Honey array situation map analysis method and device, medium and electronic equipment

By combining multi-head attention mechanism and graph neural network, the problem of insufficient dynamic feature capture in honeycomb situational analysis is solved, realizing multi-dimensional expression of node features and accurate identification of security situation.

CN121125354AActive Publication Date: 2025-12-12INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Patent Information

Application Number
CN202511657280.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-13
Publication Date
2025-12-12
Estimated Expiration
2045-11-13

AI Technical Summary

Technical Problem

Existing honeycomb situation analysis methods lack the ability to capture the dynamic evolution of the honeycomb attack and defense situation. The characteristics of nodes with different security attributes are easily confused, making it difficult to effectively integrate the traffic characteristics between nodes and limiting the dimension and richness of node feature expression.

Method used

A multi-head attention mechanism is used to enhance edge feature representation, and a graph neural network is used to aggregate node features. By calculating the similarity of the security state of a node with its neighboring nodes and dynamic traffic features, the final representation of the node is generated for security state prediction.

Benefits of technology

It accurately captures the dynamic characteristics of attack traffic in honeycomb scenarios, reduces feature obfuscation, enhances the richness and accuracy of node features, and strengthens the ability to perceive the network security situation of honeycomb networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125354A_ABST
    Figure CN121125354A_ABST
Patent Text Reader

Abstract

The invention provides a honey matrix situation map analysis method and device, a medium and electronic equipment. The honey matrix situation map analysis method comprises the steps that collected data are processed to form honey matrix network data; constructing a honey matrix situation map based on the honey matrix network data; performing time sequence modeling on the feature sequence of the edge, performing enhancement by applying a multi-head attention mechanism to obtain an enhanced edge feature representation, calculating an importance score of the edge, and performing weighted summation on the enhanced edge feature representation of the direct connection edge of the node to obtain a dynamic traffic feature of the node; selecting a new neighbor node set according to the security state similarity of the node and the initial neighbor node thereof, and obtaining node feature representation based on the new neighbor node set; and according to the node feature representation and the dynamic flow feature of the node, generating a final representation of the node feature, and performing node security state prediction to obtain a security state category. By applying the method, multi-level and multi-dimensional expression of the node features can be realized, the richness of the node features is enhanced, and the sensing precision of the honey array network security situation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a honeycomb situation analysis method, apparatus, medium, and electronic device. Background Technology

[0002] To counter evolving attack methods, honeypot technology is widely used as a proactive defense strategy. It lures attackers into a virtual environment and collects their behavioral data, thereby enabling early identification and prevention of potential threats.

[0003] However, traditional honeypot deployments struggle to adapt to real-time adjustments based on attacker dynamics and network environment changes. Against this backdrop, honey arrays have emerged as an extension of the honeypot concept. Composed of multiple honeypots, a honey array simulates a more complex and distributed network environment, designed to attract and confuse more sophisticated attackers, offering richer attack detection and analysis capabilities than a single honeypot. However, its deployment and management complexity also increases significantly. Therefore, effectively analyzing and identifying the honey array's situational awareness, mining its security status information, and adjusting deployment promptly have become crucial for improving honey array defense effectiveness.

[0004] While existing honeycomb situation analysis methods have improved their analytical performance with the help of graph neural networks, they still have significant limitations: they lack the ability to capture the dynamic evolution of the honeycomb's offensive and defensive situation; the node features of different security attributes are easily confused, reducing the model's discriminative ability; and they are also difficult to effectively integrate the traffic features between nodes, limiting the dimension and richness of node feature expression.

[0005] Therefore, it is necessary to provide a honeycomb situation diagram analysis method to improve the ability to identify the security status of nodes in the honeycomb situation diagram. Summary of the Invention

[0006] The purpose of this invention is to provide a honeycomb situation diagram analysis method, apparatus, medium, and electronic device to improve the ability to identify the security status of nodes in a honeycomb situation diagram.

[0007] In a first aspect, the honeycomb network situation map analysis method provided by the present invention includes: collecting multi-source data streams from a honeycomb network to obtain collected data; performing data preprocessing on the collected data to form honeycomb network data; and constructing a honeycomb network situation map based on the honeycomb network data, wherein the honeycomb network situation map is represented as follows: ,in, Represents a set of nodes. The system represents a set of edges. It performs temporal modeling on the feature sequences of edges within the set and applies a multi-head attention mechanism to enhance edge feature representations. Based on the connections between nodes, it calculates the importance score of edges using the node's feature vector representation and the enhanced edge feature representation. It then performs a weighted summation of the enhanced edge feature representations of the nodes' directly connected edges based on the importance score to obtain the node's dynamic flow characteristics. The system calculates the similarity of the security state of a node to its initial neighbor nodes, sorts the initial neighbor nodes based on this similarity, and selects the top k% of neighbor nodes to form a new set of neighbor nodes. Based on this new set of neighbor nodes, it aggregates node features to obtain node feature representations. Finally, it generates the node feature representation based on the node feature representation and the node's dynamic flow characteristics. Finally, it predicts the node's security state category based on the final node feature representation.

[0008] The beneficial effects of the honeycomb situational analysis method provided by this invention are as follows: it can fully characterize the dynamic characteristics of attack traffic in the honeycomb scenario, accurately capture its changing patterns over time, and inject real-time attack and defense dynamic information into node features; it filters a set of neighboring nodes with strong correlations and then aggregates the features of the filtered neighbors to ensure that the aggregation process focuses on nodes with security attributes and reduces feature confusion; it can realize the expression of node features at multiple levels and dimensions such as structure and dynamics, enhance the richness of node features, and improve the accuracy of perception of the network security situation of the honeycomb network.

[0009] In one possible embodiment, temporal modeling is performed on the feature sequences of edges in the edge set, and a multi-head attention mechanism is applied to enhance and obtain an enhanced edge feature representation. This includes: performing forward temporal modeling on the feature sequences of edges to generate a hidden state sequence representing historical dependencies and performing reverse temporal modeling to generate a hidden state sequence representing future dependencies; concatenating the two hidden state sequences to obtain the edge feature representation; applying a multi-head attention mechanism to calculate the attention weights of m attention heads; concatenating the m attention weights and performing linear projection to obtain the enhanced edge feature representation.

[0010] In another possible embodiment, based on the connection relationships between nodes, the importance score of an edge is calculated using the node's feature vector representation and enhanced edge feature representation. The dynamic flow characteristics of the node are then obtained by weighted summation of the enhanced edge feature representations of the directly connected edges based on the importance score. This includes: the edge importance score calculation satisfies the following formula: ,in, Representing an edge Importance score This represents the activation function. This represents the learnable attention parameter matrix. For nodes The eigenvector representation, For nodes With nodes Connecting edges The enhanced edge feature representation, Represents nodes The set of directly connected edges, express The Middle Bars and nodes The connected edges; the weighted summation of the enhanced edge feature representations of the directly connected edges of nodes based on importance scores satisfies the following formula: ,in, This represents the dynamic traffic characteristics of a node.

[0011] In other possible embodiments, security-related features are extracted from the feature vectors of nodes to construct security feature vectors, which are then used in the honeycomb situation diagram to correlate with the nodes. The directly connected neighbor nodes are used as the initial neighbor node set of a node. The similarity of the security states of a compute node and its initial neighbor nodes includes: compute nodes With the initial set of neighbor nodes Each neighbor node in The cosine similarity of the security feature vectors is calculated according to the following formula: ,in, Represents a node The security feature vector, Represents a node The security feature vector.

[0012] Obtaining node feature representations by aggregating node features based on the new neighbor node set includes: aggregating the features of the node itself and its new neighbor nodes in the convolutional layer of the graph neural network. Node feature representation updates in convolutional layers; splicing The node feature representations of the convolutional layers are updated and input into the fully connected layers to obtain node feature representations of the fused graph structure information.

[0013] The final representation of node features is generated based on the node feature representation and the node's dynamic traffic characteristics. The node security status is then predicted based on this final representation to obtain the security status category. The final representation of node features is generated according to the following formula: ,in, The final representation of node features. This represents the learnable parameter matrix of the fully connected layer used to fuse node features and dynamic traffic features. Representing node features, It represents the dynamic traffic characteristics of a node; predicts the probability distribution of a node's security status based on the final representation of the node's characteristics; and obtains the node's security status category based on the probability distribution of the node's security status.

[0014] Data preprocessing for the collected data includes: dividing the collected data into training and testing sets; cleaning and standardizing the data in the training set; and standardizing the data in the testing set.

[0015] Secondly, the present invention also provides a honeycomb network situation map analysis device, comprising: a data acquisition unit, used to acquire multi-source data streams in a honeycomb network to obtain acquired data, and to perform data preprocessing on the acquired data to form honeycomb network data; and a situation map construction unit, used to construct a honeycomb network situation map based on the honeycomb network data, wherein the honeycomb network situation map is represented as follows: ,in, Represents a set of nodes. The system comprises: an edge set; a flow feature generation unit, used to perform temporal modeling on the feature sequences of edges in the edge set and apply a multi-head attention mechanism to enhance the edge feature representation; an important score of the edge is calculated based on the feature vector representation of the node and the enhanced edge feature representation according to the connection relationship between nodes; a weighted sum of the enhanced edge feature representations of the directly connected edges of the node is performed based on the importance score to obtain the dynamic flow feature of the node; a node feature generation unit, used to calculate the similarity of the security state of a node with its initial neighbor nodes; the initial neighbor nodes are sorted based on the similarity of the security state, and the top k% of the neighbor nodes are selected to form a new set of neighbor nodes corresponding to the node; node feature aggregation is performed on the corresponding nodes based on the new set of neighbor nodes to obtain the node feature representation; and a prediction unit, used to generate the final representation of the node features based on the node feature representation and the dynamic flow feature of the node, and to predict the node security state category based on the final representation of the node features.

[0016] Thirdly, the present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described honeycomb situation diagram analysis method.

[0017] Fourthly, the present invention also provides an electronic device, comprising: a processor and a memory; the memory being used to store a computer program; the processor being used to execute the computer program stored in the memory, so that the electronic device performs the above-described honeycomb situation analysis method.

[0018] For the beneficial effects of the second to fourth aspects mentioned above, please refer to the description of the first aspect mentioned above. Attached Figure Description

[0019] Figure 1A flowchart illustrating a honeycomb situation diagram analysis method provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of the execution flow of a honeycomb situation diagram analysis method provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of a honeycomb situation analysis device provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of an electronic device structure provided in an embodiment of the present invention. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions in the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without inventive effort are within the scope of protection of this invention. Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by those skilled in the art. The terms "comprising" and similar expressions used herein mean that the element or object preceding the word covers the element or object listed following the word and its equivalents, but do not exclude other elements or objects.

[0021] This embodiment provides a honeycomb situation diagram analysis method, device, medium, and electronic equipment.

[0022] See Figure 1 and Figure 2 Honeycomb situation analysis methods include: S101: Collect data from multiple data streams in the honeycomb network, and perform data preprocessing on the collected data to form honeycomb network data.

[0023] In one possible embodiment, collecting multi-source data streams in the honeycomb network specifically includes collecting network traffic data, security device log data, and device status detection data. Network traffic data refers to metrics such as throughput, round-trip time, and pulse signal strength; security device log data refers to metrics such as the number of security alarms, security audit coverage, number of security devices, and vulnerability exploitation frequency; and device status detection data refers to metrics such as the lifespan of critical devices. Due to the multi-source and heterogeneous nature of the data sources, the collected data needs to be preprocessed to form honeycomb network data.

[0024] In a honeycomb network, the security status of nodes is divided into high risk, medium risk, suspicious, unknown risk, isolated and no risk, from high to low.

[0025] In one possible embodiment, data preprocessing of the collected data includes: dividing the collected data into a training set and a test set; performing data cleaning and data standardization on the data in the training set; and performing data standardization on the data in the test set.

[0026] In one specific embodiment, after the collected data is obtained, it is divided into a training set and a test set. Preprocessing of the collected data includes data cleaning and data standardization. Data standardization is applicable to preprocessing data in both the training and test sets, while data cleaning is only applicable to preprocessing data in the training set.

[0027] For example, data cleaning includes: handling missing and duplicate values ​​using appropriate methods for different types of data streams. For instance, for time-series data such as traffic data and device status monitoring data, linear interpolation is used to fill missing values, and duplicate records are deleted by timestamp comparison; for security device log data, isolated missing log entries are skipped, and completely duplicate log records are deleted; for node security attribute data (such as vulnerability exploitation frequency and security alert count), the mode is used to fill discrete missing values ​​to ensure feature integrity. Data standardization includes: scaling the data proportionally. The purpose of standardization is to eliminate differences in data features, making the impact of different features on the model roughly the same. For example, Min-Max normalization can be used for data standardization, with the following formula: ,in, Represents the original feature values. Represents the normalized eigenvalues. This represents the minimum value among the original features. This represents the maximum value among the original features.

[0028] S102: Construct a honeycomb situation map based on honeycomb network data. The honeycomb situation map is represented as follows: ,in, Represents a set of nodes. Represents the set of edges.

[0029] In one possible embodiment, the honey array situation diagram In, node set It consists of honeypot entities in the honeycomb network, each node For each honeypot, its characteristics are constructed based on honeypot behavioral data, including the number of security alerts, security audit coverage, number of security devices, vulnerability exploitation frequency, average lifetime of critical devices within the sub-gateway, and subnet traffic change rate. The node feature matrix is ​​represented as follows: , where nodes The eigenvectors are represented as Edge set Characterizing the traffic interactions along the honeypot attack path, each edge Indicates that the attacker started from the node To the node Traffic relationships generated during an attack. Edge features are constructed based on real-time traffic data, including throughput, round-trip time, pulse signal strength, and timestamp. Due to the temporal nature of traffic, edges... The features are represented as time series ,in express Time Node To node Traffic characteristics.

[0030] S103: Perform time-series modeling on the feature sequences of edges in the edge set and apply a multi-head attention mechanism to enhance the edge feature representation. Based on the connection relationship between nodes, calculate the importance score of the edge using the feature vector representation of the node and the enhanced edge feature representation. Based on the importance score, perform a weighted summation of the enhanced edge feature representation of the directly connected edges of the node to obtain the dynamic flow feature of the node.

[0031] In one possible embodiment, temporal modeling is performed on the feature sequences of edges in the edge set, and a multi-head attention mechanism is applied to enhance and obtain an enhanced edge feature representation. This includes: performing forward temporal modeling on the feature sequences of edges to generate a hidden state sequence representing historical dependencies and performing reverse temporal modeling to generate a hidden state sequence representing future dependencies; concatenating the two hidden state sequences to obtain the edge feature representation; applying a multi-head attention mechanism to calculate the attention weights of m attention heads; concatenating the m attention weights and performing linear projection to obtain the enhanced edge feature representation.

[0032] Based on the connectivity between nodes, the importance score of an edge is calculated using the node's feature vector representation and the enhanced edge feature representation. The dynamic flow characteristics of the node are then obtained by weighted summation of the enhanced edge feature representations of the directly connected edges based on these importance scores. The edge importance score calculation satisfies the following formula: ,in, Representing an edge Importance score This represents the activation function. This represents the learnable attention parameter matrix. For nodes The eigenvector representation, For nodes With nodes Connecting edges The enhanced edge feature representation, Represents nodes The set of directly connected edges, express The Middle Bars and nodes The connected edges; based on the importance score, the enhanced edge feature representation of the directly connected edges of the nodes is weighted and summed to satisfy the following formula: ,in, This represents the dynamic traffic characteristics of a node.

[0033] In a specific embodiment, for the edge set Each edge Feature sequences Timing modeling is performed using a bidirectional gated cyclic unit (BiGRU). The BiGRU consists of a forward GRU and a backward GRU: the forward GRU operates sequentially over time (…). Process the sequence to generate a sequence of hidden states representing historical dependencies. Reverse GRU in reverse time order ( Process the sequence to generate a sequence of hidden states representing future dependencies. By concatenating two hidden state sequences, a side feature representation incorporating bidirectional temporal information is obtained. The process of generating edge feature representations through temporal modeling of the sequence features of edges satisfies the following formula: , , By using bidirectional modeling, we can not only capture the historical dependencies of network traffic, but also use information from subsequent moments to create a more accurate characterization of the persistence or periodicity of attack traffic patterns.

[0034] A multi-head attention mechanism is introduced to enhance edge feature representations to further explore nonlinear interaction patterns between features. Specifically, the multi-head attention mechanism... Multiple parallel attention heads capture semantic information from different feature subspaces. This represents a hyperparameter, the value of which is set according to the specific task scenario and performance requirements. For the first... Each attention point is first used to generate a query through a linear transformation. ),key( ),value( The vector is then processed through an attention mechanism to calculate the output attention weights, and finally concatenated. The output of each attention head is linearly projected to obtain the enhanced edge feature representation. A multi-head attention mechanism is introduced to enhance the edge feature representation. The calculation of the enhanced edge feature representation satisfies the following formula: , ,in, Indicates the first The attention weights output by each attention head. , and They represent the first A matrix of query, key, and value parameters for each attention head. Represents the key vector Dimensions Used for and The dot product result is scaled to avoid gradient vanishing; ,in, This represents the output projection parameter matrix. Multi-head parallel computation is used to simultaneously model multi-dimensional flow patterns in different semantic spaces, improving the expressive power of edge features.

[0035] The enhanced edge feature representations are weighted and aggregated to generate dynamic flow features for nodes, thus associating the temporal features of edges with node attributes. Specifically, the attention mechanism learns the association strength between nodes and edges, calculating an importance score for each edge: ,in, This represents the learnable attention parameter matrix. This represents the activation function (LeakyReLU is usually chosen). This represents the concatenation operation. Based on importance scores, nodes are obtained by weighted summation of the temporal characteristics of all directly connected edges. Dynamic traffic characteristics: Weighted aggregation of enhanced edge feature representations to generate dynamic traffic features enables nodes to focus their dynamic traffic features more on edges that significantly impact their security status (such as edges carrying abnormal attack traffic), effectively improving the discriminative power of the features.

[0036] In honeycomb scenarios, attack path traffic often exhibits complex patterns such as nonlinear mutations and multi-path coupling. Conventional temporal modeling methods, such as recurrent neural networks, struggle to fully characterize these dynamic features, and existing methods lack a collaborative modeling framework for graph structure and traffic temporal sequence. This solution strengthens causal relationships through bidirectional dependency modeling of edge feature sequences and enhances feature discriminative power by combining a multi-head attention mechanism. Furthermore, it utilizes the attention mechanism to map temporal modeling results to nodes, thereby effectively addressing the unique challenges of honeycomb environments.

[0037] S104: Calculate the security state similarity between a node and its initial neighbor nodes, sort the initial neighbor nodes based on the security state similarity, select the top k% of the neighbor nodes to form a new set of neighbor nodes corresponding to the node, and perform node feature aggregation on the corresponding node based on the new set of neighbor nodes to obtain the node feature representation.

[0038] In one possible implementation, security-related features are extracted from the feature vectors of nodes to construct security feature vectors, which are then used in the honeycomb situation diagram to correlate with the nodes. The directly connected neighbor nodes are used as the initial neighbor node set of a node. The similarity of the security states of a compute node and its initial neighbor nodes includes: compute node With the initial set of neighbor nodes Each neighbor node in The cosine similarity of the security feature vectors is calculated according to the following formula: ,in, Represents a node The security feature vector, Represents a node The security feature vector.

[0039] In one possible embodiment, obtaining node feature representations by aggregating node features based on the new neighbor node set includes: aggregating the features of the node itself and its new neighbor nodes in the convolutional layer of the graph neural network. Node feature representation updates in convolutional layers; splicing The node feature representations of the convolutional layers are updated and input into the fully connected layers to obtain node feature representations of the fused graph structure information.

[0040] For example, security-related features are extracted from the feature vectors of nodes to construct security feature vectors, such as those for nodes in a honeycomb situation map. From its eigenvectors Extract security-related features, including the number of security alerts, security audit coverage, number of security devices, vulnerability exploitation frequency, and average lifetime of critical devices within sub-gateways, to construct a security feature vector. Based on security feature vectors, using nodes Initial set of neighbor nodes (i.e., situation diagram and) The candidate range is defined by directly connected nodes, and the nodes are calculated. With each neighbor node The cosine similarity of the security feature vectors between them is used as the security state similarity between them, and is calculated according to the following formula: ,in, Represents a node The security feature vector, Represents a node The security feature vector.

[0041] Based on nodes The similarity of the security states between the nodes and their neighbors in the initial neighbor set is determined using a Top-K sampling strategy. The neighbors are sorted from highest to lowest similarity, and the top K% (usually set to 50%) nodes are selected as the security state similarity. New Neighbor Node Set .

[0042] Based on the new set of neighboring nodes, feature aggregation is performed on the node itself and its neighboring node sets. For example, for nodes in the honeycomb situation map... The node feature aggregation process of a graph convolutional network satisfies the following formula: ,in, Represents a node In convolutional layers The updated feature representation after feature aggregation. Represents a node In the feature representation of the previous layer , Agg represents an aggregation function (usually a degree-normalized weighted summation). Represents a convolutional layer Learnable parameter matrix. The outputs of nodes in the intermediate layers of the graph convolutional network are concatenated, and the concatenated result is then input into a fully connected layer to obtain node feature representations that fuse graph structure information. The concatenation process satisfies the following formula: ,in, This represents the total number of layers in the graph convolutional network (the number can be flexibly set according to the size of the graph dataset). This represents the learnable parameter matrix of the fully connected layer used to fuse the update features of each convolutional layer node in the graph convolutional network.

[0043] This invention selects neighbors with strong security attributes related to the target node and employs a TopK sampling strategy to select a set of neighboring nodes with strong security attribute associations for each node. This ensures that subsequent feature aggregation in the graph neural network focuses more on neighboring nodes with high correlation to the target node, thereby reducing interference from irrelevant or heterogeneous features. The shallow layers of the neural network collect and integrate local information, extracting relevant information reflecting local topological characteristics through interactions with neighboring nodes. The deep layers capture global information across a larger graph structure, summarizing and fusing information from various local regions to outline the macroscopic features and global topological state of the entire graph. Finally, the outputs generated by nodes in the intermediate layers of the graph convolutional network are concatenated to represent local and global information in the node features.

[0044] S105: Generate the final representation of node features based on the node feature representation and the node's dynamic traffic features, and predict the node's security status to obtain the security status category based on the final representation of node features.

[0045] In one possible embodiment, a final representation of node features is generated based on the node feature representation and the node's dynamic traffic characteristics. A security state category is then predicted based on this final representation, including: the final representation of node features is generated according to the following formula: ,in, The final representation of node features. This represents the learnable parameter matrix of the fully connected layer used to fuse node features and dynamic traffic features. Representing node features, It represents the dynamic traffic characteristics of a node; predicts the probability distribution of a node's security status based on the final representation of the node's characteristics; and obtains the node's security status category based on the probability distribution of the node's security status.

[0046] For example, for nodes whose security status needs to be identified in the honeycomb situation diagram The node features learned through a fully connected layer fusion graph convolutional network Dynamic traffic characteristics of nodes The final representation of the generated node features: ,in, The final representation of node features. This represents the learnable parameter matrix of the fully connected layer used to fuse node features and dynamic traffic features. The final representation of the node features is input into the Softmax function to obtain the predicted probability distribution of the node's security state. The safety status category of a node is determined based on the maximum value of the predicted probability distribution.

[0047] In one possible embodiment, after constructing a model for honeycomb situational analysis according to the designed method, the model parameters are optimized based on the training set using a cross-entropy loss function, which satisfies the following formula: ,in, Represents a node The true label (using one-hot encoding, security status is) (If it is 1, then it is 0). Indicates the predicted node's safe state is The probability, Indicates the number of training samples. The label representing the security status of a node. , This represents the number of safe states. The predicted probability distribution is optimized by minimizing the loss function. The model is trained to approximate the true label as closely as possible, and the final safety status category of the node is determined based on the maximum probability. After training, its performance is evaluated using a test set.

[0048] The honeycomb situation analysis method provided by this invention designs a method that uses bidirectional gated cyclic units to perform time-series modeling of the traffic of attack paths in the honeycomb network and combines it with a multi-head attention mechanism for enhancement. This method accurately captures the changing patterns of traffic dynamics over time, solves the problem of insufficient dynamic situation characterization by traditional methods, injects real-time attack and defense dynamic information into node features, and improves the ability to capture dynamic traffic features.

[0049] Similarity is calculated based on node security features, and a TopK sampling strategy is used to select the set of neighboring nodes with the strongest correlation. This ensures that the feature aggregation process fully considers the correlation between security states of nodes, avoiding feature confusion caused by aggregating node features with excessively different security states. Furthermore, a graph convolutional network is used to aggregate the selected neighboring features, ensuring that the aggregation process focuses on nodes with related security attributes, reducing feature confusion, and enhancing the discriminative power of node features and the robustness of the model.

[0050] By fusing the structural features and dynamic traffic features output by the graph neural network through a fully connected layer, the node features are expressed at multiple levels and dimensions, including structure and dynamics, thereby enhancing the richness of node features and improving the model's perception accuracy of the honeycomb network security situation.

[0051] See the instruction manual appendix Figure 3 This embodiment also provides a honeycomb situation map analysis device, which is used to implement the above method embodiment. The device includes: The acquisition unit 201 is used to acquire multi-source data streams in the honeycomb network to obtain acquired data, and to perform data preprocessing on the acquired data to form honeycomb network data.

[0052] Situation map construction unit 202 is used to construct a honeycomb situation map based on honeycomb network data. The honeycomb situation map is represented as follows: ,in, Represents a set of nodes. Represents the set of edges.

[0053] The flow feature generation unit 203 is used to perform time-series modeling on the feature sequence of edges in the edge set and apply a multi-head attention mechanism to enhance the edge feature representation. Based on the connection relationship between nodes, the importance score of the edge is calculated using the feature vector representation of the node and the enhanced edge feature representation. The enhanced edge feature representation of the directly connected edges of the node is weighted and summed based on the importance score to obtain the dynamic flow feature of the node.

[0054] The node feature generation unit 204 is used to calculate the security state similarity between a node and its initial neighbor nodes, sort the initial neighbor nodes based on the security state similarity, select the top k% of the neighbor nodes to form a new neighbor node set corresponding to the node, and perform node feature aggregation on the corresponding node based on the new neighbor node set to obtain the node feature representation.

[0055] The prediction unit 205 is used to generate the final representation of node features based on the node feature representation and the dynamic traffic features of the node, and to predict the node security status category based on the final representation of node features.

[0056] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.

[0057] In other embodiments of this application, an electronic device is disclosed, such as... Figure 4 As shown, the electronic device 300 may include: one or more processors 301; a memory 302; a display 303; one or more application programs (not shown); and one or more computer programs 304. These devices can be connected via one or more communication buses 305. The one or more computer programs 304 are stored in the memory and configured to be executed by the one or more processors 301. The one or more computer programs 304 include instructions that can be used to perform actions such as... Figure 1 And the various steps in the corresponding embodiments.

[0058] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0059] In the embodiments of this application, the functional units can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0060] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as flash memory, portable hard disk, read-only memory, random access memory, magnetic disk, or optical disk.

[0061] The above description is merely a specific implementation of the embodiments of this application, but the protection scope of the embodiments of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the embodiments of this application should be covered within the protection scope of the embodiments of this application. Therefore, the protection scope of the embodiments of this application should be determined by the protection scope of the claims.

Claims

1. A method for analyzing honeycomb formation situation diagrams, characterized in that, include: Collect data by acquiring multi-source data streams in the honeycomb network, and perform data preprocessing on the acquired data to form honeycomb network data; A honeycomb situation map is constructed based on the honeycomb network data, and the honeycomb situation map is represented as follows: ,in, Represents a set of nodes. Represents the set of edges; Temporal modeling is performed on the feature sequence of the edges in the edge set, and a multi-head attention mechanism is applied to enhance the edge feature representation. Based on the connection relationship between nodes, the importance score of the edge is calculated using the feature vector representation of the node and the enhanced edge feature representation. The enhanced edge feature representation of the directly connected edges of the node is weighted and summed based on the importance score to obtain the dynamic flow feature of the node. Calculate the security state similarity between a node and its initial neighbor nodes, sort the initial neighbor nodes based on the security state similarity, select the top k% of the neighbor nodes to form a new set of neighbor nodes corresponding to the node, and perform node feature aggregation on the corresponding node based on the new set of neighbor nodes to obtain the node feature representation. The final representation of node features is generated based on the node feature representation and the node's dynamic traffic features. The node security status is then predicted based on the final representation of node features to obtain the security status category.

2. The method according to claim 1, characterized in that, Temporal modeling is performed on the feature sequences of edges in the edge set, and a multi-head attention mechanism is applied to enhance and obtain enhanced edge feature representations, including: Forward temporal modeling is performed on the feature sequence of the edge to generate a hidden state sequence representing historical dependencies, and backward temporal modeling is performed to generate a hidden state sequence representing future dependencies. The two hidden state sequences are concatenated to obtain the edge feature representation. A multi-head attention mechanism is applied to calculate the attention weights of m attention heads, and the m attention weights are concatenated and linearly projected to obtain an enhanced edge feature representation.

3. The method according to claim 1, characterized in that, Based on the connection relationships between nodes, importance scores of edges are calculated using the node's feature vector representation and enhanced edge feature representation. The dynamic flow characteristics of the nodes are then obtained by weighted summation of the enhanced edge feature representations of the nodes' directly connected edges based on these importance scores. This includes: The importance score of an edge is calculated according to the following formula: ,in, Representing an edge Importance score This represents the activation function. This represents the learnable attention parameter matrix. For nodes The eigenvector representation, For nodes With nodes Connecting edges The enhanced edge feature representation, Represents nodes The set of directly connected edges, express The Middle Bars and nodes Connecting edges; The weighted summation of the enhanced edge feature representations of the directly connected edges of the nodes based on the importance scores satisfies the following formula: ,in, This represents the dynamic traffic characteristics of a node.

4. The method according to claim 1, characterized in that, Security-related features are extracted from the feature vectors of nodes to construct security feature vectors, which are then used in the honeycomb situation diagram to correlate with nodes. The directly connected neighbor nodes are used as the initial neighbor node set of a node. ; The similarity of the security states of a compute node to its initial neighbor nodes includes: compute nodes With the initial set of neighbor nodes Each neighbor node in The cosine similarity of the security feature vectors is calculated according to the following formula: ,in, Represents a node The security feature vector, Represents a node The security feature vector.

5. The method according to claim 1, characterized in that, Based on the new set of neighboring nodes, node feature aggregation is performed on the corresponding nodes to obtain node feature representations, including: In the convolutional layer of a graph neural network, features of the node itself and its new neighboring nodes are aggregated to obtain... The node update feature representation of the convolutional layer; splicing The node feature representations of the convolutional layers are updated and input into the fully connected layers to obtain node feature representations of the fused graph structure information.

6. The method according to claim 1, characterized in that, Based on the node feature representation and the node's dynamic traffic characteristics, a final representation of the node features is generated. Based on this final representation, the node's security status is predicted to obtain a security status category, including: The final representation of node features is generated according to the following formula: ,in, The final representation of node features. This represents the learnable parameter matrix of the fully connected layer used to fuse node features and dynamic traffic features. Representing node features, Represents the dynamic traffic characteristics of a node; The probability distribution of a node's security state is predicted based on the final representation of its features, and the node's security state category is obtained based on the probability distribution of its security state.

7. The method according to claim 1, characterized in that, Data preprocessing of the collected data includes: The collected data is divided into a training set and a test set; The data in the training set is cleaned and standardized, and the data in the test set is standardized.

8. A honeycomb situation analysis device, characterized in that, The device includes: The acquisition unit is used to acquire multi-source data streams in the honeycomb network to obtain acquired data, and to perform data preprocessing on the acquired data to form honeycomb network data; The situation map construction unit is used to construct a honeycomb situation map based on the honeycomb network data, wherein the honeycomb situation map is represented as follows: ,in, Represents a set of nodes. Represents the set of edges; The flow feature generation unit is used to perform time-series modeling on the feature sequence of the edges in the edge set and apply a multi-head attention mechanism to enhance the edge feature representation. Based on the connection relationship between nodes, the importance score of the edge is calculated using the feature vector representation of the node and the enhanced edge feature representation. Based on the importance score, the enhanced edge feature representation of the directly connected edges of the node is weighted and summed to obtain the dynamic flow feature of the node. The node feature generation unit is used to calculate the security state similarity between a node and its initial neighbor nodes, sort the initial neighbor nodes based on the security state similarity, select the top k% of the neighbor nodes to form a new neighbor node set corresponding to the node, and perform node feature aggregation on the corresponding node based on the new neighbor node set to obtain the node feature representation. The prediction unit is used to generate a final representation of node features based on the node feature representation and the dynamic traffic features of the node, and to predict the node security status category based on the final representation of node features.

9. A computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by the processor, it implements the honeycomb situation diagram analysis method according to any one of claims 1 to 7.

10. An electronic device, characterized in that, include: Processor and memory; The memory is used to store computer programs; The processor is used to execute the computer program stored in the memory to cause the electronic device to perform the honeycomb situation map analysis method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Information processing method and device, equipment and storage medium

    CN116915511A

  • GCN-based honey situation map analysis method

    CN119316238A

  • Node feature construction method based on honey point intelligence and neighborhood weight adaptive updating

    CN119670810A

  • Honeypot configuration method based on graph neural network

    CN120200848A

  • Ai-controlled sensor network for threat mapping and characterization and risk adjusted response

    US20250175456A1

Cited By

  • Honey array driven network security situation awareness method and system

    CN122027363A