基于知识图谱的网络安全态势感知方法

By using a knowledge graph-based approach, the structure of the topological relationship graph is obtained and the threat spread intensity is calculated. Combined with an adaptive suppression mechanism, this solves the problem of quantitative assessment of network security situational awareness in existing technologies, and enables real-time response to network threats and dynamic adjustment of resources.

CN121887508BActive Publication Date: 2026-07-17SHANDONG ZHENGZHOU INFORMATION TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANDONG ZHENGZHOU INFORMATION TECHNOLOGY CO LTD
Filing Date
2026-01-21
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing network security situational awareness technologies are unable to quantitatively assess the spread intensity of security threats among topologically related nodes, and are susceptible to baseline drift interference caused by fluctuations in business load, resulting in false alarms, delayed response to sudden threats, and imbalance in the allocation of protection resources.

Method used

A knowledge graph-based approach is adopted to obtain multi-source network traffic data sequences, extract the topology graph structure, calculate the threat spread intensity, and use an adaptive suppression mechanism to obtain compensation correction values. Based on the overall network situation index, network security situation awareness is realized, and closed-loop control is executed.

Benefits of technology

It effectively assesses the instantaneous outbreak characteristics of network threats, reduces the imbalance in the allocation of protection resources, and improves the response speed to sudden threats and the dynamic adaptability of the protection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887508B_ABST
    Figure CN121887508B_ABST
Patent Text Reader

Abstract

本发明属于信息安全数据处理技术领域,具体涉及基于知识图谱的网络安全态势感知方法,包括:提取网络流量数据中的实体交互逻辑,构建拓扑关联图结构;基于活跃路径的告警权重、连接紧密度及节点总数,获取威胁扩散强度;利用饱和控制函数,根据实时背景流量载荷与历史平均安全基准流量获取补偿修正值,实现对业务波动产生基准漂移的自适应抑制;基于补偿修正值与扩散强度差值,结合突变增益获取全网态势指数,并执行防火墙封禁及设备参数调节的闭环自适应控制。本发明解决了现有技术难以评估威胁扩散强度且易受业务波动干扰产生虚警的问题,实现了对网络威胁瞬时爆发特征的捕捉与资源的分配。
Need to check novelty before this filing date? Find Prior Art