Data security management method and system based on cloud computing platform

By collecting data in real time on the cloud computing platform, generating fake data samples using GAN, optimizing discriminant models, HMM predicts security situations, and combining DQL and DDQN for attack path prediction, the problem of limited detection range and insufficient adaptability for new attacks in the existing technology is solved, real-time and intelligent defense strategy adjustment is achieved, and the security of the cloud computing platform is improved.

CN120337247AActive Publication Date: 2025-07-18JIANGSU XILIXI TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510389068.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-07-18
Estimated Expiration
2045-05-08

AI Technical Summary

Technical Problem

The existing feature-based cloud computing platform data security protection methods are difficult to deal with new attacks, have limited detection range, and lack real-time and adaptability, making it difficult to effectively defend against advanced persistent threats and zero-day attacks.

Method used

By collecting raw data from the cloud computing platform in real time, generating fake data samples using Generative Adversarial Network (GAN), combining with the extreme learning machine (ELM) to optimize the discriminant model, building a hidden Markov model (HMM) to predict security situations, and combining deep Q learning networks (DQL and DDQN) to predict attack paths and adjust defense strategies.

Benefits of technology

It has improved the detection capabilities of new attacks, realized real-time and intelligent defense strategy adjustments, enhanced the security and adaptability of the cloud computing platform, and can respond to complex and changeable attack modes in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337247A_ABST
    Figure CN120337247A_ABST
Patent Text Reader

Abstract

The invention discloses a data security management method and system based on a cloud computing platform, and relates to the technical field of data security management, and the method comprises the steps: collecting original data of the cloud computing platform in real time, and carrying out the preprocessing; constructing a discrimination model based on a generative adversarial network (GAN) to generate a forged data sample, taking the forged data sample and a real data sample as input data, optimizing the discrimination model by using the input data based on an extreme learning machine, and discriminating attack data; and constructing a security situation model by using a hidden Markov model, optimizing parameters through a cluster particle algorithm, and outputting a predicted security situation based on real-time attack data. A discrimination model is optimized through a generative adversarial network and an extreme learning machine, the discrimination precision of attack data is effectively improved, a security situation model is established through a hidden Markov model, model parameters are optimized in combination with a cluster particle algorithm, a predicted attack path is combined with a deep Q learning network, and the security risk of attack data is improved. And attack path prediction is carried out through the dual deep Q network, and a defense strategy is adjusted in real time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security management, and particularly to a data security management method and system based on a cloud computing platform. Background Art

[0002] With the rapid development of cloud computing technology, cloud computing platforms have become an important support for modern informatization construction. By integrating computing resources, storage resources, and network resources, cloud computing platforms provide users with on-demand computing and storage services, greatly improving the utilization efficiency of resources and the flexibility of management. Especially in the fields of enterprise information management, data processing, business intelligence, etc., the application of cloud computing platforms is becoming more and more extensive. However, with the wide popularization of cloud computing, data security issues have gradually become important challenges that need to be solved urgently. Since cloud computing platforms carry a large amount of sensitive data and key services, how to effectively ensure the security of data and prevent security issues such as data leakage, tampering, and denial-of-service attacks has become a key issue in the operation of cloud computing platforms.

[0003] Currently, the traditional data security protection of cloud computing platforms mainly relies on static rules and signature-based security detection methods. For example, intrusion detection systems (IDS) and intrusion prevention systems (IPS) are widely used in the data security management of cloud computing platforms. By analyzing network traffic characteristics, log information, and behavior data to identify and intercept malicious activities. However, with the increasing complexity of attack means, especially advanced persistent threats (APT) and zero-day attacks against cloud computing platforms, the existing static rules and signature-based security protection methods are difficult to cope with new threats. For example, when facing unknown attack patterns, traditional IDS / IPS systems usually rely on predefined attack signature libraries, which makes their ability to identify new attacks weak, and the phenomena of false positives and false negatives are relatively serious. In addition, traditional security protection methods are difficult to perform real-time adaptive adjustment, and the defense effect is limited when facing large-scale distributed attacks or complex attack paths. Therefore, how to improve the intelligence, real-time performance, and adaptability of data security management methods has become an important research direction in the field of data security protection of cloud computing platforms. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a data security management method and system based on a cloud computing platform to solve the existing signature-based security protection technology, which has problems such as limited detection range and poor ability to cope with new attacks.

[0006] To solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a data security management method based on a cloud computing platform, which includes:

[0008] Real-time collect the original data of the cloud computing platform and perform preprocessing;

[0009] The original data includes security vulnerability data, node basic information, and device configuration logs;

[0010] Convert the original data into numerical data and obtain a random noise vector. Based on the generative adversarial network (GAN), construct a discriminant model to generate forged data samples, and use the real data samples as input data. Based on the extreme learning machine, optimize the discriminant model with the input data and discriminate the attack data;

[0011] Use the hidden Markov model to construct a security situation model and optimize the parameters through the cluster particle algorithm, and output the predicted security situation based on the real-time attack data;

[0012] Substitute the predicted security situation into the deep Q-learning network and combine it with the double deep Q-network to predict the attack path, and adjust the defense strategy in real time based on the predicted attack path graph.

[0013] As a preferred solution of the data security management method based on the cloud computing platform of the present invention, wherein: the real-time collection of the original data of the cloud computing platform and preprocessing includes:

[0014] Regard each device in the cloud computing platform as a node, and use the collection tool to collect the original data of each node in the cloud computing platform in real time;

[0015] The original data includes security vulnerability data, node basic information, and device configuration logs;

[0016] The preprocessing includes removing duplicates from the collected original data, deleting duplicate records, using the mean interpolation method to interpolate numerical data, and using the standard deviation method to detect and remove outliers.

[0017] As a preferred solution of the data security management method based on the cloud computing platform of the present invention, wherein: the conversion of the original data into numerical data and obtaining a random noise vector, constructing a discriminant model based on the generative adversarial network (GAN) to generate forged data samples, and using the real data samples as input data includes:

[0018] Extract the features in the preprocessed original data, convert the text data and categorical data in the features into numerical data and standardize them;

[0019] Use the standard normal distribution to sample to obtain a random noise vector of the numerical data, and use it as the input of the generative adversarial network generator;

[0020] Initialize the weight parameters of the generator and discriminator of the generative adversarial network and , input a random noise vector into the generator to generate forged data samples, input the data samples into the discriminator, and output a discrimination value;

[0021] Define the loss function of the discriminator and the loss function of the generator , the optimization objective of the discriminator is to maximize the loss function, preset the number of training rounds, repeatedly and alternately train the generator and the discriminator until the preset number of training rounds is reached, generate forged data samples by inputting a random noise vector into the trained generative adversarial network, and input the real data samples and the forged data samples as input data into the discriminator.

[0022] As a preferred solution of the data security management method based on the cloud computing platform described in the present invention, wherein: the use of the extreme learning machine to optimize the discrimination model with input data and discriminate attack data includes:

[0023] Take each group of input data of the discriminator as a sample, randomly initialize the weights and biases of each hidden layer node in the extreme learning machine, transfer the input data of the discriminator to each hidden layer node through the randomly initialized weights and biases, and apply an activation function to generate the hidden layer output, calculate for all samples, and construct a hidden layer output matrix ;

[0024] Calculate the loss function of all samples , use the gradient descent method, and minimize the loss function by adjusting the value of the output weight , and obtain the final output weight by solving the minimized loss function ;

[0025] Use the final output weight to initialize the discrimination model, input the input data into the discrimination model, set a discrimination threshold according to the discrimination value output by the discriminator, discriminate the attack data, if the discrimination value is greater than the discrimination threshold, it means that the input data is real data, otherwise, it means that the input data is attack data;

[0026] Train the discriminator for multiple rounds, update the output weight with new input data in each round, and perform incremental learning using the extreme learning machine according to the new input data to dynamically update the output weight after each training ends.

[0027] As a preferred solution of the data security management method based on the cloud computing platform described in the present invention, wherein: the use of the hidden Markov model to construct a security situation model and optimize the parameters through the cluster particle algorithm, and output a predicted security situation based on real-time attack data includes:

[0028] Define the security posture of the cloud computing platform as a Markov process, define the hidden state as the overall security posture of all nodes in the cloud computing platform, use the hidden Markov model to construct the security posture model, and initialize the parameters of the security posture model;

[0029] The parameter optimization by the cluster particle algorithm includes using random numbers to initialize the initial positions and initial velocities of each particle in the particle swarm, and selecting the size of the particle swarm;

[0030] Use K-means clustering to divide the particle swarm into multiple clusters, each cluster representing a local optimal solution region, perform independent fitness evaluations on the particles in each cluster, and the particles within the cluster share a common best position;

[0031] Calculate the fitness of each particle through the fitness function, update the position and velocity of the particle according to the velocity adjustment formula, re-evaluate the fitness of the particle according to the position update and velocity adjustment of the particle, the new position of each particle corresponds to a new solution, compare the fitness of all particles, select the particle with the maximum fitness as the global optimal particle, and update the global best position;

[0032] Select the global optimal particle as the parameter of the final security posture model;

[0033] Take the attack data at different time steps as the observation sequence, use the Viterbi algorithm to decode the optimal hidden state sequence, initialize the probability of the initial state, for each time step and each hidden state in the observation sequence, recursively calculate the maximum probability of each hidden state, and use the backtracking process to find the most likely hidden state sequence by recording the source of the maximum probability in each time step;

[0034] Detect the performance of the security posture model by evaluating the log-likelihood value of the model, and perform fine-tuning of the model parameters according to the log-likelihood value and other performance evaluation indicators;

[0035] Output the predicted security posture by substituting the real-time attack data into the security posture model.

[0036] As a preferred solution of the data security management method based on the cloud computing platform of the present invention, wherein: substituting the predicted security posture into the deep Q-learning network includes:

[0037] Define the state space and the action space , use MulVAL to generate the attack path graph between nodes in the cloud computing platform and integrate it into the state space ;

[0038] As a preferred solution of the data security management method based on the cloud computing platform of the present invention, wherein: the combination of the double deep Q network for attack path prediction and the real-time adjustment of the defense strategy based on the predicted attack path graph includes:

[0039] Taking the deep Q learning network as the initial Q network and the double deep Q network as the target Q network;

[0040] Initializing the initial Q network and the target Q network, and creating a deep neural network Denoting the initial Q network, where Denoting the parameters of the initial Q network, and creating a double deep Q network where Denoting the parameters of the target Q network;

[0041] The agent will at each time point Evaluate all actions in the action space according to the current state space Balance exploration and exploitation through the -greedy strategy. The agent selects the action with the largest current Q value with probability and selects a random action with probability , where is the exploration rate, representing the probability that the agent selects a random action; Denoting the exploration rate, representing the probability that the agent selects a random action;

[0042] Defining a reward function according to the nodes , and the reward function includes new node reward, control network node reward and collected credential reward;

[0043] Calculating the target Q value using the target Q network , selecting the next optimal action. After executing an action, the agent updates the Q value through the difference between the current Q value and the target Q value;

[0044] Regularly updating the parameters of the initial Q network to the target Q network;

[0045] Based on the attack path graph generated by MulVAL, the agent preferentially evaluates each possible attack path and selects the path that maximizes the return. By analyzing the attack path in real time, the agent adjusts the defense strategy in real time.

[0046] In a second aspect, the present invention provides a data security management system based on a cloud computing platform, including:

[0047] A data acquisition module for real-time collecting and preprocessing the original data of the cloud computing platform;

[0048] A noise generation module, which is used to convert original data into numerical data and obtain a random noise vector, construct a discriminant model based on the generative adversarial network (GAN) to generate forged data samples, and use the forged data samples and real data samples as input data;

[0049] An attack discrimination module, which is used to optimize the discriminant model by using the input data based on the extreme learning machine and discriminate attack data;

[0050] A model construction module, which is used to construct a security situation model by using the hidden Markov model and optimize the parameters by using the cluster particle algorithm;

[0051] A security prediction module, which is used to output a predicted security situation based on real-time attack data;

[0052] A path prediction module, which is used to substitute the predicted security situation into the deep Q-learning network and combine it with the double deep Q-network to predict the attack path, and adjust the defense strategy in real time based on the predicted attack path graph.

[0053] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the data security management method based on the cloud computing platform as described in the first aspect of the present invention is implemented.

[0054] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the data security management method based on the cloud computing platform as described in the first aspect of the present invention is implemented.

[0055] The beneficial effects of the present invention are as follows: by using the generative adversarial network and optimizing the discriminant model with the help of the extreme learning machine, the discrimination accuracy of attack data is effectively improved; a security situation model is established by using the hidden Markov model, and the model parameters are optimized by combining the cluster particle algorithm; the predicted attack path is combined with the deep Q-learning network, and the attack path is predicted by the double deep Q-network, and the defense strategy is adjusted in real time. Description of the Drawings

[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0057] Figure 1 It is a flowchart of the data security management method based on the cloud computing platform in Embodiment 1.

[0058] Figure 2Schematic diagram of the data security management system based on the cloud computing platform in Embodiment 1. Detailed implementation manners

[0059] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following will describe the detailed implementation manners of the present invention with reference to the accompanying drawings of the specification.

[0060] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0061] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation manner of the present invention. The appearances of "in one embodiment" in different places in this specification do not all refer to the same embodiment, nor are they separate or alternative embodiments that exclude each other with other embodiments.

[0062] Embodiment 1, referring to Figure 1 and Figure 2 , is the first embodiment of the present invention. This embodiment provides a data security management method based on the cloud computing platform, including the following steps:

[0063] S1. Real-time collect the original data of the cloud computing platform and perform preprocessing;

[0064] Specifically, real-time collecting the original data of the cloud computing platform and performing preprocessing includes:

[0065] Regarding each device (physical node or virtual node) in the cloud computing platform as a node, and using a collection tool to real-time collect the original data of each node in the cloud computing platform;

[0066] The collection tool includes using security vulnerability scanning tools (such as Nessus, OpenVAS) to scan the security vulnerability data of each node, obtaining the basic node information of each node through network topology discovery tools (such as Nmap, NetBrain), and obtaining device configuration logs through the management tools of the cloud computing platform (such as AWS CloudWatch, Azure Monitor);

[0067] The original data includes security vulnerability data (such as system vulnerabilities, service vulnerabilities, application vulnerabilities), basic node information (such as device type, operating system, running services, network configuration, etc.), and device configuration logs (such as recording the hardware status, load, CPU usage rate, memory occupancy rate of the device);

[0068] The preprocessing includes deduplicating the collected raw data and deleting duplicate records. For example, if the same user performs the same operation multiple times at the same time point, only one record is retained. The numerical data (such as the resource values of virtual machines and the magnitudes of network traffic) is interpolated using the mean interpolation method, and outliers are detected and removed using the standard deviation method.

[0069] Existing cloud computing platform security management systems usually rely on static security data or only protect against known attack signatures, ignoring the dynamics and changes of data. By using real-time collection tools such as security vulnerability scanning tools (Nessus, OpenVAS), network topology discovery tools (Nmap, NetBrain), and cloud platform management tools (AWS CloudWatch, Azure Monitor), the present invention can perform real-time data collection on each node (physical node or virtual node) of the cloud computing platform, including security vulnerability data, basic node information, device configuration logs, etc. This multi-angle real-time data collection enhances the response ability to complex attacks, enables comprehensive information to be obtained and precisely preprocessed in a shorter time, and ensures the accuracy and reliability of subsequent discriminant models and prediction models. Most current systems rely on manually configured rules to capture attack patterns, while the present invention realizes real-time and comprehensive perception of the cloud platform status through automated collection of diversified data sources, effectively solving the problem of insufficient detection of new attack patterns.

[0070] S2. Convert the raw data into numerical data and obtain a random noise vector. Based on the generative adversarial network GAN, construct a discriminant model to generate forged data samples, and use them as input data together with the real data samples;

[0071] Specifically, converting the raw data into numerical data and obtaining a random noise vector, and using the generative adversarial network GAN to construct a discriminant model to generate forged data samples and using them as input data together with the real data samples includes:

[0072] Extract the features in the preprocessed raw data, and convert the text data and categorical data in the features into numerical data and standardize them through methods such as one-hot encoding, hashing, and direct numericalization;

[0073] Use standard normal distribution sampling to obtain a random noise vector of the numerical data, and use it as the input of the generative adversarial network generator;

[0074] Initialize the weight parameters of the generator and discriminator of the generative adversarial network and , a random noise vector is input into the generator to generate forged data samples, and the data samples are input into the discriminator to output a discrimination value, where the discrimination value represents the probability that the data sample is a real data sample;

[0075] The generator is a deep neural network model, whose input is a random noise vector and output is a forged data sample (such as forged attack data), and the weight parameters of the generator are initialized;

[0076] The discriminator is a binary classification neural network used to determine whether the input data is real network traffic (real data distribution) or forged data generated by the generator (generated data distribution), and the weight parameters of the discriminator are initialized;

[0077] Define the loss function of the discriminator and the loss function of the generator . The optimization objective of the discriminator is to maximize the loss function, that is, to maximize the identification accuracy of real data samples and minimize its identification error of forged data samples. The optimization objective of the generator is to minimize the loss function, which is used to minimize the probability that the data samples it generates are identified as forged data by the discriminator, that is, to make it difficult for the discriminator to distinguish between generated data and real data. The loss function is:

[0078] ,

[0079] ,

[0080] where, is the expected value, and respectively represent the average losses of real data samples and the random noise vector on the real data distribution and the forged data distribution respectively. The distribution is a normal distribution. represents the discrimination value of the discriminator for the real data sample , represents the discrimination value of the discriminator for the forged data sample ;

[0081] According to actual requirements, preset the number of training rounds, and repeatedly and alternately train the generator and the discriminator until the preset number of training rounds is reached. By inputting a random noise vector into the trained generative adversarial network, forged data samples are generated, and the real data samples and the forged data samples are used as input data and input into the discriminator;

[0082] The alternately training the generator and the discriminator includes fixing the weight parameters of the generator , and updating the weight parameters of the discriminator , calculate the gradient using the backpropagation algorithm according to the loss function, and update the weight parameters of the discriminator , and then by fixing the weight parameters of the discriminator , update the weight parameters of the generator , calculate the gradient using the backpropagation algorithm according to the loss function, and update the weight parameters of the generator .

[0083] Traditional security systems adopt static rules or feature-based discrimination methods, which are easily bypassed by new and unknown attack patterns. However, the present invention establishes a discrimination model through a generative adversarial network (GAN), generates forged attack data samples for comparison training with real data samples, further improves the accuracy of the discrimination model, and the forged data generated by the generator enhances the diversity of the training data, enabling the discriminator to effectively distinguish real data from forged data, thereby improving the detection ability of abnormal attack behaviors. Traditional systems rely solely on a rule library for attack recognition, while the present invention uses GAN to automatically generate forged data similar to attack behaviors to train the model, enabling the system to identify new attacks without explicit rules. This method greatly enhances the adaptability and intelligence of the system and has a high ability to deal with unknown attacks.

[0084] S3. Optimize the discrimination model using the input data based on an extreme learning machine and discriminate the attack data;

[0085] Specifically, optimizing the discrimination model using the input data based on an extreme learning machine and discriminating the attack data includes:

[0086] Take each set of input data of the discriminator as a sample, randomly initialize the weights and biases of each hidden layer node in the extreme learning machine, pass the input data of the discriminator through the randomly initialized weights and biases to each hidden layer node, and apply an activation function to generate the hidden layer output. Calculate for all samples to construct a hidden layer output matrix , where each row represents the hidden layer activation output of a sample, and the hidden output matrix is:

[0087] ,

[0088] where, represents the Sigmoid activation function, represents the weights of the hidden layer nodes, represents the total number of hidden layer nodes, represents the biases of the hidden layer nodes, represents the input sample, represents the total number of samples;

[0089] To protect the cloud computing platform from potential attacks, it is necessary to identify attack behaviors promptly and accurately. The extreme learning machine optimizes the input data, enabling the discriminator to more accurately identify attack data. Through model training, the extreme learning machine can not only accurately judge known attack patterns but also effectively identify new attack patterns. As attack methods continue to evolve, the discriminant model also needs to be continuously optimized. The extreme learning machine has the ability to quickly adjust and can be updated in real time according to newly collected attack data, ensuring the efficiency and accuracy of the model, and providing the cloud computing platform with dynamic and highly adaptable attack discrimination capabilities;

[0090] Calculate the loss function for all samples , that is, the difference between the predicted output and the target output of each sample. The loss function is:

[0091] ,

[0092] where represents the output weight corresponding to the hidden layer node , represents the weight of the hidden layer node , represents the input sample , represents the bias of the hidden layer node , represents the target output (i.e., the true label) of the input sample , usually normal traffic or attack data, obtained by manually annotating network traffic data;

[0093] Use the gradient descent method to minimize the loss function by adjusting the value of the output weight . By solving the minimized loss function, the final output weight is obtained. If the hidden output matrix is non-invertible (usually occurs when the number of training samples is greater than the number of hidden layer nodes), the generalized inverse matrix is used to solve;

[0094] Initialize the discriminant model using the final output weight . By inputting the input data into the discriminant model, setting the discrimination threshold according to the discrimination value output by the discriminator, and discriminating the attack data. If the discrimination value is greater than the discrimination threshold, it indicates that the input data is real data; otherwise, it indicates that the input data is attack data;

[0095] The extreme learning machine can quickly train a neural network, greatly reducing the training time. It randomly initializes the weights of the input layer and directly calculates the weights of the output layer using simple mathematical methods, thus eliminating a large number of calculation steps in the training of traditional neural networks. When facing large-scale data, it has significant advantages over traditional neural networks. In the security detection task of the cloud computing platform, the data volume is usually very large (including node information, vulnerability data, configuration logs, etc.). The extreme learning machine can process this large-scale data while ensuring accuracy, thereby training and updating more efficiently;

[0096] The discriminator is trained in multiple rounds. In each round, the output weights are updated using new input data. After each training, incremental learning is performed using the extreme learning machine according to the new input data to dynamically update the output weights, ensuring the discriminator's adaptability to new types of attacks. The performance of the discriminator is evaluated through cross-validation. If the detection accuracy does not meet the expectations, the discriminator is optimized by adjusting the learning rate, the number of nodes in the hidden layer, the activation function, the batch size, etc.

[0097] Traditional discrimination methods (such as neural networks and support vector machines) usually require a long time in the training process and are less efficient when dealing with complex data. By introducing the extreme learning machine (ELM), the present invention achieves the goal of quickly training and optimizing the discrimination model. ELM can avoid the backpropagation calculation in traditional neural networks by randomly initializing the weights and biases of the hidden layer nodes, thereby greatly improving the training speed and achieving a good generalization effect without relying on a large-scale data set. Traditional discrimination methods often have low processing efficiency when facing large-scale data, while by using ELM, the training speed and real-time response ability of the discrimination process are greatly improved, enabling the security protection of the cloud computing platform to adapt to and respond to high-frequency attacks in a timely manner.

[0098] S4. Use the hidden Markov model to construct a security situation model and optimize the parameters through the cluster particle algorithm, and output the predicted security situation based on real-time attack data;

[0099] Specifically, using the hidden Markov model to construct a security situation model and optimize the parameters through the cluster particle algorithm, and outputting the predicted security situation based on real-time attack data includes:

[0100] Define the security situation of the cloud computing platform as a Markov process, define the hidden state as the overall security situation of all nodes in the cloud computing platform (such as normal, abnormal, under attack), use the hidden Markov model to construct a security situation model, and initialize the parameters of the security situation model. The parameters include the transition probability matrix, the observation probability matrix, and the initial state distribution;

[0101] The sum of the elements in each row of the transition probability matrix is 1, and each element represents the probability that the cloud computing platform transitions from one hidden state to another hidden state;

[0102] The sum of the elements in each row of the observation probability matrix is 1, and each element describes the probability of observing a certain observation value in each hidden state;

[0103] The initial state distribution defines the probability that the cloud computing platform is in a certain hidden state at the beginning;

[0104] The hidden Markov model is a tool suitable for describing the transitions of a system between different states. Especially when dealing with a dynamically changing system, the security posture of the cloud computing platform changes over time. These changes may be caused by normal operations, abnormal behaviors, or attack activities. It can effectively model this dynamic process and describe the transition of the platform from one security posture to another (such as from normal to abnormal, or from abnormal to the attack state). During this process, the hidden states of the platform (such as normal, abnormal, under attack) change dynamically. By establishing a state transition probability model, the security posture can be effectively tracked and predicted. In the cloud computing platform, the hidden states may not be directly observable, but through the hidden Markov model, these hidden states can be inferred from the observed data (such as traffic patterns, system logs, etc.). This is crucial for security posture modeling because it helps detect potential security issues;

[0105] The parameter optimization by the clustering particle algorithm includes using random numbers to initialize the initial positions and initial velocities of each particle in the particle swarm. Each particle represents a solution vector. The initial position of the particle represents a guess of the parameters of the security posture model, and the velocity of each particle represents the velocity of the particle in the search space, which is the amplitude of the parameter adjustment. According to the actual requirements, the size of the particle swarm is selected. Usually, the number of particles is between dozens and hundreds. Too many particles will increase the computational burden, while too few particles may lead to insufficient search space;

[0106] Use K-means clustering to divide the particle swarm into multiple clusters. Each cluster represents a local optimal solution region, avoiding the particle swarm falling into a local optimal solution and improving the overall search efficiency. Independently evaluate the fitness of the particles in each cluster. The particles within the cluster share a common best position (i.e., the global best solution within the cluster);

[0107] Using the Baum-Welch algorithm, each particle is trained iteratively. This algorithm is an EM (Expectation-Maximization) algorithm used to estimate the parameters of a model given observed data. In each iteration, the forward variables and backward variables are calculated through the E-step (forward-backward algorithm), and the expected value of the transition probability for each pair of hidden states is calculated. The transition probabilities and observation probabilities are updated using the expected values in the M-step. The E-step and M-step are repeated until the parameters of the hidden Markov model converge or reach a preset maximum number of iterations;

[0108] The forward variable represents the probability of reaching a hidden state from the initial state through a certain time point;

[0109] The backward variable represents the probability of reaching the termination state from a certain time point;

[0110] After each particle is trained, the error value is calculated using the validation dataset, and the fitness of each particle is calculated through the fitness function. The particle updates its position and velocity according to the velocity adjustment formula. The fitness of each particle serves as the basis for adjusting the position and velocity of the particle in the next step. The fitness function is:

[0111] ,

[0112] where, represents the fitness of particle and indicates the quality of the solution. The larger the value, the better the solution. represents the error value of particle and is measured using the mean squared error;

[0113] Based on the position update and velocity adjustment of the particle, the fitness of the particle is re-evaluated. The new position of each particle corresponds to a new solution. The fitness of all particles is compared, and the particle with the maximum fitness is selected as the global optimal particle, and the global best position is updated;

[0114] The global optimal particle is selected as the parameters of the final security situation model;

[0115] The particle swarm optimization algorithm can effectively avoid the problem of local optimal solutions. For parameter optimization in security situation modeling, using PSO can help find the optimal model parameters, thereby improving the prediction ability and generalization ability of the model. The transition probability matrix, observation probability matrix, and initial state distribution in the hidden Markov model are the keys to the model performance. Through the particle swarm optimization algorithm, these parameters can be optimized, thereby improving the prediction ability of the hidden Markov model for the security situation of the cloud computing platform. The PSO algorithm can search for the optimal solution within a large range by simulating the flight and exploration of particles in the search space, thereby avoiding falling into local optimal solutions and ensuring the discovery of global optimal parameters, further improving the accuracy of the model;

[0116] Take the attack data at different time steps as the observation sequence, use the Viterbi algorithm to decode the optimal hidden state sequence, initialize the probability of the initial state, for each time step and each hidden state in the observation sequence, recursively calculate the maximum probability of each hidden state, and use the backtracking process to find the most likely hidden state sequence by recording the source of the maximum probability in each time step;

[0117] Detect the performance of the security situation model by evaluating the log-likelihood value of the model, and fine-tune the model parameters according to the log-likelihood value and other performance evaluation metrics (such as accuracy, recall, etc.) to improve the accuracy of security situation prediction;

[0118] The change of the security situation is real-time and may fluctuate with the evolution of attack means and the change of system state. After the hidden Markov model is combined with the cluster particle optimization, it can accurately predict the security situation of the platform, provide an effective decision-making basis for system administrators, and timely discover potential threats. By combining the hidden Markov model and the particle swarm optimization algorithm, the dynamic changes of the platform's security situation can be captured, and the prediction of future states can be provided. Before an attack occurs, the model can predict the potential attack situation and make a response in advance. Since the attacker's attack means are constantly updated, a flexible prediction model is needed. The hidden Markov model can adapt to the changing attack patterns and environments by continuous learning and adjusting parameters, thus enhancing the ability to prevent new types of attacks;

[0119] Substitute the real-time attack data into the security situation model to output the predicted security situation.

[0120] Accurate prediction of the security situation is an essential part of cloud computing platform protection. Existing methods usually use static models or rule-based systems, which are difficult to dynamically predict and adapt to changing attack paths. The present invention uses a hidden Markov model (HMM) to construct a security situation model, combines the cluster particle algorithm to optimize the model parameters, and performs iterative training of the parameters through the Baum-Welch algorithm, further improving the model's prediction ability for the security situation. The HMM model can accurately evaluate the security state of the cloud platform in multi-step prediction, thus providing a reliable basis for attack path prediction and defense strategy adjustment. By combining the HMM and the cluster particle algorithm, the present invention solves the problems of poor dynamic adaptability and lack of real-time warning ability in traditional methods, enabling the cloud computing platform to effectively respond to changing attack situations and timely adjust the defense strategy.

[0121] S5. Substitute the predicted security situation into the deep Q-learning network and combine it with the double deep Q-network to predict the attack path, and adjust the defense strategy in real time based on the predicted attack path graph;

[0122] Specifically, substituting the predicted security situation into the deep Q-learning network includes:

[0123] Define the state space and the action space To improve the generalization ability and intelligent level of the system, use MulVAL to generate the attack path graph between nodes in the cloud computing platform and integrate it into the state space ;

[0124] Attack path prediction is the core part of the defense system. By using MulVAL to generate the attack path graph, it can help the agent simulate the behavior of the attacker, thereby predicting possible attack paths in advance. By understanding the attack paths, defense strategies can be deployed specifically to reduce the possibility of successful attacks;

[0125] The state space mentioned above includes taking the predicted security situation as a component of the state space. The state space expression is:

[0126] ,

[0127] where respectively represent the security vulnerability data (such as system vulnerabilities, service vulnerabilities, application vulnerabilities), node basic information (such as device type, operating system, running services, network configuration, etc.), device configuration logs (such as recording the hardware status, load, CPU usage rate, memory occupancy rate) of the device, and the predicted security situation at the time point ;

[0128] Whenever the input data changes, the state space is updated simultaneously. The agent adjusts its actions in real time according to the changes in the state space in the environment. If the security vulnerability data in the state space changes, the agent quickly adapts to the new attack pattern and predicts the corresponding attack path or defense strategy;

[0129] The MulVAL mentioned above refers to a tool and language for multi-stage vulnerability analysis and attack path prediction. By extracting the attack paths from the MulVAL graph and converting them into numerical features, the risk level of these paths, the importance of nodes, and the success probability of paths are used as part of the state vector. For example, if a path passes through multiple high-risk nodes, the risk value of this path can be set to be higher and reflected to the agent;

[0130] The action space mentioned above includes defining this action space according to the possible attack methods and defense measures in the cloud computing platform environment to achieve the goals of attack path prediction and defense strategy optimization. The action space expression is:

[0131] ,

[0132] Among them, respectively represent local exploitation, remote attack, lateral movement, firewall rule adjustment, traffic restriction, and source IP blocking;

[0133] The ultimate goal of setting the action space is to enable the agent to optimize the attack path prediction through the deep Q - learning model and adjust the defense strategy accordingly.

[0134] Traditional security protection methods often rely on manually configured defense rules, and have poor protection effects when facing complex attack paths and real - time changing security situations. By introducing deep Q - learning (DQL) and double - deep Q - network (DDQN), the present invention realizes intelligent attack path prediction and defense strategy optimization. DQL can train the agent through real - time attack data, enabling it to gradually learn how to handle various attack patterns. DDQN combines the Q - value update mechanism and the target network, effectively solving the over - estimation problem in traditional Q - learning, thereby improving the accuracy of attack path prediction and the real - time adjustment ability of the defense strategy. Traditional defense methods are difficult to adaptively adjust the defense strategy, while by introducing deep reinforcement learning (DQL and DDQN), the present invention realizes the ability of real - time learning and automatic adjustment, so that the system can quickly learn and optimize the strategy when facing unknown attacks, improving the security and adaptability of the platform.

[0135] Furthermore, when combining the double - deep Q - network for attack path prediction, the real - time adjustment of the defense strategy based on the predicted attack path map includes:

[0136] Taking the deep Q - learning network as the initial Q - network and the double - deep Q - network (DDQN) as the target Q - network;

[0137] Initializing the initial Q - network and the target Q - network, creating a deep neural network representing the initial Q - network, where represents the parameters of the initial Q - network, creating a double - deep Q - network where represents the parameters of the target Q - network, and at initialization, set ;

[0138] The agent will, at each time point evaluate all actions in the action space according to the current state space and balance exploration and exploitation through the - greedy strategy, The - greedy strategy helps the agent explore more in the initial stage of training and exploit the currently learned knowledge more in the later stage of training. The agent selects the action with the maximum current Q - value with a probability (exploitation), and with a Probabilistically select a random action (exploration), where the exploration rate, which represents the probability that the agent selects a random action. By presetting the exploration rate, as the training progresses, it will gradually decrease, thereby increasing the probability that the agent utilizes the known strategy;

[0139] Define the reward function according to the nodes , and the reward function includes new node rewards, control network node rewards, and collection voucher rewards, which are used to quantify the rewards obtained by the agent when selecting a specific attack path or defense strategy. The formula is:

[0140] ,

[0141] where represents the reward value obtained by the agent when executing the action at time point , , , respectively represent the weight coefficients of each reward item, , , respectively represent new node rewards, control network node rewards, and collection voucher rewards;

[0142] The new node reward refers to setting key nodes (such as management nodes, database nodes) in the cloud computing platform according to actual needs. Whenever the attack path selected by the agent successfully reaches a new node, according to the complexity of the network topology and the attack path, the agent will give a reward based on the criticality of the discovered node. If the node is a key node, the reward value will increase, otherwise, the reward value will decrease. For example, if the agent selects an attack path and discovers a server containing sensitive data, the reward value increases. If an insignificant routing node is discovered, the reward value decreases;

[0143] The control network node reward means that whenever the agent successfully attacks and controls a node, the control state of the node changes, and the agent gives a reward based on the importance of the node and its impact on the subsequent attack path. If a key node is controlled, the reward value will increase, otherwise, the reward value will decrease. For example, if the agent controls a host and successfully uses it as a springboard for subsequent attacks, the reward value increases, while if a low-value node (such as a peripheral device) is controlled, the reward value decreases;

[0144] The said collection voucher reward means that whenever the agent successfully collects important vouchers (such as administrator passwords, database connection information, etc.), the reward value will increase. Voucher collection is usually associated with the success rate of the attack target and the complexity of the attack path. When important vouchers are collected, the reward value increases, and when ordinary vouchers are collected, the reward value decreases. For example, if the agent successfully obtains the administrator voucher and controls high-value network resources, the reward value is high; if only the voucher of a non-critical user is obtained, the reward value is low.

[0145] Calculate the target Q value using the target Q network , select the next optimal action, and the formula is:

[0146] ,

[0147] Among them, represents the reward value obtained by the agent when executing the action at time point , represents the discount factor, which controls the influence degree of future rewards, represents the next state space in the target Q network select the action with the maximum Q value of, representing the return that the agent expects to obtain by taking this action starting from the current state;

[0148] After executing an action, the agent updates the Q value through the difference between the current Q value and the target Q value, and the formula is:

[0149] ,

[0150] Among them, represents the Q value of the initial Q network when selecting the action in the state space , represents the learning rate, which determines the influence degree of new data on the Q value update;

[0151] Through multiple trainings and Q value updates, the agent will be able to more accurately select the attack path and defense measures, thereby improving the prediction and defense effects;

[0152] Regularly update the parameters of the initial Q network to the target Q network;

[0153] Deep Q-learning can optimize the decision-making process of the agent in a complex environment, while DDQN further solves the overestimation problem that may exist in standard DQN. By combining these methods, the agent can continuously improve the prediction of the attack path, adjust the defense strategy in real time, and improve the defense effect;

[0154] ​Based on the attack path graph generated by MulVAL, the agent first evaluates each possible attack path and selects the path that maximizes the reward. This process relies on the Q-value update of DDQN, enabling the agent to adaptively select the best path during training. By analyzing the attack path in real time, the agent adjusts the defense strategy in real time.

[0155] Through the combination of multiple intelligent algorithms such as Generative Adversarial Network (GAN), Extreme Learning Machine (ELM), Hidden Markov Model (HMM), and Deep Q-Learning (DQL), the present invention forms a multi-level defense mechanism. Each technical module complements each other, forming a complete security protection system from data collection, attack prediction to defense strategy adjustment. Compared with the existing single defense technology, this multi-technology fusion method can improve the protection effect from multiple dimensions, enabling the system to cope with complex attack patterns and changing security threats. Traditional systems usually rely on a single defense mechanism, while the present invention significantly improves the overall intelligence level and accuracy of security protection through a multi-level intelligent defense system and can better handle complex attack paths and dynamically changing attack patterns.

[0156] This embodiment also provides a data security management system based on a cloud computing platform, including:

[0157] A data collection module for real-time collecting and preprocessing the original data of the cloud computing platform;

[0158] A noise generation module for converting the original data into numerical data and obtaining a random noise vector, constructing a discriminant model based on the Generative Adversarial Network GAN to generate forged data samples, and using the forged data samples and real data samples as input data;

[0159] An attack discrimination module for optimizing the discriminant model using the input data based on the Extreme Learning Machine and discriminating attack data;

[0160] A model construction module for constructing a security situation model using the Hidden Markov Model and optimizing the parameters through a cluster particle algorithm;

[0161] A security prediction module for outputting a predicted security situation based on real-time attack data;

[0162] A path prediction module for substituting the predicted security situation into a Deep Q-Learning network and combining with a Double Deep Q-Network for attack path prediction, and adjusting the defense strategy in real time based on the predicted attack path graph.

[0163] This embodiment also provides a computer device, which is applicable to the case of a data security management method based on a cloud computing platform, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the data security management method based on the cloud computing platform as proposed in the above embodiment.

[0164] The computer device may be a terminal. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0165] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the data security management method based on the cloud computing platform as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM for short), Electrically Erasable Programmable Read-Only Memory (EEPROM for short), Erasable Programmable Read-Only Memory (EPROM for short), Programmable Read-Only Memory (PROM for short), Read-Only Memory (ROM for short), magnetic memory, flash memory, a magnetic disk, or an optical disc.

[0166] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A data security management method based on a cloud computing platform, characterized in that: Including: Collecting the original data of the cloud computing platform in real time and performing preprocessing; The original data includes security vulnerability data, node basic information, and device configuration logs; Converting the original data into numerical data and obtaining a random noise vector, constructing a discriminant model based on the generative adversarial network GAN to generate forged data samples, and using the real data samples as input data, optimizing the discriminant model using the input data based on the extreme learning machine and discriminating attack data; Using the hidden Markov model to construct a security situation model and optimizing the parameters through the cluster particle algorithm, and outputting the predicted security situation based on the real-time attack data; Substituting the predicted security situation into the deep Q-learning network and combining the double deep Q-network to predict the attack path, and adjusting the defense strategy in real time based on the predicted attack path graph.

2. The data security management method based on a cloud computing platform according to claim 1, wherein: The converting the original data into numerical data and obtaining a random noise vector, constructing a discriminant model based on the generative adversarial network GAN to generate forged data samples, and using the real data samples as input data includes: Extracting the features in the preprocessed original data, converting the text data and categorical data in the features into numerical data and performing standardization; Using the standard normal distribution sampling to obtain the random noise vector of the numerical data and using it as the input of the generative adversarial network generator; Initialize the weight parameters of the generator and discriminator of the generative adversarial network and , input a random noise vector into the generator to generate a forged data sample, input the data sample into the discriminator, and output a discrimination value; Define the loss function of the discriminator and the loss function of the generator , the optimization objective of the discriminator is to maximize the loss function. Set the preset number of training epochs, and repeatedly and alternately train the generator and the discriminator until the preset number of training epochs is reached. By inputting a random noise vector into the trained generative adversarial network, a forged data sample is generated, and the real data sample and the forged data sample are used as input data and input into the discriminator.

3. The data security management method based on a cloud computing platform according to claim 2, wherein: The optimizing the discriminant model using the input data based on the extreme learning machine and discriminating attack data includes: Take each set of input data of the discriminator as a sample, randomly initialize the weights and biases of each hidden layer node in the extreme learning machine, pass the input data of the discriminator to each hidden layer node through the randomly initialized weights and biases, and apply the activation function to generate the hidden layer output. Calculate for all samples to construct the hidden layer output matrix ; Calculate the loss function for all samples , using the gradient descent method, by adjusting the output weights values to minimize the loss function, and by solving the minimized loss function, obtain the final output weights ; Use the final output weights Initialize the discriminant model. By inputting the input data into the discriminant model, set the discrimination threshold according to the discrimination value output by the discriminator to discriminate the attack data. If the discrimination value is greater than the discrimination threshold, it means that the input data is real data; otherwise, it means that the input data is attack data. Performing multiple rounds of training on the discriminator, updating the output weights with new input data in each round, and after each training, performing incremental learning using the extreme learning machine according to the new input data and dynamically updating the output weights.

4. The data security management method based on a cloud computing platform according to claim 3, wherein: The using the hidden Markov model to construct a security situation model and optimizing the parameters through the cluster particle algorithm, and outputting the predicted security situation based on the real-time attack data includes: Defining the security situation of the cloud computing platform as a Markov process, defining the hidden state as the overall security situation of all nodes in the cloud computing platform, using the hidden Markov model to construct a security situation model, and initializing the parameters of the security situation model; The optimizing the parameters through the cluster particle algorithm includes initializing the initial position and initial velocity of each particle in the particle swarm using random numbers and selecting the size of the particle swarm; Using K-means clustering to divide the particle swarm into multiple clusters, each cluster representing a local optimal solution area, independently evaluating the fitness of the particles in each cluster, and the particles in the cluster sharing a common best position; Calculating the fitness of each particle through the fitness function, updating the position and velocity of the particle according to the velocity adjustment formula, re-evaluating the fitness of the particle according to the position update and velocity adjustment of the particle, the new position of each particle corresponding to a new solution, comparing the fitness of all particles, selecting the particle with the maximum fitness as the global optimal particle, and updating the global best position; Selecting the global optimal particle as the parameters of the final security situation model; Use the attack data at different time steps as the observation sequence, and use the Viterbi algorithm to decode the optimal hidden state sequence. Initialize the probability of the initial state. For each time step and each hidden state in the observation sequence, recursively calculate the maximum probability of each hidden state. Use the backtracking process to find the most likely hidden state sequence by recording the source of the maximum probability at each time step; Detect the performance of the security situation model by evaluating the log-likelihood value of the model. Fine-tune the model parameters according to the log-likelihood value and other performance evaluation metrics; Substitute the real-time attack data into the security situation model to output the predicted security situation.

5. The data security management method based on a cloud computing platform according to claim 4, characterized in that: The substitution of the predicted security situation into the deep Q-learning network includes: Define the state space and the action space and use MulVAL to generate the attack path graph between nodes in the cloud computing platform and integrate it into the state space .

6. The data security management method based on a cloud computing platform according to claim 5, characterized in that: The combination of the double deep Q-network for attack path prediction and the real-time adjustment of the defense strategy based on the predicted attack path graph includes: Use the deep Q-learning network as the initial Q-network and the double deep Q-network as the target Q-network; Initialize the initial Q-network and the target Q-network, and create a deep neural network Denote the initial Q-network, where Denote the parameters of the initial Q-network, and create a double deep Q-network , where Denote the parameters of the target Q-network; The agent will at each time point evaluate the action space according to the current state space All actions in, through -greedy policy to balance exploration and exploitation, the agent selects the action with the largest current Q-value with probability and selects a random action with probability, where exploration rate, representing the probability that the agent selects a random action; Define the reward function according to the nodes , where the reward function includes the new node reward, the control network node reward, and the collection voucher reward; Calculate the target Q value using the target Q network , select the next optimal action. After executing an action, the agent updates the Q value based on the difference between the current Q value and the target Q value; Regularly update the parameters of the initial Q-network to the target Q-network; Based on the attack path graph generated by MulVAL, the agent preferentially evaluates each possible attack path and selects the path that maximizes the reward. By analyzing the attack path in real time, the agent adjusts the defense strategy in real time.

7. The data security management method based on a cloud computing platform according to claim 1, characterized in that: The preprocessing includes deduplicating the collected raw data, deleting duplicate records, using the mean interpolation method to interpolate numerical data, and using the standard deviation method to detect and remove outliers.

8. A data security management system for a cloud computing platform based on the data security management method for a cloud computing platform according to any one of claims 1-7, characterized in that: It includes: A data collection module for real-time collecting the raw data of the cloud computing platform and performing preprocessing; A noise generation module for converting the raw data into numerical data and obtaining a random noise vector, constructing a discriminant model based on the generative adversarial network GAN to generate forged data samples, and using the forged data samples and the real data samples as input data; An attack discrimination module for optimizing the discriminant model using the input data based on the extreme learning machine and discriminating the attack data; A model construction module for constructing a security situation model using the hidden Markov model and optimizing the parameters through the cluster particle algorithm; A security prediction module for outputting the predicted security situation based on the real-time attack data; A path prediction module for substituting the predicted security situation into the deep Q-learning network and combining the double deep Q-network for attack path prediction, and real-time adjusting the defense strategy based on the predicted attack path graph.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the data security management method based on the cloud computing platform according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the data security management method based on the cloud computing platform according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Attack-oriented network security situation prediction method, device and system

    CN108494810A

  • Cyberspace security situation awareness detection and analysis system and method

    CN110855687A

  • Network security situation element identification system and method based on particle swarm optimization

    CN113486337A

  • Distributed GAN attack and defense method and system oriented to data sharing

    CN117278305A

  • Network defense model training method, network defense method and device

    CN117459306A

Cited By

  • Cloud security multi-level depth defense system construction method and system

    CN121396667A

  • Methods and Systems for Constructing a Multi-Layer, In-Depth Cloud Security Defense System

    CN121396667B