Network security posture prediction method and apparatus
Patent Information
- Application Number
- CN202610892961.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-21
- Publication Date
- 2026-09-15
Smart Images

Figure CN122764597A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to methods and apparatus for predicting network security situations. Background Technology
[0002] With the deep integration of network technology into various scenarios such as smart homes, smart cities, and smart agriculture, the network environment is becoming increasingly heterogeneous and dynamic, and attack methods are becoming more complex and covert, placing higher demands on the ability to anticipate and predict network security issues.
[0003] As a forward-looking core component of the situational awareness system, cybersecurity situation prediction can predict future changes in security status based on historical situational data. It is a key technology for achieving proactive cybersecurity defense, and its prediction accuracy directly determines the effectiveness and timeliness of defense strategies.
[0004] The current application of deep learning technology in time series prediction is driving the upgrade of cybersecurity situation prediction from traditional statistical models to intelligent modeling. However, existing technologies still struggle to adapt to the inherent characteristics of cybersecurity situations, such as nonlinearity, abrupt changes, and spatiotemporal correlations. The accuracy and stability of forward-looking predictions need further improvement. Therefore, an effective solution is urgently needed to address these issues. Summary of the Invention
[0005] To address the aforementioned technical problems, this invention provides a method and apparatus for predicting network security situation.
[0006] In a first aspect, the present invention provides a method for predicting network security situation, comprising: Based on intrusion detection data, situation assessment data, and network traffic data of the target network, multi-dimensional features are determined. These multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior. Based on the multi-dimensional features at different times and a sliding time window of a set length, a time series is constructed; The time series is input into a set spatiotemporal dual-feature model to construct spatiotemporal dual features, thereby obtaining a feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-feature model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network. The feature matrix is subjected to feature weighted fusion and regression mapping to obtain the security status value corresponding to the target network.
[0007] In some embodiments, the determination of multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network includes: The intrusion detection data is statistically and aggregated to obtain the detection-derived features, which include the proportion of attack traffic, the average confidence level, and the proportion of target attacks, wherein the confidence level of the target attacks is higher than the confidence level threshold. Feature extraction is performed on the situation assessment data to obtain the historical situation features; The network traffic data is statistically analyzed to obtain the network traffic characteristics, which include average packet length, peak flow rate, average connection duration, TCP percentage, and UDP percentage.
[0008] In some embodiments, the step of inputting the time series into a predefined spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics and obtain a feature matrix that integrates temporal dependence and spatial correlation includes: The time series sequence is input into the time series convolutional network to extract local abrupt change features of the situation, thereby obtaining a feature sequence containing local abrupt change features of the situation. The feature sequence is input into the convolutional long short-term memory network to perform spatiotemporal dual-feature joint modeling, thereby obtaining the feature matrix that integrates temporal dependence and spatial correlation.
[0009] In some embodiments, the temporal convolutional network includes residual connection layers and at least two cascaded dilated convolutional layers, each with a different dilation rate; The step of inputting the temporal sequence into the temporal convolutional network to extract local abrupt change features of the situation, thereby obtaining a feature sequence containing local abrupt change features, includes: Multi-scale situational change features are extracted from the time series by using at least two cascaded dilated convolutional layers. The time series sequence is residually mapped through the residual connection layer to obtain the mapping result, and the mapping result is fused with the multi-scale situational change features to obtain the feature sequence containing the situational local change features.
[0010] In some embodiments, the extraction of multi-scale abrupt change features from the time-series sequence through at least two cascaded dilated convolutional layers to obtain multi-scale abrupt change features includes: For the current dilated convolutional layer in the at least two cascaded dilated convolutional layers, the input and bias term of the current dilated convolutional layer are weighted based on the kernel weights of the current dilated convolutional layer to obtain a weighted sum; The weighted sum is processed using the first activation function to obtain the output of the current dilated convolutional layer; Wherein, if the current dilated convolutional layer is the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the temporal sequence; if the current dilated convolutional layer is not the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the output of the previous dilated convolutional layer; if the current dilated convolutional layer is the last dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the output of the current dilated convolutional layer is the multi-scale situational change feature.
[0011] In some embodiments, the convolutional long short-term memory network includes at least two cascaded convolutional long short-term memory layers; The step of inputting the feature sequence into the convolutional long short-term memory network for joint spatiotemporal dual-feature modeling to obtain the feature matrix that integrates temporal dependence and spatial correlation includes: For each of the convolutional long short-term memory layers, a first gate vector is obtained by extracting a gate vector based on the input data of the convolutional long short-term memory layer through the input gate of the convolutional long short-term memory layer. By using the forget gate of the convolutional long short-term memory layer, the gating vector is extracted based on the input data of the convolutional long short-term memory layer to obtain the second gating vector; The memory state at the current moment is obtained by updating the state through the memory unit of the convolutional long short-term memory layer based on the first gate vector, the second gate vector and the input data of the convolutional long short-term memory layer. The third gating vector is obtained by extracting the gating vector based on the input data of the convolutional long short-term memory layer through the output gate of the convolutional long short-term memory layer. The hidden state of the output of the convolutional long short-term memory layer is determined through the hidden layer of the convolutional long short-term memory layer, based on the third gating vector and the memory state at the current time. Wherein, the input data of the first convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature sequence, the input data of the other convolutional long short-term memory layers in the at least two convolutional long short-term memory layers is the hidden state output by the previous convolutional long short-term memory layer, the hidden state output by the last convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature matrix, the dimension of the hidden layer of the first convolutional long short-term memory layer is the first dimension, the dimension of the hidden layer of the last convolutional long short-term memory layer is the second dimension, and the first dimension is greater than the second dimension.
[0012] In some embodiments, the step of performing feature weighted fusion and regression mapping on the feature matrix to obtain the security posture value corresponding to the target network includes: Based on the attention mechanism, the feature matrix is subjected to feature weight fusion to obtain a fused feature matrix; The security posture value corresponding to the target network is obtained by performing regression mapping on the fused feature matrix through a fully connected layer.
[0013] In some embodiments, the feature matrix includes T spatiotemporal feature vectors at time steps, where T represents the set length, and the attention mechanism is a time step attention mechanism. The attention-based mechanism is used to perform feature weighting and fusion on the feature matrix to obtain a fused feature matrix, including: Based on the time-step attention mechanism, the weight of each spatiotemporal feature vector is determined; Based on the weight of each spatiotemporal feature vector, each spatiotemporal feature vector is weighted and fused to obtain the fused feature matrix.
[0014] In some embodiments, the step of performing regression mapping on the fused feature matrix through a fully connected layer to obtain the security posture value corresponding to the target network includes: The fused feature matrix is nonlinearly mapped through the fully connected layer to obtain the mapped value; Based on the second activation function, the mapping value is activated and output to obtain the security posture value corresponding to the target network.
[0015] Secondly, the present invention also provides a network security situation prediction device, comprising: The determination module is configured to determine multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network. The multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior. The first construction module is configured to construct a time series based on the multi-dimensional features at different times and a sliding time window of a set length; The second construction module is configured to input the time series into a set spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics, thereby obtaining a feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-characteristic model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network. The mapping module is configured to perform feature weighted fusion and regression mapping on the feature matrix to obtain the security status value corresponding to the target network.
[0016] Thirdly, the present invention also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the network security situation prediction method described in the first aspect above.
[0017] Fourthly, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network security situation prediction method described in the first aspect above.
[0018] Fifthly, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the network security situation prediction method described in the first aspect above.
[0019] Compared with existing technologies, the network security situation prediction method and apparatus provided by this invention determine multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network. These multi-dimensional features include network traffic features, detection-derived features, and historical situation features. Detection-derived features are used to quantify the intensity and credibility of network attack behavior, overcoming the limitations of a single situation value input. By quantifying the intensity and credibility of attack behavior through "detection-derived features," the core driving factor of situation change—attack behavior—is introduced into a spatiotemporal dual-characteristic model, establishing an intrinsic correlation between attack features and situation changes, providing sufficient information support for high-precision prediction. Based on multi-dimensional features at different times and a sliding time window of a set length, a time series is constructed, effectively mitigating the impact of long-term... The accuracy decay problem in time-series prediction is addressed by maintaining high accuracy and stability across all time steps. The time series is input into a predefined spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics, resulting in a feature matrix that integrates temporal dependencies and spatial correlations. A hybrid architecture combining cascaded temporal convolutional networks and convolutional long short-term memory networks is employed. The temporal convolutional network captures local abrupt changes in the situation, while the convolutional long short-term memory network simultaneously models long-term temporal dependencies and multi-feature spatial correlation features, overcoming the limitation of general models that can only model in a single dimension. Furthermore, the feature matrix undergoes feature weighted fusion and regression mapping to obtain the security situation value corresponding to the target network, improving the accuracy and reliability of the security situation value and thus achieving high-precision forward-looking prediction of network security situation.
[0020] Details of one or more embodiments of the present invention are set forth in the following drawings and description to make other features, objects and advantages of the invention more readily apparent. Attached Figure Description
[0021] The accompanying drawings, which are provided to further illustrate the invention, constitute a part of this invention. Those skilled in the art will recognize that other drawings can be derived from these drawings without any inventive effort. The illustrative embodiments and descriptions of the invention are used to explain the invention and do not constitute an undue limitation thereof.
[0022] Figure 1 This is a flowchart illustrating the network security situation prediction method provided by the present invention.
[0023] Figure 2 This is a schematic diagram of the network security situation prediction device provided by the present invention.
[0024] Figure 3 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0025] To more clearly understand the objectives, technical solutions, and advantages of this invention, the technical solutions of this invention will be clearly and completely described and explained below with reference to the accompanying drawings and embodiments. Obviously, the described embodiments are only some embodiments of this invention, not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0026] Unless otherwise defined, the technical or scientific terms used in this invention shall have the general meaning understood by one of ordinary skill in the art to which this invention pertains. Words such as “a,” “an,” “an,” “the,” “the,” and “these” used in this invention do not indicate quantitative limitation and may be singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this invention are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or modules (units) is not limited to the listed steps or modules (units) but may include steps or modules (units) not listed, or may include other steps or modules (units) inherent to these processes, methods, products, or devices. The terms “connected,” “linked,” and “coupled” used in this invention are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. “A plurality” used in this invention refers to two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. Normally, the character " / " indicates that the objects before and after it are in an "or" relationship. The terms "first," "second," "third," etc., used in this invention are merely for distinguishing similar objects and do not represent a specific ordering of the objects.
[0027] First, a brief description of the relevant content involved in this invention will be given.
[0028] Existing cybersecurity situation prediction technologies mostly use a single situation value sequence as the core input of the prediction model, only mining the surface temporal patterns of the situation values themselves, and failing to effectively reuse the multi-dimensional features extracted in the pre-intrusion detection and situation assessment stages. Specifically, the implementation methods are as follows: Data input: Only the time series of a single situation value output from the historical situation assessment is used as the model input, ignoring basic statistical characteristics of network traffic (such as average packet length, proportion of Transmission Control Protocol (TCP)) and intrusion detection derived characteristics (such as proportion of attack traffic, detection confidence). Model modeling: It directly reuses general time series prediction models such as Long Short-Term Memory (LSTM), Gated Recurrent Unit (GRU), and Temporal Convolutional Network (TCN), without customizing the architecture design for the dual characteristics of the time series dependence and feature spatial correlation of network security situation. It can only capture the time series pattern in a single dimension and cannot explore the spatial correlation between multiple features. Feature utilization: The lack of a targeted feature weighting mechanism results in features with different contributions to situational changes being treated with equal weight. Redundant features can easily interfere with modeling accuracy, and the role of key attack-derived features cannot be effectively highlighted.
[0029] Therefore, most existing network security situation prediction technologies have the following drawbacks: The feature utilization is one-sided and the prediction basis is insufficient: using only a single situation value as input severs the technical link between intrusion detection and situation prediction, idles the basic statistical features and derived features in the intrusion detection stage, fails to capture the internal driving logic of "attack behavior - situation change", and is prone to prediction bias due to missing information. Poor model adaptability and difficulty in dealing with spatiotemporal characteristics: General time series models (LSTM, GRU, single TCN) can only model temporal dependencies and cannot effectively explore the spatial correlation between multi-dimensional features. They are insufficient in capturing local changes in the situation caused by sudden attacks and are prone to prediction lag. Fixed feature weights result in low utilization efficiency: There is no dynamic feature weight allocation mechanism, making it impossible to differentiate features based on their contribution to situational changes. Redundant features interfere with modeling accuracy, weakening the role of key attack features and resulting in insufficient model generalization ability and stability. Long-term prediction accuracy decays significantly: The ability to model long-term situation evolution is limited. As the prediction step length increases, the accumulation of time-series dependence leads to amplified errors. In long-term prediction tasks such as 48 steps, the accuracy drops significantly, making it difficult to meet the forward-looking early warning needs of real-world scenarios.
[0030] To address the shortcomings of existing network security situation prediction technologies, such as one-sided feature utilization, poor model adaptability, low feature utilization efficiency, and long-term prediction accuracy decay, this invention provides a network security situation prediction method and apparatus to solve the following problems: How to reuse the multi-dimensional features of the intrusion detection process, construct a multi-dimensional input system, make up for the information shortcomings of a single situational value input, and establish a driving correlation between attack behavior and situational changes; How to design a hybrid model architecture that adapts to the spatiotemporal characteristics of network security situation, while accurately capturing the local mutation features, long-term time-series dependency features, and multi-feature spatial correlation features of the situation; How to introduce a dynamic feature weight allocation mechanism to adaptively adjust the weights according to the contribution of features to situational changes, strengthen key features, suppress redundant features, and improve the model's generalization ability and stability; How to alleviate the accuracy decay problem in long-term forecasting, improve the forecast accuracy and stability under different forecast step sizes such as 12 steps, 24 steps, and 48 steps, and meet the needs of forward-looking early warning in multiple scenarios.
[0031] The following is combined with Figures 1 to 2The present invention describes a network security situation prediction method and apparatus.
[0032] Figure 1 This is a flowchart illustrating the network security situation prediction method provided by the present invention, as follows: Figure 1 As shown, this network security situation prediction method includes the following steps: Step 101: Based on the intrusion detection data, situation assessment data, and network traffic data of the target network, determine multi-dimensional features. The multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior.
[0033] Specifically, the target network is the network for which security posture prediction is required.
[0034] In practical applications, the target dataset (such as the CICIDS2017 dataset) can be used as a basis to reuse the output results of the pre-intrusion detection (intrusion detection data) and the situation assessment (situation assessment data) for the target network. Combined with the original network traffic (network traffic data), three types of original feature sets can be constructed, that is, to determine multi-dimensional features including network traffic features, detection-derived features, and historical situation features. : ; in, As network traffic characteristics, To detect derived features, This reflects the characteristics of the historical situation.
[0035] Step 102: Construct a time series based on the multi-dimensional features at different times and a sliding time window of a set length.
[0036] Specifically, the length is set to T, that is, the time step is T, which can be set according to the requirements. For example, T=24.
[0037] In practical applications, a sliding time window of length T is used to construct a time series from the single-step feature vector, i.e., the multi-dimensional features of a single time step. The input tensor for forming the spatiotemporal dual-characteristic model is: ; Where T is the set length. For the multi-dimensional features at time step tT, For the multi-dimensional features at time step t-(T+1), For the multidimensional features at time step t.
[0038] Furthermore, to avoid the impact of differences in feature dimensions on the accuracy of subsequent spatiotemporal dual-property construction, Z-score standardization can be used to normalize the time series, unifying the dimensions and obtaining a normalized time series. Subsequent steps are then performed based on this normalized time series. The normalization formula is: ; Where x is the time series sequence before normalization. Let μ be the normalized time series, μ be the mean of the time series in the training set, and δ be the standard deviation of the time series in the training set.
[0039] It should be noted that μ and δ are not calculated from the current time series, but are global parameters obtained solely from the training set statistics. When standardizing the training, validation, and test sets, the same set of μ and δ (both from the training set) is used to ensure consistency in data distribution and avoid data leakage.
[0040] In practice, for each feature dimension of the current time series x, subtract the mean of the training set corresponding to that dimension, and then divide by the standard deviation of the training set corresponding to that dimension.
[0041] For example, suppose the current time series x has d feature dimensions, then: ; in, Let x be the j-th feature in the normalized time series. (j) The j-th feature in the time series before normalization Let be the mean of the j-th feature in the training set. Let be the standard deviation of the j-th feature in the training set.
[0042] In this way, features of different dimensions can be unified to a similar scale (mean of 0, standard deviation of 1), which is beneficial to the stable training and convergence of deep learning models (spatiotemporal dual-characteristic models).
[0043] Step 103: Input the time series into the set spatiotemporal dual-characteristic model to construct the spatiotemporal dual characteristics and obtain the feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-characteristic model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network.
[0044] Specifically, the spatiotemporal dual-characteristic model adopts a hybrid architecture of cascading temporal convolutional networks and convolutional long short-term memory networks (TCN-ConvLSTM).
[0045] In practical applications, to address the temporal dependence and spatial correlation of network security situation, a hybrid architecture of TCN-ConvLSTM cascade is adopted. The temporal convolutional network captures local abrupt changes in situation through multi-scale dilated convolution (such as a sudden rise / fall in situation caused by an attack). The convolutional long short-term memory network models long temporal dependence features and multi-feature spatial correlation features simultaneously through convolutional gating mechanism, that is, it integrates the feature matrix of temporal dependence and spatial correlation (such as the correlation between TCP ratio and attack traffic ratio). In this way, the deficiency of general models that can only model in a single dimension can be solved.
[0046] Step 104: Perform feature weighted fusion and regression mapping on the feature matrix to obtain the security status value corresponding to the target network.
[0047] In practical applications, the spatiotemporal features of the T time steps in the feature matrix output by the spatiotemporal dual-feature model can be subjected to feature weighting fusion and regression mapping to obtain the security status value corresponding to the target network.
[0048] The network security situation prediction method provided by this invention determines multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network. These multi-dimensional features include network traffic features, detection-derived features, and historical situation features. Detection-derived features are used to quantify the intensity and credibility of network attack behavior, overcoming the limitations of a single situation value input. By using "detection-derived features" to quantify the intensity and credibility of attack behavior, the core driving factor of situation change is introduced into a spatiotemporal dual-characteristic model, establishing an intrinsic correlation between attack features and situation changes, and providing sufficient information support for high-precision prediction. Based on multi-dimensional features at different times and a sliding time window of a set length, a time series is constructed, effectively alleviating the difficulty in accuracy during long-term prediction. The problem of degree decay is addressed, maintaining high accuracy and stability in predictions at each time step. The time series is input into a predefined spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics, resulting in a feature matrix that integrates temporal dependencies and spatial correlations. A hybrid architecture combining cascaded temporal convolutional networks and convolutional long short-term memory networks is employed. The temporal convolutional network captures local abrupt changes in the situation, while the convolutional long short-term memory network simultaneously models long-term temporal dependencies and multi-feature spatial correlation features, overcoming the limitation of general models that can only model in a single dimension. Furthermore, the feature matrix undergoes feature weighted fusion and regression mapping to obtain the security situation value corresponding to the target network, improving the accuracy and reliability of the security situation value, thereby achieving high-precision forward-looking prediction of network security situation.
[0049] In some embodiments, the determination of multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network includes: The intrusion detection data is statistically and aggregated to obtain the detection-derived features, which include the proportion of attack traffic, the average confidence level, and the proportion of target attacks, wherein the confidence level of the target attacks is higher than the confidence level threshold. Feature extraction is performed on the situation assessment data to obtain the historical situation features; The network traffic data is statistically analyzed to obtain the network traffic characteristics, which include average packet length, peak flow rate, average connection duration, TCP percentage, and UDP percentage.
[0050] Specifically, the proportion of targeted attacks is also the proportion of high-confidence attacks.
[0051] In practical applications, intrusion detection data contains multi-dimensional data, such as attack categories and confidence levels. Therefore, by statistically analyzing and aggregating intrusion detection data, three-dimensional detection-derived features can be obtained, namely, the proportion of attack traffic, the mean confidence level, and the proportion of target attacks.
[0052] The situation assessment data is a one-dimensional historical situation value, which can be combined with attack scores, frequency, and the proportion of normal traffic to obtain historical situation characteristics.
[0053] It is possible to directly perform data statistics on the network traffic data of the target network to obtain five-dimensional basic statistical characteristics, namely network traffic characteristics.
[0054] Furthermore, based on three-dimensional detection-derived features, one-dimensional historical situation features, and five-dimensional network traffic features, a three-category, nine-dimensional multi-dimensional feature set is constructed. .in, The network traffic characteristics are five-dimensional, including average packet length, peak flow rate, average connection duration, TCP share, and User Datagram Protocol (UDP) share, reflecting the basic operating status of network traffic. These are three-dimensional detection-derived features, calculated from intrusion detection results, including attack traffic percentage, average confidence level, percentage of high-confidence attacks, and connection between attack behavior and situational changes. The historical situation features are one-dimensional and output by the forward situation assessment framework, serving as a monitoring signal benchmark for the prediction task.
[0055] In this embodiment of the invention, the limitations of a single situation value input are overcome. The network traffic characteristics (average packet length, peak flow rate, average connection duration, TCP percentage, UDP percentage) and detection-derived characteristics (attack traffic percentage, average confidence level, high-confidence attack percentage) of the pre-intrusion detection stage are systematically reused. A 9-dimensional feature sequence is constructed by combining historical situation values. The intensity and credibility of attack behavior are quantified by the detection-derived characteristics. The core driving factor of situation change, "attack behavior", is introduced into the spatiotemporal dual-characteristic model to establish the intrinsic relationship between attack characteristics and situation changes, providing sufficient information support for high-precision prediction.
[0056] In some embodiments, the step of inputting the time series into a predefined spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics and obtain a feature matrix that integrates temporal dependence and spatial correlation includes: The time series sequence is input into the time series convolutional network to extract local abrupt change features of the situation, thereby obtaining a feature sequence containing local abrupt change features of the situation. The feature sequence is input into the convolutional long short-term memory network to perform spatiotemporal dual-feature joint modeling, thereby obtaining the feature matrix that integrates temporal dependence and spatial correlation.
[0057] In practical applications, temporal convolutional networks serve as front-end feature extractors for spatiotemporal dual-feature models. They capture local abrupt changes in the situation in temporal sequences (such as sudden rises / falls in situation caused by sudden attacks) through multi-scale dilated convolutions, resulting in feature sequences containing local abrupt changes in situation.
[0058] As the core computational unit of the spatiotemporal dual-feature model, the convolutional long short-term memory network, through the convolutional gating mechanism, models long temporal dependency features and multi-feature spatial correlation features based on feature sequences containing local abrupt changes in the situation, that is, a feature matrix that integrates temporal dependency and spatial correlation (such as the correlation between TCP proportion and attack traffic proportion).
[0059] In this embodiment of the invention, by using temporal convolutional networks and convolutional long short-term memory networks, local abrupt changes, long temporal dependencies, and spatial correlations of the situation are captured simultaneously. There is no significant lag in the sudden rise / fall of the situation caused by sudden attacks, and the fitting effect is more accurate.
[0060] In some embodiments, the temporal convolutional network includes residual connection layers and at least two cascaded dilated convolutional layers, each with a different dilation rate; The step of inputting the temporal sequence into the temporal convolutional network to extract local abrupt change features of the situation, thereby obtaining a feature sequence containing local abrupt change features, includes: Multi-scale situational change features are extracted from the time series by using at least two cascaded dilated convolutional layers. The time series sequence is residually mapped through the residual connection layer to obtain the mapping result, and the mapping result is fused with the multi-scale situational change features to obtain the feature sequence containing the situational local change features.
[0061] Specifically, temporal convolutional networks employ a multi-layered one-dimensional dilated convolutional architecture, meaning that a temporal convolutional network stacks multiple one-dimensional dilated convolutional layers. Each dilated convolutional layer may contain multiple one-dimensional convolutional kernels (channels), and the layers are connected through residual connections. A one-dimensional convolutional kernel refers to a kernel that slides only in the temporal dimension, not in the feature dimension. The core of temporal convolutional networks is causal dilated convolution combined with residual connections, specifically designed to capture the local abrupt changes in situational characteristics caused by sudden attacks.
[0062] In practical applications, temporal convolutional networks use N one-dimensional dilated convolutional layers with different dilation rates to extract multi-scale abrupt change features from temporal sequences, thus obtaining multi-scale abrupt change features. And through residual connection layers, time series sequences Perform residual mapping to obtain the mapping result. .
[0063] Then, through a residual connection layer, the multi-scale situational abrupt change features and mapping results are fused to obtain a feature sequence containing local situational abrupt change features. : ; Where Res is the residual mapping, which is adjusted by 1×1 convolution when the dimensions are mismatched; the feature sequence of local abrupt change features. ,and They are consistent, both being 9-dimensional.
[0064] In this embodiment of the invention, N one-dimensional dilated convolutional layers with different dilation rates can be used to extract features of sudden changes in the situation at different scales, thereby improving the accuracy of multi-scale features of sudden changes in the situation. Through residual connection layers, the problem of gradient vanishing in deep networks can be solved, and multi-scale feature fusion can be achieved, thereby improving the accuracy of feature sequences containing features of local sudden changes in the situation.
[0065] In some embodiments, the extraction of multi-scale abrupt change features from the time-series sequence through at least two cascaded dilated convolutional layers to obtain multi-scale abrupt change features includes: For the current dilated convolutional layer in the at least two cascaded dilated convolutional layers, the input and bias term of the current dilated convolutional layer are weighted based on the kernel weights of the current dilated convolutional layer to obtain a weighted sum; The weighted sum is processed using the first activation function to obtain the output of the current dilated convolutional layer; Wherein, if the current dilated convolutional layer is the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the temporal sequence; if the current dilated convolutional layer is not the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the output of the previous dilated convolutional layer; if the current dilated convolutional layer is the last dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the output of the current dilated convolutional layer is the multi-scale situational change feature.
[0066] In practical applications, the data processing procedure for each of the N dilated convolutional layers can be represented by the following formula: ; Where l is a positive integer less than or equal to N, i.e., the index of the current dilated convolutional layer (the l-th dilated convolutional layer); X is the input of the current dilated convolutional layer; dl is the dilation rate of the current dilated convolutional layer; *dl is the convolution operation of the dilation rate dl; These are the kernel weights (learnable parameters) of the current dilated convolutional layer. This is the bias term (learnable parameter) for the current dilated convolutional layer. This is the output of the current dilated convolutional layer; ReLU is the rectified linear unit, i.e., the first activation function.
[0067] For example, at least two dilated convolutional layers are converted into three dilated convolutional layers, and the dilation rates of the three dilated convolutional layers are set to d1=1, d2=2, and d3=4, respectively, to achieve multi-scale mutation feature capture.
[0068] It should be noted that the input to the first dilated convolutional layer is a temporal sequence, the input to the r-th dilated convolutional layer is the output of the (r-1)-th dilated convolutional layer, where r is a positive integer greater than 1 and less than or equal to N. The output of the Nth dilated convolutional layer is a multi-scale situational abrupt change feature.
[0069] In this embodiment of the invention, by using causal dilation convolution, it can be ensured that the output depends only on the current and historical inputs, adapting to the characteristics of time-series data, thereby improving the reliability of multi-scale situational change features.
[0070] In some embodiments, the convolutional long short-term memory network includes at least two cascaded convolutional long short-term memory layers; The step of inputting the feature sequence into the convolutional long short-term memory network for joint spatiotemporal dual-feature modeling to obtain the feature matrix that integrates temporal dependence and spatial correlation includes: For each of the convolutional long short-term memory layers, a first gate vector is obtained by extracting a gate vector based on the input data of the convolutional long short-term memory layer through the input gate of the convolutional long short-term memory layer. By using the forget gate of the convolutional long short-term memory layer, the gating vector is extracted based on the input data of the convolutional long short-term memory layer to obtain the second gating vector; The memory state at the current moment is obtained by updating the state through the memory unit of the convolutional long short-term memory layer based on the first gate vector, the second gate vector and the input data of the convolutional long short-term memory layer. The third gating vector is obtained by extracting the gating vector based on the input data of the convolutional long short-term memory layer through the output gate of the convolutional long short-term memory layer. The hidden state of the output of the convolutional long short-term memory layer is determined through the hidden layer of the convolutional long short-term memory layer, based on the third gating vector and the memory state at the current time. Wherein, the input data of the first convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature sequence, the input data of the other convolutional long short-term memory layers in the at least two convolutional long short-term memory layers is the hidden state output by the previous convolutional long short-term memory layer, the hidden state output by the last convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature matrix, the dimension of the hidden layer of the first convolutional long short-term memory layer is the first dimension, the dimension of the hidden layer of the last convolutional long short-term memory layer is the second dimension, and the first dimension is greater than the second dimension.
[0071] Specifically, the convolutional long short-term memory network consists of M cascaded convolutional long short-term memory layers, where M is a positive integer greater than or equal to 2.
[0072] For example, the Convolutional Long Short-Term Memory (CLSMemory) network employs a two-layer cascaded structure, replacing the fully connected layers in the gates of the CLSMemory layers with convolutional operations. This allows for the modeling of long-term temporal dependencies while simultaneously mining multi-feature spatial associations. The hidden layer dimensions of the two CLSMemory layers are 128 (coarse-grained global modeling) and 64 (fine-grained core feature refinement), respectively, with convolutional kernel sizes of (3,1) for both. The output of the first CLSMemory layer serves as the input to the second CLSMemory layer. The input to the first CLSMemory layer is the feature sequence, while the hidden state output by the second CLSMemory layer is a feature matrix that integrates temporal dependencies and spatial associations.
[0073] Taking the first convolutional long short-term memory layer as an example, the core gating update formula for the convolutional long short-term memory layer is: Input Gate: ; Forgotten Gate: ; Memory unit: ; Output gate: ; Hidden state: ; Where t is the current time step, ranging from 1 to T; i t Let σ be the first gating vector; σ is the Sigmoid activation function. The feature sequence at time step t; For input gate The convolution kernel weights, The hidden state H in the input gate at the previous time step t-1 The convolution kernel weights; * represents the convolution operation; b i For the bias term of the input gate; f t W is the second gating vector; xf Forgotten Gate The convolution kernel weights, W hf The hidden state H in the previous moment within the forget gate t-1 convolution kernel weights; b f c is the bias term for the forget gate; t The current memory state; ⊙ represents the Hadamard product; c t-1 The previous memory state; tanh is the hyperbolic tangent activation function; W xc For memory units The convolution kernel weights, W hc The hidden state H in the memory unit at the previous time step t-1 convolution kernel weights; b c For the bias term of the memory unit; o t W is the third gating vector; xo For the output gate The convolution kernel weights, W ho The hidden state H in the output gate at the previous time step t-1 convolution kernel weights; b o For the bias term of the output gate; H t This represents the current hidden state.
[0074] It should be noted that the forget gate is used to control the forgetting of information, that is, to determine c. t-1 How much information needs to be retained (discarding historical information that is no longer important); input gate control information is written, which determines the current input. How much new information needs to be added to c? t The output gate controls the output information, which determines c. t How much information needs to be output as a hidden state H? t .
[0075] Furthermore, the convolution kernel and hidden layer dimensions directly participate in the computation in the core gating: all gating uses convolution operations, and the number of channels in the convolution kernel is determined by the input dimension and the hidden layer dimension.
[0076] In this embodiment of the invention, through a gating mechanism, the convolutional long short-term memory network can remember the long-term situational evolution pattern (such as attack periodicity) and forget irrelevant instantaneous noise; at the same time, it can capture the joint pattern between different features within the same time step (such as a high attack ratio accompanied by a high TCP ratio), thus achieving true spatiotemporal dual-feature modeling.
[0077] It should be noted that constructing a temporal feature sequence using a sliding time window of length T, and determining the optimal parameter combination (such as the convolution kernel [1,2,4] of the temporal convolutional network, two stacked convolutional long short-term memory layers in the convolutional long short-term memory network, 4 attention heads, and a learning rate of 0.001) by combining the hyperparameter sensitivity analysis of the spatiotemporal dual-characteristic model, can effectively alleviate the accuracy decay problem in long-term prediction and maintain high accuracy and stability in 12 / 24 / 48-step prediction.
[0078] In some embodiments, the step of performing feature weighted fusion and regression mapping on the feature matrix to obtain the security posture value corresponding to the target network includes: Based on the attention mechanism, the feature matrix is subjected to feature weight fusion to obtain a fused feature matrix; The security posture value corresponding to the target network is obtained by performing regression mapping on the fused feature matrix through a fully connected layer.
[0079] Specifically, the attention mechanism can be a hierarchical attention mechanism or a time-step attention mechanism.
[0080] In practical applications, when the attention mechanism is a hierarchical attention mechanism, feature weights for the network traffic dimension, detection-derived dimension, and historical situation dimension in the feature matrix can be dynamically allocated based on the hierarchical attention mechanism to strengthen key features and suppress redundant features. Furthermore, based on each feature weight, the features in the network traffic dimension, detection-derived dimension, and historical situation dimension of the feature matrix are weighted and fused to obtain a fused feature matrix.
[0081] When the attention mechanism is a time-step attention mechanism, the feature weights of each time step in the feature matrix can be dynamically allocated based on the time-step attention mechanism to strengthen key features and suppress redundant features. Then, based on the feature weights of each time step, the features of each time step in the feature matrix are weighted and fused to obtain a fused feature matrix.
[0082] Furthermore, the fused feature matrix is regressed and mapped through a fully connected layer (a regression layer specifically designed for outputting multi-step predictions) to obtain the security posture value corresponding to the target network.
[0083] In this embodiment of the invention, by introducing an attention mechanism, the weight of each feature in the dynamically allocated feature matrix is determined, that is, the contribution difference of each feature is distinguished, the attack-derived features that are highly related to the situation change are automatically strengthened, the interference of redundant features is weakened, and the feature utilization efficiency and model generalization ability are improved.
[0084] In some embodiments, the feature matrix includes T spatiotemporal feature vectors at time steps, where T represents the set length, and the attention mechanism is a time step attention mechanism. The attention-based mechanism is used to perform feature weighting and fusion on the feature matrix to obtain a fused feature matrix, including: Based on the time-step attention mechanism, the weight of each spatiotemporal feature vector is determined; Based on the weight of each spatiotemporal feature vector, each spatiotemporal feature vector is weighted and fused to obtain the fused feature matrix.
[0085] In practical applications, a time-step-based adaptive attention mechanism, namely the time-step attention mechanism, can be designed to automatically learn weight coefficients for the spatiotemporal features of T time steps in the feature matrix. This can focus on key periods that have a significant impact on situational changes (such as the moment when the situation suddenly rises or falls due to an attack outbreak), suppress the interference of redundant historical information, and improve the efficiency of feature utilization and the generalization ability of the model.
[0086] The attention mechanism learns a weight for each time step. The calculation formula is as follows: ; Among them, H t This represents the hidden state at time step t in the feature matrix (e.g., 64-dimensional), which is the spatiotemporal feature vector at time step t. Indicates transpose; v, W a and b a All of these are learnable attention parameters.
[0087] The formula for calculating the weighted fused feature vector, i.e., the fused feature matrix Z, is as follows: ; in, The weights of the spatiotemporal feature vector at time step t are calculated from the learnable parameters. The fused feature matrix Z aggregates the contribution information from different time periods within the entire time window, providing a more discriminative feature representation for subsequent regression prediction.
[0088] In this embodiment of the invention, by introducing a time-step attention mechanism after the convolutional long short-term memory network, the spatiotemporal feature vectors of all time steps output by the convolutional long short-term memory network are adaptively weighted. This not only improves the efficiency of feature utilization, but also automatically focuses on key time periods that have a significant impact on situational changes (such as time steps where the situation suddenly escalates due to an attack outbreak), suppresses redundant information and noise interference, and further enhances the stability and generalization ability of the model.
[0089] In some embodiments, the step of performing regression mapping on the fused feature matrix through a fully connected layer to obtain the security posture value corresponding to the target network includes: The fused feature matrix is nonlinearly mapped through the fully connected layer to obtain the mapped value; Based on the second activation function, the mapping value is activated and output to obtain the security posture value corresponding to the target network.
[0090] Specifically, the second activation function can be the Sigmoid activation function.
[0091] In practical applications, the feature matrix obtained after hierarchical attention fusion, i.e., the fused feature matrix Z, can be flattened into a one-dimensional vector, and regression mapping can be completed through a fully connected layer to output the future multi-step network security posture value (security posture value) S. Specifically, the processing is as follows: Nonlinear mapping in fully connected layers: ; The Sigmoid activation function is used to activate the output: ; Where F is the mapping value; ReLU is the activation function; W1 is the weight matrix of the nonlinear mapping; Flatten represents the flattening operation; b1 is the bias vector of the nonlinear mapping; the Sigmoid activation function constrains the output to the [0,1] interval, consistent with the situation quantization standard, and can achieve situation value prediction of different step lengths such as 12 steps, 24 steps, and 48 steps; W2 is the weight matrix of the activation output; b2 is the bias vector of the activation output.
[0092] In this embodiment of the invention, the output security posture value can be made more accurate through nonlinear mapping of the fully connected layer and Sigmoid activation.
[0093] The network security situation prediction method provided by this invention achieves sufficient prediction information through multi-dimensional feature enhancement, realizes accurate modeling of spatiotemporal dual characteristics through TCN-ConvLSTM cascade architecture, and realizes efficient utilization of features through hierarchical attention mechanism. The three work together to enable the model to mine the evolution law from the whole link of "attack behavior-traffic characteristics-situation change", thereby improving the prediction accuracy and realizing high-precision forward prediction of network security situation.
[0094] Compared with existing network security situation prediction technologies, the network security situation prediction method provided by this invention achieves a comprehensive improvement in prediction accuracy, generalization ability, and long-term stability. The technical effects are demonstrated through quantitative experimental data and qualitative characteristics, as follows: 1. Quantitative Results (Based on the CICIDS2017 dataset, 24-step core prediction task): Prediction accuracy is significantly improved: the normalized mean absolute error (MAE) is as low as 0.0368, the mean squared error (MSE) is controlled within 0.0028, and the coefficient of determination (R²) is as high as 0.9469. Compared with the traditional LSTM model (MAE=0.0634, MSE=0.0069, R²=0.8421), MAE is reduced by 42%, MSE is reduced by 59%, and R² is improved by 12.4%. Excellent stability in multi-step prediction: MAE=0.0312 and R²=0.9637 for 12-step short-term prediction, and MAE=0.0445 and R²=0.9127 for 48-step prediction. As the prediction step length increases, the accuracy decay is much lower than that of existing models, which solves the problem of a significant decrease in long-term prediction accuracy. Compared with mainstream models, it has obvious advantages: under the same experimental conditions, its performance is significantly better than existing models such as LSTM, GRU, single TCN, and single ConvLSTM. The MAE and MSE are the lowest and the R² is the highest for each prediction step size.
[0095] 2. Qualitative effect: Full utilization of features: It realizes the linkage of technical links between intrusion detection and situation prediction, reuses multi-dimensional features to establish the driving correlation of "attack behavior-situation change", and the prediction results are more in line with the actual evolution of network security situation; Spatiotemporal dual-feature adaptation: The TCN-ConvLSTM cascaded architecture simultaneously captures local abrupt changes, long-term temporal dependencies, and spatial correlations of the situation, with no significant lag in the sudden rise / fall of the situation caused by sudden attacks, resulting in more accurate fitting. Strong generalization ability: The hierarchical attention mechanism dynamically adjusts feature weights, weakens the interference of redundant features, and strengthens key attack-derived features. It can maintain high accuracy in multiple scenarios such as smart home, smart city, and smart agriculture, and has excellent scenario adaptability. High engineering practicality: The model parameters are optimized through hyperparameter sensitivity analysis, taking into account both prediction accuracy and computational efficiency. The input features are general network traffic and intrusion detection indicators, which are easy to interface with existing network security situation awareness systems and facilitate engineering deployment.
[0096] It should be noted that the steps shown in the above process or in the flowchart of the accompanying figures can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0097] This invention also provides a network security situation prediction device, which is used to implement the above embodiments and preferred embodiments, and will not be repeated for details already described. The terms "module," "unit," "subunit," etc., used below can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0098] The network security situation prediction device provided by the present invention is described below. The network security situation prediction device described below and the network security situation prediction method described above can be referred to in correspondence.
[0099] Figure 2 This is a schematic diagram of the network security situation prediction device provided by the present invention, as shown below. Figure 2 As shown, the network security situation prediction device includes: The determination module 201 is configured to determine multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network. The multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior. The first construction module 202 is configured to construct a time series based on the multi-dimensional features at different times and a sliding time window of a set length; The second construction module 203 is configured to input the time series into a set spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics and obtain a feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-characteristic model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network. The mapping module 204 is configured to perform feature weighted fusion and regression mapping on the feature matrix to obtain the security status value corresponding to the target network.
[0100] The network security situation prediction device provided by this invention determines multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network. These multi-dimensional features include network traffic features, detection-derived features, and historical situation features. Detection-derived features are used to quantify the intensity and credibility of network attack behavior, overcoming the limitations of a single situation value input. By quantifying the intensity and credibility of attack behavior through "detection-derived features," the core driving factor of situation change—attack behavior—is introduced into a spatiotemporal dual-characteristic model, establishing an intrinsic correlation between attack features and situation changes, providing sufficient information support for high-precision prediction. Based on multi-dimensional features at different times and a sliding time window of a set length, a time series is constructed, effectively alleviating the difficulty in precision prediction over long periods. The problem of degree decay is addressed, maintaining high accuracy and stability in predictions at each time step. The time series is input into a predefined spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics, resulting in a feature matrix that integrates temporal dependencies and spatial correlations. A hybrid architecture combining a cascaded temporal convolutional network and a convolutional long short-term memory network is employed. The temporal convolutional network captures local abrupt changes in the situation, while the convolutional long short-term memory network simultaneously models long-term temporal dependencies and multi-feature spatial correlation features, overcoming the limitation of general models that can only model in a single dimension. Furthermore, the feature matrix undergoes feature weighted fusion and regression mapping to obtain the security situation value corresponding to the target network, improving the accuracy and reliability of the security situation value, thereby achieving high-precision forward-looking prediction of network security situation. In some embodiments, the determining module 201 is specifically configured as follows: The intrusion detection data is statistically and aggregated to obtain the detection-derived features, which include the proportion of attack traffic, the average confidence level, and the proportion of target attacks, wherein the confidence level of the target attacks is higher than the confidence level threshold. Feature extraction is performed on the situation assessment data to obtain the historical situation features; The network traffic data is statistically analyzed to obtain the network traffic characteristics, which include average packet length, peak flow rate, average connection duration, TCP percentage, and UDP percentage.
[0101] In some embodiments, the second building module 203 is specifically configured as follows: The time series sequence is input into the time series convolutional network to extract local abrupt change features of the situation, thereby obtaining a feature sequence containing local abrupt change features of the situation. The feature sequence is input into the convolutional long short-term memory network to perform spatiotemporal dual-feature joint modeling, thereby obtaining the feature matrix that integrates temporal dependence and spatial correlation.
[0102] In some embodiments, the temporal convolutional network includes residual connection layers and at least two cascaded dilated convolutional layers, each with a different dilation rate; The second building module 203 is specifically configured as follows: Multi-scale situational change features are extracted from the time series by using at least two cascaded dilated convolutional layers. The time series sequence is residually mapped through the residual connection layer to obtain the mapping result, and the mapping result is fused with the multi-scale situational change features to obtain the feature sequence containing the situational local change features.
[0103] In some embodiments, the second building module 203 is specifically configured as follows: For the current dilated convolutional layer in the at least two cascaded dilated convolutional layers, the input and bias term of the current dilated convolutional layer are weighted based on the kernel weights of the current dilated convolutional layer to obtain a weighted sum; The weighted sum is processed using the first activation function to obtain the output of the current dilated convolutional layer; Wherein, if the current dilated convolutional layer is the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the temporal sequence; if the current dilated convolutional layer is not the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the output of the previous dilated convolutional layer; if the current dilated convolutional layer is the last dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the output of the current dilated convolutional layer is the multi-scale situational change feature.
[0104] In some embodiments, the convolutional long short-term memory network includes at least two cascaded convolutional long short-term memory layers; The second building module 203 is specifically configured as follows: For each of the convolutional long short-term memory layers, a first gate vector is obtained by extracting a gate vector based on the input data of the convolutional long short-term memory layer through the input gate of the convolutional long short-term memory layer. By using the forget gate of the convolutional long short-term memory layer, the gating vector is extracted based on the input data of the convolutional long short-term memory layer to obtain the second gating vector; The memory state at the current moment is obtained by updating the state through the memory unit of the convolutional long short-term memory layer based on the first gate vector, the second gate vector and the input data of the convolutional long short-term memory layer. The third gating vector is obtained by extracting the gating vector based on the input data of the convolutional long short-term memory layer through the output gate of the convolutional long short-term memory layer. The hidden state of the output of the convolutional long short-term memory layer is determined through the hidden layer of the convolutional long short-term memory layer, based on the third gating vector and the memory state at the current time. Wherein, the input data of the first convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature sequence, the input data of the other convolutional long short-term memory layers in the at least two convolutional long short-term memory layers is the hidden state output by the previous convolutional long short-term memory layer, the hidden state output by the last convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature matrix, the dimension of the hidden layer of the first convolutional long short-term memory layer is the first dimension, the dimension of the hidden layer of the last convolutional long short-term memory layer is the second dimension, and the first dimension is greater than the second dimension.
[0105] In some embodiments, the mapping module 204 is specifically configured as follows: Based on the attention mechanism, the feature matrix is subjected to feature weight fusion to obtain a fused feature matrix; The security posture value corresponding to the target network is obtained by performing regression mapping on the fused feature matrix through a fully connected layer.
[0106] In some embodiments, the feature matrix includes T spatiotemporal feature vectors at time steps, where T represents the set length, and the attention mechanism is a time step attention mechanism. The mapping module 204 is specifically configured as follows: Based on the time-step attention mechanism, the weight of each spatiotemporal feature vector is determined; Based on the weight of each spatiotemporal feature vector, each spatiotemporal feature vector is weighted and fused to obtain the fused feature matrix.
[0107] In some embodiments, the mapping module 204 is specifically configured as follows: The fused feature matrix is nonlinearly mapped through the fully connected layer to obtain the mapped value; Based on the second activation function, the mapping value is activated and output to obtain the security posture value corresponding to the target network.
[0108] It should be noted that the above modules can be functional modules or program modules, and can be implemented through software or hardware. For modules implemented through hardware, the above modules can reside in the same processor; or the above modules can be located in different processors in any combination.
[0109] Figure 3 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 3 As shown, the electronic device may include: a processor 310, a communications interface 320, a memory 330, and a communication bus 340, wherein the processor 310, the communications interface 320, and the memory 330 communicate with each other via the communication bus 340. The processor 310 can call logical instructions in the memory 330 to execute a network security situation prediction method, which includes: Based on intrusion detection data, situation assessment data, and network traffic data of the target network, multi-dimensional features are determined. These multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior. Based on the multi-dimensional features at different times and a sliding time window of a set length, a time series is constructed; The time series is input into a set spatiotemporal dual-feature model to construct spatiotemporal dual features, thereby obtaining a feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-feature model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network. The feature matrix is subjected to feature weighted fusion and regression mapping to obtain the security status value corresponding to the target network.
[0110] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0111] The present invention also provides an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.
[0112] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.
[0113] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program: Based on intrusion detection data, situation assessment data, and network traffic data of the target network, multi-dimensional features are determined. These multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior. Based on the multi-dimensional features at different times and a sliding time window of a set length, a time series is constructed; The time series is input into a set spatiotemporal dual-feature model to construct spatiotemporal dual features, thereby obtaining a feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-feature model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network. The feature matrix is subjected to feature weighted fusion and regression mapping to obtain the security status value corresponding to the target network.
[0114] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated in this embodiment.
[0115] On the other hand, in conjunction with the network security situation prediction method provided in the above embodiments, the present invention also provides a non-transitory computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above network security situation prediction method embodiments.
[0116] In another aspect, in conjunction with the network security situation prediction method provided in the above embodiments, the present invention also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.
[0117] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0118] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A cyber-security posture prediction method, characterized by, include: Based on intrusion detection data, situation assessment data, and network traffic data of the target network, multi-dimensional features are determined. These multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior. Based on the multi-dimensional features at different times and a sliding time window of a set length, a time series is constructed; The time series is input into a set spatiotemporal dual-feature model to construct spatiotemporal dual features, thereby obtaining a feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-feature model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network. The feature matrix is subjected to feature weighted fusion and regression mapping to obtain the security status value corresponding to the target network.
2. The cyber security posture prediction method of claim 1, wherein, The intrusion detection data, situation assessment data, and network traffic data based on the target network are used to determine multi-dimensional features, including: The intrusion detection data is statistically and aggregated to obtain the detection-derived features, which include the proportion of attack traffic, the average confidence level, and the proportion of target attacks, wherein the confidence level of the target attacks is higher than the confidence level threshold. Feature extraction is performed on the situation assessment data to obtain the historical situation features; The network traffic data is statistically analyzed to obtain the network traffic characteristics, which include average packet length, peak flow rate, average connection duration, TCP percentage, and UDP percentage.
3. The cyber security posture prediction method of claim 1, wherein, The step involves inputting the time series into a predefined spatiotemporal dual-characteristic model to construct the spatiotemporal dual characteristics, resulting in a feature matrix that integrates temporal dependence and spatial correlation, including: The time series sequence is input into the time series convolutional network to extract local abrupt change features of the situation, thereby obtaining a feature sequence containing local abrupt change features of the situation. The feature sequence is input into the convolutional long short-term memory network to perform spatiotemporal dual-feature joint modeling, thereby obtaining the feature matrix that integrates temporal dependence and spatial correlation.
4. The network security situation prediction method according to claim 3, characterized in that, The temporal convolutional network comprises a residual connection layer and at least two cascaded dilated convolutional layers, each of which has a different dilation rate. The step of inputting the temporal sequence into the temporal convolutional network to extract local abrupt change features of the situation, thereby obtaining a feature sequence containing local abrupt change features, includes: Multi-scale situational change features are extracted from the time series by using at least two cascaded dilated convolutional layers. The time series sequence is residually mapped through the residual connection layer to obtain the mapping result, and the mapping result is fused with the multi-scale situational change features to obtain the feature sequence containing the situational local change features.
5. The network security situation prediction method according to claim 4, characterized in that, The process involves extracting multi-scale abrupt change features from the time-series sequence through at least two cascaded dilated convolutional layers, resulting in multi-scale abrupt change features, including: For the current dilated convolutional layer in the at least two cascaded dilated convolutional layers, the input and bias term of the current dilated convolutional layer are weighted based on the kernel weights of the current dilated convolutional layer to obtain a weighted sum; The weighted sum is processed using the first activation function to obtain the output of the current dilated convolutional layer; Wherein, if the current dilated convolutional layer is the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the temporal sequence; if the current dilated convolutional layer is not the first dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the input of the current dilated convolutional layer is the output of the previous dilated convolutional layer; if the current dilated convolutional layer is the last dilated convolutional layer in the cascaded at least two dilated convolutional layers, then the output of the current dilated convolutional layer is the multi-scale situational change feature.
6. The network security situation prediction method according to claim 3, characterized in that, The convolutional long short-term memory network includes at least two cascaded convolutional long short-term memory layers; The step of inputting the feature sequence into the convolutional long short-term memory network for joint spatiotemporal dual-feature modeling to obtain the feature matrix that integrates temporal dependence and spatial correlation includes: For each of the convolutional long short-term memory layers, a first gate vector is obtained by extracting a gate vector based on the input data of the convolutional long short-term memory layer through the input gate of the convolutional long short-term memory layer. By using the forget gate of the convolutional long short-term memory layer, the gating vector is extracted based on the input data of the convolutional long short-term memory layer to obtain the second gating vector; The memory state at the current moment is obtained by updating the state through the memory unit of the convolutional long short-term memory layer based on the first gate vector, the second gate vector and the input data of the convolutional long short-term memory layer. The third gating vector is obtained by extracting the gating vector based on the input data of the convolutional long short-term memory layer through the output gate of the convolutional long short-term memory layer. The hidden state of the output of the convolutional long short-term memory layer is determined through the hidden layer of the convolutional long short-term memory layer, based on the third gating vector and the memory state at the current time. Wherein, the input data of the first convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature sequence, the input data of the other convolutional long short-term memory layers in the at least two convolutional long short-term memory layers is the hidden state output by the previous convolutional long short-term memory layer, the hidden state output by the last convolutional long short-term memory layer in the at least two convolutional long short-term memory layers is the feature matrix, the dimension of the hidden layer of the first convolutional long short-term memory layer is the first dimension, the dimension of the hidden layer of the last convolutional long short-term memory layer is the second dimension, and the first dimension is greater than the second dimension.
7. The network security situation prediction method according to claim 1, characterized in that, The step of performing feature weighting fusion and regression mapping on the feature matrix to obtain the security posture value corresponding to the target network includes: Based on the attention mechanism, the feature matrix is subjected to feature weight fusion to obtain a fused feature matrix; The security posture value corresponding to the target network is obtained by performing regression mapping on the fused feature matrix through a fully connected layer.
8. The network security situation prediction method according to claim 7, characterized in that, The feature matrix includes T spatiotemporal feature vectors at time steps, where T represents the set length, and the attention mechanism is a time step attention mechanism. The attention-based mechanism is used to perform feature weighting and fusion on the feature matrix to obtain a fused feature matrix, including: Based on the time-step attention mechanism, the weight of each spatiotemporal feature vector is determined; Based on the weight of each spatiotemporal feature vector, each spatiotemporal feature vector is weighted and fused to obtain the fused feature matrix.
9. The network security situation prediction method according to claim 7, characterized in that, The step of performing regression mapping on the fused feature matrix through a fully connected layer to obtain the security posture value corresponding to the target network includes: The fused feature matrix is nonlinearly mapped through the fully connected layer to obtain the mapped value; Based on the second activation function, the mapping value is activated and output to obtain the security posture value corresponding to the target network.
10. A network security situation prediction device, characterized in that, include: The determination module is configured to determine multi-dimensional features based on intrusion detection data, situation assessment data, and network traffic data of the target network. The multi-dimensional features include network traffic features, detection-derived features, and historical situation features. The detection-derived features are used to quantify the intensity and credibility of network attack behavior. The first construction module is configured to construct a time series based on the multi-dimensional features at different times and a sliding time window of a set length; The second construction module is configured to input the time series into a set spatiotemporal dual-characteristic model to construct spatiotemporal dual characteristics, thereby obtaining a feature matrix that integrates temporal dependence and spatial correlation. The spatiotemporal dual-characteristic model adopts a hybrid architecture of cascaded temporal convolutional network and convolutional long short-term memory network. The mapping module is configured to perform feature weighted fusion and regression mapping on the feature matrix to obtain the security status value corresponding to the target network.