Network surveying and mapping behavior analysis method and system based on historical data
By constructing a network mapping behavior analysis model, utilizing standard mapping traffic data and historical anomaly characteristics, and calculating comprehensive feature coefficients and weights, the problems of low efficiency and accuracy in existing technologies are solved, and accurate identification and prediction of network mapping behavior are achieved.
Patent Information
- Application Number
- CN202511093222.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-05
- Publication Date
- 2025-12-12
AI Technical Summary
In existing technologies, network mapping behavior analysis is inefficient and has low accuracy, failing to accurately uncover network mapping behavior models and trends.
By constructing multiple sets of surveying and mapping logs, standard surveying and mapping traffic data is obtained and combined with historical anomaly characteristics. Comprehensive feature coefficients and weights are calculated to construct a network surveying and mapping behavior analysis model, which is then analyzed and predicted using neural networks.
It enables accurate identification and prediction of network mapping behavior, improving analysis efficiency and accuracy.
Smart Images

Figure CN121125162A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a network mapping behavior analysis method and system based on historical data. BACKGROUND
[0002] Network mapping behavior analysis refers to a process of detecting, collecting and analyzing information such as assets, services and vulnerabilities in network space through technical means, so as to draw network space topology and identify potential risks.
[0003] In the prior art, feature extraction is usually performed on historical network traffic data by relying on manual or simple automatic tools, which is not only inefficient, but also cannot accurately mine network mapping behavior models and trends, resulting in low accuracy and prediction ability of network mapping behavior analysis. Therefore, there is an urgent need for a network mapping behavior analysis method and system based on historical data to accurately extract feature information and realize accurate identification and prediction of network mapping behavior. SUMMARY
[0004] To solve the above technical problems, the present application provides a network mapping behavior analysis method and system based on historical data, which constructs multiple mapping log sets, obtains standard mapping traffic data and analyzes in combination with historical abnormal features, calculates comprehensive feature coefficients and determines feature data and weights, constructs a network mapping behavior analysis model, and realizes accurate identification and prediction of network mapping behavior.
[0005] In some embodiments of the present application, a network mapping behavior analysis method based on historical data is provided, comprising: Obtaining historical mapping logs and extracting the behavior type of each historical mapping log, dividing the historical mapping logs according to the behavior type to obtain multiple mapping log sets; Extracting historical mapping traffic data of each historical mapping log and performing cleaning and standardization processing to obtain standard mapping traffic data and combine historical abnormal features for comprehensive analysis, calculating comprehensive feature coefficients according to the analysis results and determining feature data of different behavior types; According to the comprehensive feature coefficients, the weights of the corresponding feature data are set, and the feature data, the corresponding weights and the historical abnormal features are trained by a neural network to obtain a network mapping behavior analysis model, and a real-time mapping behavior analysis report is generated to determine whether to generate an early warning instruction.
[0006] In some embodiments of the present application, the historical mapping logs are divided according to the behavior type to obtain multiple mapping log sets, comprising: The behavior type includes normal behavior and abnormal behavior; The historical mapping log with the behavior type of abnormal behavior is analyzed to determine historical abnormal characteristics of the corresponding abnormal behavior in the historical mapping log, and each historical abnormal characteristic is mapped with a corresponding historical abnormal coefficient; The historical abnormal characteristics in different historical mapping logs are analyzed to obtain the correlation degree of the abnormal behavior of different historical mapping logs; The historical mapping log with the behavior type of abnormal behavior is divided according to the correlation degree, and a plurality of mapping log sets are constructed according to the division result; Each mapping log set includes a plurality of historical mapping logs.
[0007] In some embodiments of the present application, the historical mapping traffic data of each historical mapping log is extracted and preprocessed and standardized to obtain standard mapping traffic data, including: The historical mapping traffic data of each historical mapping log in the same mapping log set is preprocessed, and the preprocessing includes filling missing values, removing abnormal values and duplicate data; The preprocessed historical mapping traffic data is standardized, and the standardization includes uniform data format and spatiotemporal reference alignment processing; The standard mapping traffic data of each historical mapping log is generated.
[0008] In some embodiments of the present application, the historical abnormal characteristics are analyzed, the comprehensive feature coefficients are calculated according to the analysis result, and the feature data of different behavior types are determined, including: A historical mapping log in the same mapping log set is randomly selected as a target mapping log; The similarity coefficient of each historical abnormal characteristic of the target mapping log and the historical abnormal characteristics of other historical mapping logs is calculated; The historical abnormal characteristics with a similarity coefficient greater than a preset similarity coefficient threshold are selected and set as target abnormal characteristics; The coefficient difference between the historical abnormal coefficient of each target abnormal characteristic of the target mapping log and the historical abnormal coefficient of the corresponding historical abnormal characteristic of other historical mapping logs in the same mapping log set; The historical abnormal coefficient, the corresponding historical abnormal characteristic and the historical mapping log with a coefficient difference less than a preset coefficient difference threshold are removed, and a comparison abnormal characteristic matrix of the target mapping log is constructed according to the historical abnormal characteristics and the historical abnormal coefficients of the remaining historical mapping logs; The historical abnormal coefficients of the historical abnormal characteristics corresponding to the remaining historical mapping logs are sorted in descending order of the coefficient difference; The coefficient difference value of the historical abnormal coefficient of a target abnormal feature corresponding to the target mapping log and the historical abnormal feature of the remaining historical mapping logs is a column of the comparison abnormal feature matrix, and a plurality of target abnormal features of the target mapping log are behaviors; The comparison abnormal feature matrix of each historical mapping log in the same mapping log set is sequentially generated; The historical time node of each target abnormal feature in the comparison abnormal feature matrix is determined, and the comparison data matrix is generated based on the standard mapping flow data of the target mapping log and other historical mapping logs in the comparison abnormal feature matrix according to the same time principle; The comparison data matrix and the comparison abnormal feature matrix are segmented to obtain a comparison sequence group, and the comparison sequence group includes a comparison data sequence and a comparison abnormal feature sequence; The sequence similarity is generated according to the comparison sequence group; The undetermined data is determined according to the sequence similarity, the comprehensive feature coefficient of each undetermined data is calculated, and the feature data is determined.
[0009] In some embodiments of the present application, the comparison data matrix and the comparison abnormal feature matrix are segmented to obtain a comparison sequence group, including: According to each comparison abnormal feature matrix, a plurality of standard mapping flow data of the target mapping log and other historical mapping logs at the same historical time node are extracted; Each standard mapping flow data of the target mapping log is compared with the corresponding standard mapping flow data of other historical mapping logs in the comparison abnormal feature matrix to obtain a plurality of data difference values of each standard mapping flow data; The plurality of data difference values of each standard mapping flow data are sorted according to the column sorting mode of the comparison abnormal feature matrix to obtain a plurality of comparison data matrices of the comparison abnormal feature matrix; Each comparison data matrix is mapped with a target abnormal feature, and the plurality of data difference values are sorted according to the arrangement order of the coefficient difference value of the historical abnormal coefficient of the mapped target abnormal feature; The data difference value of a standard mapping flow data of the target mapping log and the corresponding standard mapping flow data of the remaining historical mapping logs is a column of each comparison data matrix, and a plurality of standard mapping flow data of the target mapping log are behaviors; The column where each target abnormal feature in the comparison abnormal feature matrix is located is set as a comparison abnormal feature sequence, and the column where each standard mapping flow data in the comparison data matrix mapped by the target abnormal feature is set as a comparison data sequence; The comparison abnormal feature sequence and a plurality of comparison data sequences in the mapped comparison data matrix are randomly combined to obtain a plurality of comparison sequence groups.
[0010] In some embodiments of the present application, the sequence similarity includes: a plurality of sequence similarity evaluation indicators are preset; each sequence similarity evaluation indicator is evaluated based on the plurality of sequence similarity evaluation indicators, to obtain a sub-similarity of each sequence similarity evaluation indicator; a sequence similarity of the corresponding sequence group is generated according to the plurality of sub-similarities; The calculation formula of the sequence similarity is: ; Wherein, D is the sequence similarity, is the sub-similarity of the i th sequence similarity evaluation indicator, and a i is the weight coefficient of the i th sequence similarity evaluation indicator.
[0011] In some embodiments of the present application, the comprehensive feature coefficient of each pending data is calculated and the feature data is determined, including: a sequence similarity threshold is preset; the standard surveying and mapping flow data with a sequence similarity greater than the sequence similarity threshold is set as the pending data of the mapped target abnormal feature; a feature coefficient is generated according to the coefficient difference in the comparison sequence group of the pending data and the target abnormal feature and the corresponding data difference; The pending data of the target abnormal feature of all comparison abnormal feature matrices in the same surveying and mapping log set are compared and analyzed to obtain the occurrence frequency of the same pending data for the same target abnormal feature and the average feature coefficient; A compensation coefficient is set according to the occurrence frequency of the same pending data for the same target abnormal feature; A comprehensive feature coefficient of the corresponding pending data is generated according to the number of target abnormal features mapped by the same pending data, the average feature coefficient, the compensation coefficient and the weight coefficient of the corresponding target abnormal feature; The calculation formula of the comprehensive feature coefficient is: ; wherein, T is the comprehensive feature coefficient, m is the number of target abnormal features mapped by the current pending data, m0 is the total number of target abnormal features, is the average feature coefficient of the current specific data and the s th target abnormal feature, is the compensation coefficient of the s th target abnormal feature, is the weight coefficient of the s th target abnormal feature.
[0012] In some embodiments of the present application, the weight of the corresponding feature data is set according to the comprehensive feature coefficient, including: a comprehensive feature coefficient threshold is preset; The undetermined data with the comprehensive feature coefficient greater than the comprehensive feature coefficient threshold value is set as the feature data of the behavior type corresponding to the corresponding set of mapping logs; A comprehensive feature coefficient difference value is generated according to the comprehensive feature coefficient and the comprehensive feature coefficient threshold value. A first weight coefficient of the corresponding feature data is set according to the comprehensive feature coefficient difference value of the feature data of the same behavior type, and a second weight coefficient of the corresponding feature data is set according to the sequence similarity difference value of the feature data of the same behavior type. The weight of the corresponding feature data is generated according to the first weight coefficient and the second weight coefficient.
[0013] In some embodiments of the present application, a network mapping behavior analysis model is obtained, including: All feature data of the same set of mapping logs and the weight of each feature data are taken as a training input data set, and historical abnormal features of the corresponding behavior type are taken as a training output data set. A neural network is trained according to the training input data set and the training output data set, and a network mapping behavior analysis sub-model of the corresponding behavior type is obtained. The network mapping behavior analysis sub-models of different behavior types are fused to obtain a network mapping behavior analysis model. Based on the network mapping behavior analysis model, real-time mapping traffic data is analyzed to obtain a real-time mapping behavior analysis report, and it is determined whether to generate an early warning signal.
[0014] In some embodiments of the present application, a network mapping behavior analysis system based on historical data is further included, including: An acquisition module is configured to acquire historical mapping logs, extract a behavior type of each historical mapping log, divide the historical mapping logs according to the behavior type, and obtain a plurality of sets of mapping logs. A determination module is configured to extract historical mapping traffic data of each historical mapping log, perform cleaning and standardization processing, obtain standard mapping traffic data, and perform comprehensive analysis in combination with historical abnormal features, calculate a comprehensive feature coefficient according to an analysis result, and determine feature data of different behavior types. An analysis module is configured to set a weight of the corresponding feature data according to the comprehensive feature coefficient, perform neural network training on the feature data, the corresponding weight, and the historical abnormal features, obtain a network mapping behavior analysis model, generate a real-time mapping behavior analysis report, and determine whether to generate an early warning instruction.
[0015] Compared with the prior art, the network mapping behavior analysis method and system based on historical data according to the embodiments of the present application have the beneficial effects that: By constructing a plurality of surveying and mapping log sets, obtaining standard surveying and mapping flow data and combining historical abnormal characteristics for analysis, calculating a comprehensive characteristic coefficient and determining characteristic data and weights, a network surveying and mapping behavior analysis model is constructed to realize accurate identification and prediction of network surveying and mapping behavior. BRIEF DESCRIPTION OF DRAWINGS
[0016] Figure 1 is a flow diagram of a network surveying and mapping behavior analysis method based on historical data in an embodiment of the present application; Figure 2 is a schematic diagram of a network surveying and mapping behavior analysis system based on historical data in an embodiment of the present application. DETAILED DESCRIPTION
[0017] The specific embodiments of the present application will be further described in detail below with reference to the accompanying drawings and embodiments. The following embodiments are used to illustrate the present application, but not to limit the scope of the present application.
[0018] In the description of the present application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation of the present application.
[0019] The terms "first", "second" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0020] In the description of the present application, it should be noted that unless otherwise specified and limited, the terms "mounting", "connecting", "connecting" should be understood broadly, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium; it can be the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0021] As shown in Figure 1 The network surveying and mapping behavior analysis method based on historical data in an embodiment of the present application includes: Step S101: Obtain historical mapping logs and extract the behavior type of each historical mapping log, divide the historical mapping logs according to the behavior type, and obtain a plurality of mapping log sets; Step S102: Extract the historical mapping traffic data of each historical mapping log and perform cleaning and standardization processing, obtain standard mapping traffic data, and comprehensively analyze in combination with historical abnormal characteristics, calculate a comprehensive feature coefficient according to the analysis result, and determine feature data of different behavior types; Step S103: According to the comprehensive feature coefficient, set the weight of the corresponding feature data, and perform neural network training on the feature data, the corresponding weight and the historical abnormal characteristics, obtain a network mapping behavior analysis model, and generate a real-time mapping behavior analysis report, and determine whether to generate an early warning instruction.
[0022] In some embodiments of the present application, the historical mapping logs are divided according to the behavior type, and a plurality of mapping log sets are obtained, including: The behavior type includes normal behavior and abnormal behavior; The historical mapping logs with abnormal behavior are analyzed to determine the historical abnormal characteristics of the corresponding abnormal behavior in the historical mapping logs, and each historical abnormal characteristic is mapped to a corresponding historical abnormal coefficient; The historical abnormal characteristics in different historical mapping logs are analyzed to obtain the correlation degree of the abnormal behavior of different historical mapping logs; The historical mapping logs with abnormal behavior are divided according to the correlation degree, and a plurality of mapping log sets are constructed according to the division result; Each mapping log set includes a plurality of historical mapping logs.
[0023] In this embodiment, the historical abnormal characteristics include historical malicious detection behavior traffic, historical attack IP, vulnerability exploitation method, and victim asset.
[0024] In this embodiment, the mapping log set refers to the historical mapping logs with abnormal behavior whose correlation degree is greater than a preset correlation degree threshold.
[0025] In this embodiment, the correlation degree of the abnormal behavior of different historical mapping logs is calculated to identify whether the abnormal behavior in different historical mapping logs has similar behavior or time correlation, IP address correlation, etc. For example, frequent access to a specific domain name appears in a plurality of historical mapping logs, or whether a certain abnormal behavior also appears at a similar time point in other logs, which may indicate that these abnormal behaviors belong to the same attacker or attack organization or exist in a coordinated attack.
[0026] In the embodiment, the historical mapping logs are divided by calculating the correlation degrees of different historical mapping logs, a plurality of mapping log sets are obtained, a foundation is laid for subsequent determination of influence coefficients of historical mapping traffic data of different behavior types, and network mapping behavior analysis efficiency is improved.
[0027] In some embodiments of the application, historical mapping traffic data of each historical mapping log is extracted and preprocessed and standardized, to obtain standard mapping traffic data, including: The historical mapping traffic data of each historical mapping log in the same mapping log set is preprocessed, and the preprocessing includes filling in missing values, removing abnormal values and duplicate data; The preprocessed historical mapping traffic data is standardized, and the standardization includes uniform data format and spatiotemporal reference alignment processing; Standard mapping traffic data of each historical mapping log is generated.
[0028] In the embodiment, the historical mapping traffic data is preprocessed and standardized to ensure that multi-source data can be integrated and analyzed, to lay a foundation for subsequent determination of load characteristics and corresponding influence coefficients, and to improve data accuracy.
[0029] In some embodiments of the application, the historical abnormal features are comprehensively analyzed, the comprehensive feature coefficients are calculated according to the analysis results, and the feature data of different behavior types are determined, including: A historical mapping log in the same mapping log set is randomly selected as a target mapping log; The similarity coefficient of each historical abnormal feature of the target mapping log and the historical abnormal features of other historical mapping logs is calculated; The historical abnormal features with a similarity coefficient greater than a preset similarity coefficient threshold are selected and set as target abnormal features; The coefficient difference between the historical abnormal coefficient of each target abnormal feature of the target mapping log and the historical abnormal coefficient of the corresponding historical abnormal feature of other historical mapping logs in the same mapping log set is calculated; The historical abnormal coefficient, the corresponding historical abnormal feature and the historical mapping log with a coefficient difference less than a preset coefficient difference threshold are removed, and a comparison abnormal feature matrix of the target mapping log is constructed according to the remaining historical abnormal features and historical abnormal coefficients of the historical mapping logs; The historical abnormal coefficients of the historical abnormal features of the remaining historical mapping logs are sorted in descending order of the coefficient difference; The coefficient difference value of the historical abnormality coefficient of a target abnormality feature of the target mapping log and the historical abnormality feature corresponding to the remaining historical mapping log is a column of the comparison abnormality feature matrix. The comparison abnormality feature matrix of each historical mapping log in the same mapping log set is sequentially generated. The historical time node of each target abnormality feature in the comparison abnormality feature matrix is determined, and the comparison data matrix is generated based on the standard mapping traffic data of the target mapping log and other historical mapping logs in the comparison abnormality feature matrix according to the same time principle. The comparison data matrix and the comparison abnormality feature matrix are segmented to obtain a comparison sequence group, and the comparison sequence group includes a comparison data sequence and a comparison abnormality feature sequence. The sequence similarity is generated according to the comparison sequence group. The undetermined data is determined according to the sequence similarity, the comprehensive feature coefficient of each undetermined data is calculated, and the feature data is determined.
[0030] In this embodiment, the target abnormality feature refers to a historical abnormality feature with a large similarity coefficient in the target mapping log and other historical mapping logs in the same mapping log set, and the historical abnormality coefficient refers to the different abnormality degree of the similar historical abnormality feature. For example, the historical abnormality feature is access frequency abnormality, and the historical abnormality coefficient is set by the specific access frequency. The larger the access frequency is, the larger the historical abnormality coefficient is, and vice versa.
[0031] In this embodiment, the comparison abnormality feature matrix and the comparison data matrix are constructed, the comparison sequence group is determined, the sequence similarity of the comparison sequence group is calculated, and the dependence degree of each standard mapping traffic data and the target abnormality feature is evaluated, so as to screen out the feature data and determine the weight, thereby laying a foundation for subsequent construction of a network mapping behavior analysis model and improving the mapping behavior analysis accuracy.
[0032] In some embodiments of the present application, the comparison data matrix and the comparison abnormality feature matrix are segmented to obtain the comparison sequence group, including: According to each comparison abnormality feature matrix, a plurality of standard mapping traffic data of the target mapping log and other historical mapping logs at the same historical time node are extracted; Each standard mapping traffic data of the target mapping log is compared with the corresponding standard mapping traffic data of other historical mapping logs in the comparison abnormality feature matrix to obtain a plurality of data difference values of each standard mapping traffic data; The plurality of data difference values of each standard mapping traffic data are sorted according to the column sorting mode of the comparison abnormality feature matrix to obtain a plurality of comparison data matrices of the comparison abnormality feature matrix. Each comparison data matrix is mapped with a target abnormal feature, and a plurality of data differences are sorted according to the arrangement order of the coefficient difference of the historical abnormal coefficient of the mapped target abnormal feature; The column of each comparison data matrix is a data difference between a standard mapping flow data of the target mapping log and a corresponding standard mapping flow data of the remaining historical mapping log, and the action is a plurality of standard mapping flow data of the target mapping log. Each column of each target abnormal feature in the comparison abnormal feature matrix is set as a comparison abnormal feature sequence, and each standard mapping flow data in the comparison data matrix mapped by the target abnormal feature is set as a comparison data sequence. The comparison abnormal feature sequence and a plurality of comparison data sequences in the mapped comparison data matrix are randomly combined to obtain a plurality of comparison sequence groups.
[0033] In this embodiment, by constructing a plurality of comparison sequence groups, the correlation between a plurality of coefficient differences of each target abnormal feature and a plurality of data differences of the mapped standard mapping flow data, i.e., sequence similarity, is evaluated, the calculation accuracy of the comprehensive feature coefficient of each standard mapping flow data for the abnormal feature is improved, and the analysis accuracy of the network mapping behavior is improved.
[0034] In some embodiments of the present application, the sequence similarity includes: A plurality of sequence similarity evaluation indexes are preset; Each comparison sequence group is evaluated based on a plurality of sequence similarity evaluation indexes to obtain a sub-similarity of each sequence similarity evaluation index; A sequence similarity of the corresponding comparison sequence group is generated according to a plurality of sub-similarities; The calculation formula of the sequence similarity is: ; Wherein, D is the sequence similarity, is the sub-similarity of the i th sequence similarity evaluation index, and ai is the weight coefficient of the i th sequence similarity evaluation index.
[0035] In this embodiment, the sequence similarity evaluation indexes include but are not limited to sequence numerical difference similarity, sequence fluctuation similarity, distribution position of the maximum and minimum values in the sequence, linear correlation degree, etc.
[0036] In some embodiments of the present application, calculating the comprehensive feature coefficient of each pending data and determining the feature data includes: A sequence similarity threshold is preset; The standard mapping flow data with a sequence similarity greater than the sequence similarity threshold is set as the pending data of the mapped target abnormal feature; According to the coefficient difference value of the alignment sequence of the to-be-determined data and the target abnormal feature and the corresponding data difference value, a feature coefficient is generated; The to-be-determined data of the target abnormal feature of all the alignment abnormal feature matrices in the same set of mapping logs are compared and analyzed to obtain the occurrence frequency of the same to-be-determined data for the same target abnormal feature and the mean value of the feature coefficient; According to the occurrence frequency of the same to-be-determined data for the same target abnormal feature, a compensation coefficient is set; According to the number of the target abnormal features mapped by the same to-be-determined data, the mean value of the feature coefficient, the compensation coefficient, and the weight coefficient of the corresponding target abnormal feature, a comprehensive feature coefficient of the corresponding to-be-determined data is generated. The calculation formula of the comprehensive feature coefficient is: ; wherein T is the comprehensive feature coefficient, m is the number of the target abnormal features mapped by the current to-be-determined data, m0 is the total number of the target abnormal features, is the mean value of the feature coefficient of the current specific data and the s-th target abnormal feature, is the compensation coefficient of the s-th target abnormal feature, is the weight coefficient of the s-th target abnormal feature.
[0037] In the embodiment, the feature coefficient is used to indicate the abnormal performance feature degree of the corresponding to-be-determined data for the target abnormal feature. The greater the coefficient difference value caused by the data difference value is, the greater the feature coefficient is, and vice versa.
[0038] In the embodiment, the greater the occurrence frequency is, the greater the frequency of the same to-be-determined data contained in the to-be-determined data mapped by the same target abnormal feature in different sets of mapping logs is. The greater the occurrence frequency is, the greater the compensation coefficient is, and vice versa. The value range of the compensation coefficient is (0.8, 1.2).
[0039] In some embodiments of the present application, the weight of the corresponding feature data is set according to the comprehensive feature coefficient, including: A comprehensive feature coefficient threshold is set in advance; The to-be-determined data with the comprehensive feature coefficient greater than the comprehensive feature coefficient threshold is set as the feature data of the behavior type corresponding to the set of mapping logs; A comprehensive feature coefficient difference value is generated according to the comprehensive feature coefficient and the comprehensive feature coefficient threshold; A first weight coefficient of the corresponding feature data is set according to the comprehensive feature coefficient difference value of the feature data of the same behavior type, and a second weight coefficient of the corresponding feature data is set according to the sequence similarity difference value of the feature data of the same behavior type; The weight of the corresponding feature data is generated according to the first weight coefficient and the second weight coefficient.
[0040] In the embodiment, the greater the integrated feature coefficient difference value is, the greater the first weight coefficient is, and vice versa. The sequence similarity difference value is calculated according to the sequence similarity and the sequence similarity threshold value. The greater the sequence similarity difference value is, the greater the second weight coefficient is, and vice versa.
[0041] In the embodiment, the weight = the first weight coefficient * 0.7 + the second weight coefficient * 0.3.
[0042] In the embodiment, by determining the feature data and matching the corresponding weight, the network mapping behavior analysis sub-model of different behavior types is constructed as the training input data set, the mapping behavior analysis efficiency and accuracy are improved, and the network security protection level is improved.
[0043] In some embodiments of the present application, the network mapping behavior analysis model is obtained, including: According to all feature data of the same mapping log set and the weight of each feature data as the training input data set, the historical abnormal feature of the corresponding behavior type is taken as the training output data set; According to the training input data set and the training output data set, neural network training is performed to obtain the network mapping behavior analysis sub-model of the corresponding behavior type; According to the network mapping behavior analysis sub-model of different behavior types, model fusion is performed to obtain the network mapping behavior analysis model; Based on the network mapping behavior analysis model, real-time mapping traffic data is analyzed to obtain a real-time mapping behavior analysis report, and it is judged whether to generate an early warning signal.
[0044] In the embodiment, the real-time mapping behavior analysis report includes whether there is an abnormal behavior. If yes, the behavior type is determined and the real-time abnormal feature is determined, the operation behavior of the current abnormal behavior in the future period is predicted, and if there is an abnormal behavior or an abnormal behavior in the future period, an early warning signal is sent.
[0045] In some embodiments of the present application, as shown in Figure 2 Also includes a network mapping behavior analysis system based on historical data: The acquisition module is used for acquiring historical mapping logs and extracting the behavior type of each historical mapping log, dividing the historical mapping logs according to the behavior type, and obtaining a plurality of mapping log sets; The determination module is used for extracting historical mapping traffic data of each historical mapping log and performing cleaning and standardization processing to obtain standard mapping traffic data and combine historical abnormal features for comprehensive analysis, calculating the integrated feature coefficient according to the analysis result, and determining the feature data of different behavior types; The analysis module is configured to set weights of the corresponding feature data according to the comprehensive feature coefficients, and perform neural network training on the feature data, the corresponding weights and the historical abnormal features to obtain a network mapping behavior analysis model and generate a real-time mapping behavior analysis report to determine whether to generate an early warning instruction.
[0046] The above merely describes the preferred embodiments of the present application. It should be noted that those skilled in the art can make several improvements and replacements without departing from the technical principles of the present application, and these improvements and replacements should also be considered as the protection scope of the present application.
Claims
1. A method for network mapping behavior analysis based on historical data, characterized in that, The method comprises the following steps: acquiring historical mapping logs and extracting the behavior types of each historical mapping log, dividing the historical mapping logs according to the behavior types to obtain a plurality of mapping log sets; extracting the historical mapping traffic data of each historical mapping log and performing cleaning and standardization processing to obtain standard mapping traffic data and perform comprehensive analysis in combination with historical abnormal features, calculating comprehensive feature coefficients according to the analysis results and determining feature data of different behavior types; setting the weights of the corresponding feature data according to the comprehensive feature coefficients, and performing neural network training on the feature data, the corresponding weights and the historical abnormal features to obtain a network mapping behavior analysis model and generate a real-time mapping behavior analysis report to determine whether to generate an early warning instruction.
2. The method of claim 1, wherein the historical data-based network mapping behavior analysis method is characterized by, The historical mapping logs are divided according to the behavior types to obtain a plurality of mapping log sets, which comprise: the behavior types include normal behavior and abnormal behavior; the historical mapping logs with abnormal behavior are analyzed to determine the historical abnormal features of the corresponding abnormal behavior in the historical mapping logs, and each historical abnormal feature is mapped with a corresponding historical abnormal coefficient; the historical abnormal features in different historical mapping logs are analyzed in terms of correlation degree to obtain the correlation degree of the abnormal behavior of different historical mapping logs; the historical mapping logs with abnormal behavior are divided according to the correlation degree, and a plurality of mapping log sets are constructed according to the division results; each mapping log set includes a plurality of historical mapping logs.
3. The method of claim 2, wherein the historical data is obtained from a network management system (NMS) or an element management system (EMS). The historical mapping traffic data of each historical mapping log is preprocessed and standardized to obtain standard mapping traffic data, which comprises: the historical mapping traffic data of each historical mapping log in the same mapping log set is preprocessed, and the preprocessing includes filling in missing values, removing abnormal values and duplicate data; the preprocessed historical mapping traffic data is standardized, and the standardization processing includes unifying data format and time-space benchmark alignment processing; standard mapping traffic data of each historical mapping log is generated.
4. The method of claim 3, wherein the historical data is obtained from a network management system (NMS) or an element management system (EMS). comprehensive analysis is performed in combination with historical abnormal features, comprehensive feature coefficients are calculated according to the analysis results, and feature data of different behavior types are determined, which comprises: a historical mapping log in the same mapping log set is randomly selected as a target mapping log; the similarity coefficient of each historical abnormal feature of the target mapping log and the historical abnormal features of other historical mapping logs is calculated; the historical abnormal features with a similarity coefficient greater than a preset similarity coefficient threshold are selected and set as target abnormal features; the coefficient difference between the historical abnormal coefficient of each target abnormal feature of the target mapping log and the historical abnormal coefficient of the corresponding historical abnormal feature of other historical mapping logs in the same mapping log set is calculated; the historical abnormal coefficient, the corresponding historical abnormal feature and the historical mapping log with a coefficient difference less than a preset coefficient difference threshold are removed, and a comparison abnormal feature matrix of the target mapping log is constructed according to the historical abnormal features and the historical abnormal coefficients of the remaining historical mapping logs; wherein the historical abnormal coefficients of the historical abnormal features of the remaining historical mapping logs are sorted in descending order of the coefficient difference. The coefficient difference value of the historical abnormality coefficient of a target abnormality feature of the target mapping log and the historical abnormality feature corresponding to the remaining historical mapping logs in the comparison abnormality feature matrix, and the target abnormality feature of the target mapping log; The comparison abnormality feature matrix of each historical mapping log in the same mapping log set is generated in sequence; The historical time node of each target abnormality feature in the comparison abnormality feature matrix is determined, and the comparison data matrix of the target mapping log and other historical mapping logs in the comparison abnormality feature matrix is obtained based on the same time principle. The comparison data matrix and the comparison abnormality feature matrix are segmented to obtain a comparison sequence group, and the comparison sequence group includes a comparison data sequence and a comparison abnormality feature sequence; Sequence similarity is generated according to the comparison sequence group; The comprehensive feature coefficient of each pending data is calculated and the feature data is determined according to the sequence similarity.
5. The method of claim 4, wherein the historical data-based network mapping behavior analysis method is characterized by, The comparison data matrix and the comparison abnormality feature matrix are segmented to obtain a comparison sequence group, including: According to each comparison abnormality feature matrix, a plurality of standard mapping flow data of the target mapping log and other historical mapping logs at the same historical time node are extracted; Each standard mapping flow data of the target mapping log is compared with the standard mapping flow data corresponding to other historical mapping logs in the comparison abnormality feature matrix to obtain a plurality of data difference values of each standard mapping flow data; The plurality of data difference values of each standard mapping flow data are sorted according to the column sorting mode of the comparison abnormality feature matrix to obtain a plurality of comparison data matrices of the comparison abnormality feature matrix; Each comparison data matrix is mapped with a target abnormality feature, and the plurality of data difference values are sorted according to the arrangement order of the coefficient difference value of the historical abnormality coefficient of the mapped target abnormality feature; Each comparison data matrix is mapped with a target abnormality feature, and the plurality of data difference values are sorted according to the arrangement order of the coefficient difference value of the historical abnormality coefficient of the mapped target abnormality feature; Each comparison data matrix is mapped with a target abnormality feature, and the plurality of data difference values are sorted according to the arrangement order of the coefficient difference value of the historical abnormality coefficient of the mapped target abnormality feature; Each column of the comparison data matrix is set as a data difference value of a standard mapping flow data of the target mapping log and a standard mapping flow data corresponding to the remaining historical mapping logs, and is a plurality of standard mapping flow data of the target mapping log; 6. The method of claim 5, wherein the historical data-based network mapping behavior analysis method is characterized by, Each column of each target abnormality feature in the comparison abnormality feature matrix is set as a comparison abnormality feature sequence, and each column of each standard mapping flow data in the comparison data matrix mapped by the target abnormality feature is set as a comparison data sequence; The comparison abnormality feature sequence and the plurality of comparison data sequences mapped by the comparison data matrix are randomly combined to obtain a plurality of comparison sequence groups. The sequence similarity includes: A plurality of sequence similarity evaluation indexes are preset; Each comparison sequence group is evaluated for similarity based on the plurality of sequence similarity evaluation indexes to obtain a sub-similarity of each sequence similarity evaluation index; ; wherein D is a sequence similarity, is a sub-similarity of the ith sequence similarity evaluation index, and ai is a weight coefficient of the ith sequence similarity evaluation index.
7. The method of claim 5, wherein the historical data-based network mapping behavior analysis method is characterized by, The sequence similarity of the corresponding comparison sequence group is generated according to the plurality of sub-similarities; The calculation formula of the sequence similarity is: The comprehensive feature coefficient of each pending data is calculated and the feature data is determined, including: A sequence similarity threshold is preset; The standard mapping flow data with a sequence similarity greater than the sequence similarity threshold is set as the pending data of the mapped target abnormality feature; According to the coefficient difference value of the matching sequence of the pending data and the target abnormal feature and the corresponding data difference value, a feature coefficient is generated; The pending data of the target abnormal feature of all the matching abnormal feature matrices in the same set of mapping logs are compared and analyzed to obtain the occurrence frequency and the average feature coefficient of the same pending data for the same target abnormal feature; According to the occurrence frequency of the same pending data for the same target abnormal feature, a compensation coefficient is set; According to the number of target abnormal features mapped by the same pending data, the average feature coefficient, the compensation coefficient, and the weight coefficient of the corresponding target abnormal feature, a comprehensive feature coefficient of the corresponding pending data is generated; The calculation formula of the comprehensive feature coefficient is: ; wherein T is a comprehensive feature coefficient, m is the number of target abnormal features mapped by the current pending data, m0 is the total number of target abnormal features, is the feature coefficient mean of the current specific data and the s-th target abnormal feature, is the compensation coefficient of the s-th target abnormal feature, is the weight coefficient of the s-th target abnormal feature.
8. The method of claim 7, wherein the historical data-based network mapping behavior analysis method is characterized by, According to the comprehensive feature coefficient, the weight of the corresponding feature data is set, including: The comprehensive feature coefficient threshold is set in advance; The pending data with a comprehensive feature coefficient greater than the comprehensive feature coefficient threshold is set as the feature data of the behavior type corresponding to the set of mapping logs; According to the comprehensive feature coefficient and the comprehensive feature coefficient threshold, a comprehensive feature coefficient difference value is generated; According to the comprehensive feature coefficient difference value of the feature data of the same behavior type, a first weight coefficient of the corresponding feature data is set, and according to the sequence similarity difference value of the feature data of the same behavior type, a second weight coefficient of the corresponding feature data is set; According to the first weight coefficient and the second weight coefficient, the weight of the corresponding feature data is generated.
9. The method of claim 8, wherein the historical data-based network mapping behavior analysis method is characterized by, A network mapping behavior analysis model is obtained, including: According to all the feature data of the same set of mapping logs and the weight of each feature data as the training input data set, the historical abnormal features of the corresponding behavior type are taken as the training output data set; According to the training input data set and the training output data set, neural network training is performed to obtain a network mapping behavior analysis sub-model of the corresponding behavior type; According to the network mapping behavior analysis sub-models of different behavior types, model fusion is performed to obtain a network mapping behavior analysis model; Based on the network mapping behavior analysis model, real-time mapping traffic data is analyzed to obtain a real-time mapping behavior analysis report, and it is judged whether to generate an early warning signal.
10. A network cartography behavior analysis system based on historical data, characterized in that, Including: The acquisition module is used to acquire historical mapping logs and extract the behavior type of each historical mapping log, divide the historical mapping logs according to the behavior type, and obtain multiple sets of mapping logs; The determination module is used to extract the historical mapping traffic data of each historical mapping log and perform cleaning and standardization processing to obtain standard mapping traffic data and combine the historical abnormal features for comprehensive analysis, calculate the comprehensive feature coefficient according to the analysis result, and determine the feature data of different behavior types; The analysis module is used to set the weight of the corresponding feature data according to the comprehensive feature coefficient, and perform neural network training on the feature data, the corresponding weight, and the historical abnormal features to obtain a network mapping behavior analysis model, generate a real-time mapping behavior analysis report, and determine whether to generate an early warning instruction.