Network security early warning method and system based on big data
By building a network security early warning system and using traffic analysis models to monitor and analyze data traffic, the problem of traditional systems being unable to identify hidden attacks has been solved, achieving more efficient network security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANXI NORMAL UNIV
- Filing Date
- 2024-11-13
- Publication Date
- 2026-05-15
AI Technical Summary
Existing network security protection systems are unable to identify network attacks hidden in normal network data, leading to frequent network security incidents and a low level of security.
A network security early warning system is built, which uses network traffic monitoring stations, IoT node devices, response workstations and back-end early warning workstations to monitor and analyze data traffic using a trained traffic analysis model, so as to achieve timely isolation and early warning of abnormal data traffic.
It has raised the level of cybersecurity early warning, reduced the occurrence of cybersecurity incidents, and enhanced the ability to identify and handle unknown cyberattacks.
Smart Images

Figure CN122053092A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, and in particular relates to a network security early warning method and system based on big data. Background Technology
[0002] With the advancement of technology and the continuous development of the internet, people's lifestyles have been greatly changed, providing immense convenience. The internet has played an irreplaceable role in the long-term development of society and the economy. However, with the rapid development of the internet, cybersecurity incidents are also emerging one after another, such as hacker attacks and the leakage of customer information. In order to reduce or even avoid the occurrence of insecure network phenomena, various network security devices are constantly emerging to ensure the security and reliability of the internet.
[0003] However, due to the rapid development of existing network attack technologies, traditional network security protection systems can only intercept and filter known network attack data. Some network attack data is hidden in normal network data, which traditional network security protection systems cannot identify and process, thus causing network security incidents. Summary of the Invention
[0004] The purpose of this invention is to provide a network security early warning method and system based on big data. By building a network security early warning system, the system monitors the data traffic entering IoT node devices and uses a trained traffic analysis model to provide early warning responses, thus solving the problems of existing network security protections being unable to identify and process data and having low network security levels.
[0005] To solve the above-mentioned technical problems, the present invention is achieved through the following technical solution: This invention relates to a network security early warning method based on big data, comprising the following steps: Step S1: Build a network security early warning system; wherein the network security early warning system includes a network traffic monitoring station, IoT node devices, a response workstation, and a background early warning workstation; Step S2: The network traffic monitoring station monitors the data traffic flowing into the detection domain; Step S3: The IoT node devices analyze the data traffic collected by the network traffic monitoring station and the data traffic received by other node devices; Step S4: The response workstation receives abnormal data traffic reported by the IoT node device and promptly isolates and blocks the IoT node device; Step S5: The response workstation sends the response result to the background early warning workstation; Step S6: The background early warning workstation issues an early warning based on the response results.
[0006] As a preferred technical solution, in step S2, the network traffic monitoring station extracts device and traffic information variables from the management object information database by installing traffic monitoring devices in the traffic links that need to be monitored; the specific information of the network traffic includes the number of input bytes, the number of input non-broadcast packets, the number of input broadcast packets, the number of input dropped packets, the number of input error packets, the number of input unknown protocol packets, the number of output bytes, the number of output non-broadcast packets, the number of output broadcast packets, the number of output dropped packets, the number of output error packets, and the output leader.
[0007] As a preferred technical solution, in step S3, the data traffic collected by the network traffic monitoring station needs to be cleaned, segmented, labeled with parts of speech, and have word weights set in sequence, and the processed data traffic information is stored in the database.
[0008] As a preferred technical solution, the process for the IoT node device to analyze data traffic in step S3 is as follows: Step S31: Obtain a large amount of network traffic data information through big data; Step S32: Extract time-series features from the inbound and outbound traffic data, and divide the extracted feature data into training and testing sets; Step S33: Build a convolutional neural network and initialize the convolutional neural network model parameters; Step S34: Input the training set into the convolutional neural network model for training, and continuously optimize the network model; Step S35: Input the test set into the convolutional neural network model for testing to obtain the traffic analysis model; Step S36: Input the collected data traffic into the trained traffic analysis model and import the output results into the classifier; Step S37: The classifier determines whether the data traffic is abnormal and classifies the warning level.
[0009] As a preferred technical solution, in step S4, the response workstation has a built-in response scheme database. When the IoT node device reports abnormal data traffic, the type and category of the abnormal data traffic are obtained. The type and category of the abnormal data traffic are matched with the response scheme database. If the match is successful, the scheme in the response scheme database is directly called and executed. If the match fails, it means that the type and category of the abnormal data traffic is appearing for the first time. The type and category of the abnormal data traffic are then sent to the background early warning workstation, where staff manually handle the IoT node device and store the handling scheme in the response scheme database.
[0010] As a preferred technical solution, in step S6, the background early warning workstation generates a danger alarm interface for visual display of the topology map of IoT node devices, analysis results, and network danger alarms.
[0011] This invention is a network security early warning system based on big data, including a network traffic monitoring station, IoT node devices, a response workstation, and a background early warning workstation; The network traffic monitoring station uses firewalls and intrusion detection systems to monitor data traffic flowing into the detection domain; The IoT node device is used to analyze the data traffic collected by the network traffic monitoring station and the data traffic received by other node devices; The response workstation is used to isolate and block abnormal data traffic reported by IoT node devices; The background early warning workstation is used to issue early warnings based on the response results.
[0012] As a preferred technical solution, the network traffic monitoring station performs anomaly analysis on the collected data and the data received from other node devices, including the IoT node devices performing anomaly analysis on the collected data and the data received from other node devices based on the built-in traffic analysis model.
[0013] As a preferred technical solution, the IoT node device periodically collects data and receives information transmitted by other node devices, including collecting data within a periodic time period and receiving information transmitted by other node devices during other time periods outside the periodic time period.
[0014] The present invention has the following beneficial effects: This invention improves the level of network security early warning by building a network security early warning system to monitor data traffic entering IoT node devices and using a trained traffic analysis model for early warning response, thereby reducing the occurrence of network security incidents.
[0015] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a flowchart of a network security early warning method based on big data according to the present invention; Figure 2 This is a schematic diagram of the structure of a network security early warning system based on big data according to the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Furthermore, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0020] To make the purpose, technical solution, and advantages of this application clearer, the following will be described in conjunction with the appendix. Figure 1 The embodiments of this application will be described in further detail.
[0021] To make the purpose, technical solution, and advantages of this application clearer, the following description is provided in conjunction with the appendix. Figure 1-2 The present application will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the application.
[0022] Example 1 Please see Figure 1 As shown, this invention is a network security early warning method based on big data, comprising the following steps: Step S1: Build a network security early warning system; the network security early warning system includes a network traffic monitoring station, IoT node devices, a response workstation, and a background early warning workstation; Step S2: The network traffic monitoring station monitors the data traffic flowing into the detection domain; Step S3: The IoT node devices analyze the data traffic collected by the network traffic monitoring station and the data traffic received by other node devices; Step S4: The response workstation receives abnormal data traffic reported by the IoT node device and promptly isolates and blocks the IoT node device; Step S5: The response workstation sends the response result to the background early warning workstation; Step S6: The background early warning workstation issues an early warning based on the response results.
[0023] In step S2, the network traffic monitoring station extracts device and traffic information variables from the management object information database by installing traffic monitoring devices in the traffic links that need to be monitored. The specific information of network traffic includes the number of input bytes, the number of input non-broadcast packets, the number of input broadcast packets, the number of input dropped packets, the number of input error packets, the number of input unknown protocol packets, the number of output bytes, the number of output non-broadcast packets, the number of output broadcast packets, the number of output dropped packets, the number of output error packets, and the output leader.
[0024] In step S3, the data traffic collected by the network traffic monitoring station needs to be cleaned, segmented, labeled with parts of speech, and have word weights set in sequence, and the processed data traffic information is stored in the database.
[0025] In step S3, the process of IoT node devices analyzing data traffic is as follows: Step S31: Obtain a large amount of network traffic data information through big data; Step S32: Extract time-series features from the inbound and outbound traffic data, and divide the extracted feature data into training and testing sets; Step S33: Build a convolutional neural network and initialize the convolutional neural network model parameters; Step S34: Input the training set into the convolutional neural network model for training, and continuously optimize the network model; Step S35: Input the test set into the convolutional neural network model for testing to obtain the traffic analysis model; Step S36: Input the collected data traffic into the trained traffic analysis model and import the output results into the classifier; Step S37: The classifier determines whether the data traffic is abnormal and classifies the warning level.
[0026] In step S4, the response workstation has a built-in response scheme database. When the IoT node device reports abnormal data traffic, it obtains the type and category of the abnormal data traffic. It then matches the type and category of the abnormal data traffic with the response scheme database. If the match is successful, it directly calls the scheme in the response scheme database for execution. If the match fails, it indicates that the type and category of the abnormal data traffic is appearing for the first time. In this case, the type and category of the abnormal data traffic are sent to the background early warning workstation, where staff manually handle the IoT node device and store the handling scheme in the response scheme database.
[0027] In step S6, the background early warning workstation generates a danger alarm interface to visualize the topology map of IoT node devices, analysis results, and network danger alarms.
[0028] Example 2 See Figure 2 As shown, this invention is a network security early warning system based on big data, which can be used to execute the method described in Embodiment 1 of this invention. It includes: a network traffic monitoring station, IoT node devices, a response workstation, and a background early warning workstation. The network traffic monitoring station uses firewalls and intrusion detection systems to monitor data traffic flowing into the detection domain. The IoT node devices are used to analyze the data traffic collected by the network traffic monitoring station and the data traffic received by other node devices. The response workstation is used to isolate and block abnormal data traffic reported by the IoT node devices. The background early warning workstation is used to issue early warnings based on the response results.
[0029] The network traffic monitoring station performs anomaly analysis on the collected data and the data received from other node devices. This includes IoT node devices performing anomaly analysis on the collected data and the data received from other node devices based on their built-in traffic analysis models.
[0030] IoT node devices periodically collect data and receive information transmitted by other node devices, including collecting data within a periodic time period and receiving information transmitted by other node devices at other time periods outside the periodic time period.
[0031] Cybersecurity risk warning is a crucial measure that helps organizations and individuals identify and prevent cybersecurity threats in a timely manner. Here are some common practices for cybersecurity risk warning: I. Conduct Risk Assessment First, conduct a comprehensive risk assessment to determine the types and levels of potential cybersecurity threats facing the organization or individual. This involves a thorough scan and evaluation of the network system's security architecture, network topology, applications, and hardware vulnerabilities, as well as an examination of the organization's or individual's cybersecurity policies and practices, to identify and assess potential risks.
[0032] II. Establish a security incident monitoring system Establish a security incident monitoring and early warning system, including tools and technologies such as log auditing, intrusion detection systems (IDS), and intrusion prevention systems (IPS). These systems can monitor and record network activity and analyze and identify potential threats. Simultaneously, establish a real-time response mechanism to take timely and necessary countermeasures to isolate and prevent network attacks.
[0033] III. Regular drills and tests Regularly conduct cybersecurity drills and tests, including simulations of cyberattacks and incident response exercises. These drills and tests allow for the assessment of the effectiveness and reliability of an organization's or individual's cybersecurity protection, and the timely identification and resolution of potential vulnerabilities and issues.
[0034] IV. Timely update and patch security vulnerabilities Timely updating and patching of security vulnerabilities in network systems and applications is a crucial step. Pay close attention to security updates and patches released by software and hardware vendors, and promptly install and apply these patches to reduce the risk of network system attacks.
[0035] V. Strengthen employee training and education Strengthen employees' cybersecurity awareness training and education so that they understand common cybersecurity risks and threats, master basic security protection knowledge and skills, and comply with the cybersecurity policies and regulations formulated by the organization or individuals.
[0036] VI. Collaborating with the Cybersecurity Community Establish connections and collaborations with the cybersecurity community to obtain the latest information and early warnings on cybersecurity threats and risks in a timely manner, share and exchange security experiences and technologies, and participate in relevant security research and collaborative projects.
[0037] It is worth noting that the various units included in the above system embodiments are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.
[0038] Furthermore, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware, and the corresponding program can be stored in a computer-readable storage medium.
[0039] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. A network security early warning method based on big data, characterized in that, Includes the following steps: Step S1: Build a network security early warning system; wherein the network security early warning system includes a network traffic monitoring station, IoT node devices, a response workstation, and a background early warning workstation; Step S2: The network traffic monitoring station monitors the data traffic flowing into the detection domain; Step S3: The IoT node devices analyze the data traffic collected by the network traffic monitoring station and the data traffic received by other node devices; Step S4: The response workstation receives abnormal data traffic reported by the IoT node device and promptly isolates and blocks the IoT node device; Step S5: The response workstation sends the response result to the background early warning workstation; Step S6: The background early warning workstation issues an early warning based on the response results.
2. The network security early warning method based on big data according to claim 1, characterized in that, In step S2, the network traffic monitoring station extracts device and traffic information variables from the management object information database by installing traffic monitoring devices in the traffic links that need to be monitored. The specific information of the network traffic includes the number of input bytes, the number of input non-broadcast packets, the number of input broadcast packets, the number of input dropped packets, the number of input error packets, the number of input unknown protocol packets, the number of output bytes, the number of output non-broadcast packets, the number of output broadcast packets, the number of output dropped packets, the number of output error packets, and the output leader.
3. The network security early warning method based on big data according to claim 1, characterized in that, In step S3, the data traffic collected by the network traffic monitoring station needs to be cleaned, segmented, labeled with parts of speech, and weighted with words in sequence, and the processed data traffic information is stored in the database.
4. The network security early warning method based on big data according to claim 1, characterized in that, In step S3, the process by which the IoT node device analyzes data traffic is as follows: Step S31: Obtain a large amount of network traffic data information through big data; Step S32: Extract time-series features from the inbound and outbound traffic data, and divide the extracted feature data into training and testing sets; Step S33: Build a convolutional neural network and initialize the convolutional neural network model parameters; Step S34: Input the training set into the convolutional neural network model for training, and continuously optimize the network model; Step S35: Input the test set into the convolutional neural network model for testing to obtain the traffic analysis model; Step S36: Input the collected data traffic into the trained traffic analysis model and import the output results into the classifier; Step S37: The classifier determines whether the data traffic is abnormal and classifies the warning level.
5. The network security early warning method based on big data according to claim 1, characterized in that, In step S4, the response workstation has a built-in response scheme database. When the IoT node device reports abnormal data traffic, it obtains the type and category of the abnormal data traffic. It matches the type and category of the abnormal data traffic with the response scheme database. If the match is successful, it directly calls the scheme in the response scheme database for execution. If the match fails, it means that the type and category of the abnormal data traffic is appearing for the first time. In this case, it sends the type and category of the abnormal data traffic to the background early warning workstation, where staff manually handle the IoT node device and store the handling scheme in the response scheme database.
6. The network security early warning method based on big data according to claim 1, characterized in that, In step S6, the background early warning workstation generates a danger alarm interface to visualize the topology map of IoT node devices, analysis results, and network danger alarms.
7. A big data-based network security early warning system, comprising a network traffic monitoring station, IoT node devices, a response workstation, and a background early warning workstation, characterized in that: The network traffic monitoring station uses firewalls and intrusion detection systems to monitor data traffic flowing into the detection domain; The IoT node device is used to analyze the data traffic collected by the network traffic monitoring station and the data traffic received by other node devices; The response workstation is used to isolate and block abnormal data traffic reported by IoT node devices; The background early warning workstation is used to issue early warnings based on the response results.
8. A network security early warning system based on big data according to claim 7, characterized in that, The network traffic monitoring station performs anomaly analysis on the collected data and data received from other node devices, including the IoT node devices performing anomaly analysis on the collected data and data received from other node devices based on the built-in traffic analysis model.
9. A network security early warning system based on big data according to claim 7, characterized in that, The IoT node device periodically collects data and receives information transmitted by other node devices, including collecting data within a periodic time period and receiving information transmitted by other node devices during other time periods outside the periodic time period.