Method and device for early warning of virus attacks based on sub-area and time period analysis

By analyzing virus activity data by region and time period, calculating multi-dimensional indicators to generate security evaluation levels and issuing early warnings, the problem of lack of macro perspective and poor timeliness in existing virus defense methods is solved, and accurate and timely early warning and situational awareness of virus attacks are achieved.

CN122437700APending Publication Date: 2026-07-21NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
Filing Date
2026-05-08
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing virus defense methods lack a macro perspective, have single early warning indicators, and are not timely, making it difficult to achieve accurate and timely early warning of virus attacks.

Method used

By analyzing virus activity source data by region and time period, multi-dimensional intermediate indicators such as average number of times per machine is infected, proportion of infected hosts, and abnormal host indicators are calculated to generate security evaluation levels and issue early warning information. Analysis is supported by different time units such as day, week, and month.

Benefits of technology

It achieves comprehensive, accurate, and timely situational awareness and early warning of virus attacks, reduces false alarms and missed alarms, improves the timeliness and operability of early warnings, and supports automated decision-making and visualization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437700A_ABST
    Figure CN122437700A_ABST
Patent Text Reader

Abstract

The application discloses a virus attack early warning method and device based on regional and time period analysis, and relates to the technical field of network security; the method comprises the following steps: acquiring virus activity source data of a target region in a specific time unit, including the number of active hosts, the number of infection events, the number of involved hosts and the number of virus types; calculating intermediate indexes based on the source data, including the average number of infections per host, the proportion of infected hosts and the abnormal host index; generating a security evaluation level according to the intermediate indexes such as the number of virus types according to a preset rule; and finally warning information according to the evaluation level; the application combines the regional and time dimensions, and uses multi-index comprehensive evaluation to realize more comprehensive and accurate macroscopic situation awareness and timely early warning of virus attack activities, and effectively overcomes the shortcomings of single early warning perspective and vulnerability to interference in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, specifically to a method and apparatus for virus attack early warning based on regional and time-segmented analysis. Background Technology

[0002] With the rapid development of network technology, the spread and attacks of computer viruses, Trojans, and other malicious programs are becoming increasingly frequent and complex, posing a serious threat to the cybersecurity of individuals, businesses, and even nations. Traditional virus defense methods, such as antivirus software and firewalls, mainly focus on post-incident detection and removal, lacking the ability to perceive the overall security situation and provide early warnings.

[0003] Existing early warning systems often lack a macro perspective, have limited early warning indicators, and are slow to respond.

[0004] The key challenge is to develop a virus attack early warning system that integrates multiple indicators from a macro perspective and supports dynamic analysis by region and time period to achieve more accurate and timely security threat warnings. Summary of the Invention

[0005] In view of the above problems, the present invention provides a virus attack early warning method and device based on regional and time-segmented analysis, so as to achieve more comprehensive, accurate and timely situational awareness and early warning of virus attack activities.

[0006] In a first aspect, embodiments of the present invention provide a virus attack early warning method based on regional and time-segmented analysis, including: Obtain source data on virus activity in the target area within at least one time unit. The source data includes: the number of active hosts, the number of infection events, the number of hosts involved in the infection events, and the number of virus types involved in the infection events. Based on the source data, one or more intermediate indicators are calculated to assess the security status of the target area within the time unit. The intermediate indicators include: average number of times per machine is infected, proportion of infected hosts, and indicators for identifying abnormal hosts. Based on preset rules, at least one of the intermediate indicators is used to generate a safety evaluation level for the target area within the time unit. Based on the aforementioned safety assessment level, corresponding early warning information will be issued.

[0007] In some embodiments, the metrics used to identify abnormal hosts are calculated using the following steps: Based on the average number of times each machine was exposed to the virus, the upward standard deviation of the number of times each machine was exposed to the virus was calculated. Calculate the abnormal standard for the number of exposures based on the average number of exposures per machine and the upward standard deviation; The number of hosts whose number of infections exceeds the abnormal infection threshold is counted as the number of abnormal hosts. The proportion of the number of abnormal hosts to the total number of infection events is calculated as the proportion of abnormal host infections.

[0008] In some embodiments, the intermediate indicator on which the safety evaluation level is based is the number of virus types involved in the infection event.

[0009] In some embodiments, generating a security evaluation level for the target area within the time unit by using at least one of the intermediate indicators according to preset rules includes: The number of virus types is compared with multiple preset threshold ranges; Based on the comparison results, the safety evaluation levels are divided into four grades: excellent, good, average, and poor.

[0010] In some embodiments, based on the security assessment level, corresponding early warning information is issued, including: When the security assessment level is poor, a red alert for a particularly serious cybersecurity incident will be issued. When the security assessment level is medium, an orange alert for a major cybersecurity incident will be issued. When the security assessment level is "good", a yellow alert for a major cybersecurity incident will be issued. When the security assessment level is excellent, a blue alert for general cybersecurity incidents will be issued.

[0011] In some embodiments, the target area is a logical range that maps to an administrative division or IP address range.

[0012] In some embodiments, the time unit includes days, and a comprehensive evaluation of the security situation is conducted based on the time unit of days for weeks, months, and quarters.

[0013] Secondly, embodiments of the present invention provide a virus attack early warning device based on regional and time-segmented analysis, the device comprising: The acquisition module is used to acquire source data of virus activity in a target area within at least one time unit. The source data includes: the number of active hosts, the number of infection events, the number of hosts involved in the infection events, and the number of virus types involved in the infection events. The calculation module is used to calculate one or more intermediate indicators for evaluating the security status of the target area within the time unit based on the source data. The intermediate indicators include: average number of times per machine is infected, proportion of infected hosts, and indicators for identifying abnormal hosts. The generation module is used to generate a safety evaluation level for the target area within the time unit by using at least one of the intermediate indicators according to preset rules. The early warning module is used to issue corresponding early warning information based on the security assessment level.

[0014] In some embodiments, the device further includes a visualization module for displaying the source data, intermediate indicators, security evaluation levels, and early warning information in graphical or tabular form.

[0015] Thirdly, embodiments of this application provide an electronic device, including a memory and a processor, wherein the memory stores program code that can run on the processor, and when the program code is executed by the processor, it implements the virus attack early warning method based on regional and time-segmented analysis as described in any embodiment of the first aspect.

[0016] Fourthly, embodiments of this application provide a computer storage medium storing one or more programs, which can be executed by an electronic device as described in the third aspect to implement the virus attack early warning method based on regional and time-segmented analysis as described in any embodiment of the first aspect.

[0017] This invention provides a virus attack early warning method and device based on regional and time-segmented analysis. By collecting data from different regions and performing aggregated analysis, it can grasp the spatial distribution patterns of virus activity from a macro perspective, identify high-risk areas, and provide decision support for resource allocation, achieving macro-level situational awareness. It integrates multiple dimensions of indicators, such as the number of virus events, the range of infected hosts, infection intensity, virus diversity, and abnormal spread points, making the security assessment more comprehensive, objective, and accurate. This effectively reduces false alarms and missed alarms in single-indicator early warnings, achieving multi-dimensional and accurate assessment. It supports analysis by different time units such as days, weeks, and months, enabling timely detection of short-term virus outbreak trends and rapid communication of risk levels through hierarchical early warning information, improving the timeliness and operability of early warnings. The entire process can be completed automatically, reducing manual intervention and improving efficiency. Simultaneously, combined with visualization, the security situation is clear at a glance, facilitating rapid understanding and response by management personnel.

[0018] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0019] The invention will now be described in more detail with reference to embodiments and the accompanying drawings.

[0020] Figure 1 The diagram illustrates an exemplary virus attack early warning method based on regional and time-segmented analysis, as proposed in one embodiment of the present invention. Figure 2 A schematic diagram of an exemplary virus analysis process according to an embodiment of the present invention is shown; Figure 3 The diagram shows a structural block diagram of a virus attack early warning device based on regional and time-segmented analysis proposed in one embodiment of the present invention. Figure 4 This diagram illustrates a structural block diagram of an electronic device for performing a virus attack early warning method based on regional and time-segmented analysis according to an embodiment of this application. Figure 5 This illustration shows a structural block diagram of a computer-readable storage medium for storing or carrying a virus attack early warning method based on regional and time-segmented analysis according to an embodiment of this application. Detailed Implementation

[0021] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and are not intended to limit the present invention.

[0022] Currently, existing technologies mainly focus on using AI models and federated learning methods for virus attack early warning. These technologies typically involve detecting and issuing early warnings of location-based threats through dynamic behavioral analysis. However, existing early warning systems often have the following shortcomings: Lack of a macro perspective: Most focus on security incidents of individual hosts or single network nodes, making it difficult to discover the trends and patterns of virus spread at the regional level.

[0023] The early warning indicators are too simplistic: they are usually based solely on the absolute number of virus events, failing to take into account multi-dimensional indicators such as the scope of host infection, the diversity of virus types, and abnormal host behavior. This results in low accuracy of early warnings and a high risk of false alarms or missed alarms.

[0024] Poor timeliness: The analysis cycle is inflexible and cannot be dynamically analyzed in different time periods according to the characteristics of different regions, making it difficult to detect concentrated outbreak trends in a timely manner.

[0025] Therefore, the applicant believes that there is an urgent need in this field for a virus attack early warning technology that can comprehensively analyze multiple indicators from a macro perspective and support dynamic analysis by region and time period, so as to achieve more accurate and timely security threat early warning.

[0026] The following describes an application scenario of a virus attack early warning method based on regional and time-segmented analysis provided by an embodiment of the present invention: Please see Figure 1 , Figure 1 This is a flowchart illustrating a virus attack early warning method based on regional and time-segmented analysis provided in this embodiment of the invention. In this embodiment, the virus attack early warning method based on regional and time-segmented analysis can be applied to, for example... Figure 3 The virus attack early warning device 300 shown is based on regional and time-time analysis. Figure 4 In the electronic device 200 shown, the following is specifically for... Figure 1 The process shown is described in detail. A virus attack early warning method based on regional and time-segmented analysis may include S110 to S140.

[0027] S110: Obtain source data on virus activity in the target area within at least one time unit. The source data includes: the number of active hosts, the number of infection events, the number of hosts involved in the infection events, and the number of virus types involved in the infection events.

[0028] In this embodiment, the core of the model is quantitative analysis based on regional and time dimensions. A region can refer to a specific logical range and is the basic unit of analysis. Source data is the basis for all calculations and evaluations and can be collected from network security management platforms or security probe systems.

[0029] In some implementations, the target area is a logical range that maps to administrative divisions or IP address ranges.

[0030] In this embodiment, the division of regions is flexible and can be defined according to management needs. First, a region is defined as a specific logical range, which can be mapped to an administrative division or an IP address range. In this method, these are collectively referred to as units. For example, it can be a province, a city, or a specific local area network segment, such as an IP address range. This division method allows the analysis to adapt to the management needs of networks of different levels and sizes.

[0031] In some implementations, the time unit includes days, and a comprehensive evaluation of the security situation is conducted based on the time unit of days for weeks, months, and quarters.

[0032] In this embodiment, the regional time-dimensional security level evaluation uses the day as the smallest unit. Based on the daily evaluation, a comprehensive evaluation of the security situation over a week, month, or quarter can be performed, using the day as the smallest unit of analysis to calculate daily security indicators. Furthermore, by aggregating daily indicators over a week, month, or quarter—such as by taking the average, maximum, or weighted value—a comprehensive security situation evaluation over a longer period can be achieved, which helps in identifying trend changes.

[0033] S120: Based on source data, calculate one or more intermediate indicators for assessing the security status of the target area within a time unit. The intermediate indicators include: average number of times per machine is infected, the proportion of infected hosts, and indicators for identifying abnormal hosts.

[0034] In this embodiment, intermediate indicators are key parameters extracted from the raw data that more accurately reflect the security status. Calculating the average number of infections per machine and the proportion of infected hosts can assess the breadth and depth of infection. The introduction of abnormal host indicators is to distinguish the pattern of virus outbreaks, determining whether it is a widespread infection or a concentrated outbreak caused by a few nodes.

[0035] In some implementations, the indicators for identifying abnormal hosts in S120 are calculated using the following steps, which may include S121 to S124, wherein: S121: Calculate the upward standard deviation of the number of times each machine is infected, based on the average number of times each machine is infected.

[0036] In this embodiment, the upward standard deviation is used to measure the dispersion of the number of times each host is infected with the virus relative to the average value within the region. In particular, it focuses on fluctuations above the average value and can effectively capture abnormally high infection rates.

[0037] S122: Calculate the abnormal standard for the number of times of infection based on the average number of times of infection per machine and the upward standard deviation.

[0038] In this embodiment, the abnormal number of virus infections can be used as a threshold to determine whether a host is an abnormal host. When the number of daily virus infections of a host exceeds this standard value, the host is considered to have abnormal virus infection behavior and may be a virus source or a key target for infection.

[0039] S123: Count the number of hosts whose number of infections exceeds the abnormal infection threshold, and use this count as the number of abnormal hosts.

[0040] S124: Calculate the proportion of abnormal hosts to the total number of infection events, and use this as the proportion of abnormal host infections.

[0041] In this embodiment, the proportion of times abnormal hosts were infected reflects the extent to which virus activity was caused by a small number of abnormal hosts. The higher the proportion, the more concentrated the virus spread, potentially indicating the existence of super-spreaders, requiring focused attention.

[0042] In some implementations, the intermediate indicator used to determine the safety assessment level is the number of virus types involved in the infection incident.

[0043] In this embodiment, the number of virus types is a key basis for the final security assessment and early warning classification. This is because the number of virus types reflects the complexity and diversity of the threat, and can serve as an important indicator for measuring the severity of a security incident.

[0044] S130: Based on preset rules, at least one of the intermediate indicators is used to generate a safety evaluation level for the target area within a time unit.

[0045] In this embodiment, the security assessment level is a qualitative conclusion about the security status of the area on a given day. This conclusion is based on quantitative indicators, such as a comparison of the number of virus types with a preset threshold, ensuring that the assessment results are objective and consistent.

[0046] In some embodiments, S130 may further include S131 to S132, wherein: S131: Compare the number of virus types with multiple preset threshold ranges.

[0047] In this embodiment, multiple preset thresholds, such as a, b, and c, can be set to form four consecutive intervals. The specific values ​​of these thresholds can be set based on a combination of factors, including network size, the number of hosts, and the administrator's tolerance for risk.

[0048] S132: Based on the comparison results, the safety evaluation level is divided into four levels: excellent, good, average, and poor.

[0049] In this embodiment, the classification rules are simple and clear, making it easy for managers to quickly understand the risk levels.

[0050] S140: Issue corresponding early warning information based on the safety assessment level.

[0051] In this embodiment, the warning information is the output of the evaluation results and action guidelines. A color-coded warning mechanism is used to transform the abstract security level into specific and operable warning instructions.

[0052] In some embodiments, S140 may further include S141 to S144, wherein: S141: When the security assessment level is poor, a red alert for a particularly serious cybersecurity incident will be issued.

[0053] In this embodiment, a red alert represents a particularly serious cybersecurity incident. At this time, the system should immediately issue an alert to the highest-level cybersecurity administrator and may trigger automated emergency response procedures, such as isolating key areas and initiating source tracing analysis.

[0054] S142: When the security assessment level is medium, issue an orange alert for major cybersecurity incidents.

[0055] In this embodiment, an orange alert represents a major cybersecurity incident. The regional cybersecurity officer should be notified to strengthen monitoring and prepare for necessary manual intervention measures.

[0056] S143: When the security assessment level is good, a yellow alert for a major cybersecurity incident will be issued.

[0057] In this embodiment, a yellow alert indicates a major cybersecurity incident. This can be prominently displayed on the large screen in the security monitoring center to remind on-duty personnel to pay attention to the security situation in that area.

[0058] S144: When the security assessment level is excellent, a blue alert for general cybersecurity incidents will be issued.

[0059] In this embodiment, a blue alert represents a general cybersecurity incident or a normal state. Typically, only logging is performed, or it is displayed as low risk in reports, without requiring the activation of special emergency procedures.

[0060] See Figure 2 As shown, in the specific application implementation stage, this application may include the following process: First, the region is defined as a specific logical area, which can be mapped to an administrative division or an IP range; in this method, it is collectively referred to as a unit. The time-based security level evaluation based on the region uses the day as the smallest unit. Based on the daily evaluation, a comprehensive evaluation of weekly, monthly, and quarterly security is conducted. The model principle is as follows: The following uses a drug-related incident as an example to explain the model's principles.

[0061] Step 1. The source data for the model is as follows: IPs: refers to the range of IP addresses, which is the statistical measure of virus activity within a certain range in the model.

[0062] Day: refers to the day, which is the statistical value of virus activity within a certain range of days in the model.

[0063] Active Host (ips, day): refers to the number of active (powered on and connected to the network) hosts within the range of ips on day day.

[0064] Infect_CS(ips, day): This refers to the number of infection events occurring within the range of ips on day .

[0065] InfectHost(ips, day): refers to the number of hosts involved in the infection event within the range of ips on day day.

[0066] Number of hosts involved in the poisoning incident: Infect_GS(ips, day): refers to the number of virus types involved in the infection events within the range of ips on day .

[0067] Step 2. Analysis of intermediate indicators of the model Intermediate indicators are indicators obtained from source data analysis according to certain principles and calculation formulas. The relationship between intermediate indicators and their calculation formulas are explained below: Infect_CS_M(ips, day): This refers to the average number of times each machine is infected within the range of ips on day . The calculation formula is as follows:

[0068] InfectHost_Prp(ips, day): This refers to the percentage of hosts within the range of ips that are infected with the virus on day 1. The calculation formula is as follows:

[0069] Infect_CS_SSD(ips, day): This refers to the upward standard deviation of the number of times each machine is infected within the range of ips on day 1. The calculation formula is as follows:

[0070] Where n is the number of IPs that meet the conditions.

[0071] Infect_CS_Max(ips, day): This refers to the abnormal standard for the number of infections within the range of ips on day . The calculation formula is as follows:

[0072] If the number of times a host is infected with a virus exceeds this value, the number of times the host is infected with a virus is considered abnormal.

[0073] Infect_Abnml_Host(ips, day): This refers to the number of infected and abnormal hosts within the range of ips on day 1. The calculation formula is as follows:

[0074]

[0075] Infect_Abnml_Prp(ips, day): This refers to the percentage of infected hosts within the range of ips on day 1. The calculation formula is as follows:

[0076] Virus outbreaks can be either localized and widespread. Infect_CS_M(ips, day) cannot distinguish between these two scenarios. Introducing Infect_CS_Max(ips, day), Infect_Abnml_Host(ips, day), and Infect_Abnml_Prp(ips, day) into the virus model can effectively differentiate between virus outbreak scenarios.

[0077] Step 3. Model Comprehensive Analysis The ultimate goal of the network virus security assessment and early warning model is to derive a security assessment based on the average number of virus infections per machine. Along with the security assessment, the model also provides the basis for it, namely the values ​​of various intermediate and final indicators. By presenting these values ​​in the form of graphs, tables, etc., administrators can gain a comprehensive understanding of the system's security. The correlation and calculation formulas for the comprehensive indicators are as follows: Infect_CS_PJ(ips, day): Refers to the average number of times each machine is infected within the range of ips on day , calculated using the following formula:

[0078] =

[0079]

[0080]

[0081] The values ​​of a, b, and c are determined by a combination of factors, including the scale of the number of machines and the requirements for the warning level.

[0082] When Infect_GS(ips, day)≤a, it is a general network security incident warning, and a blue warning message is issued; When a < Infect_GS (ips, day) ≤ b, it is a warning of a major network security incident, and a yellow warning message is issued. When b < Infect_GS (ips, day) ≤ c, it is a warning of a major cybersecurity incident, and an orange warning message is issued. When c < Infect_GS(ips, day), a red alert is issued for a particularly serious cybersecurity incident.

[0083] In summary, this application combines time and regional dimensions to monitor the overall security status of the network in real time, detect and warn of abnormal areas and viruses, and establish a unified virus centralized evaluation and early warning management system covering the entire network to evaluate the overall status in real time and effectively control its spread.

[0084] Please see Figure 3 , Figure 3 A structural block diagram of a virus attack early warning device 300 based on regional and time-segmented analysis provided by the present invention includes: an acquisition module 310, a calculation module 320, a generation module 330, and an early warning module 340, wherein: The acquisition module 310 is used to acquire source data of virus activity in the target area within at least one time unit. The source data includes: the number of active hosts, the number of infection events, the number of hosts involved in the infection events, and the number of virus types involved in the infection events. The calculation module 320 is used to calculate one or more intermediate indicators for evaluating the security status of the target area within a time unit based on the source data. The intermediate indicators include: the average number of times per machine is infected, the proportion of infected hosts, and indicators for identifying abnormal hosts. The generation module 330 is used to generate a safety evaluation level of the target area within a time unit by using at least one of the intermediate indicators according to preset rules. The early warning module 340 is used to issue corresponding early warning information based on the safety assessment level.

[0085] In some implementations, the virus attack early warning device 300 based on regional and time-segmented analysis further includes a visualization module, which displays source data, intermediate indicators, security evaluation levels, and early warning information in graphical or tabular form.

[0086] It should be noted that the device embodiments in this invention correspond to the aforementioned method embodiments. The specific principles in the device embodiments can be found in the content of the aforementioned method embodiments, and will not be repeated here.

[0087] In the several embodiments provided in this example, the coupling between modules can be electrical, mechanical, or other forms of coupling.

[0088] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0089] Please see Figure 4 , Figure 4The present application provides a structural block diagram of an electronic device 200 that can perform the above-described virus attack early warning method based on regional and time-segmented analysis. The electronic device 200 may be a smartphone, tablet computer, computer, or portable computer.

[0090] The electronic device 200 also includes a processor 202 and a memory 204. The memory 204 stores programs that can execute the contents of the foregoing embodiments, and the processor 202 can execute the programs stored in the memory 204.

[0091] The processor 202 may include one or more cores for data processing and message matrix units. The processor 202 connects to various parts within the electronic device 200 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 204, and by calling data stored in the memory 204. Optionally, the processor 202 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 202 may integrate one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem / decoder. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem / decoder handles wireless communication. It is understood that the modem / decoder may also be implemented separately as a communication chip, without being integrated into the processor.

[0092] Memory 204 may include random access memory (RAM) or read-only memory (ROM). Memory 204 can be used to store instructions, programs, code, code sets, or instruction sets. Memory 204 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (e.g., instructions for a user to obtain random numbers), instructions for implementing the various method embodiments described below, etc. The data storage area may also store data (e.g., random numbers) created by the terminal during use.

[0093] Electronic device 200 may also include a network module and a screen. The network module is used to receive and transmit electromagnetic waves, converting electromagnetic waves into electrical signals, thereby enabling communication with communication networks or other devices, such as audio playback devices. The network module may include various existing circuit elements used to perform these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, SIM cards, memory, etc. The network module can communicate with various networks such as the Internet, corporate intranets, and wireless networks, or communicate with other devices via wireless networks. The aforementioned wireless networks may include cellular telephone networks, wireless local area networks, or metropolitan area networks. The screen can display interface content and facilitate data interaction.

[0094] Please refer to Figure 5 , Figure 5 This diagram illustrates a structural block diagram of a computer-readable storage medium according to an embodiment of this application. The computer-readable storage medium 400 stores program code 410, which can be called by a processor to execute the methods described in the above method embodiments.

[0095] The computer-readable storage medium 400 may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium 400 has storage space for program code 410 that performs any of the method steps described above. This program code 410 can be read from or written to one or more computer program products. The program code 410 may be compressed, for example, in a suitable form.

[0096] This application also provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the virus attack early warning method based on region- and time-segmented analysis described in the various optional implementations above.

[0097] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A virus attack early warning method based on regional and time-segmented analysis, characterized in that, The method includes: Obtain source data on virus activity in the target area within at least one time unit. The source data includes: the number of active hosts, the number of infection events, the number of hosts involved in the infection events, and the number of virus types involved in the infection events. Based on the source data, one or more intermediate indicators are calculated to assess the security status of the target area within the time unit. The intermediate indicators include: average number of times per machine is infected, proportion of infected hosts, and indicators for identifying abnormal hosts. Based on preset rules, at least one of the intermediate indicators is used to generate a safety evaluation level for the target area within the time unit. Based on the aforementioned safety assessment level, corresponding early warning information will be issued.

2. The virus attack early warning method based on regional and time-segmented analysis according to claim 1, characterized in that, The metrics used to identify abnormal hosts are calculated using the following steps: Based on the average number of times each machine was exposed to the virus, the upward standard deviation of the number of times each machine was exposed to the virus was calculated. Calculate the abnormal standard for the number of exposures based on the average number of exposures per machine and the upward standard deviation; The number of hosts whose number of infections exceeds the abnormal infection threshold is counted as the number of abnormal hosts. The proportion of the number of abnormal hosts to the total number of infection events is calculated as the proportion of abnormal host infections.

3. The virus attack early warning method based on regional and time-segmented analysis according to claim 2, characterized in that, The intermediate indicator on which the safety evaluation level is based is the number of virus types involved in the infection event.

4. The virus attack early warning method based on regional and time-segmented analysis according to claim 3, characterized in that, The step of generating a safety evaluation level for the target area within the time unit by using at least one of the intermediate indicators according to preset rules includes: The number of virus types is compared with multiple preset threshold ranges; Based on the comparison results, the safety evaluation levels are divided into four grades: excellent, good, average, and poor.

5. The virus attack early warning method based on regional and time-segmented analysis according to claim 4, characterized in that, Based on the aforementioned security assessment level, corresponding early warning information will be issued, including: When the security assessment level is poor, a red alert for a particularly serious cybersecurity incident will be issued. When the security assessment level is medium, an orange alert for a major cybersecurity incident will be issued. When the security assessment level is "good", a yellow alert for a major cybersecurity incident will be issued. When the security assessment level is excellent, a blue alert for general cybersecurity incidents will be issued.

6. The virus attack early warning method based on regional and time-segmented analysis according to claim 1, characterized in that, The target area is a logical range, mapped to an administrative division or IP address range.

7. A virus attack early warning device based on regional and time-segmented analysis, characterized in that, The device includes: The acquisition module is used to acquire source data of virus activity in a target area within at least one time unit. The source data includes: the number of active hosts, the number of infection events, the number of hosts involved in the infection events, and the number of virus types involved in the infection events. The calculation module is used to calculate one or more intermediate indicators for evaluating the security status of the target area within the time unit based on the source data. The intermediate indicators include: average number of times per machine is infected, proportion of infected hosts, and indicators for identifying abnormal hosts. The generation module is used to generate a safety evaluation level for the target area within the time unit by using at least one of the intermediate indicators according to preset rules. The early warning module is used to issue corresponding early warning information based on the security assessment level.

8. The virus attack early warning device based on regional and time-segmented analysis according to claim 7, characterized in that, The device also includes a visualization module for displaying the source data, intermediate indicators, security evaluation levels, and early warning information in graphical or tabular form.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores program code that can run on the processor. When the program code is executed by the processor, it implements the virus attack early warning method based on regional and time-segmented analysis as described in any one of claims 1-6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program code that can be invoked by one or more processors to execute the virus attack early warning method based on regional and time-segmented analysis as described in any one of claims 1-6.