A method and device for resilient security situation awareness of private networks based on spatiotemporal dual-modality

By using spatiotemporal dual-modal data processing and dynamic weight optimization, the problems of low accuracy and poor stability in 5G private network security situation awareness are solved, realizing an efficient and robust security situation awareness method, and providing accurate security operation and maintenance decision support for 5G private networks.

CN121463041BActive Publication Date: 2026-04-03UNIV OF SCI & TECH BEIJING
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-21
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing 5G private network security situation awareness methods suffer from low security situation awareness accuracy, poor clustering stability, and insufficient adaptability when facing highly mobile terminals, flexible topology adjustments, and hard isolation architectures. This can easily lead to misjudgments, especially in production control scenarios.

Method used

A spatiotemporal dual-modal private network elastic security situation awareness method is adopted. Data is collected through 5G network terminal equipment, network base stations and application servers. After data normalization, spatiotemporal stability fusion analysis is performed by combining the isolated forest algorithm and time series prediction model to obtain security enhancement data. The binary K-means clustering algorithm is used for dynamic weight optimization and clustering. Finally, the security situation awareness is visualized by principal component analysis.

Benefits of technology

It effectively overcomes the local optima problem of traditional clustering, adapts to the dynamic scenarios of mobility and load changes in 5G private networks, provides accurate and intuitive basis for security operation and maintenance decisions, and improves the accuracy and robustness of security situation awareness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121463041B_ABST
    Figure CN121463041B_ABST
Patent Text Reader

Abstract

This invention discloses a method and apparatus for resilient security situation awareness of private networks based on spatiotemporal dual-modality, relating to the field of wireless communication network security technology. The method includes: performing spatiotemporal stability fusion analysis based on the isolated forest algorithm and a time-series prediction model, and constructing security enhancement data; judging threat behavior based on the security enhancement data and mobile feature data, and dynamically optimizing the initial risk feature weights to obtain optimized risk feature weights; using a binary K-means clustering algorithm for clustering, and performing correlation mapping on the clustering results based on a preset security situation threshold and optimized risk feature weights to obtain a security situation label set; and visualizing the security situation awareness based on principal component analysis, using the security core data and the security situation label set. This invention is a highly efficient and robust resilient security situation awareness method for private networks based on spatiotemporal dual-modality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wireless communication network security technology, and in particular to a method and device for elastic security situation awareness of private networks based on spatiotemporal dual-modality. Background Technology

[0002] 5G private networks, as a new type of dedicated communication network for mobile networking and low-altitude communication scenarios, have become a core infrastructure supporting the digital transformation of key industries such as power and transportation, thanks to their technological advantages of ultra-high bandwidth, ultra-low latency, and massive connectivity. Particularly in the power system, 5G private networks must not only meet the communication needs of traditional fixed scenarios but also adapt to new application scenarios such as mobile networking, demonstrating high mobility, flexible topology adjustment, and low latency. As an important exploratory topic in the field of resilient security systems for the power system, it expands the space for digital development, promotes the extension of 5G integrated applications to core production control scenarios, and helps industrial digital transformation and the improvement of new productivity. However, current security situation awareness for 5G private networks is still in the exploratory stage. Existing solutions mostly follow the perception logic of traditional fixed networks, making it difficult to adapt to the special architecture and scenario requirements of private networks. Therefore, this paper proposes a spatiotemporal dual-modal method for resilient security situation awareness in private networks, which has significant application value for comprehensive perception and detection of network resilient security.

[0003] Currently, there is no mature solution for security situation awareness in 5G private networks. Traditional methods suffer from three major problems in practical applications: First, non-security anomalies are easily generated during terminal movement, such as temporary degradation of equipment status due to signal attenuation. These interference data, mixed with security features, further amplify clustering errors, leading to misjudgments of the security situation. Second, due to frequent fluctuations in features such as equipment status and network traffic caused by terminal movement, the traditional K-means clustering algorithm, which relies on fixed initial centroids, is prone to getting stuck in local optima, blurring the boundary between stable and vulnerable situations, which may lead to misjudgments in production control scenarios. Third, traditional methods use fixed feature weights, but 5G private networks experience dynamic scene switching. The core features affecting the situation differ in different scenarios, and fixed weights cannot adapt to scene changes, resulting in decreased perception accuracy.

[0004] In existing technologies, there is a lack of a highly efficient and robust method for resilient security situation awareness of private networks based on spatiotemporal dual-modality. Summary of the Invention

[0005] To address the technical problems of low security situation awareness accuracy, poor clustering stability, and insufficient adaptability in existing 5G private networks due to their high mobility, flexible topology adjustment, and hard isolation architecture, this invention provides a method and apparatus for elastic security situation awareness in private networks based on spatiotemporal dual-modality. The technical solution is as follows:

[0006] On the one hand, a spatiotemporal dual-modal method for resilient security situation awareness of private networks is provided. This method is implemented by a resilient security situation awareness device for private networks and includes:

[0007] Data is collected through 5G network terminal equipment, network base stations and application servers to obtain raw security core data; the raw security core data is then normalized to obtain security core data.

[0008] Based on the isolated forest algorithm and time series prediction model, spatiotemporal stability fusion analysis is performed on the core security data to obtain spatiotemporal stability data; the spatiotemporal stability data is added to the core security data to obtain security enhancement data.

[0009] Acquire mobile feature data; based on preset mobile speed thresholds and bandwidth utilization thresholds, determine threat behavior according to security enhancement data and mobile feature data to obtain security threat judgment results; dynamically optimize the initial risk feature weights according to the security threat judgment results to obtain optimized risk feature weights;

[0010] Based on the security enhancement data, the binary K-means clustering algorithm was used to perform clustering to obtain the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster.

[0011] Based on the preset security situation threshold and optimized risk feature weights, a security situation label set is obtained by performing correlation mapping based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster.

[0012] Based on principal component analysis, security situation perception is visualized using core security data and a set of security situation labels.

[0013] On the other hand, a spatiotemporal dual-modal private network resilient security situation awareness device is provided. This device is applied to the spatiotemporal dual-modal private network resilient security situation awareness method, and the device includes:

[0014] The data acquisition module is used to collect data through 5G network terminal equipment, network base stations and application servers to obtain raw security core data; and to normalize the raw security core data to obtain security core data.

[0015] The data augmentation module is used to perform spatiotemporal stability fusion analysis based on the isolated forest algorithm and time series prediction model, and obtain spatiotemporal stability data from the core security data; and to add the spatiotemporal stability data to the core security data to obtain enhanced security data.

[0016] The weight optimization module is used to acquire mobile feature data; based on preset mobile speed thresholds and bandwidth utilization thresholds, it judges threat behavior according to security enhancement data and mobile feature data to obtain security threat judgment results; based on the security threat judgment results, it dynamically optimizes the initial risk feature weights to obtain optimized risk feature weights.

[0017] The data clustering module is used to perform clustering based on the security enhancement data using the binary K-means clustering algorithm to obtain the third sub-cluster security data, the fourth sub-cluster security data, and the fifth sub-cluster security data;

[0018] The security situation mapping module is used to perform correlation mapping based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster based on the preset security situation threshold and optimized risk feature weights, to obtain a set of security situation labels.

[0019] The perception and visualization module is used to visualize security situation perception based on principal component analysis, using core security data and a set of security situation labels.

[0020] On the other hand, a private network resilient security situation awareness device is provided, the private network resilient security situation awareness device comprising: a processor; a memory, the memory storing computer-readable instructions, which, when executed by the processor, implement any of the methods in the above-described spatiotemporal dual-modal private network resilient security situation awareness method.

[0021] On the other hand, a computer-readable storage medium is provided, wherein at least one instruction is stored in the storage medium, and the at least one instruction is loaded and executed by a processor to implement any of the above-described methods of the spatiotemporal dual-modal private network resilient security situation awareness method.

[0022] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following:

[0023] This invention proposes a spatiotemporal dual-modal resilient security situation awareness method for private networks. It collects four core data categories—device status, threat intelligence, security events, and network traffic—from 5G private network terminal devices, base stations, and security management platform servers, establishing and normalizing the collected data into a log. After data preprocessing to form a high-quality dataset, LSTM temporal anomaly detection and isolated forest spatial anomaly detection are performed, and spatiotemporal features are fused to construct a 5-dimensional enhanced dataset. Based on the binary K-means algorithm, iterative splitting begins from an initial single cluster. By calculating the sum of squared errors, the cluster with the greatest internal differences is prioritized for splitting, resulting in three stable clusters. An initial weight vector is configured based on private network characteristics, and the weights are elastically adjusted according to terminal mobility speed and bandwidth utilization. Weighted Euclidean distance is used to optimize sample cluster assignment. The clustering results are then regularly mapped to stable, vulnerable, and threat situations. This invention effectively overcomes the local optima problem of traditional clustering, adapts to the dynamic scenarios of 5G private network mobility and load changes, and provides accurate and intuitive basis for security operation and maintenance decisions. This invention is a highly efficient and robust spatiotemporal dual-modal resilient security situation awareness method for private networks. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a flowchart of a method for resilient security situation awareness of a private network based on spatiotemporal dual-modality, provided by an embodiment of the present invention.

[0026] Figure 2 This is a block diagram of a private network elastic security situation awareness device based on spatiotemporal dual-modality provided in an embodiment of the present invention;

[0027] Figure 3 This is a schematic diagram of the structure of a private network elastic security situation awareness device provided in an embodiment of the present invention. Detailed Implementation

[0028] The technical solution of the present invention will now be described with reference to the accompanying drawings.

[0029] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.

[0030] In the embodiments of this invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning. Similarly, the terms "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning.

[0031] In this embodiment of the invention, sometimes a subscript such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning they express is the same.

[0032] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0033] This invention provides a method for resilient security situation awareness of private networks based on spatiotemporal dual-modality. This method can be implemented by a resilient security situation awareness device for private networks, which can be a terminal or a server. Figure 1 The flowchart shown is for a spatiotemporal dual-modal private network resilient security situation awareness method. The processing flow of this method may include the following steps:

[0034] S1. Collect data through 5G network terminal equipment, network base stations and application servers to obtain raw security core data; normalize the raw security core data to obtain security core data.

[0035] In one feasible implementation, the present invention collects multi-dimensional data through a data center system and a fusion terminal containing sensors and monitoring equipment. According to the characteristics and sources of different data, a data collection log is established to record information such as collection time, collection node, and initial data value, which facilitates subsequent traceability and anomaly investigation.

[0036] The collected raw data is preprocessed to eliminate the dimensional differences between different indicators, resulting in a 5G private network multi-parameter dataset.

[0037] The collected data is cleaned to remove useless and erroneous data. The first four types of data are normalized using the deviation standardization method, as shown in the following formula (1):

[0038] (1)

[0039] in, The data is normalized and its range is [0,1]. The original data, The maximum value of the original data. This is the minimum value of the original data.

[0040] All data is mapped to the 0-1 range to eliminate dimensional differences and allow different types of data to participate in subsequent calculations. Simultaneously, a sliding window algorithm is deployed to handle mobile interference, and traffic and device status data are monitored in real time. If a transient anomaly is detected, it is identified as mobile handover noise, and the noise point is replaced with the mean of adjacent data within the window, ensuring data continuity and avoiding interference with subsequent clustering.

[0041] The core security data includes device status data, threat intelligence data, security incident data, and network traffic data.

[0042] In one feasible implementation, the core security data includes four categories: device status data, threat intelligence data, security event data, and network traffic data. Device status data is obtained through a network element status monitoring interface, including CPU load and link packet loss rate, and is normalized to a range of 0-1, where 1 represents a stable link and no device faults. Threat intelligence data is obtained by connecting to a dedicated network threat intelligence platform and matched against attack behaviors in the traffic; the matching degree is normalized to a value of 0-1, where 1 represents a high-threat situation. Security event data is obtained from a security management platform, counting the number of events such as abnormal access and unauthorized operations, and normalizing the event density by unit time; 1 represents high-risk, frequent occurrences. Network traffic data is collected through traffic probes, analyzing traffic rate and traffic anomalies; fluctuation amplitude is normalized to a value of 0-1, where 1 represents severely abnormal traffic.

[0043] S2. Based on the isolated forest algorithm and time series prediction model, spatiotemporal stability fusion analysis is performed on the core security data to obtain spatiotemporal stability data; the spatiotemporal stability data is added to the core security data to obtain security enhancement data.

[0044] Among them, the time series prediction model is built based on a long short-term neural network;

[0045] The time series prediction model consists of an input layer and an output layer;

[0046] The input layer consists of 64 long and short term neural units and 32 fully connected units with ReLU activation; the output layer consists of 4 linear activation units.

[0047] In one feasible implementation, the present invention employs a Long Short-Term Memory Network (LSTM) to construct a time series prediction model, the shape of which is: The sequence contains 64 LSTM units and 32 fully connected units with ReLU activation. The output layer has 4 units, using linear activation, and outputs the predicted value. The model uses the Adam optimizer and is trained with mean squared error (MSE) as the loss function. The loss function formula is as follows (2):

[0048] (2);

[0049] in, The number of training samples, For the true value, These are predicted values.

[0050] Optionally, based on the Isolation Forest algorithm and time series prediction model, spatiotemporal stability fusion analysis is performed on the core security data to obtain spatiotemporal stability data, including:

[0051] Based on the core security data, real-time data prediction is performed using a time-series prediction model to obtain the predicted core security data.

[0052] The reconstruction error set is obtained by calculating based on the core security data and the predicted core security data.

[0053] Based on the reconstruction error set, the interquartile range method is used to calculate and obtain the dynamic anomaly threshold;

[0054] Based on the dynamic anomaly threshold, time series anomaly judgment is performed according to the reconstruction error set to obtain the time series anomaly data set and the time series normal data set.

[0055] Based on core security data, the isolated forest algorithm is used to perform real-time spatial anomaly detection, obtaining a set of spatial anomaly data and a set of spatial normal data.

[0056] Spatiotemporal stability fusion analysis is performed on the time-series abnormal data set, the time-series normal data set, the spatial abnormal data set, and the spatial normal data set to obtain a spatiotemporal stable data set;

[0057] Based on the spatiotemporal stable data set, a spatiotemporal stability score set is obtained by calculating the reconstruction error set and the dynamic anomaly threshold; the spatiotemporal stability score set is determined as the spatiotemporal stable data.

[0058] In one feasible implementation, the standardized four-dimensional timing security core data is: Each of them It is a 4-dimensional vector , where are the normalized values ​​of the corresponding device status, threat intelligence, security events, and network traffic at time t, respectively. A sliding window method is used to construct samples: the time step (window length) is set to T, and the input sequence of the i-th sample is . The dimension is (T,4), and the corresponding target output is With dimensions (4, 1), the final sample set is obtained. ,in .

[0059] After predicting the core security data, the reconstruction error of each predicted sample is calculated. ,in Indicates the sample index. These correspond to device status, threat intelligence, security incidents, and network traffic, respectively.

[0060] The dynamic anomaly threshold was determined using the IQR method, and the upper quartiles of all reconstruction errors were calculated. and lower quartile The interquartile range is obtained. The abnormal threshold is When a certain sample When this time point is determined to be a time series outlier, the corresponding data is considered abnormal, and its index is [index missing]. For normal points, the time stability score is calculated based on the ratio of the mean MSE within the historical window to the threshold, according to the corresponding normal data. .

[0061] The Isolation Forest algorithm is used to detect spatial anomalies in four-dimensional samples within the same time period, with the input being a standardized four-dimensional feature dataset. ,in The output is the anomaly score. The closer to 1, the more abnormal it is. The time was judged as a spatial anomaly.

[0062] The spatial anomaly results are fused with the temporal anomaly results. If either the temporal or spatial detection is abnormal, the spatiotemporal stability is 0; if both spatiotemporal detections are normal, the spatiotemporal stability is 0. Finally, the original four-dimensional features are spliced ​​with the spatiotemporal stability features to construct five-dimensional security enhancement data.

[0063] S3. Acquire mobile feature data; Based on preset mobile speed threshold and bandwidth utilization threshold, determine threat behavior according to security enhancement data and mobile feature data to obtain security threat judgment results; Based on the security threat judgment results, dynamically optimize the initial risk feature weights to obtain optimized risk feature weights.

[0064] Optionally, based on the security threat assessment results, the initial risk feature weights are dynamically optimized to obtain optimized risk feature weights, including:

[0065] The initial risk characteristic weights include device status weight (0.15), threat intelligence weight (0.35), security event weight (0.25), network traffic weight (0.15), and spatiotemporal stability weight (0.1).

[0066] Optimized risk feature weights include first optimized risk feature weights, second optimized risk feature weights, or third optimized risk feature weights.

[0067] When the security threat assessment result is only mobile enhancement, the optimized risk feature weight is the first optimized risk feature weight; the first optimized risk feature weight includes the first device status weight of 0.05, the first threat intelligence weight of 0.35, the first security event weight of 0.25, the first network traffic weight of 0.2, and the first spatiotemporal stability weight of 0.15;

[0068] When the security threat assessment result is that only the load increases, the optimized risk feature weight is the second optimized risk feature weight; the second optimized risk feature weight includes the second device status weight of 0.15, the second threat intelligence weight of 0.2, the second security event weight of 0.35, the second network traffic weight of 0.15, and the second spatiotemporal stability weight of 0.15;

[0069] When the security threat assessment result is enhanced mobility and increased load, the optimized risk feature weight is the third optimized risk feature weight; the third optimized risk feature weight includes the third device status weight of 0.05, the second threat intelligence weight of 0.2, the second security event weight of 0.35, the second network traffic weight of 0.2, and the second spatiotemporal stability weight of 0.2.

[0070] In one feasible implementation, the mobility characteristic data includes terminal mobility speed and base station handover interval. A dynamic acquisition frequency strategy is adopted, whereby the acquisition frequency is dynamically adjusted according to the terminal mobility speed. When the mobility speed exceeds a threshold, a high-frequency acquisition of 10Hz is used; otherwise, a conventional acquisition of 1Hz is used. All data are... Interpolation alignment is performed on the reference time slot to ensure spatiotemporal data synchronization.

[0071] Based on the initial risk characteristic weights set according to the risk characteristics of the private network, the characteristic weights are dynamically adjusted according to indicators such as terminal mobile speed and bandwidth utilization when mobility is enhanced or load increases, so as to adapt to the elastic changes of the 5G private network.

[0072] The initial risk feature weights correspond to the first four categories of features: device status, threat intelligence, security events, and network traffic. The initial weight for spatiotemporal stability features is 0.1. Among these, threat intelligence has the highest weight because 5G private network terminals are easily exposed to attack surfaces when they move, such as during brief protection gaps when switching base stations.

[0073] On the one hand, the system monitors the terminal's movement speed using 5G positioning capabilities or terminal GPS data. When the movement speed exceeds a set threshold, it is determined to be enhanced mobility. At this point, the weights are adjusted, increasing the network traffic weight from 0.15 to 0.2, because traffic fluctuations during movement better reflect link pressure; the device status weight is decreased from 0.15 to 0.05, because temporary instability caused by movement is normal, reducing false alarms; and the spatiotemporal stability weight is increased from 0.1 to 0.15. The adjusted weight vector... .

[0074] On the other hand, monitoring the private network bandwidth utilization rate is crucial. When the bandwidth utilization rate exceeds a set threshold, it is considered an increase in load. High load easily leads to congestion and abnormal events. In this case, the weights are adjusted: the security event weight is increased from 0.25 to 0.35 because abnormal access and unauthorized operations have a greater impact under high load; the threat intelligence weight is decreased from 0.35 to 0.2 because attacks are less likely to penetrate under high load, thus reducing its priority; and the spatiotemporal stability weight is increased from 0.1 to 0.15. (Adjusted weight vector) When terminal mobility increases and load rises, the weight vector is adjusted to... .

[0075] S4. Based on the security enhancement data, use the binary K-means clustering algorithm to perform clustering to obtain the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster.

[0076] Optionally, based on the security enhancement data, a binary K-means clustering algorithm is used to perform clustering to obtain security data for the third, fourth, and fifth sub-clusters, including:

[0077] Based on a preset spatiotemporal stability threshold, the initial sample centroid is determined according to the security enhancement data;

[0078] Based on the initial sample centroids, and according to the security enhancement data, the basic K-means clustering algorithm is used to split the clusters to obtain the security data of the first sub-cluster and the security data of the second sub-cluster.

[0079] Based on the initial sample centroid, the sum of squared errors of the first sub-cluster and the sum of squared errors of the second sub-cluster are calculated according to the security data of the first sub-cluster and the security data of the second sub-cluster.

[0080] Based on a preset spatiotemporal stability threshold, the centroids of the first and second subclusters are determined according to the security data of the first and second subclusters.

[0081] Based on the centroid of the first sub-cluster, and according to the secure data of the first sub-cluster, the basic K-means clustering algorithm is used to perform temporary cluster splitting to obtain the secure data of the first temporary sub-cluster and the secure data of the second temporary sub-cluster.

[0082] Based on the centroid of the first sub-cluster, the sum of squared errors of the first temporary sub-cluster and the sum of squared errors of the second temporary sub-cluster are calculated according to the security data of the first temporary sub-cluster and the security data of the second temporary sub-cluster.

[0083] The first error reduction is calculated based on the sum of squared errors of the first sub-cluster, the sum of squared errors of the first temporary sub-cluster, and the sum of squared errors of the second temporary sub-cluster.

[0084] Based on the centroid of the second sub-cluster, and according to the secure data of the second sub-cluster, the basic K-means clustering algorithm is used to perform temporary cluster splitting to obtain the secure data of the third and fourth temporary sub-clusters.

[0085] Based on the centroid of the second sub-cluster, the sum of squared errors of the third temporary sub-cluster and the sum of squared errors of the fourth temporary sub-cluster are calculated according to the safety data of the third temporary sub-cluster and the safety data of the fourth temporary sub-cluster.

[0086] The second error reduction is calculated based on the sum of squared errors of the second sub-cluster, the sum of squared errors of the third temporary sub-cluster, and the sum of squared errors of the fourth temporary sub-cluster.

[0087] Based on the first error reduction and the second error reduction, the subclusters to be split are screened according to the first subcluster safety data and the second subcluster safety data to obtain the safety data of the unsplit subclusters, the safety data of the subclusters to be split, and the corresponding centroids of the subclusters to be split.

[0088] The secure data of the unsplit subcluster is identified as the secure data of the third subcluster.

[0089] Based on the centroid of the sub-cluster to be split, and according to the safe data of the sub-cluster to be split, the basic K-means clustering algorithm is used to split the cluster, and the safe data of the fourth sub-cluster and the safe data of the fifth sub-cluster are obtained.

[0090] In one feasible implementation, based on the security requirements of the private network, three types of situations are clearly defined: threat, vulnerability, and stability, and a target number of clusters is set. All preprocessed data are considered as one initial cluster. Samples with time stability > 0.8 are selected as initial centroids, and the initial cluster is divided into two sub-clusters using the basic K-means algorithm. and Calculate the sum of squared errors (SSE) between the two subclusters after splitting. and The calculation formula is as follows (3):

[0091] (3);

[0092] in, To enhance data security, Let C be the centroid of cluster C.

[0093] Then temporarily partition using the basic K-means algorithm. get and Temporary division get and Computational clusters and SSE sum and clusters and SSE sum Calculation error reduction as well as .Compare and Based on the magnitude of the error, the cluster with the largest reduction in error was selected and formally divided into two new clusters, ultimately forming three stable clusters.

[0094] S5. Based on the preset security situation threshold and optimized risk feature weights, perform correlation mapping based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster to obtain a set of security situation labels.

[0095] Optionally, based on a preset security posture threshold and optimized risk feature weights, a security posture label set is obtained by performing correlation mapping based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster, including:

[0096] Based on the optimized risk feature weights, the spatial score set is obtained by using the weighted centroid calculation method based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster.

[0097] Based on the security data of the third sub-cluster, the security data of the fourth sub-cluster, and the security data of the fifth sub-cluster, the corresponding spatiotemporal stability data are obtained; the corresponding spatiotemporal stability data are used as a time score set.

[0098] Based on a preset security situation threshold, the security situation of the third sub-cluster security data, the fourth sub-cluster security data, and the fifth sub-cluster security data is determined according to the spatial score set and the temporal score set, and a security situation label set is obtained.

[0099] In one feasible implementation, based on the adjusted weights The weighted Euclidean distance between the sample and the cluster center is recalculated using the following formula (4):

[0100] (4);

[0101] in, To enhance data security, As the cluster center, For the first Class feature weights.

[0102] The new distance is used to rematch samples with cluster centers, update the cluster affiliation of samples, and ensure that the clustering results fit the current network state.

[0103] Calculate the spatial score for each cluster center. ,in For the first dimensional feature weights, The time score is the j-th eigenvalue of the cluster center. Take the 5th eigenvalue.

[0104] Based on the preset security status threshold, the security status label set is mapped. "Threat posture"; if ,or The first is described as "fragile"; the rest are described as "stable".

[0105] S6. Based on principal component analysis, visualize security situation perception according to core security data and security situation label set.

[0106] In one feasible implementation, since the collected sample data includes four dimensions—device status, threat intelligence, security events, and network traffic—which are high-dimensional spatial data that cannot be directly observed, Principal Component Analysis (PCA) is used to compress the four-dimensional spatial feature vectors into a two-dimensional space and then perform visualization rendering. This clearly presents the distribution density, geometric boundaries, and relative positional relationships of threat, vulnerability, and stable states on a two-dimensional plane, providing security operations personnel with an intuitive basis for decision-making.

[0107] The input to the dimensionality reduction process is the normalized dataset, which serves as the original four-dimensional data matrix. The core of dimensionality reduction lies in finding an optimal linear projection transformation, which first calculates the four-dimensional matrix. covariance matrix The calculation formula is as follows (5):

[0108] (5);

[0109] Where m is the sample size. Let be the mean vector of all samples.

[0110] For covariance matrix Perform eigenvalue decomposition to obtain four feature vectors. There are four principal components. These principal components are arranged in descending order of their corresponding eigenvalues. This invention selects the eigenvectors corresponding to the two largest eigenvalues ​​to construct the projection matrix. The four-dimensional matrix With this projection matrix Multiplying them together yields a two-dimensional data matrix. Each row represents the new coordinates of a sample in two-dimensional space. Based on the correspondence between security enhancement data and core security data, the security posture labels are visualized.

[0111] This invention proposes a spatiotemporal dual-modal resilient security situation awareness method for private networks. It collects four core data categories—device status, threat intelligence, security events, and network traffic—from 5G private network terminal devices, base stations, and security management platform servers, establishing and normalizing the collected data into a log. After data preprocessing to form a high-quality dataset, LSTM temporal anomaly detection and isolated forest spatial anomaly detection are performed, and spatiotemporal features are fused to construct a 5-dimensional enhanced dataset. Based on the binary K-means algorithm, iterative splitting begins from an initial single cluster. By calculating the sum of squared errors, the cluster with the greatest internal differences is prioritized for splitting, resulting in three stable clusters. An initial weight vector is configured based on private network characteristics, and the weights are elastically adjusted according to terminal mobility speed and bandwidth utilization. Weighted Euclidean distance is used to optimize sample cluster assignment. The clustering results are then regularly mapped to stable, vulnerable, and threat situations. This invention effectively overcomes the local optima problem of traditional clustering, adapts to the dynamic scenarios of 5G private network mobility and load changes, and provides accurate and intuitive basis for security operation and maintenance decisions. This invention is a highly efficient and robust spatiotemporal dual-modal resilient security situation awareness method for private networks.

[0112] Figure 2 This is a block diagram of a spatiotemporal dual-modal private network resilient security situation awareness device provided in an embodiment of the present invention. This device is used in a spatiotemporal dual-modal private network resilient security situation awareness method. (Refer to...) Figure 2 The device includes a data acquisition module 210, a data augmentation module 220, a weight optimization module 230, a data clustering module 240, a security situation mapping module 250, and a perception visualization module 260. Among them:

[0113] The data acquisition module 210 is used to collect data through 5G network terminal equipment, network base stations and application servers to obtain raw security core data; and to normalize the raw security core data to obtain security core data.

[0114] The data augmentation module 220 is used to perform spatiotemporal stability fusion analysis based on the isolated forest algorithm and time series prediction model, and obtain spatiotemporal stability data by adding the spatiotemporal stability data to the security core data to obtain security augmentation data.

[0115] The weight optimization module 230 is used to acquire mobile feature data; based on preset mobile speed threshold and bandwidth utilization threshold, it judges threat behavior according to security enhancement data and mobile feature data to obtain security threat judgment results; based on the security threat judgment results, it dynamically optimizes the initial risk feature weights to obtain optimized risk feature weights.

[0116] The data clustering module 240 is used to perform clustering based on the security enhancement data using the binary K-means clustering algorithm to obtain the third sub-cluster security data, the fourth sub-cluster security data, and the fifth sub-cluster security data;

[0117] The security situation mapping module 250 is used to perform correlation mapping based on the third sub-cluster security data, the fourth sub-cluster security data and the fifth sub-cluster security data, according to the preset security situation threshold and optimized risk feature weights, to obtain a set of security situation labels.

[0118] The perception and visualization module 260 is used to perform security situation perception and visualization based on principal component analysis, according to core security data and a set of security situation labels.

[0119] The core security data includes device status data, threat intelligence data, security incident data, and network traffic data.

[0120] Among them, the time series prediction model is built based on a long short-term neural network;

[0121] The time series prediction model consists of an input layer and an output layer;

[0122] The input layer consists of 64 long and short term neural units and 32 fully connected units with ReLU activation; the output layer consists of 4 linear activation units.

[0123] Optionally, the data enhancement module 220 is further used for:

[0124] Based on the core security data, real-time data prediction is performed using a time-series prediction model to obtain the predicted core security data.

[0125] The reconstruction error set is obtained by calculating based on the core security data and the predicted core security data.

[0126] Based on the reconstruction error set, the interquartile range method is used to calculate and obtain the dynamic anomaly threshold;

[0127] Based on the dynamic anomaly threshold, time series anomaly judgment is performed according to the reconstruction error set to obtain the time series anomaly data set and the time series normal data set.

[0128] Based on core security data, the isolated forest algorithm is used to perform real-time spatial anomaly detection, obtaining a set of spatial anomaly data and a set of spatial normal data.

[0129] Spatiotemporal stability fusion analysis is performed on the time-series abnormal data set, the time-series normal data set, the spatial abnormal data set, and the spatial normal data set to obtain a spatiotemporal stable data set;

[0130] Based on the spatiotemporal stable data set, a spatiotemporal stability score set is obtained by calculating the reconstruction error set and the dynamic anomaly threshold; the spatiotemporal stability score set is determined as the spatiotemporal stable data.

[0131] Optionally, the weight optimization module 230 is further used for:

[0132] The initial risk characteristic weights include device status weight (0.15), threat intelligence weight (0.35), security event weight (0.25), network traffic weight (0.15), and spatiotemporal stability weight (0.1).

[0133] Optimized risk feature weights include first optimized risk feature weights, second optimized risk feature weights, or third optimized risk feature weights.

[0134] When the security threat assessment result is only mobile enhancement, the optimized risk feature weight is the first optimized risk feature weight; the first optimized risk feature weight includes the first device status weight of 0.05, the first threat intelligence weight of 0.35, the first security event weight of 0.25, the first network traffic weight of 0.2, and the first spatiotemporal stability weight of 0.15;

[0135] When the security threat assessment result is that only the load increases, the optimized risk feature weight is the second optimized risk feature weight; the second optimized risk feature weight includes the second device status weight of 0.15, the second threat intelligence weight of 0.2, the second security event weight of 0.35, the second network traffic weight of 0.15, and the second spatiotemporal stability weight of 0.15;

[0136] When the security threat assessment result is enhanced mobility and increased load, the optimized risk feature weight is the third optimized risk feature weight; the third optimized risk feature weight includes the third device status weight of 0.05, the second threat intelligence weight of 0.2, the second security event weight of 0.35, the second network traffic weight of 0.2, and the second spatiotemporal stability weight of 0.2.

[0137] Optionally, the data clustering module 240 is further used for:

[0138] Based on a preset spatiotemporal stability threshold, the initial sample centroid is determined according to the security enhancement data;

[0139] Based on the initial sample centroids, and according to the security enhancement data, the basic K-means clustering algorithm is used to split the clusters to obtain the security data of the first sub-cluster and the security data of the second sub-cluster.

[0140] Based on the initial sample centroid, the sum of squared errors of the first sub-cluster and the sum of squared errors of the second sub-cluster are calculated according to the security data of the first sub-cluster and the security data of the second sub-cluster.

[0141] Based on a preset spatiotemporal stability threshold, the centroids of the first and second subclusters are determined according to the security data of the first and second subclusters.

[0142] Based on the centroid of the first sub-cluster, and according to the secure data of the first sub-cluster, the basic K-means clustering algorithm is used to perform temporary cluster splitting to obtain the secure data of the first temporary sub-cluster and the secure data of the second temporary sub-cluster.

[0143] Based on the centroid of the first sub-cluster, the sum of squared errors of the first temporary sub-cluster and the sum of squared errors of the second temporary sub-cluster are calculated according to the security data of the first temporary sub-cluster and the security data of the second temporary sub-cluster.

[0144] The first error reduction is calculated based on the sum of squared errors of the first sub-cluster, the sum of squared errors of the first temporary sub-cluster, and the sum of squared errors of the second temporary sub-cluster.

[0145] Based on the centroid of the second sub-cluster, and according to the secure data of the second sub-cluster, the basic K-means clustering algorithm is used to perform temporary cluster splitting to obtain the secure data of the third and fourth temporary sub-clusters.

[0146] Based on the centroid of the second sub-cluster, the sum of squared errors of the third temporary sub-cluster and the sum of squared errors of the fourth temporary sub-cluster are calculated according to the safety data of the third temporary sub-cluster and the safety data of the fourth temporary sub-cluster.

[0147] The second error reduction is calculated based on the sum of squared errors of the second sub-cluster, the sum of squared errors of the third temporary sub-cluster, and the sum of squared errors of the fourth temporary sub-cluster.

[0148] Based on the first error reduction and the second error reduction, the subclusters to be split are screened according to the first subcluster safety data and the second subcluster safety data to obtain the safety data of the unsplit subclusters, the safety data of the subclusters to be split, and the corresponding centroids of the subclusters to be split.

[0149] The secure data of the unsplit subcluster is identified as the secure data of the third subcluster.

[0150] Based on the centroid of the sub-cluster to be split, and according to the safe data of the sub-cluster to be split, the basic K-means clustering algorithm is used to split the cluster, and the safe data of the fourth sub-cluster and the safe data of the fifth sub-cluster are obtained.

[0151] Optionally, the security situation mapping module 250 is further used for:

[0152] Based on the optimized risk feature weights, the spatial score set is obtained by using the weighted centroid calculation method based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster.

[0153] Based on the security data of the third sub-cluster, the security data of the fourth sub-cluster, and the security data of the fifth sub-cluster, the corresponding spatiotemporal stability data are obtained; the corresponding spatiotemporal stability data are used as a time score set.

[0154] Based on a preset security situation threshold, the security situation of the third sub-cluster security data, the fourth sub-cluster security data, and the fifth sub-cluster security data is determined according to the spatial score set and the temporal score set, and a security situation label set is obtained.

[0155] This invention proposes a spatiotemporal dual-modal resilient security situation awareness method for private networks. It collects four core data categories—device status, threat intelligence, security events, and network traffic—from 5G private network terminal devices, base stations, and security management platform servers, establishing and normalizing the collected data into a log. After data preprocessing to form a high-quality dataset, LSTM temporal anomaly detection and isolated forest spatial anomaly detection are performed, and spatiotemporal features are fused to construct a 5-dimensional enhanced dataset. Based on the binary K-means algorithm, iterative splitting begins from an initial single cluster. By calculating the sum of squared errors, the cluster with the greatest internal differences is prioritized for splitting, resulting in three stable clusters. An initial weight vector is configured based on private network characteristics, and the weights are elastically adjusted according to terminal mobility speed and bandwidth utilization. Weighted Euclidean distance is used to optimize sample cluster assignment. The clustering results are then regularly mapped to stable, vulnerable, and threat situations. This invention effectively overcomes the local optima problem of traditional clustering, adapts to the dynamic scenarios of 5G private network mobility and load changes, and provides accurate and intuitive basis for security operation and maintenance decisions. This invention is a highly efficient and robust spatiotemporal dual-modal resilient security situation awareness method for private networks.

[0156] Figure 3 This is a schematic diagram of the structure of a private network elastic security situation awareness device provided in an embodiment of the present invention, such as... Figure 3 As shown, the private network elastic security situation awareness device may include the above-mentioned Figure 2 The illustrated device is a private network resilient security situation awareness device based on spatiotemporal dual-modality. Optionally, the private network resilient security situation awareness device 310 may include a first processor 2001.

[0157] Optionally, the private network resilient security situation awareness device 310 may also include a memory 2002 and a transceiver 2003.

[0158] The first processor 2001, memory 2002, and transceiver 2003 can be connected via a communication bus.

[0159] The following is combined Figure 3 A detailed introduction to each component of the 310 private network elastic security situation awareness device:

[0160] The first processor 2001 is the control center of the private network elastic security situational awareness device 310. It can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement embodiments of the present invention, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).

[0161] Optionally, the first processor 2001 can perform various functions of the private network resilient security situation awareness device 310 by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.

[0162] In a specific implementation, as one example, the first processor 2001 may include one or more CPUs, for example... Figure 3 CPU0 and CPU1 are shown in the diagram.

[0163] In a specific implementation, as one example, the private network elastic security situation awareness device 310 may also include multiple processors, for example... Figure 3 The first processor 2001 and the second processor 2004 are shown in the diagram. Each of these processors can be a single-core processor or a multi-core processor. Here, a processor can refer to one or more devices, circuits, and / or processing cores used to process data (such as computer program instructions).

[0164] The memory 2002 is used to store the software program that executes the present invention, and is controlled by the first processor 2001 to execute it. The specific implementation method can be referred to the above method embodiment, and will not be repeated here.

[0165] Optionally, the memory 2002 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory 2002 may be integrated with the first processor 2001 or may exist independently, and may be connected via the interface circuit of the private network flexible security situation awareness device 310. Figure 3 (Not shown in the image) is coupled to the first processor 2001, and this embodiment of the invention does not specifically limit this.

[0166] The transceiver 2003 is used to communicate with network devices or with terminal devices.

[0167] Alternatively, transceiver 2003 may include a receiver and a transmitter. Figure 3 (Not shown separately). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0168] Optionally, the transceiver 2003 can be integrated with the first processor 2001, or it can exist independently and be connected via the interface circuit of the private network elastic security situation awareness device 310. Figure 3 (Not shown in the image) is coupled to the first processor 2001, and this embodiment of the invention does not specifically limit this.

[0169] It should be noted that, Figure 3 The structure of the private network resilient security situation awareness device 310 shown in the figure does not constitute a limitation on the router. The actual private network resilient security situation awareness device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0170] Furthermore, the technical effects of the private network elastic security situation awareness device 310 can be referenced from the technical effects of the private network elastic security situation awareness method based on spatiotemporal dual-modality described in the above method embodiments, and will not be repeated here.

[0171] It should be understood that the first processor 2001 in the embodiments of the present invention may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or it may be any conventional processor, etc.

[0172] It should also be understood that the memory in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0173] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0174] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0175] In this invention, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.

[0176] It should be understood that, in various embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0177] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0178] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices, apparatuses, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0179] In the several embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0180] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0181] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0182] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0183] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for resilient security situation awareness of private networks based on spatiotemporal dual-modality, characterized in that, The method includes: Data is collected through 5G network terminal equipment, network base stations and application servers to obtain raw security core data; the raw security core data is then normalized to obtain security core data. Based on the isolated forest algorithm and time series prediction model, spatiotemporal stability fusion analysis is performed on the core security data to obtain spatiotemporal stability data; the spatiotemporal stability data is added to the core security data to obtain security enhancement data. The method of obtaining spatiotemporal stability data based on the isolated forest algorithm and time series prediction model, using core security data for spatiotemporal stability fusion analysis, includes: Based on the core security data, real-time data prediction is performed using a time-series prediction model to obtain the predicted core security data. The reconstruction error set is obtained by calculating based on the core security data and the predicted core security data. Based on the reconstruction error set, the interquartile range method is used to calculate and obtain the dynamic anomaly threshold; Based on the dynamic anomaly threshold, time series anomaly judgment is performed according to the reconstruction error set to obtain the time series anomaly data set and the time series normal data set. Based on core security data, the isolated forest algorithm is used to perform real-time spatial anomaly detection, obtaining a set of spatial anomaly data and a set of spatial normal data. Spatiotemporal stability fusion analysis is performed on the time-series abnormal data set, the time-series normal data set, the spatial abnormal data set, and the spatial normal data set to obtain a spatiotemporal stable data set; Based on the spatiotemporal stable data set, a spatiotemporal stability score set is obtained by calculating the reconstruction error set and the dynamic anomaly threshold; the spatiotemporal stability score set is determined as the spatiotemporal stable data. Acquire mobile feature data; based on preset mobile speed thresholds and bandwidth utilization thresholds, determine threat behavior according to security enhancement data and mobile feature data to obtain security threat judgment results; dynamically optimize the initial risk feature weights according to the security threat judgment results to obtain optimized risk feature weights; The step of dynamically optimizing the initial risk feature weights based on the security threat assessment results to obtain optimized risk feature weights includes: The initial risk characteristic weights include a device status weight of 0.15, a threat intelligence weight of 0.35, a security event weight of 0.25, a network traffic weight of 0.15, and a spatiotemporal stability weight of 0.

1. The optimized risk feature weights include a first optimized risk feature weight, a second optimized risk feature weight, or a third optimized risk feature weight. When the security threat assessment result is mobile-only enhancement, the optimized risk feature weight is the first optimized risk feature weight; the first optimized risk feature weight includes a first device status weight of 0.05, a first threat intelligence weight of 0.35, a first security event weight of 0.25, a first network traffic weight of 0.2, and a first spatiotemporal stability weight of 0.15; When the security threat assessment result is that only the load increases, the optimized risk feature weight is the second optimized risk feature weight; the second optimized risk feature weight includes a second device status weight of 0.15, a second threat intelligence weight of 0.2, a second security event weight of 0.35, a second network traffic weight of 0.15, and a second spatiotemporal stability weight of 0.15; When the security threat assessment result is enhanced mobility and increased load, the optimized risk feature weight is the third optimized risk feature weight; the third optimized risk feature weight includes a third device status weight of 0.05, a second threat intelligence weight of 0.2, a second security event weight of 0.35, a second network traffic weight of 0.2, and a second spatiotemporal stability weight of 0.2; Based on the security enhancement data, the binary K-means clustering algorithm was used to perform clustering to obtain the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster. Based on the preset security situation threshold and optimized risk feature weights, a security situation label set is obtained by performing correlation mapping based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster. Based on principal component analysis, security situation perception is visualized using core security data and a set of security situation labels.

2. The method for resilient security situation awareness of private networks based on spatiotemporal dual-modality according to claim 1, characterized in that, The core security data includes device status data, threat intelligence data, security incident data, and network traffic data.

3. The method for resilient security situation awareness of private networks based on spatiotemporal dual-modality according to claim 1, characterized in that, The time-series prediction model is constructed based on a long short-term neural network; The time-series prediction model includes an input layer and an output layer; The input layer comprises 64 long short-term neural units and 32 fully connected units with ReLU activation; the output layer comprises 4 linear activation units.

4. The method for resilient security situation awareness of private networks based on spatiotemporal dual-modality according to claim 1, characterized in that, The process involves using a binary K-means clustering algorithm to divide the data based on the enhanced security data, obtaining secure data for the third, fourth, and fifth sub-clusters, including: Based on a preset spatiotemporal stability threshold, the initial sample centroid is determined according to the security enhancement data; Based on the initial sample centroids, and according to the security enhancement data, the basic K-means clustering algorithm is used to split the clusters to obtain the security data of the first sub-cluster and the security data of the second sub-cluster. Based on the initial sample centroid, the sum of squared errors of the first sub-cluster and the sum of squared errors of the second sub-cluster are calculated according to the security data of the first sub-cluster and the security data of the second sub-cluster. Based on a preset spatiotemporal stability threshold, the centroids of the first and second subclusters are determined according to the security data of the first and second subclusters. Based on the centroid of the first sub-cluster, and according to the secure data of the first sub-cluster, the basic K-means clustering algorithm is used to perform temporary cluster splitting to obtain the secure data of the first temporary sub-cluster and the secure data of the second temporary sub-cluster. Based on the centroid of the first sub-cluster, the sum of squared errors of the first temporary sub-cluster and the sum of squared errors of the second temporary sub-cluster are calculated according to the security data of the first temporary sub-cluster and the security data of the second temporary sub-cluster. The first error reduction is calculated based on the sum of squared errors of the first sub-cluster, the sum of squared errors of the first temporary sub-cluster, and the sum of squared errors of the second temporary sub-cluster. Based on the centroid of the second sub-cluster, and according to the secure data of the second sub-cluster, the basic K-means clustering algorithm is used to perform temporary cluster splitting to obtain the secure data of the third and fourth temporary sub-clusters. Based on the centroid of the second sub-cluster, the sum of squared errors of the third temporary sub-cluster and the sum of squared errors of the fourth temporary sub-cluster are calculated according to the safety data of the third temporary sub-cluster and the safety data of the fourth temporary sub-cluster. The second error reduction is calculated based on the sum of squared errors of the second sub-cluster, the sum of squared errors of the third temporary sub-cluster, and the sum of squared errors of the fourth temporary sub-cluster. Based on the first error reduction and the second error reduction, the subclusters to be split are screened according to the first subcluster safety data and the second subcluster safety data to obtain the safety data of the unsplit subclusters, the safety data of the subclusters to be split, and the corresponding centroids of the subclusters to be split. The secure data of the unsplit subcluster is identified as the secure data of the third subcluster. Based on the centroid of the sub-cluster to be split, and according to the safe data of the sub-cluster to be split, the basic K-means clustering algorithm is used to split the cluster, and the safe data of the fourth sub-cluster and the safe data of the fifth sub-cluster are obtained.

5. The method for resilient security situation awareness of private networks based on spatiotemporal dual-modality according to claim 1, characterized in that, The process involves establishing a preset security posture threshold and optimizing risk feature weights, then performing a correlation mapping based on the security data of the third, fourth, and fifth sub-clusters to obtain a set of security posture labels, including: Based on the optimized risk feature weights, the spatial score set is obtained by using the weighted centroid calculation method based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster. Based on the security data of the third sub-cluster, the security data of the fourth sub-cluster, and the security data of the fifth sub-cluster, the corresponding spatiotemporal stability data are obtained; the corresponding spatiotemporal stability data are used as a time score set. Based on a preset security situation threshold, the security situation of the third sub-cluster security data, the fourth sub-cluster security data, and the fifth sub-cluster security data is determined according to the spatial score set and the temporal score set, and a security situation label set is obtained.

6. A spatiotemporal dual-modal private network resilient security situation awareness device, wherein the spatiotemporal dual-modal private network resilient security situation awareness device is used to implement the spatiotemporal dual-modal private network resilient security situation awareness method as described in any one of claims 1-5, characterized in that, The device includes: The data acquisition module is used to collect data through 5G network terminal equipment, network base stations and application servers to obtain raw security core data; and to normalize the raw security core data to obtain security core data. The data augmentation module is used to perform spatiotemporal stability fusion analysis based on the isolated forest algorithm and time series prediction model, and obtain spatiotemporal stability data from the core security data; and to add the spatiotemporal stability data to the core security data to obtain enhanced security data. The weight optimization module is used to acquire mobile feature data; based on preset mobile speed thresholds and bandwidth utilization thresholds, it judges threat behavior according to security enhancement data and mobile feature data to obtain security threat judgment results; based on the security threat judgment results, it dynamically optimizes the initial risk feature weights to obtain optimized risk feature weights. The data clustering module is used to perform clustering based on the security enhancement data using the binary K-means clustering algorithm to obtain the third sub-cluster security data, the fourth sub-cluster security data, and the fifth sub-cluster security data; The security situation mapping module is used to perform correlation mapping based on the security data of the third sub-cluster, the fourth sub-cluster, and the fifth sub-cluster based on the preset security situation threshold and optimized risk feature weights, to obtain a set of security situation labels. The perception and visualization module is used to visualize security situation perception based on principal component analysis, using core security data and a set of security situation labels.

7. A private network resilient security situation awareness device, characterized in that, The private network elastic security situation awareness device includes: processor; A memory storing computer-readable instructions that, when executed by the processor, implement the method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains program code that can be invoked by a processor to execute the method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Information security management method and system based on sensitive data

    CN120449206A

  • Computer security protection system based on artificial intelligence

    CN120850291A