Communication security situation awareness identification system
By constructing a communication security situation awareness and identification system, the limitations of traditional communication security protection in dealing with unknown threats and cross-domain attacks have been overcome. It enables early warning of unknown threats and accurate tracing of attack chains, and enhances the adaptability to complex network environments.
Patent Information
- Application Number
- CN202511671102.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-14
- Publication Date
- 2026-01-13
AI Technical Summary
Traditional communication security protection methods are unable to cope with unknown threats, lack a global perspective, cannot perceive attack chains across networks and devices, and the massive amount of security logs leads to response delays, making it difficult to adapt to complex network architectures and the widespread access of IoT devices.
Construct a communication security situation awareness and identification system, including user terminal and platform terminal. Through data collection module, basic analysis module and result display module, it performs real-time monitoring and basic situation analysis. Combined with attack reserve database and situation analysis module, it performs real-time updates and correlation analysis to achieve early warning of unknown threats and accurate tracing of attack chains.
It enables early warning of unknown threats and accurate tracing of attack chains, enhances the generalization capability of communication security situational awareness, and adapts to intelligent and cross-domain attacks in complex network environments.
Smart Images

Figure CN121333759A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of communication security situation awareness technology, specifically a communication security situation awareness and identification system. Background Technology
[0002] Traditional communication security protection methods mainly rely on perimeter defense, such as firewalls and intrusion detection systems (IDS). These technologies identify known threats through preset rules or signature databases and are effective in static, isolated network environments. However, with the rapid iteration and intelligent development of network attack methods, traditional methods have gradually revealed their limitations: First, signature-based detection methods are difficult to deal with unknown threats, especially zero-day exploits and new types of malware; second, isolated security devices lack a global perspective, cannot perceive attack chains across networks and devices, and are difficult to detect the covert behavior of advanced persistent threats; third, the massive amount of security logs and alerts leads to "alert fatigue," making it difficult for security personnel to extract key threats from the massive amounts of data, resulting in response delays.
[0003] At the same time, the complexity of communication network architecture has increased significantly. The deployment of technologies such as hybrid cloud, edge computing, and SD-WAN (Software-Defined Wide Area Network) has blurred network boundaries and dynamically changed traffic paths, making traditional security strategies based on fixed topologies inadequate. Furthermore, the widespread access of IoT devices has further expanded the attack surface, with numerous low-power, weakly authenticated devices becoming potential entry points, and traditional security mechanisms struggling to cover such heterogeneous terminals. Against this backdrop, communication security protection needs to shift from "passive defense" to "proactive awareness," achieving early threat detection, precise location, and rapid response through global situational analysis. Summary of the Invention
[0004] To address the problems of the above solutions, this invention provides a communication security situation awareness and identification system.
[0005] The objective of this invention can be achieved through the following technical solutions: A communication security situation awareness and identification system, comprising a user terminal and a platform terminal; The user interface includes a data collection module, a basic analysis module, and a results display module. The acquisition module is used to monitor communication data in real time and send the communication monitoring data to the basic analysis module. The basic analysis module is used to perform basic communication security situation analysis based on communication monitoring data to obtain corresponding basic situation awareness data, including attack behavior data, risk scores, and attack chains; and to send the basic situation awareness data to the situation analysis module on the platform.
[0006] Furthermore, the basic analysis module includes an attack identification unit, a risk assessment unit, and an attack reconstruction unit; The attack identification unit is used to analyze communication monitoring data to obtain corresponding attack behavior data; The risk assessment unit is used to perform risk assessment and obtain a risk score; The attack restoration unit is used to restore the attack chain.
[0007] The result display module is used to display results, acquire basic situational awareness data and related situational awareness data, and display the basic situational awareness data and related situational awareness data according to a preset display method.
[0008] The platform includes an attack reserve database and a situation analysis module. The attack reserve is used to store data on various communication attack methods.
[0009] Furthermore, the attack reserve is updated in real time.
[0010] Furthermore, the attack reserve is updated in real time, including: The system collects various communication attack methods in real time, performs calibration analysis on the collected communication attack methods based on the attack reserve database, and obtains the calibration results corresponding to the communication statistics methods. The calibration results include calibration pass and calibration fail. Based on the calibration results, data on communication attack methods that have passed the calibration are generated, and the attack reserve is updated and stored based on the data on communication attack methods.
[0011] Furthermore, the collected communication attack methods are calibrated and analyzed based on the attack reserve database, including: Establish a calibration model, the expression of which is: ; In the formula: (s, U) are the input data, s represents the corresponding communication attack method, and U is the reserve set corresponding to the attack reserve; s∉U means that the corresponding communication attack method does not belong to the reserve set; the output data is the calibration value HP(s, U), and the calibration value is 1 or 0; A reserve set is generated in real time based on the attack reserve database. The collected communication attack methods are integrated with the reserve set as input data and input into the calibration model for analysis to obtain the calibration value corresponding to the communication attack method. When the calibration value is 1, the calibration result is "calibration passed". When the calibration value is 0, the calibration result is "calibration failed".
[0012] The situation analysis module is used to perform situation correlation analysis, identify the received basic situation awareness data, and perform correlation analysis on the basic situation awareness data according to the attack reserve database to obtain the associated communication attack method data. Security posture simulation is performed based on associated communication attack data to obtain corresponding associated posture awareness data; the associated posture awareness data is then sent to the user terminal.
[0013] Furthermore, correlation analysis is performed on basic situational awareness data based on the attack reserve, including: Identify the attack behavior data, risk scores, and attack chains corresponding to the basic situational awareness data; analyze the basic situational awareness data and the data of various communication attack methods in the attack reserve to obtain the correlation assessment results between the data of each communication attack method and the basic situational awareness data; the correlation assessment results include no correlation, correlation, and execution probability; The corresponding implementation probability is added to the communication attack method data that is correlated according to the correlation assessment results, and the communication attack method data is used as the communication attack method data correlated with the basic situational awareness data.
[0014] Furthermore, correlation analysis is performed on basic situational awareness data based on the attack reserve, including: Establish a correlation analysis model, the expression of which is: ; In the formula: (q, p) are the input data, q is the corresponding communication attack method data; p is the basic situational awareness data; q→p indicates that there is a correlation between the corresponding communication attack method data and the basic situational awareness data; the output data is the correlation value GP(q, p), and the correlation value is 1 or 0; The data on communication attack methods and basic situational awareness in the attack reserve are analyzed using a correlation analysis model to obtain the correlation value of the communication attack method data. When the correlation value is 0, it indicates that there is no correlation between the data on the communication attack method and the basic situational awareness data. When the correlation value is 1, it is determined that there is a correlation between the communication attack method data and the basic situational awareness data; the probability of implementation corresponding to the communication attack method data is estimated.
[0015] Furthermore, security posture simulation is performed based on associated communication attack data, including: A digital twin is established, and the communication attack data is simulated and analyzed using the digital twin to obtain related situational awareness data.
[0016] Compared with the prior art, the beneficial effects of the present invention are: By constructing a dynamic perception and global collaborative communication security protection system, it effectively overcomes the inherent limitations of traditional boundary defense mechanisms in dealing with intelligent and cross-domain attacks; it breaks through the passive mode of static rule matching, and achieves early warning of unknown threats and accurate tracing of attack chains through multi-dimensional threat intelligence fusion and real-time situational analysis; through the mutual cooperation between the attack reserve, situational analysis module and basic analysis module, it increases the generalization capability of communication security situational awareness, and has a higher and more flexible adaptability to new attack methods. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a block diagram illustrating the principle of the present invention. Detailed Implementation
[0019] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0020] like Figure 1 As shown, a communication security situation awareness and identification system includes a user terminal and a platform terminal; The user terminal is used by users and generally communicates with the platform.
[0021] The user interface includes a data collection module, a basic analysis module, and a results display module. The acquisition module is used to collect communication monitoring data related to communication security situational awareness in real time, such as network traffic (e.g., NetFlow, sFlow), system logs (Windows / Linux event logs), terminal behavior data (e.g., USB device access records), and threat intelligence (e.g., vulnerability databases, malicious IP lists), and send the communication monitoring data to the basic analysis module.
[0022] For example, deploy traffic probes or log collectors at key nodes such as network boundaries, core switches, and servers to ensure comprehensive data coverage.
[0023] The basic analysis module is used to perform basic communication security situation analysis based on communication monitoring data, and obtain corresponding basic situation awareness data, including attack behavior data, risk scores, and attack chains; and sends the basic situation awareness data to the platform.
[0024] The basic analysis module is a function module that sets up functions based on existing communication security situation awareness and identification technologies.
[0025] In one embodiment, the basic analysis module includes an attack identification unit, a risk assessment unit, and an attack reconstruction unit; The attack identification unit is used to analyze communication monitoring data to obtain corresponding attack behavior data.
[0026] To obtain attack behavior data based on existing methods.
[0027] The risk assessment unit is used to conduct risk assessments and obtain risk scores.
[0028] By combining factors such as threat frequency, scope of impact, and asset value, a risk score (such as CVSS score) is calculated for this attack behavior data.
[0029] The attack reconstruction unit is used to reconstruct the attack chain; For example, traffic attribution techniques can be used to reconstruct the attack chain (such as the complete path from phishing emails to internal network penetration).
[0030] The data obtained from each functional unit are integrated into basic situational awareness data.
[0031] Other real-time examples may also include related functional units such as risk prediction.
[0032] The results display module is used to display results, acquire basic situational awareness data and related situational awareness data, and display the basic situational awareness data and related situational awareness data according to a preset display method, such as charts and graphs. It can also be combined with human-computer interaction, intelligent question answering and other technologies for display.
[0033] The platform includes an attack reserve database and a situation analysis module. The attack reserve is used to store data on various communication attack methods. The communication attack method data includes information related to the communication attack method, such as the attack category and behavior pattern, the specific technical means and tools used in the attack, and other related information.
[0034] In one embodiment, to ensure the accuracy of the analysis, the attack reserve database needs to be comprehensive. Therefore, the attack reserve database needs to be dynamically updated, and the update method is as follows: Based on various existing technologies, various communication attack methods can be obtained in real time. For example, the platform can pre-specify several data channels and then obtain various communication attack methods from the corresponding data channels. The collected communication attack methods are calibrated and analyzed based on the attack reserve database to obtain the calibration results corresponding to the communication statistics methods. The calibration results include calibration pass and calibration fail. Based on the calibration results, data on communication attack methods that have passed calibration is generated. The attack reserve is updated and stored based on the data on communication attack methods. Data on communication attack methods that have passed calibration is stored, and data on communication attack methods that are outdated or have poor calibration results can be replaced.
[0035] In one embodiment, calibration analysis of the collected communication attack methods is performed based on an attack reserve database, including: Establish a calibration model, the expression of which is: ; In the formula: (s, U) represents the input data, s represents the corresponding communication attack method, and U is the reserve set corresponding to the attack reserve, which is formed by the data of each communication attack method in the attack reserve; s∉U means that the corresponding communication attack method does not belong to the reserve set, that is, there is no corresponding communication attack method in the reserve set and it cannot be replaced. For example, if the reserve set has method B, and the attack simulation effect of method B can replace the attack simulation of method A, then method A is considered to be replaceable and is considered to belong to the reserve set. For example, if an optimized method of a certain attack method is stored, its historical method can be replaced. It is used to reduce the amount of subsequent analysis and improve the analysis efficiency. According to the substitution relationship, the attack reserve can be updated. For example, if the newly stored communication attack method data can replace the original communication attack method data in the attack reserve, it will be removed. The platform marks the corresponding training set for training, and the output data is the calibration value HP(s, U), and the calibration value is 1 or 0. Based on the attack reserve database, a corresponding reserve set is generated in real time. The collected communication attack methods are integrated with the reserve set as input data and input into the calibration model for analysis to obtain the calibration value corresponding to the communication attack method. When the calibration value is 1, the calibration result is "calibration passed". When the calibration value is 0, the calibration result is "calibration failed".
[0036] In one embodiment, the attack reserve is updated in real time, which can be done using various existing methods.
[0037] The situation analysis module is used to perform situation correlation analysis, identify the received basic situation awareness data, and perform correlation analysis on the basic situation awareness data according to the attack reserve database to obtain the associated communication attack method data. Security situation simulation is performed based on associated communication attack data to obtain corresponding associated situation awareness data, that is, the current communication security situation awareness data under the corresponding communication attack data, which is marked as associated situation awareness data; the associated situation awareness data is then sent to the user terminal.
[0038] In one embodiment, correlation analysis is performed on basic situational awareness data based on an attack reserve, including: Identify the attack behavior data, risk scores, and attack chains corresponding to the basic situational awareness data; analyze the basic situational awareness data and the data of various communication attack methods in the attack reserve to determine whether there is a correlation between the corresponding communication attack method data and the basic situational awareness data. If the communication attack method corresponding to the data of the communication attack method may be used in the future, it is considered to be correlated. If the correlation is determined, the corresponding implementation probability is estimated, that is, the probability of using the communication attack method to launch an attack. The real-time probability will be added to the data on communication attack methods.
[0039] In one embodiment, correlation prediction can be performed based on an attack reserve database without updating models or other methods, using existing techniques. For example, it can be estimated whether a communication attack method is likely to be applied under the current user situation and basic situational awareness data, based on historical data corresponding to various communication attack methods. If so, the corresponding implementation probability can be estimated based on the relevant historical data. This does not require updating models or other methods when new attack methods emerge. For example, existing situational predictions based on machine learning may fail to be processed in a timely manner when new attacks occur due to lack of training, resulting in decreased accuracy and potential failure due to a lack of corresponding features. In this embodiment, however, it is sufficient to estimate the implementation probability based on the relevant historical data. If the implementation probability is not 0, it can be considered as a correlation.
[0040] In one embodiment, correlation analysis is performed on basic situational awareness data based on an attack reserve, including: A correlation analysis model is established based on the user's actual communication situation. The expression of the correlation analysis model is as follows: ; In the formula: (q, p) represents the input data, where q represents the corresponding communication attack method data, p represents the basic situational awareness data, and q→p indicates a correlation between the corresponding communication attack method data and the basic situational awareness data. The output data is the correlation value GP(q, p), which can be 1 or 0. The relevant historical data of the corresponding communication attack method data is used for judgment, and the platform sets a corresponding training set for training, so that it can subsequently determine whether there is a correlation between the communication attack method data and the basic situational awareness data. The data on communication attack methods and basic situational awareness in the attack reserve are analyzed by using a correlation analysis model to obtain the correlation values of the corresponding communication attack method data. When the correlation value is 0, there is no correlation between the data on evaluating communication attack methods and the basic situational awareness data. When the correlation value is 1, it indicates that there is a correlation between the communication attack method data and the basic situational awareness data. Based on the communication attack method data, relevant historical attack data is collected to determine the implementation probability based on the basic situational awareness data. Alternatively, the historical data can be statistically analyzed according to the corresponding background conditions, and the implementation probability can be determined based on the corresponding attack ratio.
[0041] The results of the correlation assessment were compiled.
[0042] In one embodiment, security posture simulation is performed based on associated communication attack method data, including: Based on the existing communication security protection situation and digital twin technology, a corresponding digital twin is established. The digital twin is used to simulate and analyze communication attack methods to obtain related situational awareness data, taking into account the corresponding implementation probability.
[0043] In one embodiment, security posture simulation can be performed based on associated communication attack method data, and simulation and prediction can also be performed based on various other existing methods; how to combine the attack effect and implementation probability of the corresponding communication attack method data for prediction.
[0044] The above formulas are all numerical calculations after removing dimensions. The formulas are obtained by software simulation based on a large amount of data and are closest to the real situation. The preset parameters and preset thresholds in the formulas are set by those skilled in the art according to the actual situation or obtained by simulation based on a large amount of data.
[0045] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. A communication security situation awareness and identification system, characterized in that, Including both the user end and the platform end; The user-side includes a data collection module, a basic analysis module, and a results display module; the platform-side includes an attack reserve database and a situational analysis module. The acquisition module is used to monitor communication data in real time and send the communication monitoring data to the basic analysis module. The basic analysis module is used to perform basic communication security situation analysis based on communication monitoring data to obtain corresponding basic situation awareness data, which includes attack behavior data, risk scores, and attack chains. Send basic situation awareness data to the situation analysis module on the platform; The result display module is used to display the results, acquire basic situational awareness data and related situational awareness data, and display the basic situational awareness data and related situational awareness data according to a preset display method. The attack reserve is used to store data on various communication attack methods; The situation analysis module is used to perform situation correlation analysis, identify the received basic situation awareness data, and perform correlation analysis on the basic situation awareness data according to the attack reserve database to obtain the associated communication attack method data. Security posture simulation is performed based on associated communication attack data to obtain corresponding associated posture awareness data; the associated posture awareness data is then sent to the user terminal.
2. The communication security situation awareness and identification system according to claim 1, characterized in that, The basic analysis module includes an attack identification unit, a risk assessment unit, and an attack reconstruction unit; The attack identification unit is used to analyze communication monitoring data to obtain corresponding attack behavior data; The risk assessment unit is used to perform risk assessment and obtain a risk score; The attack restoration unit is used to restore the attack chain.
3. The communication security situation awareness and identification system according to claim 1, characterized in that, The attack reserve is updated in real time.
4. The communication security situation awareness and identification system according to claim 3, characterized in that, The attack reserve is updated in real time, including: The system collects various communication attack methods in real time, performs calibration analysis on the collected communication attack methods based on the attack reserve database, and obtains the calibration results corresponding to the communication statistics methods. The calibration results include calibration pass and calibration fail. Based on the calibration results, data on communication attack methods that have passed the calibration are generated, and the attack reserve is updated and stored based on the data on communication attack methods.
5. A communication security situation awareness and identification system according to claim 4, characterized in that, The collected communication attack methods are calibrated and analyzed based on the attack database, including: Establish a calibration model, the expression of which is: ; In the formula: (s, U) are the input data, s represents the corresponding communication attack method, and U is the reserve set corresponding to the attack reserve; s∉U means that the corresponding communication attack method does not belong to the reserve set; the output data is the calibration value HP(s, U), and the calibration value is 1 or 0; A reserve set is generated in real time based on the attack reserve database. The collected communication attack methods are integrated with the reserve set as input data and input into the calibration model for analysis to obtain the calibration value corresponding to the communication attack method. When the calibration value is 1, the calibration result is "calibration passed". When the calibration value is 0, the calibration result is "calibration failed".
6. The communication security situation awareness and identification system according to claim 1, characterized in that, Based on the attack reserve database, correlation analysis is performed on basic situational awareness data, including: Identify the attack behavior data, risk scores, and attack chains corresponding to the basic situational awareness data; analyze the basic situational awareness data and the data of various communication attack methods in the attack reserve to obtain the correlation assessment results between the data of each communication attack method and the basic situational awareness data; the correlation assessment results include no correlation, correlation, and execution probability; The corresponding implementation probability is added to the communication attack method data that is correlated according to the correlation assessment results, and the communication attack method data is used as the communication attack method data correlated with the basic situational awareness data.
7. A communication security situation awareness and identification system according to claim 6, characterized in that, Based on the attack reserve database, correlation analysis is performed on basic situational awareness data, including: Establish a correlation analysis model, the expression of which is: ; In the formula: (q, p) are the input data, q is the corresponding communication attack method data; p is the basic situational awareness data; q→p indicates that there is a correlation between the corresponding communication attack method data and the basic situational awareness data; the output data is the correlation value GP(q, p), and the correlation value is 1 or 0; The data on communication attack methods and basic situational awareness in the attack reserve are analyzed using a correlation analysis model to obtain the correlation value of the communication attack method data. When the correlation value is 0, it indicates that there is no correlation between the data on the communication attack method and the basic situational awareness data. When the correlation value is 1, it is determined that there is a correlation between the communication attack method data and the basic situational awareness data; the probability of implementation corresponding to the communication attack method data is estimated.
8. A communication security situation awareness and identification system according to claim 1, characterized in that, Security posture simulation is performed based on associated communication attack data, including: A digital twin is established, and the communication attack data is simulated and analyzed using the digital twin to obtain related situational awareness data.