Computer network alerting system and method
By constructing a vulnerability relationship network and conducting multi-step attack simulations, attack threat paths in computer networks are identified and isolated, solving the problems of inaccurate threat identification and delayed emergency response in existing technologies, and achieving efficient network security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SICHUAN VOCATIONAL & TECHN COLLEGE
- Filing Date
- 2026-02-04
- Publication Date
- 2026-04-21
AI Technical Summary
Existing computer network alarm methods have significant bottlenecks in threat identification accuracy and emergency response effectiveness. They fail to effectively identify multi-step attack paths, have high false alarm and false negative rates, and lack global vulnerability assessment and closed-loop response mechanisms.
By monitoring the communication behavior sequences of each node within the target network, a vulnerability relationship network is constructed, multi-step attack simulations are performed, attack threat paths are identified, behavioral alarm rules are set, and targeted inquiries and proactive isolation are conducted to achieve global vulnerability assessment and dynamic risk assessment.
It improves the accuracy of computer network alarms, reduces false alarm and false negative rates, and enables comprehensive perception and effective emergency response to multi-step attacks.
Smart Images

Figure CN121644240B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network alarm technology, and more specifically, to a computer network alarm system and method. Background Technology
[0002] As computer networks evolve from closed architectures to open interconnections, accurately identifying actual attack activities and achieving efficient emergency response has become a core challenge. Current mainstream methods mainly rely on triggering passive alarms with fixed thresholds or performing simple matching based on single attack characteristics. While these methods improve threat awareness to some extent, they often suffer from high false alarm rates, delayed responses, and rigid isolation strategies when dealing with complex and ever-changing attack paths and dynamically evolving threat behaviors, making it difficult to reliably ensure system security in complex network environments.
[0003] Existing computer network alerting methods suffer from significant bottlenecks in threat identification accuracy and emergency response effectiveness. They typically lack a global vulnerability distribution model based on communication behavior sequences, fail to integrate the inherent risks of attack threat paths with the dynamic risks of real-time access behavior, and lack closed-loop response mechanisms. Specifically, existing solutions only monitor isolated anomaly data from single nodes, failing to extract communication behavior sequences or construct vulnerability relationship networks, thus failing to grasp the global vulnerability distribution and resulting in insufficient multi-step attack path identification capabilities. Alternatively, they employ passive alerts with fixed thresholds, failing to calculate inherent threat values for attack threat paths and generate dynamic risk assessment values, leading to high false positive and false negative rates, and lacking targeted probing verification and proactive isolation measures. This makes the system significantly inadequate in protecting against complex multi-step attacks and dynamic network threats. Therefore, improving the accuracy of computer network alerts through a global vulnerability assessment mechanism has become a challenging problem for the industry. Summary of the Invention
[0004] This application provides a computer network alarm system and method, which can improve the accuracy of computer network alarms through a global vulnerability assessment mechanism.
[0005] In a first aspect, this application provides a computer network alarm method, comprising the following steps:
[0006] The communication data of each node in the target network is monitored, and the communication behavior sequence of the network nodes is extracted.
[0007] Based on the communication behavior sequence, the communication interaction mode between each communication node is determined, and all communication interaction modes are bound to the risk verification link between the corresponding communication nodes to obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network.
[0008] Multi-step attack simulation is performed on the vulnerability network to identify multiple attack threat paths from the network periphery access point to the internal protected resources, and the inherent threat value of each attack threat path is determined based on the defense response characteristics in each attack threat path.
[0009] Monitor the access behavior characteristics of communication nodes involved in all attack threat paths, set real-time access behavior alarm rules by comparing the access behavior characteristics with the basic threat level of the corresponding communication nodes, match and verify the real-time access behavior alarm rules with the inherent threat value of each attack threat path, and generate a risk assessment value of the current overall threat status.
[0010] When the risk assessment value is greater than the preset alarm trigger value, a targeted query is initiated to the communication node in the corresponding attack threat path, and the existence of attack activity is determined based on the returned query response information. If confirmed, an active isolation alarm is triggered.
[0011] Preferably, determining the communication interaction mode between each communication node based on the communication behavior sequence specifically includes:
[0012] Real-time network security situation information of network nodes is obtained from the communication behavior sequence;
[0013] Based on the network security situation information, determine the security situation vector between each communication node;
[0014] By integrating all security posture vectors through the security policy engine, communication interaction patterns between communication nodes are generated.
[0015] Preferably, all communication interaction modes are bound to the risk verification links between corresponding communication nodes to obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network. Specifically, this includes:
[0016] Obtain the risk verification link between communication nodes established after security assessment;
[0017] Vulnerability feature verification is performed on all communication interaction modes and their corresponding risk verification links to obtain link risk information on the vulnerability distribution of the decision network within the target communication network;
[0018] Based on the link risk information, determine the vulnerability relationship network of the decision network vulnerability distribution within the target communication network.
[0019] Preferably, performing multi-step attack simulations on the vulnerability network to identify multiple attack threat paths from peripheral access points to internal protected resources specifically includes:
[0020] Based on the vulnerability relationship network, multiple aggregate attack resistances are identified from the network periphery access points to the internal protected resources;
[0021] Determine the attack penetration path with the highest success rate based on all aggregated attack resistance;
[0022] The attack penetration path with the highest success rate of iterative attacks reveals multiple attack threat paths from peripheral network access points to internal protected resources.
[0023] Preferably, determining the inherent threat value of each attack threat path based on the defense response characteristics of each attack threat path specifically includes:
[0024] Obtain historical security event logs for each network node along each attack threat path;
[0025] Identify the defensive response characteristics in each attack threat path;
[0026] Each defense response feature is mapped to the corresponding historical security event log to obtain the inherent threat value of each attack threat path.
[0027] Preferably, the behavioral alert rules for real-time access behavior are matched and verified with the inherent threat value of each attack threat path to generate a risk assessment value for the current overall threat status. Specifically, this includes:
[0028] The behavioral alarm rules are matched and mapped with the attack characteristics of each attack threat path to identify potential attack paths activated by real-time alarms.
[0029] Calculate the dynamic impact factors in the potential attack paths;
[0030] The risk assessment value of the current overall threat situation is determined based on all dynamic influencing factors and the inherent threat value of each attack threat path.
[0031] Preferably, when the risk assessment value is greater than the preset alarm trigger value, initiating a targeted inquiry to the communication node in the corresponding attack threat path specifically includes:
[0032] Obtain communication protocol information when the risk assessment value is greater than the preset alarm trigger value from the activated attack threat path;
[0033] The communication protocol information is matched with a predefined probing strategy library to construct and send a secure probing message carrying verification credentials.
[0034] The response behavior of communication nodes in the attack threat path is compared and analyzed using a preset security response baseline, and the output is a targeted probing result to characterize whether the node has been actually attacked.
[0035] Secondly, this application provides a computer network alarm system, comprising:
[0036] The acquisition module is used to monitor the communication data of each node in the target network and extract the communication behavior sequence of the network nodes.
[0037] The processing module is used to determine the communication interaction mode between each communication node based on the communication behavior sequence, bind all communication interaction modes with the risk verification link between the corresponding communication nodes, and obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network.
[0038] The processing module is also used to perform multi-step attack simulation on the vulnerability relationship network, identify multiple attack threat paths from the network periphery access point to the internal protected resources, and determine the inherent threat value of each attack threat path based on the defense response characteristics in each attack threat path.
[0039] The processing module is also used to monitor the access behavior characteristics issued by communication nodes involved in all attack threat paths, set real-time access behavior alarm rules by comparing the access behavior characteristics with the basic threat level of the corresponding communication nodes, match and verify the real-time access behavior alarm rules with the inherent threat value of each attack threat path, and generate a risk assessment value of the current overall threat status.
[0040] The execution module is used to initiate a targeted query to the communication node in the corresponding attack threat path when the risk assessment value is greater than the preset alarm trigger value, and determine whether there is an attack activity based on the returned query response information, and actively isolate and alarm upon confirmation.
[0041] Thirdly, this application provides a computer device, the computer device including a memory and a processor, the memory storing code, and the processor configured to acquire the code and execute the above-described computer network alarm method.
[0042] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned computer network alarm method.
[0043] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects:
[0044] In this embodiment, proactive isolation alarms enable accurate threat identification and efficient emergency response in computer networks. First, by monitoring the communication data of each node within the target network, communication behavior sequences are extracted, communication interaction patterns are determined, and risk verification links are bound to construct a vulnerability relationship network. This allows for a global understanding of the vulnerability distribution of the decision-making network, effectively addressing the limitations of existing technologies that rely on isolated monitoring of single nodes. Second, multi-step attack simulations are performed on the vulnerability relationship network to identify multiple attack threat paths from external network access points to internal protected resources and determine their inherent threat values. This enables comprehensive awareness of potential multi-step attack penetration paths, resolving the insufficient multi-step attack identification capabilities of existing technologies. Then, by monitoring the access behavior characteristics of nodes involved in the attack threat path, setting behavioral alarm rules, and matching and verifying them with inherent threat values to generate risk assessment values, it is possible to achieve a fusion assessment of inherent and dynamic risks, solving the shortcomings of existing technologies that rely on fixed thresholds for passive alarms, and significantly reducing the false alarm rate and false negative rate. Finally, when the risk assessment value exceeds the preset alarm trigger value, a targeted inquiry is initiated, and after confirming the attack based on the response information, an active isolation alarm is triggered. This overcomes the limitations of existing technologies that rely on passive notifications, effectively verifies actual attacks and prevents their spread, and significantly improves the effectiveness of emergency response. In summary, the solution proposed in this application can improve the accuracy of computer network alarms through a global vulnerability assessment mechanism. Attached Figure Description
[0045] Figure 1 This is a schematic diagram illustrating an application scenario for computer network risk verification based on some embodiments of this application;
[0046] Figure 2 This is an exemplary flowchart of a computer network alarm method according to some embodiments of this application;
[0047] Figure 3 This is a flowchart illustrating the determination of behavior alarm rules according to some embodiments of this application;
[0048] Figure 4 This is a schematic diagram of the structure of a computer network alarm system according to some embodiments of this application;
[0049] Figure 5 This is a schematic diagram of the structure of a computer device for a computer network alarm method according to some embodiments of this application. Detailed Implementation
[0050] To better understand the technical solution of this application, the technical solution of this application will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0051] refer to Figure 1This figure is a schematic diagram of an application scenario for computer network risk verification according to some embodiments of this application. The figure includes a risk data collector, a risk analysis server group, a communication link layer, and a terminal device. The risk data collector is connected to the risk analysis server group through the communication link layer, and the terminal device interacts with the risk data collector and the risk analysis server group through the communication link layer. The risk data collector first collects risk-related data such as network communication data and node behavior data from the terminal device, and transmits this data to the risk analysis server group through the communication link layer. After receiving the data, the risk analysis server group processes it and, in conjunction with preset risk verification logic, sequentially performs communication behavior sequence extraction, communication interaction pattern recognition, vulnerability relationship network construction, attack threat path deduction, and risk assessment value calculation, ultimately generating a risk verification result. The risk analysis server group synchronizes the risk verification result through the communication link layer. If there is an abnormal risk in the nodes involved with the terminal device, it will also send a warning message to the relevant links through the communication link layer.
[0052] Among them, the risk data collector may include network traffic collection devices, node behavior log collection tools, and boundary access awareness interfaces; the risk analysis server group may be a distributed risk computing cluster deployed in a network security area, or a risk analysis service node built on a security cloud; the terminal device may be, but is not limited to, a business server, office terminal, mobile access device, or application node within the network; the communication link layer is the network channel that carries the data transmission of each component, covering intranet communication links, security isolation links, etc.
[0053] refer to Figure 2 The figure is an exemplary flowchart of a computer network alarm method according to some embodiments of this application. The computer network alarm method mainly includes the following steps:
[0054] In step 101, the communication data of each node in the target network is monitored, and the communication behavior sequence of the network nodes is extracted.
[0055] It should be noted that the methods for monitoring the communication data of each node in the target network in this application can also include deploying a syslog collector on the node host to capture communication records in the system log; polling the node network interface through the SNMP protocol to obtain traffic statistics; capturing the communication flow in the software-defined network with the help of the traffic visualization function of the SDN controller; and deploying an API gateway at the application layer to monitor the call communication between services. These methods cover multiple levels and are adapted to the monitoring needs of different network architectures.
[0056] In some embodiments, monitoring the communication data of each node in the target network and extracting the communication behavior sequence of the network nodes can be achieved in the following way: First, deploy optical splitters, NetFlow collectors, and traffic capture tools such as tcpdump at key locations such as the core links, access nodes, and border gateways of the target network to fully cover the communication links of all network nodes to achieve full traffic capture. The captured content should include source / destination IP addresses, source / destination port numbers, communication protocol types, data transmission timestamps, packet sizes, and session establishment / disconnection status. Then, perform preprocessing operations on the captured raw data: through session identifiers, data... The system performs packet verification and removes redundant data from repeated captures, filters out invalid content such as broadcast packets and known legitimate test traffic, and then converts heterogeneous formats such as pcap and NetFlow into a unified JSON format containing "session ID, source node identifier, destination node identifier, protocol type, timestamp, behavior description, and data size". Finally, the preprocessed session data is arranged in ascending order of timestamps in units of "source node - destination node" to form a complete communication behavior sequence that records the communication trajectory between nodes. For example, the sequence between an office terminal and an intranet server will sequentially present continuous communication behavior steps such as TCP connection establishment, SSH authentication, file transfer, and connection termination.
[0057] It should be noted that, in this application, the communication behavior sequence refers to a structured sequence that records the sequential protocol order of communication between target network nodes.
[0058] In step 102, the communication interaction mode between each communication node is determined according to the communication behavior sequence, and all communication interaction modes are bound to the risk verification link between the corresponding communication nodes to obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network.
[0059] It should be noted that the communication interaction mode in this application refers to the regular communication behavior type of the security level attribute of the communication behavior between communication nodes.
[0060] In some embodiments, determining the communication interaction mode between communication nodes based on the communication behavior sequence can be achieved using the following steps:
[0061] Real-time network security situation information of network nodes is obtained from the communication behavior sequence;
[0062] Based on the network security situation information, determine the security situation vector between each communication node;
[0063] By integrating all security posture vectors through the security policy engine, communication interaction patterns between communication nodes are generated.
[0064] It should be noted that the network security situation information in this application refers to a multi-dimensional data set reflecting the current communication state security of communication nodes; the security situation vector in this application refers to standardized vector data that quantifies the security state between communication nodes; and the security policy engine in this application is a processing rule used to fuse the security situation vector.
[0065] In specific implementation, firstly, the network security situation information of network nodes can be obtained in real time from the communication behavior sequence in the following way: the dimensions of the situation information are defined as communication protocol compliance, session duration, abnormal data payload characteristics, and node connection frequency; then, data for each dimension is extracted from the extracted communication behavior sequence: protocol compliance is determined by whether the protocol in the sequence belongs to the node's preset legal protocol set; session duration is determined by the time difference between the node's sessions in the sequence; abnormal data payload characteristics are compared with the character distribution of the sequence payload and the node's historical normal payload; and connection frequency is determined by the number of sessions between the node and the node per unit time, thus obtaining the network security situation information. Then, the security situation vector between each communication node can be determined based on the network security situation information in the following way: using vector quantization, the situation information of each dimension is mapped to numerical values: protocol compliance dimension, compliance is recorded as 1, non-compliance as 0; session duration dimension, within ±20% of the node's historical average duration is recorded as 1, exceeding it is recorded as 0.5; data load anomaly characteristic dimension, normal is recorded as 1, anomaly as 0; connection frequency dimension, within ±30% of the historical frequency is recorded as 1, exceeding it is recorded as 0.5; the values are arranged in the order of "protocol compliance, session duration, load anomaly, connection frequency" to form the security situation vector. Finally, the communication interaction patterns between communication nodes can be generated by fusing all security posture vectors through the security policy engine in the following way: The security policy engine includes a weighted summation and pattern matching module: First, weighted summation is performed, assigning weights to the four dimensions of the security posture vector, such as protocol compliance 0.3, session duration 0.2, load anomaly 0.3, and connection frequency 0.2. The weights are derived from the attribution analysis of security events in the target network over the past six months. The vector comprehensive score is calculated, and all scores are quantized to between 0 and 1. Then, pattern matching is performed, dividing the scores into three intervals: ≥0.8 corresponds to "normal communication interaction pattern", 0.5≤score<0.8 corresponds to "suspicious communication interaction pattern", and <0.5 corresponds to "abnormal communication interaction pattern". The output is the communication interaction pattern between each communication node.
[0066] In some embodiments, binding all communication interaction modes with the corresponding risk verification links between communication nodes to obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network can be achieved through the following steps:
[0067] Obtain the risk verification link between communication nodes established after security assessment;
[0068] Vulnerability feature verification is performed on all communication interaction modes and their corresponding risk verification links to obtain link risk information on the vulnerability distribution of the decision network within the target communication network;
[0069] Based on the link risk information, determine the vulnerability relationship network of the decision network vulnerability distribution within the target communication network.
[0070] It should be noted that the risk verification link in this application is structured link data describing the propagation path, exploitation conditions, and potential hazards of security weaknesses between communication nodes; the vulnerability feature verification in this application refers to a standardized verification process used to confirm the matching degree and correlation of vulnerability features between communication interaction patterns and corresponding risk verification links; the link risk information in this application refers to the structured information obtained after vulnerability feature verification of communication interaction patterns and corresponding risk verification links; and the vulnerability relationship network in this application refers to a graph structure network that presents the distribution, propagation path, and risk level of decision network vulnerabilities within the target communication network.
[0071] It should be noted that the determination method for the vulnerability distribution of the decision network within the target communication network in this application can also adopt a hierarchical determination method that weights attack path coverage and link risk. Using the constructed vulnerability relationship network as a carrier, the full attack threat path is first simulated; then the path coverage exposure of each communication node is statistically analyzed, and the vulnerability score of the node is calculated by combining the hazard level and transmission success probability in the link risk information through a preset weighted model; finally, the vulnerability distribution is determined by hierarchical clustering based on the score and combined with the risk intensity distribution of the attack path. The dense area of nodes with high exposure and high score is the core risk area. The model weight and clustering threshold are both calibrated based on simulated attack experiments over the past three months.
[0072] In specific implementation, firstly, obtaining the risk verification links between communication nodes established after security assessment can be achieved as follows: retrieve the official security assessment report of the target communication network for the past 6 months, and extract the risk verification links between communication nodes that have been dually verified by the CVSS vulnerability scoring system and internal security audit process; perform structured processing on the extracted link data, and supplement necessary attributes such as the corresponding communication node pairs, core vulnerability types, vulnerability exploitation preconditions, and potential hazard levels to obtain the risk verification links. Then, vulnerabilities are verified for all communication interaction modes and their corresponding risk verification links to obtain the link risk information of the decision network vulnerability distribution within the target communication network. This can be achieved as follows: extract the corresponding vulnerability association features for each communication interaction mode, and simultaneously extract matching vulnerability propagation features from the risk verification links; calculate the matching degree of the two sets of features using a cosine similarity algorithm, and filter effective association pairs based on the association threshold set based on the verification experiments of the past 3 months; supplement each effective association pair with information such as vulnerability hazard level, vulnerability propagation success probability, and association validity identifier, ultimately generating link risk information containing complete attributes. Finally, the vulnerability relationship network for determining the vulnerability distribution of the decision network within the target communication network based on the link risk information can be implemented in the following way: A basic graph structure framework is constructed using all communication nodes within the target communication network as vertices; the “communication interaction mode – risk verification link” verified by vulnerability features is used as directed edges, and the corresponding link risk information is added to the graph structure as the core attribute of the edge; the constructed network is standardized using the adjacency matrix method in graph theory to generate a vulnerability relationship network containing vertex attributes, edge attributes, and a complete topology.
[0073] In step 103, a multi-step attack simulation is performed on the vulnerability relationship network to identify multiple attack threat paths from the network periphery access point to the internal protected resources, and the inherent threat value of each attack threat path is determined based on the defense response characteristics in each attack threat path.
[0074] It should be noted that the multi-step attack simulation in this application is a complete analysis process that simulates an attacker gradually penetrating from a network periphery access point to an internal protected resource; the network periphery access point in this application refers to the starting node of the multi-step attack simulation, used to define the starting range of the attack threat path; the internal protected resource in this application refers to the ending node of the multi-step attack simulation, used to define the ending range of the attack threat path.
[0075] In some embodiments, performing multi-step attack simulations on the vulnerability network to identify multiple attack threat paths from peripheral access points to internal protected resources can be achieved through the following steps:
[0076] Based on the vulnerability relationship network, multiple aggregate attack resistances are identified from the network periphery access points to the internal protected resources;
[0077] Determine the attack penetration path with the highest success rate based on all aggregated attack resistance;
[0078] The attack penetration path with the highest success rate of iterative attacks reveals multiple attack threat paths from peripheral network access points to internal protected resources.
[0079] It should be noted that, in this application, the aggregate attack resistance refers to a quantitative indicator of the sum of the attack resistance of all nodes and links on a candidate path from the network periphery access point to the internal protected resource within the vulnerability relationship network; the attack penetration path in this application refers to a single attack penetration path with the minimum aggregate attack resistance and the maximum corresponding attack success rate among the current candidate paths; and the attack threat path in this application refers to multiple attack penetration paths with different attack success rates, starting from the network periphery access point and ending at the internal protected resource.
[0080] In specific implementation, firstly, the determination of multiple aggregated attack resistances from the network periphery access point to the internal protected resource based on the vulnerability relationship network can be achieved in the following way: using the vulnerability relationship network as a carrier, firstly extract all candidate paths from the network periphery access point to the internal protected resource, and then for each candidate path, extract the link risk information of each link and the defense response characteristics of each node within the path, and use a weighted summation model to calculate the aggregated attack resistance of a single path, where the link transmission obstacle weight is 0.4 and the node defense obstacle weight is 0.6. The weight values are based on the attribution analysis results of simulated attack experiments over the past 3 months, and finally, multiple aggregated attack resistances are obtained. Then, determining the attack penetration path with the highest success rate based on all aggregated attack resistance can be achieved as follows: The attack success rate and aggregated attack resistance are strictly negatively correlated; that is, the lower the aggregated attack resistance, the higher the success rate. Using an improved Dijkstra algorithm, the aggregated attack resistance is used as the path weight. Starting from the network perimeter access point and ending at the internal protected resource, the aggregated attack resistance of all candidate paths is traversed, and the single path with the smallest weight is finally selected as the attack penetration path with the highest success rate. Finally, iterating through the attack penetration path with the highest success rate to obtain multiple attack threat paths from the network perimeter access point to the internal protected resource can be achieved as follows: After obtaining the attack penetration path with the highest success rate each time, a resistance adjustment operation is performed on all links on that path, multiplying its aggregated attack resistance by an adjustment factor of 1.2. This adjustment factor is determined based on the path iteration verification results of simulated attack experiments over the past three months. After adjustment, the process of obtaining a new attack penetration path with the highest success rate is repeated. This iterative operation is repeated until a preset number of paths are obtained or the adjusted aggregated attack resistance exceeds a threshold. All obtained paths are then considered as all attack threat paths.
[0081] In some embodiments, determining the inherent threat value of each attack threat path based on the defense response characteristics in each attack threat path can be achieved through the following steps:
[0082] Obtain historical security event logs for each network node along each attack threat path;
[0083] Identify the defensive response characteristics in each attack threat path;
[0084] Each defense response feature is mapped to the corresponding historical security event log to obtain the inherent threat value of each attack threat path.
[0085] In specific implementation, firstly, obtaining the historical security event logs of each network node on each attack threat path can be achieved as follows: retrieve the local security event logs of each network node on each attack threat path for the past 12 months and the synchronized logs stored in the centralized log management system, perform preprocessing operations such as deduplication, filling in missing fields, and format standardization, and filter out event data directly related to node defense measures to obtain the historical security event logs of each network node on each attack threat path. Next, determining the defense response characteristics in each attack threat path can be achieved as follows: for each attack threat path, extract the relevant information on the defense measures of all network nodes on the path, determine the three core dimensions of the defense response characteristics: defense measure type, completeness of triggering conditions, and actual defense effectiveness; use a structured extraction method of feature engineering to quantify and encode each dimension, and determine the dimension weights based on the results of defense effectiveness experimental analysis over the past 6 months, ultimately forming the standardized defense response characteristics for each path. Finally, mapping each defense response feature to the corresponding historical security event log to obtain the inherent threat value of each attack threat path can be achieved in the following way: an association rule mining algorithm can be used to associate and map each defense response feature of each path with the corresponding historical security event log, and the frequency and severity of the security events corresponding to the feature in the log can be statistically analyzed; a weighted summation calculation model can be used to convert the mapping result into the inherent threat value of the path. The model weights and value ranges are calibrated based on the results of simulated attack experiments over the past 6 months, and finally, a standardized inherent threat value for each attack threat path is obtained.
[0086] It should be noted that the historical security event log in this application refers to structured data stored locally on the network node or in a centralized log system, which records the types, times, severity, and response results of past security events that occurred on the node; the defense response characteristics in this application refer to the set of quantitative characteristics of the defense measures attributes of each network node; and the inherent threat value in this application refers to a standardized indicator that quantifies the risk level of attack threat paths.
[0087] In step 104, the access behavior characteristics issued by communication nodes involved in all attack threat paths are monitored. By comparing the access behavior characteristics with the basic threat level of the corresponding communication nodes, real-time access behavior alarm rules are set. The real-time access behavior alarm rules are matched and verified with the inherent threat value of each attack threat path to generate a risk assessment value of the current overall threat status.
[0088] In some embodiments, monitoring the access behavior characteristics of communication nodes involved in all attack threat paths can be achieved in the following way: Deploy distributed network traffic monitoring tools (such as Suricata), host behavior collection tools (such as Osquery), and application layer API gateway monitoring modules at the core link of the target communication network, the hosts of each communication node involved in the attack threat path, and the border gateway to form a full-dimensional monitoring system; capture in real time the source IP address, destination IP address, source port number, destination port number, communication protocol type, access timestamp, access frequency per unit time, and key features of data payload when these communication nodes initiate access, while filtering out invalid data such as broadcast packets and known legitimate test traffic, and use the information obtained after standardizing the format of the captured heterogeneous data as the access behavior characteristics of the communication nodes.
[0089] It should be noted that, in this application, access behavior characteristics refer to the quantified set of IP, port, protocol, time, frequency, and data presented when the communication nodes involved in the attack threat path initiate access.
[0090] In some embodiments, reference Figure 3 As shown in the figure, this is a flowchart illustrating the process of determining behavioral alarm rules in some embodiments of this application. In this embodiment, setting real-time access behavior alarm rules by comparing the access behavior characteristics with the basic threat level of the corresponding communication node can be achieved through the following steps:
[0091] In step 1041, the security deviation between the access behavior characteristics and the basic threat level of the corresponding communication node is determined;
[0092] In step 1042, the security deviation is corrected based on the intrusion detection rule base and threat intelligence;
[0093] In step 1043, behavior alarm rules for real-time access behavior are set based on the corrected security deviation.
[0094] It should be noted that, in this application, the security deviation refers to a standardized indicator that quantifies the difference between the matching characteristics of access behavior and the basic threat level of the corresponding communication node; the basic threat level in this application refers to the inherent risk level corresponding to the security level of the network area; the intrusion detection rule base in this application refers to a structured database that stores known intrusion behavior characteristics, historical security alarm records, and baselines of legitimate access behavior; the threat intelligence in this application includes a real-time security information set containing known malicious IP addresses, new attack behavior characteristics, and dynamic risk node information; and the behavior alarm rules in this application refer to a set of hierarchical response rules for the real-time access behavior of communication nodes involved in the attack threat path.
[0095] In specific implementation, the security deviation between the access behavior characteristics and the basic threat level of the corresponding communication node can be determined as follows: the access behavior characteristics are quantified and encoded, with each dimension assigned a score of 0-10, where 10 is completely in line with the normal standard; the basic threat level of the corresponding communication node is then converted into a standard score, with high level 8-10 points, medium level 4-7 points, and low level 1-3 points; the multidimensional spatial distance between the two is calculated using the Euclidean distance algorithm, and this distance is the security deviation. Then, the security deviation can be corrected based on the intrusion detection rule base and threat intelligence in the following way: retrieve the rule entries in the intrusion detection rule base that match the current access behavior characteristics. These rule entries include known attack behavior characteristics, historical false alarm records, and a legitimate access whitelist. If the access behavior characteristics match the legitimate whitelist, the security deviation will be reduced by 20%, and if they match known attack characteristics, it will be increased by 30%. At the same time, access the real-time threat intelligence from third-party security vendors and the dynamic risk information from internal security audits. If the access source IP is in the high-risk list of the threat intelligence, the deviation will be increased by 25%, and if it is a low-risk IP, the original value will be maintained. Finally, setting real-time access behavior alarm rules based on the corrected security deviation can be achieved in the following way: Divide the corrected security deviation into three intervals: low deviation interval (0-3 points), medium deviation interval (3-7 points), and high deviation interval (7-10 points); set three levels of behavior alarm rules accordingly: "continuous monitoring + log recording" for the low deviation interval, "enhanced monitoring + threshold warning" for the medium deviation interval, and "real-time alarm + behavior interception plan triggering" for the high deviation interval; each rule specifies the triggering conditions, response actions, and duration, and the rules can be dynamically adjusted based on subsequent security event feedback.
[0096] In some embodiments, matching and verifying the behavioral alarm rules for real-time access behavior with the inherent threat value of each attack threat path to generate a risk assessment value for the current overall threat status can be achieved through the following steps:
[0097] The behavioral alarm rules are matched and mapped with the attack characteristics of each attack threat path to identify potential attack paths activated by real-time alarms.
[0098] Calculate the dynamic impact factors in the potential attack paths;
[0099] The risk assessment value of the current overall threat situation is determined based on all dynamic influencing factors and the inherent threat value of each attack threat path.
[0100] It should be noted that the attack characteristics of the attack threat path in this application refer to the set of attributes that each attack threat path possesses, which can characterize its attack method, penetration stage, and target node attributes; the potential attack path in this application refers to the attack threat path where the matching degree between the behavior alarm rule and the attack characteristics reaches a preset threshold; the dynamic impact factor in this application refers to a standardized indicator that quantifies the impact of real-time alarms on the risk level of potential attack paths; and the risk assessment value in this application refers to an indicator that quantifies the current overall security risk level of the target communication network.
[0101] In specific implementation, firstly, the behavioral alarm rules are matched and mapped with the attack characteristics of each attack threat path to identify potential attack paths activated by real-time alarms. This can be achieved in the following way: extract the core alarm characteristics of the behavioral alarm rules, including the access behavior type triggered by the alarm, the communication nodes involved, and the dimensions of abnormal behavior; then extract the attack characteristics of each attack threat path, including the attack starting node, penetration stage, and target node of the path; perform structured quantization encoding on the two sets of characteristics, and use the cosine similarity algorithm to calculate the feature matching degree between a single behavioral alarm rule and a single attack threat path; set the matching degree threshold to 0.7, which is calibrated based on the results of simulated alarm and attack path matching experiments on the target network over the past 3 months; attack threat paths with a matching degree ≥ 0.7 are potential attack paths activated by real-time alarms. Then, the dynamic impact factor in the potential attack path can be calculated in the following way: Three core calculation dimensions of the dynamic impact factor are determined: the level of real-time alarms (high, medium, low), the frequency of alarm triggering, and the importance of the alarm-related nodes in the potential attack path; each dimension is quantified and assigned a value: high-level alarms 8-10 points, medium-level alarms 4-7 points, low-level alarms 1-3 points; alarm frequency is assigned a value of 1-10 points based on the number of triggers per unit time; node importance is assigned a value of 1-10 points based on the proportion of core links in the path; a weighted summation model is used to calculate the dynamic impact factor, with weights determined based on the results of dynamic risk impact experiments over the past 6 months: alarm level weight 0.5, alarm frequency weight 0.3, and node importance weight 0.2. The calculation results are normalized to the 0-1 range, which is the dynamic impact factor of the potential attack path. Finally, the risk assessment value of the current overall threat status can be determined based on all dynamic influencing factors and the inherent threat value of each attack path. This can be achieved in the following way: a weighted product summation model is used to calculate the risk assessment value of the current overall threat status. In the model, the risk contribution value of a single potential attack path is the dynamic influencing factor of that path multiplied by its inherent threat value. The overall risk assessment value is the sum of the risk contribution values of all potential attack paths. If there are no activated potential attack paths, the overall risk assessment value is 0. The product of the inherent threat value and the dynamic influencing factor can effectively reflect the real-time comprehensive risk of the path. The summation can accurately characterize the overall threat status. The calculation result ranges from 0 to 100, with higher values indicating a greater overall threat.
[0102] In step 105, when the risk assessment value is greater than the preset alarm trigger value, a targeted query is initiated to the communication node in the corresponding attack threat path, and the existence of attack activity is determined based on the returned query response information. After confirmation, an active isolation alarm is triggered.
[0103] In some embodiments, when the risk assessment value is greater than a preset alarm trigger value, initiating a targeted inquiry to the communication node in the corresponding attack threat path can be achieved through the following steps:
[0104] Obtain communication protocol information when the risk assessment value is greater than the preset alarm trigger value from the activated attack threat path;
[0105] The communication protocol information is matched with a predefined probing strategy library to construct and send a secure probing message carrying verification credentials.
[0106] The response behavior of communication nodes in the attack threat path is compared and analyzed using a preset security response baseline, and the output is a targeted probing result to characterize whether the node has been actually attacked.
[0107] It should be noted that the preset alarm trigger value in this application can be implemented in the following way: a two-dimensional calibration method combining simulated attack experiments with historical security event statistics can be used. Typical attack scenarios of the target network over the past six months are selected for simulation experiments, and the attack success probability corresponding to different risk assessment values is recorded. Simultaneously, the correspondence between risk assessment values and actual harm levels in historical security events during the same period is statistically analyzed. An initial trigger value is calculated using a weighted regression model, and then iteratively optimized through three months of actual operation. Finally, an alarm trigger value that balances false positive and false negative rates is set, with model weights and iteration thresholds calibrated based on experimental data.
[0108] It should be noted that the targeted probing in this application refers to a precise security probe operation conducted on communication nodes in the activated attack threat path when the risk assessment value of the current overall threat status exceeds a preset alarm trigger value; the communication protocol information in this application is structured information including protocol type, interaction port, data format, and authentication method; the probing strategy library in this application refers to a pre-stored set of standardized probing schemes adapted to different communication protocols and targeting various node weaknesses; the security probing message in this application refers to a standardized message carrying verification credentials for probing node status; the targeted probing result in this application is conclusive information characterizing whether a node has suffered an actual attack; and the verification credentials in this application are temporary access credentials generated based on the target network node authentication system.
[0109] In specific implementation, firstly, obtaining the communication protocol information when the risk assessment value is greater than the preset alarm trigger value from the activated attack threat paths can be achieved in the following way: traverse the activated attack threat paths and filter out the target paths with risk assessment values greater than the preset alarm trigger value; extract the communication protocol information of all communication nodes in these paths, including protocol type, interaction port number, data encapsulation format, and authentication method; perform preprocessing operations such as deduplication and filling in missing fields on the extracted information, and remove invalid or conflicting protocol information to obtain the communication protocol information when the risk assessment value is greater than the preset alarm trigger value. Then, the communication protocol information is matched with a predefined probing strategy library to construct and send a secure probing message carrying verification credentials. This can be achieved in the following way: The predefined probing strategy library is invoked, which contains probing strategies for mainstream protocols such as TCP, HTTP, and SSH. Each strategy specifies the message structure, probe fields, and sending frequency. An exact matching algorithm is used to match the extracted communication protocol information with the protocol type and port number in the strategy library to determine the appropriate probing strategy. A temporary verification credential is generated based on the target network node authentication system. A secure probing message is constructed according to the matched probing strategy, ensuring that the message format conforms to the protocol specifications and that the probe fields do not trigger node defense interception. The message is sent to the target communication node through an encrypted transmission channel, with the sending frequency controlled within a range that does not affect the node's normal business operations. Finally, the response behavior of communication nodes in the attack threat path is compared and analyzed using a preset security response baseline. The output of the targeted inquiry result, which characterizes whether the node has been actually attacked, can be achieved in the following way: Obtain the actual response behavior of the communication node to the security inquiry message, including the response message format, feedback duration, and data field content; call the preset security response baseline and use a feature similarity algorithm to calculate the matching degree between the actual response and the baseline from three dimensions: response format standardization, feedback duration reasonableness, and data field integrity; set a matching degree threshold, which is calibrated based on the difference analysis results between "normal node response" and "attacked node response" in the simulated attack experiments over the past 6 months; if the matching degree is lower than the threshold, it is determined that the node has been actually attacked; if it is higher than the threshold, it is determined that the node has not been actually attacked, and finally, a clear targeted inquiry result is output.
[0110] In practice, the presence of an attack activity is determined based on the returned probe response information. Upon confirmation, proactive isolation and alarm activation can be implemented as follows: After obtaining the probe response information returned by the communication node, a feature similarity algorithm is used to compare the response from three dimensions: response format standardization, feedback duration reasonableness, and data field completeness. If the matching degree is lower than the threshold calibrated through nearly three months of simulated attack experiments, a second targeted probe verification is initiated. If the verification result is still abnormal, an attack activity is confirmed. An active isolation mechanism is then triggered, cutting off the communication connection between the node and other nodes in the attack threat path, restricting their network access permissions, and simultaneously pushing alarm information containing the attack path, node information, and threat level to the operation and maintenance management platform to ensure timely and accurate emergency response.
[0111] It should be noted that, in this application, the probe response information refers to the structured data returned by the communication node to the security probe message during the directed probe process, which includes the response format, feedback duration, and data fields.
[0112] On the other hand, in some embodiments, this application provides a computer network alarm system, with reference to... Figure 4 The figure is a schematic diagram of the structure of a computer network alarm system according to some embodiments of this application. The computer network alarm system 400 includes: a data acquisition module 401, a processing module 402, and an execution module 403, which are described below:
[0113] The acquisition module 401 in this application is mainly used to monitor the communication data of each node in the target network and extract the communication behavior sequence of the network nodes.
[0114] Processing module 402, in this application, is used to determine the communication interaction mode between each communication node according to the communication behavior sequence, bind all communication interaction modes with the risk verification link between the corresponding communication nodes, and obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network.
[0115] In this application, the processing module 402 is also used to perform multi-step attack simulation on the vulnerability relationship network, identify multiple attack threat paths from the network periphery access point to the internal protected resources, and determine the inherent threat value of each attack threat path based on the defense response characteristics in each attack threat path.
[0116] In this application, the processing module 402 is also used to monitor the access behavior characteristics issued by the communication nodes involved in all attack threat paths, set real-time access behavior alarm rules by comparing the access behavior characteristics with the basic threat level of the corresponding communication nodes, match and verify the real-time access behavior alarm rules with the inherent threat value of each attack threat path, and generate a risk assessment value of the current overall threat status.
[0117] The execution module 403 in this application is mainly used to initiate a targeted query to the communication node in the corresponding attack threat path when the risk assessment value is greater than the preset alarm trigger value, and to determine whether there is an attack activity based on the returned query response information, and to actively isolate and alarm after confirmation.
[0118] In addition, this application also provides a computer device, the computer device including a memory and a processor, the memory storing code, and the processor being configured to acquire the code and execute the above-described computer network alarm method.
[0119] In some embodiments, reference Figure 5 The figure is a schematic diagram of the structure of a computer device implementing a computer network alarm method according to some embodiments of this application. The computer network alarm method in the above embodiments can be implemented through... Figure 5 The computer device shown is used to implement this, and the computer device 500 includes at least one processor 501, a communication bus 502, a memory 503, and at least one communication interface 504.
[0120] Processor 501 can be a general-purpose central processing unit (CPU) or an application-specific integrated circuit (ASIC).
[0121] The communication bus 502 can be used to transmit information between the aforementioned components.
[0122] Memory 503 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile optical discs, Blu-ray discs, etc.), magnetic disks or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 503 may exist independently and be connected to processor 501 via communication bus 502. Memory 503 may also be integrated with processor 501.
[0123] The memory 503 stores program code for executing the scheme of this application, and its execution is controlled by the processor 501. The processor 501 executes the program code stored in the memory 503. The program code may include one or more software modules. In the above embodiment, the computer network alarm method can be implemented by the processor 501 and one or more software modules in the program code in the memory 503.
[0124] Communication interface 504 uses any transceiver-like device to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.
[0125] In a specific implementation, as one example, a computer device may include multiple processors, each of which may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. Here, a processor may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).
[0126] The aforementioned computer device can be a general-purpose computer device or a special-purpose computer device. In specific implementations, the computer device can be a desktop computer, a portable computer, a network server, a handheld digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, a communication device, or an embedded device. This application does not limit the type of computer device.
[0127] In addition, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described computer network alarm method.
[0128] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0129] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A computer network alarm method, characterized in that, Includes the following steps: The communication data of each node in the target network is monitored, and the communication behavior sequence of the network nodes is extracted. Based on the communication behavior sequence, the communication interaction mode between each communication node is determined, and all communication interaction modes are bound to the risk verification link between the corresponding communication nodes to obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network. Here, the communication interaction mode refers to the regular communication behavior type of the security level attribute of the communication behavior between each communication node. Multi-step attack simulation is performed on the vulnerability network to identify multiple attack threat paths from the network periphery access point to the internal protected resources, and the inherent threat value of each attack threat path is determined based on the defense response characteristics in each attack threat path. Monitor the access behavior characteristics of communication nodes involved in all attack threat paths, set real-time access behavior alarm rules by comparing the access behavior characteristics with the basic threat level of the corresponding communication nodes, match and verify the real-time access behavior alarm rules with the inherent threat value of each attack threat path, and generate a risk assessment value of the current overall threat status. When the risk assessment value is greater than the preset alarm trigger value, a targeted query is initiated to the communication node in the corresponding attack threat path, and the existence of attack activity is determined based on the returned query response information. If confirmed, an active isolation alarm is triggered. Specifically, determining the communication interaction mode between each communication node based on the communication behavior sequence includes: The network security situation information of network nodes is obtained in real time from the communication behavior sequence; Determine the security situation vector between each communication node based on the network security situation information; By fusing all security posture vectors through the security policy engine, communication interaction patterns between various communication nodes are generated. Specifically, multi-step attack simulation of the vulnerability network identifies multiple attack threat paths from peripheral access points to internal protected resources, including: Based on the vulnerability relationship network, multiple aggregate attack resistances are identified from the network periphery access points to the internal protected resources; Determine the attack penetration path with the highest success rate based on all aggregated attack resistance; The attack penetration path with the highest success rate of iterative attacks reveals multiple attack threat paths from peripheral network access points to internal protected resources.
2. The method as described in claim 1, characterized in that, By binding all communication interaction modes with the corresponding risk verification links between communication nodes, the vulnerability relationship network of the decision network vulnerability distribution within the target communication network is obtained, specifically including: Obtain the risk verification link between communication nodes established after security assessment; Vulnerability feature verification is performed on all communication interaction modes and their corresponding risk verification links to obtain link risk information on the vulnerability distribution of the decision network within the target communication network; Based on the link risk information, the vulnerability relationship network of the decision network vulnerability distribution within the target communication network is determined.
3. The method as described in claim 1, characterized in that, The inherent threat value of each attack threat path is determined based on the defense response characteristics of each attack threat path, specifically including: Obtain historical security event logs for each network node along each attack threat path; Identify the defensive response characteristics in each attack threat path; Each defense response feature is mapped to the corresponding historical security event log to obtain the inherent threat value of each attack threat path.
4. The method as described in claim 1, characterized in that, The behavioral alert rules for real-time access behavior are matched and verified with the inherent threat value of each attack threat path to generate a risk assessment value for the current overall threat status. Specifically, this includes: The behavioral alarm rules are matched and mapped with the attack characteristics of each attack threat path to identify potential attack paths activated by real-time alarms. Calculate the dynamic influence factors in the potential attack paths; The risk assessment value of the current overall threat situation is determined based on all dynamic influencing factors and the inherent threat value of each attack threat path.
5. The method as described in claim 1, characterized in that, When the risk assessment value is greater than the preset alarm trigger value, a targeted inquiry is initiated to the communication node in the corresponding attack threat path, specifically including: Obtain communication protocol information when the risk assessment value is greater than the preset alarm trigger value from the activated attack threat path; The communication protocol information is matched with a predefined probing strategy library to construct and send a secure probing message carrying verification credentials. The response behavior of communication nodes in the attack threat path is compared and analyzed using a preset security response baseline, and the output is a targeted probing result to characterize whether the node has been actually attacked.
6. A computer network alarm system, which uses the method described in any one of claims 1 to 5 to perform computer network alarm, characterized in that, The system includes: The acquisition module is used to monitor the communication data of each node in the target network and extract the communication behavior sequence of the network nodes. The processing module is used to determine the communication interaction mode between each communication node based on the communication behavior sequence, bind all communication interaction modes with the risk verification link between the corresponding communication nodes, and obtain the vulnerability relationship network of the decision network vulnerability distribution within the target communication network. The processing module is also used to perform multi-step attack simulation on the vulnerability relationship network, identify multiple attack threat paths from the network periphery access point to the internal protected resources, and determine the inherent threat value of each attack threat path based on the defense response characteristics in each attack threat path. The processing module is also used to monitor the access behavior characteristics issued by communication nodes involved in all attack threat paths, set real-time access behavior alarm rules by comparing the access behavior characteristics with the basic threat level of the corresponding communication nodes, match and verify the real-time access behavior alarm rules with the inherent threat value of each attack threat path, and generate a risk assessment value of the current overall threat status. The execution module is used to initiate a targeted query to the communication node in the corresponding attack threat path when the risk assessment value is greater than the preset alarm trigger value, and determine whether there is an attack activity based on the returned query response information, and actively isolate and alarm upon confirmation.
7. A computer device comprising a memory and a processor, the memory storing code, characterized in that, The processor is configured to acquire the code and execute the computer network alarm method as described in any one of claims 1 to 5.
8. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the computer network alarm method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Computer network security intelligent analysis system and method based on big data
CN117896137A
Artificial Intelligence-based Quantified Cyber Defense Control Model
US20240314158A1