Remote sensing satellite network security situational awareness method and system with dual prevention mechanism

By combining a multi-stage data processing workflow with Bayesian networks and deep learning models, a structured dataset is generated and a dynamic security situation map is constructed. This solves the problems of multi-source heterogeneous data fusion and dynamic attack chain reasoning in remote sensing satellite ground system networks, realizes real-time collaborative governance and minute-level source tracing, and improves the network security defense capabilities.

CN121151901BActive Publication Date: 2026-05-26NAT SATELLITE METEOROLOGICAL CENT

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NAT SATELLITE METEOROLOGICAL CENT
Filing Date
2025-10-10
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Remote sensing satellite ground system networks face challenges in real-time fusion of multi-source heterogeneous data and lack dynamic attack chain reasoning mechanisms, resulting in insufficient risk quantification capabilities, delayed vulnerability remediation and threat response, and a lack of collaborative analysis of risk data and potential data, making it impossible to achieve minute-level attack tracing and collaborative decision-making.

Method used

A multi-stage data processing workflow is adopted, which combines Bayesian networks and deep learning models to generate structured datasets, construct risk heat maps and hazard lists, use graph databases and community discovery algorithms to construct dynamic safety situation maps, and combine weighted scoring models and analytic hierarchy process to generate comprehensive safety indices and emergency plans.

Benefits of technology

It enables real-time collaborative governance of multi-source heterogeneous data, enhances the probabilistic reasoning capability of dynamic attack chains, supports minute-level accurate tracing and collaborative decision-making, and improves the defense capability of remote sensing satellite ground system networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121151901B_ABST
    Figure CN121151901B_ABST
Patent Text Reader

Abstract

This invention discloses a remote sensing satellite network security situational awareness method and system with a dual prevention mechanism. The method includes: acquiring multi-source heterogeneous data from a remote sensing satellite ground system network; generating a structured dataset through cleaning, denoising, and standardization; recording network assets using an asset identification algorithm based on the structured dataset; and generating a risk heatmap of the network assets using a Bayesian network model and entropy weighting method; detecting abnormal traffic and behavior using a deep learning model based on the risk heatmap and the structured dataset; and generating a priority-marked list of vulnerabilities using a general vulnerability scoring standard and a threat intelligence database; and constructing a dynamic security situation map using a graph database and community discovery algorithm based on the risk heatmap and the vulnerability list. This invention improves the real-time fusion capability of multi-source heterogeneous data, enhances the dynamic attack chain reasoning mechanism, and enables collaborative decision-making for risk warning and vulnerability management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of remote sensing satellite network security technology, and in particular to a remote sensing satellite network security situational awareness method and system with a dual prevention mechanism. Background Technology

[0002] The cybersecurity of current remote sensing satellite ground systems faces severe challenges: traditional situational awareness technologies adopt a single-point detection mode, and their static rule base is unable to cope with new threats such as AI-generated attacks, resulting in insufficient risk quantification capabilities; there is a time lag between vulnerability remediation and threat response, and the governance of hidden dangers is seriously lagging behind the evolution of attacks; the lack of a collaborative analysis mechanism between risk data and hidden danger data leads to a distortion of the overall situational assessment.

[0003] These problems are particularly prominent in the operation of remote sensing satellite ground systems. To ensure the continuity of global climate monitoring and disaster early warning, it is necessary to integrate heterogeneous data from multiple sources such as data center servers, network equipment and security components in real time. However, there are differences in data formats and protocols among multiple subsystems within the ground system, resulting in data time synchronization and format heterogeneity. Traditional methods cannot construct a unified risk feature vector within the system.

[0004] A more prominent technical bottleneck lies in the fact that, for covert attacks such as malicious command injection and data theft within ground systems, existing technologies are unable to establish a correlation model of attack events between nodes within the system (such as the causal chain of abnormal traffic and illegal access), and also lack the ability to reconstruct multi-node attack paths through dynamic Bayesian inference.

[0005] This results in three major closed-loop defects in the remote sensing satellite ground system network:

[0006] Vulnerability scanning, threat response, and situation assessment are disconnected from each other, making it difficult to achieve attack attribution within minutes.

[0007] Risk warning, hazard identification, and emergency response lack collaborative decision support;

[0008] Internal system anomalies (such as hardware failures) cannot be effectively distinguished from malicious behavior (such as malware implantation).

[0009] The core contradictions are manifested in two major technological gaps:

[0010] First, the challenge of real-time fusion of multi-source heterogeneous data: It is necessary to overcome the spatiotemporal alignment technology of data between multiple independent subsystems within the ground system and extract the joint feature vectors covering the network layer and the application layer;

[0011] Secondly, the dynamic attack chain reasoning mechanism is lacking: a threat propagation probability graph model that integrates the network node topology of the ground system needs to be constructed to achieve a leap in the ability to detect single-point anomalies and reconstruct multi-node attack chains. Summary of the Invention

[0012] This invention provides a remote sensing satellite network security situational awareness method and system with a dual prevention mechanism, which improves the real-time fusion capability of multi-source heterogeneous data, enhances the dynamic attack chain reasoning mechanism, and realizes collaborative decision-making for risk warning and hidden danger management.

[0013] To achieve the above objectives, in a first aspect, this invention provides a remote sensing satellite network security situational awareness method with a dual prevention mechanism, comprising: acquiring multi-source heterogeneous data from a remote sensing satellite ground system network, and generating a structured dataset through cleaning, denoising, and standardization. Based on the structured dataset, network assets are recorded using an asset identification algorithm, and a risk heatmap of the network assets is generated using a Bayesian network model and entropy weighting method. Based on the risk heatmap and the structured dataset, abnormal traffic and behavior are detected using a deep learning model, and a priority-marked list of vulnerabilities is generated using a general vulnerability scoring standard and a threat intelligence database. Based on the risk heatmap and the vulnerability list, a dynamic security situation map is constructed using a graph database and community discovery algorithm. Based on the dynamic security situation map, a comprehensive security index, a remediation priority list, and an emergency response plan are generated using a weighted scoring model and the analytic hierarchy process, and a situational assessment report and governance recommendations are output.

[0014] Secondly, this invention provides a remote sensing satellite network security situation awareness system with a dual prevention mechanism, comprising: a dataset generation module, a heatmap generation module, a vulnerability list generation module, a map construction module, and an output module. The dataset generation module acquires multi-source heterogeneous data from the remote sensing satellite ground system network and generates a structured dataset through cleaning, denoising, and standardization. The heatmap generation module records network assets using an asset identification algorithm based on the structured dataset and generates a risk heatmap of the network assets using a Bayesian network model and entropy weighting method. The vulnerability list generation module detects abnormal traffic and behavior using a deep learning model based on the risk heatmap and the structured dataset, and generates a priority-marked vulnerability list using a general vulnerability scoring standard and a threat intelligence database. The map construction module constructs a dynamic security situation map using a graph database and community discovery algorithm based on the risk heatmap and the vulnerability list. The output module generates a comprehensive security index, a remediation priority list, and an emergency response plan based on the dynamic security situation map using a weighted scoring model and the analytic hierarchy process, and outputs a situation assessment report and governance recommendations.

[0015] Thirdly, the present invention provides an electronic device, comprising:

[0016] At least one processor; and

[0017] A memory that is communicatively connected to the at least one processor;

[0018] The memory stores instructions that can be executed by the at least one processor, which are then executed by the at least one processor to enable the at least one processor to perform the remote sensing satellite network security situational awareness method with the dual prevention mechanism described above.

[0019] Fourthly, the present invention provides a computer-readable storage medium including a computer program and instructions, which, when the computer program or the instructions are executed on a computer, cause the computer to perform the dual prevention mechanism described above for remote sensing satellite network security situational awareness.

[0020] Compared with existing technologies, the remote sensing satellite network security situation awareness method and system based on the dual prevention mechanism of the present invention integrates multi-source heterogeneous data to generate a structured dataset, combines Bayesian networks and deep learning models to dynamically assess risks and construct a security situation map, and finally outputs collaborative governance suggestions. This solves the problems of insufficient multi-source heterogeneous data fusion capability, lack of attack chain reasoning, and lagging risk governance in traditional methods, and has the advantages of improving real-time performance, accuracy, and collaborative decision-making capabilities. Attached Figure Description

[0021] Figure 1 This is a flowchart illustrating a remote sensing satellite network security situational awareness method with a dual prevention mechanism according to Embodiment 1 of the present invention.

[0022] Figure 2 This is a schematic diagram of the structure of a remote sensing satellite network security situational awareness system with a dual prevention mechanism according to Embodiment 2 of the present invention;

[0023] Figure 3 This is a schematic diagram of the structure of an electronic device according to Embodiment 3 of the present invention;

[0024] Figure 4 This is a flowchart illustrating a remote sensing satellite network security situational awareness method with a dual prevention mechanism in a specific embodiment of the present invention. Detailed Implementation

[0025] The embodiments of the present invention will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely illustrative of the present invention and not intended to limit the scope of the invention. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the embodiments of the present invention, and not all structures.

[0026] To facilitate understanding, the main implementation concepts of the various embodiments of the present invention will be briefly described first.

[0027] In traditional network security situational awareness technologies, single-point detection relies on static rule bases for risk identification, making it difficult to quantify the potential impact of new threats. A time lag exists between vulnerability remediation processes and vulnerability discovery, resulting in a lack of synchronization between remediation measures and threat response. Situational assessments cannot establish a dynamic analytical framework from a global perspective due to the lack of unified correlation between risk and vulnerability data. In remote sensing satellite ground system network scenarios, multi-dimensional heterogeneous data such as server logs, operation logs, and network traffic need to be fused in real time. However, differences in data formats and protocols among multiple independent subsystems within the ground system lead to increased data time synchronization errors and significant format differences, making it difficult to construct joint feature vectors. Covert attacks often involve the coordinated manipulation of multiple nodes within the system. Existing technologies cannot effectively correlate attack events within the system; for example, the causal link between abnormal traffic and unauthorized access is not identified, and the lack of dynamic probabilistic reasoning capabilities makes it impossible to reconstruct multi-node attack chains.

[0028] For example, remote sensing satellite ground system networks need to process TCP / IP traffic data and network device logs from server clusters. Due to clock asynchrony within the system causing latency jitter, the timestamp timing benchmarks of different log sources have millisecond-level deviations, resulting in a misalignment between traffic behavior sequences and device states. Attackers exploit vulnerabilities in internal system protocols to forge control commands, synchronously injecting them into operation and maintenance management ports, triggering service anomalies between system nodes. Existing detection models only match known attack patterns based on single-point traffic statistical features, without establishing a probability model of attack paths between nodes within the system. This makes it impossible to distinguish between performance fluctuations caused by hardware failures and malicious software attacks, leading to an increased false positive rate and missed detections of critical attack chains.

[0029] If the above problems are not addressed, the spatiotemporal alignment error of multi-source heterogeneous data will continue to amplify, and the failure of joint feature extraction will result in risk heatmaps failing to accurately reflect high-risk areas. The lack of causal relationships in dynamic attack chains makes it impossible to trace covert, coordinated attacks in a timely manner, rendering minute-level response mechanisms ineffective. The collaborative decision-making loop between risk warning and hazard mitigation is broken, and when facing new types of cyberattacks, the remote sensing satellite ground system network experiences delays in patching vulnerabilities at critical nodes, potentially leading to data service interruptions or misjudgments in business processing.

[0030] To address the aforementioned challenges, this invention first tackles the issue of real-time collaborative governance of multi-source heterogeneous data, exploring how to achieve spatiotemporal alignment and joint feature extraction of multi-source data within a ground system. Traditional methods rely on static cleaning rules from a single data source, which cannot adapt to temporal deviations and format differences caused by internal system interference. To resolve this, this invention introduces a multi-stage data processing flow, constructing a unified feature vector through dynamic cleaning and structured transformation, employing a combination of noise detection and median filtering to eliminate the impact of data synchronization noise.

[0031] To address the lack of a probabilistic inference mechanism for dynamic attack chains, this invention analyzes how to establish a risk model of correlation between nodes within a system. Existing technologies cannot distinguish between anomalies and malicious behavior within the system, resulting in a high false positive rate. This invention attempts to combine Bayesian networks with deep learning models, employing a dual mechanism of threat quantification and anomaly pattern recognition to capture the spatiotemporal correlation features of network attacks within the system. For example, convolutional layers are used to extract spatiotemporal features of traffic, and recurrent layers capture temporal dependencies, enhancing the detection capability of coordinated attack chains. Example 1, Figure 1 This is a flowchart illustrating a remote sensing satellite network security situational awareness method with a dual prevention mechanism according to Embodiment 1 of the present invention, as shown below. Figure 1 As shown, Embodiment 1 provides a remote sensing satellite network security situational awareness method with a dual prevention mechanism, including:

[0032] Step S100: Obtain multi-source heterogeneous data from the remote sensing satellite ground system network, and generate a structured dataset through cleaning, denoising, and standardization.

[0033] Specifically, multi-source heterogeneous data refers to data from different sources and formats within the remote sensing satellite ground system network. This can include server equipment logs, network equipment alarms, and unstructured management data. Through cleaning, denoising, and standardization, structured data can be transformed to address data format differences and time synchronization issues caused by internal system interference. Structured datasets, on the other hand, are collections of data that have undergone cleaning, denoising, and format standardization. Specifically, data cleaning algorithms and median filtering methods can be used to remove duplicates and outliers, providing standardized input for subsequent risk analysis.

[0034] Step S200: Based on the structured dataset, record network assets using an asset identification algorithm, and generate a risk heatmap of network assets using a Bayesian network model and entropy weight method.

[0035] Specifically, asset identification algorithms refer to technologies that match software and hardware identifiers by comparing them against a pre-defined feature library. This can involve feature extraction and pattern matching methods to build a network asset inventory to support threat quantification. Bayesian network models are inference methods based on probabilistic graphical models and conditional probability tables. Specifically, they can calculate the probability and impact of threats by inputting threat data, quantifying the potential risks of dynamic attack chains. Entropy weighting methods are weighting methods that assess the dispersion of risk indicators through information entropy. Specifically, they can objectively assign weights to each indicator in the threat quantification results, addressing the problem that traditional static rule bases cannot adapt to new threats.

[0036] Step S300: Based on the risk heatmap and the structured dataset, a deep learning model is used to detect abnormal traffic and behavior, and a list of potential vulnerabilities with marked priorities is generated through a general vulnerability scoring standard and a threat intelligence database.

[0037] Specifically, a deep learning model refers to a neural network structure containing convolutional and recurrent layers. Convolutional operations can be used to extract spatiotemporal features of traffic, while recurrent layers capture temporal dependencies to identify covert attack behaviors. A general vulnerability scoring standard is an evaluation system based on a weighted sum of basic and time-related indicators. It can prioritize vulnerability features to achieve real-time correlation between vulnerability remediation and discovery. A threat intelligence database is a collection of data storing known attack patterns. It can match attack patterns using vulnerability identifiers and correlate attack events within the system to reconstruct multi-node attack chains. A vulnerability list is a list of vulnerabilities with asset identifiers and priority tags. It can integrate vulnerability priority sequences with threat intelligence matching results to provide input for a dynamic security posture map.

[0038] Step S400: Based on the risk heat map and the hazard list, a dynamic security situation map is constructed using graph database and community detection algorithms;

[0039] Specifically, a graph database refers to a database type that stores the relationships between nodes and edges. It can utilize path analysis algorithms and community detection algorithms to construct attack path models, enabling probabilistic reasoning of attack chains between nodes within the system. A dynamic security situation map, on the other hand, is a visualized map reflecting the distribution of network risks. It can calculate evaluation index values ​​through critical path sequences and community clustering, supporting collaborative governance and closed-loop decision-making.

[0040] Step S500: Based on the dynamic security situation map, a comprehensive security index, a repair priority list, and an emergency plan are generated using a weighted scoring model and the analytic hierarchy process, and a situation assessment report and governance recommendations are output.

[0041] Specifically, the weighted scoring model refers to an assessment method that uses risk weights and hazard priorities to sum up the results. It can be combined with the analytic hierarchy process (AHP) to generate a list of repair priorities, thus solving the problem of the disconnect between situation assessment and risk data.

[0042] This invention achieves a dual closed loop of collaborative governance of multi-source heterogeneous data and probabilistic inference of attack chains by dynamically linking risk heatmaps and hazard lists. This method combines Bayesian networks, deep learning models, and graph databases to address the spatiotemporal alignment problem of data within the system at the data layer, establish a node attack path model within the system at the analysis layer, and finally output governance suggestions through a dynamic security situation map, forming a collaborative decision-making closed loop of risk warning, hazard location, and response and handling.

[0043] The working process and principle of this invention are as follows: First, multi-source heterogeneous data, including server operation logs, equipment operation logs, and network traffic data, is acquired from the remote sensing satellite ground system network. This data is processed through cleaning, noise reduction, and standardization to generate a structured dataset. This process achieves spatiotemporal alignment and unified format conversion of the multi-source heterogeneous data. Next, network asset identification and risk assessment are performed based on the structured dataset. Asset identification algorithms are used to record the hardware and software assets in the network. Bayesian network models are used to quantify the threat probability faced by each asset, and entropy weighting is used to calculate the weights of different risk indicators. By fusing this information, a risk heatmap of network assets is generated, visually displaying the risk distribution. Then, combining the risk heatmap and the structured dataset, a deep learning model is used to detect abnormal traffic and behavior. This model extracts spatiotemporal features through convolutional layers and captures temporal dependencies through recurrent layers, enhancing the ability to identify coordinated attacks. The detection results are combined with general vulnerability scoring standards and a threat intelligence database to generate a list of vulnerabilities with priority labels. Based on the risk heatmap and the vulnerability list, a graph database is used to store network topology and risk information, and a community detection algorithm is used to divide network communities. This information is integrated into a dynamic security situation map, reflecting real-time changes in the cybersecurity situation. Finally, based on the dynamic security situation map, a weighted scoring model is used to calculate a comprehensive security index, and the analytic hierarchy process (AHP) is used to generate a remediation priority list and contingency plans. These results are integrated into a situation assessment report, providing decision support for cybersecurity management. The entire process forms a closed-loop security situation awareness mechanism, achieving end-to-end management from data collection and risk assessment to vulnerability handling. The combination of Bayesian networks and deep learning enhances the ability to identify new threats, and the construction of the dynamic map provides a global perspective on security situation analysis.

[0044] Based on the above analysis, this invention achieves real-time collaborative governance of multi-source heterogeneous data, solving the problem of spatiotemporal data alignment within the system. The combination of Bayesian networks and deep learning models establishes a probabilistic reasoning mechanism for dynamic attack chains, improving the ability to identify covert collaborative attacks. The construction of a dynamic security situation map provides a unified perspective for global risk assessment, supporting minute-level precise source tracing. The application of weighted scoring models and the analytic hierarchy process (AHP) forms a collaborative decision-making closed loop for risk warning, hazard location, and response, enhancing the defense capabilities of remote sensing satellite ground system networks against new types of cyberattacks.

[0045] In this embodiment, step S100 includes: step S101, obtaining server device logs, network device alarms, and manually uploaded unstructured management data from the remote sensing satellite ground system network to generate a multi-source heterogeneous dataset; step S102, using a cleaning algorithm to remove duplicates from the multi-source heterogeneous dataset to obtain a deduplicated dataset, wherein the cleaning algorithm removes identical records by comparing the similarity of data entries; step S103, performing noise detection on the deduplicated dataset; if the data noise exceeds a preset threshold, a median filtering method is used to smooth out outliers to obtain a cleaned dataset; otherwise, the deduplicated dataset is used as the cleaned dataset; step S104, extracting key fields from the cleaned dataset and converting it into a unified structure to generate a structured dataset.

[0046] The standardization process is configured to standardize timestamps in server device logs (e.g., convert to ISO 8601 format), parse binary protocol data from network device alarms into structured text (e.g., convert SNMP Trap data into JSON key-value pairs), and extract key fields and store them as key-value pairs from manually uploaded unstructured management data (e.g., Excel spreadsheets, PDF reports). This achieves preliminary alignment and integration of multi-source data, generating a multi-source heterogeneous dataset. The cleaning algorithm uses a Jaccard similarity-based comparison method to calculate the joint similarity of device ID, timestamp, and event type fields. Records with a combined similarity exceeding 0.9 are identified as duplicates and removed. Noise detection compares the variance of numerical fields (e.g., traffic values, CPU utilization) with a preset threshold (e.g., variance greater than 5). If the variance exceeds the threshold, a median filter with a window size of 5 is used for smoothing. Key field extraction includes core fields such as device number, event type, timestamp, and threat level, which are uniformly converted into a predefined JSON schema structure.

[0047] Specifically, the raw time data in server device logs is first converted to a unified UTC timezone format. Binary packets from network device alarms are converted into readable text by parsing protocol header fields (such as IP and TCP headers), and the alarm type and level are extracted. Manually uploaded Excel or PDF data is extracted using regular expressions and natural language processing techniques to obtain key information (such as device status, operator, and event description). During data deduplication, a joint similarity calculation is performed on the device ID, timestamp, and event type fields to avoid duplicate entries due to different data collection frequencies. Noise detection uses a sliding window variance calculation for time-series data (such as traffic sequences and memory usage sequences). When the variance of three consecutive windows exceeds a threshold, median filtering is triggered to correct abnormal jump values. Finally, a field mapping table is used to uniformly convert device identifiers and event codes in heterogeneous data into standardized asset numbers and event type codes, generating a dataset with a consistent field structure and data type.

[0048] Through the above technical solution, this invention achieves effective integration and standardized processing of multi-source heterogeneous data in remote sensing satellite ground system networks. By cleaning, denoising, and standardizing the data, data from different sources and formats are uniformly converted into a structured form, providing a standardized data foundation for subsequent analysis. The cleaning algorithm and noise detection steps effectively remove duplicates and outliers from the data, improving data quality. The resulting structured dataset facilitates subsequent risk analysis and situational awareness, providing reliable data support for the security management of remote sensing satellite ground system networks.

[0049] In this embodiment, step S200 includes: step S201, obtaining hardware and software features from the structured dataset, and using an asset identification algorithm to match hardware and software identifiers against a preset feature library to obtain a network asset list; step S202, extracting threat data corresponding to each asset in the network asset list from the structured dataset according to the network asset list, inputting the threat data through a Bayesian network model, wherein the Bayesian network model uses a pre-established probabilistic graphical model and conditional probability table to calculate the probability of threat occurrence and impact value, and determining the threat quantification result; step S203, using the entropy weight method to evaluate the dispersion of each risk indicator in the threat quantification result through information entropy, and calculating the risk indicator weight set; step S204, fusing the threat quantification result through the risk indicator weight set to generate a risk heatmap in which the risk level distribution is represented by color gradient.

[0050] The asset identification algorithm uses standard hardware and software feature templates from a pre-defined feature library to perform pattern matching on IP address, port number, and device model fields in a structured dataset, with a matching threshold set at 85% similarity. The conditional probability table of the Bayesian network model includes a joint probability distribution across three dimensions: threat type, vulnerability exploitation probability, and asset exposure surface. The threat occurrence probability is calculated using Bayesian inference, and the impact value is determined based on the product of asset value level and vulnerability severity. The entropy weighting method calculates the information entropy value of each risk indicator and normalizes it into weight coefficients, ranging from 0.1 to 0.9, with lower weight coefficients for indicators with high dispersion. A color gradient uses red, orange, yellow, and green to classify risk levels, with red corresponding to areas with a threat occurrence probability exceeding 60% and an impact value higher than 8.

[0051] Specifically, in the remote sensing satellite ground system network, the asset identification algorithm first extracts feature vectors from the device model field of the structured dataset and compares them with the standard features of servers, switches, and firewalls in a preset feature library. Successfully matched devices generate a list containing IP addresses and asset types. Subsequently, threat data is extracted from the alarm logs of the structured dataset, including the number of unauthorized accesses, abnormal traffic peaks, and the number of software version vulnerabilities. This data is then input into a Bayesian network model, which calculates the probability of a threat occurrence based on the pre-defined conditional dependency between hardware failure probabilities and malicious attack probabilities. For example, when a server experiences performance anomalies during system maintenance, the Bayesian network model sets the system anomaly probability to 35% and the malicious attack probability to 65%. The entropy weighting method calculates information entropy for the frequency, impact range, and duration indicators in the threat quantification results. The duration indicator is assigned a weight of 0.7 due to its lower dispersion, while the frequency indicator is assigned a weight of 0.3 due to its higher dispersion. Finally, in the risk heatmap, red areas mark key nodes with a threat occurrence probability exceeding 75% and an impact value reaching 9 points, while orange areas mark edge nodes with probabilities between 50% and 75%.

[0052] As a preferred embodiment, the specific implementation of the present invention is as follows: Hardware and software features are obtained from a structured dataset, and an asset identification algorithm is used to compare and match hardware and software identifiers against a pre-established feature library to obtain a network asset list. Specifically, information such as device MAC addresses and operating system versions can be obtained using network scanning tools and compared with a pre-established asset feature library to generate a network asset list containing fields such as device type, IP address, and system version. Based on the network asset list, threat data corresponding to each asset in the network asset list is extracted from the structured dataset and input into a Bayesian network model. The Bayesian network model uses a pre-established probabilistic graphical model and conditional probability table to calculate the probability of threat occurrence and impact value, determining the threat quantification result. For example, threat data such as device vulnerability information and abnormal access records can be extracted and input into a pre-trained Bayesian network to obtain the threat probability and impact degree of each asset. Based on the threat quantification result, the entropy weight method is used to evaluate the dispersion of each risk indicator in the threat quantification result through information entropy, calculating a set of risk indicator weights. Specifically, the information entropy of each risk indicator can be calculated, and the indicator weight can be determined based on the magnitude of the information entropy to obtain a set of weight coefficients. By fusing threat quantification results with a set of risk indicator weights, a risk heatmap is generated, using color gradients to represent the risk level distribution. Furthermore, indicators such as threat probability and impact level can be multiplied by their corresponding weights and summed to obtain a comprehensive risk score. This score is then mapped onto a color gradient to generate an intuitive risk heatmap.

[0053] Based on the above analysis, this invention achieves accurate identification and risk assessment of network assets in remote sensing satellite ground systems. This allows for rapid location of high-risk assets, providing a key focus for subsequent security protection. Furthermore, the use of a Bayesian network model for threat quantification enhances the ability to reason about complex attack chains. Simultaneously, the entropy weighting method is used to determine indicator weights, avoiding biases from subjective weighting. The resulting risk heatmap visually presents the network security situation, helping managers quickly grasp the overall risk status and formulate targeted protection strategies.

[0054] In this embodiment, step S300 includes: step S301, obtaining high-risk area data from the risk heatmap, extracting traffic features through convolutional layers and capturing temporal dependencies through recurrent layers using a deep learning model to obtain abnormal traffic identifiers; step S302, extracting corresponding behavioral sequence data from the structured dataset based on the abnormal traffic identifiers, and determining a vulnerability priority sequence by weighting and summing the vulnerability features in the behavioral sequence data using a general vulnerability scoring standard with basic and time indicators, wherein the vulnerability priority sequence includes vulnerability identifiers and priority scores; step S303, querying a threat intelligence database using the vulnerability identifiers in the vulnerability priority sequence, matching known attack patterns to obtain a set of matching vulnerabilities; step S304, generating a list of vulnerabilities listing asset identifiers and corresponding priority tags based on the set of matching vulnerabilities and the priority scores in the vulnerability priority sequence.

[0055] Specifically, the deep learning model employs a combination of 1D convolutional layers and recurrent layers. The 1D convolutional layers extract local spatial features of traffic data (such as packet length and protocol type distribution), while the recurrent layers capture the temporal dependencies of traffic changes (such as periodic traffic surge patterns) through gating mechanisms. In the general vulnerability scoring criteria, basic indicators include attack complexity and impact scope, while time indicators cover the vulnerability disclosure date and remediation status. Weighting coefficients are dynamically adjusted through historical attack data analysis. The threat intelligence database stores the characteristic fingerprints of known attack patterns, and the matching process uses a combination of regular expressions and fuzzy hashing to support cross-protocol layer attack feature correlation mapping.

[0056] Specifically, standardized traffic data undergoes multi-scale feature extraction via a 1D convolutional layer to generate a feature sequence containing a time dimension. A recurrent layer performs time-step analysis on the feature sequence to identify traffic spikes or low-frequency abnormal patterns (e.g., traffic values ​​below the normal average by 3 standard deviations). Abnormal traffic identifiers trigger the extraction of behavioral sequence data, which is then segmented into sub-sequences based on time windows. The vulnerability features of each sub-sequence are weighted using a common vulnerability scoring standard to calculate a base score (0-10 points) and a time decay factor (decreasing exponentially), resulting in a priority score. The threat intelligence database uses a distributed graph structure to store attack patterns. During matching, associated nodes are retrieved based on vulnerability identifiers, and adjacent edges are traversed to obtain attack path patterns (e.g., combined attacks involving malware propagation and privilege escalation). During the generation of the vulnerability list, the priority score is multiplied by the attack path threat level. Vulnerabilities exceeding a threshold (e.g., 7 points) are tagged with labels containing the asset IP address and suggested remediation code.

[0057] As a preferred embodiment, the specific implementation of the present invention is as follows: High-risk area data is obtained from a risk heatmap; a deep learning model is used to extract traffic features through convolutional layers and capture temporal dependencies through recurrent layers to obtain abnormal traffic identifiers. Specifically, firstly, network traffic data corresponding to high-risk areas is extracted from the risk heatmap and input into a pre-trained deep learning model. This model includes multi-layer one-dimensional convolutional networks and long short-term memory networks. The one-dimensional convolutional network is used to extract local features of the traffic data, and the long short-term memory network is used to capture temporal dependencies. The model outputs a probability value for abnormal traffic; when this value exceeds a preset threshold, it is marked as abnormal traffic. Based on the abnormal traffic identifier, corresponding behavioral sequence data is extracted from a structured dataset. A general vulnerability scoring standard is used to weight and sum the vulnerability features in the behavioral sequence data using basic indicators and time indicators to determine a vulnerability priority sequence. The vulnerability priority sequence includes a vulnerability identifier and a priority score. Specifically, basic indicators include attack complexity, attack vector, and impact scope, while time indicators include vulnerability disclosure time and patch release time. Each indicator is assigned different weights according to its importance, and the final priority score is obtained through weighted summation. The vulnerability database is queried using vulnerability identifiers from the vulnerability priority sequence to match known attack patterns, resulting in a set of matching vulnerabilities. The threat intelligence database stores known attack pattern characteristics; by associating and matching vulnerability identifiers, potential attack methods related to the current vulnerability are identified. Based on the matching vulnerability set and the priority scores in the vulnerability priority sequence, a list of vulnerabilities is generated, listing asset identifiers and corresponding priority tags. The vulnerability list is sorted in descending order of priority score, and each entry includes an asset identifier, vulnerability description, attack pattern, and priority tag.

[0058] Based on the above analysis, this invention achieves accurate detection of abnormal traffic and priority ranking of potential threats in remote sensing satellite ground system networks. The deep learning model can adaptively extract traffic features, exhibiting stronger generalization ability compared to traditional rule-based methods. The application of a general vulnerability scoring standard makes vulnerability assessment more objective and quantifiable. The introduction of a threat intelligence database enhances the ability to predict potential attacks. The final generated threat list provides security managers with clear guidance on remediation priorities, helping to improve remediation efficiency and reduce cybersecurity risks.

[0059] In this embodiment, the step of obtaining high-risk area data from the risk heatmap and extracting traffic features through convolutional layers and capturing temporal dependencies using a deep learning model to obtain abnormal traffic identifiers includes: obtaining network traffic sequences of high-risk areas from the risk heatmap; preprocessing the network traffic sequences using a deep learning model to obtain standardized traffic data; extracting the spatiotemporal features of the standardized traffic data through 1D convolutional layers of the deep learning model to obtain a feature sequence with a time dimension; analyzing the temporal dependencies of the traffic feature vectors through the recurrent layers of the deep learning model to determine abnormal traffic patterns; and generating abnormal traffic identifiers by comparing the abnormal traffic patterns with a preset threshold.

[0060] The preprocessing process includes normalizing the network traffic sequence to eliminate dimensional differences in traffic data collected from different points. A 1D convolutional layer uses a 3-width kernel sliding along the time axis to extract local spatial features of the traffic data, generating a feature sequence containing the time dimension. The recurrent layer employs a bidirectional LSTM structure to perform forward and backward temporal analysis on the feature sequence, capturing long-term dependencies in traffic changes. Abnormal traffic pattern detection is achieved by calculating the Euclidean distance between the feature vector and a preset threshold; when the distance exceeds the threshold, an identifier is generated.

[0061] Specifically, standardized traffic data is transformed into a distribution with a mean of 0 and a variance of 1 using the Z-score method, eliminating the impact of data bias on model training. 1D convolutional layers perform convolution operations in the time dimension. For example, a time window with an input sequence length of 100 generates a 98-dimensional feature vector after convolution, with each vector corresponding to the spatial features of traffic in a local time period. When the recurrent layer processes the feature vectors using bidirectional LSTM, the forward LSTM processes sequentially from t=1 to t=98, and the backward LSTM processes in reverse order from t=98 to t=1. The hidden states from both directions are concatenated and output to form a feature representation containing complete temporal information. The anomaly detection stage employs a dynamic threshold mechanism. The preset threshold is automatically adjusted based on the statistical distribution of historical traffic data; for example, three times the standard deviation of the mean of normal traffic feature vectors is used as the judgment boundary. When a feature vector exceeds the threshold, identification data containing a timestamp, traffic type, and anomaly level is generated. This identification data forms a data loop with the subsequent vulnerability scoring module.

[0062] As a preferred embodiment, the present invention is implemented as follows: Network traffic sequences of high-risk areas are obtained from a risk heatmap. A deep learning model is used to preprocess the network traffic sequences to obtain standardized traffic data. Preprocessing includes normalization and denoising of the traffic data. The spatiotemporal features of the standardized traffic data are extracted using a 1D convolutional layer of the deep learning model to obtain a feature sequence with a time dimension. The 1D convolutional layer uses three convolutional kernels with a kernel size of 3, a stride of 1, and padding of 1. The temporal dependencies of the traffic feature vectors are analyzed using a recurrent layer of the deep learning model to determine abnormal traffic patterns. The recurrent layer uses a Long Short-Term Memory (LSTM) network containing 64 hidden units. Abnormal traffic identifiers are generated based on a comparison between the abnormal traffic pattern and a preset threshold. The preset threshold is obtained through historical data statistics; when the abnormal score exceeds the threshold, it is marked as abnormal traffic.

[0063] Through the above technical solution, this invention can effectively extract the spatiotemporal characteristics and temporal dependencies of network traffic, and accurately identify abnormal traffic patterns. This improves the detection capability of complex attack behaviors in remote sensing satellite ground system networks and reduces the false alarm rate. Furthermore, this solution can adapt to dynamically changing network environments, promptly detect new attack patterns, and enhance the security protection level of remote sensing satellite ground system networks.

[0064] In this embodiment, step S400 includes: Step S401, obtaining the coordinates of high-risk areas from the risk heatmap and extracting the priority of hazards from the hazard list, and inserting hazard nodes carrying priority attributes into a graph database; Step S402, defining the relationship between nodes according to the hazard list, generating edge weights, and using the Dijkstra algorithm from the highest-risk node to the core node through path analysis to obtain the critical path sequence; Step S403, dividing the network community based on the node connection relationship in the graph database using the Louvain algorithm to obtain community clusters; Step S404, extracting the priority attributes of path nodes according to the critical path sequence and the community clusters, calculating the evaluation index value by weighted summation of path sequence length and hazard priority, and obtaining the control measure set; Step S405, integrating the investigation process chain with the event response chain, and integrating the graph database, critical path sequence, community clusters, and control measure set to determine the risk control threshold and generate a dynamic safety situation map.

[0065] The process of inserting potential hazard nodes involves binding high-risk areas with priority tags in the hazard list through coordinate mapping, ensuring that node attributes include both spatial location and risk level dimensions. Edge weight generation is based on the matching degree of data flow frequency and protocol type between nodes; for example, node pairs with transmission frequencies exceeding a preset threshold are assigned higher weight values. The Dijkstra algorithm uses a priority queue to optimize the data structure, keeping the traversal time complexity from the highest-risk node to the core node to O(n log n). The Louvain algorithm iteratively adjusts the community partitioning through modularity optimization, stopping splitting when the node connection density within a community reaches 0.85. Evaluation metrics are calculated using normalized path lengths and priority scores, with weight coefficients set to 0.6 and 0.4, respectively, ensuring that high-priority nodes in the critical path have a dominant influence on the metric values.

[0066] Specifically, high-risk area coordinates are mapped to graph database node coordinate attributes through internal logical regions. Hazard priority is extracted from the hazard list and written into node tag attributes, forming a set of hazard nodes with multi-dimensional attributes. Edge weights are dynamically generated based on the matching degree of communication protocol types between nodes and the data packet transmission frequency. For example, when the transmission frequency between TCP protocol nodes exceeds 1000 times / second, the edge weight is set to 0.9. During the Dijkstra algorithm traversal, the path with the smallest cumulative edge weight value is selected first. When the number of hops on the path from the highest-risk node to the core node exceeds 5, a path splitting alarm is triggered. When the Louvain algorithm divides communities, the initial number of communities is set to 1 / 3 of the number of high-risk nodes, and the community boundaries are dynamically adjusted through modularity increment calculation. Path sequence length is standardized, mapping the maximum path length to 1. Hazard priority scores are linearly normalized, and weighted summation generates an evaluation index value in the 0-1 range. The control measure set generates targeted defense strategies for path nodes with index values ​​exceeding 0.7, such as deploying traffic scrubbing equipment or updating access control lists. The final dynamic security situation map uses timestamps to mark community clusters and critical path changes, and automatically triggers the emergency response plan execution link when the risk control threshold exceeds 0.8.

[0067] As a preferred embodiment, the present invention is implemented as follows: High-risk area coordinates are obtained from a risk heatmap, and hazard priorities are extracted from a hazard list. Hazard nodes carrying priority attributes are then inserted into a graph database. Specifically, high-risk areas are located using color gradients in the risk heatmap, and corresponding coordinate information is extracted. Simultaneously, priority labels for each hazard item are extracted from the hazard list. Then, nodes are created using the Neo4j graph database, and hazard information and its priority are inserted as node attributes. Based on the hazard list, the relationships between nodes are defined, edge weights are generated, and the Dijkstra algorithm is used to traverse from the highest-risk node to the core node using path analysis, obtaining a critical path sequence. Further, based on the relationships between hazard items in the hazard list, edge relationships are created between nodes in the graph database. Edge weights are determined based on the strength of the association. Then, the starting node with the highest risk and the ending node of the core asset are determined, and the optimal path between the two points is calculated using Dijkstra's shortest path algorithm, obtaining a critical path sequence. The Louvain algorithm is used to divide the network into communities based on the node connection relationships in the graph database, resulting in community clusters. In practical implementation, the Louvain community discovery algorithm is applied to the nodes in the graph database to divide the network into multiple communities based on the connection density between nodes, forming community clusters. Priority attributes of path nodes are extracted based on the critical path sequence and community clusters. Evaluation index values ​​are calculated by weighted summation of path sequence length and hazard priority, obtaining a set of control measures. Thus, priority attributes of each node are extracted from the critical path sequence and weighted summation is performed based on path length to obtain a path risk evaluation index. The corresponding set of control measures is determined based on this index value. By integrating the investigation process chain with the event response chain, and combining the graph database, critical path sequence, community clusters, and control measure set, risk control thresholds are determined, generating a dynamic security situation map. For example, predefined investigation processes and event response processes are integrated to form a complete response chain. Then, the topology, critical paths, community division results, and control measures in the graph database are visualized and integrated, risk control thresholds are set, and finally, a dynamically updated security situation map is generated.

[0068] Based on the above analysis, this invention achieves a transformation from static risk assessment to dynamic security situation awareness. By constructing network topology relationships through a graph database and combining path analysis and community detection algorithms, it can quickly identify critical risk paths and risk clustering areas. Simultaneously, it integrates investigation processes and incident response chains, forming a closed-loop security management mechanism. This dynamic and visualized security situation map provides intuitive decision support for security managers, helping to improve the accuracy of risk identification and the targeting of response measures. Furthermore, by setting risk control thresholds, it enables timely early warning of abnormal situations, thereby enhancing the system's proactive defense capabilities.

[0069] In this embodiment, the step of defining the relationships between nodes based on the hazard list, generating edge weights, and using the Dijkstra algorithm to traverse from the highest-risk node to the core node using path analysis to obtain the critical path sequence includes: obtaining nodes and edge weights from the graph database, wherein the nodes include hazard nodes defined based on the hazard list, and the edge weights are generated based on the relationships between nodes; determining the highest-risk node and the core node, wherein the highest-risk node is determined according to the high-risk area coordinates of the risk heatmap, and the core node is a predefined critical network asset node; and using the Dijkstra algorithm to calculate the shortest path from the highest-risk node to the core node to obtain the critical path sequence.

[0070] Among them, the edge weight is generated by quantifying the probability value or influence of the attack path between nodes, for example, multiplying the communication frequency between nodes with the vulnerability correlation as the weight value; the highest risk node is mapped to the graph database node by the system coordinates of the area where the color gradient in the risk heat map exceeds the red threshold; the core node is predefined as the core server or key network equipment of the remote sensing satellite ground system; the Dijkstra algorithm filters out the path sequence with the smallest total weight by iteratively updating the cumulative weight between nodes.

[0071] Specifically, the graph database stores the attributes of vulnerable nodes, including vulnerability identifiers, priority scores, and system logical location coordinates. Edge weights are calculated based on the type of communication links between nodes or the correlation strength of historical attack events; for example, the correlation coefficient between the number of unauthorized accesses and the number of abnormal logins is used as the edge weight parameter. The highest-risk node is identified by parsing coordinate data from the risk heatmap and matching it with nodes in the graph database corresponding to the system's logical region, such as server nodes in high-incidence attack areas. Core nodes are determined through a pre-defined list of critical assets, such as satellite data processing servers. During Dijkstra's algorithm traversal, starting from the highest-risk node, the cumulative edge weights of all possible paths to the core node are calculated, and the path with the smallest total weight is selected as the critical path sequence. For example, the total weight is calculated by weighting the probability of unauthorized access, the difficulty of vulnerability exploitation, and the number of hops between nodes. The resulting path sequence accurately reflects the core paths of the attack chain within the system, providing a data foundation for dynamic attack reasoning.

[0072] As a preferred embodiment, the specific implementation of the present invention is as follows: Nodes and edge weights are obtained from a graph database. Nodes include potential hazard nodes defined based on a hazard list, and edge weights are generated based on the relationships between nodes. The highest-risk node and core nodes are determined. The highest-risk node is determined based on the coordinates of high-risk areas in a risk heatmap, and the core nodes are predefined critical network asset nodes. The Dijkstra algorithm is used to calculate the shortest path from the highest-risk node to the core node, resulting in a critical path sequence. Specifically, node information is first extracted from the graph database, including the identifier, type, priority, and other attributes of potential hazard nodes. Edge weights are generated by analyzing the strength of relationships between nodes, such as co-occurrence frequency and information flow transmission probability. Further, the highest-risk node is determined based on the coordinates with the highest risk value in the risk heatmap, and predefined critical network device nodes are set as core nodes. Thus, using the Dijkstra shortest path algorithm, the shortest path for risk propagation is calculated by traversing from the highest-risk node to the core node, forming a critical path sequence. This sequence contains the most likely attack path from the high-risk area to the core asset.

[0073] Through the above technical solution, this invention can effectively identify high-risk propagation paths in a network, providing precise location for subsequent risk control. By storing network topology and risk information in a graph database and combining it with Dijkstra's algorithm for path analysis, the shortest risk propagation path from high-risk areas to core assets can be quickly identified. This method overcomes the limitations of traditional static rules in dealing with complex network topologies, improving the accuracy and efficiency of risk propagation path identification. Furthermore, the use of a graph database to store network structure information gives the solution good scalability, adapting to increases in network size and complexity. In addition, by combining risk heatmaps with network topology maps for analysis, risk assessment and network structure are organically integrated, providing a more comprehensive and accurate decision-making basis for subsequent security situation awareness and risk control.

[0074] In this embodiment, step S500 includes: Step S501, obtaining network risk assessment data from the dynamic security situation map, including community clusters, critical path sequences, and control measure sets, and using a weighted scoring model to sum the risk weights by the hazard priorities to obtain a comprehensive security index; Step S502, constructing a risk level comparison matrix based on the network risk assessment data in the dynamic security situation map, and inputting the comprehensive security index, the risk distribution of community clusters, and the priority attributes of critical path sequences into the comparison matrix using the analytic hierarchy process (AHP), calculating the risk remediation urgency score, and generating a remediation priority list and emergency plan; Step S503, integrating governance suggestions based on the remediation priority list, emergency plan, and control measure set, and outputting a situation assessment report; Step S504, if the comprehensive security index exceeds a preset threshold, optimizing the governance suggestions based on the event response chain in the dynamic security situation map and updating the situation assessment report.

[0075] The weighted scoring model normalizes the risk distribution of community clusters using a pre-defined weight allocation table. For example, it uses the proportion of nodes within a community and the path sequence length as weighting factors, combined with the priority score of potential hazards for linear weighted summation. The comparison matrix of the analytic hierarchy process (AHP) is constructed using a 1-9 scale, comparing the priority attributes of critical path sequences with the community risk distribution pairwise. After consistency checks, the eigenvectors are calculated to determine the weight ratio of each level. The preset threshold is dynamically adjusted based on historical attack data. For example, when the system network traffic anomaly rate exceeds 15%, the threshold is automatically increased to 1.2 times the baseline value to reduce the false alarm rate.

[0076] Specifically, community clusters in the network risk assessment data are divided using the Louvain algorithm to reflect the clustering characteristics of attack paths. The weighted scoring model first extracts the average risk value of nodes within a community. For example, if a community contains 5 high-risk nodes with an average priority score of 8.2, its risk weight is set to 0.35. Simultaneously, the total priority scores of nodes in the critical path sequence are calculated. For example, if a path contains 3 nodes with scores of 9, 7, and 6, the total is 22. The community weights are multiplied by the path scores and then summed to obtain a comprehensive security index of 75.6. In the matrix constructed using the analytic hierarchy process (AHP), community risk distributions are compared pairwise with critical path priorities. For example, if community A has a high risk level and a path priority of urgent, the corresponding element in the matrix is ​​assigned a value of 5, indicating that the former is significantly more important than the latter. By calculating the maximum eigenvalue of the matrix and its corresponding vector, the urgency of repair scores is ranked, generating a list of nodes to be prioritized for repair. When the overall security index exceeds the threshold, for example, when the index reaches 80, the system automatically triggers the emergency plan optimization process. Based on the attack path probability model in the event response chain, the weight of the misjudged path caused by hardware failure is reduced by 30%, and the vulnerability repair order in the governance recommendations is updated.

[0077] As a preferred embodiment, the specific implementation of the present invention is as follows: A situation assessment module is deployed in the remote sensing satellite ground system server cluster, and the following steps are performed: Network risk assessment data is extracted from the dynamic security situation map, specifically including five community clusters divided by the Louvain algorithm, a critical path sequence generated based on the Dijkstra algorithm, and a set of control measures containing access control policies. When using a weighted scoring model, the risk weight set is pre-calculated using the entropy weight method. For example, the community risk distribution weight is set to 0.6, the critical path priority weight is set to 0.3, and the control measure effectiveness weight is set to 0.1. The priority scores of potential hazards in each community cluster are weighted and summed to obtain a comprehensive security index of 78.5. Further, when constructing the risk level comparison matrix, the comprehensive security index and the node priority attributes in the critical path sequence are mapped to matrix elements. The risk repair urgency score is calculated using the analytic hierarchy process. For example, a core node, being located on three critical paths simultaneously, is assigned the highest score of 9.2, and a list containing nodes that require priority repair is generated. The emergency plan sets that when the comprehensive security index exceeds the threshold of 75, the security hardening process and intrusion detection measures for the core node are immediately initiated. The final situation assessment report integrates a remediation priority list, emergency response plans, and a set of control measures, specifically including vulnerability remediation work order numbers, response time windows, and operation instruction sets. When the overall security index remains above the threshold, based on the malware attack patterns identified in the incident response chain, the governance recommendations include adding ground system internal network isolation and protocol enhancement schemes.

[0078] Based on the above analysis, this invention effectively solves the decision-making lag problem caused by the disconnect between risk assessment and hazard management data in traditional methods. By dynamically integrating network risk assessment data with the remediation strategy generation mechanism, a synchronous closed loop is achieved between security index calculation and emergency plan formulation, enabling precise location of core remediation nodes before the attack chain has fully spread. Furthermore, based on the comparison matrix construction using the analytic hierarchy process (AHP), the topological characteristics of the ground system's collaborative attack path are transformed into quantifiable remediation priority parameters, significantly improving the minute-level response capability of remote sensing satellite ground systems when facing covert attacks within the system.

[0079] In a specific embodiment of the present invention, such as Figure 4 As shown, the remote sensing satellite network security situational awareness method with a dual prevention mechanism of the present invention includes:

[0080] 1. Data Acquisition and Preprocessing: Automatically acquire basic operational data, log data, and safety equipment alarm data from the remote sensing satellite ground system network, as well as uploaded safety management work reports, policy documents, process records, etc. Clean, denoise, and standardize multi-source heterogeneous data to generate structured datasets;

[0081] 2. Implementation of risk management mechanism: Based on preprocessed data, potential risk points of network assets in the organization are identified through dynamic adaptive network security threat modeling and risk quantification algorithms, risk levels are assessed and risk heat maps are generated;

[0082] 3. Implementation of the hidden danger investigation mechanism: Utilize vulnerability scanning tools and abnormal behavior detection models to proactively probe the network system, identify existing vulnerabilities and abnormal behaviors, and combine methods such as supervision and inspection, statutory self-inspection, security audit, security reporting, incident investigation, and information analysis to generate a list of hidden dangers and mark their priorities;

[0083] 4. Dual Prevention Integration Analysis: Correlate the risk heat map with the hidden danger list, combine historical attack data and industry threat intelligence to construct a dynamic security situation map, including the network security risk assessment situation, network security risk control situation, network security hidden danger investigation situation, and network security incident situation.

[0084] 5. Situation assessment and decision support: Based on the security situation map, a weighted scoring model is used to calculate the comprehensive network security index, generate a situation assessment report, and provide remediation suggestions and emergency plans. If major network security vulnerabilities are involved, instructions can be issued to isolate the network assets involved.

[0085] 6. Closed-loop governance and feedback optimization: Implement hazard rectification based on remediation suggestions, update the risk database, and optimize the accuracy of risk identification and hazard detection through machine learning models to form a closed-loop management of network security.

[0086] In this embodiment, the implementation of the risk management mechanism includes: recording network assets in the local area network of the remote sensing satellite ground system using a network asset identification algorithm based on software and hardware characteristics; setting initial network security threat types, attack characteristics, and paths for network asset types; quantifying the probability and impact of threats using a Bayesian network model; determining the weights of risk indicators using the entropy weight method, and classifying the network asset into high, medium, and low risk levels based on the risk matrix; performing correlation calculations on the effectiveness of overall network asset risk control measures, and outputting the overall risk value.

[0087] In this embodiment, the implementation of the hidden danger investigation mechanism includes: using a deep learning-based abnormal traffic detection model to identify complex threats such as DDoS attacks, APT attacks, malicious code attacks, and application vulnerability exploits in the local area network of the remote sensing satellite ground system; using the CVSS scoring standard to prioritize asset vulnerabilities and matching them with a threat intelligence database to determine the urgency of remediation; and using a deep search algorithm to perform keyword matching on unstructured data of management categories to determine the effectiveness of risk management measures.

[0088] In this embodiment, the dual prevention fusion analysis stores the correlation between risks and hidden dangers through a graph database and uses a community discovery algorithm to identify key attack paths.

[0089] In this embodiment, the closed-loop governance and feedback optimization includes: establishing a hidden danger rectification work order system, setting up a risk and hidden danger database, establishing a hidden danger investigation and governance workflow, and tracking the repair progress in real time; using a reinforcement learning model to dynamically adjust risk identification and hidden danger investigation strategies to improve the system's adaptive capabilities; and adopting a security compliance baseline collision algorithm to identify the level of network security risks, which are divided into general security risks and major security risks.

[0090] In this embodiment, the remote sensing satellite network security situational awareness method with a dual prevention mechanism is applied to a remote sensing satellite network security situational awareness system with a dual prevention mechanism. The system includes: a data acquisition module, a risk management module, a vulnerability investigation module, a fusion analysis module, a decision support module, and a closed-loop governance module. The data acquisition module acquires multi-source data from remote sensing satellite ground system servers, key network equipment, security products, and manually uploaded management-related unstructured data. The risk management module is configured to perform asset identification, threat modeling, risk quantification, and visualization heatmap generation. The vulnerability investigation module is configured to perform vulnerability scanning, abnormal behavior detection, vulnerability investigation task execution, and vulnerability classification and grading labeling. The fusion analysis module is configured to correlate risk and vulnerability data to construct a dynamic security situation map. The decision support module is configured to generate security indices, assessment reports, and governance recommendations. The closed-loop governance module is configured to track the rectification process, optimize model parameters, and update the database. The fusion analysis module integrates a graph computing engine, supporting real-time correlation of risk nodes and vulnerability points on the attack chain.

[0091] In a specific example, the method of this invention includes integrating data such as network equipment logs of remote sensing satellite ground systems, operation logs of critical servers, and security device alarms, as well as operation logs of remote sensing satellite applications and log data of the underlying hardware environment, and performing normalization processing through ETL tools. Monte Carlo simulation is used to assess the probability of attack paths, and risk values ​​are calculated in conjunction with asset values. Agentless scanners are deployed to detect zero-day vulnerabilities and high-risk vulnerabilities, and LSTM models are used to identify covert attack behaviors. An "asset-risk-vulnerability-attacker" association network is constructed in the Neo4j graph database to identify key vulnerabilities. A remediation priority list is generated based on the Analytic Hierarchy Process (AHP), and the expected effects of different governance strategies are simulated. Remediation operations are executed through automated orchestration tools (such as SOAR), and the detection model is optimized using adversarial training. Thus, this invention combines risk management (prevention) with vulnerability identification and remediation (control during the event), covering the entire lifecycle of network security. It uses graph computing technology to associate risks and vulnerabilities, constructs a multi-dimensional security situation map, and improves the system's adaptive defense capabilities through machine learning feedback optimization of the model.

[0092] Example 2, Figure 2 This is a schematic diagram of the structure of a remote sensing satellite network security situational awareness system with a dual prevention mechanism, as shown in Embodiment 2 of the present invention. Figure 2 As shown in Embodiment 2, a remote sensing satellite network security situation awareness system with a dual prevention mechanism is provided, including: a dataset generation module 201, a heatmap generation module 202, a vulnerability list generation module 203, a map construction module 204, and an output module 205. The dataset generation module 201 is used to acquire multi-source heterogeneous data from the remote sensing satellite ground system network, and generate a structured dataset through cleaning, denoising, and standardization. The heatmap generation module 202 is used to record network assets using an asset identification algorithm based on the structured dataset, and generate a risk heatmap of the network assets using a Bayesian network model and entropy weight method. The vulnerability list generation module 203 is used to detect abnormal traffic and behavior using a deep learning model based on the risk heatmap and the structured dataset, and generate a vulnerability list with priority markings using a general vulnerability scoring standard and a threat intelligence database. The map construction module 204 is used to construct a dynamic security situation map based on the risk heatmap and the vulnerability list using a graph database and community detection algorithm. The output module 205 is used to generate a comprehensive security index, a repair priority list, and an emergency plan based on the dynamic security situation map using a weighted scoring model and the analytic hierarchy process, and output a situation assessment report and governance recommendations.

[0093] In this embodiment, the dataset generation module 201 includes a first obtaining unit, a second obtaining unit, a third obtaining unit, and a first generating unit. The first obtaining unit is used to acquire server device logs, network device alarms, and manually uploaded management-related unstructured data from the remote sensing satellite ground system network to generate a multi-source heterogeneous dataset. The second obtaining unit is used to remove duplicates from the multi-source heterogeneous dataset using a cleaning algorithm to obtain a deduplicated dataset, wherein the cleaning algorithm removes identical records by comparing the similarity of data entries. The third obtaining unit is used to perform noise detection on the deduplicated dataset; if the data noise exceeds a preset threshold, a median filtering method is used to smooth out outliers to obtain a cleaned dataset; otherwise, the deduplicated dataset is used as the cleaned dataset. The first generating unit is used to extract key fields from the cleaned dataset and convert them into a unified structure to generate a structured dataset.

[0094] In this embodiment, the heatmap generation module 202 includes a fourth obtaining unit, a first determining unit, a calculation unit, and a first generating unit. The fourth obtaining unit is used to acquire hardware and software features from the structured dataset, and use an asset identification algorithm to compare and match hardware and software identifiers against a preset feature library to obtain a network asset list. The first determining unit is used to extract threat data corresponding to each asset in the network asset list from the structured dataset, input the threat data through a Bayesian network model, and use a pre-established probabilistic graphical model and conditional probability table to calculate the probability of threat occurrence and impact value, thus determining the threat quantification result. The calculation unit is used to use the entropy weight method to evaluate the dispersion of each risk indicator in the threat quantification result using information entropy, and calculate a risk indicator weight set. The first generating unit is used to fuse the threat quantification result through the risk indicator weight set to generate a risk heatmap where the risk level distribution is represented by a color gradient.

[0095] In this embodiment, the vulnerability list generation module 203 includes a fifth obtaining unit, a second determining unit, a sixth obtaining unit, and a second generating unit. The fifth obtaining unit is used to obtain high-risk area data from the risk heatmap, extract traffic features through convolutional layers using a deep learning model, and capture temporal dependencies through recurrent layers to obtain abnormal traffic identifiers. The second determining unit is used to extract corresponding behavioral sequence data from the structured dataset based on the abnormal traffic identifiers, and use a general vulnerability scoring standard to weight and sum the vulnerability features in the behavioral sequence data using basic and time indicators to determine a vulnerability priority sequence, wherein the vulnerability priority sequence includes vulnerability identifiers and priority scores. The sixth obtaining unit is used to query a threat intelligence database using the vulnerability identifiers in the vulnerability priority sequence, match known attack patterns, and obtain a set of matching vulnerabilities. The second generating unit is used to generate a vulnerability list listing asset identifiers and corresponding priority tags based on the set of matching vulnerabilities and the priority scores in the vulnerability priority sequence.

[0096] In this embodiment, the step of obtaining high-risk area data from the risk heatmap and extracting traffic features through convolutional layers and capturing temporal dependencies using a deep learning model to obtain abnormal traffic identifiers includes: obtaining network traffic sequences of high-risk areas from the risk heatmap; preprocessing the network traffic sequences using a deep learning model to obtain standardized traffic data; extracting the spatiotemporal features of the standardized traffic data through 1D convolutional layers of the deep learning model to obtain a feature sequence with a time dimension; analyzing the temporal dependencies of the traffic feature vectors through the recurrent layers of the deep learning model to determine abnormal traffic patterns; and generating abnormal traffic identifiers based on a comparison of the abnormal traffic patterns with a preset threshold.

[0097] In this embodiment, the graph construction module 204 includes: an adoption unit, a seventh obtaining unit, an eighth obtaining unit, an acquisition unit, and a third generation unit. The adoption unit is used to obtain the coordinates of high-risk areas from the risk heatmap, extract hazard priorities from the hazard list, and insert hazard nodes carrying priority attributes into the graph database. The seventh obtaining unit is used to define the relationships between nodes according to the hazard list, generate edge weights, and use the Dijkstra algorithm (a path analysis method) to traverse from the highest-risk node to the core node to obtain a critical path sequence. The eighth obtaining unit is used to divide the network into communities based on the node connection relationships in the graph database using the Louvain algorithm to obtain community clusters. The acquisition unit is used to extract the priority attributes of path nodes based on the critical path sequence and the community clusters, calculate the evaluation index value by weighted summation of the path sequence length and hazard priority, and obtain a set of control measures. The third generation unit is used to integrate the event response chain through the investigation process chain, and integrate the graph database, critical path sequence, community clusters, and control measure set to determine the risk control threshold and generate a dynamic safety situation map.

[0098] In this embodiment, the process of defining the relationships between nodes based on the hazard list, generating edge weights, and using Dijkstra's algorithm to traverse from the highest-risk node to the core node using path analysis to obtain the critical path sequence includes: obtaining nodes and edge weights from the graph database, wherein the nodes include hazard nodes defined based on the hazard list, and the edge weights are generated based on the relationships between nodes; determining the highest-risk node and the core node, wherein the highest-risk node is determined based on the high-risk area coordinates of the risk heatmap, and the core node is a predefined critical network asset node; and using Dijkstra's algorithm to calculate the shortest path from the highest-risk node to the core node to obtain the critical path sequence.

[0099] In this embodiment, the output module 205 includes a ninth obtaining unit, a fourth generating unit, an output unit, and an optimization unit. The ninth obtaining unit is used to acquire network risk assessment data from the dynamic security situation map, including community clusters, critical path sequences, and control measure sets. A weighted scoring model is used to sum the risk weights multiplied by the priority of potential hazards to obtain a comprehensive security index. The fourth generating unit is used to construct a risk level comparison matrix based on the network risk assessment data in the dynamic security situation map. The comprehensive security index, the risk distribution of community clusters, and the priority attributes of critical path sequences are input into the comparison matrix using the analytic hierarchy process (AHP) to calculate the risk remediation urgency score and generate a remediation priority list and emergency response plan. The output unit is used to integrate governance suggestions based on the remediation priority list, emergency response plan, and control measure set, and output a situation assessment report. The optimization unit is used to optimize the governance suggestions and update the situation assessment report based on the event response chain in the dynamic security situation map if the comprehensive security index exceeds a preset threshold.

[0100] The various variations and specific examples of the remote sensing satellite network security situation awareness method with dual prevention mechanism provided in Embodiment 1 are also applicable to the remote sensing satellite network security situation awareness system with dual prevention mechanism provided in this embodiment. Through the foregoing detailed description of a remote sensing satellite network security situation awareness method with dual prevention mechanism, those skilled in the art can clearly understand the implementation method of a remote sensing satellite network security situation awareness system with dual prevention mechanism in this embodiment. Therefore, for the sake of brevity, it will not be described in detail here.

[0101] Example 3, Figure 3 This is a schematic diagram of the structure of an electronic device according to Embodiment 3 of the present invention, as shown below. Figure 3 As shown, Embodiment 3 also provides an electronic device 300, which may include a processor 301 and a memory 302.

[0102] Memory 302 is used to store programs. Memory 302 may include volatile memory, such as random-access memory (RAM), such as static random-access memory (SRAM), double data rate synchronous dynamic random-access memory (DDR SDRAM), etc.; memory may also include non-volatile memory, such as flash memory. Memory 302 is used to store computer programs (such as application programs, functional modules, etc. that implement the above methods), computer instructions, etc. The computer programs, computer instructions, etc., can be partitioned and stored in one or more memories 302. Furthermore, the computer programs, computer instructions, data, etc., can be accessed by processor 301.

[0103] The aforementioned computer programs and instructions can be stored in one or more partitions of memory 302. Furthermore, the aforementioned computer programs and instructions can be invoked by processor 301.

[0104] The processor 301 is configured to execute the computer program stored in the memory 302 to implement the various steps in the methods described in the above embodiments.

[0105] For details, please refer to the relevant descriptions in the preceding method embodiments.

[0106] The processor 301 and the memory 302 can be independent structures or integrated structures. When the processor 301 and the memory 302 are independent structures, the memory 302 and the processor 301 can be coupled together via bus 303.

[0107] The electronic device in this embodiment can execute the technical solution in the above method. Its specific implementation process and technical principle are the same, and will not be repeated here.

[0108] Example 4: Example 4 also provides a computer-readable storage medium including a computer program and instructions, which, when the computer program or instructions are run on a computer, cause the computer to execute the remote sensing satellite network security situational awareness method with dual prevention mechanism of any embodiment of the present invention.

[0109] Computer-readable storage media include various media that can store program code, such as USB flash drives, external hard drives, ROM, RAM, magnetic disks, or optical disks.

[0110] This embodiment also provides a computer program product, which includes: a computer program stored in a readable storage medium, at least one processor of an electronic device can read the computer program from the readable storage medium, and the at least one processor executes the computer program to cause the electronic device to perform the solution provided in any of the above embodiments.

[0111] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this invention disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this invention can be achieved, and this is not limited herein.

[0112] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A remote sensing satellite network security situational awareness method with a dual prevention mechanism, characterized in that, include: Multi-source heterogeneous data is acquired from the remote sensing satellite ground system network. This multi-source heterogeneous data includes data that is out of sync and has different formats due to differences in data formats and protocols among multiple subsystems within the ground system. A structured dataset that solves the spatiotemporal alignment problem is generated through the following steps: The server device logs, network device alarms, and manually uploaded management-related unstructured data are obtained from the multi-source heterogeneous data, wherein the network device alarms include binary protocol data; The timestamps in the server device logs are uniformly converted to UTC time zone; the binary protocol data of the network device alarms are parsed to extract the alarm type and level; and the key fields of the manually uploaded management unstructured data are extracted and stored as key-value pairs. A cleaning algorithm based on Jaccard similarity is used to perform joint similarity calculation on the device ID, timestamp, and event type fields. When the overall similarity exceeds 0.9, it is judged as a duplicate record and removed to obtain a deduplicated dataset. Noise detection is performed on the numerical fields in the deduplicated dataset. If the variance of three consecutive sliding windows exceeds a preset threshold, a median filter with a window size of 5 is used for smoothing to obtain the cleaned dataset. The device identifiers and event codes in the cleaned dataset are uniformly converted into standardized asset numbers and event type codes through a field mapping table, generating a dataset with consistent field structure and data type. Based on the structured dataset, an asset identification algorithm is used to record network assets, and a risk heatmap of network assets is generated using a Bayesian network model and entropy weight method. Based on the risk heatmap and the structured dataset, a deep learning model is used to detect abnormal traffic and behavior, and a list of potential vulnerabilities with marked priorities is generated through a general vulnerability scoring standard and a threat intelligence database. Based on the risk heatmap and the hazard list, a dynamic security situation map is constructed using graph databases and community detection algorithms; Based on the dynamic security situation map, a comprehensive security index, a remediation priority list, and an emergency plan are generated using a weighted scoring model and the analytic hierarchy process. A situation assessment report and governance recommendations are then output.

2. The remote sensing satellite network security situational awareness method with a dual prevention mechanism as described in claim 1, characterized in that, Based on the structured dataset, network assets are recorded using an asset identification algorithm, and a risk heatmap of the network assets is generated using a Bayesian network model and entropy weight method, including: Software and hardware features are obtained from the structured dataset, and software and hardware identifiers are matched against a preset feature library using an asset identification algorithm to obtain a network asset list. Based on the network asset list, threat data corresponding to each asset in the network asset list is extracted from the structured dataset. The threat data is then input into a Bayesian network model, which uses a pre-established probabilistic graphical model and conditional probability table to calculate the probability of threat occurrence and impact value, and to determine the threat quantification result. Based on the threat quantification results, the entropy weight method is used to evaluate the dispersion of each risk indicator in the threat quantification results through information entropy, and the risk indicator weight set is calculated. By fusing the threat quantification results with the set of risk indicator weights, a risk heatmap is generated, in which the risk level distribution is represented by a color gradient.

3. The remote sensing satellite network security situational awareness method with a dual prevention mechanism as described in claim 1, characterized in that, Based on the risk heatmap and the structured dataset, a deep learning model is used to detect abnormal traffic and behavior. A priority-marked list of vulnerabilities is generated using a general vulnerability scoring standard and a threat intelligence database, including: High-risk area data are obtained from the risk heatmap, and a deep learning model is used to extract traffic features through convolutional layers and capture temporal dependencies through recurrent layers to obtain abnormal traffic identifiers. Based on the abnormal traffic identifier, the corresponding behavioral sequence data is extracted from the structured dataset. The vulnerability features in the behavioral sequence data are weighted and summed using basic indicators and time indicators using a general vulnerability scoring standard to determine the vulnerability priority sequence, wherein the vulnerability priority sequence includes vulnerability identifiers and priority scores. By querying the threat intelligence database using vulnerability identifiers in the vulnerability priority sequence and matching known attack patterns, a set of matching vulnerabilities is obtained. Based on the matching vulnerability set and the priority score in the vulnerability priority sequence, a vulnerability list is generated that lists asset identifiers and corresponding priority tags.

4. The remote sensing satellite network security situational awareness method with a dual prevention mechanism as described in claim 3, characterized in that, High-risk area data are obtained from the risk heatmap. A deep learning model is used to extract traffic features through convolutional layers and capture temporal dependencies through recurrent layers to obtain abnormal traffic identifiers, including: Network traffic sequences of high-risk areas are obtained from the risk heatmap, and the network traffic sequences are preprocessed using a deep learning model to obtain standardized traffic data. The spatiotemporal features of the standardized traffic data are extracted through the 1D convolutional layer of the deep learning model to obtain a feature sequence with a time dimension; By analyzing the time dependency of traffic feature vectors through the recurrent layers of the deep learning model, abnormal traffic patterns can be determined. An abnormal traffic identifier is generated by comparing the abnormal traffic pattern with a preset threshold.

5. The remote sensing satellite network security situational awareness method with a dual prevention mechanism as described in claim 1, characterized in that, Based on the risk heatmap and the hazard list, a dynamic security situation map is constructed using graph databases and community detection algorithms, including: The coordinates of high-risk areas are obtained from the risk heat map, and the priority of hazards is extracted from the hazard list. Hazard nodes carrying priority attributes are then inserted using a graph database. Based on the hazard list, define the relationships between nodes, generate edge weights, and use the Dijkstra algorithm from the highest-risk node to the core node through path analysis to obtain the critical path sequence. The Louvain algorithm is used to divide network communities based on the node connection relationships in a graph database, resulting in community clusters. Based on the critical path sequence and the community cluster, the priority attributes of the path nodes are extracted, and the evaluation index value is calculated by weighted summation of the path sequence length and the priority of the hidden danger, so as to obtain the set of control measures. By investigating the process chain and integrating the event response chain, and combining the graph database, critical path sequence, community clusters and control measures set, risk control thresholds are determined and a dynamic security situation map is generated.

6. The remote sensing satellite network security situational awareness method with a dual prevention mechanism as described in claim 5, characterized in that, Based on the hazard list, the relationships between nodes are defined, edge weights are generated, and Dijkstra's algorithm is used to traverse from the highest-risk node to the core node using path analysis, resulting in the following critical path sequence: Nodes and edge weights are obtained from the graph database, wherein the nodes include hazard nodes defined based on the hazard list, and the edge weights are generated based on the relationships between nodes. The highest-risk node and the core node are determined, wherein the highest-risk node is determined based on the coordinates of the high-risk area of ​​the risk heatmap, and the core node is a predefined critical network asset node. The Dijkstra algorithm is used to calculate the shortest path from the highest-risk node to the core node, thus obtaining the critical path sequence.

7. A remote sensing satellite network security situational awareness system with a dual prevention mechanism, based on the remote sensing satellite network security situational awareness method with a dual prevention mechanism as described in any one of claims 1-6, characterized in that, The remote sensing satellite network security situational awareness system with the dual prevention mechanism includes: The dataset generation module is used to acquire multi-source heterogeneous data from the remote sensing satellite ground system network and generate structured datasets through cleaning, denoising, and standardization. The heatmap generation module is used to record network assets based on the structured dataset using an asset identification algorithm, and to generate a risk heatmap of the network assets using a Bayesian network model and entropy weight method. The vulnerability list generation module is used to detect abnormal traffic and behavior using a deep learning model based on the risk heatmap and the structured dataset, and generate a vulnerability list with priority markings through a general vulnerability scoring standard and a threat intelligence database. The graph construction module is used to construct a dynamic security situation graph based on the risk heatmap and the hazard list, using graph databases and community detection algorithms; and The output module is used to generate a comprehensive security index, a repair priority list, and an emergency plan based on the dynamic security situation map using a weighted scoring model and the analytic hierarchy process, and to output a situation assessment report and governance recommendations.

8. An electronic device, characterized in that, include: At least one processor; as well as A memory that is communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the remote sensing satellite network security situational awareness method with dual prevention mechanism as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, It includes computer programs and instructions that, when the computer program or the instructions are run on a computer, cause the computer to perform a remote sensing satellite network security situational awareness method with a dual prevention mechanism as described in any one of claims 1-6.