Network security situation awareness method based on knowledge graph
By using a knowledge graph-based network security situational awareness method, the topological relationship graph structure is obtained and the threat spread intensity is calculated. Combined with an adaptive suppression mechanism, the problem of inaccurate threat spread intensity assessment and resource allocation imbalance in existing technologies is solved, and accurate quantitative description and dynamic response to network threats are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANDONG ZHENGZHOU INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2026-01-21
- Publication Date
- 2026-04-17
AI Technical Summary
Existing network security situational awareness technologies are unable to quantitatively assess the spread intensity of security threats among topologically related nodes, and are susceptible to baseline drift interference caused by fluctuations in business load, resulting in false alarms, imbalances in the allocation of protection resources, and delayed responses.
A knowledge graph-based approach is adopted to obtain multi-source network traffic data sequences, extract the topology graph structure, calculate the threat spread intensity, and use an adaptive suppression mechanism to obtain compensation correction values. Based on the overall network situation index, closed-loop control is achieved, and the allocation of protection resources is dynamically adjusted.
Effectively assess the instantaneous outbreak characteristics of cyber threats, reduce the imbalance in the allocation of protection resources and false alarms, and achieve accurate quantitative description and dynamic response to cyber threats.
Smart Images

Figure CN121887508A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security data processing technology. More specifically, this invention relates to a network security situation awareness method based on knowledge graphs. Background Technology
[0002] Network security situation awareness, as a key link in ensuring data transmission security and network protocol operation stability, is essentially about identifying potential unauthorized access, protocol attacks, or abnormal penetration behaviors by real-time monitoring and multi-dimensional analysis of traffic data in large-scale, distributed networks. With the evolution of software-defined networking and large-scale interconnection architecture, the interaction logic between network entities has become highly complex and dynamic. Network traffic not only contains basic packet payload information, but also forms intricate logical connections in the time and space dimensions.
[0003] Current information security protection systems generally rely on intrusion detection systems, firewall policies, and traditional log auditing methods. These methods are effective in handling known attack characteristics and single-point security incidents. However, when facing penetration attacks with strong propagation and high coordination, existing technical solutions often focus on statistical analysis of single traffic characteristics or isolated security alerts, lacking effective utilization of the depth of topological relationships between network assets. This results in significant limitations in the protection system's ability to assess the spread path and evolution level of security threats across all network nodes, making it difficult for operations and maintenance personnel to accurately grasp the substantial impact of attack behavior on the overall network architecture.
[0004] Meanwhile, the business load in real network environments is not constant. Influenced by large-scale data exchange, periodic business peaks, or the regularity of normal network access fluctuations, background traffic often exhibits significant dynamic shifts. Because existing situational awareness models generally employ preset static thresholds or security benchmarks based on simple moving averages, the system is highly susceptible to misjudgments when facing normal traffic increases during peak business periods due to a lack of effective background suppression mechanisms. This leads to numerous false alarms and triggers unnecessary defense responses. Furthermore, for sudden threats exhibiting exponential burst characteristics within a short period, existing protection frameworks often fail to accurately identify the rate of change in threat intensity, resulting in delayed issuance of security protocol adjustment commands and difficulty in achieving dynamic and accurate allocation of protection resources in the temporal and spatial domains. Therefore, effectively filtering background business noise and achieving accurate quantitative representation of threat propagation in complex and ever-changing traffic environments has become a bottleneck that urgently needs to be addressed in the field of information security data processing. Summary of the Invention
[0005] To address the limitations of existing situational awareness technologies in quantitatively assessing the spread intensity of security threats among interconnected nodes in a network topology, and their susceptibility to false alarms caused by baseline drift due to fluctuations in service load, leading to delayed responses to sudden threats and imbalanced allocation of protection resources, this invention provides a knowledge graph-based network security situational awareness method. The method includes: acquiring and processing multi-source network traffic data sequences to obtain preprocessed network traffic data sequences; extracting entity connection relationships from the preprocessed network traffic data sequences to obtain a topology graph structure; extracting active paths triggered by the preprocessed network traffic data sequences from the topology graph structure, and obtaining the average alarm weight, connection density, and total number of nodes for these active paths; obtaining the threat spread intensity based on the average alarm weight, connection density, and total number of nodes; obtaining historical average security baseline traffic based on the preprocessed network traffic data sequences; obtaining a compensation correction value based on real-time background traffic load, historical average security baseline traffic, threat spread intensity, and a preset sensitivity adjustment factor; obtaining a network-wide situational awareness index based on the compensation correction value, threat spread intensity, and a preset mutation gain coefficient; and achieving network security situational awareness based on the network-wide situational awareness index.
[0006] This invention obtains the topological association graph structure, assesses the threat spread intensity, and uses an adaptive suppression mechanism to obtain compensation and correction values to obtain a network-wide situation index and execute closed-loop control. This enables the assessment of the instantaneous outbreak characteristics of network threats and reduces the imbalance in the allocation of protection resources in knowledge graph-based network security situation awareness.
[0007] Preferably, the processing includes: preprocessing the network address, port, and protocol fields in the multi-source network traffic data sequence using standard attribute extraction technology, and obtaining the preprocessed network traffic data sequence by setting the sampling frequency based on the synchronization clock signal.
[0008] This invention employs standard attribute extraction technology to process the address and protocol fields in multi-source network traffic data sequences and obtains preprocessed network traffic data sequences based on a synchronous clock signal. This results in the obtained traffic data having a unified time attribute and providing standardized data support for subsequent evaluation in information security data processing.
[0009] Preferably, the threat diffusion intensity satisfies the expression: In the formula, For a moment The intensity of threat spread, For a moment Average alarm weight of active path nodes For a moment Connection tightness of associated edges For a moment The total number of nodes covered by the path. This is a structural complexity compensation term. The sampling interval is... The time decay coefficient, It is a natural constant. This is the natural logarithm operator.
[0010] Preferably, the structural complexity compensation term is obtained by: extracting the adjacency matrix of the topological association graph structure, and determining the structural complexity compensation term by calculating the average degree of all nodes in the topological association graph structure.
[0011] This invention determines the structural complexity compensation term by obtaining the adjacency matrix of the topological association graph structure and calculating the average degree of all nodes. This reflects the dilution effect of different network topological densities, thus enabling the assessment of threat diffusion intensity during situational awareness to better reflect the actual physical connection state.
[0012] Preferably, the compensation correction value satisfies the expression: In the formula, For a moment The generated compensation correction value, For a moment Real-time background traffic load, For a moment Historical average safe baseline flow rate As a sensitivity adjustment factor, For a moment The intensity of threat spread, It is the hyperbolic tangent function. It is a positive number.
[0013] Preferably, the historical average security baseline traffic is obtained by performing a moving average calculation on the preprocessed network traffic data sequence in normal operation within a preset time window to obtain the historical average security baseline traffic.
[0014] This invention performs a moving average calculation on traffic data in normal operation within a preset time window to obtain the historical average safe baseline traffic, providing a reliable reference for the adaptive suppression mechanism and reducing the generation of false alarms when faced with baseline drift caused by business fluctuations.
[0015] Preferably, the overall network situation index satisfies the expression: In the formula, For a moment The generated overall network situation index, For a moment The generated compensation correction value, This is the mutation gain coefficient. For a moment The intensity of threat spread, For a moment The intensity of threat spread, For absolute value operators, It is the hyperbolic tangent function.
[0016] Preferably, the network security situation awareness based on the overall network situation index includes: issuing firewall policy blocking instructions based on the comparison results of the overall network situation index and the judgment threshold, adjusting the traffic filtering opening of the core switch, and improving the packet auditing depth of the security gateway.
[0017] This invention implements firewall policies to block and adjust the traffic filtering capacity of core switches and improve the packet auditing depth of security gateways based on the overall network situation index. This achieves closed-loop adaptive control of network threats and enables the protection strength to be dynamically adjusted according to the risk level in situational awareness scenarios.
[0018] Preferably, the value of the mutation gain coefficient is... .
[0019] Preferably, the structural complexity compensation term is set to a value of .
[0020] The beneficial effects of this invention are as follows: This invention utilizes a topological graph structure to assess the intensity of threat spread. By considering the alarm weight of active paths and the tightness of connections, it enables the assessment of the evolution of security threats and reduces the risk of missed detections in information security data processing.
[0021] This invention introduces an adaptive suppression mechanism and dynamically obtains compensation correction values based on the ratio of real-time background traffic load to historical average safe baseline traffic to suppress baseline drift. This reduces the likelihood of misjudging normal traffic fluctuations as attacks during peak business periods in situational awareness.
[0022] This invention combines the compensation correction value and the difference in diffusion intensity with the mutation gain coefficient to obtain the overall network situation index and perform closed-loop adaptive control to adjust equipment parameters. This enables the network security protection system to assess the instantaneous outbreak characteristics of threats and reduces the problem of untimely resource allocation. Attached Figure Description
[0023] Figure 1 This is a flowchart illustrating the knowledge graph-based network security situation awareness method of the present invention; Figure 2 This diagram illustrates the intensity of threat spread. Figure 3 This diagram illustrates the effect of dynamic compensation for reference offset. Figure 4 This diagram illustrates the changes in the overall network security posture index. Detailed Implementation
[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0025] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0026] This invention discloses a network security situation awareness method based on knowledge graphs, referring to... Figure 1 This includes steps S1 to S4: S1. Obtain and process multi-source network traffic data sequences to obtain preprocessed network traffic data sequences. Extract entity connection relationships from the preprocessed network traffic data sequences to obtain the topology graph structure.
[0027] It should be noted that in complex network operating environments, the information interaction between network devices exhibits highly nonlinear and time-varying characteristics. If we only observe the operating data of a single device in isolation, we will not be able to accurately discover the propagation path and evolution pattern of attack behavior between different devices. Therefore, this invention captures mirrored traffic and security logs, extracts entity interaction logic, and maps it into a topological association graph structure with spatial connection characteristics, thereby providing an intuitive data foundation with geometric correlation characteristics for subsequent accurate assessment of the security status of the entire network.
[0028] Specifically, this invention employs standard attribute extraction technology to perform feature preprocessing on network address, port, and protocol fields in network traffic data. This invention sets the data collection sampling frequency to be... Hz, corresponding sampling interval The value is s.
[0029] Furthermore, this invention invokes a protocol analysis engine based on deep packet inspection technology to perform deep parsing of the captured raw network traffic data, extracting interaction triples containing source address, destination address, service port, and communication protocol; obtains system operation status records provided by security logs, and extracts abnormal entity behavior features recorded in the security logs; utilizes existing asset discovery and dependency mapping technologies, such as Simple Network Management Protocol (SNMP) polling technology and passive traffic feature recognition technology, to load the extracted interaction triples and abnormal entity behavior features into a graph database, defining each independent asset entity as a node, defining the communication relationship between entities as an edge, and finally generating a topological association graph structure reflecting the connection relationship of assets across the entire network.
[0030] S2. Extract the active paths triggered by the preprocessed network traffic data sequence in the topology graph structure, and obtain the average alarm weight, connection density and total number of nodes of the active paths. Obtain the threat spread intensity based on the average alarm weight, connection density and total number of nodes.
[0031] It should be noted that the spread of attack behavior in the topology graph structure is constrained by the node connectivity density and duration. If the dilution effect of network topology density is ignored, the system will not be able to accurately distinguish between local noise and global penetration. When the total number of nodes covered by the path is large, the potential attack energy will be dispersed by diversified assets, producing a phenomenon similar to energy dilution. This invention evaluates the dynamic process of threat evolution between different nodes by calculating the threat spread intensity.
[0032] Specifically, this invention obtains the threat propagation intensity based on active paths triggered by network traffic data in the topology graph structure. The threat propagation intensity satisfies the expression:
[0033] In the formula, Indicates time The intensity of threat spread, Indicates time Average alarm weight of active path nodes Indicates time Connection tightness of associated edges Indicates time The total number of nodes covered by the path. This represents the structural complexity compensation term. Indicates the sampling interval. Indicates the time decay coefficient. Represents the natural constant. This represents the natural logarithm operator.
[0034] In the formula, the total number of nodes covered by the path is... A larger value indicates that the potential attack energy is dispersed among diverse assets, thus increasing the denominator and driving the final threat diffusion intensity. The reduction in size accurately describes the dilution effect of the topological graph structure on threat energy.
[0035] It should be noted that the value range of the structural complexity compensation term is within... to If the structural complexity compensation term is set too small, it will lead to an overestimation of the threat posed by sparse networks. Therefore, this invention selects... As an empirical value, it can objectively describe the dilution effect while ensuring sensitivity to intensive attacks, providing a reliable data foundation.
[0036] For example, Figure 2 This is a diagram illustrating the intensity of threat diffusion, recording the system's monitoring process of a sudden security threat in a real network environment. The data shows that the threat diffusion intensity does not increase smoothly, but rather exhibits a step-like abrupt change accompanied by violent fluctuations. This realistically reflects the uncertain evolutionary path of attackers moving laterally and causing damage between different nodes in the knowledge graph, demonstrating that this invention can effectively capture the dynamic diffusion process of complex attacks.
[0037] S3. Obtain historical average security baseline traffic based on preprocessed network traffic data sequence, and obtain compensation correction value based on real-time background traffic load, historical average security baseline traffic, threat spread intensity, and preset sensitivity adjustment factor.
[0038] It should be noted that the operating status of the network environment will experience baseline drift as the service load changes. In order to suppress background noise caused by service fluctuations and prevent false alarms caused by baseline drift, this invention introduces a nonlinear saturation function to establish an adaptive suppression mechanism. The threat assessment weight is dynamically corrected using real-time background traffic load to ensure that the system will not misjudge normal traffic growth as a network attack during periods of surging service activity.
[0039] Specifically, the present invention obtains compensation correction values based on real-time background traffic load at a given time, and the compensation correction values satisfy the expression:
[0040] In the formula, For a moment The generated compensation correction value, For a moment Real-time background traffic load, For a moment Historical average safe baseline flow rate As a sensitivity adjustment factor, For a moment The intensity of threat spread, It is the hyperbolic tangent function. To prevent positive numbers with a denominator of zero, empirical values are used. .
[0041] In the formula, the adaptive inhibition mechanism within the parentheses With real-time background traffic load As the value increases, the background noise level rises, the hyperbolic tangent function shifts towards the saturation region, causing the value within the brackets to decrease, ultimately affecting the compensation correction value. By reducing the non-linear mapping, the system can automatically lower the evaluation weight during peak business periods.
[0042] The sensitivity adjustment factor is used to adjust the strength of the adaptive suppression mechanism's response to business fluctuations. The value range of the sensitivity adjustment factor is typically within... to If the sensitivity adjustment factor is set too small, the system becomes overly sensitive to business fluctuations, potentially causing genuine threat behaviors to be missed. Therefore, this invention selects... As an empirical value, it can ensure the effectiveness of the adaptive suppression mechanism while avoiding excessive loss of threat signals and improving the accuracy of the assessment.
[0043] For example, Figure 3 This is a schematic diagram illustrating the dynamic compensation effect of the reference offset. The figure shows the final detection deviation record after processing by the saturation control function of this invention under extremely complex network background traffic interference. Although the original network environment has huge unpredictable fluctuations, the compensation detection deviation shown in the figure is always suppressed within a very narrow noise band near zero, proving that this invention can effectively filter out environmental reference offset and ensure the stability of detection results under harsh operating conditions.
[0044] S4. Obtain the overall network situation index based on the compensation correction value, threat diffusion intensity, and preset mutation gain coefficient, and realize network security situation awareness based on the overall network situation index.
[0045] It should be noted that situation assessment needs to have numerical stability to handle large-scale concurrent threats and remain highly sensitive to the mutation rate of threats. This invention eliminates subjective asset weights and uses the instantaneous mutation characteristics of threat diffusion intensity to construct a nonlinear discriminant model, thereby capturing the nonlinear burst characteristics of threats in the time domain, realizing a quantitative description of network security capabilities and closed-loop adaptive adjustment of the protection system.
[0046] Specifically, this invention obtains the overall network situation index based on the compensation correction value at time and the difference in diffusion intensity. The overall network situation index satisfies the expression:
[0047] In the formula, Indicates time The generated overall network situation index, Indicates time The generated compensation correction value, Represents the mutation gain coefficient. Indicates time The intensity of threat spread, Indicates time The intensity of threat spread, This represents the absolute value operator.
[0048] In the formula, An increase in the value indicates a violent outbreak of threats across nodes; the saturation gain term increases, driving the overall network situation index. Rapidly expanding, the multiplicative coupling structure enables a comprehensive characterization of static threat energy and dynamic rate of change, ensuring that the system has an extremely high response speed during the threat mutation phase.
[0049] The range of values for the mutation gain coefficient is typically within... to Between these two points, if the mutation gain coefficient is set too high, the system is susceptible to fluctuations caused by single-point flow pulse interference; if the mutation gain coefficient is set too low, it cannot promptly reflect large-scale penetration behavior. This invention selects... As an empirical value, it can accurately capture the instantaneous characteristics of a threat while ensuring the stability of numerical calculations.
[0050] Furthermore, this invention performs closed-loop adaptive adjustment based on the overall network situation index, and the overall network situation index... When the threshold is exceeded, the present invention automatically issues firewall policy blocking instructions through the controller and adjusts the traffic filtering opening of the core switch. At the same time, it dynamically increases the packet auditing depth of the security gateway. The system uses the network situation index to provide sensitive feedback on the outbreak of threats and automatically corrects the execution strength of the firewall blocking rules, realizing the dynamic allocation and closed-loop adaptive adjustment of network security protection resources.
[0051] For example, Figure 4 This is a schematic diagram of the changes in the overall network security situation index. After the threat was identified, the overall network security situation index experienced a rapid increase with obvious fluctuations. Then, at the moment the closed-loop control strategy was triggered, it quickly turned around and showed an exponential decay. Finally, it returned to the low security zone against the background of residual noise, which verifies the effectiveness and real-time performance of the closed-loop control from perception to automatic response of the present invention.
Claims
1. A knowledge graph-based method for network security situation awareness, characterized in that, include: The multi-source network traffic data sequence is acquired and processed to obtain a preprocessed network traffic data sequence. Entity connection relationships are extracted from the preprocessed network traffic data sequence to obtain the topology graph structure. Extract active paths triggered by preprocessed network traffic data sequences in the topology graph structure, and obtain the average alarm weight, connection density, and total number of nodes of the active paths. Based on the average alarm weight, connection density, and total number of nodes, obtain the threat spread intensity. Historical average security baseline traffic is obtained based on preprocessed network traffic data sequences, and compensation correction values are obtained based on real-time background traffic load, historical average security baseline traffic, threat spread intensity, and preset sensitivity adjustment factors. The overall network situation index is obtained based on the compensation correction value, the threat diffusion intensity, and the preset mutation gain coefficient, and network security situation awareness is realized based on the overall network situation index.
2. The knowledge graph-based network security situation awareness method according to claim 1, characterized in that, The processing includes: Standard attribute extraction techniques are used to preprocess the network address, port, and protocol fields in the multi-source network traffic data sequence, and the sampling frequency is set based on the synchronous clock signal to obtain the preprocessed network traffic data sequence.
3. The knowledge graph-based network security situation awareness method according to claim 1, characterized in that, The threat diffusion intensity satisfies the expression: ; In the formula, For a moment The intensity of threat spread, For a moment Average alarm weight of active path nodes For a moment Connection tightness of associated edges For a moment The total number of nodes covered by the path. This is a structural complexity compensation term. The sampling interval is... The time decay coefficient, It is a natural constant. This is the natural logarithm operator.
4. The knowledge graph-based network security situation awareness method according to claim 3, characterized in that, The structural complexity compensation term is obtained as follows: Extract the adjacency matrix of the topological graph structure, and determine the structural complexity compensation term by calculating the average degree of all nodes in the topological graph structure.
5. The knowledge graph-based network security situation awareness method according to claim 1, characterized in that, The compensation correction value satisfies the expression: ; In the formula, For a moment The generated compensation correction value, For a moment Real-time background traffic load, For a moment Historical average safe baseline flow rate As a sensitivity adjustment factor, For a moment The intensity of threat spread, It is the hyperbolic tangent function. It is a positive number.
6. The knowledge graph-based network security situation awareness method according to claim 5, characterized in that, The historical average safety baseline traffic is obtained as follows: Within a preset time window, a moving average is calculated on the preprocessed network traffic data sequence that is in normal operation to obtain the historical average safe baseline traffic.
7. The knowledge graph-based network security situation awareness method according to claim 1, characterized in that, The overall network situation index satisfies the expression: ; In the formula, For a moment The generated overall network situation index, For a moment The generated compensation correction value, This is the mutation gain coefficient. For a moment The intensity of threat spread, For a moment The intensity of threat spread, For absolute value operators, It is the hyperbolic tangent function.
8. The knowledge graph-based network security situation awareness method according to claim 7, characterized in that, The method of achieving network security situation awareness based on the overall network situation index includes: Based on the comparison results of the overall network situation index and the judgment threshold, firewall policy blocking instructions are issued, the traffic filtering opening of the core switch is adjusted, and the packet auditing depth of the security gateway is improved.
9. The knowledge graph-based network security situation awareness method according to claim 1, characterized in that, The value of the mutation gain coefficient is... .
10. The knowledge graph-based network security situation awareness method according to claim 3, characterized in that, The structural complexity compensation term takes the value of .
Citation Information
Patent Citations
Graph-based network security event modeling method and system
CN120915582A
Industrial internet attack and defense situation and risk early warning perception method
CN121217376A
Network security situation adaptive active defense system and method
WO2023077617A1