A network security abnormal behavior early warning management method

By constructing a security behavior architecture diagram and comparing and analyzing historical and network monitoring data, the problem of comprehensiveness and accuracy in the early warning management of abnormal network security behavior in existing technologies has been solved, and comprehensive and accurate judgment and early warning of abnormal behavior of target networks has been achieved.

CN121418209BActive Publication Date: 2026-03-03JIANGMEN POLYTECHNIC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511998516.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-29
Publication Date
2026-03-03
Estimated Expiration
2045-12-29

AI Technical Summary

Technical Problem

Existing technologies cannot make comprehensive and accurate judgments on abnormal behavior based on the actual behavior of the target network, resulting in a lack of comprehensiveness and accuracy in the results of network security abnormal behavior early warning management.

Method used

By constructing a security behavior architecture diagram, generating architecture nodes based on historical behavior data, conducting comparative analysis of the behavior architecture layers, combining network monitoring data to judge abnormal behavior, and setting early warning assessment intervals to determine the early warning method.

Benefits of technology

It enables comprehensive and accurate judgment of abnormal behavior in the target network, improves the comprehensiveness and accuracy of abnormal behavior early warning management, and refines it into abnormal monitoring behavior, behavior architecture layer and overall network early warning management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121418209B_ABST
    Figure CN121418209B_ABST
Patent Text Reader

Abstract

This invention discloses a network security abnormal behavior early warning management method in the field of network security technology, including the following steps: S1: constructing a security behavior architecture diagram of the target network; S2: inputting security monitoring behaviors into the security behavior architecture diagram and analyzing the target security behaviors; S3: setting an early warning evaluation interval; S4: judging abnormal monitoring behaviors and analyzing the behavior early warning methods of the abnormal monitoring behaviors; S5: analyzing the architecture layer anomaly coefficient of the behavior architecture layer and analyzing the abnormal behavior architecture layer and its architecture layer early warning method; S6: analyzing the network anomaly coefficient of the target network and analyzing the network early warning method of the target network; and performing abnormal behavior early warning of the target network based on the behavior early warning method, architecture layer early warning method, and network early warning method. This invention improves the comprehensiveness and accuracy of target network abnormal behavior early warning management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and specifically to a method for early warning and management of abnormal network security behavior. Background Technology

[0002] In the digital age, the internet has deeply integrated into all aspects of individuals and businesses, becoming an indispensable infrastructure. However, the accompanying cybersecurity issues are also becoming increasingly severe. Frequent cybersecurity threats, data breaches, and equipment failures are causing serious damage to personal information security and related infrastructure for business operations. Given the increasingly severe cybersecurity situation, building cybersecurity anomaly behavior early warning and management devices is a key measure to cope with complex and ever-changing cyber threats. In this context, cybersecurity anomaly behavior early warning and management, as a core component for early threat identification and avoidance, can serve as a crucial support for a cybersecurity protection system in terms of technical effectiveness and reliability.

[0003] The network security abnormal behavior early warning management methods in related technologies often fail to make a comprehensive and accurate judgment on the abnormal behavior of the target network based on the actual behavior of the target network, and fail to accurately determine the early warning target and early warning method based on the abnormal behavior judgment results. As a result, the early warning management results of the target network's abnormal behavior lack comprehensiveness and accuracy, and there is room for improvement. Summary of the Invention

[0004] The purpose of this application is to provide a network security abnormal behavior early warning management method to improve the problem that network security abnormal behavior early warning management methods in related technologies often cannot make a comprehensive and accurate judgment on the abnormal behavior of the target network based on the actual behavior of the target network, and cannot accurately determine the early warning target and early warning method of the target network based on the abnormal behavior judgment result, resulting in the lack of comprehensiveness and accuracy of the abnormal behavior early warning management result of the target network.

[0005] This application provides a method for early warning and management of abnormal network security behavior, including:

[0006] Step S1: Obtain historical behavior data of the target network, and obtain the security standard behavior of the target network based on the historical behavior data; generate architecture nodes based on the security standard behavior, generate a behavior architecture layer based on the architecture nodes, and construct the security behavior architecture diagram corresponding to the target network based on the behavior architecture layer and architecture nodes.

[0007] Step S2: Obtain network monitoring data, and obtain the security monitoring behavior of the target network based on the network monitoring data; input the security monitoring behavior into the security behavior architecture diagram, and perform a first comparison analysis between the security monitoring behavior and the security behavior architecture diagram to obtain the target behavior architecture layer; perform a second comparison analysis between the security monitoring behavior and the architecture nodes in the target behavior architecture layer to obtain the target security behavior;

[0008] Step S3: Set the early warning assessment interval, and each early warning assessment interval corresponds to an early warning response method;

[0009] Step S4: Based on the security monitoring behavior and the target security behavior, determine and obtain the abnormal monitoring behavior in the security monitoring behavior, and the behavior abnormality coefficient corresponding to the abnormal monitoring behavior; and analyze the behavior early warning method corresponding to the abnormal monitoring behavior based on the early warning assessment interval and the behavior abnormality coefficient.

[0010] Step S5: Based on the behavior anomaly coefficient analysis corresponding to the abnormal monitoring behavior, obtain the architecture layer anomaly coefficient corresponding to each behavior architecture layer in the security behavior architecture diagram; and based on the early warning evaluation interval and the architecture layer anomaly coefficient analysis, obtain the abnormal behavior architecture layer in the security behavior architecture diagram, as well as the architecture layer early warning method corresponding to the abnormal behavior architecture layer.

[0011] Step S6: Based on the architecture layer anomaly coefficients of each behavior architecture layer in the security behavior architecture diagram, obtain the network anomaly coefficients corresponding to the target network; based on the early warning evaluation interval and network anomaly coefficient analysis, obtain the network early warning method for the target network; based on the behavior early warning method, architecture layer early warning method, and network early warning method, issue an early warning for the abnormal behavior of the target network.

[0012] Furthermore, based on historical behavioral data, the target network's security standard behavior is obtained, specifically as follows:

[0013] Configure security behavior types, which include network behavior types, device behavior types, user behavior types, and data behavior types;

[0014] Based on the security behavior type, the historical behavior data is extracted to obtain the security standard behavior contained in the historical behavior data, and the security behavior type corresponding to the security standard behavior.

[0015] The security standard behaviors include network standard behaviors, device standard behaviors, user standard behaviors, and data standard behaviors.

[0016] Furthermore, based on security standard behavior, architecture nodes are generated; based on these architecture nodes, a behavior architecture layer is generated; and based on the behavior architecture layer and architecture nodes, a security behavior architecture diagram corresponding to the target network is constructed, specifically as follows:

[0017] A behavior architecture layer is constructed based on the security behavior types corresponding to security standard behaviors; the behavior architecture layer includes a network behavior architecture layer, a device behavior architecture layer, a user behavior architecture layer, and a data behavior architecture layer;

[0018] Network architecture nodes are generated based on the network standard behaviors, and the network architecture nodes correspond to the network standard behaviors; and the network architecture nodes are recorded as architecture layer nodes in the network behavior architecture layer.

[0019] Based on the device standard behavior, device architecture nodes are generated, and the device architecture nodes correspond to the device standard behavior; and the device architecture nodes are recorded as architecture layer nodes in the device behavior architecture layer.

[0020] User architecture nodes are generated based on the user's standard behavior, and the user architecture nodes correspond to the user's standard behavior; and the user architecture nodes are recorded as architecture layer nodes in the user behavior architecture layer.

[0021] Based on the network behavior architecture layer, device behavior architecture layer, user behavior architecture layer, and data behavior architecture layer, a security behavior architecture diagram corresponding to the target network is constructed.

[0022] Furthermore, network monitoring data is acquired, and the security monitoring behavior of the target network is obtained based on the network monitoring data, specifically as follows:

[0023] Based on the security behavior type, the network monitoring data is extracted to obtain the corresponding security monitoring behavior in the network monitoring data, and the monitoring behavior type corresponding to the security monitoring behavior.

[0024] The types of security monitoring activities include network monitoring, device monitoring, user monitoring, and data monitoring.

[0025] Furthermore, a first comparison analysis is performed between the security monitoring behavior and the security behavior architecture diagram to obtain the target behavior architecture layer; a second comparison analysis is performed between the security monitoring behavior and the architecture nodes in the target behavior architecture layer to obtain the target security behavior, specifically:

[0026] The monitoring behavior type corresponding to the security monitoring behavior is compared with the security behavior type corresponding to each behavior architecture layer in the security behavior architecture diagram; and the behavior architecture layer whose security behavior type matches the monitoring behavior type is recorded as the target behavior architecture layer corresponding to the security monitoring behavior.

[0027] The security monitoring behavior is compared with the security standard behavior corresponding to the architecture layer node in the target behavior architecture layer; the architecture layer node in the target behavior architecture layer that matches the security monitoring behavior is recorded as the target node, and the security standard behavior corresponding to the target node is recorded as the target security behavior.

[0028] Furthermore, early warning assessment intervals are set, and each early warning assessment interval corresponds to an early warning response method, specifically:

[0029] The early warning assessment interval includes the behavioral early warning assessment interval, the architectural early warning assessment interval, and the network early warning assessment interval;

[0030] Each of the behavioral warning assessment intervals corresponds to a behavioral response method; each of the architecture warning assessment intervals corresponds to an architecture response method; and each of the network warning assessment intervals corresponds to a network response method.

[0031] Further, step S4 specifically includes:

[0032] The security monitoring behavior is compared with the target security behavior. If the security monitoring behavior is inconsistent with the target security behavior, the security monitoring behavior is recorded as an abnormal monitoring behavior. The behavioral deviation value between the abnormal monitoring behavior and the target security behavior is obtained.

[0033] Based on the monitoring behavior type of the abnormal monitoring behavior, set the first behavior weight of the abnormal monitoring behavior; obtain the number of related behaviors of the abnormal monitoring behavior, and set the second behavior weight of the abnormal monitoring behavior based on the number of related behaviors; obtain the abnormal weight of the abnormal monitoring behavior based on the first behavior weight and the second behavior weight.

[0034] The behavioral deviation value of the abnormal monitoring behavior is weighted according to the aforementioned abnormal weight to obtain the behavioral abnormality coefficient corresponding to the abnormal monitoring behavior;

[0035] The abnormal behavior coefficient corresponding to the abnormal monitoring behavior is compared with the behavior early warning assessment interval, and the behavior response mode corresponding to the behavior early warning assessment interval where the abnormal behavior coefficient is located is recorded as the behavior early warning mode corresponding to the abnormal monitoring behavior.

[0036] Further, step S5 specifically includes:

[0037] Nodes in the target behavior architecture layer that do not match the security monitoring behavior are marked as missing nodes.

[0038] Obtain the number of missing nodes corresponding to the missing nodes in the target behavior architecture layer, and the total number of nodes in the target behavior architecture layer; obtain the missing behavior coefficient corresponding to the target behavior architecture layer based on the number of missing nodes and the total number of nodes;

[0039] The abnormal behavior coefficients corresponding to the abnormal monitoring behaviors in the target behavior architecture layer are summed to obtain the abnormal behavior coefficients corresponding to the target behavior architecture layer.

[0040] Set missing weights and abnormal weights, and obtain the architecture layer abnormality coefficients corresponding to the target behavior architecture layer based on the missing weights and missing behavior coefficients, abnormal weights and abnormal behavior coefficients;

[0041] The abnormal coefficient of the architecture layer corresponding to the behavioral architecture layer is compared with the architecture early warning evaluation interval. If the abnormal coefficient of the architecture layer corresponding to the behavioral architecture layer is within the architecture early warning evaluation interval, the behavioral architecture layer is determined to be an abnormal behavioral architecture layer.

[0042] The architecture response method corresponding to the architecture early warning evaluation interval where the architecture layer anomaly coefficient is located is recorded as the architecture layer early warning method corresponding to the abnormal behavior architecture layer.

[0043] Further, step S6 specifically includes:

[0044] The architecture layer weights of the behavior architecture layer are set based on the security behavior types corresponding to the behavior architecture layers; the architecture layer weights correspond to the security behavior types.

[0045] The anomaly coefficients of the behavioral architecture layer are weighted according to the architecture layer weights to obtain the comprehensive anomaly coefficients corresponding to the behavioral architecture layer; the comprehensive anomaly coefficients of each behavioral architecture layer in the security behavioral architecture diagram are summed to obtain the network anomaly coefficients corresponding to the target network.

[0046] The network anomaly coefficient of the target network is compared with the network early warning assessment interval. If the network anomaly coefficient of the target network is not within the network early warning assessment interval, then no network early warning is required for the target network.

[0047] If the network anomaly coefficient corresponding to the target network is within the network early warning assessment range, then a network early warning needs to be issued for the target network, and the network response method corresponding to the network early warning assessment range where the network anomaly coefficient is located is recorded as the network early warning method corresponding to the target network.

[0048] In summary, the beneficial effects of this application are:

[0049] 1. This application obtains the standard security behavior of the target network based on historical behavior data, constructs a behavior architecture layer based on the security behavior types corresponding to the standard security behavior, generates architecture layer nodes in the behavior architecture layer based on the standard security behavior, and constructs a security behavior architecture diagram of the target network based on the behavior architecture layer and the architecture layer nodes in the behavior architecture layer. That is, the security behavior architecture diagram contains the behavior architecture layer, and the behavior architecture layer contains architecture layer nodes corresponding to the standard security behavior. In addition, the security monitoring behavior of the target network is obtained based on network monitoring data. By judging abnormal behavior of the security monitoring behavior through the behavior architecture layer and architecture layer nodes in the security behavior architecture diagram, the abnormal judgment results of the security monitoring behavior can be more comprehensive and accurate, and the comprehensive and accurate abnormal behavior judgment of the target network can be achieved based on the actual behavior of the target network.

[0050] 2. This application constructs a security behavior architecture diagram. After inputting the security monitoring behavior of the target network into the security behavior architecture diagram, it performs a two-way comparative analysis between the security monitoring behavior and the security behavior architecture diagram. Firstly, it performs a first comparative analysis between the security monitoring behavior and the behavior architecture layer in the security behavior architecture diagram to obtain the target behavior architecture layer corresponding to the security monitoring behavior. Secondly, it performs a second comparative analysis between the security monitoring behavior and the architecture nodes in the target behavior architecture layer to obtain the target security behavior corresponding to the security monitoring behavior. Through the target behavior architecture layer and the target security behavior, a security standard behavior that precisely matches the security monitoring behavior can be obtained, further improving the accuracy of the anomaly judgment results of the security monitoring behavior.

[0051] 3. This application refines the security behavior early warning management of the target network into three dimensions: early warning management of abnormal monitoring behavior, early warning management of the abnormal behavior architecture layer, and overall early warning management of the target network. This refined early warning management further improves the comprehensiveness and accuracy of the abnormal behavior early warning management results for the target network. Specifically, it identifies and obtains abnormal monitoring behaviors and their corresponding behavior anomaly coefficients based on security monitoring behaviors and target security behaviors. It then analyzes the early warning assessment interval and behavior anomaly coefficients to obtain the corresponding behavior early warning methods. Based on the behavior anomaly coefficients corresponding to the abnormal monitoring behaviors, it obtains the architecture layer anomaly coefficients for each behavior architecture layer in the security behavior architecture diagram. Based on the early warning assessment interval and architecture layer anomaly coefficients, it obtains the abnormal behavior architecture layer in the security behavior architecture diagram and the corresponding architecture layer early warning methods. Finally, based on the architecture layer anomaly coefficients for each behavior architecture layer in the security behavior architecture diagram, it obtains the network anomaly coefficients corresponding to the target network. Finally, it analyzes the early warning assessment interval and network anomaly coefficients to obtain the corresponding network early warning methods for the target network. Attached Figure Description

[0052] To more clearly illustrate the technical solutions of the embodiments of this application, some of the accompanying drawings in the embodiments of this application will be briefly described below. It should be understood that the following drawings only show some embodiments of this application and should not be considered as a limitation on the scope of this application.

[0053] Figure 1 This is a flowchart illustrating a network security abnormal behavior early warning management method provided in this application. Detailed Implementation

[0054] The following examples and... Figure 1 This application will be described in further detail, but the implementation of this application is not limited thereto.

[0055] Reference Figure 1 The diagram shown is a flowchart illustrating a network security abnormal behavior early warning management method provided in an embodiment of this application.

[0056] A method for early warning and management of abnormal network security behavior includes:

[0057] Step S1: Obtain historical behavior data of the target network, and obtain the security standard behavior of the target network based on the historical behavior data; generate architecture nodes based on the security standard behavior, generate a behavior architecture layer based on the architecture nodes, and construct the security behavior architecture diagram corresponding to the target network based on the behavior architecture layer and architecture nodes.

[0058] Step S2: Obtain network monitoring data, and obtain the security monitoring behavior of the target network based on the network monitoring data; input the security monitoring behavior into the security behavior architecture diagram, and perform a first comparison analysis between the security monitoring behavior and the security behavior architecture diagram to obtain the target behavior architecture layer; perform a second comparison analysis between the security monitoring behavior and the architecture nodes in the target behavior architecture layer to obtain the target security behavior;

[0059] Step S3: Set the early warning assessment interval, and each early warning assessment interval has a corresponding early warning response method;

[0060] Step S4: Based on the safety monitoring behavior and the target safety behavior, determine and obtain the abnormal monitoring behavior in the safety monitoring behavior, as well as the behavior abnormality coefficient corresponding to the abnormal monitoring behavior; and analyze the behavior early warning method corresponding to the abnormal monitoring behavior based on the early warning assessment interval and the behavior abnormality coefficient.

[0061] Step S5: Based on the behavior anomaly coefficient analysis corresponding to the abnormal monitoring behavior, obtain the architecture layer anomaly coefficient corresponding to each behavior architecture layer in the security behavior architecture diagram; and based on the early warning assessment interval and architecture layer anomaly coefficient analysis, obtain the abnormal behavior architecture layer in the security behavior architecture diagram, as well as the architecture layer early warning method corresponding to the abnormal behavior architecture layer.

[0062] Step S6: Based on the architecture layer anomaly coefficients of each behavior architecture layer in the security behavior architecture diagram, obtain the network anomaly coefficients corresponding to the target network; based on the early warning assessment interval and network anomaly coefficient analysis, obtain the network early warning method for the target network; and conduct abnormal behavior early warning for the target network based on the behavior early warning method, architecture layer early warning method, and network early warning method.

[0063] In some embodiments, after acquiring network monitoring data of the target network, the security monitoring behavior of the target network is input into the security behavior architecture diagram of the target network. The target behavior architecture layer and target security behavior corresponding to the security monitoring behavior are obtained through the security behavior architecture diagram. Step S4 obtains the abnormal monitoring behavior of the target network that requires early warning, and the corresponding behavior early warning method. Step S5 obtains the abnormal behavior architecture layer of the target network that requires early warning, and the corresponding architecture layer early warning method. Step S6 determines whether an early warning is needed for the entire target network, and if an early warning is needed for the entire target network, the corresponding network early warning method is obtained. Furthermore, steps S3 to S6 of this application can be embedded within the security behavior architecture diagram, meaning that inputting the security monitoring behavior of the target network into the security behavior architecture diagram yields the behavior early warning method, the architecture layer early warning method, and the network early warning method. Steps S3 to S6 of this application are also embedded in an analysis model independent of the security behavior architecture diagram, and the analysis process of steps S3 to S6 is implemented based on the analysis model.

[0064] The target network's security standard behavior is obtained based on historical behavioral data, specifically as follows:

[0065] Configure security behavior types, which include network behavior types, device behavior types, user behavior types, and data behavior types;

[0066] Based on the type of security behavior, the content of the historical behavior data is extracted to obtain the standard security behaviors contained in the historical behavior data, as well as the type of security behavior corresponding to the standard security behaviors.

[0067] Security standard behaviors include network standard behaviors, device standard behaviors, user standard behaviors, and data standard behaviors.

[0068] In some embodiments, security behavior types can also be customized according to the actual management needs of the target network. For example, security behavior types may only include network behavior types, user behavior types, and data behavior types.

[0069] In some embodiments, historical behavior data includes at least one security standard behavior, and each security standard behavior corresponds to standard behavior content. For example, a security standard behavior is short-term login failure, and the standard behavior content of this security standard behavior can be ≥5 login failures within 1 hour. That is, a security standard behavior is actually composed of the security standard behavior and the standard behavior content of the security standard behavior. It should be noted that the standard behavior content of the security standard behavior can be preset according to the actual network application of the target network.

[0070] In some embodiments, standard network behaviors include, but are not limited to, abnormal bandwidth usage, unauthorized VPN access, etc., wherein the standard behavior of abnormal bandwidth usage can be set as bandwidth usage ≥90% and lasting for more than 30 minutes.

[0071] In some embodiments, the standard behavior of the device includes, but is not limited to, standard behaviors such as abnormal core server processes and unfamiliar terminals accessing the intranet. The standard behavior of abnormal core server processes can be set to the process occupying ≥80% of CPU and lasting for more than 1 hour.

[0072] In some embodiments, standard user behaviors include, but are not limited to, short-term login failures and simultaneous online access of the same account on multiple devices. The standard behavior of short-term login failures can be set to ≥6 login failures within 1 hour.

[0073] In some embodiments, standard data behaviors include, but are not limited to, batch export of sensitive data and transmission of sensitive data through an unencrypted channel. The standard behavior of batch export of sensitive data can be set to export ≥500 sensitive data items in a single transaction.

[0074] Based on security standard behavior, architecture nodes are generated; based on these architecture nodes, a behavior architecture layer is generated; and based on the behavior architecture layer and architecture nodes, a security behavior architecture diagram corresponding to the target network is constructed, specifically as follows:

[0075] A behavior architecture layer is constructed based on the security behavior types corresponding to security standard behaviors; the behavior architecture layer includes a network behavior architecture layer, a device behavior architecture layer, a user behavior architecture layer, and a data behavior architecture layer;

[0076] Network architecture nodes are generated based on standard network behaviors, and these nodes correspond to the standard network behaviors. The network architecture nodes are then recorded as architecture layer nodes in the network behavior architecture layer.

[0077] Device architecture nodes are generated based on standard device behaviors, and these device architecture nodes correspond to the standard device behaviors. The device architecture nodes are then recorded as architecture layer nodes in the device behavior architecture layer.

[0078] User architecture nodes are generated based on standard user behaviors, and each user architecture node corresponds to a standard user behavior; these user architecture nodes are then recorded as architecture layer nodes in the user behavior architecture layer.

[0079] Construct a security behavior architecture diagram corresponding to the target network based on the network behavior architecture layer, device behavior architecture layer, user behavior architecture layer, and data behavior architecture layer.

[0080] In some embodiments, there is a one-to-one correspondence between behavioral architecture layers and security behavior types. The number of behavioral architecture layers in the security behavioral architecture diagram corresponds to the number of security behavior types in the target network.

[0081] Obtain network monitoring data, and based on this data, determine the security monitoring behavior of the target network, specifically:

[0082] Based on the security behavior type, the network monitoring data is extracted to obtain the corresponding security monitoring behavior in the network monitoring data, as well as the monitoring behavior type corresponding to the security monitoring behavior.

[0083] Security monitoring activities include network monitoring, equipment monitoring, user monitoring, and data monitoring.

[0084] In some embodiments, network monitoring data includes at least one security monitoring behavior, and each security monitoring behavior corresponds to a monitoring behavior type; wherein the monitoring behavior type is consistent with the security behavior type, for example, if the security behavior type includes network behavior type, device behavior type, user behavior type and data behavior type, then the monitoring behavior type also includes network behavior type, device behavior type, user behavior type and data behavior type; in addition, the security monitoring behavior is also composed of the security monitoring behavior and the monitoring behavior content of the security monitoring behavior.

[0085] The first comparison analysis between security monitoring behaviors and the security behavior architecture diagram yields the target behavior architecture layer; the second comparison analysis between security monitoring behaviors and the architecture nodes in the target behavior architecture layer yields the target security behaviors, specifically:

[0086] Compare the monitoring behavior type corresponding to the security monitoring behavior with the security behavior type corresponding to each behavior architecture layer in the security behavior architecture diagram; and record the behavior architecture layer whose security behavior type matches the monitoring behavior type as the target behavior architecture layer corresponding to the security monitoring behavior.

[0087] The security monitoring behavior is compared with the security standard behavior corresponding to the architecture layer node in the target behavior architecture layer; the architecture layer node in the target behavior architecture layer that matches the security monitoring behavior is recorded as the target node, and the security standard behavior corresponding to the target node is recorded as the target security behavior.

[0088] In some embodiments, when comparing the security monitoring behavior with the security standard behavior corresponding to the architecture layer node in the target behavior architecture layer, the security monitoring behavior is matched with the standard behavior of the security standard behavior. For example, if the security monitoring behavior is to export sensitive data in batches, then the architecture layer node in the target behavior architecture layer whose corresponding security standard behavior is also to export sensitive data in batches is the target node, and the security standard behavior of exporting sensitive data in batches is the target security behavior.

[0089] Set up early warning assessment intervals, each with a corresponding early warning response method, as follows:

[0090] The early warning assessment intervals include the behavioral early warning assessment interval, the architectural early warning assessment interval, and the network early warning assessment interval;

[0091] Each behavioral warning assessment interval corresponds to a behavioral response method; each architectural warning assessment interval corresponds to an architectural response method; and each network warning assessment interval corresponds to a network response method.

[0092] In some embodiments, the number of behavioral warning assessment intervals, architectural warning assessment intervals, and network warning assessment intervals is at least one; the behavioral response method, architectural response method, and network response method can all be customized according to the actual operating environment of the target network and network management requirements.

[0093] Step S4 is as follows:

[0094] The safety monitoring behavior is compared with the target safety behavior. If the safety monitoring behavior is inconsistent with the target safety behavior, the safety monitoring behavior is recorded as an abnormal monitoring behavior. The behavior deviation value between the abnormal monitoring behavior and the target safety behavior is obtained.

[0095] Based on the monitoring behavior type of the abnormal monitoring behavior, set the first behavior weight of the abnormal monitoring behavior; obtain the number of related behaviors of the abnormal monitoring behavior, and set the second behavior weight of the abnormal monitoring behavior based on the number of related behaviors; obtain the abnormal weight of the abnormal monitoring behavior based on the first behavior weight and the second behavior weight.

[0096] The behavioral anomaly coefficient corresponding to the abnormal monitoring behavior is obtained by assigning weights to the behavioral deviation values ​​of the abnormal monitoring behavior based on the anomaly weights.

[0097] The abnormal behavior coefficient corresponding to the abnormal monitoring behavior is compared with the behavior early warning assessment interval, and the behavior response method corresponding to the behavior early warning assessment interval where the abnormal behavior coefficient is located is recorded as the behavior early warning method corresponding to the abnormal monitoring behavior.

[0098] In some embodiments, the behavior deviation value can be obtained by comparing the monitoring behavior content of the abnormal monitoring behavior with the standard behavior content of the target security behavior. For example, if the abnormal monitoring behavior is to export sensitive data in batches, and its monitoring behavior content is to export ≥600 sensitive data items in a single batch; and the target security behavior is to export sensitive data in batches, and its standard behavior content is to export ≥500 sensitive data items in a single batch, then the behavior deviation value between the abnormal monitoring behavior and the target security behavior is 100.

[0099] In some embodiments, the first behavior weight corresponds to the monitoring behavior type, with each monitoring behavior type corresponding to a first behavior weight. The second behavior weight is positively correlated with the number of associated behaviors of the abnormal monitoring behavior; that is, the greater the number of associated behaviors of the abnormal monitoring behavior, the greater the second behavior weight of the abnormal monitoring behavior. The second behavior weight can be calculated using the following function: Second behavior weight = Number of associated behaviors * Proportional factor, where the proportional factor can be set to 1, in which case the second behavior weight and the number of associated behaviors are numerically consistent. Furthermore, the number of associated behaviors can be obtained through the specific network relationships of the target network, specifically referring to the number of other behaviors that would become abnormal if the abnormal monitoring behavior were abnormal.

[0100] In some embodiments, the abnormal weight of abnormal monitoring behavior can be calculated by the following calculation function: Abnormal weight = First factor * First behavior weight + Second factor * Second behavior weight, where the first factor and the second factor are the influence weight values ​​of the first behavior weight and the second behavior weight on the abnormal weight, respectively. The specific values ​​of the first factor and the second factor can be preset according to the actual management needs of the target network. For example, the first factor and the second factor can be set to 1 and 1.2, respectively.

[0101] Step S5 is as follows:

[0102] Nodes in the target behavior architecture layer that do not match the security monitoring behavior are marked as missing nodes.

[0103] Obtain the number of missing nodes corresponding to the missing nodes in the target behavior architecture layer, as well as the total number of nodes in the target behavior architecture layer; based on the number of missing nodes and the total number of nodes, obtain the missing behavior coefficient corresponding to the target behavior architecture layer;

[0104] The abnormal behavior coefficients corresponding to the abnormal monitoring behaviors in the target behavior architecture layer are summed to obtain the abnormal behavior coefficients corresponding to the target behavior architecture layer.

[0105] Set missing weights and abnormal weights, and obtain the architecture layer abnormality coefficients corresponding to the target behavior architecture layer based on the missing weights and missing behavior coefficients, abnormal weights and abnormal behavior coefficients;

[0106] The abnormal coefficient of the architecture layer corresponding to the behavioral architecture layer is compared with the architecture early warning assessment interval. If the abnormal coefficient of the architecture layer corresponding to the behavioral architecture layer is within the architecture early warning assessment interval, the behavioral architecture layer is judged to be an abnormal behavioral architecture layer.

[0107] The architecture response method corresponding to the architecture warning evaluation interval where the architecture layer anomaly coefficient is located is recorded as the architecture layer warning method corresponding to the abnormal behavior architecture layer.

[0108] In some embodiments, the missing behavior coefficient corresponding to the target behavior architecture layer can be calculated using the following function: Missing behavior coefficient = (Number of missing nodes / Total number of nodes) * 100%; the architecture layer anomaly coefficient corresponding to the target behavior architecture layer can be calculated using the following function: Architecture layer anomaly coefficient = Missing weight * Missing behavior coefficient + Anomaly weight * Anomaly behavior coefficient, where the missing weight and the anomaly weight are the influence weights of the missing behavior coefficient and the anomaly behavior coefficient on the architecture layer anomaly coefficient, respectively. The specific values ​​of the missing weight and the anomaly weight can be preset according to the actual management needs of the target network. For example, the missing weight and the anomaly weight can be set to 1 and 1.5, respectively.

[0109] In some embodiments, if the architecture layer anomaly coefficient corresponding to the behavior architecture layer is not within the architecture warning evaluation range, then the behavior architecture layer is determined to be an abnormal behavior architecture layer, and in this case, it is not necessary to issue a warning for the behavior architecture layer.

[0110] Step S6 is as follows:

[0111] The architecture layer weights are set based on the security behavior types corresponding to the behavior architecture layers; the architecture layer weights correspond to the security behavior types.

[0112] The anomaly coefficients of the behavioral architecture layer are weighted according to the architecture layer weights to obtain the comprehensive anomaly coefficients corresponding to the behavioral architecture layer; the comprehensive anomaly coefficients of each behavioral architecture layer in the security behavioral architecture diagram are summed to obtain the network anomaly coefficients corresponding to the target network.

[0113] The network anomaly coefficient of the target network is compared with the network early warning assessment interval. If the network anomaly coefficient of the target network is not within the network early warning assessment interval, then there is no need to issue a network early warning for the target network.

[0114] If the network anomaly coefficient of the target network is within the network early warning assessment range, then a network early warning needs to be issued for the target network, and the network response method corresponding to the network early warning assessment range where the network anomaly coefficient is located is recorded as the network early warning method corresponding to the target network.

[0115] In some embodiments, the architecture layer weights of the behavior architecture layer are set according to the security behavior type corresponding to the behavior architecture layer, and each security behavior type corresponds to an architecture layer weight.

[0116] In some embodiments, providing early warning of abnormal behavior of the target network based on behavioral warning methods, architectural layer warning methods, and network warning methods refers to: providing early warning for abnormal monitoring behavior based on the warning method corresponding to the behavioral warning method; providing early warning for the abnormal behavior architecture layer based on the warning method corresponding to the architectural layer warning method; and providing early warning for the target network based on the warning method corresponding to the network warning method.

[0117] The above are merely preferred embodiments of this application. The scope of protection of this application is not limited to the above embodiments. All technical solutions within the scope of this application's concept are within the scope of protection of this application. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of this application should also be considered within the scope of protection of this application.

Claims

1. A method for early warning and management of abnormal network security behavior, characterized in that, include: Step S1: Obtain historical behavior data of the target network, and obtain the security standard behavior of the target network based on the historical behavior data; Based on the security standard behavior, generate architecture nodes, generate a behavior architecture layer based on the architecture nodes, and construct a security behavior architecture diagram corresponding to the target network based on the behavior architecture layer and architecture nodes. Step S2: Obtain network monitoring data, and determine the security monitoring behavior of the target network based on the network monitoring data; The security monitoring behavior is input into the security behavior architecture diagram, and the security monitoring behavior and the security behavior architecture diagram are compared and analyzed to obtain the target behavior architecture layer. The target security behavior is obtained by performing a second comparison analysis between the security monitoring behavior and the architecture nodes in the target behavior architecture layer. Step S3: Set the early warning assessment interval, and each early warning assessment interval corresponds to an early warning response method; Step S4: Based on the security monitoring behavior and the target security behavior, determine and obtain the abnormal monitoring behavior in the security monitoring behavior, and the behavior abnormality coefficient corresponding to the abnormal monitoring behavior; and analyze the behavior early warning method corresponding to the abnormal monitoring behavior based on the early warning assessment interval and the behavior abnormality coefficient. Step S5: Based on the behavior anomaly coefficient analysis corresponding to the abnormal monitoring behavior, obtain the architecture layer anomaly coefficient corresponding to each behavior architecture layer in the security behavior architecture diagram; and based on the early warning evaluation interval and the architecture layer anomaly coefficient analysis, obtain the abnormal behavior architecture layer in the security behavior architecture diagram, as well as the architecture layer early warning method corresponding to the abnormal behavior architecture layer. Step S6: Based on the architecture layer anomaly coefficients of each behavior architecture layer in the security behavior architecture diagram, obtain the network anomaly coefficient corresponding to the target network; based on the early warning evaluation interval and network anomaly coefficient analysis, obtain the network early warning method corresponding to the target network; based on the behavior early warning method, architecture layer early warning method, and network early warning method, issue an early warning for the abnormal behavior of the target network.

2. The network security abnormal behavior early warning management method according to claim 1, characterized in that, The target network's security standard behavior is obtained based on historical behavioral data, specifically as follows: Configure security behavior types, which include network behavior types, device behavior types, user behavior types, and data behavior types; Based on the security behavior type, the historical behavior data is extracted to obtain the security standard behavior contained in the historical behavior data, and the security behavior type corresponding to the security standard behavior. The security standard behaviors include network standard behaviors, device standard behaviors, user standard behaviors, and data standard behaviors.

3. The network security abnormal behavior early warning management method according to claim 2, characterized in that, Based on security standard behavior, architecture nodes are generated; based on these architecture nodes, a behavior architecture layer is generated; and based on the behavior architecture layer and architecture nodes, a security behavior architecture diagram corresponding to the target network is constructed, specifically as follows: A behavior architecture layer is constructed based on the security behavior types corresponding to security standard behaviors; the behavior architecture layer includes a network behavior architecture layer, a device behavior architecture layer, a user behavior architecture layer, and a data behavior architecture layer; Network architecture nodes are generated based on the network standard behaviors, and the network architecture nodes correspond to the network standard behaviors. And the network architecture nodes are recorded as architecture layer nodes in the network behavior architecture layer; Device architecture nodes are generated based on the device standard behaviors, and the device architecture nodes correspond to the device standard behaviors. And record the device architecture node as the architecture layer node in the device behavior architecture layer; User architecture nodes are generated based on the user's standard behavior, and the user architecture nodes correspond to the user's standard behavior; and the user architecture nodes are recorded as architecture layer nodes in the user behavior architecture layer. Based on the network behavior architecture layer, device behavior architecture layer, user behavior architecture layer, and data behavior architecture layer, a security behavior architecture diagram corresponding to the target network is constructed.

4. The network security abnormal behavior early warning management method according to claim 3, characterized in that, Obtain network monitoring data, and based on the network monitoring data, determine the security monitoring behavior of the target network, specifically as follows: Based on the security behavior type, the network monitoring data is extracted to obtain the corresponding security monitoring behavior in the network monitoring data, and the monitoring behavior type corresponding to the security monitoring behavior. The types of security monitoring activities include network monitoring, device monitoring, user monitoring, and data monitoring.

5. The network security abnormal behavior early warning management method according to claim 4, characterized in that, The security monitoring behavior is compared and analyzed with the security behavior architecture diagram to obtain the target behavior architecture layer; the security monitoring behavior is compared and analyzed with the architecture nodes in the target behavior architecture layer to obtain the target security behavior, specifically: The monitoring behavior type corresponding to the security monitoring behavior is compared with the security behavior type corresponding to each behavior architecture layer in the security behavior architecture diagram; and the behavior architecture layer whose security behavior type matches the monitoring behavior type is recorded as the target behavior architecture layer corresponding to the security monitoring behavior. The security monitoring behavior is compared with the security standard behavior corresponding to the architecture layer node in the target behavior architecture layer; the architecture layer node in the target behavior architecture layer that matches the security monitoring behavior is recorded as the target node, and the security standard behavior corresponding to the target node is recorded as the target security behavior.

6. The network security abnormal behavior early warning management method according to claim 5, characterized in that, Set early warning assessment intervals, each of which corresponds to an early warning response method, specifically: The early warning assessment interval includes the behavioral early warning assessment interval, the architectural early warning assessment interval, and the network early warning assessment interval; Each of the behavioral warning assessment intervals corresponds to a behavioral response method; each of the architecture warning assessment intervals corresponds to an architecture response method; and each of the network warning assessment intervals corresponds to a network response method.

7. The network security abnormal behavior early warning management method according to claim 6, characterized in that, Step S4 is as follows: The security monitoring behavior is compared with the target security behavior. If the security monitoring behavior is inconsistent with the target security behavior, the security monitoring behavior is recorded as an abnormal monitoring behavior. And obtain the behavioral deviation value between the abnormal monitoring behavior and the target safety behavior; The weight of the first behavior of the abnormal monitoring behavior is set based on the monitoring behavior type of the abnormal monitoring behavior; Obtain the number of associated behaviors of the abnormal monitoring behavior, set the second behavior weight of the abnormal monitoring behavior based on the number of associated behaviors, and obtain the abnormal weight of the abnormal monitoring behavior based on the first behavior weight and the second behavior weight; The behavioral deviation value of the abnormal monitoring behavior is weighted according to the aforementioned abnormal weight to obtain the behavioral abnormality coefficient corresponding to the abnormal monitoring behavior; The abnormal behavior coefficient corresponding to the abnormal monitoring behavior is compared with the behavior early warning assessment interval, and the behavior response mode corresponding to the behavior early warning assessment interval where the abnormal behavior coefficient is located is recorded as the behavior early warning mode corresponding to the abnormal monitoring behavior.

8. The network security abnormal behavior early warning management method according to claim 7, characterized in that, Step S5 is as follows: Nodes in the target behavior architecture layer that do not match the security monitoring behavior are marked as missing nodes. Obtain the number of missing nodes corresponding to the missing nodes in the target behavior architecture layer, and the total number of nodes in the target behavior architecture layer; The missing behavior coefficients corresponding to the target behavior architecture layer are obtained based on the number of missing nodes and the total number of nodes. The abnormal behavior coefficients corresponding to the abnormal monitoring behaviors in the target behavior architecture layer are summed to obtain the abnormal behavior coefficients corresponding to the target behavior architecture layer. Set missing weights and abnormal weights, and obtain the architecture layer abnormality coefficients corresponding to the target behavior architecture layer based on the missing weights and missing behavior coefficients, abnormal weights and abnormal behavior coefficients; The abnormal coefficient of the architecture layer corresponding to the behavioral architecture layer is compared with the architecture early warning evaluation interval. If the abnormal coefficient of the architecture layer corresponding to the behavioral architecture layer is within the architecture early warning evaluation interval, the behavioral architecture layer is determined to be an abnormal behavioral architecture layer. The architecture response method corresponding to the architecture early warning evaluation interval where the architecture layer anomaly coefficient is located is recorded as the architecture layer early warning method corresponding to the abnormal behavior architecture layer.

9. A network security abnormal behavior early warning management method according to claim 8, characterized in that, Step S6 is as follows: The architecture layer weights of the behavior architecture layer are set based on the security behavior types corresponding to the behavior architecture layer; the architecture layer weights correspond to the security behavior types. The anomaly coefficients of the behavioral architecture layer are weighted according to the architecture layer weights to obtain the comprehensive anomaly coefficients corresponding to the behavioral architecture layer; the comprehensive anomaly coefficients of each behavioral architecture layer in the security behavioral architecture diagram are summed to obtain the network anomaly coefficients corresponding to the target network. The network anomaly coefficient of the target network is compared with the network early warning assessment interval. If the network anomaly coefficient of the target network is not within the network early warning assessment interval, then no network early warning is required for the target network. If the network anomaly coefficient corresponding to the target network is within the network early warning assessment range, then a network early warning needs to be issued for the target network, and the network response method corresponding to the network early warning assessment range where the network anomaly coefficient is located is recorded as the network early warning method corresponding to the target network.

Citation Information

Patent Citations

  • Network security monitoring and early warning method and system based on multi-source data

    CN120200860A

  • Graph-based network security event modeling method and system

    CN120915582A