Method, device and system for ensuring safe operation of network in strong electromagnetic environment
By identifying the correlation between strong electromagnetic interference and network attack events, a safe operation and maintenance plan was developed, which resolved the impact of complex network attacks composed of strong electromagnetic interference and network attacks on network equipment and ensured the safe operation of network equipment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-30
- Publication Date
- 2026-04-14
AI Technical Summary
Under a combined network attack consisting of strong electromagnetic interference and traditional network attacks, network devices face problems such as equipment failure, data loss, and communication interruption. Existing technologies are unable to effectively identify and respond to such combined attacks.
By acquiring secure operation data of network devices, identifying and marking the correlation between strong electromagnetic interference and network attack events, and formulating corresponding secure operation and maintenance plans, the secure operation of network devices can be ensured.
It can accurately identify and process the correlation of events in complex network attacks, provide precise security operation and maintenance solutions, and ensure the security and stability of network devices.
Smart Images

Figure CN121864401A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method for ensuring network security operation in a strong electromagnetic environment. Background Technology
[0002] In practice, network defenders need to deal with a variety of traditional network attacks, including but not limited to at least one of the following: malware attacks, phishing attacks, denial-of-service attacks, man-in-the-middle attacks, SQL injection attacks, cross-site scripting attacks, session hijacking, and zero-day attacks.
[0003] Strong electromagnetic interference (EMI) differs from traditional cyberattacks. It primarily interferes with electronic devices and communication systems through physical means, causing equipment malfunctions or data transmission interruptions. EMI attacks can lead to equipment damage, data loss, communication disruptions, and other problems, affecting the normal operation of the system.
[0004] However, while responding to cyberattacks, network defenders also need to be constantly vigilant about the impact of strong electromagnetic interference on network equipment. This is mainly because strong electromagnetic interference can be used as a supplementary means, combined with traditional cyberattacks, to form complex attacks. For example, attackers can first use strong electromagnetic interference to paralyze network equipment or cause the security system to fail, and then carry out traditional cyberattacks to further damage the system or steal data stored on the network equipment.
[0005] Therefore, in practice, network attackers may take advantage of situations where network defenders are subjected to strong electromagnetic interference to launch network attacks, thereby stealing or damaging the data stored in the network devices protected by the network defenders.
[0006] In response to the above situation, this invention proposes a method, apparatus and system for ensuring the safe operation of the network in a strong electromagnetic environment, in order to solve the impact of complex network attacks including strong electromagnetic interference on network equipment, which has become an urgent technical problem to be solved. Summary of the Invention
[0007] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method, device and system for ensuring the safe operation of the network in a strong electromagnetic environment. This invention can identify composite network attacks composed of strong electromagnetic interference and traditional network attacks, and provides corresponding security operation and maintenance solutions for such composite network attacks to solve the impact of composite network attacks involving strong electromagnetic interference on network devices.
[0008] To address the existing technical problems, the present invention provides the following technical solution: A method for ensuring network security operation in a strong electromagnetic environment includes: Acquire security operation data of network devices; the security operation data refers to the operation data of security events reported by the aforementioned network devices during operation; the security events include network attack events and / or, strong electromagnetic interference events; Mark the safety operation data corresponding to the aforementioned safety events, and determine whether the aforementioned safety operation data reflects one or more safety events; When the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, the correlation between the event progress reflected by the security operation data of different security events is determined and mapped to the corresponding security operation and maintenance plan for execution, so as to ensure the safe operation of network equipment.
[0009] Furthermore, the network device includes at least one of the following: network traffic device, network security device, network management device, storage network device, load balancing device, optimization and acceleration device, access device, network interface device, wireless network device, industrial network device, and Internet of Things device; The secure operation data includes at least one of the following: device configuration data, performance monitoring data, network traffic data, session connection data, user activity data, access control data, alarm event monitoring and response data, and log recording data.
[0010] Furthermore, when at least one network attack event and at least one strong electromagnetic interference event are correlated in terms of event progression, the security events are combined to form a composite attack event.
[0011] Furthermore, the marker includes: Analyze the correlations between various safety operation data reflecting event progress; Based on the aforementioned relationship between the events, the order of occurrence of the aforementioned multiple safe operation data is determined, and the number of safe events to which the aforementioned safe operation data belongs is determined accordingly. Based on the aforementioned relationship between events, the security events are sequentially identified as the first security event, the second security event, ..., up to the Nth security event, where N is a positive integer; Corresponding to the aforementioned security event sequence identifier, the corresponding security event sequence identifier is matched to the aforementioned safe operation data.
[0012] Furthermore, after determining the correlation of the aforementioned security events' progress, the cause-oriented attributes of the corresponding security events are determined for the aforementioned security operation data; the cause-oriented attributes include device software causing device software problems, device software causing device hardware problems, device hardware causing device software problems, and / or, device hardware causing device hardware problems.
[0013] Furthermore, after determining the causal attributes of the corresponding security event, it also includes: Obtain the cause-oriented attributes of each security event under the correlation of different event progress; For the selected security events to be processed, extract the corresponding cause-oriented attributes and the security operation data corresponding to the aforementioned security events to match the security operation and maintenance plan.
[0014] Furthermore, the security events to be processed are determined based on the aforementioned event progression correlations; The configuration of the security operation and maintenance plan is matched with the event progress correlation between the aforementioned security events to be processed, so as to ensure that the security operation and maintenance plan is set in accordance with the aforementioned event progress correlation.
[0015] A device for ensuring safe operation of the network in a strong electromagnetic environment, comprising: A data acquisition unit is used to acquire secure operation data of network devices; the secure operation data refers to the operation data of security events reported by the aforementioned network devices during operation; the security events include network attack events and / or strong electromagnetic interference events; The event marking unit is used to mark the safety operation data corresponding to the aforementioned safety event and to determine whether the safety event reflected by the aforementioned safety operation data is one or more; The incident handling unit is used to determine the correlation between the security operation data of different security events when the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, and to map the corresponding security operation and maintenance plan for execution, so as to ensure the safe operation of network equipment.
[0016] A system for ensuring network security operation in a strong electromagnetic environment includes: Network nodes are used to send and receive data; The information processing module is used to process strong electromagnetic interference data and network traffic data in environments with strong electromagnetic interference. System server, which connects network nodes and information processing modules; The system server is configured to: acquire security operation data of network devices; the security operation data refers to the operation data of security events reported by the aforementioned network devices during operation; the security events include network attack events and / or, strong electromagnetic interference events; mark the security operation data corresponding to the aforementioned security events, determine whether the security events reflected by the aforementioned security operation data are one or more; when the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, determine the correlation of event progress reflected by the security operation data between different security events, and map it to the corresponding security operation and maintenance plan for execution, so as to ensure the secure operation of network devices.
[0017] A computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the methods described above.
[0018] Based on the above advantages and positive effects, the advantages of this invention are: it can identify and mark the correlation between the progress of multiple security events, providing accurate guidance for the subsequent formulation of security operation and maintenance plans, thereby ensuring the safe operation of network devices. Attached Figure Description
[0019] Figure 1 A flowchart provided for an embodiment of the present invention.
[0020] Figure 2 This is a schematic diagram of the device provided in an embodiment of the present invention.
[0021] Figure 3 This is a schematic diagram of the system provided in an embodiment of the present invention.
[0022] Explanation of reference numerals in the attached figures: Device 200, data acquisition unit 201, event marking unit 202, event handling unit 203; System 300, network node 301, information processing module 302, system server 303. Detailed Implementation
[0023] The following detailed description, in conjunction with the accompanying drawings and specific embodiments, provides a method, apparatus, and system for ensuring network security operation in a strong electromagnetic environment, as disclosed in this invention. It should be noted that the technical features or combinations of technical features described in the following embodiments should not be considered isolated; they can be combined to achieve better technical effects. In the accompanying drawings of the following embodiments, the same reference numerals in each drawing represent the same features or components, which can be applied to different embodiments. Therefore, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0024] It should be noted that the structures, proportions, sizes, etc., illustrated in the accompanying drawings are merely for illustrative purposes and to aid those skilled in the art in understanding and reading the invention. They are not intended to limit the conditions under which the invention can be implemented. Any modifications to the structure, changes in proportions, or adjustments to size, provided they do not affect the effectiveness or purpose of the invention, should fall within the scope of the technical content disclosed in the invention. The scope of the preferred embodiments of the present invention includes other implementations, wherein functions may be performed not in the order stated or discussed, including substantially simultaneously or in reverse order, depending on the functions involved. This should be understood by those skilled in the art to which the embodiments of the present invention pertain.
[0025] Techniques, methods, and apparatus known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and apparatus should be considered part of the specification. In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values. Example
[0026] See Figure 1 The diagram shown is a flowchart provided by the present invention. The implementation steps S100 of the method are as follows: S101, obtain security operation data of network devices.
[0027] The network devices include, but are not limited to, at least one of the following: network traffic devices (e.g., routers, switches, etc.), network security devices (e.g., firewalls, intrusion detection systems, etc.), network management devices (e.g., network monitoring systems, traffic analyzers, etc.), storage network devices (e.g., storage area network switches, network-attached storage devices, etc.), load balancing devices (e.g., hardware load balancers, software load balancers, etc.), optimization and acceleration devices (e.g., WAN optimization devices, application delivery controllers, etc.), access devices (e.g., wireless access points, Ethernet access switches, etc.), network interface devices (e.g., network interface cards, fiber optic interface modules, etc.), wireless network devices (e.g., wireless access points, wireless controllers, etc.), industrial network devices (e.g., industrial Ethernet switches, industrial routers, etc.), and Internet of Things (IoT) devices (e.g., IoT gateways, IoT sensors, etc.).
[0028] The security operation data refers to the operation data of the aforementioned network devices that report security events during operation.
[0029] Specifically, the secure operation data includes, but is not limited to, at least one of the following: device configuration data (e.g., device configuration files, routing tables, firewall rules, and access control lists); performance monitoring data (e.g., CPU utilization, memory utilization, bandwidth utilization, network latency, and packet loss rate); network traffic data (e.g., network traffic source, network traffic destination, protocol type, and packet size); session connection data (e.g., active session information, active connection information, source IP address, destination IP address, port number, and protocol type); user activity data (e.g., user login records, user logout records, user operation history, and permission change records); access control data (e.g., access control rule execution status, access attempt records, and access denial logs); alarm event monitoring and response data (e.g., intrusion detection alarms, defense alarms, device failure alarms, performance alarms, and configuration change alarms); and log recording data (e.g., system logs, security logs, network logs, and application logs).
[0030] The technical terms used in the aforementioned network equipment and security operation data are all existing technologies in this field, and therefore will not be elaborated upon here.
[0031] It is worth noting that the security operation data is used to provide feedback on the operation data corresponding to security events during the operation of the aforementioned network devices. Specifically, the security operation data can reflect network attack situations (including but not limited to the scope of network attacks, involving devices, attack types, attack levels, etc.) and / or strong electromagnetic interference situations (including but not limited to the scope of strong electromagnetic interference, involving devices, strong electromagnetic interference types, strong electromagnetic interference levels, etc.).
[0032] In this embodiment, the security events include network attack events and / or strong electromagnetic interference events.
[0033] Specifically, when at least one network attack event and at least one strong electromagnetic interference event have a correlation in their event progression, the security events are combined to form a composite attack event.
[0034] S102, mark the safety operation data corresponding to the aforementioned safety event, and determine whether the safety event reflected by the aforementioned safety operation data is one or multiple.
[0035] S103, when the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, determine the correlation between the event progress reflected by the security operation data of different security events, and map it to the corresponding security operation and maintenance plan for execution, so as to ensure the safe operation of network equipment.
[0036] The complex network attack involving strong electromagnetic interference events in this embodiment is characterized by its complexity, synergistic effects, stealth, and wide-ranging impact.
[0037] Specifically, strong electromagnetic interference (EMI) and cyberattacks are two distinct attack methods. The former involves physical-level interference, while the latter attacks through network-level means. This diversity of attack methods increases the complexity of events, making it difficult for a single analysis method to comprehensively cover all threats. EMI and cyberattacks can complement each other; for example, EMI can be used to disable critical hardware, thus creating opportunities for cyberattacks. Conversely, cyberattacks can be used to shut down security systems, making EMI more effective. The involvement of both physical and network-level attacks means that in complex cyberattacks involving EMI events, the EMI itself may not be immediately detected, but it can pave the way for subsequent cyberattacks. Furthermore, complex cyberattacks involving EMI events not only affect network systems but may also damage physical equipment, resulting in a wider impact.
[0038] Based on this, it can be determined that when the aforementioned security incidents include at least one strong electromagnetic interference incident and at least one network attack incident, it is necessary to determine the correlation between the event progress reflected by the security operation data of different security incidents, and then through correlation analysis, accurately know the cause of the security incident and the equipment affected in the subsequent development, so as to provide a suitable security operation and maintenance solution.
[0039] As one of the preferred embodiments of this example, the marking includes step S110: S111, analyze the correlation between multiple safety operation data reflecting the progress of events.
[0040] The event progression correlation is used to reflect the order of occurrence of security events and / or the causal relationship in the progress of security events; wherein, the causal relationship in the progress of security events includes the correlation caused by multiple causes and one effect, multiple causes and multiple effects, one cause and one effect, and one cause and multiple effects during the progress of events.
[0041] S112, Based on the aforementioned event progression relationship, determine the order of occurrence among the aforementioned multiple safe operation data, and correspondingly determine the number of safe events to which the aforementioned safe operation data belongs.
[0042] When determining the order of occurrence of the aforementioned multiple safety operation data, it is preferable to sort them according to the generation time of the aforementioned safety operation data.
[0043] S113. Based on the aforementioned relationship of event progression, the security events are sequentially identified as the first security event, the second security event, ..., up to the Nth security event, where N is a positive integer.
[0044] In this context, the first security event is preferably configured as the initiating security event; each subsequent security event has an event progression relationship with the preceding security event, and the subsequent security events include security events that occur sequentially and security events that occur in parallel.
[0045] It is worth noting that a security incident may consist of a complete lifecycle comprised of multiple development stages, including but not limited to: reconnaissance, weaponization, delivery, utilization, installation, command and control, and action. Since these development stages are existing technology in the field, they will not be elaborated upon further here.
[0046] Specifically, the security event sequence identifier can identify in detail the development stages of the interconnection between previous and subsequent security events.
[0047] In the process of multiple security incidents occurring sequentially, while a previous security incident may be progressing to any stage of development, there is a possibility that a subsequent security incident may intervene. In this case, there may be a correlation in the progress of the previous security incident and the subsequent security incident, that is, an event progress correlation.
[0048] In the example: When a security incident involves at least one strong electromagnetic interference event and at least one network attack event, as an example and not a limitation, security incident 1 (SE1) is a strong electromagnetic interference attack. In the reconnaissance phase, the attacker surveys the target area to determine the layout and type of critical electronic equipment. The corresponding security operation data is shown by nearby surveillance cameras recording suspicious personnel loitering near the target area. In the weaponization phase, the attacker prepares high-power electromagnetic interference equipment and adjusts its frequency and power to target the equipment. The corresponding security operation data is shown by equipment manufacturing records and test logs. In the delivery phase, the attacker deploys the electromagnetic interference equipment near the target area to interfere with critical electronic equipment through radio waves. The corresponding security operation data is shown by electromagnetic spectrum monitoring in the target area showing abnormal electromagnetic activity. In the exploitation phase, the electromagnetic interference causes the target company's network equipment (such as routers and switches) to malfunction, resulting in network communication interruption. The corresponding security operation data is shown by network equipment logs showing abnormal restart and fault records.
[0049] During the same period, there was also Security Incident 2 (SE2), namely a cyberattack. In the reconnaissance phase, attackers exploited the chaos caused by network device failures to scan the target company's internal network, searching for vulnerable systems. The corresponding security data showed abnormal port scanning and probing activity in network traffic logs. In the weaponization phase, attackers developed or customized malware to exploit specific vulnerabilities in the target system. The corresponding security data showed malware creation and compilation records. In the delivery phase, attackers delivered malware via phishing emails or by exploiting system vulnerabilities. The corresponding security data showed suspicious email activity in mail server logs and abnormal file downloads and executions in system logs. In the exploitation phase… The malware executes on the target system, gaining system control privileges. The corresponding security data manifests as abnormal user activity and privilege escalation records in the target system's logs. During the installation phase, the malware installs a backdoor program on the target system for subsequent access. The corresponding security data manifests as abnormal installation records of new services and processes in the system logs. In the command and control phase, the malware establishes a connection with the attacker's command and control server. The corresponding security data manifests as abnormal external connections and data transmission records in the network traffic logs. In the action phase, the attacker steals sensitive data or damages the system through the backdoor program. The corresponding security data manifests as abnormal activity in file access records and data transmission logs.
[0050] Analysis reveals that in this example, the exploitation phase of SE1 and the reconnaissance phase of SE2 are related. The electromagnetic interference of SE1 causes network equipment failure and network communication interruption, creating an opportunity for the reconnaissance phase of SE2. There is a causal relationship between the two in the progression of the security event. The interference of SE1 temporarily disables network security measures, making it easier for attackers to scan the network. The exploitation phase of SE1 and the delivery phase of SE2 are also related. Given the chaos caused in SE1, attackers are more likely to successfully exploit system vulnerabilities or deliver phishing emails in SE2. There is a causal relationship between the two in the progression of the security event, that is, the interference of SE1 reduces the target system's defense capabilities and increases the success rate of SE2 delivery. The reconnaissance phase of SE2 and the weaponization phase of SE2 are also related. The scanning activities of SE2 collect vulnerability information of the target system, helping attackers to customize malware. There is a sequential relationship between the two in the progression of the security event. The results of the reconnaissance phase of SE2 are directly used in the weaponization phase.
[0051] Accordingly, in order to facilitate the management of multiple security events and to clearly understand from which specific development stage they are connected, it is preferable to configure timestamps, event identifiers, and association identifiers for each development stage of the aforementioned security events, so as to refine the security event sequence identification between the development stages of multiple security events.
[0052] Taking the previous example, Security Event 1 (SE1) is a strong electromagnetic interference attack, corresponding to the reconnaissance phase (SE1-R1), with a timestamp of 2025-10-20 09:00 and an event identifier of SE1-R1. Since the reconnaissance phase of Security Event 1 is the starting security event, its associated identifier is none. Furthermore, to facilitate understanding of this reconnaissance phase, corresponding descriptive identifiers can be configured, such as: Suspicious personnel loitering near the target area, and surveillance cameras recording their activities.
[0053] During the weaponization phase (SE1-W1), the timestamp is 2025-10-21 10:00, the event identifier is SE1-W1, the associated identifier is SE1-R1, and the corresponding description identifier is that the attacker is preparing high-power electromagnetic interference equipment.
[0054] During the delivery phase (SE1-D1), the timestamp is 2025-10-22 08:00, the event identifier is SE1-D1, the associated identifier is SE1-W1, and the corresponding description is that electromagnetic interference equipment is deployed near the target area.
[0055] During the utilization phase (SE1-E1), the timestamp is 2025-10-22 08:05, the event identifier is SE1-E1, the associated identifier is SE1-D1, and the corresponding description is that electromagnetic interference caused network equipment failure and network communication interruption.
[0056] Security Incident 2 (SE2) is a cyberattack. During the reconnaissance phase (SE2-R1), the timestamp is 2025-10-22 08:10, the event identifier is SE2-R1, the associated identifier is SE1-E1, and the description indicates that the attacker exploited the chaos during a network device failure to scan the target company's internal network. During the weaponization phase (SE2-W1), the timestamp is 2025-10-22 09:00, the event identifier is SE2-W1, the associated identifier is SE2-R1, and the description indicates that the attacker developed malware to exploit vulnerabilities in the target system. During the delivery phase (SE2-D1), the timestamp is 2025-10-22 10:00, the event identifier is SE2-D1, the associated identifier is SE2-W1, and the description indicates that the attacker delivered malware via phishing emails or exploiting system vulnerabilities. During the exploitation phase (SE2-E1), the timestamp is 2025-10-22. At 10:05, the event identifier is SE2-E1, the associated identifier is SE2-D1, and the corresponding description indicates that malware executes on the target system and gains system control privileges. In the installation phase (SE2-I1), the timestamp is 2025-10-22 10:10, the event identifier is SE2-I1, the associated identifier is SE2-E1, and the corresponding description indicates that malware installs a backdoor program on the target system. In the command and control phase (SE2-C1), the timestamp is 2025-10-22 10:15, the event identifier is SE2-C1, the associated identifier is SE2-I1, and the corresponding description indicates that malware establishes a connection with the command and control server. In the action phase (SE2-A1), the timestamp is 2025-10-22 10:30, the event identifier is SE2-A1, the associated identifier is SE2-C1, and the corresponding description indicates that the attacker steals data or damages the system through a backdoor program.
[0057] Therefore, refining the sequence identifiers of security events across multiple security event development stages can help managers effectively understand the relationships between these stages and also help to trace the attacker's actions within complex attack chains.
[0058] S114 corresponds to the aforementioned security event sequence identifier, and matches the aforementioned security operation data with the corresponding security event sequence identifier.
[0059] Preferably, after determining the correlation of the aforementioned security events, the cause-oriented attributes of the corresponding security events are determined for the aforementioned security operation data; the cause-oriented attributes include device software causing device software problems, device software causing device hardware problems, device hardware causing device software problems, and / or, device hardware causing device hardware problems.
[0060] Using the previous example, after determining the correlation of the security events' progress, the cause-oriented attributes of the corresponding security events can be determined based on the security operation data. This includes situations where device software causes device hardware problems, such as EMI interference leading to firewall hardware failure and the firewall firmware failing to boot properly; and situations where device hardware causes device software problems, such as EMI interference affecting switch hardware causing the switch operating system to crash or restart.
[0061] Preferably, after determining the cause-oriented attribute of the corresponding security event, the method further includes step S120: S121, obtain the cause-oriented attributes of each security event under different event progress relationships.
[0062] S122, for the selected security event to be processed, extract the corresponding cause-oriented attributes and the security operation data corresponding to the aforementioned security event to be processed, so as to match the security operation and maintenance plan.
[0063] In this embodiment, the security operation and maintenance scheme includes both hardware security operation and maintenance scheme and software security operation and maintenance scheme, thereby helping to comprehensively handle complex network attacks involving strong electromagnetic interference events.
[0064] Furthermore, it is worth noting that in practical applications, considering factors such as event priority, allocation of security resources, response efficiency of security maintenance, and cost of security maintenance, administrators or systems can select which security events to handle in order to achieve better security maintenance results.
[0065] Specifically, the security events to be processed are determined based on the aforementioned event progress correlation; the configuration of the security operation and maintenance plan matches the event progress correlation between the aforementioned security events to be processed, so as to ensure that the security operation and maintenance plan is set in accordance with the aforementioned event progress correlation.
[0066] As an example, and not a limitation, taking the previous example, the security events to be processed are determined based on the aforementioned event progression relationships. Multiple relationships exist between different stages of SE1 and SE2, including causal and sequential relationships. Specifically, the exploitation stage of SE1, the reconnaissance stage of SE2, the delivery stage of SE2, and the weaponization stage of SE2 are preferred as security events to be processed, in order to effectively counter different attacker methods through a multi-layered protection strategy. Furthermore, a security operation and maintenance plan is configured corresponding to these selected security events to be processed.
[0067] The configuration of the security operation and maintenance scheme is adapted to the selection of security events to be handled. The configuration of the security operation and maintenance scheme can be determined based on existing network security protection measures, so it will not be elaborated on here.
[0068] Among these methods, identifying security events to be processed based on the correlation of event progression and configuring security operation and maintenance solutions that match these events has the following advantages: it can accurately pinpoint the root causes and key issues of security events; when the security operation and maintenance solution matches the correlation of event progression, it can identify and respond to security events more quickly, reducing response time; furthermore, based on the correlation of event progression, it can identify potential security threats and vulnerabilities earlier and take preventive measures in advance; and thirdly, based on the correlation of security events to be processed, it can allocate limited security operation and maintenance resources (such as manpower, time, and technology) more rationally, improve the overall security operation and maintenance efficiency, and reduce the overall security risk of the network system.
[0069] Other technical features are described in the previous embodiments and will not be repeated here.
[0070] In addition, see Figure 2 As shown, the present invention also provides an embodiment of a device 200 for ensuring network security operation in a strong electromagnetic environment, comprising: A data acquisition unit is used to acquire secure operation data of network devices; the secure operation data refers to the operation data of security events reported by the aforementioned network devices during operation; the security events include network attack events and / or strong electromagnetic interference events; The event marking unit is used to mark the safety operation data corresponding to the aforementioned safety event and to determine whether the safety event reflected by the aforementioned safety operation data is one or more; The incident handling unit is used to determine the correlation between the security operation data of different security events when the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, and to map the corresponding security operation and maintenance plan for execution, so as to ensure the safe operation of network equipment.
[0071] Other technical features are described in the previous embodiments and will not be repeated here.
[0072] In addition, see Figure 3 As shown, the present invention also provides an embodiment of a system 300 for ensuring network security operation in a strong electromagnetic environment, comprising: Network node 301 is used for sending and receiving data.
[0073] In practice, the network node can be configured as any of the network devices in this embodiment.
[0074] The information processing module 302 is used to process strong electromagnetic interference data and network traffic data in a strong electromagnetic interference environment.
[0075] System server 303, which is connected to network node 301 and information processing module 302.
[0076] The system server 303 is configured to: acquire security operation data of network devices; the security operation data refers to the operation data of security events fed back by the aforementioned network devices during operation; the security events include network attack events and / or, strong electromagnetic interference events; mark the security operation data corresponding to the aforementioned security events, determine whether the security events reflected by the aforementioned security operation data are one or more; when the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, determine the correlation of event progress reflected by the security operation data between different security events, and map it to the corresponding security operation and maintenance plan for execution, so as to ensure the secure operation of network devices.
[0077] Other technical features are described in the previous embodiments and will not be repeated here.
[0078] Furthermore, embodiments of the present invention also provide a computer-readable storage medium storing a program for use in the aforementioned system for ensuring network security operation in a strong electromagnetic environment. When the program is executed by a processor, it can implement the steps of the method for ensuring network security operation in a strong electromagnetic environment described above.
[0079] Other technical features are described in the previous embodiments and will not be repeated here.
[0080] In the foregoing description, within the scope of this disclosure, components may be selectively and operationally incorporated in any number. Furthermore, terms such as “comprising,” “encompassing,” and “having” should be interpreted by default as inclusive or open-ended, rather than exclusive or closed, unless explicitly defined as such. All technical, scientific, or other terms shall be interpreted as understood by one of those skilled in the art, unless explicitly defined as such. Public terms found in dictionaries should not be interpreted in a too idealistic or impractical manner in the context of the relevant technical documentation, unless explicitly defined as such in this disclosure.
[0081] While exemplary aspects of this disclosure have been described for illustrative purposes, those skilled in the art will recognize that the foregoing description is merely a description of preferred embodiments of the invention and is not intended to limit the scope of the invention in any way. The scope of the preferred embodiments of the invention includes other implementations in which functions may be performed in a different order than those described or discussed. Any modifications or alterations made by those skilled in the art based on the foregoing disclosure are within the scope of the claims.
Claims
1. A method for ensuring network security operation in a strong electromagnetic environment, characterized in that, include: Obtain secure operational data from network devices; The secure operation data refers to the operational data of security events reported by the aforementioned network devices during operation; the security events include network attack events and / or, strong electromagnetic interference events. Mark the safety operation data corresponding to the aforementioned safety events, and determine whether the aforementioned safety operation data reflects one or more safety events; When the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, the correlation between the event progress reflected by the security operation data of different security events is determined and mapped to the corresponding security operation and maintenance plan for execution, so as to ensure the safe operation of network equipment.
2. The method according to claim 1, characterized in that, The network devices include at least one of the following: network traffic devices, network security devices, network management devices, storage network devices, load balancing devices, optimization and acceleration devices, access devices, network interface devices, wireless network devices, industrial network devices, and Internet of Things devices. The secure operation data includes at least one of the following: device configuration data, performance monitoring data, network traffic data, session connection data, user activity data, access control data, alarm event monitoring and response data, and log recording data.
3. The method according to claim 1, characterized in that, When at least one network attack event and at least one strong electromagnetic interference event are correlated in terms of their progress, the security events are combined to form a composite attack event.
4. The method according to claim 1, characterized in that, The marker includes: Analyze the correlations between various safety operation data reflecting event progress; Based on the aforementioned relationship between the events, the order of occurrence of the aforementioned multiple safe operation data is determined, and the number of safe events to which the aforementioned safe operation data belongs is determined accordingly. Based on the aforementioned relationship between events, the security events are sequentially identified as the first security event, the second security event, ..., up to the Nth security event, where N is a positive integer; Corresponding to the aforementioned security event sequence identifier, the corresponding security event sequence identifier is matched to the aforementioned safe operation data.
5. The method according to claim 4, characterized in that, After determining the correlation of the aforementioned security events' progress, the cause-oriented attributes of the corresponding security events are determined for the aforementioned security operation data; the cause-oriented attributes include device software causing device software problems, device software causing device hardware problems, device hardware causing device software problems, and / or, device hardware causing device hardware problems.
6. The method according to claim 5, characterized in that, After determining the cause-oriented attributes of the corresponding security event, the following is also included: Obtain the cause-oriented attributes of each security event under the correlation of different event progress; For the selected security events to be processed, extract the corresponding cause-oriented attributes and the security operation data corresponding to the aforementioned security events to match the security operation and maintenance plan.
7. The method according to claim 6, characterized in that, The security events to be processed are determined based on the aforementioned event progression relationships; The configuration of the security operation and maintenance plan is matched with the event progress correlation between the aforementioned security events to be processed, so as to ensure that the security operation and maintenance plan is set in accordance with the aforementioned event progress correlation.
8. An apparatus for ensuring safe operation of the network in a strong electromagnetic environment according to any one of claims 1-7, characterized in that... include: The data acquisition unit is used to acquire security operation data of network devices; The secure operation data refers to the operational data of security events reported by the aforementioned network devices during operation; the security events include network attack events and / or, strong electromagnetic interference events. The event marking unit is used to mark the safety operation data corresponding to the aforementioned safety event and to determine whether the safety event reflected by the aforementioned safety operation data is one or more; The incident handling unit is used to determine the correlation between the security operation data of different security events when the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, and to map the corresponding security operation and maintenance plan for execution, so as to ensure the safe operation of network equipment.
9. A system for ensuring safe operation of the network in a strong electromagnetic environment according to any one of claims 1-7, characterized in that... include: Network nodes are used to send and receive data; The information processing module is used to process strong electromagnetic interference data and network traffic data in environments with strong electromagnetic interference. System server, which connects network nodes and information processing modules; The system server is configured to: acquire security operation data of network devices; the security operation data refers to the operation data of security events reported by the aforementioned network devices during operation; the security events include network attack events and / or strong electromagnetic interference events; mark the security operation data corresponding to the aforementioned security events, determine whether the security events reflected by the aforementioned security operation data are one or more; when the aforementioned security events include at least one strong electromagnetic interference event and at least one network attack event, determine the correlation of event progress reflected by the security operation data between different security events, and map it to the corresponding security operation and maintenance plan for execution, so as to ensure the secure operation of network devices.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-7.