| With the development of network attack technologies,various network devices including servers,hosts,and routers are facing increasingly severe security threats.Traditional network security measures,such as firewalls,anti-virus technology,and vulnerability detection technology,lack effective coordination,and their analysis sources are single.Therefore,it is difficult to timely detect abnormal behavior in the network,resulting in inadequate situation assessment.To address this problem,this study proposed an intelligent analysis framework by combining multi-source situational factor extraction,data fusion,multidimensional and multiscale index evaluation,and device operational factors and artificial intelligence algorithms.The main contents are as follows:(1)A "hierarchical + modular" operational situational intelligence analysis framework was proposed.By combining the common situation awareness model,the intelligent analysis framework of the devices’ operation situation was designed as a "hierarchical" structure,which consisted of "functional" modules within the layer to realize the extraction and integration of multi-source situation elements and situation analysis.(2)A network flow anomaly detection model based on multi-teacher knowledge distillation was proposed.By mining and integrating the implied 1D sequence knowledge and 2D image knowledge in the network flow,and using distillation to impart the model to students,the compression of the model was achieved without degrading the performance.Experiments showed that the method can effectively improve the anomaly detection performance and the detection accuracy of less sample classes in unbalanced datasets,meanwhile reduce the resource consumption during model inference deployment.(3)A clustering-based anomaly detection model for log data was proposed.By using structured log sequence sliding windows,and drawing on the word and sentence representation in natural language processing,a vectorized representation of log windows(log sentences)was completed.Then by combining with data dimensionality reduction,the anomalous information hidden in the high-dimensional vectorized log sequence data was exposed,and the anomaly handling of log data was realized by outlier detection.Experiments showed that the proposed method can effectively detect anomalies in log data and was sensitive to unknown anomalies.(4)A network devices operation situation evaluation and prediction model was proposed based on fuzzy hierarchical analysis and GRU-attention.By combining the "hierarchical + modular" situational analysis framework,a fusion scheme of different situational elements and an operation situational index system of network devices were proposed to realize the "all-round" evaluation of network devices operation situational values.Additionally,based on the time series attribute of situational data,GRU-attention neural network was used to predict it and achieve the intelligent analysis of the network devices operating situation. |