Intelligent Security Situation Awareness Method and System Based on Multidimensional Data Analysis

The intelligent security situation awareness method, which utilizes multi-dimensional data analysis, solves the problem of the disconnect between attack and defense drills and the actual network environment. It enables timely identification and proactive defense against complex and new types of attacks, thereby improving the efficiency of network security protection.

CN122137640APending Publication Date: 2026-06-02ZHEJIANG CHUANGZHI TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG CHUANGZHI TECH CO LTD
Filing Date
2026-03-11
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In the existing network security defense system, attack and defense drills are disconnected from the actual network environment, resulting in the inability to identify complex new attacks in a timely manner, which affects the accuracy and initiative of security situation awareness.

Method used

The intelligent security situation awareness method based on multidimensional data analysis includes classifying, filtering and merging attack event databases of wireless communication networks, constructing virtual communication networks for attack drills, obtaining multidimensional drill datasets, performing attack and defense situation fusion modeling, and introducing a security situation assessment index system for security situation awareness and management.

Benefits of technology

It has improved attack identification capabilities, enhanced the practicality of attack and defense drills, improved the efficiency of network security protection, and enabled timely identification and proactive defense against complex and new types of attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137640A_ABST
    Figure CN122137640A_ABST
Patent Text Reader

Abstract

This application provides an intelligent security situation awareness method and system based on multidimensional data analysis, relating to the field of network security technology. The method includes: classifying, filtering, and fusing attack event databases of wireless communication networks to determine multidimensional attack drill schemes; conducting attack drills on virtual communication networks according to the multidimensional attack drill schemes; performing attack and defense situation fusion modeling based on the multidimensional drill dataset to obtain a multidimensional drill attack and defense confrontation model; introducing a security situation assessment index system to conduct security situation awareness on the multidimensional drill attack and defense confrontation model, constructing a multidimensional drill security situation profile; and performing enhanced security management of the wireless communication network. This application solves the technical problem in existing technologies where the disconnect between attack and defense drills and the actual network environment leads to the inability to timely identify complex new attacks, affecting the accuracy of security situation awareness. It comprehensively improves attack identification capabilities, enhances the practicality of attack and defense drills, and improves network security protection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, specifically to an intelligent security situation awareness method and system based on multidimensional data analysis. Background Technology

[0002] In the current network security defense system, there is a significant disconnect between attack and defense drills and actual production network environments. Traditional attack and defense drills are mostly conducted in static, isolated test environments, which make it difficult to accurately reproduce the complex business logic, dynamic traffic, and specific asset configurations in real networks. As a result, the defense strategies validated in these drills often fail when faced with complex and covert new attacks in real-world scenarios due to environmental differences and background noise, thus failing to effectively respond to actual attacks. The current network security protection system lacks a real-time security situation assessment mechanism, typically responding only after an attack has occurred. This fails to achieve proactive early warning and real-time defense throughout the entire attack process, resulting in a delayed response. Overall security capabilities remain in a passive state that is difficult to measure and cannot be optimized in a closed loop, severely restricting the accuracy and proactivity of security situation awareness.

[0003] In summary, existing technologies suffer from a technical problem: the disconnect between attack and defense drills and actual network environments makes it impossible to identify complex new attacks in a timely manner, thus affecting the accuracy of security situation awareness. Summary of the Invention

[0004] The purpose of this application is to provide an intelligent security situation awareness method and system based on multi-dimensional data analysis, in order to solve the technical problem in the prior art that the disconnect between attack and defense drills and the actual network environment leads to the inability to identify complex new attacks in a timely manner, thus affecting the accuracy of security situation awareness.

[0005] To achieve the above objectives, this application provides an intelligent security situation awareness method and system based on multidimensional data analysis.

[0006] Firstly, this application provides an intelligent security situation awareness method based on multidimensional data analysis. This method is implemented through an intelligent security situation awareness system based on multidimensional data analysis. The method includes: classifying, filtering, and fusing attack event databases of wireless communication networks to determine multidimensional attack drill schemes; constructing a virtual communication network and conducting attack drills on the virtual communication network according to the multidimensional attack drill schemes to obtain a multidimensional drill dataset; performing attack and defense situation fusion modeling based on the multidimensional drill dataset to obtain a multidimensional drill attack and defense confrontation model; introducing a security situation assessment index system to perform security situation awareness on the multidimensional drill attack and defense confrontation model to construct a multidimensional drill security situation profile; and performing security enhancement management on the wireless communication network based on the multidimensional drill security situation profile.

[0007] Optionally, attack objectives are categorized based on the attack event database to obtain intrusion control attack event areas, data theft attack event areas, business disruption attack event areas, and deception manipulation attack event areas; support cleansing and disruption filtering are performed on the intrusion control attack event areas to obtain intrusion control drill schemes; support cleansing and disruption filtering are performed on the data theft attack event areas to obtain data theft drill schemes; support cleansing and disruption filtering are performed on the business disruption attack event areas to obtain business disruption drill schemes; support cleansing and disruption filtering are performed on the deception manipulation attack event areas to obtain deception manipulation drill schemes; and the intrusion control drill scheme, data theft drill scheme, business disruption drill scheme, and deception manipulation drill scheme are output as the multi-dimensional attack drill scheme.

[0008] Optionally, attack parameter features are extracted based on the intrusion control attack event area to obtain multiple intrusion attack feature sequences; the frequency of each intrusion attack feature sequence appearing in the intrusion control attack event area is counted to obtain the support of each intrusion attack; based on the support of each intrusion attack, the multiple intrusion attack feature sequences are cleaned according to a predetermined intrusion attack support to establish an intrusion attack support space; the destructiveness of the intrusion attack support space is evaluated based on the intrusion control attack event area to obtain the destructiveness of each intrusion attack; based on the destructiveness of each intrusion attack, the intrusion attack support space is filtered according to a predetermined intrusion attack destructiveness to establish an intrusion attack candidate space; attack parameters are fused based on the intrusion attack candidate space to generate the intrusion control drill plan.

[0009] Optionally, a multidimensional dataset of the wireless communication network is obtained, which includes network topology data, communication link characteristic data, protocol interaction data, service bearer relationship data, and network operation status data; dynamic modeling is performed based on the multidimensional dataset to generate the virtual communication network.

[0010] Optionally, an intrusion control exercise data set is extracted from the multidimensional exercise dataset; multimodal feature recognition is performed on the intrusion control exercise data set to obtain attack-side behavior feature sequences, defense-side response feature sequences, and protected asset feature sequences; time series alignment and event correlation are performed on the attack-side behavior feature sequences and the defense-side response feature sequences to obtain the intrusion attack-defense interaction situation distribution; three-way coupling modeling is performed based on the protected asset feature sequences and the intrusion attack-defense interaction situation distribution to obtain the intrusion exercise attack-defense confrontation model; based on the intrusion exercise attack-defense confrontation model, attack-defense situation fusion modeling is further performed on the multidimensional exercise dataset to generate the multidimensional exercise attack-defense confrontation model.

[0011] Optionally, the security situation assessment indicator system includes a primary assessment indicator layer and a secondary assessment indicator layer. The primary assessment indicator layer includes multiple primary assessment indicators, such as attack threat level, defense effectiveness, and asset risk level. The secondary assessment indicator layer includes attack threat level indicators, defense effectiveness indicators, and asset risk level indicators. The attack threat level indicators include attack frequency changes, attack intensity changes, attack coverage, and attack persistence. The defense effectiveness indicators include defense response latency, defense interception success rate, defense resource utilization level, and attack attribution accuracy. The asset risk level indicators include asset exposure level, asset importance, and asset exposure scope.

[0012] Optionally, key elements of the intrusion drill attack-defense confrontation model are identified based on the secondary evaluation index layer to obtain an intrusion drill element vector set, which includes intrusion attack threat element vectors, intrusion defense element vectors, and intrusion asset risk element vectors. A multi-dimensional security situation assessment is then performed on the intrusion drill element vector set based on the primary evaluation index layer to obtain the intrusion security situation assessment result. Differential identification is then performed on the intrusion security situation assessment result based on the expected security situation result to obtain the intrusion security situation differential result. An intrusion drill security situation profile is constructed based on the intrusion drill attack-defense confrontation model, the intrusion security situation assessment result, and the intrusion security situation differential result. Based on the intrusion drill security situation profile, security situation awareness is further performed on the multi-dimensional drill attack-defense confrontation model according to the security situation assessment index system to generate the multi-dimensional drill security situation profile.

[0013] Optionally, a big data retrieval is performed based on the first-level assessment indicator layer to obtain attack threat level assessment records, defense effectiveness assessment records, and asset risk level assessment records; an attack threat level assessment model is trained based on the attack threat level assessment records; a defense effectiveness assessment model is trained based on the defense effectiveness assessment records; and an asset risk level assessment model is trained based on the asset risk level assessment records; the attack threat level assessment model, the defense effectiveness assessment model, and the asset risk level assessment model are connected as parallel nodes to generate a multi-dimensional security situation assessment model; the intrusion drill element vector set is input into the multi-dimensional security situation assessment model, and the intrusion security situation assessment result is output.

[0014] Optionally, a virtual-real linkage gateway is deployed between the virtual communication network and the wireless communication network to link the virtual and real states and isolate attacks on the virtual communication network and the wireless communication network.

[0015] Secondly, this application also provides an intelligent security situation awareness system based on multidimensional data analysis, used to execute the intelligent security situation awareness method based on multidimensional data analysis as described in the first aspect. The intelligent security situation awareness system based on multidimensional data analysis includes: a classification, filtering, and fusion module for classifying, filtering, and fusing attack event databases of wireless communication networks to determine multidimensional attack drill schemes; an attack drill module for constructing a virtual communication network and conducting attack drills on the virtual communication network according to the multidimensional attack drill scheme to obtain a multidimensional drill dataset; an attack-defense situation fusion and modeling module for performing attack-defense situation fusion modeling based on the multidimensional drill dataset to obtain a multidimensional drill attack-defense confrontation model; a security situation awareness module for introducing a security situation assessment index system to perform security situation awareness on the multidimensional drill attack-defense confrontation model and construct a multidimensional drill security situation profile; and a security enhancement management module for performing security enhancement management on the wireless communication network based on the multidimensional drill security situation profile.

[0016] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0017] By classifying, filtering, and integrating attack event databases for wireless communication networks, a multi-dimensional attack drill scheme is determined. A virtual communication network is constructed, and attack drills are conducted on this virtual network according to the multi-dimensional attack drill scheme, obtaining a multi-dimensional drill dataset. Based on this dataset, an attack-defense situation fusion model is created, resulting in a multi-dimensional attack-defense adversarial model. A security situation assessment index system is introduced to assess the security situation of this model, constructing a multi-dimensional security situation profile. Finally, security enhancement management is implemented for the wireless communication network based on this profile. In other words, by classifying, filtering, and integrating attack event databases, a more comprehensive attack drill scheme is established. A virtual communication network is constructed, and multi-dimensional attack drills are conducted. The acquired multi-dimensional drill dataset is used for attack-defense situation fusion modeling. A security situation assessment index system is introduced for security situation awareness. Security enhancement management is implemented for the wireless communication network, comprehensively improving attack identification capabilities, enhancing the practicality of attack-defense drills, and improving network security protection efficiency.

[0018] The above description is merely an overview of the technical solution of this application. To better understand the technical means of this application and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of this application more apparent, specific embodiments of this application are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent through the following description. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0020] Figure 1 This is a flowchart illustrating the intelligent security situation awareness method based on multidimensional data analysis proposed in this application.

[0021] Figure 2 This is a schematic diagram of the intelligent security situation awareness system based on multidimensional data analysis proposed in this application.

[0022] Figure labeling: Classification and filtering fusion module 11, attack drill module 12, attack and defense situation fusion modeling module 13, security situation awareness module 14, security enhancement management module 15. Detailed Implementation

[0023] This application provides an intelligent security situation awareness method and system based on multidimensional data analysis. It addresses the technical problem in existing technologies where the disconnect between attack and defense drills and the actual network environment leads to the inability to promptly identify complex new attacks, thus affecting the accuracy of security situation awareness. By classifying, filtering, and integrating attack event databases, a more comprehensive attack drill scheme is established. A virtual communication network is constructed and multidimensional attack drills are conducted. The acquired multidimensional drill dataset is used for attack and defense situation fusion modeling. A security situation assessment index system is introduced for security situation awareness, and enhanced security management of the wireless communication network is implemented. This comprehensively improves attack identification capabilities, enhances the practicality of attack and defense drills, and improves the efficiency of network security protection.

[0024] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. It should be understood that this application is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application. It should also be noted that, for ease of description, only the parts related to this application are shown in the accompanying drawings, not all of them.

[0025] Example 1, please refer to the appendix. Figure 1 This application provides an intelligent security situation awareness method based on multidimensional data analysis. The method is applied to an intelligent security situation awareness system based on multidimensional data analysis, and specifically includes the following steps:

[0026] The attack event database of wireless communication networks is classified, filtered, and integrated to determine a multi-dimensional attack exercise plan.

[0027] Furthermore, this application also includes the following steps: classifying attack objectives according to the attack event database to obtain intrusion control attack event areas, data theft attack event areas, business disruption attack event areas, and deception manipulation attack event areas; performing support cleaning and disruption filtering fusion according to the intrusion control attack event areas to obtain intrusion control drill schemes; performing support cleaning and disruption filtering fusion according to the data theft attack event areas to obtain data theft drill schemes; performing support cleaning and disruption filtering fusion according to the business disruption attack event areas to obtain business disruption drill schemes; performing support cleaning and disruption filtering fusion according to the deception manipulation attack event areas to obtain deception manipulation drill schemes; and outputting the intrusion control drill scheme, the data theft drill scheme, the business disruption drill scheme, and the deception manipulation drill scheme as the multi-dimensional attack drill scheme.

[0028] Furthermore, this application also includes the following steps: extracting attack parameter features based on the intrusion control attack event area to obtain multiple intrusion attack feature sequences; calculating the frequency of each intrusion attack feature sequence appearing in the intrusion control attack event area to obtain the support of each intrusion attack; cleaning the multiple intrusion attack feature sequences based on the support of each intrusion attack according to a predetermined intrusion attack support to establish an intrusion attack support space; evaluating the destructiveness of the intrusion attack support space based on the intrusion control attack event area to obtain the destructiveness of each intrusion attack; filtering the intrusion attack support space based on the destructiveness of each intrusion attack according to a predetermined intrusion attack destructiveness to establish an intrusion attack candidate space; and fusing attack parameters based on the intrusion attack candidate space to generate the intrusion control drill plan.

[0029] Specifically, by analyzing a database of attack events in wireless communication networks, four attack zones are identified: intrusion control attack zone, data theft attack zone, service disruption attack zone, and deception manipulation attack zone. Each zone represents a set of attack events of different types within the network, primarily categorized based on the attack objective. Using natural language processing techniques and a predefined rule base of attack objective keywords, events containing keywords such as privilege escalation and remote execution are classified as intrusion control; those involving the extraction of unauthorized data are classified as data theft. Semantic analysis is performed on each attack event description in the database, automatically assigning it to one of these zones, thus forming a preliminary classification dataset.

[0030] The attack event database for wireless communication networks is a structured database where each record describes a past or potential attack instance on a wireless communication network. Records typically include information such as the attack time, techniques used, attack flow, target system, and impact. Sources include public vulnerability databases, threat reports, internal security incident logs, and research papers. Intrusion control attacks aim to gain unauthorized access and control over target system or network resources, such as exploiting vulnerabilities to gain administrator privileges or deploying backdoors; data theft attacks aim to illegally obtain or steal sensitive data in transmission or storage, such as man-in-the-middle attacks on communication content or database penetration; business disruption attacks aim to interfere with, interrupt, or degrade the normal operation of a target network or service, such as distributed denial-of-service attacks or signaling storm attacks; and deception and manipulation attacks aim to forge identities, data, or states for fraud or misleading purposes, such as fake base station attacks, GPS spoofing, and data tampering.

[0031] Based on the data characteristics of each attack event area, targeted attack drill plans are generated through support-based cleaning and damage-based filtering. Support is the frequency of an attack signature sequence appearing in a certain type of attack event area, measuring the prevalence or commonality of the attack method. Support cleaning involves filtering out attack signature sequences with sufficiently high frequency based on a preset support threshold, eliminating those that are occasional, outdated, or very niche, ensuring the drill plan focuses on mainstream threats. Damage is a quantitative assessment of the potential harm caused by an attack event. Assessment dimensions may include the extent of data leakage, data tampering, service interruption, the number of affected users or devices, and the difficulty of recovery. Damage filtering involves further filtering attack methods with severe harm from the support-cleansed attack signatures based on a preset damage threshold, ensuring the drill plan targets high-risk threat scenarios.

[0032] Deep analysis of each event record within the intrusion control attack event area utilizes a feature extraction engine integrating natural language processing and regular expressions to automatically identify and populate predefined parameter templates, such as attack stage, exploited vulnerability number, protocol port used, target asset type, attack payload, and legacy items. This transforms unstructured text into a standardized sequence of intrusion attack features. Attack parameter feature extraction identifies and extracts key information of predefined categories from unstructured or semi-structured attack event description text, converting it into machine-readable standardized fields. For example, from the event description of an attacker exploiting the CVE2021 vulnerability to achieve remote code execution and install a backdoor program on a Windows system via the SMB protocol, the following parameters can be extracted: attack stage: vulnerability exploitation; exploited vulnerability: CVE2021; protocol: SMB; target system: Windows; subsequent action: backdoor installation. The intrusion attack feature sequence is a set of attack features extracted from the attack event and arranged chronologically.

[0033] Frequency statistics are performed on all generated intrusion attack signature sequences. The support score for each intrusion attack is calculated by dividing the number of occurrences of each sequence by the total number of events in the intrusion control attack event area, quantifying the prevalence or popularity of that specific attack method among similar attacks. The predetermined intrusion attack support score is a pre-set percentage threshold, such as 5% or 10%, used to determine whether an attack signature sequence is common enough to be retained. This is an adjustable parameter used to control the breadth of coverage of mainstream attacks in the exercise plan. Based on the predetermined intrusion attack support score, all low-frequency or long-tail attack sequences with support scores below the threshold are automatically removed. The remaining sequences constitute an intrusion attack support space focused on mainstream methods, representing a library of commonly used intrusion control attack methods in the current environment.

[0034] The intrusion attack support space is assessed for damage based on the intrusion control attack event zone. This involves quantifying the potential harm caused by attack characteristic sequences, considering not only the severity of technical vulnerabilities but also factors such as attack reachability, scope of impact, likelihood of business interruption, data leakage risk, and recovery costs. A weighted scoring model is used to calculate a comprehensive damage score. The base CVSS score of vulnerabilities in the captured sequence is extracted and weighted according to internally defined asset importance levels and business continuity impact coefficients. For example, a remote execution vulnerability targeting a core database server will have a significantly higher damage score than the same vulnerability targeting a test server. After calculation, based on a preset damage threshold (e.g., 0.75), all sequences with scores greater than or equal to the predetermined intrusion attack damage score are selected, forming an intrusion attack candidate space containing highly universal and highly harmful attack techniques. The predetermined intrusion attack damage score is a pre-set damage score threshold used to determine whether the harm of an attack method reaches a severity level. This is an adjustable parameter used to ensure that exercises focus on high-risk threats. The intrusion attack candidate space is a set of attack feature sequences with a damage score of not less than a predetermined threshold, which are further filtered from the intrusion attack support space. It represents common and high-risk intrusion control attack methods and is the core material for building high-value drill schemes.

[0035] Analyze the logical relationships between sequences in the intrusion attack candidate space, combine, expand and script the attacker's tactical logic in actual combat, combine the connectable technologies to generate a comprehensive attack exercise plan, simulate how a real attacker connects multiple technologies to form a complete attack chain from initial intrusion to establishing persistent control.

[0036] For example, from the categorized intrusion control attack event area, a subset of intrusion attacks targeting enterprise wireless LANs and VPNs within the past year was selected, totaling 843 valid event records. For an event described as an attacker successfully logging into the SSL-VPN portal of a FortiGate device used by the company's VPN and then exploiting a CVE2018 path traversal vulnerability to download system configuration files, the sequence was extracted: initial access was cracking, target was the VPN device, protocol was SSL-VPN, vulnerability exploited was CVE2018, attack action was path traversal, and configuration file acquisition. Support statistics showed that sequence S1, cracking weak passwords for VPN / portal login, appeared 127 times (support = 127 / 843); sequence S2, exploiting the CVE2018 vulnerability, appeared 89 times (support = 89 / 843); and sequence S3, exploiting a hard-coded backdoor in a discontinued IP camera, appeared 4 times (support = 4 / 843). A predetermined support threshold of 5% was set, retaining sequences with support ≥5% such as S1 and S2, and removing low-frequency sequences such as S3. After cleaning, the intrusion attack support space contained 68 characteristic sequences. Sequence S1, although technically simple to crack, targets a core VPN entry point; a breach would have a significant impact. Based on the CVSS score, the vulnerability might be N / A, but its business impact is high, resulting in a comprehensive damage score of 6.8. Sequence S2, with a base score of 9.8 for CVE2018 (severe), could directly lead to sensitive information leakage, paving the way for subsequent attacks and affecting numerous devices, resulting in a comprehensive damage score of 9.2. Sequence S4 utilizes a low-risk SQL injection vulnerability in an OA system, with 8% support, but its CVSS score is only 4.3, and the target system is not core, resulting in a comprehensive damage score of only 3.5. The predetermined damage threshold was set at 7.0. S2 was retained, while S1 and S4 were removed, resulting in a final intrusion attack candidate space containing 15 sequences, including S2, with a damage score ≥7.0. The candidate input space includes sequences such as S2, another lateral movement sequence with a damage level of 8.1 utilizing the SMB protocol, and a sequence with a damage level of 7.5 for creating a hidden account on a server. Identifying S2 grants initial privileges, lateral movement allows for privilege expansion, and account creation enables persistence. These are combined to generate a scenario called "Initial Intrusion and Internal Network Penetration Exercise Based on VPN Vulnerability": The attacker attempts to exploit the CVE-2018-13379 vulnerability to download the sslvpn1 file from the target VPN device (corresponding to S2); parses session credentials from the file to simulate logging into the VPN internal network; scans for live hosts and Windows machines with open port 445 on the internal network; attempts to exploit vulnerabilities such as EternalBlue or weak passwords to implant payloads into the target machine via the SMB protocol (corresponding to the lateral movement sequence); and adds a hidden administrator account on the successfully controlled host via command line (corresponding to the hidden account creation sequence).

[0037] Based on the technical correlations of sequences in the intrusion attack candidate space, they are logically linked together, and necessary reconnaissance and lateral movement steps are inserted to generate an intrusion control drill plan. This support cleaning-disruption filtering-parameter fusion process is completely repeated for the other three event areas to obtain corresponding drill plans: an intrusion control drill plan, a data theft drill plan, a service disruption drill plan, and a deception manipulation drill plan. These drill plans are then packaged and output as a multi-dimensional attack drill plan, containing multiple attack types and attack characteristic sequences, enabling comprehensive and multi-faceted simulation and drills of different types of network attacks.

[0038] By using support level scrubbing, the exercises are ensured to focus on the most common and active attack methods, avoiding wasting resources on outdated or extremely low-probability threats and keeping the exercise content synchronized with the real threat environment. Through damage level filtering, exercise resources are forcibly concentrated on high-risk attack scenarios that could cause serious business losses, ensuring that improvements in security defense capabilities directly correspond to risk reduction, achieving a risk-oriented approach to security investment. Based on the classification of attack objectives, the generated exercise schemes ensure that they cover all core adversarial dimensions such as control, data theft, sabotage, and deception, comprehensively testing and improving the network's overall defense capabilities in terms of confidentiality, integrity, availability, and realism, avoiding the one-sided defects of the protection system.

[0039] A virtual communication network is constructed, and an attack exercise is conducted on the virtual communication network according to the multi-dimensional attack exercise scheme to obtain a multi-dimensional exercise dataset.

[0040] Furthermore, this application also includes the following steps: obtaining a multidimensional dataset of the wireless communication network, the multidimensional dataset including network topology data, communication link characteristic data, protocol interaction data, service bearer relationship data, and network operation status data; and performing dynamic modeling based on the multidimensional dataset to generate the virtual communication network.

[0041] Specifically, multi-source data collection is performed on the target real wireless communication network to obtain a multidimensional dataset of the wireless communication network, including network topology data, communication link characteristic data, protocol interaction data, service bearer relationship data, and network operation status data. Wireless communication networks are communication network infrastructures that transmit data via radio waves, such as 4G / 5G cellular networks, Wi-Fi networks, and satellite communication networks, and include components such as terminal equipment, access networks, transmission networks, and core networks. Network topology data describes the physical connections and logical relationships between network devices (base stations, routers, switches, servers, etc.), often represented by a graph structure of nodes and edges; communication link characteristic data quantifies parameters describing link performance, such as bandwidth, latency, packet loss rate, signal strength, and bit error rate. Protocol interaction data refers to the format, sequence, content, and interaction status of signaling and data generated when devices in the network communicate according to communication protocols such as TCP / IP; service carrying relationship data describes how upper-layer application services, such as video streaming, voice calls, and IoT telemetry, are mapped to the configuration and association rules of underlying network resources; network operation status data reflects the real-time dynamic performance indicators and logs of the network, such as device CPU / memory usage, number of connections, traffic rate, alarm events, session status, etc.

[0042] By using network management system interfaces, SNMP protocols, traffic mirroring, device configuration export, performance monitoring tools, and data interfaces of business support systems, network topology data, communication link characteristic data, protocol interaction data, service bearer relationship data, and network operation status data are collected to form a unified and time-aligned multidimensional dataset.

[0043] Dynamic modeling is performed using network simulation and virtualization technologies. Nodes (virtual base stations, routers, etc.) are instantiated in the simulation platform based on network topology data, and their connections are configured. Bandwidth, latency, and packet loss parameters are set for virtual links based on link characteristic data. Corresponding protocol stack models are loaded for virtual nodes based on protocol interaction data, such as implementing 5G control plane signaling flows or configuring protocol parameters. Based on service bearer relationship data, corresponding policy control functions and service flow generators are configured in the virtual network to simulate real service traffic patterns. The resource states of each virtual node are initialized based on network operating status data, and dynamic events may be injected to simulate network load fluctuations. This generates a highly realistic virtual communication network in terms of behavior, performance, and functionality.

[0044] The exercise control engine analyzes the multi-dimensional attack exercise scheme, transforming each attack action into specific operational instructions for the virtual network. This includes sending a malicious data packet exploiting the CVE2021 vulnerability to a specific virtual IP, or simulating a fake base station broadcasting deceptive signaling. During the exercise, distributed probes (such as soft probes and virtual optical splitters) and log collectors deployed within the virtual network synchronously collect network traffic data packets, system and security logs of all virtual nodes, performance monitoring metrics, and alarm events generated by virtual security devices. Because the entire exercise process is programmatically controlled, each line of collected data is automatically and precisely tagged with metadata, including attack scheme ID, attack step number, timestamp, and attack target. Once an exercise scheme is completed, all tagged data is aggregated, structured, and stored as an independent multi-dimensional exercise dataset. This process of loading the scheme, executing the exercise, synchronously collecting data, tagging, and storing is repeated for each exercise scheme in the scheme set, ultimately resulting in a series of exercise datasets corresponding to different attack scenarios, collectively forming a multi-dimensional exercise dataset. A multidimensional exercise dataset is a collection of data with precise timestamps and attack phase labels, collected synchronously from various levels of the virtual network during attack exercises, such as traffic, logs, performance counters, and security device alerts. Each independent exercise generates a complete dataset documenting the entire attack and defense interaction process.

[0045] Conducting multi-dimensional attack drills in virtual communication networks ensures a comprehensive assessment of the network's impact from different types of attacks. Executing pre-programmed drills in virtual networks allows for the simultaneous collection of data from multiple dimensions, including network traffic, device logs, performance metrics, and security alerts, covering the entire attack and defense interaction process. Crucially, because the attack steps are programmatically controlled and known, precise contextual labels are automatically associated with each piece of collected data, such as attack stage, technology ID, and target asset, thereby generating a large-scale, high-quality, labeled adversarial sample dataset.

[0046] Based on the multidimensional exercise dataset, offensive and defensive situation fusion modeling is performed to obtain a multidimensional exercise offensive and defensive confrontation model.

[0047] Furthermore, this application also includes the following steps: extracting an intrusion control exercise data set based on the multidimensional exercise dataset; performing multimodal feature recognition based on the intrusion control exercise data set to obtain attack-side behavior feature sequences, defense-side response feature sequences, and protected asset feature sequences; performing time series alignment and event association on the attack-side behavior feature sequences and the defense-side response feature sequences to obtain an intrusion attack-defense interaction situation distribution; performing three-way coupling modeling based on the protected asset feature sequences and the intrusion attack-defense interaction situation distribution to obtain an intrusion exercise attack-defense confrontation model; and, based on the intrusion exercise attack-defense confrontation model, continuing to perform attack-defense situation fusion modeling on the multidimensional exercise dataset to generate the multidimensional exercise attack-defense confrontation model.

[0048] Specifically, based on the multi-dimensional exercise dataset, a subset of data generated from executing intrusion control attack drills is selected to form an intrusion control exercise dataset. Multimodal feature identification is performed on this dataset, using a specialized parser to extract features from the raw data. For the attack side, attack scripts or traffic logs are parsed to extract attack stages, exploited vulnerabilities, executed commands, lateral movement paths, etc., and sorted chronologically to form an attack side behavioral feature sequence. For the defense side, logs and alerts from various security devices are parsed to extract alert types, severity levels, response actions, timestamps, etc., forming a defense side response feature sequence. For the asset side, asset status changes, such as process trees, network connections, file operations, registry modifications, resource utilization, etc., are extracted from system logs, performance monitoring, and application logs to form a protected asset feature sequence. Attacker-side behavioral feature sequences are features extracted from the attacker's perspective, describing attack steps, techniques, tools, and attack paths, such as scanning IP segments, exploiting specific vulnerabilities, and executing specific commands. Defender-side response feature sequences are features extracted from the defender's perspective, describing the detection, alarm, and blocking responses of defense devices. Protected asset feature sequences are features extracted from the perspective of protected network assets (such as servers, terminals, and databases), describing the state changes of assets during the attack process.

[0049] Time series alignment is performed on the attack-side behavioral characteristic sequence and the defense-side response characteristic sequence to ensure that attack and defense events correspond in chronological order. A unified timeline is established, aligning events in the attack and defense sequences according to timestamps. The attack behavior and defense response sequences, arranged by timestamps, are compared and correlated to identify their temporal and causal relationships. For example, if an attacker initiates an exploit attempt at time T, and the defense system generates an alert at T+Δt, these two events can be correlated as an attack-detection event pair. It is then determined which defense responses target which attack action, and response delays are calculated. Discrete events are transformed into a series of attack-defense correlation pairs. The coverage and response time distribution of defenses at different attack stages are statistically analyzed, i.e., the intrusion attack-defense interaction situation distribution, describing the coverage and response efficiency of the defense system at different attack stages.

[0050] This paper couples the behaviors of attackers, defenders, and protected assets into a model to analyze their mutual influence. Using attack behavior sequences and asset state sequences as inputs, and defense response sequences as outputs, while considering asset state changes as an intermediate variable, a joint model is trained to reflect the causal or correlational relationships among the three. This model captures complex relationships such as an 80% probability that a specific IDS rule will issue an alert within 2 seconds when a specific vulnerability exploitation attempt occurs and the target server has a missing patch. The resulting specialized model is the intrusion drill attack-defense adversarial model.

[0051] The core idea of ​​the intrusion drill attack-defense confrontation model is to place attack behavior, defense response, and asset vulnerability within a framework of simultaneous evolution. By explicitly modeling the causal and feedback relationships among these three elements, it deduces the dynamic development process of security events. The model consists of an input encoding module, a core computation module, and an output synthesis module. The input encoding module is responsible for transforming standardized attack behavior feature sequences, defense response feature sequences, and protected asset feature sequences into high-dimensional feature vectors. A cross-sequence attention layer automatically establishes key correlations, such as matching specific attack techniques with their target asset types and deployed defense measures. The core computation module is the heart of the model, consisting of three interconnected neural network units: an intrusion intent inference unit simulates attacker decisions and predicts subsequent attack steps based on the current environment; a defense strategy generation unit recommends defense actions based on the current situation and evaluates their expected effectiveness; and an asset state transition unit quantitatively updates the asset's security attribute score based on the occurring attack and defense actions. These three units are tightly coupled through a shared state vector and closed-loop feedback. The predictive output of the attack unit drives the updates of the defense unit and the state unit. The new asset vulnerabilities calculated by the state unit are fed back to the attack and defense units, affecting the next round of decisions, thus simulating a real dynamic game.

[0052] The three units are pre-trained step-by-step using historical exercise data to learn basic patterns. Then, joint fine-tuning is performed, with multi-step rolling simulations to make the model's output sequence approximate real data. The loss function is a weighted sum of the predicted losses of each part, and a curriculum learning strategy is used during training. Reinforcement learning optimization is introduced, treating the defense unit as an agent that engages in self-play in a simulated environment, with the reward of protecting assets, to explore better strategies. When combined with the field of wireless communication networks, the feature definitions and state vectors of the intrusion exercise attack-defense adversarial model are deeply integrated with domain knowledge, such as asset types including base stations and core network elements, attack techniques including fake base stations and signaling storms, and defense actions including air interface resource scheduling. Finally, the intrusion exercise attack-defense adversarial model, as an executable inference function, takes the initial attack and defense asset states as input and outputs a complete attack-defense interaction inference path, key situational indicators, and a visualized adversarial causal graph, clearly revealing the internal logic of why attacks succeed or fail.

[0053] Based on the intrusion drill attack-defense adversarial model, further attack-defense situation fusion modeling is performed on the multi-dimensional drill dataset. Specifically, data theft drill datasets, service disruption drill datasets, and deception manipulation drill datasets are extracted from the multi-dimensional drill dataset. The aforementioned feature identification, alignment and correlation, and three-way coupling modeling process are repeated to establish corresponding data theft attack-defense adversarial models, service disruption attack-defense adversarial models, and deception manipulation attack-defense adversarial models, respectively. Combining these models, a multi-dimensional drill attack-defense adversarial model is generated, providing corresponding attack-defense situation analysis and prediction capabilities for different types of attack intentions. Each dataset has a corresponding attack-defense adversarial model, ensuring a comprehensive assessment of defense capabilities across various attack scenarios.

[0054] By constructing dedicated models for each of the four main attack objectives, the resulting multi-dimensional offensive and defensive adversarial model possesses targeted analytical capabilities. When facing hybrid attacks or attacks with uncertain intentions, multiple models can be run in parallel for comparison, or the evolution of attack stages can be discovered through the correlation between models. This allows security operations to go beyond single alert events and conduct higher-level situational assessments from the perspective of attacker intent and tactical chains.

[0055] A security situation assessment index system is introduced to conduct security situation perception on the multi-dimensional exercise attack and defense confrontation model and construct a multi-dimensional exercise security situation profile.

[0056] Furthermore, this application also includes the following steps: the security situation assessment indicator system includes a primary assessment indicator layer and a secondary assessment indicator layer; the primary assessment indicator layer includes multiple primary assessment indicators, which include attack threat level, defense effectiveness, and asset risk level; the secondary assessment indicator layer includes attack threat level element indicators, defense effectiveness element indicators, and asset risk level element indicators; the attack threat level element indicators include attack frequency change, attack intensity change, attack coverage, and attack behavior persistence; the defense effectiveness element indicators include defense response latency, defense interception success rate, defense resource consumption level, and attack attribution accuracy; the asset risk level element indicators include asset exposure level, asset importance, and asset exposure scope.

[0057] Specifically, a security posture assessment indicator system is a framework used to evaluate the overall state and defense capabilities of cybersecurity. It typically uses a series of indicators to comprehensively evaluate aspects such as network attack threats, defense effectiveness, and asset security, helping security personnel identify potential security risks and take appropriate measures. The security posture assessment indicator system includes a primary assessment indicator layer and a secondary assessment indicator layer. The primary assessment indicator layer consists of high-level indicators, usually including the most fundamental and important dimensions that directly relate to the overall assessment of the cybersecurity posture. These typically include the degree of attack threat, defense effectiveness, and asset risk level. The secondary assessment indicator layer consists of specific, actionable tactical metrics that support the primary indicators.

[0058] Attack threat level measures the level of pressure exerted on a target network by external attackers, focusing on the activity, intensity, and scope of attack activities; defense effectiveness measures the capability level of the target network's own security protection system, focusing on the efficiency and success rate of the defense system in detecting, responding to, and handling threats; asset risk level measures the potential loss level of critical resources in the network due to their own attributes, exposure, and threats, focusing on the value, vulnerability, and severity of threats faced by the assets.

[0059] The attack threat level indicators include changes in attack frequency, changes in attack intensity, attack coverage, and persistence of attack behavior; the defense effectiveness indicators include defense response latency, defense interception success rate, defense resource utilization level, and attack attribution accuracy; the asset risk level indicators include asset exposure level, asset importance, and asset exposure scope.

[0060] Regarding the severity of the attack, attack frequency is obtained by counting the number of alert logs per unit time; attack intensity is calculated by retrieving vulnerability scores associated with each attack from the vulnerability database and averaging them within a sliding time window; attack coverage is determined by aggregating the number of network segments to which the attacked target IP addresses belong; and attack persistence is analyzed by using session analysis algorithms to perform time clustering analysis on attack sequences from the same source. Regarding defense effectiveness, response latency is calculated by comparing the timestamps of intrusion detection system alerts with the timestamps of firewall / endpoint response logs; interception success rate is calculated by comparing the number of intrusion detection system alerts with the number of blocking logs from intrusion prevention system / web application firewall; resource consumption is obtained through monitoring the performance metrics of the security platform server; and attribution accuracy is recorded by documenting the results of the security operations team's attribution analysis and confirmation of high-level events. Regarding asset risk level, asset exposure is automatically scored based on network location and port configuration information in the asset database; asset importance is pre-entered into the asset database based on business impact assessments; and asset exposure range is obtained by matching the results of periodic vulnerability scans with the asset database. All secondary indicator data undergoes cleaning and normalization, such as scaling values ​​of different dimensions to the range of 0-1. Then, based on predefined weights (e.g., attack frequency variation accounting for 30% of attack threat level, attack intensity accounting for 40%), the scores of the higher-level indicators are calculated through weighted aggregation. This multi-layered refinement of primary and secondary evaluation indicators allows for accurate assessment of different dimensions of cybersecurity, providing comprehensive situational awareness.

[0061] Furthermore, this application also includes the following steps: identifying key elements of the intrusion drill attack-defense confrontation model according to the secondary evaluation index layer, obtaining an intrusion drill element vector set, wherein the intrusion drill element vector set includes intrusion attack threat element vectors, intrusion defense element vectors, and intrusion asset risk element vectors; performing a multi-dimensional security situation assessment on the intrusion drill element vector set according to the primary evaluation index layer, obtaining an intrusion security situation assessment result; performing differential identification on the intrusion security situation assessment result according to the security situation expectation result, obtaining an intrusion security situation differential result; constructing an intrusion drill security situation profile based on the intrusion drill attack-defense confrontation model, the intrusion security situation assessment result, and the intrusion security situation differential result; and further performing security situation perception on the multi-dimensional drill attack-defense confrontation model based on the intrusion drill security situation profile and the security situation assessment index system, generating the multi-dimensional drill security situation profile.

[0062] Furthermore, this application also includes the following steps: performing big data retrieval based on the first-level assessment indicator layer to obtain attack threat level assessment records, defense effectiveness assessment records, and asset risk level assessment records; training an attack threat level assessment model based on the attack threat level assessment records; training a defense effectiveness assessment model based on the defense effectiveness assessment records; training an asset risk level assessment model based on the asset risk level assessment records; connecting the attack threat level assessment model, the defense effectiveness assessment model, and the asset risk level assessment model as parallel nodes to generate a multi-dimensional security posture assessment model; inputting the intrusion drill element vector set into the multi-dimensional security posture assessment model, and outputting the intrusion security posture assessment result.

[0063] Specifically, based on the secondary evaluation index layer, key elements of the intrusion exercise attack and defense confrontation model are identified to obtain an intrusion exercise element vector set. This identifies key elements affecting the network security situation, including intrusion attack threat element vectors, intrusion defense element vectors, and intrusion asset risk element vectors. The intrusion attack threat element vector is a mathematical vector whose components correspond to the calculated values ​​of various secondary indicators under the attack threat level, such as attack frequency change 1.5, attack intensity change 0.8, attack coverage 0.3, and attack behavior persistence 0.9. These values ​​are usually normalized results. The intrusion defense element vector is a mathematical vector whose components correspond to the calculated values ​​of various secondary indicators under the defense effectiveness level, such as defense response latency 200, defense interception success rate 0.85, defense resource utilization level 0.65, and attack attribution accuracy 0.7. The intrusion asset risk element vector is a mathematical vector whose components correspond to the calculated values ​​of various secondary indicators under the asset risk level, such as asset exposure level 0.7, asset importance 0.9, and asset exposure range 0.4.

[0064] Based on the first-level assessment indicator layer, big data retrieval is performed. Historical records related to the assessment are searched and obtained from large-scale data sources such as historical security event databases, attack and defense exercise record libraries, and network asset management systems. These records include element vectors observed in real or simulated exercises in history, as well as the corresponding first-level indicator rating labels determined by experts after the event or derived from the actual business impact. This results in attack threat level assessment records, defense effectiveness assessment records, and asset risk level assessment records.

[0065] An attack threat assessment model is trained using attack threat element vectors and corresponding attack threat level evaluation record label scores. Before training, data cleaning, missing value handling, and feature standardization are required. The attack threat level assessment model is an interpretable machine learning model based on a gradient boosting decision tree architecture. Its core consists of a feature input layer, a multi-level sequential decision tree ensemble layer, and a linear combination output layer, aiming to learn the complex mapping relationship from specific attack feature elements to a comprehensive threat level score. The feature input layer of the attack threat level assessment model directly receives the standardized intrusion attack threat element vector. The four dimensions of this vector—attack frequency change rate, attack intensity change value, attack coverage ratio, and attack behavior persistence index—constitute the four fundamental aspects of the threat observed by the model. The core computational layer of the attack threat assessment model consists of hundreds of shallow decision trees connected sequentially. Each tree is a simple set of decision rules. For example, if the attack frequency changes by more than 150% and the attack strength is higher than 7.0, the threat contribution value is increased by 0.05. The residuals (prediction errors) fitted by the previous tree are learned by the next tree. This progressive error correction mechanism enables the attack threat assessment model to capture the complex nonlinear relationships and interaction effects between features. The specific steps for training an attack threat assessment model begin with data preparation: extracting massive amounts of element vector-expert rating paired data from historical attack threat assessment records and dividing it into training and validation sets at an 8:2 ratio; during training, the initial base prediction value is first set as the average of all training sample labels, and then a decision tree is iteratively constructed. In each iteration, the gradient between the current prediction value and the true label is calculated, i.e., the direction and magnitude of the error, and a new tree is grown with the goal of fitting this gradient. The growth process is achieved by precisely controlling the depth of the tree, usually limited to 3 to 6 layers to prevent overfitting, the minimum number of samples per leaf node, such as 10, and the contribution weight of each tree to the final result, i.e., the learning rate, which is usually set to a decimal between 0.05 and 0.2, to ensure stable convergence; key regularization parameters such as subsampling rate and feature sampling rate are also introduced to enhance the model's generalization ability. The integration with the cybersecurity field is mainly reflected in the embedding of domain knowledge in feature engineering: for example, before inputting attack intensity variation features, the original CVSS score is transformed through a non-linear function based on industry consensus to better align with experts' judgment logic for high-risk vulnerabilities; simultaneously, the loss function used for model training is designed as a weighted mean squared error, assigning higher weights to historical samples that were rated as extremely high threats by experts due to causing severe business disruptions, thus making the model more focused on high-threat scenarios. The internal mechanism of the entire model is transparent: after training, by analyzing the total number of times each feature is used as a split point in all decision trees and the average gain, the relative importance of factors such as attack intensity and attack frequency to the final threat score can be quantitatively assessed, thus forming a reliable evaluation model that is no longer a black box, and whose decision logic can be traced back to specific features and rules.Ultimately, the model takes the aforementioned four element vectors as input, undergoes layer-by-layer nonlinear transformation and weighted aggregation through a decision tree set, and outputs a continuous value between 0 and 100, which is the predicted attack threat level score. This achieves accurate, automated, and interpretable assessment of the threat level in unknown attack scenarios. Similarly, defense effectiveness assessment models and asset risk level assessment models are trained separately.

[0066] The attack threat assessment model, defense effectiveness assessment model, and asset risk level assessment model are encapsulated as three independent parallel processing nodes and integrated into a unified multi-dimensional security posture assessment model. When it is necessary to evaluate the simulation results of a new intrusion exercise attack-defense confrontation model, the intrusion exercise element vector set is input into the trained multi-dimensional security posture assessment model, and the intrusion security posture assessment results are output, namely the attack threat level, defense effectiveness, and asset risk level corresponding to the intrusion exercise attack-defense confrontation model. For the current input intrusion exercise scenario, three quantitative scores are given simultaneously: attack threat level score, defense effectiveness score, and asset risk level score.

[0067] Based on the expected security situation results, the intrusion security situation assessment results are differentially identified. Expected security situation results for this network are retrieved from the policy library, including expected attack threat level, expected defense effectiveness, and expected asset risk level. The assessment results are subtracted from the expected values ​​item by item to obtain the intrusion security situation differential results, indicating which aspects have not met the standards and the magnitude of the gap. Differential identification involves subtracting the intrusion security situation assessment results (actual performance) from the expected security situation results (target baseline) item by item to obtain the gap value for each indicator. A positive gap indicates failure to meet the standards, while a negative gap indicates performance better than expected.

[0068] The intrusion security situation differential results are overlaid with the intrusion exercise attack and defense confrontation model and the intrusion security situation assessment results to construct an intrusion exercise security situation profile. This profile not only includes the assessment score, but also organically combines the original deduction process, quantitative assessment results and gap analysis. It is usually supplemented with charts for intuitive display, forming a complete characterization of the specific intrusion exercise scenario.

[0069] We continue to conduct security posture awareness exercises for different types of attacks, such as data theft, business disruption, and deception manipulation, and generate corresponding multi-dimensional security posture profiles. Finally, we integrate these profiles into a comprehensive multi-dimensional security posture report to assess the network security posture under different attack types. The multi-dimensional security posture profile is the final output; it is a collection of profiles containing four independent and parallel security posture profiles obtained after exercising, evaluating, and generating profiles for four typical attack objectives: intrusion control, data theft, business disruption, and deception manipulation. These four profiles together constitute a panoramic view of the network's ability to protect against threats across all dimensions.

[0070] Multi-dimensional security posture assessment provides a comprehensive understanding of the network's security status, encompassing multiple dimensions such as attack threats, defense capabilities, and asset risks. Differential identification methods accurately pinpoint the discrepancies between the current network state and the desired state, helping to uncover defensive vulnerabilities and potential risks. Multi-dimensional security posture profiles generated from different attack drills reflect real-time changes in network security, enabling timely identification and response to new security threats.

[0071] Security enhancement management is performed on the wireless communication network based on the multi-dimensional exercise security posture profile.

[0072] Specifically, the security operations team reviews the multi-dimensional security posture profiles from the drills, focusing on the security posture difference results under various scenarios. For example, if the security posture profile from a data theft drill shows a defense effectiveness difference of -30 points and an extremely high asset risk level, it indicates that existing protective measures, such as perimeter firewalls and intrusion detection systems, are almost ineffective against data leakage attacks. The decision engine will determine the priority of improvements based on the size of the gap, asset importance, and remediation costs. Subsequently, specific enhancement measures are developed for high-priority issues. For example, to address weaknesses in data theft protection, the solution might include deploying a data loss prevention system on the north-south gateway of the network and configuring policies to detect and block the outflow of sensitive data; deploying database auditing and encryption modules on the core database server; and updating the rules of endpoint antivirus software to detect new types of data-stealing Trojans.

[0073] To ensure the effectiveness of the solution and avoid negative impacts on the production network, the next step is virtual environment pre-validation: the aforementioned enhancement measures, such as new policy rules and virtual device images, are imported into the previously constructed virtual communication network. Then, the original data theft drill that resulted in the high score difference, or even more complex variants, are run again. The improvement effect is quantified by comparing the security posture assessment results before and after implementing the enhancement measures. For example, the validation might show that after deploying the data loss prevention system, the success rate of intercepting the same data theft attack increases from 30% to 95%, and the asset risk level decreases from 85 points to 45 points.

[0074] Only measures that have been verified and proven effective will be deployed in the production network through security operations and maintenance processes. This includes, for example, installing data loss prevention system hardware on real gateways and loading verified policies. Finally, this round of enhancement measures, verification results, and final deployment status will be recorded, and the expected security posture will be updated. This initiates a new cycle of attack scheme design, virtual drills, assessment profiling, and enhanced management, driving the continuous evolution of security protection capabilities.

[0075] Security enhancement management is a closed-loop decision-making and execution process based on data insights. Based on the precise diagnoses provided by multi-dimensional security posture profiles from drills, targeted improvement measures are formulated and implemented, such as policy optimization, equipment upgrades, and architecture adjustments. The effectiveness of these measures is then verified in subsequent virtual or real environments, thereby achieving iterative improvements in network protection capabilities. Its core is the process from identifying the problem to solving it and confirming its effectiveness.

[0076] By identifying and fixing vulnerabilities in the network, the defense system's ability to protect against different types of attacks was enhanced, improving overall network security. For areas with high asset exposure, strengthened protection measures were implemented to reduce the risk of network attacks and lower the likelihood of data leaks and business interruptions.

[0077] Furthermore, this application also includes the following steps: deploying a virtual-real linkage gateway between the virtual communication network and the wireless communication network, and using the virtual-real linkage gateway to link the virtual communication network and the wireless communication network in virtual and real states and isolate attacks.

[0078] Specifically, a virtual-physical linkage gateway is deployed between the virtual communication network and the wireless communication network to connect the two networks. This allows data, events, and behaviors in the virtual network to influence the real network in real time, and vice versa. The virtual-physical linkage gateway exchanges data through specific protocols and interfaces, ensuring synchronization and interaction between the virtual and real networks. A virtual-physical linkage gateway is a combination of dedicated security devices and software agents deployed between the virtual communication network and the real, operating wireless communication network. It acts as a controlled, unidirectional, logical connection channel between the two networks, rather than a direct physical bridge. Its main function is to achieve unidirectional synchronization of specific management and status data while ensuring absolute security isolation. Virtual-physical status linkage is achieved by synchronizing certain read-only, non-sensitive runtime status information from the real wireless communication network, such as the current snapshot of the network topology, compliant versions of device configurations, and macroscopic statistical characteristics of service traffic, to the virtual communication network through the virtual-physical linkage gateway. Simultaneously, verified security policies and configuration scripts from the virtual network can be pushed back to the management interface of the real network after rigorous review. Its core is the controlled flow of data, rather than direct network connectivity. Attack isolation is the strict logical and physical isolation capability of a virtual-physical interconnected gateway. It ensures that any malicious traffic, attack code, or abnormal state generated by any attack drills conducted in the virtual communication network cannot be leaked or penetrated into the real wireless communication network. It is the most fundamental security red line of the gateway and is usually achieved through technologies such as unidirectional data flow design, physical isolation chips, strict content filtering, and protocol stripping.

[0079] In terms of physical architecture, the virtual-physical linkage gateway acts as an independent hardware device or a high-security virtual machine. Its two network interfaces connect to the management isolation zone of the production network—a secure area dedicated to network management traffic and isolated from the business plane—and the control network of the virtual network, respectively. Logically, the gateway runs multiple functional modules. First is the state synchronization module, which periodically retrieves authorized state data, such as the list of currently active base stations, logical connections between core network elements, and active access control list entries, by calling the read-only application programming interface of the production network management system. This data undergoes data cleaning and desensitization, removing all sensitive information, and is then converted into configuration scripts or data models recognizable by the virtual network simulation platform. This data is then injected unidirectionally into the virtual communication network, driving its dynamic updates and maintaining synchronization with the production network infrastructure. Second is the policy push and verification module. Once the security team verifies an effective security enhancement policy in the virtual network, they can submit the policy package to the gateway's policy staging area. The gateway's policy compliance check engine automatically verifies it against a predefined security policy baseline. After confirming no conflicts or risks, it generates corresponding production network device configuration instructions. Finally, there is an impenetrable attack isolation barrier, implemented through a physical unidirectional fiber channel or a hardware-based logical unidirectional transmission device. This ensures that data flows from the virtual network to the gateway can only be written to a specific storage area of ​​the gateway at the physical layer, with absolutely no possibility of reverse reading or transmission. Simultaneously, all data flows synchronized from the production network to the virtual network undergo protocol stripping, transmitting only pure data fields and completely filtering out any executable code or active session information. Through this series of designs, the gateway achieves a precise balance between state linkage and attack isolation.

[0080] In summary, the intelligent security situation awareness method based on multidimensional data analysis provided in this application has the following technical effects: By classifying, filtering, and fusing attack event databases of wireless communication networks, a multidimensional attack drill scheme is determined; a virtual communication network is constructed, and attack drills are conducted on the virtual communication network according to the multidimensional attack drill scheme to obtain a multidimensional drill dataset; attack and defense situation fusion modeling is performed based on the multidimensional drill dataset to obtain a multidimensional drill attack and defense confrontation model; a security situation assessment index system is introduced to perform security situation awareness on the multidimensional drill attack and defense confrontation model, constructing a multidimensional drill security situation profile; and security enhancement management is performed on the wireless communication network based on the multidimensional drill security situation profile. In other words, by classifying, filtering, and fusing attack event databases, a more comprehensive attack drill scheme is established; a virtual communication network is constructed and multidimensional attack drills are conducted; attack and defense situation fusion modeling is performed on the obtained multidimensional drill dataset; a security situation assessment index system is introduced for security situation awareness; and security enhancement management is performed on the wireless communication network, comprehensively improving attack identification capabilities, enhancing the practicality of attack and defense drills, and improving network security protection efficiency.

[0081] Example 2: Based on the same inventive concept as the intelligent security situation awareness method based on multidimensional data analysis in Example 1, this application also provides an intelligent security situation awareness system based on multidimensional data analysis. Please refer to the appendix. Figure 2 The intelligent security situation awareness system based on multidimensional data analysis includes:

[0082] The classification, filtering, and fusion module 11 is used to classify, filter, and fuse attack event databases of wireless communication networks to determine multi-dimensional attack drill schemes; the attack drill module 12 is used to construct a virtual communication network and conduct attack drills on the virtual communication network according to the multi-dimensional attack drill schemes to obtain a multi-dimensional drill dataset; the attack and defense situation fusion modeling module 13 is used to perform attack and defense situation fusion modeling based on the multi-dimensional drill dataset to obtain a multi-dimensional drill attack and defense confrontation model; the security situation awareness module 14 is used to introduce a security situation assessment index system to perform security situation awareness on the multi-dimensional drill attack and defense confrontation model and construct a multi-dimensional drill security situation profile; and the security enhancement management module 15 is used to perform security enhancement management on the wireless communication network based on the multi-dimensional drill security situation profile.

[0083] Furthermore, the classification, filtering, and fusion module 11 in the intelligent security situation awareness system based on multidimensional data analysis is also used for: classifying attack objectives according to the attack event database to obtain intrusion control attack event areas, data theft attack event areas, business disruption attack event areas, and deception manipulation attack event areas; performing support cleaning and disruption filtering fusion according to the intrusion control attack event areas to obtain intrusion control drill schemes; performing support cleaning and disruption filtering fusion according to the data theft attack event areas to obtain data theft drill schemes; performing support cleaning and disruption filtering fusion according to the business disruption attack event areas to obtain business disruption drill schemes; performing support cleaning and disruption filtering fusion according to the deception manipulation attack event areas to obtain deception manipulation drill schemes; and outputting the intrusion control drill scheme, the data theft drill scheme, the business disruption drill scheme, and the deception manipulation drill scheme as the multidimensional attack drill scheme.

[0084] Furthermore, the classification, filtering, and fusion module 11 in the intelligent security situation awareness system based on multidimensional data analysis is also used for: extracting attack parameter features based on the intrusion control attack event area to obtain multiple intrusion attack feature sequences; counting the frequency of each intrusion attack feature sequence appearing in the intrusion control attack event area to obtain the support of each intrusion attack; cleaning the multiple intrusion attack feature sequences based on the support of each intrusion attack according to a predetermined intrusion attack support to establish an intrusion attack support space; evaluating the destructiveness of the intrusion attack support space based on the intrusion control attack event area to obtain the destructiveness of each intrusion attack; filtering the intrusion attack support space based on the destructiveness of each intrusion attack according to a predetermined intrusion attack destructiveness to establish an intrusion attack candidate space; and fusing attack parameters based on the intrusion attack candidate space to generate the intrusion control drill plan.

[0085] Furthermore, the attack drill module 12 in the intelligent security situation awareness system based on multidimensional data analysis is also used to: acquire a multidimensional dataset of the wireless communication network, the multidimensional dataset including network topology data, communication link characteristic data, protocol interaction data, service bearer relationship data and network operation status data; and perform dynamic modeling based on the multidimensional dataset to generate the virtual communication network.

[0086] Furthermore, the attack and defense situation fusion modeling module 13 in the intelligent security situation awareness system based on multidimensional data analysis is also used for: extracting an intrusion control exercise data set based on the multidimensional exercise dataset; performing multimodal feature recognition based on the intrusion control exercise data set to obtain attack-side behavior feature sequences, defense-side response feature sequences, and protected asset feature sequences; performing time series alignment and event association on the attack-side behavior feature sequences and the defense-side response feature sequences to obtain an intrusion attack and defense interaction situation distribution; performing three-way coupling modeling based on the protected asset feature sequences and the intrusion attack and defense interaction situation distribution to obtain an intrusion exercise attack and defense confrontation model; and, based on the intrusion exercise attack and defense confrontation model, continuing to perform attack and defense situation fusion modeling on the multidimensional exercise dataset to generate the multidimensional exercise attack and defense confrontation model.

[0087] Furthermore, the security situation awareness module 14 in the intelligent security situation awareness system based on multi-dimensional data analysis is also used for: the security situation assessment index system includes a primary assessment index layer and a secondary assessment index layer; the primary assessment index layer includes multiple primary assessment indicators, including attack threat level, defense effectiveness, and asset risk level; the secondary assessment index layer includes attack threat level element indicators, defense effectiveness element indicators, and asset risk level element indicators; the attack threat level element indicators include attack frequency change, attack intensity change, attack coverage, and attack behavior persistence; the defense effectiveness element indicators include defense response latency, defense interception success rate, defense resource consumption level, and attack tracing accuracy; the asset risk level element indicators include asset exposure level, asset importance, and asset exposure range.

[0088] Furthermore, the security situation awareness module 14 in the intelligent security situation awareness system based on multidimensional data analysis is also used for: identifying key elements of the intrusion exercise attack-defense confrontation model according to the secondary evaluation index layer, obtaining an intrusion exercise element vector set, the intrusion exercise element vector set including intrusion attack threat element vector, intrusion defense element vector, and intrusion asset risk element vector; performing multidimensional security situation assessment on the intrusion exercise element vector set according to the primary evaluation index layer, obtaining intrusion security situation assessment results; performing differential identification on the intrusion security situation assessment results according to the security situation expectation results, obtaining intrusion security situation differential results; constructing an intrusion exercise security situation profile based on the intrusion exercise attack-defense confrontation model, the intrusion security situation assessment results, and the intrusion security situation differential results; and continuing to perform security situation awareness on the multidimensional exercise attack-defense confrontation model based on the intrusion exercise security situation profile and the security situation assessment index system, generating the multidimensional exercise security situation profile.

[0089] Furthermore, the security situation awareness module 14 in the intelligent security situation awareness system based on multidimensional data analysis is also used for: performing big data retrieval based on the first-level evaluation index layer to obtain attack threat level assessment records, defense effectiveness assessment records, and asset risk level assessment records; training an attack threat level assessment model based on the attack threat level assessment records; training a defense effectiveness assessment model based on the defense effectiveness assessment records; training an asset risk level assessment model based on the asset risk level assessment records; connecting the attack threat level assessment model, the defense effectiveness assessment model, and the asset risk level assessment model as parallel nodes to generate a multidimensional security situation assessment model; inputting the intrusion drill element vector set into the multidimensional security situation assessment model, and outputting the intrusion security situation assessment result.

[0090] Furthermore, the intelligent security situation awareness system based on multi-dimensional data analysis also includes: deploying a virtual-real linkage gateway between the virtual communication network and the wireless communication network, and using the virtual-real linkage gateway to link the virtual and real states of the virtual communication network and the wireless communication network and isolate attacks.

[0091] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The intelligent security situation awareness method and specific examples based on multidimensional data analysis in the foregoing embodiment one are also applicable to the intelligent security situation awareness system based on multidimensional data analysis in this embodiment. Through the foregoing detailed description of the intelligent security situation awareness method based on multidimensional data analysis, those skilled in the art can clearly understand the intelligent security situation awareness system based on multidimensional data analysis in this embodiment. Therefore, for the sake of brevity, it will not be described in detail here.

[0092] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0093] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application also intends to include such modifications and variations.

Claims

1. An intelligent security situation awareness method based on multidimensional data analysis, characterized in that, include: The attack event database of wireless communication networks is classified, filtered, and integrated to determine a multi-dimensional attack exercise plan; Construct a virtual communication network and conduct attack drills on the virtual communication network according to the multi-dimensional attack drill scheme to obtain a multi-dimensional drill dataset; Based on the multi-dimensional exercise dataset, perform offensive and defensive situation fusion modeling to obtain a multi-dimensional exercise offensive and defensive confrontation model; A security situation assessment index system is introduced to conduct security situation perception on the multi-dimensional exercise attack and defense confrontation model, and a multi-dimensional exercise security situation profile is constructed. Security enhancement management is performed on the wireless communication network based on the multi-dimensional exercise security posture profile.

2. The intelligent security situation awareness method based on multidimensional data analysis as described in claim 1, characterized in that, The attack event database for wireless communication networks is categorized, filtered, and integrated to determine multi-dimensional attack drill schemes, including: Based on the attack event database, attack objectives are classified to obtain intrusion control attack event areas, data theft attack event areas, business disruption attack event areas, and deception and manipulation attack event areas; Based on the intrusion control attack event area, support cleaning and damage screening and fusion are performed to obtain an intrusion control drill plan; Based on the data theft attack event area, support cleaning and damage filtering are performed and fused to obtain a data theft drill plan; Based on the business disruption attack event area, support cleaning and disruption filtering and fusion are performed to obtain a business disruption drill plan; Based on the deception and manipulation attack event area, support cleaning and damage filtering and fusion are performed to obtain a deception and manipulation exercise plan; The intrusion control exercise plan, the data theft exercise plan, the business disruption exercise plan, and the deception manipulation exercise plan are output as the multi-dimensional attack exercise plan.

3. The intelligent security situation awareness method based on multidimensional data analysis as described in claim 2, characterized in that, Based on the intrusion control attack event area, support cleaning and damage screening and fusion are performed to obtain an intrusion control drill plan, including: Based on the intrusion control attack event area, attack parameter features are extracted to obtain multiple intrusion attack feature sequences; The frequency of each intrusion attack feature sequence in the intrusion control attack event area is counted to obtain the support of each intrusion attack. Based on the aforementioned intrusion attack support levels, the multiple intrusion attack feature sequences are cleaned according to the predetermined intrusion attack support levels to establish an intrusion attack support space. Based on the intrusion control attack event area, the degree of damage to the intrusion attack support space is evaluated to obtain the degree of damage of each intrusion attack. Based on the destructive power of each intrusion attack, the intrusion attack support space is filtered according to the predetermined intrusion attack destructive power to establish an intrusion attack candidate space; The attack parameters are fused based on the intrusion attack candidate space to generate the intrusion control drill scheme.

4. The intelligent security situation awareness method based on multidimensional data analysis as described in claim 1, characterized in that, Based on the multidimensional exercise dataset, an offensive and defensive situation fusion model is performed to obtain a multidimensional exercise offensive and defensive confrontation model, including: Extract the intrusion control exercise data set based on the multidimensional exercise dataset; Multimodal feature identification is performed based on the intrusion control exercise data set to obtain attack-side behavior feature sequences, defense-side response feature sequences, and protected asset feature sequences; Time series alignment and event correlation are performed on the attack-side behavioral feature sequence and the defense-side response feature sequence to obtain the intrusion attack-defense interaction situation distribution; Based on the protected asset feature sequence and the intrusion attack and defense interaction situation distribution, a three-way coupling model is performed to obtain an intrusion drill attack and defense confrontation model. Based on the intrusion drill attack and defense confrontation model, the attack and defense situation fusion model is further performed on the multi-dimensional drill dataset to generate the multi-dimensional drill attack and defense confrontation model.

5. The intelligent security situation awareness method based on multidimensional data analysis as described in claim 1, characterized in that, The security situation assessment indicator system includes a primary assessment indicator layer and a secondary assessment indicator layer; The primary assessment indicator layer includes multiple primary assessment indicators, which include the degree of attack threat, the effectiveness of defense, and the asset risk level. The secondary assessment indicator layer includes attack threat level indicators, defense effectiveness indicators, and asset risk level indicators. The attack threat level indicators include changes in attack frequency, changes in attack intensity, attack coverage, and persistence of attack behavior; The key performance indicators of the defense effectiveness include defense response latency, defense interception success rate, defense resource consumption level, and attack attribution accuracy. The asset risk level indicators include the degree of asset exposure, the importance of the asset, and the scope of asset exposure.

6. The intelligent security situation awareness method based on multidimensional data analysis as described in claim 1, characterized in that, A security situation assessment index system is introduced to conduct security situation awareness on the multi-dimensional exercise attack and defense confrontation model, and a multi-dimensional exercise security situation profile is constructed, including: Based on the secondary evaluation index layer, key elements of the intrusion exercise attack and defense confrontation model are identified to obtain the intrusion exercise element vector set, which includes intrusion attack threat element vector, intrusion defense element vector, and intrusion asset risk element vector. A multi-dimensional security situation assessment is performed on the intrusion drill element vector set based on the first-level assessment index layer to obtain the intrusion security situation assessment results. Based on the expected security situation results, the intrusion security situation assessment results are differentially identified to obtain the intrusion security situation differential results; Based on the intrusion exercise attack and defense confrontation model, the intrusion security situation assessment results, and the intrusion security situation differential results, an intrusion exercise security situation profile is constructed. Based on the security situation profile of the intrusion exercise, the security situation perception of the multi-dimensional exercise attack and defense confrontation model is further carried out according to the security situation assessment index system, and the multi-dimensional exercise security situation profile is generated.

7. The intelligent security situation awareness method based on multidimensional data analysis as described in claim 6, characterized in that, A multi-dimensional security posture assessment is performed on the intrusion drill element vector set based on the primary assessment index layer to obtain the intrusion security posture assessment results, including: Based on the first-level assessment indicator layer, big data retrieval is performed to obtain attack threat level assessment records, defense effectiveness assessment records, and asset risk level assessment records; Based on the attack threat level assessment records, train the attack threat level assessment model; Based on the defense effectiveness assessment records, train the defense effectiveness assessment model; Based on the asset risk level assessment records, train the asset risk level assessment model; The attack threat level assessment model, the defense effectiveness assessment model, and the asset risk level assessment model are connected as parallel nodes to generate a multi-dimensional security situation assessment model. The intrusion drill element vector set is input into the multidimensional security situation assessment model, and the intrusion security situation assessment result is output.

8. The intelligent security situation awareness method based on multi-dimensional data analysis as described in claim 1, characterized in that, Constructing a virtual communication network includes: Obtain a multidimensional dataset of the wireless communication network, which includes network topology data, communication link characteristic data, protocol interaction data, service bearer relationship data, and network operation status data; The virtual communication network is generated by dynamically modeling based on the multidimensional dataset.

9. The intelligent security situation awareness method based on multidimensional data analysis as described in claim 1, characterized in that, A virtual-real linkage gateway is deployed between the virtual communication network and the wireless communication network to link the virtual and real states and isolate attacks on the virtual communication network and the wireless communication network.

10. An intelligent security situation awareness system based on multidimensional data analysis, characterized in that: The steps for implementing the intelligent security situation awareness method based on multidimensional data analysis according to any one of claims 1 to 9, wherein the intelligent security situation awareness system based on multidimensional data analysis comprises: The classification, filtering, and fusion module is used to classify, filter, and fuse attack event databases of wireless communication networks to determine multi-dimensional attack drill schemes. The attack drill module is used to construct a virtual communication network and conduct attack drills on the virtual communication network according to the multi-dimensional attack drill scheme to obtain a multi-dimensional drill dataset. The offensive and defensive situation fusion modeling module is used to perform offensive and defensive situation fusion modeling based on the multi-dimensional exercise dataset to obtain a multi-dimensional exercise offensive and defensive confrontation model. The security situation awareness module is used to introduce a security situation assessment index system to conduct security situation awareness on the multi-dimensional exercise attack and defense confrontation model and construct a multi-dimensional exercise security situation profile. The security enhancement management module is used to perform security enhancement management on the wireless communication network based on the multi-dimensional exercise security situation profile.