Enterprise information security management method and system based on artificial intelligence

Through the enterprise information security management method based on artificial intelligence, the graph learning model is used to perform threat perception and attack path identification, and a protection strategy is generated, which solves the problem of the inability to deal with unknown threats and internal threats in the existing technology, real-time response and effective protection are achieved.

CN120200851AActive Publication Date: 2025-06-24SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD

Patent Information

Application Number
CN202510669800.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-06-24
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

The existing technology cannot effectively respond to unknown threats and internal threats, and traditional information security protection systems lack adaptability and real-time response capabilities, and cannot warning and block potential threats before an attack occurs.

Method used

Adopting an enterprise information security management method based on artificial intelligence, by constructing behavioral analysis models and attack simulations, using graph learning models for threat perception and behavioral risk assessment, identifying attack paths, and generating a protection strategy candidate set for each path.

Benefits of technology

Real-time identification and response to unknown threats and internal threats is achieved, system response speed is improved, and enterprise information security protection can be effectively intervened in real time to prevent threats from spreading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200851A_ABST
    Figure CN120200851A_ABST
Patent Text Reader

Abstract

The invention discloses an enterprise information security management method and system based on artificial intelligence, and belongs to the technical field of information management, and the method comprises the steps: inputting original data, integrating the original data into a first behavior graph structure, and constructing an attribute vector for a user node; threat perception and behavior risk assessment are carried out through a graph learning model, and the threat probability of each edge is output; identifying and quantifying attack paths in the graph, and generating an attack path set and a path risk score set; generating a protection strategy candidate set for each path, performing evaluation to obtain a grading result of the protection strategies, and sorting the protection strategies according to the grading result; and a protection strategy is deployed, the deployment state and protection feedback are monitored, after strategy deployment is completed, the state of a deployment target is recorded, a lightweight monitoring assembly is installed on the deployment target, and deployment feedback information is collected. According to the method, potential security threats are identified in real time in a mode of combining intelligent prediction and simulation, and the security policy is dynamically adjusted according to the change of the threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information management, and particularly relates to an enterprise information security management method and system based on artificial intelligence. Background Art

[0002] With the rapid development of information technology and the advancement of globalization, enterprises are constantly facing various information security challenges in their daily operations. Enterprise information security management not only involves data protection, network security, but also includes complex issues such as preventing data leakage, system intrusion, and malware attacks. In this context, most traditional information security protection systems rely on means such as rule-based firewalls, intrusion detection systems (IDS), access control, and encryption technologies. These traditional technologies detect and prevent attacks by setting rules, pattern recognition, and signature matching. However, with the continuous evolution of network attack technologies, especially the emergence of new attack means such as advanced persistent threats (APT) and zero-day vulnerability attacks, these traditional security protection measures gradually show many limitations.

[0003] First of all, existing firewalls and intrusion detection systems usually rely on static rules and signature matching, which are usually manually configured by security experts and can only deal with known threats. For new attacks that have not been identified, existing systems often cannot detect and respond in a timely manner. Secondly, traditional security protection systems lack adaptability. Once encountering complex or unknown attacks, existing systems often cannot make effective real-time adjustments and protections, resulting in the expansion of attack incidents. More critically, most current enterprise information security protection methods can only deal with external attacks and lack effective prevention and monitoring of internal threats (such as employees abusing permissions and internal data leakage).

[0004] In addition, there is generally a problem of data analysis delay in existing systems. Due to the huge amount of data generated in enterprise networks, traditional data processing methods often have a certain delay in security analysis and cannot achieve real-time threat detection and response. The information systems of modern enterprises need to respond quickly and be able to warn and prevent potential threats before attacks occur. However, traditional rule-based methods show obvious deficiencies in dealing with rapidly changing network environments and attack patterns and cannot provide dynamic protection.

[0005] Therefore, we propose an enterprise information security management method and system based on artificial intelligence to solve the above problems. Summary of the Invention

[0006] The purpose of the present invention is to propose an enterprise information security management method and system based on artificial intelligence to solve the problems in the prior art that unknown threats and internal threats cannot be dealt with.

[0007] To achieve the above object, the present invention adopts the following technical solutions:

[0008] An enterprise information security management method based on artificial intelligence, comprising:

[0009] S1: Input the original data, where the original data includes a user privilege information set, a network connection record set, and a resource access log set;

[0010] Integrate the original data into a first-line graph structure and construct an attribute vector for the user nodes;

[0011] S2: Based on the first-line graph, perform threat perception and behavioral risk assessment through a graph learning model, and output the threat probability of each edge;

[0012] The learning steps of the graph learning model include node embedding generation, edge representation construction, and edge-level risk prediction;

[0013] The node embedding generation performs information aggregation through graph convolution with structural normalization;

[0014] The edge representation construction is completed by concatenating the two-end node embeddings and edge attributes;

[0015] The edge-level risk prediction obtains a risk score by inputting the edge representation vector into a single-layer perceptron;

[0016] Output the edge risk score set and the node embedding set;

[0017] S3: Based on the edge risk score set and the node embedding set, combined with the first-line graph, identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generate an attack path set and a path risk score set; the generation steps are as follows:

[0018] Starting from each non-core node, use breadth-first search with a limited depth to construct a set of potential attack paths on the premise that the edge risk score is higher than the set threshold;

[0019] Design a path scoring function for measuring the feasibility and concealment of the attacker's lateral penetration along the path;

[0020] For each node, retain the top K paths with the highest scores starting from it and reaching the core node set;

[0021] Design a structure perturbation test mechanism to perform path credibility confidence analysis on the high-scoring paths;

[0022] S4: Based on the attack path set and the path risk score, generate a candidate set of protection strategies for each path, evaluate the effect of the protection strategies to obtain the scoring results of the protection strategies, and sort the protection strategies according to the scoring results;

[0023] The generation of the protection strategy generates corresponding protection strategies according to risk scores, path behaviors, and access frequencies according to a preset

[0024] The evaluation is completed by calculating the difference in risk scores of the path before and after applying the corresponding protection strategy;

[0025] The sorting is carried out according to preset rules; the preset rules include maximizing policy effects and balancing costs and benefits;

[0026] S5: Based on the protection strategy candidate set and the scoring results of the corresponding protection strategies, deploy the protection strategies and monitor the deployment status and protection feedback; the deployment includes the following steps:

[0027] Call the policy deployment mapping function to translate the logical policy into system control commands;

[0028] Perform deployment priority sorting on all policies, deploy them in descending order of priority, skip conflicting policies or place them in the manual confirmation queue;

[0029] After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0030] Preferably, the node set of the first row of the graph contains three types of nodes: users, hosts, and resources;

[0031] The edge set of the first row of the graph represents the operation behavior of the user on other nodes;

[0032] The edge attributes of the first row of the graph represent behavior details, and the node attributes of the first row of the graph represent behavior identities and frequencies.

[0033] Preferably, a role difference factor is introduced in the edge representation to measure the cross-level access intensity between the user and the target. The role difference factor takes the L1 norm, representing the absolute value of the role level difference.

[0034] Preferably, the path scoring function is obtained by inputting the edge risk score into a single-layer perceptron, performing a linear transformation, and then compressing the linear transformation result through a Sigmoid function.

[0035] Preferably, a role crossing weight is introduced in the path scoring function, and the role crossing weight is calculated through the role encoding of the nodes at both ends of the edge.

[0036] Preferably, a path structure jump penalty term is introduced in the path scoring function. The path structure jump penalty term represents the mean square change rate of the continuous node embedding vectors in the path, highlighting the hidden coherence of the attack.

[0037] Preferably, the structural perturbation test mechanism randomly removes the edges not on the path in the graph and re-evaluates the change in the path score. If the path score fluctuation is less than the threshold, the path is marked as a structurally stable path.

[0038] Preferably, the generation of the protection strategy includes the following rules:

[0039] Node-level strategy: If the behavioral risk score of a certain node in the path is relatively high, a strategy for this node can be generated, including freezing the account and restricting access rights;

[0040] Edge-level strategy: If a certain edge in the path involves communication with a high-risk protocol or an unconventional port, a strategy for restricting protocol access or blocking the port is generated;

[0041] Path interruption strategy: If the path is composed of multiple nodes through low-risk behaviors combined, and there is a relatively high security risk in the "connection" of the intermediate path, a strategy for disconnecting a certain critical edge or enabling strong authentication is generated.

[0042] An enterprise information security management system based on artificial intelligence includes:

[0043] A data modeling module, which inputs the original data, and the original data includes a user permission information set, a network connection record set, and a resource access log set;

[0044] Integrate the original data into a first-order graph structure and construct an attribute vector for the user nodes;

[0045] A risk assessment module, which based on the first-order graph, performs threat perception and behavioral risk assessment through a graph learning model, and outputs the threat probability of each edge;

[0046] Output an edge risk score set and a node embedding set;

[0047] A path simulation module, which based on the edge risk score set and the node embedding set, combines with the first-order graph, identifies and quantifies the attack paths composed of multiple medium and low-risk behaviors in the graph, and generates an attack path set and a path risk score set;

[0048] A strategy generation module, which based on the attack path set and the path risk score, generates a candidate set of protection strategies for each path, evaluates the effect of the protection strategies to obtain a scoring result of the protection strategies, and sorts the protection strategies according to the scoring result;

[0049] A policy deployment module, which deploys protection policies based on the protection policy candidate set and the scoring results of the corresponding protection policies, monitors the deployment status and protection feedback, records the deployment target status after the policy deployment is completed, and installs a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0050] In summary, the technical effects and advantages of the present invention are as follows: By constructing a behavior analysis model and attack simulation, the present invention can not only detect known attacks, but also identify new threats in real time through adaptive learning, ensuring that the system has the ability to cope with future attacks. In addition, the present invention also greatly improves the system response speed by introducing an efficient data processing and automatic protection adjustment mechanism, ensuring that the enterprise information security protection can effectively intervene in real time to prevent the spread of threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 is a flowchart of the method steps in the present invention;

[0052] Figure 2 is a schematic diagram of the system structure in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0054] As Figure 1 shown, an enterprise information security management method based on artificial intelligence includes:

[0055] S1: Input the original data, where the original data includes a user permission information set, a network connection record set, and a resource access log set;

[0056] Integrate the original data into a first-order graph structure, and construct an attribute vector for the user nodes;

[0057] S2: Based on the first-order graph, perform threat perception and behavior risk assessment through a graph learning model, and output the threat probability of each edge;

[0058] The learning steps of the graph learning model include node embedding generation, edge representation construction, and edge-level risk prediction;

[0059] The node embedding generation aggregates information through graph convolution with structure normalization;

[0060] The edge representation construction is completed by concatenating the node embeddings at both ends and the edge attributes;

[0061] The edge-level risk prediction obtains a risk score by inputting the edge representation vector into a single-layer perceptron;

[0062] Output the set of edge risk scores and the set of node embeddings;

[0063] S3: Based on the set of edge risk scores and the set of node embeddings, combined with the first behavior graph, identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generate an attack path set and a path risk score set; The generation steps are as follows:

[0064] Starting from each non-core node, use breadth-first search with a limited depth to construct a set of potential attack paths on the premise that the edge risk score is higher than the set threshold;

[0065] Design a path scoring function for measuring the feasibility and concealment of the attacker's lateral penetration along this path;

[0066] For each node, retain the top K paths with the highest scores starting from it and reaching the set of core nodes;

[0067] Design a structural perturbation test mechanism to conduct path credibility confidence analysis on high-scoring paths;

[0068] S4: Based on the attack path set and the path risk score, generate a candidate set of protection strategies for each path, evaluate the effect of the protection strategies to obtain the scoring results of the protection strategies, and sort the protection strategies according to the scoring results;

[0069] The generation of the protection strategy generates corresponding protection strategies according to the risk score, path behavior, and access frequency according to the preset;

[0070] The evaluation is completed by calculating the difference in the risk score of the path before and after applying the corresponding protection strategy;

[0071] The sorting is carried out according to the preset rules; the preset rules include maximizing the strategy effect and balancing cost and benefit;

[0072] S5: Based on the candidate set of protection strategies and the scoring results of the corresponding protection strategies, deploy the protection strategies, and monitor the deployment status and protection feedback; The deployment includes the following steps:

[0073] Call the policy deployment mapping function to translate the logical policy into system control commands;

[0074] Sort all policies according to the deployment priority, deploy them in descending order according to the priority, skip conflicting policies or place them in the manual confirmation queue;

[0075] After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0076] The specific steps are as follows:

[0077] Step 1: Modeling of Multi-source Heterogeneous Security Behavior Data

[0078] In this step, data from multiple key security domains within the enterprise are structurally integrated to construct a behavior graph with the ability to express entity interaction relationships and behavior semantics , which is used for subsequent identification and analysis of security threats by the graph neural network model. To ensure the integrity of the modeling structure and its high coupling with the enterprise security scenario, only three core data sources are selected for integration in this step, namely: ① User identity and permission data, ② Host network connection data, and ③ File and database access logs. These three types of data together reflect the complete security behavior chain of "who, where, what, and what was done", which is the smallest closed loop for modeling high-risk behaviors within the enterprise

[0079] Input

[0080] User permission information set : where is the user identifier is their role code in RBAC (such as ordinary employee, administrator);

[0081] Network connection record set : is the user is the accessed host address is the access timestamp is the protocol type (such as RDP, SSH);

[0082] Resource access log set : is the user is the accessed resource (such as file, database) is the access time is the operation type (such as read, write, update)

[0083] Step details:

[0084] We integrate the three types of behavior data into a unified behavior graph structure , where:

[0085] : The node set, which contains three types of nodes: users, hosts, and resources;

[0086] : The edge set, which represents the operation behavior of users on other nodes;

[0087] : The node attribute vector, such as user role, resource type, etc.;

[0088] : Edge attribute vector, used to express behavioral detail features.

[0089] The construction of the edge set is based on the following formula:

[0090]

[0091] : Respectively represent the user and their behavioral target nodes (host or resource);

[0092] : Behavioral frequency (such as the number of connections / accesses in the past 24 hours, normalized to 0–1);

[0093] : Protocol or operation type encoding, for example, RDP is 1, SSH is 2, file read is 3, write is 4, DB update is 5.

[0094] At the same time, for the user node construct an attribute vector:

[0095]

[0096] : The role encoding of this user (such as 1 for administrator and 0 for employee);

[0097] : The average daily access quantity of this user to the host or resource (used for modeling activity).

[0098] In the final graph structure, each user node is connected to the host and resource nodes it has operated on through edges. The edge attributes represent behavioral details, and the node attributes represent behavioral identity and frequency.

[0099] Output

[0100] Output 1: Structured behavior graph , where all nodes and edges carry semantic attributes;

[0101] Output 2: Behavioral edge label vector , where indicates that this behavior is labeled as a historical high-risk behavior by the security system (which can be labeled by the administrator or automatically matched and generated).

[0102] In this step, three types of representative enterprise security data are precisely selected and integrated: user identity permissions, network access records, and resource access logs. A unified behavior graph is constructed through structure mapping , significantly improving the expression ability of behavioral semantics and the structured modeling ability. Compared with the traditional method of using tables or event lists, this behavioral graph not only expresses "whether the behavior occurs", but also clarifies "the context, frequency, and protocol type of the behavior". More importantly, this graph provides a natural graph structure input for graph neural network modeling, effectively capturing potential associated abnormal patterns within the enterprise, which is the key support for subsequent threat identification and attack path analysis.

[0103] Step 2: Threat Awareness and Risk Assessment Based on Graph Learning

[0104] In this step, based on the structured behavior graph constructed in Step 1 , threat awareness and behavioral risk assessment are carried out through a graph learning model, and the threat probability of each edge is output to support subsequent attack path deduction and security policy decision-making. In the scenario of this patent, the core of enterprise information security issues lies in the potential linkage relationships between complex behaviors. These behaviors may seem normal individually, but the paths formed in the structure have serious security risks. Therefore, the goal of this step is not only to identify individual behaviors that "seem like attacks", but more importantly, to model potential threats such as privilege escalation and abnormal propagation paths hidden in the "behavior combination" through graph learning, providing intelligent support for proactive defense of the patent.

[0105] Different from general graph classification or node classification, this step focuses on edge-level threat prediction, that is, judging whether each type of operation relationship between users and hosts, files, and databases constitutes a security risk. In the design, the graph topology structure, node role attributes, behavioral context features, and security annotation labels output in Step 1 are fully integrated to construct a multi-perspective graph learning scheme for detecting highly concealed behaviors.

[0106] To identify high-risk operations brought about by structurally complex behaviors, the graph learning scheme designed in this step includes three core stages: (1) node embedding generation; (2) edge representation construction; (3) edge-level risk prediction.

[0107] The key innovation lies in: introducing a structure-sensitive regularization term, a context relationship encoding function, and a graph topology stability constraint term, which strengthens the ability to identify "abnormal behavior combinations" while maintaining computational efficiency.

[0108] First, node embedding aggregates information through structure-normalized graph convolution and is constructed as follows:

[0109]

[0110] : the embedding vector of node ;

[0111] : The initial features of neighbor nodes come from ;

[0112] : Node degree, used for normalization;

[0113] : Graph convolution weight matrix;

[0114] : Bias term;

[0115] : Node 's neighbor set.

[0116] Subsequently, we construct the edge representation , which not only concatenates the embeddings of the two end nodes and the edge attributes , but also introduces the "context role difference factor" to measure the cross-level access intensity between the user and the target:

[0117]

[0118] : The representation vector of edge ;

[0119] : Respectively represent the role encodings of nodes and , coming from ;

[0120] : Take the L1 norm to represent the absolute value of the role level difference (e.g., from an employee to a database administrator, with a high value);

[0121] : The attribute vector of the edge, coming from ;

[0122] : Concatenation operation.

[0123] This design is for a key phenomenon in the patent scenario: unauthorized access often occurs when the role span is large but the frequency of the behavior itself is not high, which is difficult to identify by traditional frequency / protocol analysis. Through the structural difference significance modeling, this factor can enhance the model's recognition of asymmetric structure threats.

[0124] Then, the risk score Obtained by inputting a single-layer perceptron through edge representation vectors:

[0125]

[0126] : Edge 's risk prediction value;

[0127] : Perceptron weight matrix;

[0128] : Bias;

[0129] : Sigmoid function.

[0130] To improve the ability to judge highly concealed edge behaviors, we designed a regularization term , which is used to punish the sensitivity of the model to local structure perturbations and improve its stability under slightly changed graph topologies:

[0131]

[0132] Where is the risk score recalculated under slight perturbations (such as deleting 5% of random edges) in the edge set , which is used to constrain the robustness of the model to structural micro-changes and enhance its generality in actual attack path construction scenarios.

[0133] The comprehensive loss function is:

[0134]

[0135] : Binary cross-entropy loss;

[0136] : Regularization term weight, controlling the importance of structural robustness;

[0137] All parameters are trained using the standard Adam optimizer.

[0138] Output:

[0139] Output 1: Edge risk score set , for subsequent path construction;

[0140] Output 2: Node embedding set , representing the semantic context vector of each node, for credibility propagation calculation in subsequent paths.

[0141] Starting from the behavior graph, this step designs a structured graph learning method for edge-level risk scoring. By combining graph structure, behavior attributes, role differences, and structural robustness modeling, a complete end-to-end threat perception process is formed. Compared with existing rule-based or clustering-based detection methods, this method can identify low-frequency but high-impact abnormal interaction paths at the structural level, especially suitable for the problem characteristics of "sparse attack behavior distribution but severe structural impact" in the scenario of this patent. By introducing the role difference term and the structural stability regularization term , this solution shows stronger pertinence and interpretability in actual attack modeling, and also significantly improves the practicality and creativity of the model in the enterprise multi-role environment.

[0142] Step 3: Attack path simulation based on the risk graph

[0143] Based on the set of edge risk scores generated in Step 2 and the set of node embeddings , combined with the complete behavior graph constructed in Step 1 , a deduction mechanism for predicting potential attack propagation paths is constructed. In enterprise information security management, attacks often do not trigger at a single point, but have the characteristics of stages and lateral movement. Especially in an enterprise environment with complex permission levels and deep system structure distribution, attackers usually penetrate into the core system through "low-risk behavior chains". Therefore, the key objective of this step is to identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and achieve forward-looking modeling of unknown attack chains in the enterprise without relying on known attack templates.

[0144] This step is the bridge connecting "risk identification" and "security policy generation", and its design logic directly affects the system response ability of the patent. Different from traditional path traversal methods, this step introduces the real complexities in multiple patent scenarios, such as "multi-role access control levels", "priority focus on core assets", "context modeling of node behavior jumps", etc., with clear technical originality and practical guidance.

[0145] The essence of an attack path is one or more high-risk propagation chains that spread from non-critical nodes (attack entrances) to critical nodes (attack targets). Due to the complexity of enterprise networks, attack chains often do not show significant characteristics, and even consist of "seemingly normal" low-intensity operations. Therefore, this step adopts the following four-stage modeling strategy:

[0146] The first stage: Construct the potential path graph

[0147] Starting from each non-core node , using breadth-first search (BFS) with limited depth, at the edge risk score Above the set threshold Under the premise of To any A collection of paths , each path Represented as a sequence of nodes , and its corresponding edge set is .

[0148] Phase 2: Path scoring function design

[0149] Path scoring function It is used to measure the feasibility and concealment of an attacker's lateral penetration along the path. In order to combine the enterprise's unique access control structure, role hierarchy span, and path structure complexity, we propose the following risk function:

[0150]

[0151] in:

[0152] : Edge risk score, from step 2;

[0153] : Role span weight, The role codes of the nodes at both ends of the edge are respectively (e.g. 0 for ordinary employees and 2 for security managers). This item amplifies the path importance of “overreaching behavior”;

[0154] : Protocol sensitivity coefficient, from Extract the communication protocol or operation type (for example, remote login protocol is set to high weight, and ordinary HTTP is set to low weight);

[0155] : The path structure jump penalty term represents the mean square change rate of the embedding vectors of consecutive nodes in the path, and is defined as follows:

[0156]

[0157] This item reflects the degree of semantic jump of nodes in the path. If an attack path has frequent changes in system roles, operation semantics, etc., it is more likely to be an attack path.

[0158] is the adjustment coefficient of the structural jump penalty term, which can be set to a value between 0.3 and 0.5.

[0159] The design of this scoring function embodies three innovative points:

[0160] Introduction It solves the problem that unauthorized jumps cannot be identified solely by the connection frequency;

[0161] Introduce It enhances the ability to identify attack channel preferences (such as SSH / RDP);

[0162] Introduce Model the context mutation of the behavior path to prevent the model from overlearning the "stacking of high-risk edges" while ignoring the covert coherence of the attack.

[0163] Phase 3: Path Screening and Sorting

[0164] For each , retain the top highest-scoring paths that start from it and reach the core node set . If there are structural redundancy behaviors such as node duplication and nesting in the path, the simplest-first principle of structure can be used to remove duplicates (such as giving priority to shorter path lengths and lower hop counts).

[0165] Phase 4: Path Credibility Confidence Analysis

[0166] For all high-scoring paths, we introduce a structural adversarial perturbation test mechanism, that is, randomly remove the edges that are not on the path in the graph, and re-evaluate the changes. If the path score fluctuation is less than the threshold , then mark this path as a structurally stable path for subsequent policy direct intervention.

[0167] Output

[0168] Output 1: Attack path set , each path is a node sequence;

[0169] Output 2: Path risk score set , sorted in descending order of score.

[0170] This step integrates the structure diagram information in Step 1, the edge risk score and node context embedding representation in Step 2, and proposes an attack path modeling method that takes into account both structural interpretability and risk forward-looking in the real scenario of enterprise information security management. By comprehensively integrating three core risk patterns in enterprise security management, namely "role span", "communication protocol preference", and "behavior continuity jump", and designing a risk scoring function and a structural perturbation test mechanism, it realizes a highly credible prediction of the lateral attack chain. This solution breaks through the limitations of the existing single-point high-risk strike model, enabling this patent to have the ability to actively identify unknown attack paths under complex organizational system structures.

[0171] Step 4: Generation and Effect Evaluation of Attack Path-Driven Policy Candidate Sets

[0172] This step is based on the attack path set output in Step 3 and the path risk scores , and automatically generates a set of policy candidates for each path. These policy candidate sets provide a series of policy decisions for high-risk behavior nodes or critical jump behaviors in the path to prevent the further expansion of the attack path. The core goal of this step is to generate multiple candidate policies based on information such as the structure of the path, risk scores, and node role characteristics, and quantitatively evaluate the effectiveness of these candidate policies.

[0173] The focus of this step is to generate dynamic and targeted policy candidate sets through the analysis of the path structure, rather than directly reacting to or deploying against attacks. Its ultimate goal is to lay a foundation for subsequent policy deployment and actual execution.

[0174] For each path , this step needs to generate multiple policy candidates and evaluate the effects of these candidate policies. The generation of policies is based on information such as key nodes, cross-node behaviors, and the total risk score of the path. The specific process is as follows:

[0175] 1. Policy Candidate Generation

[0176] Each path corresponds to a set of policy candidates , and each policy represents a protective measure for one or more behavior nodes in the path . We generate policy candidates according to the following criteria:

[0177] Node-level policy: If the behavior risk score of a certain node in the path is relatively high, policies for this node can be generated, such as freezing the account, restricting access rights, etc.;

[0178] Edge-level policy: If a certain edge in the path involves high-risk protocols (such as RDP, SSH) or communication on non-conventional ports, policies for restricting protocol access or port blocking can be generated;

[0179] Path interruption policy: If the path is composed of multiple nodes combined through low-risk behaviors, and the "connection" of the intermediate path has relatively high security risks (for example, access logs show that a "low-frequency high-privilege user" accesses "important files"), policies for disconnecting a certain critical edge or enabling strong authentication can be generated.

[0180] Specifically, assume the path , we generate candidate policies for each node , such as:

[0181]

[0182] For edges , the generated policies may be:

[0183]

[0184] These policy candidates are mainly based on the following considerations:

[0185] High-risk nodes on the path: such as when the risk score is higher than the threshold, measures are preferentially taken against it;

[0186] Role differences: such as when multiple permission levels are crossed in the path (such as from ordinary employee to administrator), "permission elevation blocking" type policies are preferentially generated;

[0187] Access frequency: such as when the behavior nodes in a certain path involve frequent access to high-privilege resources, "multi-factor authentication" type policies are generated.

[0188] 2. Policy effect evaluation

[0189] For each policy candidate after generation, its effect needs to be evaluated next. The policy effect evaluation function is defined as the degree of risk reduction of the policy for the path, and is calculated as follows:

[0190]

[0191] Where:

[0192] is the risk score of the path before the policy is applied;

[0193] is the path after the policy is applied.

[0194] When calculating , we use all the nodes and edges on the path to update, considering the node importance, edge protocol characteristics and behavior patterns, and evaluate the inhibitory effect of the policy on the attack propagation in the path. When evaluating the policy, the cost of the policy is also considered. For example, some policies (such as full-network traffic encryption) may cause business interruption, and the score will be affected when the cost is too high.

[0195] 3. Policy priority ranking and screening

[0196] After generating all policy candidates and evaluating their effects, this step will select the optimal policy according to the following rules:

[0197] Maximize policy effect: Prioritize those policies that can significantly reduce path risks, i.e., maximize ;

[0198] Balance cost and benefit: Evaluate the cost of efficient policies and select those with low cost and high efficiency.

[0199] Finally, each path will correspond to an optimal policy , which is used for subsequent deployment and execution.

[0200] Output

[0201] Output 1: Policy candidate set , the optimal protection policy for each path;

[0202] Output 2: Scoring results of policy candidates , which is used for subsequent decision-making support.

[0203] This step proposes a dynamic policy generation and evaluation method based on attack paths by combining multi-dimensions such as nodes, edge risks, and role information in the path. Different from traditional static protection policies, this method generates specialized protection policies according to the specific structure of the attack path, making the policy design more intelligent and personalized. In enterprise security management, this method can handle complex and dynamic security threat environments. Especially in scenarios with complex organizations and variable permission levels, it can provide flexible and scalable protection solutions to ensure precise risk control for each path.

[0204] Step 5: Deployment and response of protection policies

[0205] This step is based on the policy set output in Step 4 and the corresponding policy effect scores , deploys the policies to the actual enterprise security system, and monitors the deployment status and protection feedback in real time to achieve the closed-loop implementation of "from identification to response". This step does not introduce early processing structures such as graph models and embedded features, but completely focuses on the deployment mapping, execution feedback analysis, and priority scheduling around the policy structure itself. Different from the traditional practice of "policy push is deployment", this step introduces policy conflict detection, deployment feedback functions, false block rate evaluation mechanisms, etc. to improve the intelligence and controllability of deployment.

[0206] First, for each policy , call the policy deployment mapping function , and translate the logical policy into system control commands:

[0207]

[0208] Among them:

[0209] : Policy deployment instruction;

[0210] : API template corresponding to the policy type, such as blocking connection, firewall rule;

[0211] : Parameters such as target user, target service, communication protocol carried in the policy.

[0212] For example:

[0213] If is the access privilege policy for then:

[0214] { "type": "LimitAccess", "target": "user_123", "params": { "new_role": "quarantined"}}

[0215] Is mapped to:

[0216] POST / api / iam / roles / update{ "user_id": "user_123", "role": "quarantined"}

[0217] Then, perform deployment priority sorting on all policies. The priority function is defined as:

[0218]

[0219] Among them:

[0220] : Policy deployment priority;

[0221] : Risk reduction effect of the policy on the path ;

[0222] : Conflict factor. If conflicts with any policy target in then , otherwise it is .

[0223] According to values, deploy policies in descending order, skip conflicting policies or place them in the manual confirmation queue.

[0224] After each policy is deployed, the system records the status at the deployment interface and installs lightweight monitoring components on the deployment target to collect deployment feedback information. Define the policy execution feedback function as follows:

[0225]

[0226] Where:

[0227] : Policy deployment feedback score;

[0228] : Whether the policy deployment is successful (success is , failure is );

[0229] : Policy false blocking rate, equal to the number of legitimate behavior anomaly alarms generated within 30 minutes after deployment / the number of normal accesses.

[0230] If , then mark the policy as "rollback candidate" and add it to the rollback buffer pool for further processing by the administrator or the system policy manager.

[0231] This step starts from the policy structure and constructs a standardized deployment interface mapping , deployment priority function and execution feedback function , realizing dynamic scheduling and quality closed-loop of policy implementation. The innovation lies in that in the deployment stage, not only "whether it is issued" is tracked, but also "whether it is effective and whether there is misjudgment" is tracked. Combining with the effect prediction during policy generation, it realizes intelligent, controllable and quantitative feedback of deployment execution, and completely supports the last link of the enterprise information security closed-loop protection system proposed in the patent.

[0232] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages: By combining intelligent prediction and simulation, potential security threats are identified in real time, and security policies are dynamically adjusted according to the changes of threats, making up for the static and lagging problems of traditional methods. By constructing a behavior analysis model and attack simulation, not only known attacks can be detected, but also new threats can be identified in real time through adaptive learning. By introducing an efficient data processing and automatic protection adjustment mechanism, the system response speed is greatly improved, ensuring that the enterprise information security protection can carry out effective intervention in real time and prevent the spread of threats.

[0233] The embodiments of the present application also provide an enterprise information security management system based on artificial intelligence, as shown in Figure 2 , including:

[0234] A data modeling module that inputs raw data, where the raw data includes a user permission information set, a network connection record set, and a resource access log set;

[0235] Integrate the raw data into a graph structure with the first row, and construct an attribute vector for the user node;

[0236] A risk assessment module that, based on the graph with the first row, performs threat perception and behavioral risk assessment through a graph learning model, and outputs the threat probability of each edge;

[0237] Output an edge risk score set and a node embedding set;

[0238] A path simulation module that, based on the edge risk score set and the node embedding set, combines with the graph with the first row to identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generates an attack path set and a path risk score set;

[0239] A policy generation module that, based on the attack path set and the path risk score, generates a candidate set of protection policies for each path, evaluates the effectiveness of the protection policies to obtain a scoring result of the protection policies, and sorts the protection policies according to the scoring result;

[0240] A policy deployment module that, based on the candidate set of protection policies and the scoring result of the corresponding protection policies, deploys the protection policies, monitors the deployment status and protection feedback. After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0241] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages: By utilizing cutting-edge technologies such as deep learning, adaptive model optimization, and large-scale data analysis, the present invention provides an intelligent security system with dynamic and adaptive protection, which can continuously monitor, predict, and respond to various threats in a complex and dynamically changing enterprise network environment.

[0242] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. An enterprise information security management method based on artificial intelligence, characterized in that, Including: S1: Input the original data, where the original data includes a user privilege information set, a network connection record set, and a resource access log set; Integrate the original data into a first-order graph structure and construct an attribute vector for the user nodes; S2: Based on the first-order graph, perform threat perception and behavioral risk assessment through a graph learning model, and output the threat probability of each edge; The learning steps of the graph learning model include node embedding generation, edge representation construction, and edge-level risk prediction; The node embedding generation aggregates information through graph convolution with structural normalization; The edge representation construction is completed by concatenating the node embeddings at both ends and the edge attributes; The edge-level risk prediction obtains a risk score by inputting the edge representation vector into a single-layer perceptron; Output the edge risk score set and the node embedding set; S3: Based on the edge risk score set and the node embedding set, combined with the first-order graph, identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generate an attack path set and a path risk score set; The generation steps are as follows: Starting from each non-core node, use breadth-first search with a limited depth to construct a set of potential attack paths on the premise that the edge risk score is higher than the set threshold; Design a path scoring function for measuring the feasibility and concealment of the attacker's lateral penetration along the path; For each node, retain the top K paths with the highest scores starting from it and reaching the core node set; Design a structural perturbation test mechanism to perform path credibility confidence analysis on the high-scoring paths; S4: Based on the attack path set and the path risk score, generate a candidate set of protection strategies for each path, evaluate the effect of the protection strategies to obtain the scoring results of the protection strategies, and sort the protection strategies according to the scoring results; The generation of the protection strategy generates corresponding protection strategies according to the risk score, path behavior, and access frequency according to the preset; The evaluation is completed by calculating the difference in the risk score of the path before and after applying the corresponding protection strategy; The sorting is performed according to the preset rules; the preset rules include maximizing the strategy effect and balancing cost and benefit; S5: Based on the candidate set of protection strategies and the scoring results of the corresponding protection strategies, deploy the protection strategies and monitor the deployment status and protection feedback; The deployment includes the following steps: Call the policy deployment mapping function to translate the logical policy into a system control command; Perform a deployment priority sorting on all policies, deploy them in descending order according to the priority, skip the conflicting policies or place them in the manual confirmation queue; After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

2. The enterprise information security management method based on artificial intelligence according to claim 1, wherein The node set of the first-order graph contains three types of nodes: users, hosts, and resources; The edge set of the first-order graph represents the operation behaviors of users on other nodes; The edge attributes of the first-order graph represent the behavior details, and the node attributes of the first-order graph represent the behavior identity and frequency.

3. The enterprise information security management method based on artificial intelligence according to claim 1, wherein, In the edge representation construction, a role difference factor is introduced to measure the cross-level access intensity between the user and the target, and the role difference factor takes the L1 norm, representing the absolute value of the role level difference.

4. The enterprise information security management method based on artificial intelligence according to claim 1, characterized in that The path scoring function is obtained by inputting the edge risk score into a single-layer perceptron, performing a linear transformation, and then compressing the result of the linear transformation through a Sigmoid function.

5. The enterprise information security management method based on artificial intelligence according to claim 4, characterized in that A role crossing weight is introduced in the path scoring function, and the role crossing weight is calculated from the role encodings of the nodes at both ends of the edge.

6. The enterprise information security management method based on artificial intelligence according to claim 4, wherein, A path structure jump penalty term is introduced in the path scoring function, and the path structure jump penalty term represents the mean square change rate of the continuous node embedding vectors in the path, highlighting the covert coherence of the attack.

7. The method for enterprise information security management based on artificial intelligence according to claim 1, characterized in that The structure perturbation test mechanism randomly removes the edges not on the path in the graph and re-evaluates the change in the path score. If the path score fluctuation is less than the threshold, the path is marked as a structurally stable path.

8. The enterprise information security management method based on artificial intelligence according to claim 1, wherein The generation of the protection strategy includes the following rules: Node-level strategy: If the behavior risk score of a certain node in the path is high, a strategy for this node can be generated, including freezing the account and restricting access rights. Edge-level strategy: If a certain edge in the path involves communication with a high-risk protocol or an unconventional port, a strategy for restricting protocol access or blocking the port is generated. Path interruption strategy: If the path is composed of multiple nodes combined with low-risk behaviors and there is a high security risk in the "connection" of the middle path, a strategy for disconnecting a certain critical edge or enabling strong authentication is generated.

9. An enterprise information security management system based on artificial intelligence, characterized in that, Including: A data modeling module that inputs the original data, where the original data includes a user privilege information set, a network connection record set, and a resource access log set; Integrate the original data into a first-order graph structure and construct an attribute vector for the user nodes; A risk assessment module that, based on the first-order graph, performs threat perception and behavior risk assessment through a graph learning model, and outputs the threat probability of each edge; Output an edge risk score set and a node embedding set; A path simulation module that, based on the edge risk score set and the node embedding set, combines with the first-order graph to identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generates an attack path set and a path risk score set; A strategy generation module that, based on the attack path set and the path risk score, generates a candidate set of protection strategies for each path, evaluates the effectiveness of the protection strategies to obtain a scoring result of the protection strategies, and sorts the protection strategies according to the scoring result; A strategy deployment module that, based on the candidate set of protection strategies and the scoring result of the corresponding protection strategies, deploys the protection strategies, monitors the deployment status and protection feedback. After the strategy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

Citation Information

Patent Citations

  • Cross-domain network security policy automatic generation and protection policy collaboration method and system

    CN119449428A

  • Software supply chain risk detection protection method and system

    CN119808082A

  • IoT device risk assessment and scoring

    US20200195679A1

Cited By

  • User operation risk dynamic monitoring method and device based on data consanguinity and medium

    CN120579036A

  • Method, device and medium for dynamic monitoring of user operation risks based on data lineage

    CN120579036B

  • Evaluation method and device of Internet of Things interface security policy, equipment and medium

    CN120785638A

  • Method, device and medium for evaluating security policy of internet of things interface

    CN120785638B

  • Security assessment method and system for industrial control system of industrial computer

    CN120993886A