Cybersecurity situation assessment based on fuzzy cluster analysis and fuzzy comprehensive judgment decision-making
摘要
To overcome the limitations of current cybersecurity situational awareness indicators—namely, their rigidity, restricted generalization, insufficient correlation analysis, and inability to adapt rapidly to emerging threats—we propose a holistic framework that fuses fuzzy clustering with fuzzy comprehensive evaluation. Feature attributes of diverse network attack types are first standardized via a “shift–range transformation” and a fuzzy similarity matrix is built using the “similarity coefficient dot product” method. This matrix is then converted into a fuzzy equivalence relation through transitive closure, enabling fuzzy clustering of the latent associations among attack features. Thresholds derived from the clustering results and expert knowledge define primary and secondary situational factor sets. A cybersecurity evaluation set is subsequently established to map secondary factors, while Analytic Hierarchy Process determines the weights of both levels. An average weighted operator synthesizes the fuzzy mapping and the weight matrix, accounting for all fuzzy interactions to produce a situational score. Because constructing large-scale fuzzy similarity matrices, iteratively solving transitive closures, and performing dynamic clustering on real-time data streams are inherently compute-intensive tasks whose complexity grows polynomially—or even exponentially—with the number of network nodes and feature dimensions, traditional single-node sequential processing becomes infeasible. To deliver global situational awareness for national network infrastructures or large-scale cloud platforms and to enable rapid responses to sophisticated attacks such as APTs, massive parallel computing resources from supercomputers (HPC) are indispensable. Experimental results demonstrate that the framework attains high accuracy, credibility, real-time performance, and excellent scalability, fulfilling the supercomputing field’s demand for efficient, large-scale, real-time computation. Experimental results show that the proposed method achieves a situational value of 0.4693 on the UNSW-NB15 dataset and effectively reflects the network situation within the risk set defined in this study.