Network space security defense method and system based on visualization technology

By constructing a network space topology map and generating attack path projections, the problem of inaccurate network security incident handling strategies was solved, the handling of network security incidents was optimized, and the stability of business systems was improved.

CN121509019APending Publication Date: 2026-02-10BEIJING KEDONG ELECTRIC POWER CONTROL SYST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511775473.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing technologies, the handling strategies for cybersecurity incidents mainly rely on alarm information, which leads to inaccurate handling scope and affects the secure and stable operation of business systems.

Method used

By constructing a network space topology map, combining physical connections and network relationships, attack path projections are generated, affected areas are divided, alarm information and security equipment control policies are matched, and network security incident handling strategies are generated.

Benefits of technology

The strategy for handling cybersecurity incidents has been optimized, reducing the impact of improper handling on business systems and improving the efficiency of the security team in adjusting protective measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509019A_ABST
    Figure CN121509019A_ABST
Patent Text Reader

Abstract

The invention discloses a network space security defense method and system based on a visualization technology, and belongs to the technical field of network security defense. The method comprises the following steps: acquiring cyberspace asset information, cyberspace operation behavior information and alarm information, wherein the cyberspace asset information comprises security equipment; constructing a cyberspace topological graph based on the cyberspace asset information, the cyberspace operation behavior information and the alarm information; when the risk assets appear, generating an attack path deduction line in the network space topological graph based on the network relationship; according to assets having a physical connection relationship and a network relationship with the risk assets, dividing an influence area in the network space topological graph; matching the alarm information with a control strategy of the security and protection equipment to obtain an association relationship; and generating a network security event handling strategy according to the attack path deduction line, the influence area and the incidence relation. According to the invention, a traditional network security event processing strategy is optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security defense technology, specifically relating to a network space security defense method and system based on visualization technology. Background Technology

[0002] With the continuous development of asset detection and cyberspace asset mapping technologies, constructing cyberspace topology maps to intuitively reflect the operational status of cyberspace assets has become a new direction for cyberspace security protection. However, current strategies for handling cybersecurity incidents mainly rely on alarm information and the physical connections of the assets that generated the alarms, resulting in an inaccurate grasp of the appropriate handling strategy. Both overly broad and overly narrow scopes of handling can impact the secure and stable operation of business systems. Summary of the Invention

[0003] The purpose of this invention is to overcome the shortcomings of the prior art and provide a network space security defense method and system based on visualization technology, which optimizes the traditional network security incident handling strategy to reduce the impact of improper handling strategy settings on the operation of business systems.

[0004] This invention provides the following technical solution: In a first aspect, a cyberspace security defense method based on visualization technology is provided, including: acquiring cyberspace asset information, cyberspace operation behavior information, and alarm information, wherein the cyberspace asset information includes security equipment; Based on the aforementioned cyberspace asset information, cyberspace operational behavior information, and alarm information, a cyberspace topology map is constructed; wherein, the cyberspace topology map includes physical connection relationships and network relationships; When a risky asset appears, an attack path deduction route is generated in the network space topology map based on the network relationships. Based on the assets that have physical and network connections with the aforementioned risky assets, the affected areas are divided in the network space topology map; The alarm information is matched with the control strategy of the security equipment to obtain the correlation; Based on the attack path, the affected area and related relationships are deduced to generate a network security incident handling strategy.

[0005] As an optional technical solution of the present invention, the cyberspace asset information further includes host devices and network devices; The host device includes servers, workstations, and terminals; The network devices include switches and routers; The security equipment includes a firewall and a vertical encryption device.

[0006] As an optional technical solution of the present invention, the step of constructing a network space topology map based on network space asset information, network space operation behavior information, and alarm information includes: Based on the cyberspace asset information, cyberspace operation behavior information, and alarm information, a cyberspace asset topology map, a cyberspace defense map, and an asset risk point display map are constructed. The cyberspace asset topology map, the cyberspace defense map, and the asset risk point display map are integrated to obtain the cyberspace topology map. Using network control equipment as the core, a network space asset topology map is generated by constructing physical and network connections between network space assets; The pre-acquired asset security protection level is divided into boundary and internal areas. Security devices belonging to the boundary type are deployed on the corresponding boundary, and security devices belonging to the internal type are deployed in the corresponding internal areas to generate the network space deployment map. Based on the alarm information, an asset risk point display map is generated. The asset risk point display map includes risk points at the individual asset level and risk points at the spatial area level. The risk points at the individual asset level include network port open status, access control list, routing list, and vulnerability status. The risk points at the spatial area level include the network range for external access and the distribution of internal vulnerabilities.

[0007] As an optional technical solution of the present invention, the process of constructing the physical connection relationship includes: The breadth-first search algorithm is used to traverse the list of connected devices for each interface of the network control device. For connected host devices, the asset is attached based on the host device's IP address information. For cascaded network control devices, a second interface traversal is performed to build physical connection relationships level by level.

[0008] As an optional technical solution of the present invention, the network relationship includes network connection relationship and network access relationship; Based on the physical connection relationship, and combined with the routing information and access control policies of the cyberspace assets, a network connection relationship between cyberspace assets is generated. Based on pre-acquired network access behavior, network access relationships between cyberspace assets are generated.

[0009] As an optional technical solution of the present invention, based on the network relationship, an attack path deduction route is generated in the network space topology map, including: Starting with the aforementioned risky assets, reverse tracing and forward progression are performed along the network connections to generate a path deduction route.

[0010] As an optional technical solution of the present invention, the step of dividing the affected area in the network space topology map according to the assets that have physical and network connections with the risky assets includes: Assets that have a physical connection, network connection, or network access relationship with the aforementioned risky assets will be included in the affected area.

[0011] As an optional technical solution of the present invention, the step of matching alarm information with the control strategy of security equipment to obtain an association relationship includes: The alarm information includes access alarms between hosts in Zone I and Zone II, access alarms between hosts in Zone III and Zone IV, and access alarms between the master station and the factory station. For access alarms between hosts in Zone I and Zone II, and between hosts in Zone III and Zone IV, the firewall's control policy is matched based on the source IP, destination IP, source port, and destination port in the alarm information. For access alarms between the master station and the plant station, when the master station accesses the plant station and the plant station reports vertically, the master station's vertical policy must be identified; when the plant station accesses the master station and the master station reports vertically, the plant station's vertical policy must be identified; when the master station accesses the plant station and the plant station's monitoring device reports, both the master station's vertical policy and the plant station's vertical policy must be identified; when the plant station accesses the master station and the master station host reports, both the master station's vertical policy and the plant station's vertical policy must be identified.

[0012] Secondly, a security defense system based on the cyberspace security defense method described in the first aspect is provided, comprising: The data acquisition module is used to acquire cyberspace asset information, cyberspace operation behavior information, and alarm information, wherein the cyberspace asset information includes security equipment; The topology map construction module is used to construct a network space topology map based on the network space asset information, network space operation behavior information, and alarm information; wherein, the network space topology map includes physical connection relationships and network relationships; The path deduction module is used to generate attack path deduction routes in the network space topology map based on the network relationships when risky assets appear. The region division module is used to divide the affected regions in the network space topology map based on assets that have physical and network connections with the risk assets. The matching module is used to match the alarm information with the control strategy of the security equipment to obtain the association relationship; The strategy generation module is used to deduce the route, affected area, and correlation based on the attack path and generate network security incident handling strategies.

[0013] Compared with the prior art, the beneficial effects of the present invention are: This invention provides a network security defense method based on visualization technology. By constructing a network space topology map, it comprehensively infers attack paths, affected areas, and related relationships to generate appropriate security incident handling strategies. This optimizes traditional network security incident handling strategies, thereby reducing the impact of improper handling strategy settings on business system operation. Visualization technology can more intuitively help security teams discover and adjust protection measures in a timely manner. Attached Figure Description

[0014] Figure 1 This is a schematic diagram of a cyberspace security defense method in an embodiment of the present invention. Detailed Implementation

[0015] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the scope of protection of the present invention.

[0016] Example 1 This embodiment provides a network space security defense method based on visualization technology, such as... Figure 1 As shown, it includes the following steps: Step 1: Obtain information on cyberspace assets, cyberspace operational behavior, and alarm information.

[0017] The cyberspace asset information includes security equipment, host equipment, and network equipment.

[0018] The host device includes servers, workstations, and terminals; the network device includes switches and routers; and the security device includes firewalls and vertical encryption devices.

[0019] Step 2: Based on the network space asset information, network space operation behavior information, and alarm information, construct a network space topology map; wherein, the network space topology map includes physical connection relationships and network relationships.

[0020] Based on the cyberspace asset information, cyberspace operation behavior information, and alarm information, a cyberspace asset topology map, a cyberspace defense map, and an asset risk point display map are constructed. The cyberspace asset topology map, the cyberspace defense map, and the asset risk point display map are integrated to obtain the cyberspace topology map.

[0021] Using network control equipment as the core, a network space asset topology map is generated by constructing physical and network connections between network space assets.

[0022] The pre-acquired asset security protection levels are divided into boundary and internal areas. Security devices belonging to the boundary type are deployed on the corresponding boundary, and security devices belonging to the internal type are deployed in the corresponding internal areas, generating the network space deployment map. Specifically, boundary-type security devices include vertical encryption, horizontal isolation, and firewalls; internal-type security devices include trusted verification modules, malicious code clients, and operation and maintenance gateways.

[0023] Based on the alarm information, an asset risk point display map is generated. The asset risk point display map includes risk points at the individual asset level and risk points at the spatial area level. The risk points at the individual asset level include network port open status, access control list, routing list, and vulnerability status. The risk points at the spatial area level include the network range for external access and the distribution of internal vulnerabilities.

[0024] Furthermore, the process of constructing the physical connection relationship includes: traversing the list of connected devices for each interface of the network control device using a breadth-first search algorithm; for connected host devices, completing asset attachment based on the host device's IP address information; and for cascaded network control devices, performing a secondary interface traversal to construct the physical connection relationship level by level.

[0025] Furthermore, the network relationships include network connection relationships and network access relationships. Based on the physical connection relationships, combined with the routing information and access control policies of the cyberspace assets, network connection relationships between cyberspace assets are generated, providing support for network exposure surface analysis and impact surface analysis after an attack on the assets; based on pre-acquired network access behavior, network access relationships between cyberspace assets are generated, providing data support for understanding the cyberspace situation.

[0026] Step 3: When a risky asset appears, based on the network relationships, generate an attack path projection line in the network space topology map.

[0027] Starting with the aforementioned risky assets, reverse tracing and forward progression are performed along the network connections to generate a path deduction route.

[0028] Step 4: Based on the assets that have physical and network connections with the risky assets, divide the affected areas in the network space topology map.

[0029] Assets that have a physical connection, network connection, or network access relationship with the aforementioned risky assets will be included in the affected area.

[0030] Step 5: Match the alarm information with the control strategy of the security equipment to obtain the correlation.

[0031] The alarm information includes access alarms between hosts in Zone I and Zone II, access alarms between hosts in Zone III and Zone IV, and access alarms between the master station and the factory station. For access alarms between hosts in Zone I and Zone II, and between hosts in Zone III and Zone IV, the firewall's control policy is matched based on the source IP, destination IP, source port, and destination port in the alarm information. For access alarms between the master station and the plant station, when the master station accesses the plant station and the plant station reports vertically, the master station's vertical policy must be identified; when the plant station accesses the master station and the master station reports vertically, the plant station's vertical policy must be identified; when the master station accesses the plant station and the plant station's monitoring device reports, both the master station's vertical policy and the plant station's vertical policy must be identified; when the plant station accesses the master station and the master station host reports, both the master station's vertical policy and the plant station's vertical policy must be identified.

[0032] When the policy direction is identified as a positive policy: (1) The alarm source IP is located between the starting IP of the vertical policy source and the ending IP of the vertical policy source; (2) The alarm destination IP is located between the starting IP of the vertical policy and the ending IP of the vertical policy; (3) Alarm source port, located between the source start port and source end port of the vertical policy; (4) Alarm destination port, located between the destination start port and destination end port of the vertical strategy. When the above alarm information perfectly matches the vertical policy, the vertical policy will be identified and matched with the alarm pattern.

[0033] When the direction of the policy is identified as the opposite: (1) The alarm source IP is located between the destination start IP and the destination end IP of the vertical policy; (2) The alarm destination IP is located between the source start IP and the source end IP of the vertical policy; (3) Alarm source port, located between the destination start port and destination end port of the vertical strategy; (4) Alarm destination port, located between the source start port and the source end port of the vertical policy. When the above alarm information perfectly matches the vertical policy, the vertical policy will be identified and matched with the alarm pattern.

[0034] The policy direction was identified as bidirectional. (1) The alarm source IP is located between the starting IP of the vertical policy source and the ending IP of the vertical policy source; (2) The alarm destination IP is located between the starting IP of the vertical policy and the ending IP of the vertical policy; (3) Alarm source port, located between the source start port and source end port of the vertical policy; (4) Alarm destination port, located between the destination start port and destination end port of the vertical strategy; or: (1) The alarm source IP is located between the destination start IP and the destination end IP of the vertical policy; (2) The alarm destination IP is located between the source start IP and the source end IP of the vertical policy; (3) Alarm source port, located between the destination start port and destination end port of the vertical strategy; (4) Alarm destination port, located between the source start port and the source end port of the vertical policy. When the above alarm information perfectly matches the vertical policy, the vertical policy will be identified and matched with the alarm pattern.

[0035] Step Six: Based on the attack path, deduce the route, affected area, and correlation to generate a network security incident handling strategy.

[0036] Network security incident handling strategies include process-level blocking, session blocking, device blocking, switch blocking, area blocking, and policy modification. Based on the handling results, the asset status and information in the network topology map are updated.

[0037] Example 2 This embodiment provides a security defense system based on the cyberspace security defense method in Embodiment 1, including: The data acquisition module is used to acquire cyberspace asset information, cyberspace operation behavior information, and alarm information, wherein the cyberspace asset information includes security equipment; The topology map construction module is used to construct a network space topology map based on the network space asset information, network space operation behavior information, and alarm information; wherein, the network space topology map includes physical connection relationships and network relationships; The path deduction module is used to generate attack path deduction routes in the network space topology map based on the network relationships when risky assets appear. The region division module is used to divide the affected regions in the network space topology map based on assets that have physical and network connections with the risk assets. The matching module is used to match the alarm information with the control strategy of the security equipment to obtain the association relationship; The strategy generation module is used to deduce the route, affected area, and correlation based on the attack path and generate network security incident handling strategies.

[0038] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0039] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0040] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0041] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0042] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A cyberspace security defense method based on visualization technology, characterized in that, include: Acquire cyberspace asset information, cyberspace operational behavior information, and alarm information, wherein the cyberspace asset information includes security equipment; Based on the aforementioned cyberspace asset information, cyberspace operational behavior information, and alarm information, a cyberspace topology map is constructed; wherein, the cyberspace topology map includes physical connection relationships and network relationships; When a risky asset appears, an attack path deduction route is generated in the network space topology map based on the network relationships. Based on the assets that have physical and network connections with the aforementioned risky assets, the affected areas are divided in the network space topology map; The alarm information is matched with the control strategy of the security equipment to obtain the correlation; Based on the attack path, the affected area and related relationships are deduced to generate a network security incident handling strategy.

2. The network space security defense method based on visualization technology according to claim 1, characterized in that, The cyberspace asset information also includes host devices and network devices; The host device includes servers, workstations, and terminals; The network devices include switches and routers; The security equipment includes a firewall and a vertical encryption device.

3. The network space security defense method based on visualization technology according to claim 2, characterized in that, The construction of a network space topology map based on network space asset information, network space operational behavior information, and alarm information includes: Based on the cyberspace asset information, cyberspace operation behavior information, and alarm information, a cyberspace asset topology map, a cyberspace defense map, and an asset risk point display map are constructed. The cyberspace asset topology map, the cyberspace defense map, and the asset risk point display map are integrated to obtain the cyberspace topology map. Using network control equipment as the core, a network space asset topology map is generated by constructing physical and network connections between network space assets; The pre-acquired asset security protection level is divided into boundary and internal areas. Security devices belonging to the boundary type are deployed on the corresponding boundary, and security devices belonging to the internal type are deployed in the corresponding internal areas to generate the network space deployment map. Based on the alarm information, an asset risk point display map is generated. The asset risk point display map includes risk points at the individual asset level and risk points at the spatial area level. The risk points at the individual asset level include network port open status, access control list, routing list, and vulnerability status. The risk points at the spatial area level include the network range for external access and the distribution of internal vulnerabilities.

4. The network space security defense method based on visualization technology according to claim 3, characterized in that, The process of constructing the physical connection relationship includes: The breadth-first search algorithm is used to traverse the list of connected devices for each interface of the network control device. For connected host devices, the asset is attached based on the host device's IP address information. For cascaded network control devices, a second interface traversal is performed to build physical connection relationships level by level.

5. The network space security defense method based on visualization technology according to claim 3, characterized in that, The network relationships include network connection relationships and network access relationships; Based on the physical connection relationship, and combined with the routing information and access control policies of the cyberspace assets, a network connection relationship between cyberspace assets is generated. Based on pre-acquired network access behavior, network access relationships between cyberspace assets are generated.

6. The detection method according to claim 5, characterized in that, When a risky asset appears, the process of generating an attack path projection route in the network space topology map based on the network relationships includes: Starting with the aforementioned risky assets, reverse tracing and forward progression are performed along the network connections to generate a path deduction route.

7. The detection method according to claim 5, characterized in that, The process of dividing the affected areas in the network space topology map based on assets that have physical and network connections with the risky assets includes: Assets that have a physical connection, network connection, or network access relationship with the aforementioned risky assets will be included in the affected area.

8. The detection method according to claim 2, characterized in that, The process of matching alarm information with the control strategies of security equipment to obtain correlation relationships includes: The alarm information includes access alarms between hosts in Zone I and Zone II, access alarms between hosts in Zone III and Zone IV, and access alarms between the master station and the factory station. For access alarms between hosts in Zone I and Zone II, and between hosts in Zone III and Zone IV, the firewall's control policy is matched based on the source IP, destination IP, source port, and destination port in the alarm information. For access alarms between the master station and the plant station, when the master station accesses the plant station and the plant station reports vertically, the master station's vertical policy must be identified; when the plant station accesses the master station and the master station reports vertically, the plant station's vertical policy must be identified; when the master station accesses the plant station and the plant station's monitoring device reports, both the master station's vertical policy and the plant station's vertical policy must be identified; when the plant station accesses the master station and the master station host reports, both the master station's vertical policy and the plant station's vertical policy must be identified.

9. A security defense system based on the cyberspace security defense method according to any one of claims 1-8, characterized in that, include: The data acquisition module is used to acquire cyberspace asset information, cyberspace operation behavior information, and alarm information, wherein the cyberspace asset information includes security equipment; The topology map construction module is used to construct a network space topology map based on the network space asset information, network space operation behavior information, and alarm information; wherein, the network space topology map includes physical connection relationships and network relationships; The path deduction module is used to generate attack path deduction routes in the network space topology map based on the network relationships when risky assets appear. The region division module is used to divide the affected regions in the network space topology map based on assets that have physical and network connections with the risk assets. The matching module is used to match the alarm information with the control strategy of the security equipment to obtain the association relationship; The strategy generation module is used to deduce the route, affected area, and correlation based on the attack path and generate network security incident handling strategies.