Zero-trust network dynamic access control method based on AI behavior portrait
Through the zero-trust network dynamic access control method based on AI behavioral profiling, multi-source data is collected in real time, an AI behavioral profiling engine is built, risk scores are calculated and policies are dynamically adjusted, which solves the shortcomings of the traditional boundary control model and achieves effective protection against internal threats and complex attacks.
Patent Information
- Application Number
- CN202510870277.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-06-26
AI Technical Summary
Existing technologies are difficult to dynamically respond to behavioral anomalies. Traditional border control models cannot effectively deal with internal threats and advanced persistent attacks. In addition, behavioral analysis lacks multi-dimensional data fusion, resulting in a high false alarm rate and difficulty in detecting latent threats.
A zero-trust network dynamic access control method based on AI behavioral profiling is adopted. By collecting multi-source behavioral data in real time, an AI behavioral profiling engine is built, behavioral deviation is calculated and risk scores are output, access policies are dynamically adjusted, and multi-factor authentication and session monitoring are combined to achieve refined control.
It effectively blocks internal threats, reduces false alarm rates, improves network security and adaptability, and dynamically responds to complex attacks.
Smart Images

Figure CN120768583A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a zero-trust network dynamic access control method based on AI behavior profiling. Background Art
[0002] As cyberattacks become increasingly sophisticated, traditional static, perimeter-based access control models are struggling to address insider threats and advanced persistent threats (APTs). Zero Trust architecture improves security through the principle of "never trust, always verify," but existing implementations still have shortcomings. For example, most solutions rely on predefined policies and cannot dynamically respond to behavioral anomalies. For example, after legitimate credentials are stolen, attackers can move laterally without losing their privileges.
[0003] In addition, existing behavioral analysis focuses on single-dimensional data such as identity or environment, such as IP reputation, and lacks integrated analysis of user operation sequences and resource interaction patterns, resulting in a high false alarm rate and difficulty in detecting potential threats. Summary of the Invention
[0004] To this end, the present invention provides a zero-trust network dynamic access control method based on AI behavior profiling to solve the problems in the prior art.
[0005] In order to achieve the above object, the present invention provides the following technical solutions:
[0006] The zero-trust network dynamic access control method based on AI behavioral profiling includes the following steps:
[0007] Step 1: When a user or device initiates an access request, the zero-trust gateway collects and integrates multi-source behavioral data in real time.
[0008] Step 2: Build an AI behavioral profiling engine based on historical data, input the integrated multi-source behavioral data, calculate the behavioral deviation through the AI behavioral profiling engine, and output a risk score;
[0009] Step 3: Dynamic policy decision-making: The decision engine performs hierarchical control based on risk scores. For low-risk users, access rights are granted and the user enters the default session channel. For medium-risk users, multi-factor authentication is triggered and, upon successful verification, restricted rights are granted. For high-risk users, access is immediately blocked, an alert is triggered to the SOC, and attack tracing data is recorded.
[0010] Step 4: Monitor the entire behavior flow of established sessions and analyze the operation sequence and session activity in real time.
[0011] Step 5: When an escalation of risk is detected in the session, the session permissions are downgraded, high-risk operations are restricted, the session is terminated, the connection is forcibly disconnected, the account is frozen, and forensic data is preserved;
[0012] Step 6: Generate standardized audit events from all decision logs and write them to the blockchain or an immutable database. Feedback the behavioral data from the session to the AI behavioral profiling engine.
[0013] Step 7: Regularly analyze audit events and risk management results, adjust policy decision thresholds through reinforcement learning, and update the sensitive resource tag library.
[0014] Furthermore: Multi-source behavioral data includes identity information, behavioral data and environmental data; identity information mainly includes user role, device fingerprint, and authentication strength; behavioral data includes API call sequence, operation frequency, access time, and data traffic pattern; environmental data includes IP geographic location, network environment security score, and device security status.
[0015] Furthermore: through terminal agents capturing device-level behaviors, network traffic probes analyzing communication patterns, identity management systems providing identity credibility, and security information and event management systems associating global threat intelligence to achieve deep linkage, thus conducting multi-dimensional behavioral data cross-validation.
[0016] Further: The specific steps for building the AI behavior profiling engine are as follows:
[0017] (1) Collection of historical original behavior data: Through various sensors, agent programs and log systems deployed in the network environment, the original behavior data of users and systems are collected in an all-round way;
[0018] (2) Extraction of spatiotemporal features: Using time series analysis techniques to extract temporal dimension features from raw data; using geographic information system technology to analyze the spatial characteristics of user visits and construct a spatial distribution model of user behavior;
[0019] (3) Graph neural network processing: Map the extracted spatiotemporal features into graph structure data and construct a user-resource interaction graph; in which users, devices, and application entities serve as graph nodes, and the access relationships between entities serve as edges; use the graph neural network model to conduct deep learning on the graph structure data and mine the implicit patterns of user behavior in complex network relationships;
[0020] (4) Node embedding generation: Through the training of graph neural networks, high-dimensional and sparse graph node features are mapped into low-dimensional and dense node embedding vectors; each node embedding vector contains comprehensive feature information of user behavior;
[0021] (5) Time series modeling: Perform time series modeling on node embedding vectors to capture the temporal evolution of user behavior; use recurrent neural network (RNN), long short-term memory (LSTM) or temporal convolutional network (TCN) models to learn the temporal dependencies of user behavior and predict future behavior trends.
[0022] (6) Behavior profile vector generation: integrating the results of spatiotemporal feature extraction, graph neural network processing, and time series modeling to generate the user's behavior profile vector;
[0023] (7) Risk scoring engine: build a risk assessment model based on behavioral profile vectors; use machine learning algorithms to perform risk scoring on user behavior; the risk scoring results are used to dynamically adjust the user's network access rights.
[0024] Furthermore: Risk scores are generated based on comprehensive behavioral deviation, environmental risk weights, and sensitive resource tags, and behaviors are divided into three levels: low risk, medium risk, and high risk based on the risk scores.
[0025] Furthermore, the specific implementation steps of the dynamic strategy decision are as follows:
[0026] (1) User access request: When a user attempts to access protected network resources, he or she needs to send an access request to the gateway;
[0027] (2) Profile query and strategy generation: After the gateway receives the user's access request, it will send a request to the decision engine to query the user's profile; the decision engine generates dynamic strategies based on the user's historical behavior data and identity information combined with AI algorithms;
[0028] (3) Access control execution: The gateway makes real-time judgments and decisions on the user's access request based on the dynamic policy returned by the decision engine. If the policy allows access, the gateway will release the request and allow the user to access the target resource. If the policy detects potential risks, the gateway will restrict access and require the user to perform multi-factor authentication or take other security measures.
[0029] (4) Session monitoring and policy adjustment; During the user session, the gateway will continuously collect the user's real-time behavior data, and the gateway will send this real-time behavior data to the AI behavior profiling engine; The AI behavior profiling engine uses AI algorithms to analyze the user's behavior data to detect whether there are anomalies or risk fluctuations; When the AI behavior profiling engine detects risk fluctuations, it will send an early warning information to the decision engine; The decision engine re-evaluates the user's risk level based on the early warning information and generates a policy adjustment instruction; After receiving the policy adjustment instruction, the gateway will adjust the access control policy for the user session in real time to ensure the security of network resources.
[0030] Furthermore: in step 4, if abnormal behavior is detected, dynamic policy adjustment is triggered; the risk level is upgraded in real time, and the user or device session is downgraded or the session is terminated.
[0031] The present invention has the following advantages: real-time calculation of risk scores based on AI behavioral profiling, achieving a transition from "static authorization" to "dynamic permission adjustment", effectively blocking internal threats such as credential theft; full-cycle session monitoring combined with a real-time permission degradation mechanism to minimize the attack window; and improving system adaptability through reinforcement learning iterative strategy thresholds and resource tag libraries.
[0032] Other features and advantages of the present invention will be set forth in the description which follows, and in part will be obvious from the description, or may be learned by practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] To more intuitively illustrate the prior art and the present application, exemplary drawings are provided below. It should be understood that the specific shapes and structures shown in the drawings should not generally be considered as limiting conditions for implementing the present application. For example, based on the technical concepts disclosed in this application and the exemplary drawings, those skilled in the art are capable of easily making routine adjustments or further optimizations to the addition / reduction / attribution division of certain units (components), the specific shapes, positional relationships, connection methods, and dimensional ratios.
[0034] Figure 1 This is an execution flow chart of a zero-trust network dynamic access control method based on AI behavioral profiling provided in one embodiment of the present application.
[0035] Figure 2 This is a flowchart of behavioral profiling modeling in the zero-trust network dynamic access control method based on AI behavioral profiling in the present invention.
[0036] Figure 3 This is a timing diagram of policy decision-making in the zero-trust network dynamic access control method based on AI behavior profiling of the present invention. DETAILED DESCRIPTION
[0037] The following specific embodiments illustrate the implementation of the present invention. People familiar with this technology can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. It should be understood that these embodiments are only to further illustrate the present invention and cannot be understood as limiting the scope of protection of the present invention. Technical engineers in this field can make some non-essential improvements and adjustments to the present invention based on the content of the above invention; based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0038] See also Figure 1-Figure 3 The zero-trust network dynamic access control method based on AI behavior profiling includes the following steps:
[0039] Step 1: Collect multi-source real-time behavior data when access request is initiated.
[0040] When the user / device initiates an access request, the zero-trust gateway collects multi-source behavior data in real time; the multi-source behavior data includes identity information, behavior data, and environment data, etc.
[0041] Identity information mainly includes user role, device fingerprint, authentication strength, etc.; behavior data includes API call sequence, operation frequency, access time, data flow pattern, etc.; environment data includes IP geographic location, network environment security score, device security state (such as patch version).
[0042] To avoid the risk of misjudgment by a single data source, for example, abnormal operation frequency caused by network fluctuations is misjudged as attack behavior; multi-dimensional data is integrated, and multi-dimensional data cross-validation is realized through deep linkage of terminal agent, network traffic probe, identity management system (IAM), and security information and event management (SIEM) system.
[0043] Among them, the terminal agent can capture device-level behavior, such as process operation, file access, and peripheral device usage; the network traffic probe can analyze communication patterns, such as abnormal port scanning and data transmission traffic; the IAM system can provide identity trustworthiness, such as permission change history and authentication failure count; the SIEM system can associate global threat intelligence, such as known attack fingerprints and historical violation events.
[0044] For example: When the IAM system confirms that the user only has data reading permission, if the terminal agent detects abnormal write operation, the system will automatically trigger permission downgrade and generate an alarm; in the face of advanced persistent threat (APT), abnormal process behavior captured by the terminal agent, C2 communication characteristics identified by the network probe, and threat intelligence fingerprints matched by the SIEM will form a complete evidence chain, accurately identifying complex attacks that bypass single-layer defense.
[0045] Step 2: Build an AI behavior portrait engine, and based on multi-dimensional integrated multi-source behavior data, calculate the behavior deviation degree through the AI behavior portrait engine, and output the risk score.
[0046] Referring to Figure 2 , the specific steps of building the AI behavior portrait engine are as follows:
[0047] (1) Collect historical raw behavior data; through various sensors, agent programs, and log systems deployed in the network environment, collect raw behavior data of users and systems in all directions; data sources cover network traffic logs, system operation logs, application usage records, device state information, etc. dimensions, forming a multi-dimensional raw data pool.
[0048] (2) Extraction of spatiotemporal features: Using time series analysis technology, extract time dimension features from the original data, including time series patterns such as operation frequency, session duration, and access period distribution; based on geographic information system (GIS) technology, analyze the user's geographic location information, network topology structure and other spatial features to build a spatial distribution model of user behavior.
[0049] (3) Graph neural network processing: Map the extracted spatiotemporal features into graph structure data and construct a user-resource interaction graph; in which entities such as users, devices, and applications serve as graph nodes, and the access relationships between entities serve as edges; use a graph neural network model (graph convolutional network GCN is used in this embodiment) to perform deep learning on the graph structure data and explore the implicit patterns of user behavior in complex network relationships.
[0050] (4) Node embedding generation: Through the training of graph neural networks, high-dimensional and sparse graph node features are mapped into low-dimensional and dense node embedding vectors; each node embedding vector contains comprehensive feature information of user behavior, such as behavioral preferences, operating habits, risk tendencies, etc.
[0051] (5) Time series modeling: Perform time series modeling on node embedding vectors to capture the temporal evolution of user behavior; use models such as recurrent neural networks (RNN), long short-term memory networks (LSTM), or time convolutional networks (TCN) to learn the temporal dependencies of user behavior and predict future behavior trends.
[0052] (6) Behavioral profile vector generation: The user's behavioral profile vector is generated by integrating the results of spatiotemporal feature extraction, graph neural network processing, and time series modeling; this vector comprehensively reflects the user's behavioral characteristics, risk level, and behavioral trends, providing a basis for subsequent risk assessment.
[0053] (7) Risk scoring engine: build a risk assessment model based on behavioral profile vectors; use machine learning algorithms to perform risk scoring on user behavior; the risk scoring results are used to dynamically adjust the user's network access rights to achieve refined access control under zero-trust networks.
[0054] Based on comprehensive behavioral deviation, environmental risk weight, and sensitive resource tags, a real-time risk score of 0-100 is generated; for example: low risk (0-30), medium risk (31-70), and high risk (71-100).
[0055] Step 3: Dynamic policy decision-making; the decision engine performs hierarchical control based on risk scores;
[0056] Among them, for low-risk attacks, access rights are granted and the default session channel is entered; for medium-risk attacks, multi-factor authentication (MFA) is triggered, and restricted permissions (such as only read-only operations) are granted after verification; for high-risk attacks, access is immediately blocked, and an alarm is triggered to the SOC (Security Operation Center), and the attack tracing data is recorded.
[0057] See Figure 3 ,The specific implementation steps of dynamic strategy decision are as follows:
[0058] 1) User access request: When a user attempts to access protected network resources, he needs to send an access request to the gateway.
[0059] 2) Profile query and policy generation: After receiving the user's access request, the gateway will initiate a request to query the user's profile to the decision engine. The decision engine generates a dynamic policy based on the user's historical behavior data, identity information, etc., combined with AI algorithms. The dynamic policy includes a temporary token for subsequent access control and session monitoring.
[0060] 3) Access control execution: The gateway makes real-time judgments and decisions on user access requests based on the dynamic policy returned by the decision engine. If the policy allows access, the gateway will release the request and allow the user to access the target resource. If the policy detects potential risks, the gateway will restrict access and may require the user to perform multi-factor authentication (MFA) or take other security measures.
[0061] 4) Session monitoring and policy adjustment: During a user session, the gateway continuously collects real-time user behavior data, such as login time, operation frequency, and accessed resources. The gateway sends this real-time behavior data to the AI behavior profiling engine for further analysis.
[0062] The AI behavioral profiling engine uses AI algorithms to analyze user behavioral data to detect whether there are anomalies or risk fluctuations; when the AI behavioral profiling engine detects risk fluctuations, it will send an early warning information to the decision-making engine; the decision-making engine will re-evaluate the user's risk level based on the early warning information and generate policy adjustment instructions; after receiving the policy adjustment instructions, the gateway will adjust the access control policy for the user session in real time to ensure the security of network resources.
[0063] Step 4: Continuous session monitoring and real-time adjustments;
[0064] Monitor the entire behavioral flow of established sessions and analyze operation sequences (such as database query patterns and file download volume) and session activity in real time.
[0065] If abnormal behavior is detected (such as attempts to escalate privileges or a surge in data outflow), dynamic policy adjustments are triggered; the risk level is upgraded in real time (such as low to medium risk), and privilege downgrades or session terminations are executed.
[0066] Step 5: Dynamic downgrade / termination of permissions
[0067] When a risk escalation is detected in a session, session permissions are downgraded to restrict high-risk operations, such as prohibiting file uploads and closing access to sensitive APIs. The session is terminated, the connection is forcibly disconnected, the account is frozen, and forensic data, including operation recordings and network packet logs, is retained.
[0068] Step 6: Generate audit events and update profiles. Generate standardized audit events from all decision logs (risk scoring basis, policy execution actions) and write them to the blockchain or an immutable database. Feedback the behavioral data from the session to the AI behavioral profile engine to update the user / device behavioral baseline model (e.g., optimizing LSTM weights through online learning).
[0069] Step 7: Close the policy optimization loop; regularly analyze audit events and risk management results, and adjust policy decision thresholds through reinforcement learning (RL) (for example, reduce the MFA trigger threshold from 30 points to 25 points); and update the sensitive resource tag library (for example, add the core database as a high-risk resource).
[0070] The zero-trust network dynamic access control method based on AI behavioral profiling in this embodiment can dynamically adjust access policies according to users' real-time behaviors, achieve refined access control, and effectively improve network security.
[0071] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A zero-trust network dynamic access control method based on AI behavior profiling, characterized by: The following steps are involved: Step 1: When a user or device initiates an access request, the zero-trust gateway collects and integrates multi-source behavioral data in real time. Step 2: Build an AI behavioral profiling engine based on historical data, input the integrated multi-source behavioral data, calculate the behavioral deviation through the AI behavioral profiling engine, and output a risk score; Step 3: Dynamic policy decision-making: The decision engine performs hierarchical control based on risk scores. For low-risk users, access rights are granted and the user enters the default session channel. For medium-risk users, multi-factor authentication is triggered and, upon successful verification, restricted rights are granted. For high-risk users, access is immediately blocked, an alert is triggered to the SOC, and attack tracing data is recorded. Step 4: Monitor the entire behavior flow of established sessions and analyze the operation sequence and session activity in real time. Step 5: When an escalation of risk is detected in the session, the session permissions are downgraded, high-risk operations are restricted, the session is terminated, the connection is forcibly disconnected, the account is frozen, and forensic data is preserved; Step 6: Generate standardized audit events from all decision logs and write them to the blockchain or an immutable database. Feedback the behavioral data from the session to the AI behavioral profiling engine. Step 7: Regularly analyze audit events and risk management results, and adjust policy decision thresholds through reinforcement learning; Update sensitive resource tag library.
2. The zero-trust network dynamic access control method based on AI behavior profiling according to claim 1 is characterized in that: Multi-source behavioral data includes identity information, behavioral data, and environmental data; identity information mainly includes user roles, device fingerprints, and authentication strength; behavioral data includes API call sequences, operation frequency, access time, and data traffic patterns; environmental data includes IP geographic location, network environment security score, and device security status.
3. The zero-trust network dynamic access control method based on AI behavior profiling according to claim 1 is characterized in that: Through terminal agents capturing device-level behaviors, network traffic probes analyzing communication patterns, identity management systems providing identity credibility, and security information and event management systems associating global threat intelligence, we can deeply link and perform multi-dimensional behavioral data cross-verification.
4. The zero-trust network dynamic access control method based on AI behavior profiling according to claim 1 is characterized in that: The specific steps for building the AI behavior profiling engine are as follows: (1) Collection of historical original behavior data: Through various sensors, agent programs and log systems deployed in the network environment, the original behavior data of users and systems are collected in an all-round way; (2) Spatiotemporal feature extraction: using time series analysis techniques to extract time dimension features from raw data; Based on geographic information system technology, the spatial characteristics of user visits are analyzed and the spatial distribution model of user behavior is constructed; (3) Graph neural network processing: Map the extracted spatiotemporal features into graph structure data and construct a user-resource interaction graph; in which users, devices, and application entities serve as graph nodes, and the access relationships between entities serve as edges; use the graph neural network model to conduct deep learning on the graph structure data and mine the implicit patterns of user behavior in complex network relationships; (4) Node embedding generation: Through the training of graph neural networks, high-dimensional and sparse graph node features are mapped into low-dimensional and dense node embedding vectors; each node embedding vector contains comprehensive feature information of user behavior; (5) Time series modeling: Perform time series modeling on node embedding vectors to capture the temporal evolution of user behavior; learn the temporal dependencies of user behavior and predict future behavior trends; (6) Behavior profile vector generation: integrating the results of spatiotemporal feature extraction, graph neural network processing, and time series modeling to generate the user's behavior profile vector; (7) Risk scoring engine: build a risk assessment model based on behavioral profile vectors; use machine learning algorithms to perform risk scoring on user behavior; the risk scoring results are used to dynamically adjust the user's network access rights.
5. The zero-trust network dynamic access control method based on AI behavior profiling according to claim 4 is characterized in that: The risk score is generated based on the comprehensive behavioral deviation, environmental risk weight, and sensitive resource label, and the behavior is divided into three levels: low risk, medium risk, and high risk according to the risk score.
6. The zero-trust network dynamic access control method based on AI behavior profiling according to claim 1 is characterized in that: The specific implementation steps of the dynamic policy decision are as follows: (1) User access request: When a user attempts to access protected network resources, he or she needs to send an access request to the gateway; (2) Profile query and strategy generation: After the gateway receives the user's access request, it will send a request to the decision engine to query the user's profile; the decision engine generates dynamic strategies based on the user's historical behavior data and identity information combined with AI algorithms; (3) Access control execution: The gateway makes real-time judgments and decisions on user access requests based on the dynamic policies returned by the decision engine; If the policy allows access, the gateway will release the request and allow the user to access the target resource; if the policy detects potential risks, the gateway will restrict access and require the user to perform multi-factor authentication or take other security measures; (4) Session monitoring and policy adjustment; During the user session, the gateway will continuously collect the user's real-time behavior data, and the gateway will send this real-time behavior data to the AI behavior profiling engine; The AI behavior profiling engine uses AI algorithms to analyze the user's behavior data to detect whether there are anomalies or risk fluctuations; When the AI behavior profiling engine detects risk fluctuations, it will send an early warning information to the decision engine; The decision engine re-evaluates the user's risk level based on the early warning information and generates a policy adjustment instruction; After receiving the policy adjustment instruction, the gateway will adjust the access control policy for the user session in real time to ensure the security of network resources.
7. The zero-trust network dynamic access control method based on AI behavior profiling according to claim 1 is characterized in that: In step 4, if abnormal behavior is detected, the dynamic strategy adjustment is triggered; Upgrade risk levels in real time and downgrade privileges or terminate user or device sessions.
Citation Information
Patent Citations
Zero-trust network architecture for industrial internet platform
CN115361186A
User permission adjustment method and device, electronic equipment and storage medium
CN115695015A
Zero-trust network access control method and system based on time window dynamic switching
CN116545731A
Customer portrait key data mining method and system based on space-time big data
CN118797542A
Adaptive network security policy dynamic adjustment method
CN119766555A
Cited By
Dynamic access blocking method based on zero trust
CN121217444A
Zero-trust-based dynamic access blocking method
CN121217444B
Access security protection method and system based on user behavior portrait
CN121396653A
Data leakage prevention method and system based on user behavior perception
CN121396655A
Network information security access control system based on dynamic trust evaluation
CN121486049A