Network security situation awareness method and system

By comprehensively analyzing network behavior data and internal state parameters, the problem of lagging and fragmented traditional network security situation assessment has been solved, enabling a comprehensive and dynamic assessment of the overall network security situation and improving the accuracy of anomaly detection and threat identification.

CN121486069APending Publication Date: 2026-02-06GUANGZHOU XIAOCHI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511778748.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-02-06

AI Technical Summary

Technical Problem

Traditional cybersecurity posture assessment methods are ill-equipped to comprehensively address complex and covert cyber threats, exhibiting problems of assessment lag and fragmentation, and failing to detect threats in a timely manner and make accurate security responses.

Method used

By acquiring current network behavior data and internal status parameters of critical business services, abnormal fluctuation analysis is performed using short-term sensitivity thresholds and preset transmission quality indicators. Combined with internal stress index and vulnerability exploitation probability analysis, an overall network security posture assessment is generated.

Benefits of technology

It enables a comprehensive and dynamic assessment of the overall network security posture, improves the sensitivity and accuracy of anomaly detection, and can promptly identify the urgency and potential destructive power of network threats, supporting timely security response decisions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121486069A_ABST
    Figure CN121486069A_ABST
Patent Text Reader

Abstract

The invention discloses a network security situation awareness method and system, and relates to the technical field of network security, and the method comprises the steps: carrying out the network abnormal fluctuation analysis based on a current network behavior data set through employing a short-term sensitivity threshold; carrying out transmission anomaly influence analysis based on the network anomaly fluctuation data; determining an internal pressure bearing index based on the internal state parameter of the key business service; determining a target contribution weight based on the internal pressure bearing index, and generating an internal transmission problem influence factor based on the target contribution weight so as to determine the security vulnerability of the network assets in combination with the network abnormal fluctuation data and the transmission abnormal influence data; performing vulnerability utilization probability analysis based on the current network behavior data set to determine a network threat severity; and performing network overall security situation assessment based on the network threat severity and the network asset security vulnerability. According to the method, comprehensive and dynamic evaluation of the overall security situation of the network is realized, and the problems of evaluation lagging and splitting of a traditional method are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a network security situation awareness method and system. Background Technology

[0002] Currently, with the continuous expansion of network scale and the increasing complexity of applications, network security situational awareness has gradually become a key technical means to ensure the overall manageability and controllability of information systems. However, traditional security assessment methods often have some shortcomings and are difficult to comprehensively address increasingly complex and covert network threats. Current methods mostly rely on known threat signature databases or only analyze log information from single-point security devices, which makes them inadequate when facing hybrid security risks such as advanced persistent threats and abnormal fluctuations in the network.

[0003] Meanwhile, existing network security posture assessment methods often have the following limitations. Firstly, most solutions focus on isolated analysis of vulnerability scan results or intrusion alerts, failing to effectively integrate real-time network behavior data, such as sudden fluctuations in traffic or abnormal increases in data transmission latency, for dynamic impact assessment. This leads to a lag in the perception of potential risks and an inability to promptly detect ongoing threats. Secondly, traditional methods typically treat the likelihood of vulnerability exploitation separately from the current network operating state when assessing threats, lacking a comprehensive analysis of potential threat propagation paths and the system's own vulnerabilities. This fragmented approach makes it difficult for assessment results to accurately reflect the overall risk level faced by the network under its current operating state, thus significantly limiting the timeliness of security response and the accuracy of decision-making. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of the prior art. This invention provides a network security situation awareness method and system, which realizes a comprehensive and dynamic assessment of the overall network security situation and effectively solves the problems of lagging and fragmented assessment in traditional methods.

[0005] To address the aforementioned technical problems, this invention provides a network security situation awareness method, the method comprising: Obtain the current network behavior data set and the internal state parameters of key business services, and perform network anomaly fluctuation analysis based on the current network behavior data set using short-term sensitivity thresholds to obtain network anomaly fluctuation data; Based on the network anomaly fluctuation data, the impact of transmission anomalies is analyzed using preset transmission quality indicators to obtain transmission anomaly impact data. Based on the internal state parameters, the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of the internal flow control mechanism to the total duration are analyzed, and the internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. The target contribution weight is determined based on the internal pressure index, the internal transmission problem impact factor is generated based on the target contribution weight, and the network asset security vulnerability is determined based on the internal transmission problem impact factor, network abnormal fluctuation data, and transmission abnormal impact data. Based on the current network behavior data set, vulnerability exploitation probability analysis is performed to obtain the target vulnerability exploitation probability, and the severity of the network threat is determined based on the target vulnerability exploitation probability. An overall network security posture assessment is conducted based on the severity of the network threats and the vulnerability of network assets.

[0006] Optionally, the step of performing network anomaly fluctuation analysis based on the current network behavior data set using a short-term sensitivity threshold to obtain network anomaly fluctuation data includes: A set of historical network behavior data is obtained, and a long-term drift baseline is constructed using the set of historical network behavior data based on the exponentially weighted moving average method; A short-term sensitivity threshold is generated based on the long-term drift baseline and the historical fluctuation range. Based on the current network behavior data set, potential fluctuation anomaly analysis is performed using the short-term sensitivity threshold to obtain potential fluctuation anomaly data. Based on the potential fluctuation anomaly data, an in-depth investigation of anomalies is conducted to obtain in-depth investigation information of anomalies, and network anomaly fluctuation data is determined based on the in-depth investigation information of anomalies.

[0007] Optionally, determining the target contribution weight based on the internal pressure index includes: Obtain the type information of key business services, and determine the initial contribution weight based on the type information and the internal stress index; Obtain the current operating mode of the key business service, and adjust the initial contribution weight based on the current operating mode to obtain the target contribution weight.

[0008] Optionally, generating the internal transmission problem impact factor based on the target contribution weight includes: An initial transmission problem impact factor is generated based on the target contribution weight and the internal pressure index. Obtain the dependency graph of network assets, and determine the dependent assets and the services that are depended upon based on the dependency graph; Obtain the first operational status and security posture information of the dependent assets, and obtain the second operational status and business criticality level of the dependent business; The dependency risk amplification factor is determined based on the first operating status and security situation information of the dependent assets, as well as the second operating status and business criticality level of the dependent business. The initial transmission problem influence factor is adjusted based on the aforementioned dependency risk amplification factor to obtain the internal transmission problem influence factor.

[0009] Optionally, determining the dependency risk amplification factor based on the first operating state and security posture information of the dependent asset and the second operating state and business criticality level of the dependent business includes: Obtain the type information of the dependent assets and the type information of the dependent business, and determine the first risk contribution weight based on the type information of the dependent assets using a preset risk contribution weight configuration library, and determine the second risk contribution weight based on the type information of the dependent business using a preset risk contribution weight configuration library. The first risk impact score of the dependent asset is calculated based on the first operating status and security situation information of the dependent asset and the first risk contribution weight. The second risk impact score of the dependent business is calculated based on the second operating status and business criticality level of the dependent business, combined with the second risk contribution weight. The dependency risk amplification factor is determined based on the first risk impact score and the second risk impact score.

[0010] Optionally, determining the dependent risk amplification factor based on the first risk impact score and the second risk impact score includes: Construct a fusion configuration library, and match the corresponding fusion algorithm and fusion weight in the fusion configuration library based on the first risk impact score and the second risk impact score; The first risk impact score and the second risk impact score are fused based on the fusion algorithm and fusion weight to obtain the dependent risk amplification factor.

[0011] Optionally, the construction of the fusion configuration library includes: Obtain the business process status information of key business services and determine the mapping relationship between business processes and integrated configurations; Based on the business process status information, the corresponding fusion strategy configuration is matched using the mapping relationship; A fusion configuration library is built based on the aforementioned fusion strategy configuration.

[0012] Optionally, the step of performing a fusion operation on the first risk impact score and the second risk impact score based on the fusion algorithm and fusion weights to obtain the dependent risk amplification factor includes: Construct a business dependency risk map and determine the risk transmission path based on the business dependency risk map; Based on the business dependency risk map, the node risk impact score of the risk transmission path is determined, and the cumulative path risk value is calculated based on the node risk impact score. Based on the fusion algorithm and fusion weight, the first risk impact score and the second risk impact score are fused using the cumulative path risk value to obtain the dependency risk amplification factor.

[0013] Optionally, the step of performing vulnerability exploitation probability analysis based on the current network behavior data set to obtain the target vulnerability exploitation probability includes: Perform vulnerability scanning on the current network behavior data set to obtain vulnerability information; The vulnerability information is analyzed to obtain detection behavior information, and vulnerability relevance factors are matched based on the detection behavior information. Based on the aforementioned detection behavior information and vulnerability correlation factors, vulnerability exploitation probability analysis is performed to obtain the target vulnerability exploitation probability.

[0014] In addition, the present invention also provides a network security situation awareness system, the system comprising: Anomaly fluctuation analysis module: used to acquire the current network behavior data set and the internal status parameters of key business services, and to perform network anomaly fluctuation analysis based on the current network behavior data set using short-term sensitivity thresholds to obtain network anomaly fluctuation data; Transmission Impact Analysis Module: Used to perform transmission anomaly impact analysis based on the network anomaly fluctuation data using preset transmission quality indicators, and obtain transmission anomaly impact data; Pressure Index Calculation Module: Used to analyze the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of the internal flow control mechanism to the total duration based on the internal state parameters, and to determine the internal pressure index based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. Vulnerability determination module: used to determine the target contribution weight based on the internal stress index, generate the internal transmission problem impact factor based on the target contribution weight, and determine the security vulnerability of network assets based on the internal transmission problem impact factor, network abnormal fluctuation data, and transmission abnormal impact data; Threat severity determination module: used to perform vulnerability exploitation probability analysis based on the current network behavior data set, obtain the target vulnerability exploitation probability, and determine the severity of the network threat based on the target vulnerability exploitation probability; Situation assessment module: used to conduct an overall network security situation assessment based on the severity of the network threat and the vulnerability of network assets.

[0015] In this embodiment of the invention, network anomaly fluctuation analysis is performed using a short-term sensitivity threshold based on the current network behavior data set, which more accurately identifies abnormal fluctuations in the network and improves the sensitivity and accuracy of anomaly perception. Based on the network anomaly fluctuation data, transmission anomaly impact analysis is performed using preset transmission quality indicators, which can assess the impact of network anomalies on data transmission reliability and efficiency, thereby providing a more comprehensive understanding of the potential harm of anomaly events. Based on the analysis of the internal state parameters of critical business services, the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of internal flow control mechanisms to the total duration are analyzed. An internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of internal flow control mechanisms to the total duration, providing more comprehensive data support for subsequent network asset security vulnerability assessment. The target contribution weight is determined based on the internal stress index, and an internal transmission problem impact factor is generated based on the target contribution weight. Based on the internal transmission problem impact factor, network anomaly fluctuation data, and transmission anomaly impact data, network asset security vulnerability is determined, which can more accurately reflect the probability of successful asset attacks. Vulnerability exploitation probability analysis is performed based on the current network behavior data set to determine the severity of network threats, which helps to identify the urgency and potential destructive power of threats currently facing the network. By conducting an overall network security posture assessment based on the severity of network threats and the vulnerability of network assets, a comprehensive and dynamic assessment of the overall network security posture can be achieved, effectively solving the problems of lagging and fragmented assessment in traditional methods. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating the network security situation awareness method in an embodiment of the present invention; Figure 2 This is a flowchart illustrating a network security situation awareness method according to another embodiment of the present invention; Figure 3 This is a schematic diagram of the structural composition of the network security situation awareness system in an embodiment of the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] Example 1 Please see Figure 1 , Figure 1 This is a flowchart illustrating a network security situation awareness method according to an embodiment of the present invention. The method includes: S11: Obtain the current network behavior data set and the internal state parameters of key business services, and perform network abnormal fluctuation analysis based on the current network behavior data set using short-term sensitivity thresholds to obtain network abnormal fluctuation data; In the specific implementation of this invention, the following steps are taken: First, a current network behavior data set and internal state parameters of key business services are acquired. Second, a historical network behavior data set is acquired. Third, a long-term drift baseline is constructed using the historical network behavior data set based on the exponentially weighted moving average method. Fourth, a short-term sensitivity threshold is generated based on the long-term drift baseline and historical fluctuation ranges. Fifth, potential fluctuation anomaly analysis is performed using the short-term sensitivity threshold based on the current network behavior data set to obtain potential fluctuation anomaly data. Sixth, in-depth investigation of abnormal events is conducted based on the potential fluctuation anomaly data to obtain in-depth investigation information of abnormal events. Finally, network abnormal fluctuation data is determined based on the in-depth investigation information of abnormal events. By constructing a long-term drift baseline and a short-term sensitivity threshold, abnormal fluctuations in the network are identified more accurately, improving the sensitivity and accuracy of anomaly perception.

[0020] S12: Based on the network abnormal fluctuation data, perform transmission abnormality impact analysis using preset transmission quality indicators to obtain transmission abnormality impact data; In the specific implementation of this invention, based on the network anomaly fluctuation data, a preset transmission quality index is used to analyze the impact of transmission anomalies, obtaining transmission anomaly impact data. Network anomalies may lead to a decline in data transmission quality, such as increased packet loss rate and increased latency. By analyzing these transmission quality indices, the impact of network anomalies on data transmission reliability and efficiency can be assessed, thereby gaining a more comprehensive understanding of the potential hazards of anomaly events.

[0021] S13: Based on the internal state parameters, analyze the first occurrence frequency of the internal cache adjustment event, the second occurrence frequency of the data retransmission timeout event, and the proportion of the activation duration of the internal flow control mechanism to the total duration, and determine the internal stress index based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. In the specific implementation of this invention, the first occurrence frequency of the internal cache adjustment event, the second occurrence frequency of the data retransmission timeout event, and the proportion of the activation duration of the internal flow control mechanism to the total duration are analyzed based on the internal state parameters. The internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. By combining these indicators, the stress level inside the system can be quantified.

[0022] S14: Determine the target contribution weight based on the internal pressure index, generate the internal transmission problem impact factor based on the target contribution weight, and determine the network asset security vulnerability based on the internal transmission problem impact factor, network abnormal fluctuation data, and transmission abnormal impact data. In the specific implementation of this invention, the following steps are taken: First, the type information of critical business services is acquired, and an initial contribution weight is determined based on the type information and an internal pressure index. Then, the current operating mode of the critical business services is acquired, and the initial contribution weight is adjusted based on the current operating mode to obtain a target contribution weight. An initial transmission problem impact factor is generated based on the target contribution weight and the internal pressure index. Dependent assets and dependent services are determined based on the network asset dependency graph. The first operating state and security posture information of the dependent assets are acquired, as well as the second operating state and business criticality level of the dependent services. A dependency risk amplification factor is determined based on the first operating state and security posture information of the dependent assets, and the second operating state and business criticality level of the dependent services. The initial transmission problem impact factor is adjusted based on the dependency risk amplification factor to obtain an internal transmission problem impact factor. Finally, the security vulnerability of network assets is determined based on the internal transmission problem impact factor, network anomaly fluctuation data, and transmission anomaly impact data. This comprehensive assessment of the security weaknesses of each asset in the network under the current environment more accurately reflects the likelihood of a successful attack on the assets.

[0023] S15: Perform vulnerability exploitation probability analysis based on the current network behavior data set to obtain the target vulnerability exploitation probability, and determine the severity of the network threat based on the target vulnerability exploitation probability; In the specific implementation of this invention, vulnerability scanning is performed on the current network behavior data set to obtain vulnerability information; probing behavior analysis is performed on the vulnerability information to obtain probing behavior information, and vulnerability correlation factors are matched based on the probing behavior information; vulnerability exploitation probability analysis is performed based on the probing behavior information and vulnerability correlation factors to more accurately assess the probability of vulnerability exploitation and improve the early warning capability for potential threats. Determining the severity of network threats based on the target vulnerability exploitation probability helps to identify the urgency and potential destructive power of external threats currently facing the network.

[0024] S16: Conduct an overall network security posture assessment based on the severity of the network threats and the vulnerability of network assets.

[0025] In the specific implementation of this invention, an overall network security posture assessment is conducted based on the severity of the network threat and the vulnerability of network assets. The severity of external threats is combined with the vulnerability of internal assets to form a comprehensive and dynamic network security posture view. In this way, security operators can clearly understand the overall risk level currently faced by the network, thereby making timely and effective security response decisions.

[0026] In this embodiment of the invention, network anomaly fluctuation analysis is performed using a short-term sensitivity threshold based on the current network behavior data set, which more accurately identifies abnormal fluctuations in the network and improves the sensitivity and accuracy of anomaly perception. Based on the network anomaly fluctuation data, transmission anomaly impact analysis is performed using preset transmission quality indicators, which can assess the impact of network anomalies on data transmission reliability and efficiency, thereby providing a more comprehensive understanding of the potential harm of anomaly events. Based on the analysis of the internal state parameters of critical business services, the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of internal flow control mechanisms to the total duration are analyzed. An internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of internal flow control mechanisms to the total duration, providing more comprehensive data support for subsequent network asset security vulnerability assessment. The target contribution weight is determined based on the internal stress index, and an internal transmission problem impact factor is generated based on the target contribution weight. Based on the internal transmission problem impact factor, network anomaly fluctuation data, and transmission anomaly impact data, network asset security vulnerability is determined, which can more accurately reflect the probability of successful asset attacks. Vulnerability exploitation probability analysis is performed based on the current network behavior data set to determine the severity of network threats, which helps to identify the urgency and potential destructive power of threats currently facing the network. By conducting an overall network security posture assessment based on the severity of network threats and the vulnerability of network assets, a comprehensive and dynamic assessment of the overall network security posture can be achieved, effectively solving the problems of lagging and fragmented assessment in traditional methods.

[0027] Example 2 Please see Figure 2 , Figure 2 This is a flowchart illustrating a network security situation awareness method according to another embodiment of the present invention, the method comprising: S201: Obtain the current network behavior data set and the internal state parameters of key business services, obtain the historical network behavior data set, and construct a long-term drift baseline using the historical network behavior data set based on the exponentially weighted moving average method; In the specific implementation of this invention, the current network behavior data set and the internal status parameters of key business services are obtained. The current network behavior data set refers to all data related to network activities collected from the network within the current time window, such as traffic data, connection logs, protocol statistics, and packet information. This data reflects the current operating status of the network and user behavior patterns. The internal status parameters of key business services refer to internal indicators related to the health of the core business system, such as server CPU utilization, disk I / O, process status, internal cache utilization, cache adjustment event count, number of data retransmission attempts, retransmission timeout event count, and the activation status and duration of internal flow control mechanisms. These parameters directly reflect the carrying capacity and operating efficiency of the business system.

[0028] A historical network behavior dataset is acquired, which refers to the collection and storage of various network activity data, such as network traffic, connection count, packet size, and protocol type, over a past period. A long-term drift baseline is constructed using this historical network behavior dataset based on the exponentially weighted moving average method. The exponentially weighted moving average method is a commonly used time series analysis method. Its purpose is to smooth the historical network behavior dataset and assign higher weights to recent data, thereby constructing a long-term drift baseline that reflects the long-term trends and slow changes in the network. This long-term drift baseline can be understood as the dynamic average behavior pattern of the network under normal operating conditions, which can adaptively adjust to reflect long-term changes in the network environment.

[0029] S202: Generate a short-term sensitivity threshold based on the long-term drift baseline and the historical fluctuation range; In the specific implementation of this invention, a short-term sensitivity threshold is generated based on the long-term drift baseline and the historical fluctuation range. The historical fluctuation range refers to the typical deviation of network behavior data from the long-term drift baseline over a past period. By comprehensively considering the long-term drift baseline and the historical fluctuation range, a short-term sensitivity threshold can be dynamically generated. This threshold can more accurately define whether the current network behavior data deviates from the normal short-term fluctuation range. For example, this threshold can be set as the long-term drift baseline plus or minus a multiple of the standard deviation calculated based on the historical fluctuation range.

[0030] S203: Based on the current network behavior data set, perform potential fluctuation anomaly analysis using the short-term sensitivity threshold to obtain potential fluctuation anomaly data; In the specific implementation of this invention, potential fluctuation anomaly analysis is performed based on the current network behavior data set using the short-term sensitivity threshold to obtain potential fluctuation anomaly data. By comparing this current data with the dynamically generated short-term sensitivity threshold, network behaviors that exceed the normal fluctuation range can be preliminarily identified. These preliminarily identified abnormal behaviors are potential fluctuation anomaly data.

[0031] S204: Based on the potential fluctuation anomaly data, perform in-depth investigation of anomaly events to obtain in-depth investigation information of anomaly events, and determine network anomaly fluctuation data based on the in-depth investigation information of anomaly events; In the specific implementation of this invention, in-depth anomaly investigation is conducted based on the potential fluctuation anomaly data to obtain in-depth anomaly investigation information. Based on this information, network anomaly fluctuation data is determined. To avoid false alarms, these potential anomalies require further analysis. In-depth anomaly investigation may include correlation analysis of relevant logs, system status, user behavior, etc., to confirm whether the potential anomalies truly represent real network security events. Therefore, the in-depth anomaly investigation information will include a detailed description of the anomaly, contextual information, possible causes, and impact assessment. Ultimately, based on this in-depth investigation information, network anomaly fluctuation data can be accurately identified and output. This data represents confirmed network anomalies with practical security significance. This effectively filters out genuine anomalies from a large amount of network behavior data and provides detailed investigation information, thus providing more reliable and accurate input for subsequent network asset security vulnerability assessments.

[0032] S205: Based on the network abnormal fluctuation data, perform transmission abnormality impact analysis using preset transmission quality indicators to obtain transmission abnormality impact data; In the specific implementation of this invention, based on the network anomaly fluctuation data, a transmission anomaly impact analysis is performed using preset transmission quality indicators to obtain transmission anomaly impact data. The preset transmission quality indicators refer to performance standards pre-set during data transmission, such as packet loss rate, latency, jitter, and throughput. These indicators are used to measure the reliability and efficiency of data transmission. Network anomalies may lead to a decrease in data transmission quality, such as an increase in packet loss rate or latency. For example, a packet loss rate threshold of 5% can be set. When the actual packet loss rate reflected in the network anomaly fluctuation data exceeds 5%, it is considered that a transmission anomaly exists. By analyzing these transmission quality indicators, the impact of network anomalies on data transmission reliability and efficiency can be assessed, thereby gaining a more comprehensive understanding of the potential harm of anomaly events.

[0033] S206: Based on the internal state parameters, analyze the first occurrence frequency of the internal cache adjustment event, the second occurrence frequency of the data retransmission timeout event, and the proportion of the activation duration of the internal flow control mechanism to the total duration, and determine the internal stress index based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. In the specific implementation of this invention, the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of the internal flow control mechanism to the total duration are analyzed based on the internal state parameters. The first occurrence frequency of internal cache adjustment events refers to the number of times the system's internal cache performs adjustment operations within a certain period of time. Cache adjustment is usually to optimize performance or respond to changes in system load, but excessively frequent adjustments may indicate internal system pressure. The second occurrence frequency of data retransmission timeout events refers to the number of times data packets need to be retransmitted due to transmission failure within a certain period of time. High-frequency retransmission timeouts usually indicate problems with the network transmission link or insufficient processing capacity at the receiving end. The proportion of the activation duration of the internal flow control mechanism to the total duration refers to the ratio of the total duration of the system's internal flow control mechanism in an active state to the total duration of that period of time. Frequent or prolonged activation of the flow control mechanism usually means that the system is experiencing high load or resource bottlenecks.

[0034] The internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. It is further determined by observing the average occurrence frequency of internal buffer adjustment events, the average occurrence frequency of data retransmission timeout events, and the average proportion of the activation duration of the internal flow control mechanism to the total duration under normal operation over a past period. The internal stress index is then determined by combining the proportions of the first occurrence frequency, the second occurrence frequency, and the activation duration of the internal flow control mechanism to the total duration with the average proportions of the first occurrence frequency, the second occurrence frequency, and the activation duration of the internal flow control mechanism to the total duration. The expression for the internal stress index is: , in, Internal pressure index, , and The preset weighting coefficients, The first occurrence frequency, The first average occurrence frequency, The second frequency of occurrence, The second average occurrence frequency, This represents the proportion of the total duration to which the internal flow control mechanism is activated. This represents the average percentage of time the internal flow control mechanism is active relative to the total time. The internal stress index is a comprehensive indicator used to quantify the stress level experienced by critical business services. S207: Determine the target contribution weight based on the internal pressure index, generate the internal transmission problem impact factor based on the target contribution weight, and determine the network asset security vulnerability based on the internal transmission problem impact factor, network abnormal fluctuation data, and transmission abnormal impact data. In a specific implementation of the present invention, determining the target contribution weight based on the internal pressure index includes: obtaining type information of key business services and determining an initial contribution weight based on the type information and the internal pressure index; obtaining the current operating mode of the key business services and adjusting the initial contribution weight based on the current operating mode to obtain the target contribution weight.

[0035] Specifically, the process involves acquiring type information for critical business services. Type information refers to identifying and collecting the business categories or functional attributes corresponding to critical business services. For example, critical business services can be classified as database services, application server services, message queue services, API gateway services, etc. This type information reflects the inherent role and potential importance of the service within the overall business architecture. Based on this type information and the internal stress index, an initial contribution weight is determined. Specifically, this means that based on the service's type information and its current internal stress index, a preliminary assessment is made of the service's importance or risk contribution to network security situational awareness. For example, for a core database service, its initial contribution weight may naturally be higher than that of an auxiliary log service, and when its internal stress index is high, its initial contribution weight will be further amplified.

[0036] The current operating mode of critical business services is obtained. The current operating mode refers to the real-time monitoring and identification of the operational status of critical business services. For example, the operating mode may include normal operation mode, peak load mode, maintenance mode, disaster recovery mode, etc. Different operating modes may dynamically affect the business criticality of the service. Based on the current operating mode, the initial contribution weight is adjusted to obtain the target contribution weight. Specifically, this means dynamically correcting the previously determined initial contribution weight according to the current operating mode. For example, in peak load mode, even if the type information and internal stress index of a service remain unchanged, its business criticality at the current moment may be significantly increased, so its contribution weight needs to be increased; while in maintenance mode, its contribution weight may be decreased. Therefore, the target contribution weight is a dynamic evaluation result that comprehensively considers the inherent attributes of the service, its internal health status, and the real-time operating environment. This multi-dimensional and dynamic evaluation mechanism allows the target contribution weight to more accurately reflect the actual importance of critical business services in different contexts, thus providing a more reliable input for subsequent network asset security vulnerability assessments.

[0037] Furthermore, the step of generating an internal transmission problem impact factor based on the target contribution weight includes: generating an initial transmission problem impact factor based on the target contribution weight combined with an internal pressure index; obtaining a dependency graph of network assets and determining dependent assets and dependent services based on the dependency graph; obtaining the first operating status and security posture information of the dependent assets, and obtaining the second operating status and service criticality level of the dependent services; determining a dependency risk amplification factor based on the first operating status and security posture information of the dependent assets and the second operating status and service criticality level of the dependent services; and adjusting the initial transmission problem impact factor based on the dependency risk amplification factor to obtain the internal transmission problem impact factor.

[0038] Specifically, an initial transmission problem impact factor is generated based on the target contribution weight and the internal stress index. After determining the target contribution weight, it is combined with the internal stress index to preliminarily quantify the potential impact of internal transmission problems on the overall network security posture. This combination can be achieved through a preset mathematical model or empirical formula. For example, the target contribution weight and the internal stress index can be multiplied or weighted to reflect the degree of contribution of critical business services to the impact of transmission problems under different stress levels.

[0039] Obtain the dependency graph of network assets, such as servers, databases, and application services. The dependency graph refers to the collection and construction of a topology diagram showing all assets in the network and their inter-asset dependencies. Based on this dependency graph, determine the dependent assets and the services that are depended upon. This dependency graph clearly shows which assets depend on other assets (dependent assets) and which services are depended upon by other assets (depended services). For example, a front-end application may depend on a back-end database service; in this case, the front-end application is a dependent asset, and the back-end database service is a dependent service.

[0040] Obtain the first operational status and security posture information of the dependent assets. The first operational status may include indicators such as CPU utilization, memory usage, network bandwidth, and service response time. Security posture information may include the number of vulnerabilities, attack incidents, and security configuration compliance. Obtain the second operational status and business criticality level of the dependent services. The second operational status is similar to the first operational status. The business criticality level is used to measure the importance of the service to the overall operation of the organization, and is divided into different levels such as core, important, and general.

[0041] Determining the dependency risk amplification factor based on the first operational status and security posture information of the dependent asset, and the second operational status and business criticality level of the dependent business, refers to calculating a coefficient to adjust the impact factor of transmission problems by comprehensively considering the operational health, security status, and business importance of both the dependent and dependent parties. This factor aims to reflect the degree to which transmission problems may be amplified or suppressed due to the existence of the dependency relationship. For example, if a critical asset on which a core business depends is in poor operational status and has serious security vulnerabilities, the impact of transmission problems may be significantly amplified.

[0042] Adjusting the initial transmission problem impact factor based on the dependency risk amplification factor to obtain the internal transmission problem impact factor involves performing an operation between the initially generated initial transmission problem impact factor and the calculated dependency risk amplification factor to obtain the final, more accurate internal transmission problem impact factor. This adjustment can be multiplication, addition, or other more complex functional relationships, with the aim of ensuring that the final factor more realistically reflects the actual impact of the transmission problem after considering asset dependencies. This allows the generated internal transmission problem impact factor to more accurately reflect the true impact of the transmission problem in the actual network environment, thereby avoiding evaluation bias caused by ignoring dependencies.

[0043] Network asset security vulnerabilities are determined based on the aforementioned internal transmission problem impact factors, network anomaly fluctuation data, and transmission anomaly impact data. When determining network asset security vulnerabilities, a simple arithmetic average of these factors can be taken to obtain the network asset security vulnerability. Network asset security vulnerability refers to the probability that various assets in the network will be successfully attacked when facing potential threats. It comprehensively considers the asset's own weaknesses, configuration defects, and the operating environment. By integrating multiple factors such as external network behavior anomalies, transmission quality anomalies, and internal system pressure, a comprehensive assessment of the security weaknesses of each asset in the network under the current environment is conducted. This comprehensive assessment can more accurately reflect the probability of an asset being successfully attacked.

[0044] Furthermore, determining the dependency risk amplification factor based on the first operating status and security situation information of the dependent asset and the second operating status and business criticality level of the dependent business includes: obtaining the type information of the dependent asset and the type information of the dependent business; determining a first risk contribution weight based on the type information of the dependent asset using a preset risk contribution weight configuration library; determining a second risk contribution weight based on the type information of the dependent business using the preset risk contribution weight configuration library; calculating a first risk impact score of the dependent asset based on the first operating status and security situation information of the dependent asset combined with the first risk contribution weight; calculating a second risk impact score of the dependent business based on the second operating status and business criticality level of the dependent business combined with the second risk contribution weight; and determining the dependency risk amplification factor based on the first risk impact score and the second risk impact score.

[0045] Specifically, the process involves acquiring information on the types of dependent assets and the types of services they depend on. This information refers to the classification identifiers of different assets and services within the network. This type information can be pre-configured and managed within the system, for example, through an asset management system or a business management system. Based on the type information of the dependent assets, a first risk contribution weight is determined using a pre-defined risk contribution weight configuration library. Similarly, based on the type information of the dependent services, a second risk contribution weight is determined using the same library. This pre-defined risk contribution weight configuration library is a database or configuration file that stores the risk contribution weights corresponding to different asset and service types. For example, for database assets, their risk contribution weight may be higher than that of ordinary file servers; for core payment services, their risk contribution weight may be higher than that of auxiliary management services. The first and second risk contribution weights are obtained by matching the dependent assets and the dependent services from the pre-defined risk contribution weight configuration library, and are used to quantify the importance of different types of assets and services in risk assessment.

[0046] The first risk impact score of the dependent asset is calculated based on its first operational status and security situation information, combined with the first risk contribution weight. The purpose of this calculation is to quantify the risk level of the dependent asset itself. For example, if the dependent asset has a high-risk vulnerability and its operational status is abnormal, its first risk impact score will be higher.

[0047] The second risk impact score of the dependent business is calculated based on its second operational status and business criticality level, combined with the second risk contribution weight. Similarly, the purpose of calculating the second risk impact score of the dependent business is to quantify the risk level of the dependent business. For example, if the dependent business is a core business and its current operational status is poor, its second risk impact score will be higher.

[0048] The dependency risk amplification factor is determined based on both the first and second risk impact scores. This factor comprehensively reflects the risk transmission and amplification effect between the dependent asset and the relied-upon business. By integrating these two risk impact scores, the risk amplification effect in the dependency relationship can be comprehensively assessed, resulting in a more accurate dependency risk amplification factor. By introducing risk contribution weights, the actual importance of different assets and businesses in the risk transmission chain can be better reflected, making the security situation awareness results more consistent with reality and providing stronger data support for cybersecurity decision-making.

[0049] Furthermore, determining the dependency risk amplification factor based on the first risk impact score and the second risk impact score includes: constructing a fusion configuration library; matching corresponding fusion algorithms and fusion weights in the fusion configuration library based on the first risk impact score and the second risk impact score; and performing a fusion operation on the first risk impact score and the second risk impact score based on the fusion algorithm and the fusion weights to obtain the dependency risk amplification factor.

[0050] Specifically, a fusion configuration library is constructed, which refers to a database containing various fusion strategies, algorithms, and corresponding weights. This fusion configuration library can be predefined or dynamically updated based on historical data and expert experience. For example, the fusion configuration library can store fusion algorithms and their corresponding weight parameters for different business types, risk levels, or dependency patterns. Matching the corresponding fusion algorithm and weights based on the first and second risk impact scores in the fusion configuration library can be understood as the system searching for the most suitable fusion algorithm and weight combination for the current situation in the predefined fusion configuration library based on the specific values ​​of the first risk impact score of the currently dependent asset and the second risk impact score of the dependent business, the business scenario, asset type, and other contextual information. For example, when the first risk impact score is high and the second risk impact score is low, a fusion algorithm that emphasizes amplifying the high-risk impact may be matched; conversely, a more balanced algorithm may be matched. The matching process can be implemented based on a rule engine, machine learning model, or predefined lookup table.

[0051] Based on the aforementioned fusion algorithm and fusion weights, the first risk impact score and the second risk impact score are fused to obtain a dependency risk amplification factor. Specifically, this involves applying the matched fusion algorithm and weights to the first and second risk impact scores, performing mathematical calculations to derive a comprehensive dependency risk amplification factor. The aim is to more accurately quantify the risk amplification effect in dependency relationships through a scientific fusion method. This ensures that the calculation of the dependency risk amplification factor fully reflects the complex risk transmission relationship between the dependent asset and the dependent business, making the risk assessment results closer to reality.

[0052] Furthermore, the construction of the fusion configuration library includes: obtaining business process status information of key business services, determining the mapping relationship between business processes and fusion configurations; matching corresponding fusion strategy configurations based on the business process status information and the mapping relationship; and constructing the fusion configuration library based on the fusion strategy configurations.

[0053] Specifically, the system acquires business process status information for critical business services. This information refers to the system collecting and analyzing various status data during the operation of critical business services, such as the stage of business processing, current load, resource consumption, and interaction status with other business modules. This information comprehensively reflects the real-time operational status of the business process. The system also determines the mapping relationship between business processes and fusion configurations. This mapping relationship, based on predefined rules or through machine learning, establishes an association between different business process states and fusion configurations. This mapping aims to ensure that the most suitable fusion algorithm and fusion weights can be selected in different business scenarios or states to accurately assess dependency risks. For example, business processes handling sensitive data may require a more conservative fusion configuration, while non-core auxiliary businesses may use a more lenient configuration.

[0054] Based on the business process status information, the system uses the mapping relationship to match the corresponding fusion strategy configuration. According to the real-time acquired business process status information, the system searches for and selects the fusion strategy configuration that best matches the current business status from the established mapping relationship. This fusion strategy configuration includes the specific algorithm type and corresponding weight parameters used for subsequent risk score fusion calculations.

[0055] Based on the aforementioned fusion strategy configuration, a fusion configuration library is constructed. Using the matched fusion strategy configuration as a foundation, a configuration set containing multiple fusion algorithms and corresponding weights is dynamically or pre-built. This ensures that the constructed fusion configuration library can provide more targeted and accurate fusion algorithms and weights. This mechanism allows risk assessment to better adapt to dynamic business changes and avoids assessment biases that may result from using a single fixed fusion strategy.

[0056] Furthermore, the step of performing a fusion operation on the first risk impact score and the second risk impact score based on the fusion algorithm and fusion weights to obtain a dependency risk amplification factor includes: constructing a business dependency risk map and determining a risk transmission path based on the business dependency risk map; determining the node risk impact score of the risk transmission path based on the business dependency risk map and calculating the path risk accumulation value based on the node risk impact score; and performing a fusion operation on the first risk impact score and the second risk impact score using the path risk accumulation value based on the fusion algorithm and fusion weights to obtain the dependency risk amplification factor.

[0057] Specifically, constructing a business dependency risk graph refers to establishing a graphical model that can intuitively represent the complex relationships between critical business services and their dependent network assets. This graph can contain nodes (representing business services or network assets) and edges (representing the dependencies between them). Edges can be assigned direction and weight to indicate the directionality and strength of the dependency. For example, a business service may depend on multiple databases, application servers, and network devices. These dependencies and their potential risk transmission paths can be clearly represented in the graph. Determining risk transmission paths based on the business dependency risk graph means identifying all possible risk propagation paths from a risk source to a target business service or dependent business within the constructed graph. These paths can be single-hop direct dependencies or multi-hop indirect dependencies. For example, if asset A depends on asset B, and asset B depends on business C, then there is a risk transmission path from asset A to business C.

[0058] The process of determining the node risk impact score of the risk transmission path based on the business dependency risk map and calculating the path risk accumulation value based on the node risk impact score refers to the quantitative assessment of the risk impact of each node in the map and the accumulation calculation of the node risk impact scores along the identified risk transmission path. The node risk impact score can be determined comprehensively based on factors such as the node's own security status, operating status, and business criticality level. The path risk accumulation value reflects the total impact that the risk may cause when it propagates along a specific path. For example, it can be obtained by weighted summation or product operation of the risk impact scores of all nodes on the path.

[0059] Based on the fusion algorithm and fusion weights, the cumulative path risk value is used to perform a fusion calculation on the first risk impact score and the second risk impact score to obtain a dependency risk amplification factor. This means that when fusing the first and second risk impact scores, the cumulative path risk value is introduced as an important correction or weighting factor into the fusion algorithm. For example, when fusing the first risk impact score of the dependent asset (e.g., storage device D) and the second risk impact score of the dependent business (e.g., business service A), the cumulative path risk value calculated above is introduced as a correction factor or weight into the fusion algorithm. For example, if the cumulative risk value of the path D→B→A is high, then when fusing the risk impact scores of D and A, a higher weight or a greater amplification will be given, thereby obtaining a more accurate dependency risk amplification factor. This means that the fusion calculation is no longer just a simple combination of two scores, but considers the cumulative and amplified effects of risk in the actual business dependency chain, so that the final dependency risk amplification factor can more accurately reflect the true impact of risk. The obtained dependency risk amplification factor not only reflects the risks of the dependent assets and the dependent business themselves, but also includes the comprehensive impact of the transmission and accumulation of risks throughout the entire dependency chain, thereby improving the accuracy and comprehensiveness of dependency risk assessment.

[0060] S208: Perform vulnerability exploitation probability analysis based on the current network behavior data set to obtain the target vulnerability exploitation probability, and determine the severity of the network threat based on the target vulnerability exploitation probability; In a specific implementation of this invention, the step of performing vulnerability exploitation probability analysis based on the current network behavior data set to obtain the target vulnerability exploitation probability includes: performing vulnerability scanning on the current network behavior data set to obtain vulnerability information; performing detection behavior analysis on the vulnerability information to obtain detection behavior information, and matching vulnerability correlation factors based on the detection behavior information; and performing vulnerability exploitation probability analysis based on the detection behavior information and the vulnerability correlation factors to obtain the target vulnerability exploitation probability.

[0061] Specifically, performing vulnerability scanning on the current network behavior data set to obtain vulnerability information refers to detecting security vulnerabilities in all accessible assets on the network through automated tools or manual methods. This process aims to identify known vulnerabilities in the network, such as operating system vulnerabilities, application vulnerabilities, and configuration errors, and generate detailed vulnerability information reports. Vulnerability information may include vulnerability type, severity level, scope of impact, and remediation suggestions.

[0062] The vulnerability information is analyzed to obtain probing behavior information. Probing behavior analysis involves in-depth mining of the obtained vulnerability information, combining network traffic, logs, and other data to analyze whether there are probing behaviors targeting these vulnerabilities. Probing behavior information can include the IP addresses, timestamps, payloads, and scanning patterns of attackers attempting to exploit the vulnerabilities. Based on this probing behavior information, vulnerability relevance factors are matched. Vulnerability relevance factors are indicators that measure the likelihood and impact of a vulnerability being exploited. They are comprehensively evaluated based on factors such as the vulnerability's public availability, the availability of exploit tools, the complexity of the attack, and historical attack data. For example, a vulnerability with publicly available exploit tools and frequent probing behavior will have a higher relevance factor.

[0063] Based on the aforementioned probe behavior information and vulnerability relevance factors, vulnerability exploitation probability analysis is performed to obtain the exploitation probability of the target vulnerability. Vulnerability exploitation probability analysis refers to comprehensively considering the identified probe behavior information and matched vulnerability relevance factors, using methods such as statistical models, machine learning algorithms, or expert experience to calculate the probability of each vulnerability being successfully exploited. For example, a predictive model can be constructed, taking into input the frequency and intensity of probe behavior, the reputation of the attack source, and vulnerability relevance factors, and outputting a probability value between 0 and 1, representing the likelihood of the vulnerability being successfully exploited in the current network environment. This generates a more accurate and instructive target vulnerability exploitation probability. This hierarchical and progressive analysis method makes the assessment of vulnerability exploitation probability no longer static, but dynamically reflects the real threat situation in the current network environment. The severity of a network threat is determined based on the probability of exploiting the target vulnerability. The severity of a network threat refers to the potential destructive power or scope of impact of the threat currently facing the network. When determining the severity of a network threat, the probability of exploiting the target vulnerability can be mapped to a preset threat level according to the numerical range of the probability of exploiting the target vulnerability. For example, when the probability of exploiting the target vulnerability is less than 20%, the severity of the threat is low; when it is between 20% and 60%, the severity of the threat is medium; and when it is greater than 60%, the severity of the threat is high.

[0064] S209: Conduct an overall network security posture assessment based on the severity of the network threats and the vulnerability of network assets.

[0065] In the specific implementation of this invention, a simple matrix assessment method can be used to evaluate the overall network security posture based on the severity of network threats and the vulnerability of network assets. For example, the severity of network threats and the vulnerability of network assets can be divided into three levels: low, medium, and high. Then, according to a preset assessment matrix, the corresponding overall security posture can be found. For example, when the severity of network threats is medium and the vulnerability of network assets is medium, the overall network security posture assessment result is medium risk. Combining the severity of external threats with the vulnerability of internal assets forms a comprehensive and dynamic view of network security posture. In this way, security operators can clearly understand the overall risk level currently facing the network, thereby making timely and effective security response decisions.

[0066] In this embodiment of the invention, network anomaly fluctuation analysis is performed using a short-term sensitivity threshold based on the current network behavior data set, which more accurately identifies abnormal fluctuations in the network and improves the sensitivity and accuracy of anomaly perception. Based on the network anomaly fluctuation data, transmission anomaly impact analysis is performed using preset transmission quality indicators, which can assess the impact of network anomalies on data transmission reliability and efficiency, thereby providing a more comprehensive understanding of the potential harm of anomaly events. Based on the analysis of the internal state parameters of critical business services, the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of internal flow control mechanisms to the total duration are analyzed. An internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of internal flow control mechanisms to the total duration, providing more comprehensive data support for subsequent network asset security vulnerability assessment. The target contribution weight is determined based on the internal stress index, and an internal transmission problem impact factor is generated based on the target contribution weight. Based on the internal transmission problem impact factor, network anomaly fluctuation data, and transmission anomaly impact data, network asset security vulnerability is determined, which can more accurately reflect the probability of successful asset attacks. Vulnerability exploitation probability analysis is performed based on the current network behavior data set to determine the severity of network threats, which helps to identify the urgency and potential destructive power of threats currently facing the network. By conducting an overall network security posture assessment based on the severity of network threats and the vulnerability of network assets, a comprehensive and dynamic assessment of the overall network security posture can be achieved, effectively solving the problems of lagging and fragmented assessment in traditional methods.

[0067] Example 3 Please see Figure 3 , Figure 3 This is a schematic diagram of the structural composition of a network security situation awareness system according to an embodiment of the present invention. The system includes: Abnormal fluctuation analysis module 31: used to obtain the current network behavior data set and the internal status parameters of key business services, and to perform network abnormal fluctuation analysis based on the current network behavior data set using short-term sensitivity thresholds to obtain network abnormal fluctuation data; Transmission impact analysis module 32: used to perform transmission anomaly impact analysis based on the network anomaly fluctuation data using preset transmission quality indicators, and obtain transmission anomaly impact data; Pressure index calculation module 33: is used to analyze the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of the internal flow control mechanism to the total duration based on the internal state parameters, and to determine the internal pressure index based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. Vulnerability determination module 34: used to determine the target contribution weight based on the internal stress index, generate an internal transmission problem impact factor based on the target contribution weight, and determine the network asset security vulnerability based on the internal transmission problem impact factor, network abnormal fluctuation data, and transmission abnormal impact data; Threat severity determination module 35: used to perform vulnerability exploitation probability analysis based on the current network behavior data set, obtain the target vulnerability exploitation probability, and determine the severity of the network threat based on the target vulnerability exploitation probability; Situation assessment module 36: Used to conduct an overall network security situation assessment based on the severity of the network threat and the vulnerability of network assets.

[0068] In the specific implementation of this invention, the specific implementation methods of the system items can be referred to the implementation methods of the above-mentioned method items, and will not be repeated here.

[0069] In this embodiment of the invention, network anomaly fluctuation analysis is performed using a short-term sensitivity threshold based on the current network behavior data set, which more accurately identifies abnormal fluctuations in the network and improves the sensitivity and accuracy of anomaly perception. Based on the network anomaly fluctuation data, transmission anomaly impact analysis is performed using preset transmission quality indicators, which can assess the impact of network anomalies on data transmission reliability and efficiency, thereby providing a more comprehensive understanding of the potential harm of anomaly events. Based on the analysis of the internal state parameters of critical business services, the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of internal flow control mechanisms to the total duration are analyzed. An internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of internal flow control mechanisms to the total duration, providing more comprehensive data support for subsequent network asset security vulnerability assessment. The target contribution weight is determined based on the internal stress index, and an internal transmission problem impact factor is generated based on the target contribution weight. Based on the internal transmission problem impact factor, network anomaly fluctuation data, and transmission anomaly impact data, network asset security vulnerability is determined, which can more accurately reflect the probability of successful asset attacks. Vulnerability exploitation probability analysis is performed based on the current network behavior data set to determine the severity of network threats, which helps to identify the urgency and potential destructive power of threats currently facing the network. By conducting an overall network security posture assessment based on the severity of network threats and the vulnerability of network assets, a comprehensive and dynamic assessment of the overall network security posture can be achieved, effectively solving the problems of lagging and fragmented assessment in traditional methods.

[0070] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.

[0071] Furthermore, the above provides a detailed description of the network security situation awareness method and system provided by the embodiments of the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A network security situation awareness method, characterized in that, The method includes: Obtain the current network behavior data set and the internal state parameters of key business services, and perform network anomaly fluctuation analysis based on the current network behavior data set using short-term sensitivity thresholds to obtain network anomaly fluctuation data; Based on the network anomaly fluctuation data, the impact of transmission anomalies is analyzed using preset transmission quality indicators to obtain transmission anomaly impact data. Based on the internal state parameters, the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of the internal flow control mechanism to the total duration are analyzed, and the internal stress index is determined based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. The target contribution weight is determined based on the internal pressure index, the internal transmission problem impact factor is generated based on the target contribution weight, and the network asset security vulnerability is determined based on the internal transmission problem impact factor, network abnormal fluctuation data, and transmission abnormal impact data. Based on the current network behavior data set, vulnerability exploitation probability analysis is performed to obtain the target vulnerability exploitation probability, and the severity of the network threat is determined based on the target vulnerability exploitation probability. An overall network security posture assessment is conducted based on the severity of the network threats and the vulnerability of network assets.

2. The network security situation awareness method according to claim 1, characterized in that, The method of analyzing network anomalies based on the current network behavior data set using short-term sensitivity thresholds to obtain network anomaly fluctuation data includes: A set of historical network behavior data is obtained, and a long-term drift baseline is constructed using the set of historical network behavior data based on the exponentially weighted moving average method; A short-term sensitivity threshold is generated based on the long-term drift baseline and the historical fluctuation range. Based on the current network behavior data set, potential fluctuation anomaly analysis is performed using the short-term sensitivity threshold to obtain potential fluctuation anomaly data. Based on the potential fluctuation anomaly data, an in-depth investigation of anomalies is conducted to obtain in-depth investigation information of anomalies, and network anomaly fluctuation data is determined based on the in-depth investigation information of anomalies.

3. The network security situation awareness method according to claim 1, characterized in that, The determination of the target contribution weight based on the internal pressure index includes: Obtain the type information of key business services, and determine the initial contribution weight based on the type information and the internal stress index; Obtain the current operating mode of the key business service, and adjust the initial contribution weight based on the current operating mode to obtain the target contribution weight.

4. The network security situation awareness method according to claim 1, characterized in that, The generation of the internal transmission problem impact factor based on the target contribution weight includes: An initial transmission problem impact factor is generated based on the target contribution weight and the internal pressure index. Obtain the dependency graph of network assets, and determine the dependent assets and the services that are depended upon based on the dependency graph; Obtain the first operational status and security posture information of the dependent assets, and obtain the second operational status and business criticality level of the dependent business; The dependency risk amplification factor is determined based on the first operating status and security situation information of the dependent assets, as well as the second operating status and business criticality level of the dependent business. The initial transmission problem influence factor is adjusted based on the aforementioned dependency risk amplification factor to obtain the internal transmission problem influence factor.

5. The network security situation awareness method according to claim 4, characterized in that, The determination of the dependency risk amplification factor based on the first operational status and security situation information of the dependent assets, and the second operational status and business criticality level of the dependent business, includes: Obtain the type information of the dependent assets and the type information of the dependent business, and determine the first risk contribution weight based on the type information of the dependent assets using a preset risk contribution weight configuration library, and determine the second risk contribution weight based on the type information of the dependent business using a preset risk contribution weight configuration library. The first risk impact score of the dependent asset is calculated based on the first operating status and security situation information of the dependent asset and the first risk contribution weight. The second risk impact score of the dependent business is calculated based on the second operating status and business criticality level of the dependent business, combined with the second risk contribution weight. The dependency risk amplification factor is determined based on the first risk impact score and the second risk impact score.

6. The network security situation awareness method according to claim 5, characterized in that, The determination of the dependent risk amplification factor based on the first risk impact score and the second risk impact score includes: Construct a fusion configuration library, and match the corresponding fusion algorithm and fusion weight in the fusion configuration library based on the first risk impact score and the second risk impact score; The first risk impact score and the second risk impact score are fused based on the fusion algorithm and fusion weight to obtain the dependent risk amplification factor.

7. The network security situation awareness method according to claim 6, characterized in that, The construction of the integrated configuration library includes: Obtain the business process status information of key business services and determine the mapping relationship between business processes and integrated configurations; Based on the business process status information, the corresponding fusion strategy configuration is matched using the mapping relationship; A fusion configuration library is built based on the aforementioned fusion strategy configuration.

8. The network security situation awareness method according to claim 6, characterized in that, The step of performing a fusion operation on the first risk impact score and the second risk impact score based on the fusion algorithm and fusion weights to obtain the dependent risk amplification factor includes: Construct a business dependency risk map and determine the risk transmission path based on the business dependency risk map; Based on the business dependency risk map, the node risk impact score of the risk transmission path is determined, and the cumulative path risk value is calculated based on the node risk impact score. Based on the fusion algorithm and fusion weight, the first risk impact score and the second risk impact score are fused using the cumulative path risk value to obtain the dependency risk amplification factor.

9. The network security situation awareness method according to claim 1, characterized in that, The step of performing vulnerability exploitation probability analysis based on the current network behavior data set to obtain the target vulnerability exploitation probability includes: Perform vulnerability scanning on the current network behavior data set to obtain vulnerability information; The vulnerability information is analyzed to obtain detection behavior information, and vulnerability relevance factors are matched based on the detection behavior information. Based on the aforementioned detection behavior information and vulnerability correlation factors, vulnerability exploitation probability analysis is performed to obtain the target vulnerability exploitation probability.

10. A network security situation awareness system, characterized in that, The system includes: Anomaly fluctuation analysis module: used to acquire the current network behavior data set and the internal status parameters of key business services, and to perform network anomaly fluctuation analysis based on the current network behavior data set using short-term sensitivity thresholds to obtain network anomaly fluctuation data; Transmission Impact Analysis Module: Used to perform transmission anomaly impact analysis based on the network anomaly fluctuation data using preset transmission quality indicators, and obtain transmission anomaly impact data; Pressure Index Calculation Module: Used to analyze the first occurrence frequency of internal cache adjustment events, the second occurrence frequency of data retransmission timeout events, and the proportion of the activation duration of the internal flow control mechanism to the total duration based on the internal state parameters, and to determine the internal pressure index based on the first occurrence frequency, the second occurrence frequency, and the proportion of the activation duration of the internal flow control mechanism to the total duration. Vulnerability determination module: used to determine the target contribution weight based on the internal stress index, generate the internal transmission problem impact factor based on the target contribution weight, and determine the security vulnerability of network assets based on the internal transmission problem impact factor, network abnormal fluctuation data, and transmission abnormal impact data; Threat severity determination module: used to perform vulnerability exploitation probability analysis based on the current network behavior data set, obtain the target vulnerability exploitation probability, and determine the severity of the network threat based on the target vulnerability exploitation probability; Situation assessment module: used to conduct an overall network security situation assessment based on the severity of the network threat and the vulnerability of network assets.