吉林大学学报(信息科学版) ›› 2025, Vol. 43 ›› Issue (1): 143-149.

• • 上一篇    下一篇

基于多源数据挖掘的网络安全态势评估系统

王 峥崔 冉   

  1. 首都医科大学附属北京佑安医院 信息网络管理中心, 北京 100069
  • 收稿日期:2023-05-06 出版日期:2025-02-24 发布日期:2025-02-24
  • 作者简介:王峥(1983— ), 男, 北京人, 首都医科大学附属北京佑安医院工程师, 主要从事信息网络安全研究, ( Tel) 86- 18617559822(E-mail)liu20091285@ 126. com。

Network Security Situation Assessment System Based on Multi Source Data Mining

WANG Zheng, CUI Ran   

  1. Information Network Management Center, Beijing Youan Hospital, Capital Medical University, Beijing 100069, China
  • Received:2023-05-06 Online:2025-02-24 Published:2025-02-24
  • Supported by:

    北京市自然科学基金资助项目(9163025)

摘要: 为维护网络运行安全保证网络信息安全存储提出基于多源数据挖掘的网络安全态势评估系统。 首先建立以应用层、 控制层、 数据转发层为核心的 3 层网络安全态势系统架构, 为保证应用层与网络设备之间信息有效传输, 利用 OSGi ( Open Service Gateway Initiative) 设计模式对控制层的 ONOS ( Open Network Operating System)控制器实施 5 层平行建构, 以保障网络安全态势的决策响应。 利用流量探测模块内多探测器的部署,实现网络多源数据的深度挖掘; 引入 LEACH(Low Energy Adaptive Clustering Hierarchy)算法, 在网络簇首实现多源数据融合。 通过安全态势评估模块对网络入侵因子威胁等级进行分析后, 结合权系数理论对网络态势威胁因子进行威胁度赋值, 并结合网络层次划分法对运行网络服务层、 主机层、 网络层安全态势实施分层评估。 实验表明, 所提方法对网络数据运行状态分析能力较高, 面对多类型网络威胁因子的攻击行为能做到精准识别, 为网络安全运行提供重要保障。

关键词: OSGi 设计模式, ONOS 控制器, LEACH 算法, 权系数理论, 网络层次划分法

Abstract: To maintain the security of network operation and ensure the secure storage of network information, a network security situation assessment system based on multi-source data mining is proposed. This study first establishes a three-layer network security situation system architecture with application layer, control layer, and data forwarding layer as the core. To ensure effective information transmission between the application layer and network devices, the OSGi (Open Service Gateway Initiative) design pattern is used to construct a five layer parallel architecture for the ONOS(Oper Network Operating System) controller of the control layer to ensure the decision-making response of the network security situation. Utilize the deployment of multiple detectors within the traffic detection module to achieve deep mining of network multi-source data; Introduce the LEACH(Low Energy Adaptive Clustering Hierarchy) algorithm to achieve multi-source data fusion at the network cluster head. After analyzing the threat level of network intrusion factors through the security situation assessment module, combined with the weight coefficient theory, the threat level of the network situation threat factors is assigned. Combined with the network hierarchical division method, the security situation of the operational network service layer, host layer, and network layer is evaluated in layers. The experiment shows that the proposed method has a high ability to analyze the operational status of network data, and can accurately identify attacks from multiple types of network threat factors, providing important guarantees for network security operation.

Key words: open service gateway initiative (OSGi) design pattern, open network operating system(ONOS) controller, low energy adaptive clustering hierarchy(LEACH) algorithm, weight coefficient theory, network hierarchical division method

中图分类号: 

  • TP393. 08