Network security situation awareness method based on artificial intelligence
By real-time monitoring and quantitative calculation of network communication behavior, host operating status and topology, a risk potential energy index and an attack chain dynamic coupling index are constructed. This solves the problem of insufficient comprehensive quantitative analysis of network security protection in existing technologies, realizes forward-looking early warning and dynamic defense of attack chains, and improves the adaptive defense capability of network systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHENGDU RUIDIOU TECH CO LTD
- Filing Date
- 2026-03-09
- Publication Date
- 2026-04-14
AI Technical Summary
Existing network security protection technologies lack the ability to comprehensively and quantitatively analyze the overall network security situation, making it difficult to reflect the propagation trend and coupling relationship of attacks in the network topology, unable to proactively assess the risks of potential attack chains, and lacking a dynamic feedback mechanism, resulting in a lag in risk response.
By real-time monitoring of network communication behavior, host operating status, network security threat situation and topology, relevant data are collected and quantitatively calculated to construct risk potential energy index, attack chain dynamic coupling index and risk propagation convergence entropy index, forming a dynamic closed-loop control mechanism to achieve multi-factor coupled quantitative analysis of network risk status and forward-looking early warning of attack chains.
It improves the accuracy and scientific nature of risk identification, enabling dynamic identification of attack chain formation risks and lateral spread risks, thereby enhancing the adaptive defense capabilities and overall security stability of the network system.
Smart Images

Figure CN121864489A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network security situation awareness method based on artificial intelligence. Background Technology
[0002] With the rapid development of information technology and the widespread application of cloud computing, big data, the Internet of Things, and the Industrial Internet, network systems are constantly expanding in scale, becoming increasingly complex in structure, and experiencing a continuous increase in the frequency of business interactions. Cyberspace has become a crucial supporting environment for the operation of critical infrastructure. Against this backdrop, network attack methods are gradually showing trends towards automation, concealment, persistence, and chain-like penetration. Traditional security defense systems centered on single-point protection are no longer sufficient to meet the security needs of dynamic and complex network environments.
[0003] Most existing network security protection technologies employ rule-based intrusion detection systems, firewall access control mechanisms, and vulnerability scanning and assessment tools to identify and intercept known attack characteristics or abnormal behaviors. However, these methods typically rely on static rule bases or single-dimensional indicators for judgment, lacking the ability to comprehensively and quantitatively analyze the overall network security posture. They are unable to reflect the propagation trends and coupling relationships of attacks within the network topology and cannot proactively assess the risks of potential attack chains.
[0004] Furthermore, while some security management platforms in existing technologies have introduced risk scoring models or threat level assessment mechanisms, most only perform isolated calculations of risk for single nodes, lacking correlation analysis of risk propagation paths between multiple nodes, failing to establish models of the transition probability relationships between attack stages, and failing to dynamically assess the concentration of attack paths. Therefore, when attacks move laterally or spread through multiple paths within the network, existing technologies struggle to promptly identify attack chain convergence trends and key control nodes, resulting in delayed risk response and a lack of targeted defense strategies.
[0005] Furthermore, existing risk assessment methods typically lack closed-loop control mechanisms, with risk detection, risk assessment, and defense execution being isolated from each other. They fail to form a dynamic feedback system from situational awareness to strategy execution and then to state reconstruction, making it difficult to achieve continuous optimization and adaptive control of the cybersecurity situation. Summary of the Invention
[0006] The purpose of this invention is to provide an artificial intelligence-based network security situation awareness method to solve the problems mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides the following technical solution:
[0008] An artificial intelligence-based method for cybersecurity situational awareness includes the following steps:
[0009] Step 1: By real-time monitoring of network communication behavior, host operating status, network security threat situation, and the relationship between network asset security status and topology, traffic characteristic data, abnormal host behavior data, threat alarm data, and vulnerability and topology data are collected respectively.
[0010] Step 2: Based on threat alert data, abnormal host behavior data, vulnerability and topology data, and traffic characteristic data, perform quantitative calculations on threat strength, abnormal behavior degree, vulnerability risk exposure level, and abnormal traffic activity to obtain threat strength parameters, abnormal behavior rate parameters, vulnerability exposure parameters, and abnormal traffic density parameters.
[0011] Step 3: Calculate the risk potential index and compare it with the risk potential threshold to determine whether the current network risk status is qualified. If it is not qualified, an abnormal risk tracing strategy is given.
[0012] Step 4: Calculate the attack chain dynamic coupling index and compare it with the attack chain dynamic coupling threshold to determine whether the current network attack chain status is qualified. If it is not qualified, an attack chain blocking strategy is applied.
[0013] Step 5: Calculate the risk propagation convergence entropy index and compare it with the risk propagation convergence entropy threshold to determine whether there is a risk of concentrated penetration attack on the network. If so, implement concentrated penetration blocking and critical path hardening strategies to form a dynamic closed-loop control mechanism.
[0014] Further, step one includes:
[0015] S11. Real-time monitoring of network communication behavior is carried out by installing deep packet inspection equipment at the network boundary and deploying traffic collection probes at the mirror port of the switch to collect traffic characteristic data, including source IP address, destination IP address, session duration, number of data packets and abnormal traffic identification data.
[0016] S12. Monitor the host's operating status in real time. By installing a host security agent program on the host terminal and combining it with a centralized log collection method, collect abnormal host behavior data, including the number of abnormal behavior records, the number of privilege escalation events, the number of abnormal process startups, and the number of access control change records.
[0017] S13. Conduct real-time monitoring of network security threat situation, and collect threat alarm data by deploying intrusion detection equipment and firewall log collection equipment, including threat level value, threat occurrence frequency, threat type identifier and alarm duration data;
[0018] S14. Monitor the security status and structural relationships of network assets in real time. By using vulnerability scanning tools and automatic network topology discovery methods, collect vulnerability and topology data, including vulnerability risk scores, number of vulnerabilities, vulnerability level, vulnerability impact range, as well as shortest path distance between nodes, node connectivity, and node hierarchical position data.
[0019] Furthermore, step two includes:
[0020] S21. Based on threat level values, threat occurrence frequency, threat type identifiers, and alarm duration data, a weighted statistical analysis method and a time decay processing algorithm are used to perform intensity assessment and time dimension correction processing on different threat types to obtain threat intensity parameters for each type of threat.
[0021] S22. Based on the data of the number of abnormal behavior records, the number of privilege escalation events, the number of abnormal process startups, and the number of access control change records, the behavior frequency statistical analysis method and the sliding time window aggregation algorithm are used to perform merge statistics and abnormal density analysis on abnormal behaviors within a unit of time to obtain the behavior abnormality rate parameter.
[0022] S23. Based on vulnerability risk scores, number of vulnerabilities, vulnerability level, vulnerability impact range, as well as shortest path distance between nodes, node connectivity, and node hierarchical position data, a risk weighted overlay analysis method and an impact range mapping algorithm are used to comprehensively assess vulnerability risk and obtain vulnerability exposure parameters.
[0023] S24. Based on the source IP address, destination IP address, session duration, number of data packets, and abnormal traffic identification data, the abnormal traffic activity level within a unit of time is calculated and abnormal marking is filtered using traffic density statistics and time normalization processing techniques to obtain abnormal traffic density parameters.
[0024] Furthermore, step three includes:
[0025] S31. By extracting the behavior anomaly rate parameter, vulnerability exposure parameter, and traffic anomaly density parameter of the i-th node, and combining the threat intensity parameter of the k-th type of threat of the i-th node and the shortest path distance between the i-th node and the k-th type of threat source node, after dimensionless processing, the risk potential energy index is calculated and obtained.
[0026] Furthermore, step three also includes:
[0027] S32. By setting a preset risk potential threshold and comparing the risk potential index with the risk potential threshold, the first assessment result is obtained, including:
[0028] When the risk potential index is less than or equal to the risk potential threshold, it indicates that the current network risk status is acceptable, the network is in a controllable operating state, there is no risk of attack propagation, and continuous monitoring is required.
[0029] When the risk potential energy index exceeds the risk potential energy threshold, it indicates that the current network risk status is unqualified, with potential attack spread risks or security loss of control risks. This triggers the first early warning command and generates the first strategy: Using a risk source location algorithm and path reverse tracing analysis method, the contribution values of various threats involved in the risk potential energy calculation are decomposed and calculated to identify the abnormal risk threat categories and corresponding critical abnormal risk nodes that contribute the most to the risk potential energy index value. Based on the contribution ranking results, the abnormal risk threat categories are prioritized, generating a list of abnormal risk threat categories. Topological reverse tracing analysis is then performed on the propagation paths from threat source nodes to target nodes to generate a set of abnormal risk propagation paths. Based on the contribution ratio of each node in the risk potential energy index, the impact degree of abnormal risks is ranked, generating an abnormal risk contribution weight ranking result and a list of nodes to be prioritized for handling. The list of abnormal risk threat categories, the set of abnormal risk propagation paths, the abnormal risk contribution weight ranking result, and the list of nodes to be prioritized for handling are then structured and encoded to form a set of structured abnormal risk situation vectors, and the attack chain coupling analysis trigger mechanism is initiated.
[0030] Furthermore, step four includes:
[0031] S41. Initiate the attack chain coupling analysis trigger mechanism. Based on the structured anomaly risk situation vector set, use the path association modeling method and directed graph construction technology to perform stage division and sequential association analysis on the anomaly risk propagation path set, and construct the attack stage state set.
[0032] S42. Based on the set of abnormal risk propagation paths and the list of abnormal risk threat categories, the phase adjacency statistical method and the transfer relationship normalization calculation method are used to statistically analyze the association frequency between adjacent attack phases in the attack phase state set and obtain the transfer probability parameters between adjacent phases.
[0033] S43. Based on the difference in formation time of each path in the abnormal risk propagation path set, the path time interval calculation method is used to calculate the duration interval between adjacent attack phases and obtain the phase duration parameter.
[0034] S44. Based on the risk potential energy index, the average calculation method of the node set in the list of nodes in the abnormal risk priority handling node is adopted to statistically process the risk potential energy value of the nodes participating in the attack chain and obtain the average potential energy parameter.
[0035] Furthermore, step four also includes:
[0036] S45. After dimensionless processing of the obtained transition probability parameters, phase duration parameters, and average potential energy parameters between adjacent phases, the attack chain dynamic coupling index is calculated.
[0037] Furthermore, step four also includes:
[0038] S46. By setting a preset attack chain dynamic coupling threshold and comparing the attack chain dynamic coupling index with the attack chain dynamic coupling threshold, the second evaluation result is obtained, including:
[0039] When the attack chain dynamic coupling index is less than or equal to the attack chain dynamic coupling threshold, it indicates that the current network attack chain status is qualified and there is no risk of forming a complete attack chain. Continuous monitoring is required.
[0040] When the attack chain dynamic coupling index exceeds the attack chain dynamic coupling threshold, it indicates that the current network attack chain status is unqualified, posing a risk of attack chain formation or lateral propagation. This triggers a second warning instruction and generates a second strategy: employing a lateral movement behavior recognition algorithm to enhance monitoring of communication behavior between attack chain-related nodes and initiating a lateral movement monitoring mode; using deep packet inspection technology to perform deep protocol parsing and abnormal command identification of network traffic between attack chain-related nodes, conducting deep traffic auditing; employing a dynamic access control adjustment method to implement access restrictions and network isolation for attack chain-related nodes, blocking abnormal propagation paths; and performing structured encapsulation of the attack chain-related node set to generate an attack chain control node set, and initiating an adaptive defense optimization execution mechanism.
[0041] Furthermore, step five includes:
[0042] S51. Activate the adaptive defense optimization execution mechanism. Based on the attack chain control node set and the structured abnormal risk situation vector set, use the abnormal traffic ratio statistical method and the ratio normalization calculation method to statistically and normalize the abnormal traffic ratio of each node in the attack chain control node set to obtain the attack path probability parameters.
[0043] S52. Using the obtained attack path probability parameters, the square concentration method is used to statistically analyze the concentration of abnormal traffic distribution in the attack chain control node set, and calculate the risk propagation convergence entropy index.
[0044] Furthermore, step five also includes:
[0045] S53. By setting a preset risk propagation convergence entropy threshold and comparing the risk propagation convergence entropy index with the risk propagation convergence entropy threshold, the third evaluation results are obtained, including:
[0046] When the risk propagation convergence entropy index is greater than or equal to the risk propagation convergence entropy threshold, it indicates that the abnormal traffic distribution in the current attack chain control node set is dispersed, the attack propagation path is in a discrete diffusion state, the network as a whole is within the controllable range, there is no risk of concentrated penetration attack, and continuous monitoring is required.
[0047] When the risk propagation convergence entropy index is less than the risk propagation convergence entropy threshold, it indicates that the abnormal traffic distribution in the current attack chain control node set is concentrated, the attack propagation path has converged, and there is a risk of concentrated penetration attack or critical path breach. This triggers a third warning instruction and generates a third strategy: employing a critical convergence path port blocking method to close ports or restrict access on propagation paths with highly concentrated abnormal traffic; employing multi-factor authentication enhanced control technology to enforce multi-factor authentication policies on critical nodes in the attack chain control node set; employing a full network traffic mirroring analysis method to mirror and deeply audit the relevant traffic in the attack chain control node set; and employing a dynamic access control adjustment method to implement permission contraction and network isolation control on nodes with concentrated abnormal traffic, blocking concentrated penetration paths.
[0048] S54. Synchronously update the execution results of the third strategy to the network operating environment, and re-enter step one for continuous monitoring to form a dynamic closed-loop control mechanism for network security situation.
[0049] Compared with the prior art, the beneficial effects of the present invention are:
[0050] This invention unifies and integrates network communication behavior, abnormal host behavior, threat alarm information, and vulnerability and topology data to construct threat intensity parameters, abnormal behavior rate parameters, vulnerability exposure parameters, and abnormal traffic density parameters. Furthermore, it calculates the risk potential index to achieve multi-factor coupled quantitative analysis of network risk status. This overcomes the problems of strong subjectivity and high misjudgment rate of traditional single indicators or experience-based judgment methods, and improves the accuracy and scientific nature of risk identification.
[0051] This invention also constructs a set of attack phase states, combines phase transition probability, phase duration and average risk potential energy parameters, and calculates the attack chain dynamic coupling index. This enables dynamic identification of the correlation strength and evolution trend between attack phases, early detection of attack chain formation risk and lateral spread risk, and structured identification and forward-looking early warning of complex multi-stage attacks, thereby improving the defense capability against advanced persistent threats (APTs) and lateral movement behavior.
[0052] This invention also calculates the risk propagation convergence entropy index by performing squared concentration on the concentration of abnormal traffic distribution in the attack chain control node set. This can identify whether the attack path has converged or broken through in a concentrated manner, and automatically trigger strategies such as critical path blocking, multi-factor authentication enhancement, traffic mirroring auditing, and dynamic access control when the risk reaches the threshold. At the same time, the execution results are fed back to the monitoring module, forming a continuously iterative dynamic closed-loop control mechanism, thereby improving the adaptive defense capability and overall security stability of the network system. Attached Figure Description
[0053] Figure 1 This is a schematic diagram illustrating the overall execution of the method of the present invention;
[0054] Figure 2 This is a schematic diagram of the overall method flow of the present invention. Detailed Implementation
[0055] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0056] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0057] Example 1
[0058] Please see Figures 1 to 2 This invention provides a technical solution: a network security situation awareness method based on artificial intelligence, the specific steps of which include:
[0059] Step 1: By real-time monitoring of network communication behavior, host operating status, network security threat situation, and the relationship between network asset security status and topology, traffic characteristic data, abnormal host behavior data, threat alarm data, and vulnerability and topology data are collected respectively.
[0060] Step 2: Based on threat alert data, abnormal host behavior data, vulnerability and topology data, and traffic characteristic data, perform quantitative calculations on threat strength, abnormal behavior degree, vulnerability risk exposure level, and abnormal traffic activity to obtain threat strength parameters, abnormal behavior rate parameters, vulnerability exposure parameters, and abnormal traffic density parameters.
[0061] Step 3: Calculate the risk potential index and compare it with the risk potential threshold to determine whether the current network risk status is qualified. If it is not qualified, an abnormal risk tracing strategy is given.
[0062] Step 4: Calculate the attack chain dynamic coupling index and compare it with the attack chain dynamic coupling threshold to determine whether the current network attack chain status is qualified. If it is not qualified, an attack chain blocking strategy is applied.
[0063] Step 5: Calculate the risk propagation convergence entropy index and compare it with the risk propagation convergence entropy threshold to determine whether there is a risk of concentrated penetration attack on the network. If so, implement concentrated penetration blocking and critical path hardening strategies to form a dynamic closed-loop control mechanism.
[0064] Figure 1 The left side illustrates the real-time monitoring scenario described in Step 1. The interconnected nodes and flow lines in the diagram represent the collected traffic characteristic data, host abnormal behavior data, threat alarm data, and asset topology data. The path evolution trend shown in the diagram reflects the process of identifying the attack chain status in Step 4; the visual characteristics of the path convergence at the core node correspond to the technical logic of identifying concentrated penetration risks through risk propagation convergence entropy in Step 5.
[0065] "Multi-source situational data fusion monitoring" corresponds to step one, namely the synchronous collection of multi-dimensional raw data.
[0066] "Multi-dimensional risk parameter coupling quantification," corresponding to step two, addresses the lack of overall quantitative analysis in single-point protection mentioned in the background technology by calculating four core parameters (threat strength, abnormal behavior rate, vulnerability exposure, and abnormal traffic density). "Attack chain evolution and potential energy assessment," corresponding to steps three and four, achieves dynamic analysis and forward-looking assessment of attack evolution trends through the risk potential energy index and the attack chain dynamic coupling index. "Path convergence identification and closed-loop defense," corresponding to step five, identifies critical path breach risks through the convergence entropy index and generates hardening instructions, forming a dynamic closed-loop control mechanism from perception to defense to feedback.
[0067] In this embodiment, a three-level progressive evaluation mechanism is constructed, consisting of "risk potential energy index - attack chain dynamic coupling index - risk propagation convergence entropy index". This mechanism enables a layered and linked judgment method, from single-node anomaly identification to attack chain structure evolution analysis and propagation path convergence determination. This upgrades network security posture from static detection to dynamic evolution assessment and adaptive closed-loop defense control. It can not only identify potential attack spread trends in advance, but also implement precise blocking before the attack chain forms and penetrates in a concentrated manner, thereby significantly improving the overall network risk prediction capability, attack chain perception capability, and proactive defense capability.
[0068] Example 2
[0069] Please see Figures 1 to 2 In this embodiment, as explained in Embodiment 1, specifically, step one includes:
[0070] S11. Real-time monitoring of network communication behavior is carried out by installing deep packet inspection equipment at the network boundary and deploying traffic collection probes at the mirror port of the switch to collect traffic characteristic data, including source IP address, destination IP address, session duration, number of data packets and abnormal traffic identification data.
[0071] S12. Monitor the host's operating status in real time. By installing a host security agent program on the host terminal and combining it with a centralized log collection method, collect abnormal host behavior data, including the number of abnormal behavior records, the number of privilege escalation events, the number of abnormal process startups, and the number of access control change records.
[0072] S13. Conduct real-time monitoring of network security threat situation, and collect threat alarm data by deploying intrusion detection equipment and firewall log collection equipment, including threat level value, threat occurrence frequency, threat type identifier and alarm duration data;
[0073] S14. Real-time monitoring of network asset security status and structural relationships. By using vulnerability scanning tools and automatic network topology discovery methods, vulnerability and topology data are collected, including vulnerability risk scores, number of vulnerabilities, vulnerability level, vulnerability impact range, and shortest path distance between nodes, denoted as d, node connectivity and node hierarchical position data.
[0074] In this embodiment, by synchronously and in real-time monitoring and multi-source data collection of network communication behavior, host operating status, threat alarm information, and the relationship between vulnerabilities and topology, this invention achieves full coverage of the four dimensions of "traffic layer - host layer - threat layer - structure layer", constructs a unified data foundation and correlation analysis framework, and avoids the problems of misjudgment and omission caused by data fragmentation, information silos and single-point monitoring in traditional security systems, thereby significantly improving the comprehensiveness, correlation and accuracy of network security situation awareness.
[0075] Example 3
[0076] Please see Figures 1 to 2 In the explanation of Example 2, this embodiment specifically includes the following steps:
[0077] S21. Based on threat level values, threat occurrence frequency, threat type identifiers, and alarm duration data, a weighted statistical analysis method and a time decay processing algorithm are used to perform intensity assessment and time dimension correction processing on different threat types to obtain threat intensity parameters for each type of threat, denoted as R.
[0078] S22. Based on the data of the number of abnormal behavior records, the number of privilege escalation events, the number of abnormal process startups, and the number of access control change records, the behavior frequency statistical analysis method and the sliding time window aggregation algorithm are used to perform merge statistics and abnormal density analysis on abnormal behaviors within a unit time period to obtain the behavior abnormality rate parameter, denoted as A.
[0079] S23. Based on vulnerability risk scores, number of vulnerabilities, vulnerability level, vulnerability impact range, shortest path distance d between nodes, node connectivity, and node hierarchical position data, a risk weighted superposition analysis method and an impact range mapping algorithm are used to comprehensively assess vulnerability risk and obtain vulnerability exposure parameters, denoted as E.
[0080] S24. Based on the source IP address, destination IP address, session duration, number of data packets, and abnormal traffic identification data, the abnormal traffic activity level within a unit of time is calculated and abnormal marking is filtered using traffic density statistics and time normalization processing techniques to obtain the abnormal traffic density parameter, denoted as D.
[0081] In this embodiment, by performing weighted statistical analysis, time decay correction, sliding window aggregation, and risk overlay mapping on threat intensity, abnormal behavior, vulnerability exposure level, and abnormal traffic activity, this invention transforms the original heterogeneous security data into structured risk parameters of a unified scale. This achieves standardized expression and computable fusion of multi-dimensional security elements, significantly improving the objectivity, timeliness, and comparability of risk assessment, and providing stable and accurate data support for subsequent risk potential index and attack chain coupling analysis.
[0082] Example 4
[0083] Please see Figures 1 to 2 In the explanation of Example 3, this embodiment specifically includes the following steps:
[0084] S31. Extract the behavior anomaly rate parameter of the i-th node, denoted as... The vulnerability exposure parameter is denoted as... and flow anomaly density parameter, denoted as Combining the threat strength parameter of the k-th type of threat at the i-th node, denoted as... The shortest path distance between the i-th node and the k-th threat source node is denoted as . After dimensionless processing, the risk potential energy index, denoted as FSZ, is calculated and obtained, as shown in the following formula:
[0085]
[0086] In the formula, m represents the total number of threat types. Let w1, w2, and w3 represent the weight of the k-th threat class, and w1, w2, and w3 represent the weight coefficients.
[0087] Threat weight of type k The acquisition method is as follows: By statistically analyzing historical security incident data, multi-type attack sample libraries, and real network intrusion cases, the frequency of occurrence, degree of damage, and contribution ratio of propagation ability of different threat types in successful intrusion events are calculated; combined with the threat level assessment results, the success rate of threat exploitation vulnerabilities, and lateral movement capabilities, the risk amplification effect of various threats is weighted and evaluated.
[0088] : Characterizes the degree of impact of abnormal node operation status on risk potential; abnormal behavior is usually the immediate external manifestation of attack activities, which can reflect risk signals such as abuse of privileges and abnormal process initiation, but it may be affected by business fluctuations and has the second highest weight, used to reflect the risk contribution of the node's "real-time abnormal status".
[0089] The inherent security vulnerabilities of a node have the highest weighting on the impact of risk potential. Vulnerability exposure determines the probability of successful attacks and the ability to spread continuously, which is the fundamental condition for risk formation. Therefore, it is given the highest weighting as a core structural risk factor to reflect the basic role of "potential for exploitation".
[0090] : Characterizes the impact of abnormal communication activity on risk potential; traffic anomalies reflect attack propagation behavior, but are easily affected by normal business peaks, and have a medium weight, used to reflect the level of risk propagation activity;
[0091] By extracting the behavior anomaly rate parameter of the i-th node Vulnerability exposure parameters and flow anomaly density parameters Combined with the threat strength parameter of the k-th type of threat at the i-th node The risk potential index FSZ is constructed by combining the shortest path distance d between the i-th node and the k-th threat source node. This unifies and expresses the dimensions of threat intensity, topology propagation, node structural vulnerability, and real-time behavioral anomalies, enabling the overall network risk status to be assessed in the form of a single comprehensive quantitative indicator. This provides stable, continuous, and calculable basic parameter support for subsequent attack chain dynamic coupling analysis and risk propagation convergence determination.
[0092] In this embodiment, by introducing threat strength parameters, behavior anomaly rate parameters, vulnerability exposure parameters, and traffic anomaly density parameters, and combining them with the shortest path distance of the threat source to construct a risk potential energy index model, this invention couples the node's own risk characteristics with the network topology propagation relationship for calculation, realizing a comprehensive quantitative expression of risk "intensity-location-propagation impact". It can not only identify high-risk nodes, but also assess their potential diffusion impact on the overall network, thereby significantly improving the accuracy of risk positioning and the ability to predict risk evolution trends.
[0093] Example 5
[0094] Please see Figures 1 to 2 In the explanation of Example 4, specifically, step three further includes:
[0095] S32. By setting a preset risk potential energy threshold, denoted as Fth, and comparing and analyzing the risk potential energy index FSZ with the risk potential energy threshold Fth, the first evaluation result is obtained, including:
[0096] When the risk potential index FSZ ≤ the risk potential threshold Fth, it indicates that the current network risk status is acceptable, the network is in a controllable operating state, there is no risk of attack propagation, and continuous monitoring is required.
[0097] When the risk potential energy index FSZ > risk potential energy threshold Fth, it indicates that the current network risk status is unqualified, with potential attack spread risk or security loss of control risk, triggering the first warning command and generating the first strategy: using a risk source location algorithm and path reverse tracing analysis method, the contribution values of various threats participating in the risk potential energy calculation are decomposed and calculated to identify the abnormal risk threat categories and corresponding abnormal risk key nodes that contribute the most to the risk potential energy index FSZ value; according to the contribution ranking results, the abnormal risk threat categories are prioritized to generate an abnormal risk threat category list, and the propagation path between the threat source node and the target node is analyzed by topological reverse tracing to generate an abnormal risk propagation path set; according to the contribution ratio of each node in the risk potential energy index, the degree of abnormal risk impact of the nodes is ranked to generate an abnormal risk contribution weight ranking result and an abnormal risk priority handling node list; the abnormal risk threat category list, abnormal risk propagation path set, abnormal risk contribution weight ranking result, and abnormal risk priority handling node list are structured and encoded to form a structured abnormal risk situation vector set, and the attack chain coupling analysis trigger mechanism is initiated.
[0098] The risk potential threshold Fth is obtained by statistically analyzing a large amount of historical operational data from networks under normal operating conditions and different attack intensities. The distribution range of the risk potential index within the safe and abnormal ranges is extracted. Combined with network topology scale, asset importance level, and security protection capabilities, a reasonable risk potential threshold is determined. Simultaneously, referencing existing security incident handling records, industry network security assessment standards, and the experience of security operation and maintenance experts, the threshold is calibrated and graded to accurately reflect the overall risk tolerance and attack propagation sensitivity of the network. This allows for timely identification of potential attack propagation risks or security control risks, ensuring the stable operation of the network system.
[0099] In this embodiment, by classifying and judging the risk potential index against a preset threshold, and automatically triggering the risk source location and reverse path tracing analysis mechanism when the threshold is exceeded, the present invention can perform refined decomposition and sorting of risk contributions, accurately identify abnormal risk threat categories, key nodes and their propagation paths, and at the same time, structure the analysis results into an abnormal risk situation vector set, providing standardized input data for subsequent attack chain coupling analysis, realizing a seamless connection from risk assessment to attack chain structure identification, and significantly improving the pertinence of risk handling and the efficiency of linkage analysis.
[0100] Example 6
[0101] Please see Figures 1 to 2 In the explanation of Example 5, specifically, step four includes:
[0102] S41. Initiate the attack chain coupling analysis trigger mechanism. Based on the set of structured abnormal risk situation vectors, use the path association modeling method and directed graph construction technology to divide the abnormal risk propagation path set into stages and perform sequential association analysis to construct the attack stage state set, denoted as S.
[0103] S42. Based on the set of abnormal risk propagation paths and the list of abnormal risk threat categories, using the stage adjacency statistical method and the transfer relationship normalization calculation method, statistical analysis is performed on the association frequency between adjacent attack stages in the attack stage state set to obtain the transfer probability parameter between adjacent stages, denoted as... ;
[0104] S43. Based on the differences in formation time of each path in the abnormal risk propagation path set, a path time interval calculation method is used to calculate the duration interval between adjacent attack phases, obtaining the phase duration parameter, denoted as... ;
[0105] S44. Based on the risk potential energy index FSZ, the average calculation method of the node set in the list of nodes with priority handling of abnormal risks is adopted to statistically process the risk potential energy values of the nodes participating in the attack chain and obtain the average potential energy parameter, denoted as FSZavg.
[0106] In this embodiment, by constructing an attack phase state model based on a set of structured abnormal risk situation vectors, and combining it with phase transition probability, phase duration, and average risk potential energy parameters for coupled analysis, this invention achieves a phased, sequential, and dynamic characterization of the attack path evolution process. It can not only identify the correlation and evolution trend between attack behaviors, but also quantify the dynamic characteristics of attack chain formation, thereby significantly improving the ability to identify and predict multi-stage composite attacks and covert lateral diffusion behaviors.
[0107] Example 7
[0108] Please see Figures 1 to 2 In the explanation of Example Six, specifically, step four further includes:
[0109] S45. By obtaining the transition probability parameters between adjacent stages Stage duration parameters After dimensionless processing of the average potential energy parameter FSZavg, the dynamic coupling index of the attack chain, denoted as ACC, is calculated, as follows:
[0110]
[0111] In the formula, n represents the total number of attack phases. This represents the total number of phase transitions that can occur between adjacent attack phases. This represents the duration of stage j. Indicates the attack phase Towards The conditional probability of the transition.
[0112] The physical principle of the formula: The transition probability parameter between adjacent stages... Stage duration parameters The average potential energy parameter FSZavg is used for dimensionless coupling and superposition calculation. Through the comprehensive effect of "stage structure correlation strength * time accumulation effect * risk energy level", the attack chain's continuous advancement capability and formation dynamics in the time and risk energy dimensions are characterized. When the transfer probability between stages is high, the duration is long, and the risk potential energy level is high, the exponential value increases, indicating that the attack chain has a stable evolution and expansion trend, thereby realizing the dynamic quantitative expression of the risk formed by the attack chain.
[0113] In this embodiment, by performing dimensionless coupling calculations on the transition probability, duration of each phase, and average risk potential between adjacent attack phases, an attack chain dynamic coupling index is constructed. This invention provides a unified quantitative expression of the "association strength, time continuity, and risk level" of attack behavior, enabling a comprehensive assessment of the attack chain formation trend and evolution dynamics. This not only determines whether an attack has the ability to continue advancing but also identifies the risk of attack chain formation in advance, thereby improving the forward-looking early warning capability and proactive defense response capability against complex multi-stage attacks.
[0114] Example 8
[0115] Please see Figures 1 to 2 In the explanation of Example 7, specifically, step four further includes:
[0116] S46. By setting a preset attack chain dynamic coupling threshold, denoted as Ath, and comparing the attack chain dynamic coupling index ACC with the attack chain dynamic coupling threshold Ath, the second evaluation results are obtained, including:
[0117] When the attack chain dynamic coupling index ACC ≤ the attack chain dynamic coupling threshold Ath, it indicates that the current network attack chain status is qualified and there is no risk of forming a complete attack chain. Continuous monitoring is required.
[0118] When the attack chain dynamic coupling index ACC > the attack chain dynamic coupling threshold Ath, it indicates that the current network attack chain state is unqualified, and there is a risk of attack chain formation or lateral propagation. This triggers a second warning instruction and generates a second strategy: A lateral movement behavior recognition algorithm is used to enhance the monitoring of communication behavior between attack chain-related nodes, initiating a lateral movement monitoring mode; deep packet inspection technology is used to perform deep protocol parsing and abnormal command identification on network traffic between attack chain-related nodes, conducting deep traffic auditing; a dynamic access control adjustment method is used to implement access restrictions and network isolation on attack chain-related nodes, blocking abnormal propagation paths; and the set of attack chain-related nodes is structurally encapsulated to generate an attack chain control node set, initiating an adaptive defense optimization execution mechanism.
[0119] The attack chain dynamic coupling threshold Ath is obtained by modeling and analyzing multi-stage attack sample data, lateral movement behavior records, and the attack chain evolution process. The difference in the numerical distribution of the attack chain dynamic coupling index during the formation of normal behavior sequences and real attack chains is statistically analyzed. Combined with the attack stage transition frequency, stage duration, and risk potential energy level, the dynamic strength of attack chain formation is divided into intervals. By referring to typical advanced persistent threat event analysis reports, security vendor attack chain assessment models, and expert experience, the critical coupling strength threshold for attack chain formation is determined. This enables the effective differentiation between random abnormal behavior and attack chain structures with continuous advancement capabilities, and timely identification of attack chain formation risks and lateral spread risks.
[0120] In this embodiment, by comparing the attack chain dynamic coupling index with a preset threshold, and automatically triggering linked defense measures such as lateral movement monitoring, deep traffic auditing, and dynamic access control when the threshold is exceeded, the present invention can promptly and accurately block and control access restrictions when the attack chain has not yet fully formed or is in the early stage of diffusion, effectively curbing the continuous advancement and lateral propagation of the attack chain. At the same time, by generating a set of attack chain control nodes and starting an adaptive defense optimization mechanism, the defense strategy can be dynamically adjusted and continuously strengthened, significantly improving the network system's proactive defense capability and overall security stability.
[0121] Example 9
[0122] Please see Figures 1 to 2 In the explanation of Embodiment Eight, specifically, step five includes:
[0123] S51. Activate the adaptive defense optimization execution mechanism. Based on the attack chain control node set and the structured abnormal risk situation vector set, use the abnormal traffic proportion statistical method and the proportion normalization calculation method to statistically and normalize the abnormal traffic proportion of each node in the attack chain control node set, and obtain the attack path probability parameter, denoted as... ;
[0124] S52, through the obtained attack path probability parameters The squared concentration method is used to statistically analyze the concentration of abnormal traffic distribution in the set of attack chain control nodes, and the risk propagation convergence entropy index, denoted as RE, is calculated and obtained, as follows:
[0125]
[0126] In the formula, u represents the number of nodes in the attack chain control node set, and G This represents the probability of an attack path to the b-th node;
[0127] The physical principle of the formula: Based on the statistical concept of squared concentration, it is derived from the attack path probability parameter G. The sum of squares is used to measure the degree of distribution balance of abnormal traffic in the set of control nodes of the attack chain. When abnormal traffic is concentrated in a few nodes, the sum of squares of probability increases and the risk propagation convergence entropy index RE decreases, indicating that the attack path has converged and there is a risk of breakthrough at key nodes. When the abnormal traffic is more evenly distributed, the risk propagation convergence entropy index RE increases, indicating that the risk is in a discrete diffusion state. Therefore, this index is essentially used to characterize the spatial concentration and convergence trend of risk propagation, and to achieve quantitative judgment of concentrated penetration risk.
[0128] In this embodiment, by normalizing the proportion of abnormal traffic in the attack chain control node set and constructing a risk propagation convergence entropy index using the squared concentration method, this invention can quantitatively characterize the dispersion and concentration trend of abnormal traffic among different nodes. This allows for accurate identification of whether the attack path has converged and the risk of breakthrough at key nodes, enabling precise judgment and early warning of concentrated penetration behavior. It significantly improves the ability to identify and prevent targeted attacks with strong concealment and concentrated paths.
[0129] Example 10
[0130] Please see Figures 1 to 2 In the explanation of Embodiment Nine, specifically, step five further includes:
[0131] S53. By setting a preset risk propagation convergence entropy threshold, denoted as Rth, and comparing the risk propagation convergence entropy index RE with the risk propagation convergence entropy threshold Rth, the third evaluation results are obtained, including:
[0132] When the risk propagation convergence entropy index RE ≥ the risk propagation convergence entropy threshold Rth, it indicates that the abnormal traffic distribution in the current attack chain control node set is dispersed, the attack propagation path is in a discrete diffusion state, the network as a whole is within the controllable range, there is no risk of concentrated penetration attack, and continuous monitoring is required.
[0133] When the risk propagation convergence entropy index RE < the risk propagation convergence entropy threshold Rth, it indicates that the abnormal traffic distribution in the current attack chain control node set is concentrated, the attack propagation path has converged, and there is a risk of concentrated penetration attack or critical path breach. This triggers a third warning instruction and generates a third strategy: employing a critical convergence path port blocking method to close ports or restrict access on propagation paths with highly concentrated abnormal traffic; employing multi-factor authentication enhanced control technology to enforce multi-factor authentication policies on critical nodes in the attack chain control node set; employing a full network traffic mirroring analysis method to mirror and deeply audit the relevant traffic in the attack chain control node set; and employing a dynamic access control adjustment method to implement permission contraction and network isolation control on nodes with concentrated abnormal traffic, blocking concentrated penetration paths.
[0134] S54. Synchronously update the execution results of the third strategy to the network operating environment, and re-enter step one for continuous monitoring to form a dynamic closed-loop control mechanism for network security situation.
[0135] The risk propagation convergence entropy threshold Rth is obtained by conducting long-term statistical analysis of the abnormal traffic distribution in the attack chain control node set, extracting the risk propagation convergence entropy index distribution range of abnormal traffic in discrete diffusion and concentrated convergence states, and combining the distribution characteristics of network key nodes, access control policy strength, and historical concentrated penetration attack cases to conduct a sensitivity assessment of the degree of abnormal traffic concentration; at the same time, referring to industry security operation experience and expert evaluation results, the convergence entropy critical value is calibrated so that it can accurately reflect whether the attack path has a concentrated breakthrough or the risk of key node aggregation, thereby triggering key path hardening and concentrated penetration blocking measures in a timely manner, and improving the overall network security defense capability.
[0136] In this embodiment, by classifying and judging the risk propagation convergence entropy index with a preset threshold, and automatically triggering linkage control measures such as critical path blocking, multi-factor authentication enhancement, full network traffic mirroring audit, and dynamic permission contraction when abnormal traffic is highly concentrated, and feeding the execution results back to the monitoring link to form a dynamic closed loop, this invention can implement precise blocking and continuous optimization control before concentrated penetration attacks form a critical breakthrough, significantly improving the rapid response capability to critical path attacks and the adaptive adjustment capability of network security situation.
[0137] It should be noted that all calculation formulas in this application employ regression analysis, including but not limited to machine learning algorithms, to deeply analyze the collected parameters and identify their natural trends and interrelationships. Specialized software, such as Python's Scikit-learn library or the R language, is used to automatically generate mathematical models that match the data. Then, cross-validation and other methods are used to objectively evaluate the model performance, and continuous feedback and optimization are combined to ensure that the created formulas truly reflect the inherent laws of the data, thereby guaranteeing their effectiveness and accuracy. In all calculation formulas in this application, the parameters in each formula undergo dimensionless processing within a consistent range to ensure that different physical quantities are compared on the same scale; dimensionless processing techniques include, but are not limited to, min-max-normalization and Z-score standardization.
[0138] The algorithm of this invention is implemented as a Python script. Before executing the core logic, the program first executes a data loading module (e.g., using the widely used pandas library in Python) configured to read the aforementioned spreadsheet file and load its contents into the program's working memory (e.g., a DataFrame data structure). Subsequent algorithm steps will directly query and retrieve the required configuration parameters from this in-memory data structure.
[0139] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A network security situation awareness method based on artificial intelligence, characterized in that, The specific steps include: Step 1: By real-time monitoring of network communication behavior, host operating status, network security threat situation, and the relationship between network asset security status and topology, traffic characteristic data, abnormal host behavior data, threat alarm data, and vulnerability and topology data are collected respectively. Step 2: Based on threat alert data, abnormal host behavior data, vulnerability and topology data, and traffic characteristic data, perform quantitative calculations on threat strength, abnormal behavior degree, vulnerability risk exposure level, and abnormal traffic activity to obtain threat strength parameters, abnormal behavior rate parameters, vulnerability exposure parameters, and abnormal traffic density parameters. Step 3: Calculate the risk potential index and compare it with the risk potential threshold to determine whether the current network risk status is qualified. If it is not qualified, an abnormal risk tracing strategy is given. Step 4: Calculate the attack chain dynamic coupling index and compare it with the attack chain dynamic coupling threshold to determine whether the current network attack chain status is qualified. If it is not qualified, an attack chain blocking strategy is applied. Step 5: Calculate the risk propagation convergence entropy index and compare it with the risk propagation convergence entropy threshold to determine whether there is a risk of concentrated penetration attack on the network. If so, implement concentrated penetration blocking and critical path hardening strategies to form a dynamic closed-loop control mechanism.
2. The network security situation awareness method based on artificial intelligence according to claim 1, characterized in that: Step one includes: S11. Real-time monitoring of network communication behavior is carried out by installing deep packet inspection equipment at the network boundary and deploying traffic collection probes at the mirror port of the switch to collect traffic characteristic data, including source IP address, destination IP address, session duration, number of data packets and abnormal traffic identification data. S12. Monitor the host's operating status in real time. By installing a host security agent program on the host terminal and combining it with a centralized log collection method, collect abnormal host behavior data, including the number of abnormal behavior records, the number of privilege escalation events, the number of abnormal process startups, and the number of access control change records. S13. Conduct real-time monitoring of network security threat situation, and collect threat alarm data by deploying intrusion detection equipment and firewall log collection equipment, including threat level value, threat occurrence frequency, threat type identifier and alarm duration data; S14. Monitor the security status and structural relationships of network assets in real time. By using vulnerability scanning tools and automatic network topology discovery methods, collect vulnerability and topology data, including vulnerability risk scores, number of vulnerabilities, vulnerability level, vulnerability impact range, as well as shortest path distance between nodes, node connectivity, and node hierarchical position data.
3. The network security situation awareness method based on artificial intelligence according to claim 2, characterized in that: Step two includes: S21. Based on threat level values, threat occurrence frequency, threat type identifiers, and alarm duration data, a weighted statistical analysis method and a time decay processing algorithm are used to perform intensity assessment and time dimension correction processing on different threat types to obtain threat intensity parameters for each type of threat. S22. Based on the data of the number of abnormal behavior records, the number of privilege escalation events, the number of abnormal process startups, and the number of access control change records, the behavior frequency statistical analysis method and the sliding time window aggregation algorithm are used to perform merge statistics and abnormal density analysis on abnormal behaviors within a unit of time to obtain the behavior abnormality rate parameter. S23. Based on vulnerability risk scores, number of vulnerabilities, vulnerability level, vulnerability impact range, as well as shortest path distance between nodes, node connectivity, and node hierarchical position data, a risk weighted overlay analysis method and an impact range mapping algorithm are used to comprehensively assess vulnerability risk and obtain vulnerability exposure parameters. S24. Based on the source IP address, destination IP address, session duration, number of data packets, and abnormal traffic identification data, the abnormal traffic activity level within a unit of time is calculated and abnormal marking is filtered using traffic density statistics and time normalization processing techniques to obtain abnormal traffic density parameters.
4. The method for network security situation awareness based on artificial intelligence according to claim 3, characterized in that: Step three includes: S31. By extracting the behavior anomaly rate parameter, vulnerability exposure parameter, and traffic anomaly density parameter of the i-th node, and combining the threat intensity parameter of the k-th type of threat of the i-th node and the shortest path distance between the i-th node and the k-th type of threat source node, after dimensionless processing, the risk potential energy index is calculated and obtained.
5. The network security situation awareness method based on artificial intelligence according to claim 4, characterized in that: Step three also includes: S32. By setting a preset risk potential threshold and comparing the risk potential index with the risk potential threshold, the first assessment result is obtained, including: When the risk potential index is less than or equal to the risk potential threshold, it indicates that the current network risk status is acceptable, the network is in a controllable operating state, there is no risk of attack propagation, and continuous monitoring is required. When the risk potential energy index exceeds the risk potential energy threshold, it indicates that the current network risk status is unqualified, with potential attack spread risks or security loss of control risks. This triggers the first early warning command and generates the first strategy: Using a risk source location algorithm and path reverse tracing analysis method, the contribution values of various threats involved in the risk potential energy calculation are decomposed and calculated to identify the abnormal risk threat categories and corresponding critical abnormal risk nodes that contribute the most to the risk potential energy index value. Based on the contribution ranking results, the abnormal risk threat categories are prioritized, generating a list of abnormal risk threat categories. Topological reverse tracing analysis is then performed on the propagation paths from threat source nodes to target nodes to generate a set of abnormal risk propagation paths. Based on the contribution ratio of each node in the risk potential energy index, the impact degree of abnormal risks is ranked, generating an abnormal risk contribution weight ranking result and a list of nodes to be prioritized for handling. The list of abnormal risk threat categories, the set of abnormal risk propagation paths, the abnormal risk contribution weight ranking result, and the list of nodes to be prioritized for handling are then structured and encoded to form a set of structured abnormal risk situation vectors, and the attack chain coupling analysis trigger mechanism is initiated.
6. The network security situation awareness method based on artificial intelligence according to claim 5, characterized in that: Step four includes: S41. Activate the attack chain coupling analysis trigger mechanism. Based on the set of structured abnormal risk situation vectors, use path association modeling method and directed graph construction technology to divide the abnormal risk propagation path set into stages and perform sequential association analysis to construct the attack stage state set. S42. Based on the set of abnormal risk propagation paths and the list of abnormal risk threat categories, the phase adjacency statistical method and the transfer relationship normalization calculation method are used to statistically analyze the association frequency between adjacent attack phases in the attack phase state set and obtain the transfer probability parameters between adjacent phases. S43. Based on the difference in formation time of each path in the abnormal risk propagation path set, the path time interval calculation method is used to calculate the duration interval between adjacent attack phases and obtain the phase duration parameter. S44. Based on the risk potential energy index, the average calculation method of the node set in the list of nodes for priority handling of abnormal risks is adopted to statistically process the risk potential energy values of the nodes participating in the attack chain and obtain the average potential energy parameter.
7. The network security situation awareness method based on artificial intelligence according to claim 6, characterized in that: Step four also includes: S45. After dimensionless processing of the obtained transition probability parameters, stage duration parameters, and average potential energy parameters between adjacent stages, the attack chain dynamic coupling index is calculated.
8. The network security situation awareness method based on artificial intelligence according to claim 7, characterized in that: Step four also includes: S46. By setting a preset attack chain dynamic coupling threshold and comparing the attack chain dynamic coupling index with the attack chain dynamic coupling threshold, the second evaluation result is obtained, including: When the attack chain dynamic coupling index is less than or equal to the attack chain dynamic coupling threshold, it indicates that the current network attack chain status is qualified and there is no risk of forming a complete attack chain. Continuous monitoring is required. When the attack chain dynamic coupling index exceeds the attack chain dynamic coupling threshold, it indicates that the current network attack chain status is unqualified, posing a risk of attack chain formation or lateral propagation. This triggers a second warning instruction and generates a second strategy: employing a lateral movement behavior recognition algorithm to enhance monitoring of communication behavior between attack chain-related nodes and initiating a lateral movement monitoring mode; using deep packet inspection technology to perform deep protocol parsing and abnormal command identification of network traffic between attack chain-related nodes, conducting deep traffic auditing; employing a dynamic access control adjustment method to implement access restrictions and network isolation for attack chain-related nodes, blocking abnormal propagation paths; and performing structured encapsulation of the attack chain-related node set to generate an attack chain control node set, and initiating an adaptive defense optimization execution mechanism.
9. The network security situation awareness method based on artificial intelligence according to claim 8, characterized in that: Step five includes: S51. Activate the adaptive defense optimization execution mechanism. Based on the attack chain control node set and the structured abnormal risk situation vector set, use the abnormal traffic ratio statistical method and the ratio normalization calculation method to statistically and normalize the abnormal traffic ratio of each node in the attack chain control node set to obtain the attack path probability parameters. S52. Using the obtained attack path probability parameters, the square concentration method is used to statistically analyze the concentration of abnormal traffic distribution in the attack chain control node set, and calculate the risk propagation convergence entropy index.
10. A network security situation awareness method based on artificial intelligence according to claim 9, characterized in that: Step five also includes: S53. By setting a preset risk propagation convergence entropy threshold and comparing the risk propagation convergence entropy index with the risk propagation convergence entropy threshold, the third evaluation results are obtained, including: When the risk propagation convergence entropy index is greater than or equal to the risk propagation convergence entropy threshold, it indicates that the abnormal traffic distribution in the current attack chain control node set is dispersed, the attack propagation path is in a discrete diffusion state, the network as a whole is within the controllable range, there is no risk of concentrated penetration attack, and continuous monitoring is required. When the risk propagation convergence entropy index is less than the risk propagation convergence entropy threshold, it indicates that the abnormal traffic distribution in the current attack chain control node set is concentrated, the attack propagation path has converged, and there is a risk of concentrated penetration attack or critical path breach. This triggers a third warning instruction and generates a third strategy: employing a critical convergence path port blocking method to close ports or restrict access on propagation paths with highly concentrated abnormal traffic; employing multi-factor authentication enhanced control technology to enforce multi-factor authentication policies on critical nodes in the attack chain control node set; employing a full network traffic mirroring analysis method to mirror and deeply audit the relevant traffic in the attack chain control node set; and employing a dynamic access control adjustment method to implement permission contraction and network isolation control on nodes with concentrated abnormal traffic, blocking concentrated penetration paths. S54. Synchronously update the execution results of the third strategy to the network operating environment, and re-enter step one for continuous monitoring to form a dynamic closed-loop control mechanism for network security situation.
Citation Information
Cited By
Network security risk trend multidimensional correlation data analysis prediction method
CN122174228A
A cyber defense information analysis system and apparatus
CN122268679A