Dynamic detection architecture, strategy, system and method for attack variants

Through the dynamic detection method of multi-layer risk detection architecture and self-learning model, the problems of high false alarm rate, weak anti-evasion ability and high complexity of attack variant detection in the existing technology are solved, and attack variant detection with high accuracy and low false alarm rate are realized, adapting to different network environments and meeting users' personalized needs.

CN120433964APending Publication Date: 2025-08-05PEI COUNTY PEOPLES HOSPITAL

Patent Information

Application Number
CN202510497101.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

When detecting attack variants, the existing technology has problems such as high false alarm rate, weak anti-evasion ability, high complexity and poor versatility, and it is difficult to effectively identify and deal with changing attack methods.

Method used

A multi-layer risk detection architecture is adopted, including a behavior change detection layer, a code structure detection layer and a data flow detection layer, combined with a self-learning model for dynamic adjustment and detection, a gradient enhancement tree optimization model is used to perform initial screening and variant detection through the system interface module and risk initial screening module.

Benefits of technology

It improves the comprehensiveness and accuracy of attack variant detection, reduces the false alarm rate, enhances the ability to combat and escape, adapts to different network environments, and meets users' personalized needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433964A_ABST
    Figure CN120433964A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of computer security, and relates to a dynamic detection architecture, strategy, system and method for attack variants, and the multi-layer risk detection architecture is composed of a behavior change detection layer, a code structure detection layer and a data flow detection layer. The dynamic adjustment detection strategy is formed by respectively introducing a behavior change detection layer, a code structure detection layer and a data flow detection layer in a multi-layer risk detection architecture into a self-learning model; the dynamic detection system comprises a system interface module, a risk preliminary screening module and a variation detection module; the dynamic detection method comprises the following steps: primarily screening data input through the system interface module by using the risk primary screening module; inputting the primarily screened data into a variation detection module for detection and analysis, and configuring the access authority of the input data according to an output result; according to the method, the comprehensiveness of variation feature detection is improved, and the detection performance of the model is improved so as to adapt to continuously changing attack features.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer security technology and relates to a dynamic detection architecture, strategy, system and method for attack variants. Background Art

[0002] As cybersecurity threats continue to evolve and attackers' technology improves, traditional security defense mechanisms are no longer fully capable of addressing these complex attacks. Attackers are circumventing conventional security measures by modifying existing attack methods or creating new variants, exposing networks and systems to greater risks. Therefore, detecting and identifying these attack variants has become a critical step in protecting information assets and network security.

[0003] Attack variant detection is of great significance in the current information security field and is an indispensable part of protecting network and system security. By continuously improving detection mechanisms and strengthening the response capabilities of security teams, the overall level of network security can be effectively improved, ensuring the security of information assets and the stable operation of businesses. Existing attack detection methods still have a high false alarm rate, which may misreport normal traffic or behavior, affecting user experience and work efficiency. Attackers are constantly evolving their attack methods and may circumvent traditional detection methods through means such as camouflage and encryption, resulting in missed detections. Some advanced detection methods require complex setup and configuration, requiring a high level of technical expertise and high deployment and maintenance costs. Some detection methods may be limited to specific network environments or system conditions, lacking versatility and flexibility. Overall, future development directions include reducing false alarm rates, improving detection accuracy, and strengthening anti-evasion capabilities to better protect network and system security. Summary of the Invention

[0004] The present invention aims to overcome the shortcomings of the prior art and provide a dynamic detection architecture, strategy, system and method for attack variants. The shortcomings are that the existing methods have high false alarm rates, countermeasure evasion, high complexity and poor versatility.

[0005] In order to achieve the purpose of the present invention, the present invention will be implemented by adopting the following technical solutions.

[0006] A multi-layer risk detection architecture consists of a behavior change detection layer, a code structure detection layer, and a data flow detection layer, where:

[0007] Behavior change detection layer, used to detect behaviors and monitor behavioral changes of access programs to capture variant features;

[0008] The code structure detection layer is used to detect the code, analyze the code structure, and find patterns similar to known attack features;

[0009] The data flow detection layer is used to analyze data flows, track data flows, and identify abnormal interactions.

[0010] A dynamically adjusted detection strategy is formed by introducing self-learning models into the behavior change detection layer, code structure detection layer and data flow detection layer in the multi-layer risk detection architecture. It is used to monitor input data in real time and dynamically adjust the input data to different detection layers for detection based on the different characteristics of the input data. Risk prediction is performed through the introduced self-learning model. During the risk prediction process, the self-learning model is optimized and the access rights of the input data are configured based on the output results of the self-learning model.

[0011] As a preferred embodiment of the present invention, the self-learning model is a gradient boosting tree with self-learning capability.

[0012] As a preferred embodiment of the present invention, the self-learning model is designed as follows:

[0013] Suppose there is a training set (x i ,y i ), where i = 1, ..., N, x i is the input feature, y i The true label of the corresponding feature; a model F(x) is to be fitted to approximate the target function y; the initial model F0(x) is a constant, and the average value of all sample labels is selected;

[0014] The iterative process is as follows:

[0015] F m (x) = F m-1 (x)+γh m (x)

[0016] Among them, F m (x) is the model after the mth iteration, γ is the learning rate, which controls the contribution of each tree, and h m (x) represents the mth regression tree;

[0017] Use the loss function to minimize the predicted value F m The error between (x) and the true value y:

[0018]

[0019] The new regression tree h is trained by gradient descent optimization method m (x), so that the loss function L is minimized.

[0020] As a preferred solution of the present invention, the input data includes user behavior data, performance indicators, and environmental change indicators, wherein:

[0021] Said performance indicators include memory leaks, inefficient algorithms, unnecessary calculations, and excessive database queries;

[0022] The environmental change indicators include data leakage caused by changes in network configuration and communication protocols, abnormal access paths and output paths, and data loss or damage caused by hardware problems;

[0023] The user behavior data includes

[0024] A dynamic detection system for attack variants includes a system interface module, a risk screening module, and a variant detection module, wherein:

[0025] System interface module, which provides interaction mode and interface selection, allowing users to customize settings and personalize configurations to meet the needs of different user groups and is used for inputting data;

[0026] A risk screening module with a built-in pre-trained large language model for preliminary screening of data input by the system interface module;

[0027] The variant detection module has a built-in multi-layer risk detection architecture and dynamically adjusts the detection strategy to perform variant feature detection and analysis on data that has been initially screened by the risk screening module.

[0028] As a preferred solution of the present invention, the interaction mode and interface include:

[0029] Voice interaction: Users can interact with the system through voice recognition to perform operations or obtain information;

[0030] Text input: Users can interact with the system by entering text via the keyboard or input box;

[0031] Graphical User Interface: Provides an intuitive graphical user interface that allows users to interact with the system by clicking buttons and dragging elements.

[0032] As a preferred solution of the present invention, the user-defined settings and personalized configurations include:

[0033] ① Theme style settings: Allow users to customize the interface's theme style, color, font size and other appearance settings to meet the personalized preferences of different users for the interface appearance;

[0034] ② Layout adjustment: Allow users to freely adjust the interface layout, drag and drop components, adjust panel positions, etc., to adapt to different users' preferences and habits for interface layout;

[0035] ③ Shortcut key settings: Provide user-defined shortcut keys, allowing users to quickly perform operations through the shortcut key combinations they set, thereby improving operational efficiency.

[0036] A dynamic detection method for attack variants includes the following steps:

[0037] S1. Use the risk screening module to perform preliminary screening on the data input through the system interface module;

[0038] S2. Input the initially screened data into the variant detection module. Based on the different characteristics of the input data, the module dynamically adjusts the detection strategy and dynamically adjusts the input data to different detection layers in the multi-layer risk detection architecture for detection. Risk prediction is performed using the introduced self-learning model. During the risk prediction process, the self-learning model is optimized, and access rights to the input data are configured based on the output of the self-learning model.

[0039] The output results are different types of computer risk labels, including malware attacks, abnormal logins, and data leaks.

[0040] As a preferred embodiment of the present invention, the primary screening comprises the following steps:

[0041] S91. Define different types of computer risk labels;

[0042] S92. Use a large language model to perform text classification and classify input data according to risk labels;

[0043] S93. Input new computer network data into the trained large language model to perform risk detection and preliminary screening, and generate a risk detection report based on the output results of the large language model.

[0044] As a preferred solution of the present invention, the risk detection report includes risk type, key information and recommended measures.

[0045] The present invention has the following advantages:

[0046] The present invention improves the comprehensiveness of variant feature detection based on a multi-level risk detection architecture;

[0047] This paper introduces a self-learning gradient boosting tree as a risk detection model. The model has a built-in residual learning strategy to continuously improve the model. Each iteration adds a new regression tree based on the previous model to gradually improve the detection performance of the overall model.

[0048] The self-learning model introduced in this invention continuously learns and improves according to the different characteristics of the data to adapt to the ever-changing attack characteristics;

[0049] A pre-trained large language model is used to achieve fast but relatively rough initial screening of a large number of samples. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1It is the overall framework diagram of the present invention;

[0051] Figure 2 This is a schematic diagram of the multi-layer risk monitoring architecture of the present invention;

[0052] Figure 3 Schematic diagram of a dynamic detection system of the present invention; DETAILED DESCRIPTION

[0053] The present invention will be further described with reference to the accompanying drawings and embodiments.

[0054] As an embodiment of the present invention, Figure 2 As shown in Figure 1, a multi-layer risk detection architecture consists of a behavior change detection layer, a code structure detection layer, and a data flow detection layer, where:

[0055] Behavior change detection layer, used to detect behaviors and monitor behavioral changes of access programs to capture variant features;

[0056] The code structure detection layer is used to detect the code, analyze the code structure, and find patterns similar to known attack features;

[0057] The data flow detection layer is used to analyze data flows, track data flows, and identify abnormal interactions.

[0058] As an embodiment of the present invention, Figure 2 As shown, a dynamic adjustment detection strategy is formed by introducing self-learning models into the behavior change detection layer, code structure detection layer and data flow detection layer in the multi-layer risk detection architecture, which is used to monitor input data in real time. According to the different characteristics of the input data, the input data is dynamically adjusted to different detection layers for detection. Risk prediction is performed through the introduced self-learning model. During the risk prediction process, the self-learning model is optimized, and the access rights of the input data are configured according to the output results of the self-learning model.

[0059] As an embodiment of the present invention, the self-learning model is a gradient boosting tree with self-learning capability.

[0060] As an embodiment of the present invention, the self-learning model is designed as follows:

[0061] Suppose there is a training set (x i ,y i ), where i = 1, ..., N, x i is the input feature, y i The true label of the corresponding feature; a model F(x) is to be fitted to approximate the target function y; the initial model F0(x) is a constant, and the average value of all sample labels is selected;

[0062] The iterative process is as follows:

[0063] F m (x) = F m-1 (x)+γh m (x)

[0064] Among them, F m (x) is the model after the mth iteration, γ is the learning rate, which controls the contribution of each tree, and h m (x) represents the mth regression tree;

[0065] Use the loss function to minimize the predicted value F m The error between (x) and the true value y:

[0066]

[0067] The new regression tree h is trained by gradient descent optimization method m (x), so that the loss function L is minimized.

[0068] As an embodiment of the present invention, the input data includes user behavior data, performance indicators, and environmental change indicators, wherein:

[0069] Said performance indicators include memory leaks, inefficient algorithms, unnecessary calculations, and excessive database queries;

[0070] The environmental change indicators include data leakage caused by changes in network configuration and communication protocols, abnormal access paths and output paths, and data loss or damage caused by hardware problems;

[0071] The user behavior data includes access path, access frequency, access time, addition, deletion, modification and query of data;

[0072] As an embodiment of the present invention, Figure 3 As shown, a dynamic detection system for attack variants includes a system interface module, a risk screening module, and a variant detection module, wherein:

[0073] System interface module, which provides interaction mode and interface selection, allowing users to customize settings and personalize configurations to meet the needs of different user groups and is used for inputting data;

[0074] A risk screening module with a built-in pre-trained large language model for preliminary screening of data input by the system interface module;

[0075] The variant detection module has a built-in multi-layer risk detection architecture and dynamically adjusts the detection strategy to perform variant feature detection and analysis on data that has been initially screened by the risk screening module.

[0076] As a preferred solution of the present invention, the interaction mode and interface include:

[0077] Voice interaction: Users can interact with the system through voice recognition to perform operations or obtain information;

[0078] Text input: Users can interact with the system by entering text via the keyboard or input box;

[0079] Graphical User Interface: Provides an intuitive graphical user interface that allows users to interact with the system by clicking buttons and dragging elements.

[0080] As a preferred solution of the present invention, the user-defined settings and personalized configurations include:

[0081] ① Theme style settings: Allow users to customize the interface's theme style, color, font size and other appearance settings to meet the personalized preferences of different users for the interface appearance;

[0082] ② Layout adjustment: Allow users to freely adjust the interface layout, drag and drop components, adjust panel positions, etc., to adapt to different users' preferences and habits for interface layout;

[0083] ③ Shortcut key settings: Provide user-defined shortcut keys, allowing users to quickly perform operations through the shortcut key combinations they set, thereby improving operational efficiency.

[0084] As an embodiment of the present invention, Figures 1 to 3 As shown, a dynamic detection method for attack variants includes the following steps:

[0085] S1. Use the pre-trained large language model in the risk screening module to perform preliminary screening on the data input through the system interface module;

[0086] S2. Input the initially screened data into the variant detection module. Based on the different characteristics of the input data, the module dynamically adjusts the detection strategy and dynamically adjusts the input data to different detection layers in the multi-layer risk detection architecture for detection. Risk prediction is performed using the introduced self-learning model. During the risk prediction process, the self-learning model is optimized, and access rights to the input data are configured based on the output of the self-learning model.

[0087] The output results are different types of computer risk labels, including malware attacks, abnormal logins, and data leaks.

[0088] As an embodiment of the present invention, the primary screening includes the following steps:

[0089] S91. Define different types of computer risk labels;

[0090] S92. Use a large language model to perform text classification and classify input data according to risk labels;

[0091] S93. Input new computer network data into the trained large language model to perform risk detection and preliminary screening, and generate a risk detection report based on the output results of the large language model.

[0092] As an embodiment of the present invention, the risk detection report includes risk type, key information and recommended measures.

[0093] The technical solution of the present invention is described in detail above in conjunction with the embodiments / drawings, but the present invention is not limited to the above technical solution. For ordinary technicians in this technical field, after knowing the contents recorded in the present invention, they can make several equivalent transformations and substitutions without departing from the principles of the present invention. These equivalent transformations and substitutions should also be regarded as falling within the scope of protection of the present invention.

Claims

1. A multi-layer risk detection architecture, characterized in that: The multi-layer risk detection architecture consists of a behavior change detection layer, a code structure detection layer, and a data flow detection layer, where: Behavior change detection layer, used to detect behaviors and monitor behavioral changes of access programs to capture variant features; The code structure detection layer is used to detect the code, analyze the code structure, and find patterns similar to known attack features; The data flow detection layer is used to analyze data flows, track data flows, and identify abnormal interactions.

2. A dynamic adjustment detection strategy, characterized in that: The dynamic adjustment detection strategy is formed by introducing self-learning models into the behavior change detection layer, code structure detection layer and data flow detection layer in the multi-layer risk detection architecture, and is used to monitor input data in real time. According to the different characteristics of the input data, the input data is dynamically adjusted to different detection layers for detection. Risk prediction is performed through the introduced self-learning model. During the risk prediction process, the self-learning model is optimized, and the access rights of the input data are configured according to the output results of the self-learning model.

3. A dynamic adjustment detection strategy according to claim 2, characterized in that: The self-learning model is a gradient boosting tree with self-learning capability.

4. A dynamic adjustment detection strategy according to claim 3, characterized in that: The self-learning model is designed as follows: Suppose there is a training set (x i ,y i ), where i = 1, ..., N, x i is the input feature, y i The true label of the corresponding feature; To fit a model F(x) to approximate the target function y; the initial model F0(x) is a constant, and the average value of all sample labels is selected; The iterative process is as follows: F m (x)=F m-1 (x)+γh m (x) Among them, F m (x) is the model after the mth iteration, γ is the learning rate, which controls the contribution of each tree, and h m (x) represents the mth regression tree; Use the loss function to minimize the predicted value F m The error between (x) and the true value y: The new regression tree h is trained by gradient descent optimization method m (x), so that the loss function L is minimized.

5. A dynamic adjustment detection strategy according to claim 2, characterized in that: The input data includes user behavior data, performance indicators, and environmental change indicators, among which: Said performance indicators include memory leaks, inefficient algorithms, unnecessary calculations, and excessive database queries; The environmental change indicators include data leakage caused by changes in network configuration and communication protocols, abnormal access paths and output paths, and data loss or damage caused by hardware problems; The user behavior data includes access path, access frequency, access time, and addition, deletion, modification and query of data; 6. A dynamic detection system for attack variants, characterized in that: It includes a system interface module, a risk screening module, and a variant detection module, including: System interface module, which provides interaction mode and interface selection, allowing users to customize settings and personalize configurations to meet the needs of different user groups and is used for inputting data; A risk screening module with a built-in pre-trained large language model for preliminary screening of data input by the system interface module; The variant detection module has a built-in multi-layer risk detection architecture and dynamically adjusts the detection strategy to perform variant feature detection and analysis on data that has been initially screened by the risk screening module.

7. A dynamic detection system for attack variants according to claim 6, characterized in that: The interaction mode and interface include: Voice interaction: Users can interact with the system through voice recognition to perform operations or obtain information; Text input: Users can interact with the system by entering text via the keyboard or input box; Graphical User Interface: Provides an intuitive graphical user interface that allows users to interact with the system by clicking buttons and dragging elements.

8. The attack variant dynamic detection system according to claim 6, characterized in that: The user-defined settings and personalized configurations include: ① Theme style settings: Allow users to customize the interface's theme style, color, font size and other appearance settings to meet the personalized preferences of different users for the interface appearance; ② Layout adjustment: Allow users to freely adjust the interface layout, drag and drop components, adjust panel positions, etc., to adapt to different users' preferences and habits for interface layout; ③ Shortcut key settings: Provide user-defined shortcut keys, allowing users to quickly perform operations through the shortcut key combinations they set, thereby improving operational efficiency.

9. A dynamic detection method for attack variants, characterized in that: The steps include: S1. Use the risk screening module to perform preliminary screening on the data input through the system interface module; S2. Input the initially screened data into the variant detection module. Based on the different characteristics of the input data, the module dynamically adjusts the detection strategy and dynamically adjusts the input data to different detection layers in the multi-layer risk detection architecture for detection. Risk prediction is performed using the introduced self-learning model. During the risk prediction process, the self-learning model is optimized, and access rights to the input data are configured based on the output of the self-learning model. Among them, the risk prediction results are different types of computer risk labels, and the computer risk labels include malware attacks, abnormal logins, and data leaks.

10. A dynamic detection method for attack variants according to claim 9, characterized in that: The primary screening comprises the following steps: S91. Define different types of computer risk labels; S92. Use a large language model to perform text classification and classify input data according to risk labels; S93. Input new computer network data into the trained large language model to perform risk detection and preliminary screening, and generate a risk detection report based on the output results of the large language model.

Citation Information

Patent Citations

  • Malicious code escape detection method and device

    CN118709184A

  • Multi-layer system for privacy enforcement and monitoring of suspicious data access behavior

    US20060259950A1

  • Self-learning-based intrusion detection apparatus and method

    US20240205241A1

  • Model-tiering machine learning model

    US20240346387A1

Cited By

  • Industrial control equipment intelligent operation and maintenance method and system based on large model

    CN120956542A

  • Intelligent operation and maintenance method and system for industrial control equipment based on large model

    CN120956542B