Communication network security control method
By constructing a network security map with data feature layer and IP feature layer, the problem of insufficient accuracy in existing communication network security control methods is solved, and comprehensive and accurate identification and security judgment of network input data are achieved.
Patent Information
- Application Number
- CN202511666042.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-14
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-11-14
AI Technical Summary
Existing communication network control methods cannot perform comprehensive and accurate data security identification of network input data based on the actual security situation of the communication network, resulting in a lack of accuracy in security control.
Construct the data feature layer and IP feature layer of the target communication network, and use the network security map to comprehensively identify network input data, determine its security, and allow or block data interaction.
It enables comprehensive and accurate security identification of network input data based on the actual security situation of the communication network, thereby improving the accuracy of communication network security control.
Smart Images

Figure CN121125363A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication network, and in particular to a communication network security control method. BACKGROUND
[0002] At present, with the rapid development of information technology, communication network has become an indispensable infrastructure in social production and life, and is widely used in key fields such as finance, government affairs, medical treatment and industrial control. With the evolution of communication technology from 4G to 5G and 6G, and the deep integration of network and Internet of Things, cloud computing, edge computing and industrial control, the application scenarios of communication network have been expanded from "personal terminal communication" to "Internet of Everything", and the source, type and scale of network input data have increased explosively. However, while communication network carries massive data transmission and service interaction, it also faces increasingly serious security threats such as illegal intrusion, data leakage and malicious attack. These security risks not only lead to user information leakage and enterprise core data damage, but also may pose a serious threat to the stable operation of critical information infrastructure. Therefore, how to build an efficient and reliable communication network security control system has become a core problem to be solved in the current communication technology field.
[0003] The communication network control method in the related art cannot comprehensively and accurately identify the data security of network input data according to the actual security situation of the communication network, resulting in a lack of accuracy in the security control of the communication network, and there is room for improvement. SUMMARY
[0004] The purpose of the embodiments of the present application is to provide a communication network security control method to improve the problem that the communication network control method in the related art cannot comprehensively and accurately identify the data security of network input data according to the actual security situation of the communication network, resulting in a lack of accuracy in the security control of the communication network.
[0005] The present application provides a communication network security control method, comprising: Step S1: obtaining network security data of a target communication network, wherein the network security data comprises preset security data and a preset security IP; Step S2: generating a security data factor and a factor connection track according to the preset security data, and constructing a data feature layer of the target communication network according to the security data factor and the factor connection track; generating a security IP factor according to the preset security IP, and constructing an IP feature layer of the target communication network according to the security IP factor; and constructing a network security map of the target communication network according to the data feature layer and the IP feature layer; Step S3: obtaining network input data of the target communication network, and obtaining input data features and input IP features contained in the network input data; Step S4: inputting the input data features of the network input data into the data feature layer of the network security map, analyzing to obtain a data anomaly coefficient of the network input data, and judging a first data security feature of the network input data according to the data anomaly coefficient; inputting the input IP features of the network input data into the IP feature layer of the network security map, analyzing to obtain an IP anomaly coefficient of the network input data, and judging a second data security feature corresponding to the network input data according to the IP anomaly coefficient; Step S5: judging the data security of the network input data according to the first data security feature and the second data security feature; Step S6: if the data security of the network input data is normal, allowing the network input data to perform data interaction with the target communication network; if the data security of the network input data is abnormal, not allowing the network input data to perform data interaction with the target communication network.
[0006] Further, the network security data includes preset security data and a preset security IP, specifically: The preset security data includes data basic features and data correlation relationships; and the preset security IP includes IP behavior features.
[0007] Further, a security data factor and a factor connection track are generated according to the preset security data, and a data feature layer of the target communication network is constructed according to the security data factor and the factor connection track, specifically: A security data factor corresponding to the preset security data is generated based on the preset security data in the target communication network; A security data factor feature corresponding to the security data factor is generated according to the data basic features of the preset security data; wherein the data basic features include a security data type, a security data source, a security data transmission mode and a security data transmission frequency of the preset security data; A factor correlation direction corresponding to the security data factor is obtained according to the data correlation relationships of the preset security data; and a factor correlation track between the security data factors is obtained according to the factor correlation direction; The data feature layer of the target communication network is constructed based on the security data factor and the factor correlation track between the security data factors.
[0008] Further, a security IP factor is generated according to the preset security IP, and an IP feature layer of the target communication network is constructed according to the security IP factor, specifically: A security IP factor corresponding to the preset security IP is generated based on the preset security IP in the target communication network; According to the IP behavior characteristics of the preset security IP, a security IP factor feature corresponding to a security IP factor is generated; wherein the IP behavior characteristics include IP transmission data types, IP transmission time periods and IP transmission frequencies of the preset security IP; According to the security IP factor and the security IP factor feature corresponding to the security IP factor, an IP feature layer of the target communication network is constructed.
[0009] Further, according to the data feature layer and the IP feature layer, a network security map of the target communication network is constructed, specifically: The data feature layer and the IP feature layer in the network security map adopt a data parallel detection mode to perform data detection on network input data.
[0010] Further, network input data of the target communication network is obtained, and input data features and input IP features contained in the network input data are obtained, specifically: Based on the data basic features, data feature extraction is performed on the network input data, to obtain input data features corresponding to the network input data; Input IP data corresponding to the network input data is obtained, and based on the IP behavior characteristics, IP feature extraction is performed on the input IP data, to obtain input IP features corresponding to the network input data.
[0011] Further, the input data features of the network input data are input into the data feature layer of the network security map, and a data anomaly coefficient of the network input data is analyzed and obtained, specifically: According to the network input data, an input data factor is generated, and based on the input data features corresponding to the network input data, an input data factor feature corresponding to the input data factor is generated; The input data factor is input into the data feature layer of the network security map, and the input data factor and the security data factor in the data feature layer are matched in data content, to obtain a factor matching degree of the input data factor and the security data factor; The security data factor with the highest factor matching degree with the input data factor is recorded as a target security data factor; and the input data factor feature of the input data factor and the security data factor feature of the target security data factor are compared in feature, to obtain an abnormal data factor feature of the input data factor; A data feature weight value corresponding to the security data factor feature is set; the data feature weight values corresponding to the abnormal data factor features in the input data factor are accumulated and calculated, to obtain a data feature anomaly coefficient of the network input data; A factor correlation track of the target security data factor corresponding to the input data factor is obtained, and according to the factor correlation track, an influence factor number of the input data factor is obtained; According to the data feature anomaly coefficient and the influence factor number, a data anomaly coefficient of the network input data is obtained.
[0012] Further, according to the data anomaly coefficient, a first data security feature of the network input data is judged, specifically: If the data anomaly coefficient of the network input data is less than a preset data anomaly coefficient threshold, the first data security feature of the network input data is judged to be normal. If the data anomaly coefficient of the network input data is greater than or equal to the preset data anomaly coefficient threshold, the first data security feature of the network input data is judged to be abnormal.
[0013] Further, the input IP feature of the network input data is input into an IP feature layer of the network security graph, an IP anomaly coefficient of the network input data is analyzed and obtained, and according to the IP anomaly coefficient, a second data security feature corresponding to the network input data is judged, specifically: According to the input IP data of the network input data, an input IP factor is generated, and an input IP factor feature corresponding to the input IP factor is generated based on the input IP feature; The input IP factor is input into the IP feature layer of the network security graph, and the input IP factor is matched with a security IP factor in the IP feature layer to obtain a target security IP factor corresponding to the input IP factor; The input IP factor feature of the input IP factor is compared with a security IP factor feature of the target security IP factor to obtain an abnormal IP factor feature of the input IP factor; An IP feature weight corresponding to the security IP factor feature is set, and the IP feature weight corresponding to the abnormal IP factor feature is accumulated to obtain an IP anomaly coefficient of the network input data; If the IP anomaly coefficient is less than a preset IP anomaly coefficient threshold, the second data security feature of the network input data is judged to be normal; if the IP anomaly coefficient is greater than or equal to the preset IP anomaly coefficient threshold, the second data security feature of the network input data is judged to be abnormal.
[0014] Further, according to the first data security feature and the second data security feature, the data security of the network input data is judged, specifically: If at least one of the first data security feature and the second data security feature of the network input data is abnormal, the data security of the network input data is judged to be abnormal; If the first data security feature and the second data security feature of the network input data are both normal, the data security of the network input data is judged to be normal.
[0015] In summary, the beneficial effects of the present application are as follows: the preset security data of the target communication network is used to construct a data feature layer of the target communication network, the preset security IP of the target communication network is used to construct an IP feature layer of the target communication network, and a network security map of the target communication network is constructed according to the data feature layer and the IP feature layer. In addition, input data features and input IP features contained in network input data are obtained, the input data features of the network input data are input into the data feature layer of the network security map to obtain first data security features of the network input data, the input IP features of the network input data are input into the IP feature layer of the network security map to obtain second data security features corresponding to the network input data, and the data security of the network input data is judged according to the first data security features and the second data security features. Finally, if the data security of the network input data is normal, the network input data is allowed to interact with the target communication network for data; if the data security of the network input data is abnormal, the network input data is not allowed to interact with the target communication network for data, so that the network input data is comprehensively and accurately identified according to the actual security situation of the communication network, and the accuracy of the communication network security control is improved. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, some of the drawings in the embodiments of the present application will be briefly described below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be considered as limiting the scope of the present application.
[0017] Figure 1 A flowchart of a communication network security control method provided by the present application. DETAILED DESCRIPTION
[0018] The embodiments of the present application will be further described below, but the embodiments of the present application are not limited thereto. Figure 1 The embodiments of the present application will be further described below, but the embodiments of the present application are not limited thereto.
[0019] Referring to Figure 1 FIG. 1 shows a flowchart of a communication network security control method provided by an embodiment of the present application.
[0020] A communication network security control method comprises: Step S1: obtaining network security data of a target communication network, the network security data comprising preset security data and preset security IP; Step S2: generating a security data factor and a factor connection track according to the preset security data, and constructing a data feature layer of the target communication network according to the security data factor and the factor connection track; generating a security IP factor according to the preset security IP, and constructing an IP feature layer of the target communication network according to the security IP factor; and constructing a network security map of the target communication network according to the data feature layer and the IP feature layer; Step S3: obtaining network input data of the target communication network, and obtaining input data features and input IP features contained in the network input data; Step S4: inputting the input data features of the network input data into the data feature layer of the network security map, analyzing to obtain a data anomaly coefficient of the network input data, and judging a first data security feature of the network input data according to the data anomaly coefficient; inputting the input IP features of the network input data into the IP feature layer of the network security map, analyzing to obtain an IP anomaly coefficient of the network input data, and judging a second data security feature corresponding to the network input data according to the IP anomaly coefficient; Step S5: judging the data security of the network input data according to the first data security feature and the second data security feature; Step S6: if the data security of the network input data is normal, allowing the network input data to interact with the target communication network; if the data security of the network input data is abnormal, not allowing the network input data to interact with the target communication network.
[0021] The network security data includes preset security data and preset security IP, and specifically includes: The preset security data includes data basic features and data correlation relationships; and the preset security IP includes IP behavior features.
[0022] In some embodiments, the data basic features include a security data type, a security data source, a security data transmission mode and a security data transmission frequency of the preset security data; in addition, the data basic features can also be personalized to select data features as the data basic features according to actual network needs of the target communication network. In addition, the data correlation relationship can be a cause-effect relationship of the preset security data, for example, preset security data one changes, which causes preset security data two and preset security data three to change, so that preset security data one, preset security data two and preset security data three have a data correlation relationship, and preset security data one is the cause data, and preset security data two and preset security data three are the effect data.
[0023] In some embodiments, the IP can be an identity that can identify a username, a device code, a website domain name, etc., the IP behavior characteristics include IP transmission data types, IP transmission time periods, and IP transmission frequencies of the preset security IP; in addition, the IP basic characteristics can also be personalized to select IP characteristics as the IP behavior characteristics according to the actual network demand of the target communication network.
[0024] According to the preset security data, a security data factor and a factor connection track are generated, and a data feature layer of the target communication network is constructed according to the security data factor and the factor connection track, specifically: A security data factor corresponding to the preset security data is generated based on the preset security data in the target communication network; A security data factor characteristic corresponding to the security data factor is generated according to the data basic characteristics of the preset security data; wherein the data basic characteristics include a security data type, a security data source, a security data transmission mode, and a security data transmission frequency of the preset security data; A factor association direction corresponding to the security data factor is generated according to the data association relationship of the preset security data; and a factor association track between the security data factors is obtained according to the factor association direction; A data feature layer of the target communication network is constructed based on the security data factor and the factor association track between the security data factors.
[0025] In some embodiments, the target communication network can include at least one preset security data, each of the preset security data corresponds to a security data factor, and the preset security data and the security data factor are one-to-one corresponding; in addition, each of the security data factors corresponds to a security data factor characteristic, wherein the security data factor characteristic corresponds to the data basic characteristics, such as the data basic characteristics including a security data type, a security data source, a security data transmission mode, and a security data transmission frequency of the preset security data, the security data factor characteristic also includes the security data type, the security data source, the security data transmission mode, and the security data transmission frequency; In some embodiments, if the data association relationship is a cause-effect association relationship, the cause data or the effect data associated with the preset security data can be obtained, the factor association direction of the preset security data is generated, wherein the factor association direction is the cause data pointing to the effect data; in addition, the security data factors are connected to each other through the factor association track.
[0026] According to the preset security IP, a security IP factor is generated, and an IP feature layer of the target communication network is constructed according to the security IP factor, specifically: A security IP factor corresponding to the preset security IP is generated based on the preset security IP in the target communication network; According to the IP behavior characteristics of the preset security IP, a security IP factor feature corresponding to the security IP factor is generated; wherein the IP behavior characteristics include the IP transmission data type, the IP transmission time period and the IP transmission frequency of the preset security IP; According to the security IP factor and the security IP factor feature corresponding to the security IP factor, an IP feature layer of the target communication network is constructed.
[0027] In some embodiments, the target communication network can include at least one preset security IP, each of which corresponds to a security IP factor, and each of the preset security IP corresponds to a security IP factor; in addition, each of the security IP factors corresponds to a security IP factor feature, wherein the security IP factor feature corresponds to the IP behavior characteristics, such as the IP transmission data type, the IP transmission time period and the IP transmission frequency of the preset security IP, and the security IP factor feature also includes the IP transmission data type, the IP transmission time period and the IP transmission frequency; In some embodiments, the IP feature layer includes the security IP factors corresponding to all the preset security IP of the target communication network.
[0028] According to the data feature layer and the IP feature layer, a network security map of the target communication network is constructed, specifically: The data feature layer and the IP feature layer in the network security map use data parallel detection to detect the network input data.
[0029] In some embodiments, data parallel detection refers to inputting the input data features and the input IP features of the network input data into the data feature layer and the IP feature layer respectively after the network input data is input into the network security map, and simultaneously detecting the data and the IP of the network input data.
[0030] The network input data of the target communication network is obtained, and the input data features and the input IP features contained in the network input data are obtained, specifically: Based on the data basic features, the data features of the network input data are extracted to obtain the input data features corresponding to the network input data; The input IP data corresponding to the network input data is obtained, and based on the IP behavior characteristics, the IP features of the input IP data are extracted to obtain the input IP features corresponding to the network input data.
[0031] In some embodiments, the data basic features are the data basic features of the preset security data, including the security data type, the security data source, the security data transmission mode and the security data transmission frequency; in addition, the data basic features can also be personalized according to the actual network demand of the target communication network to select data features as the data basic features.
[0032] In some embodiments, the IP behavior feature is an IP behavior feature of a preset secure IP, including an IP transmission data type, an IP transmission time period, and an IP transmission frequency; in addition, the IP basic feature can also select an IP feature as the IP behavior feature according to the actual network demand of the target communication network.
[0033] The input data feature of the network input data is input into the data feature layer of the network security graph, and a data anomaly coefficient of the network input data is obtained by analysis, specifically as follows: An input data factor is generated according to the network input data, and an input data factor feature corresponding to the input data factor is generated based on the input data feature corresponding to the network input data; The input data factor is input into the data feature layer of the network security graph, and the input data factor and the security data factor in the data feature layer are matched in data content to obtain a factor matching degree of the input data factor and the security data factor; The security data factor with the highest factor matching degree with the input data factor is recorded as a target security data factor; and the input data factor feature of the input data factor and the security data factor feature of the target security data factor are compared to determine and obtain an abnormal data factor feature of the input data factor; A data feature weight corresponding to the security data factor feature is set; the data feature weight corresponding to the abnormal data factor feature in the input data factor is accumulated to obtain a data feature anomaly coefficient of the network input data; A factor correlation track corresponding to the target security data factor of the input data factor is obtained, and the number of influence factors of the input data factor is obtained according to the factor correlation track; The data anomaly coefficient of the network input data is obtained according to the data feature anomaly coefficient and the number of influence factors.
[0034] In some embodiments, the network input data corresponds to the input data factor, and the input data factor corresponds to an input data factor feature, wherein the input data factor feature corresponds to the input data feature corresponding to the network input data; for example, the input data factor feature corresponding to the input data factor includes a security data type, a security data source, and a security data transmission mode; In some embodiments, the factor matching degree is a matching degree of data content of the input data factor and the security data factor; the feature comparison of the input data factor feature of the input data factor and the security data factor feature of the target security data factor means corresponding feature comparison of the input data factor feature and the security data factor feature, i.e., if the input data factor feature includes the security data type, the security data source and the security data transmission mode, and the security data factor feature includes the security data type, the security data source and the security data transmission mode, the security data type, the security data source and the security data transmission mode in the input data factor feature are compared with the security data type, the security data source and the security data transmission mode in the security data factor feature respectively. At this time, if the security data type in the input data factor feature is inconsistent with the security data type in the security data factor feature, the security data type is determined as an abnormal data factor feature; if the security data transmission mode in the input data factor feature is inconsistent with the security data transmission mode in the security data factor feature, the security data transmission mode is also determined as an abnormal data factor feature.
[0035] In some embodiments, each security data factor feature corresponds to a data feature weight value, and the specific value of the data feature weight value can be preset according to the important influence degree of each feature in the security data factor feature on the communication network security; in addition, the data feature weight value corresponding to the abnormal data factor feature can be obtained by the input data factor corresponding to the security data factor feature of the target security data factor, and the data feature weight value corresponding to the abnormal data factor feature is consistent with the data feature weight value corresponding to the security data factor feature of the target security data factor; In some embodiments, the data anomaly coefficient of the network input data can be calculated by the following calculation function: data anomaly coefficient = data feature anomaly coefficient + (data feature anomaly coefficient * influence factor number).
[0036] and judging the first data security feature of the network input data according to the data anomaly coefficient, specifically: If the data anomaly coefficient of the network input data is less than the preset data anomaly coefficient threshold, the first data security feature of the network input data is determined as normal; If the data anomaly coefficient of the network input data is greater than or equal to the preset data anomaly coefficient threshold, the first data security feature of the network input data is determined as abnormal.
[0037] The input IP feature of the network input data is input into the IP feature layer of the network security graph, the IP anomaly coefficient of the network input data is analyzed, and the second data security feature corresponding to the network input data is judged according to the IP anomaly coefficient, specifically: An input IP factor is generated according to input IP data corresponding to network input data, and input IP factor features corresponding to the input IP factor are generated based on input IP features corresponding to the input IP data; The input IP factor is input into an IP feature layer of the network security graph, and IP matching is performed between the input IP factor and a security IP factor in the IP feature layer to obtain a target security IP factor corresponding to the input IP factor; Feature comparison is performed between input IP factor features corresponding to the input IP factor and security IP factor features of the target security IP factor, and abnormal IP factor features of the input IP factor are determined and obtained; An IP feature weight corresponding to the security IP factor features is set, and IP feature weights corresponding to the abnormal IP factor features are accumulated to obtain an IP anomaly coefficient of the network input data; If the IP anomaly coefficient is less than a preset IP anomaly coefficient threshold, it is determined that a second data security feature of the network input data is normal, and if the IP anomaly coefficient is greater than or equal to the preset IP anomaly coefficient threshold, it is determined that the second data security feature of the network input data is abnormal.
[0038] In some embodiments, the input IP data corresponds to the input IP factor, and each input IP factor corresponds to input IP factor features, wherein the input IP factor features correspond to IP behavior features; if the IP behavior features include IP transmission data types, IP transmission time periods, and IP transmission frequencies, the input IP factor features corresponding to the input IP factor also include the IP transmission data types, the IP transmission time periods, and the IP transmission frequencies. In some embodiments, IP content of the target security IP factor is consistent with IP content of the input IP factor, such as consistent usernames, consistent device codes, or consistent domain names.
[0039] In some embodiments, the feature comparison between the input IP factor feature of the input IP factor and the security IP factor feature of the target security IP factor means that the input IP factor feature and the security IP factor feature are compared in corresponding features, i.e. if the input IP factor feature contains IP transmission data type, IP transmission time period and IP transmission frequency, and the security IP factor feature contains IP transmission data type, IP transmission time period and IP transmission frequency, then the IP transmission data type, IP transmission time period and IP transmission frequency in the input IP factor feature are compared with the IP transmission data type, IP transmission time period and IP transmission frequency in the security IP factor feature respectively. At this time, if the IP transmission time period in the input IP factor feature is inconsistent with the IP transmission time period in the security IP factor feature, then the IP transmission time period is judged as an abnormal IP factor feature; if the IP transmission frequency in the input IP factor feature is inconsistent with the IP transmission frequency in the security IP factor feature, then the IP transmission frequency is also judged as an abnormal IP factor feature.
[0040] The data security of the network input data is judged according to the first data security feature and the second data security feature, specifically: If at least one of the first data security feature and the second data security feature of the network input data is abnormal, then the data security of the network input data is judged as abnormal; If the first data security feature and the second data security feature of the network input data are both normal, then the data security of the network input data is judged as normal.
[0041] The above is only the preferred embodiment of the present application, and the protection scope of the present application is not limited to the above-mentioned embodiments, and any technical solution falling within the idea of the present application is within the protection scope of the present application. It should be noted that, for ordinary technical personnel in the technical field, some improvements and refinements without departing from the principles of the present application are also considered as the protection scope of the present application.
Claims
1. A communication network security control method, characterized in that, include: Step S1: Obtain network security data of the target communication network, wherein the network security data includes preset security data and preset security IP; Step S2: Generate security data factors and factor connection trajectories based on the preset security data, and construct the data feature layer of the target communication network based on the security data factors and factor connection trajectories; Based on the preset security IP, a security IP factor is generated, and based on the security IP factor, an IP feature layer of the target communication network is constructed; based on the data feature layer and the IP feature layer, a network security map of the target communication network is constructed. Step S3: Obtain the network input data of the target communication network, and obtain the input data characteristics and input IP characteristics contained in the network input data; Step S4: Input the input data features of the network input data into the data feature layer of the network security graph, analyze and obtain the data anomaly coefficient of the network input data, and determine the first data security feature of the network input data based on the data anomaly coefficient; input the input IP features of the network input data into the IP feature layer of the network security graph, analyze and obtain the IP anomaly coefficient of the network input data, and determine the second data security feature corresponding to the network input data based on the IP anomaly coefficient; Step S5: Determine the data security of the network input data based on the first data security feature and the second data security feature; Step S6: If the data security of the network input data is normal, then allow the network input data to interact with the target communication network; If the data security of the network input data is abnormal, then the network input data is not allowed to interact with the target communication network.
2. The communication network security control method according to claim 1, characterized in that, The network security data includes preset security data and preset security IPs, specifically: The preset security data includes basic data characteristics and data relationships; the preset security IP includes IP behavior characteristics.
3. The communication network security control method according to claim 2, characterized in that, Based on the preset security data, security data factors and factor connection trajectories are generated, and a data feature layer of the target communication network is constructed based on the security data factors and factor connection trajectories, specifically as follows: Generate security data factors corresponding to the preset security data based on the preset security data in the target communication network; Based on the basic characteristics of the preset security data, generate security data factor features corresponding to the security data factors; The basic characteristics of the data mentioned above include the secure data type, secure data source, secure data transmission method, and secure data transmission frequency of the preset secure data; Based on the data association relationship of the preset security data, the factor association pointer corresponding to the security data factor is obtained; And based on the aforementioned factor correlation pointers, the factor correlation trajectories between security data factors are obtained; The data feature layer of the target communication network is constructed based on the security data factors and the factor correlation trajectories between the security data factors.
4. A communication network security control method according to claim 3, characterized in that, Based on the preset security IP, a security IP factor is generated, and based on the security IP factor, an IP feature layer of the target communication network is constructed, specifically as follows: Generate a security IP factor corresponding to a preset security IP based on a preset security IP in the target communication network; Based on the IP behavior characteristics of the preset security IP, generate security IP factor characteristics corresponding to the security IP factors; The IP behavioral characteristics mentioned above include the IP transmission data type, IP transmission time period, and IP transmission frequency of the preset secure IP; An IP feature layer of the target communication network is constructed based on the security IP factor and the security IP factor characteristics corresponding to the security IP factor.
5. A communication network security control method according to claim 4, characterized in that, Based on the data feature layer and IP feature layer, a network security map of the target communication network is constructed, specifically as follows: The data feature layer and IP feature layer in the network security graph use parallel data detection to detect network input data.
6. A communication network security control method according to claim 5, characterized in that, Obtain the network input data of the target communication network, and obtain the input data characteristics and input IP characteristics contained in the network input data, specifically: Based on the basic characteristics of the data, data features are extracted from the network input data to obtain the input data features corresponding to the network input data. Obtain the input IP data corresponding to the network input data, and extract IP features from the input IP data based on the IP behavior features to obtain the input IP features corresponding to the network input data.
7. A communication network security control method according to claim 6, characterized in that, The input data features of the network input data are input into the data feature layer of the network security graph, and the data anomaly coefficient of the network input data is obtained through analysis. Specifically: Based on the network input data, input data factors are generated, and based on the input data features corresponding to the network input data, input data factor features corresponding to the input data factors are generated. The input data factors are input into the data feature layer of the network security graph, and the input data factors are matched with the security data factors in the data feature layer to obtain the factor matching degree between the input data factors and the security data factors. The security data factor that has the highest factor matching degree with the input data factor is recorded as the target security data factor; The input data factor features are compared with the security data factor features of the target security data factor to obtain the abnormal data factor features of the input data factor. Set the data feature weights corresponding to the security data factor features; accumulate the data feature weights corresponding to the abnormal data factor features in the input data factors to obtain the data feature anomaly coefficient of the network input data; Obtain the factor correlation trajectory of the target security data factor corresponding to the input data factor, and obtain the number of influence factors of the input data factor based on the factor correlation trajectory; The data anomaly coefficient of the network input data is obtained based on the data feature anomaly coefficient and the number of influencing factors.
8. A communication network security control method according to claim 7, characterized in that, And based on the aforementioned data anomaly coefficient, the first data security characteristic of the network input data is determined, specifically as follows: If the data anomaly coefficient of the network input data is less than the preset data anomaly coefficient threshold, then the first data security feature of the network input data is determined to be normal. If the data anomaly coefficient of the network input data is greater than or equal to the preset data anomaly coefficient threshold, then the first data security feature of the network input data is determined to be abnormal.
9. A communication network security control method according to claim 8, characterized in that, The input IP characteristics of the network input data are input into the IP characteristic layer of the network security graph. The IP anomaly coefficient of the network input data is analyzed to obtain the IP anomaly coefficient. Based on the IP anomaly coefficient, the second data security characteristic corresponding to the network input data is determined. Specifically: An input IP factor is generated based on the input IP data corresponding to the network input data, and an input IP factor feature corresponding to the input IP factor is generated based on the input IP feature. The input IP factor is input into the IP feature layer of the network security graph, and the input IP factor is matched with the security IP factor in the IP feature layer to obtain the target security IP factor corresponding to the input IP factor. The input IP factor features corresponding to the input IP factor are compared with the security IP factor features of the target security IP factor to obtain the abnormal IP factor features of the input IP factor. Set the IP feature weights corresponding to the secure IP factor features; accumulate the IP feature weights corresponding to the abnormal IP factor features to obtain the IP anomaly coefficient of the network input data; If the IP anomaly coefficient is less than a preset IP anomaly coefficient threshold, the second data security feature of the network input data is determined to be normal; if the IP anomaly coefficient is greater than or equal to the preset IP anomaly coefficient threshold, the second data security feature of the network input data is determined to be abnormal.
10. A communication network security control method according to claim 9, characterized in that, The data security of network input data is determined based on the first data security feature and the second data security feature, specifically as follows: If at least one of the first data security features and the second data security features of the network input data is abnormal, then the data security of the network input data is determined to be abnormal. If both the first and second data security features of the network input data are normal, then the data security of the network input data is determined to be normal.
Citation Information
Patent Citations
Network protection method and system based on IP map
CN118041582A
Intelligent network security protection method and system based on big data
CN118413368A
Network security detection method and device for power Internet of Things, and electronic equipment
CN119172135A
Power business data security capability dynamic scheduling analysis method and system
CN120017314A
System and method for providing network security
US20070039047A1