Situation awareness and linkage disposal system based on dynamic threat modeling driving

By combining dynamic threat modeling with Monte Carlo tree search networks, utilizing threat intelligence agents and Seagull algorithm optimization, we construct multi-dimensional security data collection and standardized processing, and generate optimal linkage disposal decisions. This addresses the shortcomings of existing systems in dynamic threat modeling, intelligent decision-making, and equipment scheduling, and achieves efficient and secure network security protection.

CN120658467AInactive Publication Date: 2025-09-16SHANGHAI VIDE INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510825360.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-09-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing situational awareness and linkage disposal systems have shortcomings in dynamic threat modeling, intelligent decision-making, equipment scheduling and disposal effect evaluation. They are unable to cope with the complex and changing network security protection needs and lack global adaptability and efficient linkage capabilities.

Method used

By combining dynamic threat modeling with Monte Carlo tree search networks, and through threat agent modeling and Seagull algorithm optimization, we build multi-dimensional security data collection and standardized processing, generate optimal linkage disposal decisions, realize automated equipment scheduling and closed-loop feedback mechanisms, and support interactive situation visualization and intelligent decision-making assistance.

Benefits of technology

It has achieved accurate modeling and evolution prediction of complex threats, improved the early warning and response capabilities of unknown attacks and complex attack chains, improved security protection efficiency and system adaptability, and met the needs of efficient, secure, and intelligent linkage disposal in complex and changeable network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658467A_ABST
    Figure CN120658467A_ABST
Patent Text Reader

Abstract

The invention discloses a situation awareness and linkage disposal system based on dynamic threat modeling driving, and the system comprises a security data collection and standardization module which is used for collecting security data of a network, a host and an application layer, and carrying out the standardization processing; the dynamic threat modeling module is used for constructing a dynamic threat model; the threat agent modeling and simulation module is used for modeling each node in the threat attack graph into a threat agent; the parameter optimization module is used for globally optimizing parameters and strategy weights of the Monte Carlo tree search network by using a seagull algorithm; the linkage processing decision module is used for configuring a Monte Carlo tree search network based on the optimal parameter group; the safety equipment scheduling module is used for analyzing the optimal linkage disposal decision scheme; and the disposal effect evaluation and feedback module is used for performing multi-dimensional analysis on the disposal feedback data set. According to the invention, accurate situation awareness and linkage processing are provided for the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security linkage disposal technology, and in particular to a situation awareness and linkage disposal system driven by dynamic threat modeling. Background Art

[0002] With the continuous advancement of informatization and digitalization, the cyberspace security situation is becoming increasingly complex, and the means of network attacks are constantly evolving. Traditional static protection and single-point response measures have become difficult to cope with the endless stream of new threats. In the existing network security protection system, it usually relies on the collaborative work of multiple security devices, such as firewalls, intrusion detection systems, host protection systems, and security information and event management platforms. Through the collection and analysis of network traffic, host logs, system alarms, and security events, threat detection and response are achieved. However, most existing technologies focus on data analysis and response of a single device, lacking the ability to dynamically model the global threat situation and intelligently drive linkage disposal. As a result, it is difficult to achieve efficient and accurate protection when facing multi-stage, complex attack chains and advanced persistent threats.

[0003] Currently, mainstream situational awareness and response systems often use rule matching, feature detection, or simple correlation analysis methods to perform preliminary filtering and classification of security incidents. These methods have some detection capabilities for known threats and conventional attacks, but they are significantly lacking in response speed and accuracy when faced with multi-stage attacks launched by attackers who bypass traditional detection methods and exploit unknown vulnerabilities. Furthermore, the incident handling process often relies on manual analysis and intervention, lacking automated, intelligent linkage mechanisms. The linkage between different security devices often relies on preset strategies, making it impossible to dynamically adjust response plans based on the ever-changing threat environment and asset status. This significantly limits the adaptive capabilities and response efficiency of the protection system.

[0004] Existing technologies often use static attack graphs or threat models to model the associations between security elements such as network-wide assets, vulnerabilities, attack paths, and attackers. In practical applications, these models struggle to timely reflect dynamic changes in the network environment and threat landscape, lacking the ability to simulate and predict threat evolution, resulting in limited awareness of unknown threats and new attack chains. Furthermore, traditional attack graph analysis methods are computationally complex when faced with large-scale assets and complex attack scenarios, making real-time reasoning and response difficult. Some research has attempted to improve threat perception by introducing machine learning or deep learning methods, but these methods often focus on a single link and lack a comprehensive approach to optimizing the entire threat evolution process and coordinated response strategies.

[0005] In terms of response and disposal, existing technologies mostly use decision-making mechanisms based on experience or fixed rules, lacking sufficient data-driven and intelligent reasoning capabilities. When faced with multiple alternative disposal paths and resource constraints, it is difficult to make globally optimal linkage decisions based on the actual threat situation, asset importance, and resource availability. Even if some systems have implemented simple multi-path selection and equipment scheduling, they often ignore the dynamic evaluation and feedback of disposal effects, making it difficult for the system to self-optimize and upgrade based on historical disposal effects and the latest threat situation. In addition, in the current equipment scheduling and linkage execution process, the integration and utilization of equipment status information and feedback data is limited, and there is a lack of tracking and analysis of the entire disposal execution process, making it difficult to promptly discover and correct deficiencies and failures in the disposal process.

[0006] In terms of threat modeling and decision-making reasoning, some existing technologies attempt to use intelligent optimization methods such as Monte Carlo tree search and genetic algorithms to deduce and optimize attack paths and response plans. However, because network parameters and policy weights are difficult to dynamically adjust based on the actual environment, the optimization process is prone to falling into local optimality. Furthermore, the parameter adjustment process often relies on manual settings or static configurations, lacking global adaptability and efficient global search capabilities. Furthermore, existing optimization methods struggle to balance multi-dimensional indicators such as security, timeliness, and resource utilization in complex multi-objective decision-making scenarios, resulting in the final coordinated response plan failing to meet actual business and security needs.

[0007] In terms of treatment effect evaluation and system adaptation, existing technologies generally lack multi-dimensional data collection, evaluation, and feedback mechanisms for the entire treatment task execution process. Most systems only perform simple statistics and analysis after the fact, and are unable to promptly feedback the treatment effects to the threat model and decision-making network, limiting the model's ability to self-correct and continuously optimize. The system's adaptive and evolutionary capabilities are weak, making it difficult to cope with the ever-changing threat environment and attack techniques. For anomalies, failures, or unexpected effects that occur during the treatment process, existing systems often rely on manual intervention and lack automated anomaly detection, resource reallocation, and policy adjustment mechanisms, affecting the closed-loop management and continuous improvement of overall protection.

[0008] In summary, existing situational awareness and coordinated response technologies have significant shortcomings in dynamic threat modeling, intelligent response decision-making, automated equipment scheduling, response effect evaluation and feedback, and adaptive system optimization, making them unable to support the complex and ever-changing needs of cybersecurity protection. An innovative system that can implement full-process dynamic modeling, intelligent reasoning, automatic coordination, closed-loop feedback, and continuous optimization is urgently needed to enhance the overall capabilities and level of cyberspace security protection.

[0009] Therefore, how to provide a situational awareness and linkage disposal system driven by dynamic threat modeling is an urgent problem that needs to be solved by those skilled in the art. Summary of the Invention

[0010] One purpose of the present invention is to propose a situational awareness and linkage disposal system driven by dynamic threat modeling. The present invention automatically constructs a threat attack graph covering assets, vulnerabilities, attackers and their relationships by combining dynamic threat modeling with a Monte Carlo tree search network, and models and simulates the attack chain in a threat agent manner. The Seagull algorithm is introduced to globally optimize the parameters and policy weights of the Monte Carlo tree search network to achieve efficient reasoning and optimization of candidate disposal paths. The present invention also integrates the automatic collection and standardized processing of multi-dimensional security data, and can dynamically perceive the security situation of the network, host and application layers. The system has the ability to make linkage disposal decisions, can automatically analyze and generate the optimal linkage disposal plan, and dispatch security protection equipment to efficiently respond to threat events. Through a closed-loop disposal effect evaluation and model feedback mechanism, threat modeling and disposal strategies are continuously optimized. The present invention supports interactive situation visualization and intelligent decision-making assistance, providing users with real-time and accurate network security risk warnings and protection strategies, significantly improving security protection efficiency and response capabilities in complex environments.

[0011] A situation awareness and coordinated response system based on dynamic threat modeling according to an embodiment of the present invention includes:

[0012] The security data collection and standardization module is used to collect security data from the network, host and application layers, and perform standardization processing to generate standardized security data;

[0013] Dynamic threat modeling module, used to build dynamic threat models based on standardized security data;

[0014] The threat agent modeling and simulation module is used to model each node in the threat attack graph as a threat agent with state observation and policy decision-making capabilities;

[0015] Parameter optimization module, used to globally optimize the parameters and strategy weights of the Monte Carlo tree search network using the Seagull algorithm;

[0016] The linkage disposal decision module is used to configure the Monte Carlo tree search network based on the optimal parameter group to reason and evaluate the candidate disposal path set;

[0017] The safety equipment scheduling module is used to analyze the optimal linkage disposal decision plan and generate the equipment scheduling instruction set;

[0018] The disposal effect evaluation and feedback module is used to perform multi-dimensional analysis on the disposal feedback data set.

[0019] Optionally, modules can be connected using the following methods:

[0020] S1. Collect security data from the network, host, and application layers, perform standardization processing, and generate standardized security data;

[0021] S2. Build a dynamic threat model based on standardized security data to generate a threat attack graph that includes assets, vulnerabilities, attackers, and their relationships.

[0022] S3. Construct a Monte Carlo tree search network, modeling each node in the threat attack graph as a threat agent with state observation and policy decision-making capabilities. Based on the agent's observed state and environmental information, use the Monte Carlo tree search algorithm to simulate threat evolution paths and various response and disposal solutions to generate a set of candidate disposal paths.

[0023] S4. Use the Seagull algorithm to globally optimize the parameters and strategy weights of the Monte Carlo tree search network to obtain the optimal parameter set;

[0024] S5. Use the optimal parameter group to configure the Monte Carlo tree search network, reason and evaluate the candidate disposal path set, and output the optimal linkage disposal decision plan;

[0025] S6. Dispatch safety protection equipment and implement the optimal coordinated disposal decision plan;

[0026] S7. Evaluate the execution effect of the optimal linkage disposal decision plan and feed back the evaluation results to the dynamic threat model and Monte Carlo tree search network.

[0027] Optionally, the parameters of the Monte Carlo tree search network include node selection strategy parameters, number of simulations, exploration and utilization balance coefficient, pruning threshold, reward function coefficient, maximum search depth, agent state feature weight, and path evaluation criteria.

[0028] Optionally, the security data includes network traffic data, host logs, system alarms, user behavior records, device configuration, vulnerability information, attack event records, application access logs and status information of security protection devices.

[0029] Optionally, S2 includes the following specific steps:

[0030] S21. Decompose the standardized security data to extract information related to assets, vulnerabilities, attack behaviors, and attackers, and generate asset information sets, vulnerability information sets, attack behavior information sets, and attacker information sets;

[0031] S22. Classify the asset information set, identify the asset type, importance level, and topological location in the network, and generate an asset topology table;

[0032] S23. Associate the vulnerability information set with the asset topology table, identify the vulnerability type and risk level corresponding to each asset, and generate an asset vulnerability mapping table;

[0033] S24. Analyze the attack behavior information set, identify the attack path, attack means, and attack phase, map the attack behavior to potential target assets and related vulnerabilities, and generate an attack path table;

[0034] S25. Match the attacker information set with the attack path table, determine the association between the attacker and the identified attack path, and generate an attacker path mapping table;

[0035] S26. Integrate the asset topology table, asset vulnerability mapping table, attack path table, and attacker path mapping table to create a threat attack graph that includes assets, vulnerabilities, attackers, and associated relationships, and output the threat attack graph.

[0036] Optionally, S3 includes the following specific steps:

[0037] S31. Convert each node in the threat attack graph into a threat agent with state observation and policy decision-making capabilities to generate a threat agent set;

[0038] S32. Set an observation state space and a set of optional strategies for each threat agent, and establish a state information table and a strategy information table for the threat agent;

[0039] S33. Initialize a Monte Carlo tree search structure based on the threat agent's state information table and policy information table, define a root node and an expandable child node set, and generate an initial search tree structure;

[0040] S34, using the state observations and environmental information of the threat agent set as input, performing multiple rounds of simulations using a Monte Carlo tree search algorithm to simulate the evolution paths of various threats and corresponding response and disposal strategies, and generating a threat evolution simulation result set;

[0041] S35. Screen and evaluate each path in the threat evolution simulation result set, and generate a set of candidate disposal paths based on preset strategy pros and cons criteria.

[0042] Optionally, S4 includes the following specific steps:

[0043] S41, taking the candidate treatment path set, the initial parameters of the Monte Carlo tree search network and the strategy weight as input, initializing the Seagull algorithm population, and generating a parameter Seagull individual set;

[0044] S42, initializing the positions of the parameter seagull individual set, setting the feature vector of each parameter seagull individual according to the candidate disposal path set, and generating a parameter feature table;

[0045] S43, calculating the fitness of each parameter seagull individual in the Monte Carlo tree search network, and generating a fitness information table based on the candidate treatment path set;

[0046] S44. According to the migration and attack rules of the seagull algorithm, the position of the parameter seagull individual set is updated, the parameter feature table is adjusted, and an updated parameter seagull individual set is generated;

[0047] S45. Perform fitness evaluation on the updated parameter seagull individual set, select the parameter individual with the best fitness, and generate the optimal parameter group.

[0048] Optionally, S5 includes the following specific steps:

[0049] S51, applying the optimal parameter group to the Monte Carlo tree search network, and dynamically fine-tuning the network parameters in combination with the current real-time network security situation information to generate a self-adaptive Monte Carlo tree search network;

[0050] S52, inputting the candidate disposal path set into the adaptively configured Monte Carlo tree search network, combining the historical execution performance of each path and environmental context information, using a multi-dimensional weight dynamic adjustment algorithm to weight the candidate disposal path set and generate a weighted path state table;

[0051] S53, based on the weighted path state table and the self-adaptively configured Monte Carlo tree search network, a multi-round game reasoning mechanism is used to simulate and deduce each candidate disposal path to generate a multi-scenario reasoning result set;

[0052] S54. For the multi-scenario reasoning result set, perform a forward-looking evaluation on the performance of the path under different threat evolution scenarios and generate a forward-looking path evaluation information table;

[0053] S55. Based on the forward-looking path evaluation information table, a multi-objective optimization selection algorithm is used to screen out the path that performs best in terms of safety, timeliness and resource utilization indicators, and generate and output the optimal linkage disposal decision plan.

[0054] Optionally, S6 includes the following specific steps:

[0055] S61. Analyze the specific disposal tasks and corresponding safety protection equipment requirements in the optimal linkage disposal decision plan, and generate an equipment scheduling instruction set;

[0056] S62: Send the device dispatch instruction set to the corresponding safety protection device, start the device to execute the corresponding disposal task, and record the response status information of the device;

[0057] S63. Collect status information and feedback results of each safety protection device during the execution of the disposal task to form a disposal feedback data set;

[0058] S64. Summarize and analyze the execution results based on the disposal feedback data set and generate a disposal result report.

[0059] Optionally, S7 includes the following specific steps:

[0060] S71. Extract key execution data and related performance indicators from the disposal result report to generate an execution effect data set;

[0061] S72. Perform a multi-dimensional analysis of the execution effect data set to evaluate the performance of the disposal task in terms of safety, timeliness, and resource utilization, and generate a comprehensive evaluation result table;

[0062] S73. Compare the comprehensive evaluation results table with the original optimal linkage disposal decision plan, identify effective measures and deficiencies in the disposal process, and form a set of improvement suggestions;

[0063] S74. Feedback the improvement suggestion set to the dynamic threat model, dynamically modify the dynamic threat model parameters and threat characteristics, and generate an updated dynamic threat model;

[0064] S75, synchronizing the comprehensive evaluation result table to the Monte Carlo tree search network, adjusting the parameters and strategy weights of the Monte Carlo tree search network, and generating an optimized Monte Carlo tree search network;

[0065] S76. Combine the updated dynamic threat model with the optimized Monte Carlo tree search network to improve adaptive capabilities.

[0066] The beneficial effects of the present invention are:

[0067] This invention addresses the shortcomings of existing situational awareness and coordinated response systems in dynamic threat modeling, intelligent decision-making and reasoning, automated equipment scheduling, response effect evaluation, and system adaptive optimization. It proposes a situational awareness and coordinated response system and method driven by dynamic threat modeling. This system implements multi-dimensional security data collection and standardized processing, dynamic threat attack graph construction, intelligent agent modeling and Monte Carlo tree search reasoning, global parameter optimization, optimal coordinated response decision generation, automatic equipment scheduling, and multi-dimensional response effect evaluation and feedback. Through the organic collaboration between the system's modules, it can dynamically perceive network security situations throughout the entire process, accurately model complex threats, and predict their evolution, effectively improving the early warning and response capabilities to unknown attacks and complex attack chains.

[0068] This invention utilizes a fusion optimization mechanism combining Monte Carlo tree search and the Seagull algorithm in its decision-making process. This not only efficiently simulates and deduces multiple threat evolution paths, but also dynamically adjusts search parameters and policy weights based on the actual environment, achieving global optimal path selection under multiple objectives. Through intelligent evaluation and multi-scenario reasoning of candidate response paths, the system balances multiple metrics, including safety, timeliness, and resource utilization, automatically generating an optimal coordinated response plan and enabling precise scheduling and coordinated control of safety protection equipment, significantly improving response efficiency and the overall collaborative operational capabilities of the protection system.

[0069] In addition, the present invention can conduct a multi-dimensional, full-process comprehensive evaluation of the execution effect of the disposal task through real-time monitoring and data collection of the entire linkage disposal process. The system will promptly feed back the disposal evaluation results to the dynamic threat model and decision-making network, realize the continuous optimization and adaptive adjustment of model parameters and policy weights, and form a closed-loop self-evolution mechanism driven by data. As a result, the system can continuously improve the protection capability and decision-making level according to changes in the network environment and threat situation, significantly enhance the continuous adaptability and intelligence level of network security protection, and meet the needs of efficient, safe, and intelligent linkage disposal in complex and changing network environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0071] Figure 1 This is a flow chart of a method for a situational awareness and linkage disposal system based on dynamic threat modeling driven by the present invention;

[0072] Figure 2 This is a system flow chart of a situational awareness and linkage disposal system based on dynamic threat modeling and driven by the present invention;

[0073] Figure 3 This is a data flow diagram of the situational awareness and linkage disposal system driven by dynamic threat modeling proposed by the present invention. DETAILED DESCRIPTION

[0074] The present invention will now be described in further detail with reference to the accompanying drawings, which are simplified schematic diagrams that illustrate the basic structure of the present invention in a schematic manner.

[0075] refer to Figure 1-3 , a situational awareness and linkage disposal system driven by dynamic threat modeling, including:

[0076] The security data collection and standardization module is used to collect security data from the network, host and application layers, and perform standardization processing to generate standardized security data;

[0077] Dynamic threat modeling module, used to build dynamic threat models based on standardized security data;

[0078] The threat agent modeling and simulation module is used to model each node in the threat attack graph as a threat agent with state observation and policy decision-making capabilities;

[0079] Parameter optimization module, used to globally optimize the parameters and strategy weights of the Monte Carlo tree search network using the Seagull algorithm;

[0080] The linkage disposal decision module is used to configure the Monte Carlo tree search network based on the optimal parameter group to reason and evaluate the candidate disposal path set;

[0081] The safety equipment scheduling module is used to analyze the optimal linkage disposal decision plan and generate the equipment scheduling instruction set;

[0082] The disposal effect evaluation and feedback module is used to perform multi-dimensional analysis on the disposal feedback data set.

[0083] This invention utilizes multi-module collaboration to automatically collect security data, dynamically model threats, and simulate intelligent agents. It employs the Seagull algorithm to globally optimize decision parameters, improving the efficiency of selecting optimal threat response paths. The system automatically coordinates and dispatches protective equipment, and continuously optimizes models through closed-loop evaluation, significantly enhancing network security situational awareness and rapid response capabilities.

[0084] In this embodiment, the modules are connected through the following methods:

[0085] S1. Collect security data from the network, host, and application layers, perform standardization processing, and generate standardized security data;

[0086] S2. Build a dynamic threat model based on standardized security data to generate a threat attack graph that includes assets, vulnerabilities, attackers, and their relationships.

[0087] S3. Construct a Monte Carlo tree search network, modeling each node in the threat attack graph as a threat agent with state observation and policy decision-making capabilities. Based on the agent's observed state and environmental information, use the Monte Carlo tree search algorithm to simulate threat evolution paths and various response and disposal solutions to generate a set of candidate disposal paths.

[0088] S4. Use the Seagull algorithm to globally optimize the parameters and strategy weights of the Monte Carlo tree search network to obtain the optimal parameter set;

[0089] S5. Use the optimal parameter group to configure the Monte Carlo tree search network, reason and evaluate the candidate disposal path set, and output the optimal linkage disposal decision plan;

[0090] S6. Dispatch safety protection equipment and implement the optimal coordinated disposal decision plan;

[0091] S7. Evaluate the execution effect of the optimal linkage disposal decision plan and feed back the evaluation results to the dynamic threat model and Monte Carlo tree search network.

[0092] This invention combines dynamic threat modeling with Monte Carlo tree search to automatically collect and standardize multi-layer security data, enabling intelligent reasoning about threat evolution paths and response strategies. It also employs the Seagull algorithm to optimize parameters and improve the efficiency of optimal response paths. The system possesses closed-loop feedback capabilities, continuously optimizing security models and decision-making, significantly improving the accuracy and automation of threat responses.

[0093] In this embodiment, the parameters of the Monte Carlo tree search network include node selection strategy parameters, number of simulations, exploration and utilization balance coefficient, pruning threshold, reward function coefficient, maximum search depth, agent state feature weight, and path evaluation criteria.

[0094] This method constructs a multidimensional parameter optimization space by setting parameters for node selection strategies, simulation times, exploration-exploitation balance coefficients, pruning thresholds, reward function coefficients, maximum search depth, agent state feature weights, and path evaluation criteria, enabling refined control of the Monte Carlo tree search network. This method dynamically adjusts parameter configurations, improving the comprehensiveness, accuracy, and decision-making efficiency of threat path searches and enhancing the system's adaptability in complex security scenarios.

[0095] In this embodiment, security data includes network traffic data, host logs, system alarms, user behavior records, device configuration, vulnerability information, attack event records, application access logs and status information of security protection devices.

[0096] This invention builds a comprehensive data perception system by collecting network traffic, host logs, system alarms, user behavior, device configuration, vulnerability information, attack events, application access logs, and security device status. By integrating multi-source heterogeneous data, it achieves refined and accurate threat detection and behavior analysis, improving the comprehensiveness of security event identification and the accuracy of response, and significantly enhancing security protection capabilities in complex environments.

[0097] In this embodiment, S2 includes the following specific steps:

[0098] S21. Decompose the standardized security data to extract information related to assets, vulnerabilities, attack behaviors, and attackers, and generate asset information sets, vulnerability information sets, attack behavior information sets, and attacker information sets;

[0099] S22. Classify the asset information set, identify the asset type, importance level, and topological location in the network, and generate an asset topology table;

[0100] S23. Associate the vulnerability information set with the asset topology table, identify the vulnerability type and risk level corresponding to each asset, and generate an asset vulnerability mapping table;

[0101] S24. Analyze the attack behavior information set, identify the attack path, attack means, and attack phase, map the attack behavior to potential target assets and related vulnerabilities, and generate an attack path table;

[0102] S25. Match the attacker information set with the attack path table, determine the association between the attacker and the identified attack path, and generate an attacker path mapping table;

[0103] S26. Integrate the asset topology table, asset vulnerability mapping table, attack path table, and attacker path mapping table to create a threat attack graph that includes assets, vulnerabilities, attackers, and associated relationships, and output the threat attack graph.

[0104] This method automatically establishes a multi-level relationship between assets, vulnerabilities, attack behaviors, and attackers by decomposing standardized security data and integrating multi-dimensional information, thereby constructing a threat attack graph. This method achieves precise mapping and dynamic association of assets, vulnerabilities, attack paths, and attackers, improving the comprehensiveness and accuracy of threat modeling and providing a solid data foundation and efficient modeling capabilities for subsequent security analysis and response.

[0105] In this embodiment, S3 includes the following specific steps:

[0106] S31. Convert each node in the threat attack graph into a threat agent with state observation and policy decision-making capabilities to generate a threat agent set;

[0107] S32. Set an observation state space and a set of optional strategies for each threat agent, and establish a state information table and a strategy information table for the threat agent;

[0108] S33. Initialize a Monte Carlo tree search structure based on the threat agent's state information table and policy information table, define a root node and an expandable child node set, and generate an initial search tree structure;

[0109] S34, using the state observations and environmental information of the threat agent set as input, performing multiple rounds of simulations using a Monte Carlo tree search algorithm to simulate the evolution paths of various threats and corresponding response and disposal strategies, and generating a threat evolution simulation result set;

[0110] S35. Screen and evaluate each path in the threat evolution simulation result set, and generate a set of candidate disposal paths based on preset strategy pros and cons criteria.

[0111] This method transforms threat attack graph nodes into threat agents with state observation and policy decision-making capabilities, and combines them with a Monte Carlo tree search algorithm to simulate multiple rounds of threat evolution and response paths. By constructing a multidimensional state and policy space, it automatically screens and evaluates candidate response paths, enabling intelligent generation of threat response strategies. This effectively improves the scientific and comprehensive nature of path selection and the accuracy of actual response.

[0112] In this embodiment, S4 includes the following specific steps:

[0113] S41, taking the candidate treatment path set, the initial parameters of the Monte Carlo tree search network and the strategy weight as input, initializing the Seagull algorithm population, and generating a parameter Seagull individual set;

[0114] S42, initializing the positions of the parameter seagull individual set, setting the feature vector of each parameter seagull individual according to the candidate disposal path set, and generating a parameter feature table;

[0115] S43, calculating the fitness of each parameter seagull individual in the Monte Carlo tree search network, and generating a fitness information table based on the candidate treatment path set;

[0116] S44. According to the migration and attack rules of the seagull algorithm, the position of the parameter seagull individual set is updated, the parameter feature table is adjusted, and an updated parameter seagull individual set is generated;

[0117] S45. Perform fitness evaluation on the updated parameter seagull individual set, select the parameter individual with the best fitness, and generate the optimal parameter group.

[0118] This paper introduces the Seagull algorithm to globally optimize Monte Carlo tree search network parameters and policy weights. By constructing feature vectors and evaluating the fitness of individual Seagull parameters, it enables efficient search and dynamic adjustment in a multidimensional parameter space. This method accurately identifies the optimal parameter set, improving the accuracy of candidate response path assessments and overall system decision-making efficiency, significantly enhancing the adaptive capabilities of threat response strategies.

[0119] In this embodiment, S5 includes the following specific steps:

[0120] S51, applying the optimal parameter group to the Monte Carlo tree search network, and dynamically fine-tuning the network parameters in combination with the current real-time network security situation information to generate a self-adaptive Monte Carlo tree search network;

[0121] S52, inputting the candidate disposal path set into the adaptively configured Monte Carlo tree search network, combining the historical execution performance of each path and environmental context information, using a multi-dimensional weight dynamic adjustment algorithm to weight the candidate disposal path set and generate a weighted path state table;

[0122] S53, based on the weighted path state table and the self-adaptively configured Monte Carlo tree search network, a multi-round game reasoning mechanism is used to simulate and deduce each candidate disposal path to generate a multi-scenario reasoning result set;

[0123] S54. For the multi-scenario reasoning result set, perform a forward-looking evaluation on the performance of the path under different threat evolution scenarios and generate a forward-looking path evaluation information table;

[0124] S55. Based on the forward-looking path evaluation information table, a multi-objective optimization selection algorithm is used to screen out the path that performs best in terms of safety, timeliness and resource utilization indicators, and generate and output the optimal linkage disposal decision plan.

[0125] This method uses an adaptively configured Monte Carlo tree search network, combined with historical results and environmental context, to dynamically sort candidate response paths using multi-dimensional weights and conduct multi-scenario game analysis, enabling forward-looking evaluation of response paths. It also employs a multi-objective optimization algorithm to select the optimal linkage solution that balances security, timeliness, and resource utilization, thereby enhancing the scientific, practical, and intelligent nature of threat response strategies.

[0126] In this embodiment, S6 includes the following specific steps:

[0127] S61. Analyze the specific disposal tasks and corresponding safety protection equipment requirements in the optimal linkage disposal decision plan, and generate an equipment scheduling instruction set;

[0128] S62: Send the device dispatch instruction set to the corresponding safety protection device, start the device to execute the corresponding disposal task, and record the response status information of the device;

[0129] S63. Collect status information and feedback results of each safety protection device during the execution of the disposal task to form a disposal feedback data set;

[0130] S64. Summarize and analyze the execution results based on the disposal feedback data set and generate a disposal result report.

[0131] This method analyzes the optimal coordinated response decision plan, automatically generates and issues equipment dispatch instructions, and achieves efficient coordinated response for safety protection equipment. Combining equipment execution status and feedback data, it dynamically summarizes and analyzes response results and generates comprehensive results reports. This method improves the automation, coordination, and traceability of emergency response, significantly enhancing the scientific nature and efficiency of actual security incident handling.

[0132] In this embodiment, S7 includes the following specific steps:

[0133] S71. Extract key execution data and related performance indicators from the disposal result report to generate an execution effect data set;

[0134] S72. Perform a multi-dimensional analysis of the execution effect data set to evaluate the performance of the disposal task in terms of safety, timeliness, and resource utilization, and generate a comprehensive evaluation result table;

[0135] S73. Compare the comprehensive evaluation results table with the original optimal linkage disposal decision plan, identify effective measures and deficiencies in the disposal process, and form a set of improvement suggestions;

[0136] S74. Feedback the improvement suggestion set to the dynamic threat model, dynamically modify the dynamic threat model parameters and threat characteristics, and generate an updated dynamic threat model;

[0137] S75, synchronizing the comprehensive evaluation result table to the Monte Carlo tree search network, adjusting the parameters and strategy weights of the Monte Carlo tree search network, and generating an optimized Monte Carlo tree search network;

[0138] S76. Combine the updated dynamic threat model with the optimized Monte Carlo tree search network to improve adaptive capabilities.

[0139] This invention uses multi-dimensional analysis and comprehensive evaluation of response results to accurately identify the effectiveness and deficiencies of coordinated response solutions and generate targeted improvement recommendations. Incorporating a feedback mechanism, it dynamically modifies threat models and optimizes Monte Carlo tree search network parameters, continuously improving the system's adaptive capabilities and significantly enhancing the intelligent optimization and continuous evolution of threat response.

[0140] Example 1:

[0141] In order to verify the feasibility of the present invention in implementation, the present invention is applied to the network security protection system upgrade project of a provincial government cloud data center. The data center carries important government business systems of multiple departments in the province. In daily operation, it must not only ensure the high availability and high security of external services, but also face increasingly complex network security threats. In the past, data centers mainly relied on traditional intrusion detection systems, firewalls, host protection, and manual on-duty methods to deal with security incidents, lacking dynamic modeling and intelligent linkage disposal of threat chains. Due to the large number of business systems, wide distribution of assets, and complex types of security equipment, the traditional disposal process often has prominent problems such as response delays, inaccurate disposal decisions, and low equipment utilization in scenarios of multi-point concurrent attacks, unknown threats, and resource scheduling conflicts. In September 2023, the data center suffered three different types of network attacks in just one week, including ransomware intrusion, lateral penetration, and Web vulnerability exploitation, which resulted in a brief interruption of some business systems and an abnormal increase in log data, posing a huge challenge to the operation and maintenance and security teams.

[0142] In this deployment scenario, the system automatically collects multi-dimensional data, including network traffic, host logs, system alerts, user behavior, device configuration, vulnerability information, and attack events, through the security data collection and standardization module. The system collected 17.5 million network traffic logs, 3.2 million host logs, 4,200 system alerts, and 25 vulnerability information items, impacting over 1,200 business assets. After standardization, the data is quickly converted into a unified format suitable for dynamic threat modeling.

[0143] The dynamic threat modeling module then conducted an in-depth analysis of this data, automatically constructing a threat attack graph covering all network assets, vulnerabilities, attackers, and their relationships. The system identified 95 high-risk assets, 16 high-risk vulnerabilities, and 38 suspected attack source IP addresses. The attack graph displays potential attack paths and associated assets, helping security personnel gain a clear understanding of the threat landscape. The threat agent modeling and simulation module transformed the attack graph nodes into agents capable of state observation and policy decision-making. Using a Monte Carlo tree search network, it conducted 5,000 simulations of different threat evolution paths, generating 186 candidate remediation paths.

[0144] On this basis, the parameter optimization module introduced the Seagull algorithm to globally optimize the parameters and policy weights of the Monte Carlo tree search network, ultimately obtaining the optimal parameter set, which improved search efficiency by 22% and path evaluation accuracy by 18%. The coordinated response decision module utilized the optimized network to further reason and optimize the set of candidate response paths. Combining current resources with historical response results, it automatically outputted a response decision plan that optimized security, timeliness, and resource utilization. In this actual test, the optimal response plan included policy adjustments for eight firewalls, isolation of 15 hosts, seven vulnerability fixes, and three traffic rate limiting measures, involving 27 automated dispatch devices.

[0145] During the coordinated disposal process, the security device scheduling module automatically analyzes the disposal tasks, generates and issues device instructions. The average device response delay is reduced from 17 seconds in the original system to 8 seconds under this invention, and the failure rate is reduced to 0.7%. After the disposal is completed, the disposal effect evaluation and feedback module conducts a multi-dimensional analysis of the execution data of the entire process. The evaluation results show that the overall success rate of the disposal tasks reached 99.1%, the timeliness of the disposal increased by 31%, the utilization rate of the equipment resources involved increased by 23%, and the availability of key business systems was not affected. The system also automatically feeds back the evaluation results to the dynamic threat model and Monte Carlo tree search network to further optimize the model parameters and achieve continuous adaptive evolution.

[0146] Table 1 Comparison of situational awareness and linkage optimization effects driven by dynamic threat modeling

[0147]

[0148] Table 1 shows that under the same threat scenario, the traditional system took an average of 22 minutes to respond, with a false alarm rate of 6.7% and a manual intervention rate of 44%. The proposed system, on the other hand, reduced the average response time to 11 minutes, the false alarm rate to 2.1%, and the manual intervention rate to just 13%. Furthermore, for the three cyberattacks that occurred during this testing period, the system completed the entire process of detection, analysis, decision-making, and response within 10 minutes, with no business system interruptions or data leaks.

[0149] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.

Claims

1. A situational awareness and linkage disposal system driven by dynamic threat modeling, characterized in that: include: The security data collection and standardization module is used to collect security data from the network, host and application layers, and perform standardization processing to generate standardized security data; Dynamic threat modeling module, used to build dynamic threat models based on standardized security data; The threat agent modeling and simulation module is used to model each node in the threat attack graph as a threat agent with state observation and policy decision-making capabilities; Parameter optimization module, used to globally optimize the parameters and strategy weights of the Monte Carlo tree search network using the Seagull algorithm; The linkage disposal decision module is used to configure the Monte Carlo tree search network based on the optimal parameter group to reason and evaluate the candidate disposal path set; The safety equipment scheduling module is used to analyze the optimal linkage disposal decision plan and generate the equipment scheduling instruction set; The disposal effect evaluation and feedback module is used to perform multi-dimensional analysis on the disposal feedback data set.

2. A situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 1, characterized in that: The modules are implemented as follows: S1. Collect security data from the network, host, and application layers, perform standardization processing, and generate standardized security data; S2. Build a dynamic threat model based on standardized security data to generate a threat attack graph that includes assets, vulnerabilities, attackers, and their relationships. S3. Construct a Monte Carlo tree search network, modeling each node in the threat attack graph as a threat agent with state observation and policy decision-making capabilities. Based on the agent's observed state and environmental information, use the Monte Carlo tree search algorithm to simulate threat evolution paths and various response and disposal solutions to generate a set of candidate disposal paths. S4. Use the Seagull algorithm to globally optimize the parameters and strategy weights of the Monte Carlo tree search network to obtain the optimal parameter set; S5. Use the optimal parameter group to configure the Monte Carlo tree search network, reason and evaluate the candidate disposal path set, and output the optimal linkage disposal decision plan; S6. Dispatch safety protection equipment and implement the optimal coordinated disposal decision plan; S7. Evaluate the execution effect of the optimal linkage disposal decision plan and feed back the evaluation results to the dynamic threat model and Monte Carlo tree search network.

3. A situation awareness and linkage disposal system based on dynamic threat modeling drive according to claim 2, characterized in that: The parameters of the Monte Carlo tree search network include node selection strategy parameters, number of simulations, exploration and utilization balance coefficient, pruning threshold, reward function coefficient, maximum search depth, agent state feature weight and path evaluation criteria.

4. A situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 2, characterized in that: The security data includes network traffic data, host logs, system alarms, user behavior records, device configurations, vulnerability information, attack event records, application access logs and status information of security protection devices.

5. The situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 2 is characterized in that: The S2 includes the following specific steps: S21. Decompose the standardized security data to extract information related to assets, vulnerabilities, attack behaviors, and attackers, and generate an asset information set, a vulnerability information set, an attack behavior information set, and an attacker information set; S22. Classify the asset information set, identify the asset type, importance level, and topological location in the network, and generate an asset topology table; S23. Associate the vulnerability information set with the asset topology table, identify the vulnerability type and risk level corresponding to each asset, and generate an asset vulnerability mapping table; S24. Analyze the attack behavior information set, identify the attack path, attack means, and attack phase, map the attack behavior to potential target assets and related vulnerabilities, and generate an attack path table; S25. Match the attacker information set with the attack path table, determine the association between the attacker and the identified attack path, and generate an attacker path mapping table; S26. Integrate the asset topology table, asset vulnerability mapping table, attack path table, and attacker path mapping table to create a threat attack graph that includes assets, vulnerabilities, attackers, and associated relationships, and output the threat attack graph.

6. A situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 2, characterized in that: The S3 includes the following specific steps: S31. Convert each node in the threat attack graph into a threat agent with state observation and policy decision-making capabilities to generate a threat agent set; S32. Set an observation state space and a set of optional strategies for each threat agent, and establish a state information table and a strategy information table for the threat agent; S33. Initialize a Monte Carlo tree search structure based on the threat agent's state information table and policy information table, define a root node and an expandable child node set, and generate an initial search tree structure; S34, using the state observations and environmental information of the threat agent set as input, performing multiple rounds of simulations using a Monte Carlo tree search algorithm to simulate the evolution paths of various threats and corresponding response and disposal strategies, and generating a threat evolution simulation result set; S35. Screen and evaluate each path in the threat evolution simulation result set, and generate a set of candidate disposal paths based on preset strategy pros and cons criteria.

7. The situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 2 is characterized in that: The S4 includes the following specific steps: S41, taking the candidate treatment path set, the initial parameters of the Monte Carlo tree search network and the strategy weight as input, initializing the Seagull algorithm population, and generating a parameter Seagull individual set; S42, initializing the positions of the parameter seagull individual set, setting the feature vector of each parameter seagull individual according to the candidate disposal path set, and generating a parameter feature table; S43, calculating the fitness of each parameter seagull individual in the Monte Carlo tree search network, and generating a fitness information table based on the candidate treatment path set; S44. According to the migration and attack rules of the seagull algorithm, the position of the parameter seagull individual set is updated, the parameter feature table is adjusted, and an updated parameter seagull individual set is generated; S45. Perform fitness evaluation on the updated parameter seagull individual set, select the parameter individual with the best fitness, and generate the optimal parameter group.

8. The situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 2 is characterized in that: The S5 includes the following specific steps: S51, applying the optimal parameter group to the Monte Carlo tree search network, and dynamically fine-tuning the network parameters in combination with the current real-time network security situation information to generate a self-adaptive Monte Carlo tree search network; S52, inputting the candidate disposal path set into the adaptively configured Monte Carlo tree search network, combining the historical execution performance of each path and environmental context information, using a multi-dimensional weight dynamic adjustment algorithm to weight the candidate disposal path set and generate a weighted path state table; S53, based on the weighted path state table and the self-adaptively configured Monte Carlo tree search network, a multi-round game reasoning mechanism is used to simulate and deduce each candidate disposal path to generate a multi-scenario reasoning result set; S54. For the multi-scenario reasoning result set, perform a forward-looking evaluation on the performance of the path under different threat evolution scenarios and generate a forward-looking path evaluation information table; S55. Based on the forward-looking path evaluation information table, a multi-objective optimization selection algorithm is used to screen out the path that performs best in terms of safety, timeliness and resource utilization indicators, and generate and output the optimal linkage disposal decision plan.

9. The situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 2 is characterized in that: The S6 comprises the following specific steps: S61. Analyze the specific disposal tasks and corresponding safety protection equipment requirements in the optimal linkage disposal decision plan, and generate an equipment scheduling instruction set; S62: Send the device dispatch instruction set to the corresponding safety protection device, start the device to execute the corresponding disposal task, and record the response status information of the device; S63. Collect status information and feedback results of each safety protection device during the execution of the disposal task to form a disposal feedback data set; S64. Summarize and analyze the execution results based on the disposal feedback data set and generate a disposal result report.

10. The situational awareness and linkage handling system based on dynamic threat modeling drive according to claim 2 is characterized in that: The S7 includes the following specific steps: S71. Extract key execution data and related performance indicators from the disposal result report to generate an execution effect data set; S72. Perform a multi-dimensional analysis of the execution effect data set to evaluate the performance of the disposal task in terms of safety, timeliness, and resource utilization, and generate a comprehensive evaluation result table; S73. Compare the comprehensive evaluation results table with the original optimal linkage disposal decision plan, identify effective measures and deficiencies in the disposal process, and form a set of improvement suggestions; S74. Feedback the improvement suggestion set to the dynamic threat model, dynamically modify the dynamic threat model parameters and threat characteristics, and generate an updated dynamic threat model; S75, synchronizing the comprehensive evaluation result table to the Monte Carlo tree search network, adjusting the parameters and strategy weights of the Monte Carlo tree search network, and generating an optimized Monte Carlo tree search network; S76. Combine the updated dynamic threat model with the optimized Monte Carlo tree search network to improve adaptive capabilities.

Citation Information

Cited By

  • Automobile door hinge production line resource state scheduling system based on industrial Internet of Things

    CN121836290A

  • Self-evolution knowledge graph and attack path deduction system and method fused with context awareness

    CN121841741A

  • Method and device for collaboratively reconstructing OODA decision closed loop based on multiple agents

    CN122226380A