocessing model and the original data; Generating the abnormal risk value c of the target monitoring point according to the monitoring data packet; Judging whether to generate the first-level acquisition instruction of the target monitoring point according to the abnormal risk value c; Judging whether to generate the first-level acquisition instruction for each data monitoring point in turn.
5. The method for acquiring and processing attack and defense elements of multi-source data as described in claim 4, characterized in that, When generating the abnormal risk value c of the target monitoring point, it includes: Generating the initial abnormal value d1 of the target monitoring point based on the monitoring data packet; d1=[ μ i *j i ]; Where θ2 is the number of characteristic indicators of the target monitoring point; μ i Let j be the influence factor of the i-th characteristic indicator; i To generate a matching value for the i-th feature indicator based on the monitoring data packet; Presetting the initial abnormal value threshold D; If d1>D, setting the abnormal risk value c of the target monitoring point as the initial abnormal value d1, that is, c=d1; 6. The attack and defense element acquisition and processing method based on multi-source data as described in claim 5, characterized in that, d2=[ λ i *(w i -w' i ) 2 ]; Where θ3 is the number of abnormal indicators at the target monitoring point; λ i w is the influencing factor of the i-th abnormal indicator at the target monitoring point; i w' is the real-time reference value for the i-th abnormal indicator at the target monitoring point; i This is the standard reference value for the i-th abnormal indicator at the target monitoring point.
7. The attack and defense element acquisition and processing method based on multi-source data as described in claim 4, characterized in that, 8. The attack and defense element acquisition and processing method based on multi-source data as described in claim 7, characterized in that, Establish a sequence of associated monitoring points A2, where A2 = (a 21 ,a 22 …a 2i …a 2n2 ), where a 2i n1 represents the number of the i-th associated monitoring point of the target monitoring point; n2 represents the number of associated monitoring points of the target monitoring point. 9. A system for acquiring and processing attack and defense elements based on multi-source data, employing the attack and defense element acquisition and processing method based on multi-source data as described in any one of claims 1-8, characterized in that, The third processing module is used to acquire monitoring data packets from each data monitoring point and determine whether to generate a first-level acquisition instruction for each monitoring point based on all monitoring data packets. The central control module is also used to establish a data monitoring point sequence A, A=(a1, a2…ai…an), where ai is the i-th data monitoring point; n is the number of data monitoring points.
10. The attack and defense element acquisition and processing system based on multi-source data as described in claim 9, characterized in that, The first processing module is also used for: Based on the data monitoring point sequence A, a is set sequentially. i Monitoring points to be evaluated; Generate correlation values between the monitoring points to be evaluated and each data monitoring point based on a preset correlation model; Based on all correlation values, establish a sequence of correlation monitoring points P, P=(p1, p2…p…). i …p n1 ), where n1 is the number of associated monitoring points of the monitoring point to be evaluated; p i Let i be the i-th associated monitoring point of the monitoring point to be evaluated; Obtain historical data packets for the monitoring points to be evaluated; Generate the collected evaluation value b of the monitoring point to be evaluated based on the associated monitoring point sequence P and historical data packets; The collected evaluation values for each data monitoring point are generated sequentially; Establish a sequence of collected evaluation values B, B=(b1, b2, ..., bb2) i …b n ), where b i Let be the evaluation value collected at the i-th data monitoring point.
Citation Information
Cited By
Network security situation awareness method and system based on RPA
CN121283775A