Network security level protection evaluation method and system based on artificial intelligence
Through time-granular adaptive slicing and reverse tracing mechanism, combined with asset resistance matrix and network environment factor drift, the problem of poor dynamic adaptability of existing network security level protection assessment methods is solved, and accurate risk level division and reduction of false alarms and missed reports are achieved.
Patent Information
- Application Number
- CN202511004404.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-07-21
AI Technical Summary
Existing network security level protection assessment methods rely on manual analysis, have fixed time slice granularity, are difficult to adapt to events of different durations, have unsystematic risk factor tracing, and fail to dynamically correlate asset resistance with threat propagation characteristics, leading to deviations in assessment results.
Adaptive slicing with time granularity is used to extract key operations, and the triggering, propagation, and impact sub-genes are traced back to build an asset resistance matrix. The boundaries are dynamically adjusted, the thresholds are adjusted in combination with the drift of network environment factors, and risk levels are divided through artificial intelligence.
It enables refined analysis of network security incidents, reduces information loss and redundancy, improves the accuracy of risk factor extraction and the adaptability of evaluation results, and reduces false positives and missed reports.
Smart Images

Figure CN120639476A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet security technology, and in particular to an artificial intelligence-based network security level protection assessment method and system. Background Art
[0002] Network security level protection assessment is a key link in ensuring network system security. Its core lies in accurately identifying risks and quantifying risk levels. In existing technologies, network security level protection assessment methods have many limitations:
[0003] First, the assessment process relies too much on manual analysis and lacks an automated mechanism for extracting key operations from cybersecurity incidents. Furthermore, the fixed granularity of time slices makes it difficult to adapt to events of varying durations, resulting in loss of details for short events and redundant data for long events.
[0004] Second, risk factor tracing is unsystematic, with a lack of standardized processes for extracting triggering, propagation, and influencing sub-genes. Matching attack patterns with vulnerabilities relies on simple comparisons, without verification based on asset allocation, which can easily lead to false positives.
[0005] Third, the failure to dynamically correlate asset resistance with threat propagation characteristics leads to distorted risk boundary determination. The rigidity of security level threshold settings fails to consider fluctuations in business scenarios and the correlation between historical risk patterns, making it difficult to adapt to dynamic risk changes in complex network environments, resulting in biased final assessment results.
[0006] Therefore, there is an urgent need for an intelligent and dynamic evaluation method to improve the accuracy of network security level protection evaluation. Summary of the Invention
[0007] In response to the shortcomings of the existing technology, the present invention provides a network security level protection assessment method and system based on artificial intelligence, which solves the problem that the existing network security level protection assessment relies on manual labor and has poor dynamic adaptability.
[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions: a network security level protection evaluation method based on artificial intelligence, comprising:
[0009] S1. For network security incidents, we use time-granular adaptive slicing to extract key operations, and then trace back the triggering sub-genes, propagating sub-genes, and influencing sub-genes, splicing them into risk gene chains and storing them in the gene chain library.
[0010] S2. Construct an asset resistance matrix, calculate the transmission force score based on the propagator genes of the risk gene chain, define the risk impact range through the elastic boundary radius, and dynamically adjust the boundary;
[0011] S3. Based on the preset basic threshold of security level, combined with the basic threshold of network environment factor drift, and combined with the dynamic correction threshold of the similarity between the current state and the gene chain library, the final security risk level is divided.
[0012] As a further solution of the present invention, the slice granularity G is dynamically adjusted according to the event duration T. The specific formula is:
[0013]
[0014] in, is the floor symbol.
[0015] As a further embodiment of the present invention, the specific steps of tracing the trigger gene are as follows:
[0016] Extract abnormal commands in key slicing operations and perform standardization processing;
[0017] Perform structured analysis of attack patterns in the CVE vulnerability library to extract typical attack command templates, affected asset types, and trigger conditions corresponding to each CVE vulnerability;
[0018] Calculate the string similarity between the standardized abnormal command and the typical attack command template of the CVE vulnerability, where the similarity = 1-(edit distance / longer string length);
[0019] Based on historical attack data, a similarity threshold is preset to screen out CVE vulnerabilities with a similarity ≥ the threshold, forming a candidate vulnerability list. The candidate list is then sorted in descending order of similarity, with high-similarity vulnerabilities being retained first.
[0020] Extract the configuration information of the current network assets and verify the matching between the candidate vulnerabilities and the assets;
[0021] The final trigger sub-gene is determined by combining the similarity and verification results of the candidate vulnerabilities: if only one meets the conditions, it is directly output; if multiple meet the conditions, the vulnerability with the highest similarity and passed verification is selected.
[0022] As a further embodiment of the present invention, the specific steps of tracing back the propagator gene are:
[0023] Extract network connection records from event slices and construct a network traffic graph, where nodes are assets, edges are connection relationships, and edge weights are transmission frequencies.
[0024] The K-means algorithm is used to cluster the paths in the network traffic graph to identify high-frequency propagation paths, and the propagation carrier is determined in combination with protocol analysis.
[0025] As a further embodiment of the present invention, the specific steps of tracing the influencing sub-genes are as follows:
[0026] Establish an asset evaluation matrix based on business coreness and data sensitivity. Business coreness is divided into core, important, and marginal, with weights of 5, 3, and 1 respectively; sensitivity is divided into high, medium, and low, with weights of 5, 3, and 1 respectively;
[0027] Calculate the asset value coefficient K based on the asset evaluation matrix, where K = business coreness weight + sensitivity weight;
[0028] According to the formula
[0029] Calculate the service interruption loss L2 using the formula L2 = interruption duration × hourly business revenue × K;
[0030] The repair cost L3 is calculated using the formula L3 = emergency response labor cost + system repair cost;
[0031] Calculate the total business loss value L = L1 + L2 + L3;
[0032] According to the formula L(t) = L×e -λt Adjust the loss value of the business over time, where t is the time after the attack occurs and λ is the attenuation coefficient;
[0033] Output the influencing sub-gene and the loss value L after attenuation.
[0034] As a further solution of the present invention, the specific steps for calculating the communication power score are:
[0035] Extract the transmission vector, frequency factor, and range factor from the propagator gene;
[0036] The transmission carriers are divided into high-quality carriers, medium-quality carriers, and low-quality carriers, with corresponding basic scores of 70, 50, and 30 respectively. The carrier type can be directly matched through the network log in the transmission sub-gene;
[0037] The frequency factor = the number of transmissions per unit time / the industry benchmark number of transmissions, with a value range of [0.3, 1.5]. If it exceeds the range, the value of the interval boundary is taken;
[0038] The range factor = (number of affected asset types / 3) + 0.5, with a value range of [0.5, 1.8]. If the value exceeds the range, the value at the boundary of the range is used;
[0039] The transmission score F is obtained according to the formula F = (transmission carrier basic score × impact factor × range factor). If there are intercepted records in the communicator gene, F×0.7 needs to be calculated, where F∈[0,100]. If it exceeds the interval, the interval boundary value is taken.
[0040] As a further solution of the present invention, the average resistance of the asset is calculated And according to the formula Calculate the elastic boundary radius S, where [] represents the rounding symbol, S∈[0,5]. If S exceeds the value interval, the interval boundary value is taken.
[0041] As a further solution of the present invention, the preset safety level basic thresholds Fmin and Fmax are constructed with S as the independent variable. The specific formula is F min =50-5S-S 2 , F max =90-10S.
[0042] As a further solution of the present invention, the specific steps of obtaining the final threshold are:
[0043] According to the formula Calculate the network environment factor p(q), where q is the business activity index;
[0044] The drift threshold is obtained as follows: basic threshold × (1 + p(q));
[0045] Calculate the similarity Sim with the gene chain library, and further dynamically correct the drifted threshold according to Sim to obtain the final thresholds Fmin' and Fmax'. The specific correction rules are as follows:
[0046] If Sim>0.8, then the post-drift threshold is ×0.8;
[0047] If 0.5≤Sim≤0.8, the threshold remains unchanged after drift;
[0048] If Sim < 0.5, the post-drift threshold is × 1.1;
[0049] Security risk levels are divided by final threshold:
[0050] If F<Fmin', it is judged as low risk; if Fmin'≤F≤Fmax', it is judged as medium risk; if F>Fmax', it is judged as high risk.
[0051] An artificial intelligence-based network security level protection assessment system, comprising:
[0052] The gene chain extraction module uses time-granular adaptive slicing to extract key operations for network security incidents, and then reversely traces the triggering sub-genes, propagating sub-genes, and influencing sub-genes, splicing them into risk gene chains and storing them in the gene chain library.
[0053] The boundary framing module constructs an asset resistance matrix, calculates the transmission power score based on the propagator genes of the risk gene chain, frames the risk impact range through the elastic boundary radius, and dynamically adjusts the boundary;
[0054] The level classification module is based on the preset security level basic threshold, combined with the network environment factor drift basic threshold, and the dynamic correction threshold of the similarity between the current state and the gene chain library to divide the final security risk level.
[0055] The present invention provides a network security level protection assessment method and system based on artificial intelligence, which has the following advantages compared with the existing technology:
[0056] (1) The present invention extracts key operations through adaptive slicing at time granularity and generates risk gene chains in combination with a reverse tracing mechanism, thereby achieving refined analysis of network security incidents, avoiding information loss and redundancy caused by fixed slicing granularity, and improving the accuracy of risk factor extraction;
[0057] (2) This invention builds an asset resistance matrix and dynamically calculates the elastic boundary radius, thereby associating the spread force with the asset defense capability, and thus accurately defining the risk impact range;
[0058] (3) The present invention introduces the gene chain library similarity comparison and environmental factor drift mechanism, so that the evaluation threshold can be dynamically adjusted according to the business scenario and historical risk pattern, improving the adaptability of the level protection evaluation to complex network environments and reducing false positives and missed reports. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 Flow chart of the steps of the present invention;
[0060] Figure 2 This is a system framework diagram of the present invention. DETAILED DESCRIPTION
[0061] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0062] like Figure 1 The present invention provides a network security level protection evaluation method based on artificial intelligence, comprising:
[0063] S1. For network security incidents, we use time-granular adaptive slicing to extract key operations, and then trace back the triggering sub-genes, propagating sub-genes, and influencing sub-genes, splicing them into risk gene chains and storing them in the gene chain library.
[0064] The duration and information density of cybersecurity incidents vary greatly. Fixed slicing granularity cannot strike a balance between detail preservation and efficiency. Short events have high information density, so fixed coarse granularity will lose temporal details. Long events have low information density, so fixed fine granularity will generate massive amounts of invalid data and increase the computational burden.
[0065] Therefore, the slice granularity G needs to be dynamically adjusted according to the event duration T. The specific formula is:
[0066]
[0067] in, is the floor rounding symbol;
[0068] When 0<T≤60, it indicates a short event and requires fixed fine granularity:
[0069] Key operations of short events are concentrated in a short period of time, such as sudden SQL injection attacks. Information density is high. In this case, fine-grained slicing can retain more details and avoid merging key operations due to overly coarse slicing.
[0070] When 60<T≤720, it indicates a medium-long event, and the granularity increases linearly with time, but the growth is slow:
[0071] The key operations of medium- and long-term events are more dispersed, such as DDoS attacks that last for several hours. The information density decreases over time. It can be seen that the granularity increases by 1 minute for every 48 minutes, which avoids excessive granularity of short events while ensuring that the slices of the key stages are fine enough;
[0072] When T>720, it indicates a long event, and the granularity increases linearly with time, but the growth rate accelerates:
[0073] Long events may be in a low-activity state for most of the time, such as the spread of a worm virus that lasts for several days. The information density is extremely low. From the above formula It can be seen that for every 24 minutes, the granularity increases by 1 minute, which can quickly increase the granularity to reduce the total amount of slices;
[0074] Because key operations in network security incidents are strictly time-sequential, it is necessary to extract the original logs of system calls, network connections, file operations, etc. within each slice through a sliding window to ensure the temporal continuity and operational integrity of the logs and avoid the fragmentation of key information due to abrupt segmentation. The specific steps are as follows:
[0075] Taking the event start time t0 as the starting point, the window size is G, the window movement step is G, and the windows cannot overlap to avoid data duplication;
[0076] Starting from t0, the time segments [t0, t0+G), [t0+G, t0+2G), ..., [t0+(n-1)G, t0+nG) are intercepted in sequence until the event end time t is covered end ,When the last window is less than G, the actual remaining time is used as the granularity;
[0077] For each window, extract the system call logs, network connection logs, and file operation logs within the time period to form the operation set of the slice;
[0078] Convert the operations in each slice into feature vectors and filter out key operations;
[0079] For text operations, the specific steps to convert to feature vectors are:
[0080] Split the command string into a word list by spaces and special symbols;
[0081] Count the unique words that appear in all slices and generate a vocabulary;
[0082] Convert each operation into a vector of vocabulary dimensions, where the vector value is the number of times the word appears;
[0083] Perform TF-IDF weighting on the bag-of-words vector to enhance feature discrimination;
[0084] According to the formula Calculate the operation weight;
[0085] For numerical operations, the specific steps to convert to feature vectors are:
[0086] Normalize the numerical features by Z-score;
[0087] Concatenate the normalized numerical features into a complete feature vector;
[0088] According to the formula Calculate the operation weight;
[0089] The dynamic threshold is calculated according to the formula ((median of global operation weight) × (1 + abnormal coefficient α));
[0090] If the operation weight ≥ dynamic threshold, it is directly marked as critical weight;
[0091] The specific steps to trace the trigger gene are:
[0092] Extract abnormal commands from key slicing operations and standardize them, including removing redundant parameters and unifying command formats;
[0093] Perform structured analysis of attack patterns in the CVE vulnerability library to extract typical attack command templates, affected asset types, and trigger conditions corresponding to each CVE vulnerability;
[0094] String similarity is calculated between the standardized abnormal commands and the typical attack command templates for CVE vulnerabilities. Using an edit distance algorithm, such as the Levenshtein distance, the minimum number of insertion, deletion, and substitution operations required to convert the abnormal command into the template command is calculated. The specific formula is: Similarity = 1 - (Edit distance / Longer string length);
[0095] Based on historical attack data, a similarity threshold is preset to screen out CVE vulnerabilities with a similarity ≥ the threshold, forming a candidate vulnerability list. The candidate list is then sorted in descending order of similarity, with high-similarity vulnerabilities being retained first.
[0096] Extract the configuration information of the current network assets, including asset type, version number, open ports, and installed patches;
[0097] Verify the compatibility of candidate vulnerabilities and assets from the following three aspects: check whether the asset type is within the range of asset types affected by the vulnerability; check whether the asset version is within the range of versions affected by the vulnerability; check whether the trigger conditions are met;
[0098] Command matching alone may result in false positives, such as matching the attack command for a vulnerability, but the target asset is not affected by the vulnerability. Combining asset configuration verification can eliminate such false positives.
[0099] The final trigger sub-gene is determined by combining the similarity and verification results of the candidate vulnerabilities: if only one meets the conditions, it is directly output; if multiple conditions are met, the vulnerability with the highest similarity and passed verification is selected;
[0100] The specific steps to trace back the propagator gene are:
[0101] Extract network connection records from event slices and construct a network traffic graph, where nodes are assets, edges are connection relationships, and edge weights are transmission frequencies.
[0102] Use the K-means algorithm to cluster paths in the network traffic graph and identify high-frequency transmission paths. For example, if a certain IP frequently sends requests to multiple database servers, the transmission carrier can be determined by combining protocol analysis.
[0103] For example, the traffic graph shows that the attack originated from the web server (IP: 192.168.1.10) connecting to the database server (IP: 192.168.1.20) via port 3306 (MySQL). The number of transmitted bytes surged during the attack period. Cluster analysis marked this path as a high-frequency transmission path. Combined with protocol analysis, it was determined that the transmission vector was exploiting web vulnerabilities to obtain database permissions.
[0104] The specific steps to trace the influencing factor genes are:
[0105] Establish an asset evaluation matrix, starting from the two dimensions of business coreness and data sensitivity. Business coreness is divided into core, important, and marginal, with weights of 5, 3, and 1 respectively; sensitivity is divided into high, medium, and low, with weights of 5, 3, and 1 respectively;
[0106] Based on the matrix, the asset value coefficient K is assigned, which is the business coreness weight + sensitivity weight, and belongs to the range [2,10];
[0107] According to the formula
[0108] Calculate the service interruption loss L2 using the formula L2 = interruption duration × hourly business revenue × K;
[0109] The repair cost L3 is calculated using the formula L3 = emergency response labor cost + system repair cost;
[0110] Calculate the total business loss value L = L1 + L2 + L3;
[0111] The time decay function is used to adjust the loss value of the service over time. The specific formula is L(t) = L×e -λt , where t is the time after the attack occurs and λ is the attenuation coefficient;
[0112] Exponential decay is consistent with the impact of cybersecurity incidents, with core assets decaying slowly and marginal assets decaying quickly, which is more in line with actual risk evolution.
[0113] Output the impact sub-gene, which can be structurally described as "loss type + initial loss point + current loss point after attenuation + impact duration";
[0114] Use the Needleman-Wunsch algorithm to align the sequences of trigger genes, propagation genes, and impact genes to construct a complete risk gene chain, such as CVE-2024-1234 (trigger gene) → Web vulnerability exploitation (propagation gene) → database record tampering of 1.6 million yuan (impact gene);
[0115] The newly generated gene chain needs to calculate the cosine similarity Sim with the existing chains in the library. If Sim is less than 80%, a new record is added. If Sim is greater than or equal to 80%, the occurrence frequency of the corresponding chain is updated.
[0116] S2. Construct an asset resistance matrix, calculate the transmission force score based on the propagator genes of the risk gene chain, define the risk impact range through the elastic boundary radius, and dynamically adjust the boundary;
[0117] The protection bases of different assets naturally vary, and are generally related to the strength of protection measures (A), vulnerability repair rate (B), and the number of historical attacks (C). Asset resistance can be calculated using the formula R = A × 0.4 + B × 0.3 + C × 0.3.
[0118] Protection score A can be scored from four aspects: firewall rules, intrusion detection, data encryption measures, and access control mechanisms, each accounting for 25 points;
[0119] For firewall rules, 5 points will be deducted for each key port omitted, and 3 points will be deducted for each 5% of redundant rules exceeding the limit.
[0120] For intrusion detection, 4 points will be deducted for every 10% decrease in core asset coverage, and 2 points will be deducted for every 1% increase in false alarm rate;
[0121] Data encryption measures: 15 points will be deducted for transmission or storage without encryption;
[0122] For access control mechanisms, 10 points will be deducted for not enabling multi-factor authentication, and 5 points will be deducted for each unauthorized account found;
[0123] Bug fix score B, based on Obtain B;
[0124] The anti-attack score C is obtained by obtaining the number of successful interception attacks su and the maximum number of successful interception Sumax in the past 6 months. Calculate C;
[0125] After calculating the resistance R of each asset, map the resistance values of all assets into a two-dimensional matrix by IP address or host name, and mark the physical location of the assets;
[0126] The specific steps for calculating the transmission ability score based on the propagator gene of the risk gene chain are as follows:
[0127] Extracting transmission vector efficiency, frequency factor, and range factor from the transmission gene;
[0128] The transmission carriers are divided into three categories according to concealment, diffusion speed and coverage, corresponding to the basic points:
[0129] For high-quality carriers, the score is set to 70, such as email attachments, phishing links, and supply chain implants, which are highly concealed and can spread across networks;
[0130] For medium-quality carriers, the score is set to 50, such as port scanning and weak password brute force, which usually rely on network connections and have a medium spread speed;
[0131] For low-quality carriers, the score is set to 30, such as USB ferry and physical access, which usually rely on physical contact and have a limited diffusion range;
[0132] The carrier type can be directly matched through the network logs in the propagator gene, such as mail server records and port connection records, without the need for subjective adjustment;
[0133] Frequency factor = number of transmissions per unit time / industry benchmark transmissions. The result is rounded to one decimal place and the value range is [0.3, 1.5]. If it exceeds the range, the boundary value is directly taken;
[0134] The frequency of transmission directly reflects the speed of diffusion. Under the same carrier, an attack that spreads 100 times in an hour is much more threatening than an attack that spreads once in an hour. The factor coefficient can quantify this speed difference.
[0135] Range factor = (number of affected asset types / 3) + 0.5. Asset types include servers, terminals, network devices, and IoT devices, with a maximum of four types. The range is [0.5, 1.8]. Values outside the range are taken as the boundary value.
[0136] The wider the coverage of asset types, the greater the destructive radiation range of the spread. For example, attacking servers and network devices simultaneously may paralyze the entire network segment. The factor coefficient can quantify this breadth difference.
[0137] The transmission force score F is obtained according to the formula F = (transmission carrier basic score × impact factor × range factor). If there is a transmission interception record in the transmission sub-gene, F needs to be multiplied by 0.7, where F∈[0,100]. If it exceeds the interval, the interval boundary value is taken;
[0138] The multiplication relationship reflects the synergistic effect of carrier capability, speed, and breadth. A high-quality carrier combined with a high frequency and wide-coverage attack exponentially increases its propagation power, which conforms to the actual law of attack diffusion. However, being blocked by defensive measures during the propagation process directly reduces its actual propagation power. Multiplying by 0.7 can avoid overestimating attacks that have been partially blocked.
[0139] The specific operations for defining the risk impact range through elastic boundary radius are as follows:
[0140] Calculate the average resistance of assets
[0141] According to the formula Calculate the elastic boundary radius S, where [] represents the rounding symbol, S∈[0,5]. If S exceeds the value interval, the interval boundary value is taken. For example, S=2 represents the central asset + directly adjacent assets + adjacent assets of adjacent assets;
[0142] The assets within a radius S, centered on the asset where the triggering sub-gene is located, are considered to be highly likely to be affected.
[0143] S directly reflects the antagonistic relationship between the spread power and the asset defense capability: the stronger the spread power, the weaker the asset resistance, and the larger the boundary range, which is in line with the actual law of risk diffusion;
[0144] It is necessary to monitor the changes in asset resistance R and transmission force F in real time in order to update S in a timely manner;
[0145] For example, a corporate network has 10 assets with an average resistance of The spreading force F = 45, the initial boundary radius S = [45 / 40] = 1, and the frame range is the central asset + directly adjacent assets. After 1 hour, the vulnerability is repaired in 5 core assets. When it rises to 95 points, the new boundary radius S = [45 / 95] = 0, and the scope is narrowed to only the central assets.
[0146] S3. Preset the basic threshold of security level, combine it with the basic threshold of network environment factor drift, and dynamically modify the threshold of similarity Sim between the current state and the gene chain library to divide the security risk level;
[0147] The severity of a risk is determined by two core dimensions: the impact area S and the spread F. S quantifies the boundaries of the risk and directly determines the scale of the consequences that may be caused if the risk spreads.
[0148] For example, when S = 1, the impact is localized and small-scale, and even if the transmission force F is high, the overall risk is limited; when S = 5, the impact is global, and even if the transmission force F is medium, the overall risk may be high;
[0149] Therefore, S is used as the independent variable to construct the preset safety level basic thresholds Fmin and Fmax. The specific formula is F min =50-5S-S 2 , F max =90-10S;
[0150] The quadratic term in Fmin causes Fmin to decrease rapidly as S increases, reflecting that the low-risk threshold decreases rapidly as the scope expands;
[0151] Fmax adopts a linear decreasing formula, and the absolute value of the slope is less than the nonlinear decreasing speed of Fmin to ensure that Fmax is always higher than Fmin;
[0152] If F < Fmin, it is judged as low risk; if Fmin ≤ F ≤ Fmax, it is judged as medium risk; if F > Fmax, it is judged as high risk;
[0153] The core role of environmental factors is to adapt risk assessment criteria to the real-time state of business scenarios, avoiding mechanical thresholds that are divorced from business realities.
[0154] During peak business hours, core systems must prioritize operation. If the basic thresholds are too strict, frequent alarms may cause business interruptions. Relaxing the thresholds based on environmental factors can reduce redundant responses and balance security and business needs.
[0155] During non-working hours, when business activities are suspended, abnormal system behavior is more likely to indicate an attack. At this time, the threshold should be tightened to ensure that even minor threats trigger attention and avoid missing attacks due to excessively wide thresholds. For example, a slow scanning attack in the early morning may be harmless during the day, but it may be a precursor to an intrusion at night.
[0156] The basic thresholds Fmin and Fmax are set only based on the impact range S, without considering the time sensitivity and importance of the business. Therefore, they need to be drifted using environmental factors.
[0157] Define the business activity index q to indirectly indicate the time sensitivity and importance of the business. Here, select three core indicators: system load, transaction frequency, and number of online users, and standardize them separately:
[0158] System load, i.e. CPU usage, is normalized to a score of 0-30;
[0159] Transaction frequency, i.e. the number of business transactions per hour, normalized to 0-35 minutes;
[0160] The number of online users, i.e. the number of real-time online users, is normalized to a score of 0-35;
[0161] Calculate the business activity index q = system load score + transaction frequency score + user online score;
[0162] According to the formula Calculate the network environment factor, where the scaling factor in fractional form is used Control the rate of change of the e-base function, using 0.3 as the scaling factor to keep the function value range within (-0.3, 0.3);
[0163] The change in business activity is continuous, and the e-base function can accurately capture this nonlinear relationship:
[0164] When q is far from 50, that is, during non-peak or non-idle periods, the function value changes smoothly, avoiding large fluctuations in the factor due to short-term business fluctuations.
[0165] When q approaches 50, that is, during the regular period, the function value is more sensitive to changes in q, reflecting the need to quickly adjust the threshold during business state switching;
[0166] Calculate the post-drift threshold = basic threshold × (1 + p(q));
[0167] For example, at 14:00 on a working day, the business activity index of a certain bank system is q=70, and the calculated environmental factor p(70)=0.14. At this time, S=3, F=28, and the calculated basic thresholds Fmin=26, Fmax=60. The thresholds after the environmental factor drift are Fmin=29.6, Fmax=68.4. If the risk level is divided according to the original threshold, it is classified as medium risk. After the environmental factor drifts the basic threshold, the risk level is classified as low risk.
[0168] The drifted thresholds are further dynamically corrected based on the similarity Sim obtained by S1 and the gene chain library, and the final thresholds after correction are Fmin' and Fmax'. The specific correction rules are as follows:
[0169] If Sim>0.8, then the post-drift threshold is ×0.8;
[0170] If 0.5≤Sim≤0.8, the threshold remains unchanged after drift;
[0171] If Sim < 0.5, the post-drift threshold is × 1.1;
[0172] The higher the similarity, the more the current state conforms to the known normal rules and the more predictable the system behavior is. In this case, tightening the threshold can more sensitively capture minor anomalies to avoid missing reports.
[0173] The lower the similarity, the more likely a new pattern exists in the current state. Relaxing the threshold can reduce misjudgment of the rationality state and avoid false positives.
[0174] The specific rules for classifying security risk levels are as follows:
[0175] If F<Fmin', it is judged as low risk and can be recorded through logs; if Fmin'≤F≤Fmax', it is judged as medium risk, and an alarm needs to be triggered and relevant operators need to be notified; if F>Fmax', it is judged as high risk, and isolation, blocking and other disposal measures will be automatically triggered.
[0176] like Figure 2 , an artificial intelligence-based network security level protection evaluation system, including:
[0177] The gene chain extraction module uses time-granular adaptive slicing to extract key operations for network security incidents, and then reversely traces the triggering sub-genes, propagating sub-genes, and influencing sub-genes, splicing them into risk gene chains and storing them in the gene chain library.
[0178] The boundary framing module constructs an asset resistance matrix, calculates the transmission power score based on the propagator genes of the risk gene chain, frames the risk impact range through the elastic boundary radius, and dynamically adjusts the boundary;
[0179] The level classification module is based on the preset security level basic threshold, combined with the network environment factor drift basic threshold, and the dynamic correction threshold of the similarity between the current state and the gene chain library to divide the final security risk level.
[0180] Some of the data in the above formulas are dimensionless and numerically calculated. Meanwhile, the contents not described in detail in this specification belong to the prior art known to those skilled in the art.
[0181] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A network security level protection evaluation method based on artificial intelligence, characterized in that: include: S1. For network security incidents, we use time-granular adaptive slicing to extract key operations, and then trace back the triggering sub-genes, propagating sub-genes, and influencing sub-genes, splicing them into risk gene chains and storing them in the gene chain library. S2. Construct an asset resistance matrix, calculate the transmission force score based on the propagator genes of the risk gene chain, define the risk impact range through the elastic boundary radius, and dynamically adjust the boundary; S3. Based on the preset basic threshold of security level, combined with the basic threshold of network environment factor drift, and combined with the dynamic correction threshold of the similarity between the current state and the gene chain library, the final security risk level is divided.
2. The method for evaluating network security level protection based on artificial intelligence according to claim 1, characterized in that: The slice granularity G is dynamically adjusted according to the event duration T. The specific formula is: in, is the floor symbol.
3. The network security level protection evaluation method based on artificial intelligence according to claim 1 is characterized in that: The specific steps to trace the trigger gene are: Extract abnormal commands in key slicing operations and perform standardization processing; Perform structured analysis of attack patterns in the CVE vulnerability library to extract typical attack command templates, affected asset types, and trigger conditions corresponding to each CVE vulnerability; Calculate the string similarity between the standardized abnormal command and the typical attack command template of the CVE vulnerability, where the similarity = 1-(edit distance / longer string length); Based on historical attack data, a similarity threshold is preset to screen out CVE vulnerabilities with a similarity ≥ the threshold, forming a candidate vulnerability list. The candidate list is then sorted in descending order of similarity, with high-similarity vulnerabilities being retained first. Extract the configuration information of the current network assets and verify the matching between the candidate vulnerabilities and the assets; The final trigger sub-gene is determined by combining the similarity and verification results of the candidate vulnerabilities: if only one meets the conditions, it is directly output; if multiple meet the conditions, the vulnerability with the highest similarity and passed verification is selected.
4. The method for evaluating network security level protection based on artificial intelligence according to claim 1, characterized in that: The specific steps to trace back the propagator gene are: Extract network connection records from event slices and construct a network traffic graph, where nodes are assets, edges are connection relationships, and edge weights are transmission frequencies. The K-means algorithm is used to cluster the paths in the network traffic graph to identify high-frequency propagation paths, and the propagation carrier is determined in combination with protocol analysis.
5. The method for evaluating network security level protection based on artificial intelligence according to claim 1, characterized in that: The specific steps to trace the influencing factor genes are: Establish an asset evaluation matrix based on business coreness and data sensitivity. Business coreness is divided into core, important, and marginal, with weights of 5, 3, and 1 respectively; sensitivity is divided into high, medium, and low, with weights of 5, 3, and 1 respectively; Calculate the asset value coefficient K based on the asset evaluation matrix, where K = business coreness weight + sensitivity weight; According to the formula Calculate the data loss L1; Calculate the service interruption loss L2 using the formula L2 = interruption duration × hourly business revenue × K; The repair cost L3 is calculated using the formula L3 = emergency response labor cost + system repair cost; Calculate the total business loss value L = L1 + L2 + L3; According to the formula L(t) = L×e -λt Adjust the loss value of the business over time, where t is the time after the attack occurs and λ is the attenuation coefficient; Output the affected sub-gene and the loss value L after attenuation.
6. The method for evaluating network security level protection based on artificial intelligence according to claim 1, characterized in that: The specific steps for calculating the communication power score are as follows: Extract the transmission vector, frequency factor, and range factor from the propagator gene; The transmission carriers are divided into high-quality carriers, medium-quality carriers, and low-quality carriers, with corresponding basic scores of 70, 50, and 30 respectively. The carrier type can be directly matched through the network log in the transmission sub-gene; The frequency factor = the number of transmissions per unit time / the industry benchmark number of transmissions, with a value range of [0.3, 1.5]. If it exceeds the range, the value of the interval boundary is taken; The range factor = (number of affected asset types / 3) + 0.5, with a value range of [0.5, 1.8]. If the value exceeds the range, the value at the boundary of the range is used; The transmission score F is obtained according to the formula F = (transmission carrier basic score × impact factor × range factor). If there are intercepted records in the communicator gene, F×0.7 needs to be calculated, where F∈[0,100]. If it exceeds the interval, the interval boundary value is taken.
7. The method for evaluating network security level protection based on artificial intelligence according to claim 1, characterized in that: Calculate the average resistance of assets = the sum of all asset resistance / total assets, and according to the formula Calculate the elastic boundary radius S, where [] represents the rounding symbol, S∈[0,5]. If S exceeds the value interval, the interval boundary value is taken.
8. The method for evaluating network security level protection based on artificial intelligence according to claim 1, characterized in that: Using S as the independent variable to construct the preset safety level basic thresholds Fmin and Fmax, the specific formula is F min =50-5S-S 2 , F max =90-10S.
9. The method for evaluating network security level protection based on artificial intelligence according to claim 1, characterized in that: The specific steps to obtain the final threshold are: According to the formula Calculate the network environment factor p(q), where q is the business activity index; The drift threshold is obtained as follows: basic threshold × (1 + p(q)); Calculate the similarity Sim with the gene chain library, and further dynamically correct the drifted threshold according to Sim to obtain the final thresholds Fmin' and Fmax'. The specific correction rules are as follows: If Sim>0.8, then the post-drift threshold is ×0.8; If 0.5≤Sim≤0.8, the threshold remains unchanged after drift; If Sim < 0.5, the post-drift threshold is × 1.1; Security risk levels are divided by final threshold: If F<Fmin', it is judged as low risk; if Fmin'≤F≤Fmax', it is judged as medium risk; if F>Fmax', it is judged as high risk.
10. An artificial intelligence-based network security level protection evaluation system, used to execute the artificial intelligence-based network security level protection evaluation method according to any one of claims 1 to 9, characterized in that: include: The gene chain extraction module uses time-granular adaptive slicing to extract key operations for network security incidents, and then reversely traces the triggering sub-genes, propagating sub-genes, and influencing sub-genes, splicing them into risk gene chains and storing them in the gene chain library. The boundary framing module constructs an asset resistance matrix, calculates the transmission power score based on the propagator genes of the risk gene chain, frames the risk impact range through the elastic boundary radius, and dynamically adjusts the boundary; The level classification module is based on the preset security level basic threshold, combined with the network environment factor drift basic threshold, and the dynamic correction threshold of the similarity between the current state and the gene chain library to divide the final security risk level.
Citation Information
Patent Citations
Network attack risk mapping assessment method and system
CN119583198A
Internet of Things equipment hidden danger risk analysis method and system based on artificial intelligence
CN120034394A
Supply chain financial risk management system based on credit assessment
CN120147017A
Digital currency market fluctuation prediction method based on AI
CN120278755A
Network intrusion detection and defense system based on artificial intelligence
CN120320997A