System security access control method based on deep learning and dynamic risk perception

Through deep learning and dynamic risk-aware access control methods, using behavioral state vector modeling and graph construction, combined with Hebbian learning and Winner-Take-All mechanism, the shortcomings of traditional access control methods in dynamic environments are solved, and high-precision and adaptive access control is achieved.

CN120785607APending Publication Date: 2025-10-14GUANGXI POLICE ACAD +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510979222.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-16
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

When faced with the interweaving of multi-dimensional data features, rapid evolution of access behavior, and strong hidden nature of abnormal risks, traditional access control methods lack a deep behavioral modeling mechanism, are unable to achieve dynamic risk feedback control, have a rough response path selection mechanism, and have low behavioral data utilization.

Method used

The access control decision path is generated by deep learning-based access behavior state vector modeling, behavior evolution graph construction, Hebbian learning mechanism and Winner-Take-All competition mechanism, and is dynamically adjusted through access risk marking and behavior evolution marking.

Benefits of technology

It improves the accuracy of risk identification and the intelligence of response decisions, enhances the adaptability of behavior evolution, and realizes accurate response and continuous adaptive control of access behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785607A_ABST
    Figure CN120785607A_ABST
Patent Text Reader

Abstract

The invention discloses a system security access control method based on deep learning and dynamic risk awareness, which comprises the following steps of: generating a behavior state vector by collecting user identity, operation, equipment state and environment information, constructing an access behavior map, and establishing an access behavior map through a Hebbian learning rule; the method comprises the following steps: dynamically updating connection strength between behaviors in combination with historical behavior data, after receiving an access request, selecting an association path from a map, calculating an activation potential value, selecting an optimal path as an access decision basis by applying a Winner-Take-All selection mechanism, executing an access control operation, generating a risk mark and a behavior evolution mark, and establishing an access control strategy; the method is used for adjusting a selection threshold and an atlas weight. And finally, compressing and coding the related information, and recording the information in an access log. According to the method, intelligent judgment on the access behavior is realized by using deep learning and a dynamic risk perception mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a system security access control method based on deep learning and dynamic risk perception. Background Art

[0002] As information systems continue to become more complex and open, access security issues for system resources are becoming increasingly prominent. This is especially true in large-scale distributed systems, cloud computing platforms, and high-frequency interactive scenarios, where user behavior and access operations are highly diverse and dynamically evolving. Traditional access control methods struggle to meet the requirements of real-time, intelligent, and adaptable security. Access control no longer relies solely on static permission configuration and preset rules; it requires the introduction of new mechanisms such as behavior modeling and risk awareness.

[0003] In existing technologies, role-based access control, policy-based access control, or anomaly detection methods based on historical auditing are commonly used. Although these methods have certain effects in specific applications, they still have the following significant shortcomings when faced with challenges such as the interweaving of multi-dimensional data features, the rapid evolution of access behavior, and the high hidden nature of anomaly risks:

[0004] 1. Lack of deep behavioral modeling mechanism: Most existing methods fail to establish a systematic behavioral evolution map and lack modeling of the temporal evolution and linkage characteristics of user behavior states.

[0005] 2. Inability to implement dynamic risk feedback control: Traditional access control solutions are mostly based on static rules. Once set, it is difficult to achieve adaptive adjustments based on access context, behavioral trends, and risk status.

[0006] 3. Rough response path selection mechanism: Existing path determination or response mechanisms are mostly based on simple threshold determination or rule matching, and do not introduce synaptic connection mechanisms or winner-take-all competition strategies.

[0007] 4. Low utilization of behavioral data: Traditional log recording methods only provide static archiving and do not incorporate mechanisms such as compression coding, high-dimensional information fusion, and behavioral trajectory marking.

[0008] Therefore, how to provide a system security access control method based on deep learning and dynamic risk perception is an urgent problem that technicians in this field need to solve. Summary of the Invention

[0009] One purpose of the present invention is to propose a system security access control method based on deep learning and dynamic risk perception. The present invention adopts access behavior state vector modeling, behavior evolution graph construction, Hebbian learning mechanism and Winner-Take-All competition mechanism, and describes in detail the steps of realizing access control decision path generation, risk dynamic adjustment and behavior path adaptive update. It has the advantages of high risk identification accuracy, high degree of intelligent response decision and strong adaptability of behavior evolution.

[0010] According to an embodiment of the present invention, a system security access control method based on deep learning and dynamic risk perception includes the following steps:

[0011] Collect the user's identity characteristics, operation content, device status and context information in the access request, and generate a vector to represent the behavior state;

[0012] Based on the behavior state vector, a visit behavior evolution graph is constructed. The nodes in the visit behavior evolution graph represent the visit behavior state vector, and the edges represent the synaptic connection relationship between the visit behavior states. The weight values ​​of the synaptic connection relationship are updated according to the historical visit behavior data through the Hebbian learning rule.

[0013] In the behavior evolution graph, synaptic connection paths that have a synaptic connection relationship with the current access behavior state vector are selected, and the corresponding activation potential value of each synaptic connection path is calculated to form a set of candidate access response paths;

[0014] A Winner-Take-All selection mechanism is applied to the candidate access response path set. Each access response path in the candidate access response path set is subjected to competition based on the activation potential value, and only the access response path with the largest activation potential value is selected as the access control decision path.

[0015] Execute access control operations according to the access control decision path, and generate access risk tags and behavior evolution tags based on the access behavior state vector and the access control decision path. The access risk tag indicates the risk status of the access request, and the behavior evolution tag indicates the change trend of the behavior path.

[0016] Adjusting the response threshold for selecting a set of candidate access response paths based on the access risk tag, and updating the weight value of the corresponding synaptic connection relationship in the access behavior evolution graph based on the behavior evolution tag;

[0017] The access behavior state vector, access control decision path, access risk mark and behavior evolution mark are compressed and encoded and recorded in the access behavior log. The access behavior log includes an information set for access path tracking.

[0018] Optionally, collecting the user's identity characteristics, operation content, device status, and context information in the access request includes the following steps:

[0019] Extracting user identity features, which include the user's unique identity identifier, the user behavior profile vector generated based on historical access behavior clustering, and the user's visitor group label;

[0020] Analyze the access operation content, which includes the current access target object identifier, access intent label, access command mode, and behavior similarity score with previous operation sequences;

[0021] Record device status information, including the type tag of the access device, operating stability indicators, real-time load status, and communication delay between the device and the central system;

[0022] Obtain context information, including the timestamp of the access request, geographic location information, a summary of the currently running task stack of the operating system, and the environmental context label of the access behavior;

[0023] The above-mentioned information is numerically encoded according to the preset feature dimension mapping rules to construct the access behavior state vector.

[0024] Optionally, an access behavior evolution graph is constructed based on the access behavior state vector, and the weight values ​​of synaptic connection relationships are updated using the Hebbian learning rule according to historical access behavior data. Specifically, the following steps are performed:

[0025] Multiple access behavior state vectors are respectively established as access behavior nodes, and the access behavior node is used to represent the state information of a single access behavior at a specific time point;

[0026] Establishing a synaptic connection between access behavior state vectors having a synaptic connection relationship, the synaptic connection is used to connect two access behavior nodes, and setting an initial synaptic connection weight value for each synaptic connection, the initial synaptic connection weight value is used to represent the initial behavior linkage strength between the corresponding access behavior nodes;

[0027] Construct an access behavior evolution graph, which includes a set of access behavior nodes, a set of synaptic connections, and a set of synaptic connection weight values. The access behavior evolution graph is stored in the form of a graph structure, which records the synaptic connection paths between access behavior nodes and their corresponding synaptic connection weight values.

[0028] Extracting an access behavior state vector sequence from historical access behavior data, where the access behavior state vector sequence consists of multiple access behavior state vectors arranged in chronological order;

[0029] Identifying the synaptic connection paths corresponding to each pair of adjacent access behavior state vectors in the access behavior state vector sequence in the access behavior evolution graph, and using the synaptic connection paths as activated synaptic connection paths;

[0030] The synaptic connection weight values ​​corresponding to the activated synaptic connection paths are updated based on the Hebbian learning rule. The application of the Hebbian learning rule is based on the co-activation event of the current access behavior state vector pair. The degree of behavioral association of the activated synaptic connection paths is strengthened by increasing the synaptic connection weight values.

[0031] The updated synaptic connection weight value is written into the synaptic connection weight value set in the access behavior evolution graph for subsequent construction of the access response path set and generation of access control decisions based on the access behavior evolution graph.

[0032] Optionally, the Hebbian learning rule specifically includes:

[0033] Identify whether the access behavior state vector pair and the corresponding access behavior nodes in the access behavior evolution graph constitute a continuous activation state. If the activation interval between two access behavior nodes in the access behavior state vector sequence is within a set time range, mark the two access behavior nodes as a neuron co-activation event.

[0034] Obtaining the activation time interval Δt between the access behavior nodes constituting the neuron co-activation event, and comparing the activation time interval Δt with a preset time gating threshold to determine whether the synaptic connection path meets the synaptic connection weight value update condition;

[0035] Under the premise that the synaptic connection weight value can be updated, it is determined whether there is a synaptic connection between the access behavior nodes that constitute the neuron co-activation event. If there is a synaptic connection, the corresponding synaptic connection is marked as a synaptic connection path that is allowed to be updated;

[0036] Perform a time-gated weight update operation on the synaptic connection weight values ​​corresponding to the synaptic connection paths that are allowed to be updated:

[0037] Δw ij =η·a i ·a j g(Δt);

[0038] Where Δw ij represents the update amount of the synaptic connection weight value between the access behavior node i and the access behavior node j, η represents the learning rate, a i and a j They represent the activation values ​​of the access behavior node i and the access behavior node j respectively, and g(Δt) is the time gating function;

[0039] The updated synaptic connection weight value is written into the synaptic connection weight value set in the access behavior evolution graph, and the above steps are repeated in the training cycle of the subsequent access behavior state vector sequence until the synaptic connection weight value converges to the set stable range.

[0040] Optionally, selecting synaptic connection paths that have a synaptic connection relationship with the current access behavior state vector in the behavior evolution graph, and calculating corresponding activation potential values ​​for each synaptic connection path to form a candidate access response path set specifically includes:

[0041] Determine the access behavior node corresponding to the current access behavior state vector in the access behavior evolution graph, and retrieve all synaptic connection paths starting from the access behavior node;

[0042] Determine whether the synaptic connection weight value corresponding to each synaptic connection path is greater than the synaptic connection weight threshold, and whether the target access behavior node connected by the synaptic connection path has multiple associated records in the historical access behavior state vector sequence;

[0043] If the synaptic connection weight value is greater than the synaptic connection weight threshold and the target access behavior node has multiple associated records in the historical access behavior state vector sequence, the corresponding synaptic connection path is added to the candidate access response path set;

[0044] For each synaptic connection path in the candidate access response path set, determine the activation potential value of the corresponding synaptic connection path based on the activation state value of the current access behavior node, the synaptic connection weight value of the synaptic connection path, and the number of occurrences of the target access behavior node in the historical access behavior state vector sequence;

[0045] The candidate access response path set and the activation potential value corresponding to each synaptic connection path in the candidate access response path set are written into the access control response module for subsequent access control decision generation based on the Winner-Take-All selection mechanism.

[0046] Optionally, applying the Winner-Take-All selection mechanism to the candidate access response path set and generating an access control decision path includes the following steps:

[0047] Extracting the activation potential value corresponding to each synaptic connection path in the candidate access response path set, and constructing a potential vector set containing all activation potential values;

[0048] Normalizing the potential vector set to obtain a normalized activation potential value set, where the normalized activation potential value is used to represent the relative activation strength of the synaptic connection path;

[0049] Set the Winner-Take-All competition threshold, screen the synaptic connection paths whose normalized activation potential values ​​are not lower than the Winner-Take-All competition threshold, and the screening results constitute the competition path subset;

[0050] In the subset of competing pathways, the synaptic connection pathway with the largest normalized activation potential value is identified and marked as the preferred access response pathway;

[0051] Constructing an access control decision path based on the access behavior nodes and their sequence relationship contained in the preferred access response path. The access control decision path is a unique path sequence connecting the starting access behavior node and the target access behavior node.

[0052] The access control decision path is output to the access control execution module, and the access control decision path and its corresponding normalized activation potential value are recorded together in the access behavior log. The access behavior log is used for subsequent behavior auditing and risk analysis.

[0053] Optionally, performing access control operations according to the access control decision path and generating access risk tags and behavior evolution tags based on the access behavior state vector and the access control decision path specifically include:

[0054] Extracting the synaptic connection path between the starting access behavior node and the target access behavior node in the access control decision path, and determining the access control policy type corresponding to the synaptic connection path;

[0055] Execute corresponding access control operations based on the access control policy type. Access control operations include allowing access, denying access, restricting access, and requesting multi-factor authentication.

[0056] Perform a joint analysis of the access behavior state vector and the access control decision path, calculate the behavior deviation between the access behavior state vector and the target access behavior node, and determine the risk level of the access request based on the behavior deviation;

[0057] Generate an access risk tag based on the risk level of the access request. The access risk tag is used to indicate whether there are potential threats and abnormal patterns in the access behavior;

[0058] Detect the changing trend of the synaptic connection weight values ​​in the access control decision path, and evaluate the evolution direction and magnitude of the behavior path based on the update frequency of the access behavior state vector;

[0059] Generate a behavior evolution mark based on the change trend of the synaptic connection weight value and the change rate of the access behavior state vector. The behavior evolution mark represents the structural adjustment characteristics of the behavior path in the behavior evolution map.

[0060] The access risk label and the behavior evolution label are respectively bound to a current access behavior state vector and recorded in an access behavior log.

[0061] Optionally, the adjusting the response threshold for selecting the candidate access response path set based on the access risk label and updating the weight value of the corresponding synaptic connection relationship in the access behavior evolution graph based on the behavior evolution label specifically includes:

[0062] Extracting a risk level parameter contained in the access risk label, and judging whether the risk level parameter is higher than a risk adjustment condition corresponding to a response threshold currently used for screening the candidate access response path set;

[0063] When the risk level parameter meets the risk adjustment condition, adjusting the response threshold used for screening the candidate access response path set according to the numerical magnitude of the risk level, and the adjustment mode includes increasing the response threshold to narrow the acceptable path range, or reducing the response threshold to expand the path coverage range;

[0064] Obtaining a behavior evolution label generated by the access control operation, and identifying a path structure change trend indicated in the behavior evolution label, including a change frequency of a synaptic connection path, an adjustment direction of a path topology, and an evolution trajectory of a behavior node;

[0065] Based on the path structure change trend reflected in the behavior evolution label, determining a synaptic connection path related to the corresponding change trend in the access behavior evolution graph, and updating a synaptic connection weight value corresponding to the synaptic connection path, and the updating mode includes strengthening a stable path connection or weakening a non-stable path connection;

[0066] Writing the updated response threshold into an access response path selection module, and writing the updated synaptic connection weight value into a synaptic connection weight value set in the access behavior evolution graph.

[0067] Optionally, the compressively encoding and recording the access behavior state vector, the access control decision path, the access risk label, and the behavior evolution label into the access behavior log specifically includes:

[0068] Extracting all feature dimension information in the access behavior state vector, the access control decision path, the access risk label, and the behavior evolution label, and performing standardized representation according to a pre-defined data structure definition, and mapping each type of information into a structured vector group;

[0069] For redundant fields and high-frequency repeated fragments contained in the structured vector group, a local pattern extraction method based on a hash index is applied, the repeated fragments are replaced with corresponding compressed symbol mappings, and a compressed structure unit is formed;

[0070] Arrange the formed compression structure units in order of access time to construct a unified compressed information sequence, and embed index tags in the sequence to indicate the starting position and range limit of each information type;

[0071] Based on a unified compressed information sequence, a variable-length coding algorithm with reversible mapping is applied to perform overall compression processing on the access behavior state vector, access control decision path, access risk marker, and behavior evolution marker to form a compressed coding result.

[0072] The compression coding result is written into the access behavior log. The access behavior log is a time series structure used to record the information set generated by each access request, including the compression coding result, timestamp index and auxiliary identification field for access path tracking.

[0073] The beneficial effects of the present invention are:

[0074] (1) The present invention introduces a behavioral state vector modeling method based on deep learning, combines the access behavior evolution graph construction mechanism with the Hebbian learning rule, and improves the system's ability to perceive the temporal evolution of user access behavior. This enables the system to dynamically adapt to the changing trend of access behavior and enhance the self-learning ability of synaptic connection weights, thereby effectively identifying potential threats and abnormal paths in diverse operating environments.

[0075] (2) By introducing activation potential value calculation and Winner-Take-All competition mechanism into access response path screening, the present invention significantly improves the discrimination accuracy and response efficiency of access control paths, avoids misjudgments and missed judgments caused by traditional static matching strategies, and realizes accurate response and judgment of access requests in high-risk scenarios.

[0076] (3) The present invention combines the compression coding and recording mechanism of access control decision paths, access risk markers and behavior evolution markers to construct a log system for behavior evolution and risk dynamic tracking. It not only supports subsequent behavior retrospective analysis, but also drives the dynamic adjustment of response thresholds and synaptic connection weights through risk markers, thereby realizing continuous adaptation and evolutionary updates of the system access control strategy, and improving the overall security defense initiative and intelligence of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0078] Figure 1 This is a flowchart of the system security access control method based on deep learning and dynamic risk perception proposed by the present invention. DETAILED DESCRIPTION

[0079] The present invention will now be described in further detail with reference to the accompanying drawings, which are simplified schematic diagrams that illustrate the basic structure of the present invention in a schematic manner.

[0080] refer to Figure 1 , a system security access control method based on deep learning and dynamic risk perception includes the following steps:

[0081] Collect the user's identity characteristics, operation content, device status and context information in the access request, and generate a vector to represent the behavior state;

[0082] Based on the behavior state vector, a visit behavior evolution graph is constructed. The nodes in the visit behavior evolution graph represent the visit behavior state vector, and the edges represent the synaptic connection relationship between the visit behavior states. The weight values ​​of the synaptic connection relationship are updated according to the historical visit behavior data through the Hebbian learning rule.

[0083] In the behavior evolution graph, synaptic connection paths that have a synaptic connection relationship with the current access behavior state vector are selected, and the corresponding activation potential value of each synaptic connection path is calculated to form a set of candidate access response paths;

[0084] A Winner-Take-All selection mechanism is applied to the candidate access response path set. Each access response path in the candidate access response path set is subjected to competition based on the activation potential value, and only the access response path with the largest activation potential value is selected as the access control decision path.

[0085] Execute access control operations according to the access control decision path, and generate access risk tags and behavior evolution tags based on the access behavior state vector and the access control decision path. The access risk tag indicates the risk status of the access request, and the behavior evolution tag indicates the change trend of the behavior path.

[0086] Adjusting the response threshold for selecting a set of candidate access response paths based on the access risk tag, and updating the weight value of the corresponding synaptic connection relationship in the access behavior evolution graph based on the behavior evolution tag;

[0087] The access behavior state vector, access control decision path, access risk mark and behavior evolution mark are compressed and encoded and recorded in the access behavior log. The access behavior log includes an information set for access path tracking.

[0088] In this embodiment, collecting the user's identity characteristics, operation content, device status, and context information in the access request includes the following steps:

[0089] Extracting user identity features, which include the user's unique identity identifier, the user behavior profile vector generated based on historical access behavior clustering, and the user's visitor group label;

[0090] Analyze the access operation content, which includes the current access target object identifier, access intent label, access command mode, and behavior similarity score with previous operation sequences;

[0091] Record device status information, including the type tag of the access device, operating stability indicators, real-time load status, and communication delay between the device and the central system;

[0092] Obtain context information, including the timestamp of the access request, geographic location information, a summary of the currently running task stack of the operating system, and the environmental context label of the access behavior;

[0093] The above-mentioned information is numerically encoded according to the preset feature dimension mapping rules to construct the access behavior state vector.

[0094] This implementation method extracts the user's unique identity, behavior profile vector, and access group label, and combines the access operation content, device status information, and contextual environment elements to comprehensively characterize the user's multi-dimensional behavioral characteristics in a specific access request. It then uses feature dimension mapping rules to encode them into a unified access behavior state vector, integrating identity characteristics, operation motivations, and environmental information in a unified data structure. This significantly enhances the accuracy and context-awareness of subsequent behavior modeling and risk analysis, and provides a comprehensive and detailed input basis for the construction of dynamic evolution graphs and access control strategies.

[0095] In this embodiment, the access behavior evolution graph is constructed based on the access behavior state vector, and the weight value of the synaptic connection relationship is updated by the Hebbian learning rule according to the historical access behavior data. Specifically, the following steps are performed:

[0096] Multiple access behavior state vectors are respectively established as access behavior nodes, and the access behavior node is used to represent the state information of a single access behavior at a specific time point;

[0097] Establishing a synaptic connection between access behavior state vectors having a synaptic connection relationship, the synaptic connection is used to connect two access behavior nodes, and setting an initial synaptic connection weight value for each synaptic connection, the initial synaptic connection weight value is used to represent the initial behavior linkage strength between the corresponding access behavior nodes;

[0098] construct an access behavior evolution graph, the access behavior evolution graph comprising an access behavior node set, a synapse connection set and a synapse connection weight value set, the access behavior evolution graph being stored in a graph structure, the graph structure recording a synapse connection path between access behavior nodes and a corresponding synapse connection weight value;

[0099] extract an access behavior state vector sequence from historical access behavior data, the access behavior state vector sequence comprising a plurality of access behavior state vectors arranged in time sequence;

[0100] identify, in the access behavior evolution graph, a synapse connection path corresponding to each pair of adjacent access behavior state vectors in the access behavior state vector sequence, and take the synapse connection path as an activated synapse connection path;

[0101] update a synapse connection weight value corresponding to the activated synapse connection path based on a Hebbian learning rule, wherein application of the Hebbian learning rule is premised on a cooperative activation event of a current pair of access behavior state vectors, and the behavior correlation degree of the activated synapse connection path is strengthened by increasing the synapse connection weight value;

[0102] write the updated synapse connection weight value into the synapse connection weight value set in the access behavior evolution graph, for subsequent access response path set construction and access control decision generation based on the access behavior evolution graph.

[0103] The embodiment is based on access behavior state vectors to construct an access behavior evolution graph, each access behavior state vector is modeled as an access behavior node, and a synapse connection path is established by identifying the cooperative activation relationship between time sequences. The initial synapse connection weight value is set to quantify the behavior linkage strength between nodes. In the access process, the synapse connection path formed by adjacent nodes is dynamically identified from the historical behavior sequence, and the weight value of these paths is updated by applying the Hebbian learning rule, thereby continuously strengthening the potential evolution law between real access behaviors. This mechanism not only preserves the time sequence structure characteristics of user access behaviors, but also accumulates behavior correlation knowledge through dynamic learning of graph weights, realizes continuous optimization and intelligent evolution of access paths, and improves the linkage adaptation ability and risk identification precision of the access control system.

[0104] In the embodiment, the Hebbian learning rule specifically comprises:

[0105] identify whether the access behavior nodes corresponding to the pair of access behavior state vectors in the access behavior evolution graph constitute a continuous activation state, if the activation interval time of the two access behavior nodes in the access behavior state vector sequence is within a set time range, mark the two access behavior nodes as a neuron co-activation event;

[0106] an activation time interval Δt between the access behavior nodes constituting the neuron co-activation event is obtained, and the activation time interval Δt is compared with a preset time gating threshold to determine whether a synaptic connection path meets a synaptic connection weight value updateable condition;

[0107] Under the premise of meeting the synaptic connection weight value updateable condition, it is determined whether there is a synaptic connection between the access behavior nodes constituting the neuron co-activation event, and if there is a synaptic connection, the corresponding synaptic connection is marked as an allowed synaptic connection path for update;

[0108] A time-gated weight update operation is performed on the synaptic connection weight value corresponding to the allowed synaptic connection path for update:

[0109] Δw ij =η·a i ·a j ·g(Δt);

[0110] wherein Δw ij represents an update amount of the synaptic connection weight value between the access behavior node i and the access behavior node j, η represents a learning rate, a i and a j respectively represent activation values of the access behavior node i and the access behavior node j, and g(Δt) is a time gating function.

[0111] The formula is used to perform an update operation of the synaptic connection weight value between the access behavior nodes, and embodies a weight adjustment mechanism combining neuron co-activation strength and time-dependent relationship, the core principle of which is based on the Hebbian learning rule, that is, when two access behavior nodes are continuous in time and have significant activation values, the connection weight between them should be enhanced, so as to reflect the behavior linkage trend. Meanwhile, the time gating function is introduced, so that the connection strengthening only occurs when the activation event time interval meets a specific condition, thereby avoiding the interference of irrelevant or incidental behaviors on the graph structure. The method not only strengthens the correlation degree between real access paths, but also improves the expression ability of the access behavior graph on time evolution, has good biological inspiration and actual adaptability, and embodies significant creativity.

[0112] The updated synaptic connection weight value is written into a synaptic connection weight value set in the access behavior evolution graph, and the above steps are continuously repeated in a training period of a subsequent access behavior state vector sequence until the synaptic connection weight value converges to a set stable range.

[0113] This embodiment identifies the continuous activation states of access behavior state vectors in the access behavior evolution graph, and introduces a time gating mechanism based on the activation time interval Δt to screen the synaptic connection paths, thereby performing a Hebbian learning update operation with time-dependent characteristics to achieve dynamic adjustment of the synaptic connection weight values. Specifically, after determining that the access behavior node constitutes a neuron co-activation event and meets the gating conditions, a reinforcement learning update is performed to enhance the correlation strength between the behavior nodes, and the results are written into the access behavior evolution graph to continuously optimize the behavior representation structure. This embodiment effectively constructs a time-sensitive linkage mechanism between behaviors, enhances the ability of the behavior evolution graph to express dynamic access behavior trends, and helps the system to more accurately identify potential attack paths and high-risk behavior sequences, thereby enhancing the system's real-time security prevention and control capabilities in complex access scenarios.

[0114] In this embodiment, selecting synaptic connection paths that have a synaptic connection relationship with the current access behavior state vector in the behavior evolution graph, calculating the corresponding activation potential value for each synaptic connection path, and forming a candidate access response path set specifically includes:

[0115] Determine the access behavior node corresponding to the current access behavior state vector in the access behavior evolution graph, and retrieve all synaptic connection paths starting from the access behavior node;

[0116] Determine whether the synaptic connection weight value corresponding to each synaptic connection path is greater than the synaptic connection weight threshold, and whether the target access behavior node connected by the synaptic connection path has multiple associated records in the historical access behavior state vector sequence;

[0117] If the synaptic connection weight value is greater than the synaptic connection weight threshold and the target access behavior node has multiple associated records in the historical access behavior state vector sequence, the corresponding synaptic connection path is added to the candidate access response path set;

[0118] For each synaptic connection path in the candidate access response path set, determine the activation potential value of the corresponding synaptic connection path based on the activation state value of the current access behavior node, the synaptic connection weight value of the synaptic connection path, and the number of occurrences of the target access behavior node in the historical access behavior state vector sequence;

[0119] The candidate access response path set and the activation potential value corresponding to each synaptic connection path in the candidate access response path set are written into the access control response module for subsequent access control decision generation based on the Winner-Take-All selection mechanism.

[0120] This implementation method constructs a mapping relationship between the access behavior state vector in the access behavior evolution graph, identifies the corresponding access behavior node, and uses the node as the starting point to screen the synaptic connection paths with synaptic connection weight values ​​higher than the set threshold and with associated access history, thereby dynamically generating a set of candidate access response paths; combining the activation state, synaptic connection weight value and historical occurrence frequency of the current access behavior node, calculates the activation potential value and submits it to the access control response module, forming a response path competition mechanism with association strength judgment and historical evolution considerations, providing efficient and accurate support for subsequent Winner-Take-All-based path screening, and significantly improving the intelligence and timeliness of the access control strategy.

[0121] In this embodiment, applying the Winner-Take-All selection mechanism to the candidate access response path set and generating an access control decision path includes the following steps:

[0122] Extracting the activation potential value corresponding to each synaptic connection path in the candidate access response path set, and constructing a potential vector set containing all activation potential values;

[0123] Normalizing the potential vector set to obtain a normalized activation potential value set, where the normalized activation potential value is used to represent the relative activation strength of the synaptic connection path;

[0124] Set the Winner-Take-All competition threshold, screen the synaptic connection paths whose normalized activation potential values ​​are not lower than the Winner-Take-All competition threshold, and the screening results constitute the competition path subset;

[0125] In the subset of competing pathways, the synaptic connection pathway with the largest normalized activation potential value is identified and marked as the preferred access response pathway;

[0126] Constructing an access control decision path based on the access behavior nodes and their sequence relationship contained in the preferred access response path. The access control decision path is a unique path sequence connecting the starting access behavior node and the target access behavior node.

[0127] The access control decision path is output to the access control execution module, and the access control decision path and its corresponding normalized activation potential value are recorded together in the access behavior log. The access behavior log is used for subsequent behavior auditing and risk analysis.

[0128] This embodiment calculates the activation potential value of each synaptic connection path in the candidate access response path set and constructs it into a unified potential vector set. It uses normalization processing to improve the comparability of activation strength between paths, and selects the preferred path with the highest activation potential value as the access control decision path under the set Winner-Take-All competition mechanism; submits the path to the access control execution module and records it together with its normalized activation potential value in the access behavior log, which not only realizes intelligent decision-making of access control paths, but also provides high-quality data support for subsequent behavior auditing and risk tracking, thereby improving the system's response speed and judgment accuracy to abnormal access.

[0129] In this embodiment, the access control operation is performed according to the access control decision path, and the access risk mark and the behavior evolution mark are generated based on the access behavior state vector and the access control decision path. Specifically, the following steps are included:

[0130] Extracting the synaptic connection path between the starting access behavior node and the target access behavior node in the access control decision path, and determining the access control policy type corresponding to the synaptic connection path;

[0131] Execute corresponding access control operations based on the access control policy type. Access control operations include allowing access, denying access, restricting access, and requesting multi-factor authentication.

[0132] Perform a joint analysis of the access behavior state vector and the access control decision path, calculate the behavior deviation between the access behavior state vector and the target access behavior node, and determine the risk level of the access request based on the behavior deviation;

[0133] Generate an access risk tag based on the risk level of the access request. The access risk tag is used to indicate whether there are potential threats and abnormal patterns in the access behavior;

[0134] Detect the changing trend of the synaptic connection weight values ​​in the access control decision path, and evaluate the evolution direction and magnitude of the behavior path based on the update frequency of the access behavior state vector;

[0135] Generate a behavior evolution mark based on the change trend of the synaptic connection weight value and the change rate of the access behavior state vector. The behavior evolution mark represents the structural adjustment characteristics of the behavior path in the behavior evolution map.

[0136] The access risk tag and behavior evolution tag are respectively bound to the current access behavior state vector and recorded in the access behavior log.

[0137] This implementation jointly analyzes the access behavior state vector and the access control decision path, calculates the behavior deviation to determine the risk level of the access request, and generates a corresponding access risk tag. At the same time, it monitors the changing trend of the synaptic connection weight value, and generates a behavior evolution tag in combination with the state vector update frequency, thereby achieving accurate labeling of the risk level and evolution direction of the access behavior. This method not only realizes the dynamic adjustment of the access strategy, but also constructs a continuously traceable access behavior evolution archive by binding the tag information to the behavior state vector and recording it in the log, effectively enhancing the system's recognition sensitivity and response intelligence to risky behaviors.

[0138] In this embodiment, adjusting the response threshold for selecting the candidate access response path set based on the access risk mark and updating the weight value of the corresponding synaptic connection relationship in the access behavior evolution graph based on the behavior evolution mark specifically include:

[0139] Extracting the risk level parameter contained in the access risk tag, and determining whether the risk level parameter is higher than the risk adjustment condition corresponding to the response threshold currently used to screen the candidate access response path set;

[0140] When the risk level parameter meets the risk adjustment condition, the response threshold used for screening the candidate access response path set is adjusted according to the numerical amplitude of the risk level. The adjustment method includes increasing the response threshold to narrow the range of acceptable paths, or decreasing the response threshold to expand the path coverage range;

[0141] Obtaining the behavior evolution mark generated by the access control operation and identifying the path structure change trend indicated in the behavior evolution mark, including the change frequency of the synaptic connection path, the adjustment direction of the path topology, and the evolution trajectory of the behavior node;

[0142] Based on the path structure change trend reflected in the behavior evolution mark, determine the synaptic connection path related to the corresponding change trend in the access behavior evolution map, and update the synaptic connection weight value corresponding to the synaptic connection path, including strengthening the stable path connection or weakening the unstable path connection;

[0143] The updated response threshold is written into the access response path selection module, and the updated synaptic connection weight value is written into the synaptic connection weight value set in the access behavior evolution graph.

[0144] This implementation achieves real-time adaptive adjustment of access control policies by extracting risk level parameters from access risk tags and dynamically adjusting response thresholds during access response path screening. At the same time, combined with behavioral evolution tags generated by access control operations, the structural change trends of synaptic connection paths in the access behavior evolution graph are analyzed, and the weight values ​​of associated synaptic connections are updated in a targeted manner to strengthen stable connections and suppress abnormal paths, thereby achieving dynamic optimization of access policies and continuous evolution of behavioral models. This approach effectively improves the system's response sensitivity and risk prevention and control capabilities to complex access behaviors, and enhances the intelligence and robustness of the overall access control system.

[0145] In this embodiment, compressing and encoding the access behavior state vector, the access control decision path, the access risk mark, and the behavior evolution mark and recording them in the access behavior log specifically includes:

[0146] Extract all characteristic dimension information from access behavior state vectors, access control decision paths, access risk markers, and behavior evolution markers, and standardize their representation based on the preset data structure definition, mapping each type of information into a structured vector group.

[0147] For the redundant fields and high-frequency repeated segments contained in the structured vector group, a local pattern extraction method based on hash index is applied to replace the repeated segments with corresponding compression symbol mappings to form a compressed structure unit;

[0148] Arrange the formed compression structure units in order of access time to construct a unified compressed information sequence, and embed index tags in the sequence to indicate the starting position and range limit of each information type;

[0149] Based on a unified compressed information sequence, a variable-length coding algorithm with reversible mapping is applied to perform overall compression processing on the access behavior state vector, access control decision path, access risk marker, and behavior evolution marker to form a compressed coding result.

[0150] The compression coding result is written into the access behavior log. The access behavior log is a time series structure used to record the information set generated by each access request, including the compression coding result, timestamp index and auxiliary identification field for access path tracking.

[0151] This implementation method extracts all characteristic information from the access behavior state vector, access control decision path, access risk tag and behavior evolution tag, uses the local pattern extraction method of hash index to replace and compress high-frequency redundant fragments, and combines the time sequence and index tags to construct a unified compressed information sequence, and then applies the reversible variable-length coding algorithm for overall compression. Finally, the result is written into the time series access behavior log, thereby effectively improving the storage efficiency and retrieval speed of massive access records, realizing structured retention and rapid backtracking of access history, and providing a lightweight, efficient and scalable data support foundation for subsequent risk tracing and behavior analysis.

[0152] Example 1:

[0153] To verify the feasibility of the present invention in practice, it was applied to the data command center of a critical information infrastructure. The center processes over 100,000 system access requests per day, involving key business operations such as user authentication, remote command issuance, system log management, and policy scheduling. Due to the high sensitivity of system resources, complex attacks such as disguised access, multi-stage intrusion, and privilege escalation have frequently occurred in recent years. The existing security control methods based on rule matching or blacklist and whitelist mechanisms cannot meet the high requirements for real-time performance, adaptability, and evolutionary recognition capabilities. Therefore, the center decided to deploy the method of the present invention to upgrade the core access control logic.

[0154] In actual deployment, the system collects user identity features, operation content, device status and context information contained in access requests through the access layer to build a behavior state vector input model. All access requests are captured and represented by the model before entering the network and are connected to the constructed access behavior evolution graph as access behavior nodes.

[0155] After constructing the evolutionary graph, the system trains it using six months of historical access behavior log data, applying the Hebbian learning rule to update the weights of synaptic connection paths. During graph training, the system identifies the continuous activation relationships and activation intervals between access behavior nodes to determine whether they represent neuronal co-activation events. Based on the weight update formula, the system then performs a time-gated update of synaptic connection weights. The updated graph retains the memory and dynamic evolution capabilities of access behavior patterns.

[0156] When an actual access occurs, the system selects synaptic connection paths with synaptic connections in the graph based on the current access behavior state vector, calculates the activation potential value of each path, and thus generates a set of candidate access response paths. The Winner-Take-All mechanism is used to determine the unique access control decision path through normalization processing and competitive path selection. This path is then used to determine the final response action of this access request, such as allowing, rejecting, or triggering multi-factor authentication.

[0157] After each control operation is completed, the system simultaneously generates access risk markers and behavioral evolution markers. The former assesses access deviation and potential threats, while the latter records changes in behavioral path weights and evolutionary trends. These markers act inversely on the response threshold and graph structure weight update process, ensuring the system's adaptive adjustment capabilities.

[0158] All access behavior state vectors, decision paths, and tag data are uniformly represented by a standard vector structure and written into the access behavior log after hash index compression and variable-length encoding, forming a traceable behavioral evidence chain and providing data support for post-audit, attack and defense drills, and model optimization.

[0159] To verify the performance advantages of the above-mentioned method, a comparative experiment was conducted between the present invention and traditional rule-based access control methods. The three-month experiment was conducted on the core control platform of the data command center network. The experimental subjects included 50 critical business servers, deployed with both a traditional policy control system and the present invention. Comparison criteria included response latency, risk identification accuracy, false rejection rate, and system resource consumption.

[0160] Table 1 Comparison of access control performance under different methods

[0161]

[0162]

[0163] Experimental data shows that compared to traditional control methods, the proposed method improves average response speed by 43.7%, increases risk identification accuracy by 13.5 percentage points, and significantly reduces false rejection rate by 82.8%. It also possesses real-time rule evolution capabilities, with only a slight increase in system resource overhead. The compressed recording mechanism effectively reduces log storage pressure. In an actual attack drill scenario, the proposed system successfully intercepted a simulated permission bypass attack and accurately identified a multi-stage abnormal behavior chain with time-dependent characteristics, verifying its dynamic perception and precise interception capabilities for complex behavior patterns.

[0164] In a certain application, an internal user with advanced access rights suddenly initiated a batch export operation through a new device at night. The system identified that the state vector of this behavior deviated significantly from the historical behavior. Combined with the dramatic fluctuations in the weights of the synaptic connections in the behavior path, the system generated a high-risk access risk tag in real time and adjusted the response threshold from 0.45 to 0.65. Ultimately, the access request was blocked and the multi-factor authentication process was initiated, effectively avoiding potential data leakage.

[0165] In summary, the method of the present invention realizes deep semantic modeling, dynamic evolution analysis and intelligent access control of access behavior in actual deployment. Through the neural synaptic connection mechanism and risk feedback loop, it breaks through the static limitations of traditional rule systems, and has the advantages of structural adaptation, autonomous learning and real-time response, providing a reliable, efficient and intelligent solution for secure access control of critical infrastructure.

[0166] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.

Claims

1. A system security access control method based on deep learning and dynamic risk perception, characterized by: The following steps are involved: Collect the user's identity characteristics, operation content, device status and context information in the access request, and generate a behavior state vector; Build an access behavior evolution graph based on the behavior state vector, and update the weight value of the synaptic connection relationship through the Hebbian learning rule according to the historical access behavior data; In the behavior evolution graph, synaptic connection paths that have a synaptic connection relationship with the current access behavior state vector are selected, and the corresponding activation potential value of each synaptic connection path is calculated to form a set of candidate access response paths; Applying a Winner-Take-All selection mechanism to the candidate access response path set, and performing a competitive process on each access response path in the candidate access response path set based on the activation potential value; Execute access control operations according to the access control decision path, and generate access risk tags and behavior evolution tags based on the access behavior state vector and the access control decision path; Adjusting the response threshold for selecting a set of candidate access response paths based on the access risk tag, and updating the weight value of the corresponding synaptic connection relationship in the access behavior evolution graph based on the behavior evolution tag; The access behavior state vector, access control decision path, access risk marker, and behavior evolution marker are compressed and encoded and recorded in the access behavior log.

2. The system security access control method based on deep learning and dynamic risk perception according to claim 1 is characterized in that: The access behavior evolution graph is constructed based on the access behavior state vector, and the weight values ​​of the synaptic connection relationships are updated through the Hebbian learning rule according to the historical access behavior data. Specifically, Multiple access behavior state vectors are respectively established as access behavior nodes, and the access behavior node is used to represent the state information of a single access behavior at a specific time point; Establishing a synaptic connection between the access behavior state vectors having a synaptic connection relationship, the synaptic connection is used to connect two access behavior nodes, and setting an initial synaptic connection weight value for each synaptic connection; Construct an access behavior evolution graph, which includes a set of access behavior nodes, a set of synaptic connections, and a set of synaptic connection weight values. The access behavior evolution graph is stored in the form of a graph structure, which records the synaptic connection paths between access behavior nodes and their corresponding synaptic connection weight values. Extracting an access behavior state vector sequence from historical access behavior data, where the access behavior state vector sequence consists of multiple access behavior state vectors arranged in chronological order; Identifying the synaptic connection paths corresponding to each pair of adjacent access behavior state vectors in the access behavior state vector sequence in the access behavior evolution graph, and using the synaptic connection paths as activated synaptic connection paths; The synaptic connection weight values ​​corresponding to the activated synaptic connection paths are updated based on the Hebbian learning rule. The application of the Hebbian learning rule is based on the co-activation event of the current access behavior state vector pair. The degree of behavioral association of the activated synaptic connection paths is strengthened by increasing the synaptic connection weight values. The updated synaptic connection weight value is written into the synaptic connection weight value set in the access behavior evolution graph.

3. The system security access control method based on deep learning and dynamic risk perception according to claim 2 is characterized in that: The Hebbian learning rule specifically includes: Identify whether the access behavior state vector pair and the corresponding access behavior nodes in the access behavior evolution graph constitute a continuous activation state. If the activation interval between two access behavior nodes in the access behavior state vector sequence is within a set time range, mark the two access behavior nodes as a neuron co-activation event. Obtaining the activation time interval Δt between the access behavior nodes constituting the neuron co-activation event, and comparing the activation time interval Δt with a preset time gating threshold to determine whether the synaptic connection path meets the synaptic connection weight value update condition; Under the premise that the synaptic connection weight value can be updated, it is determined whether there is a synaptic connection between the access behavior nodes that constitute the neuron co-activation event. If there is a synaptic connection, the corresponding synaptic connection is marked as a synaptic connection path that is allowed to be updated; Performing a time-gated weight update operation on the synaptic connection weight values ​​corresponding to the synaptic connection paths that are allowed to be updated; The updated synaptic connection weight value is written into the synaptic connection weight value set in the access behavior evolution graph.

4. The system security access control method based on deep learning and dynamic risk perception according to claim 1 is characterized in that: The selecting of synaptic connection paths having a synaptic connection relationship with the current access behavior state vector in the behavior evolution graph, and calculating corresponding activation potential values ​​for each synaptic connection path to form a candidate access response path set specifically includes: Determine the access behavior node corresponding to the current access behavior state vector in the access behavior evolution graph, and retrieve all synaptic connection paths starting from the access behavior node; Determine whether the synaptic connection weight value corresponding to each synaptic connection path is greater than the synaptic connection weight threshold, and whether the target access behavior node connected by the synaptic connection path has multiple associated records in the historical access behavior state vector sequence; If the synaptic connection weight value is greater than the synaptic connection weight threshold and the target access behavior node has multiple associated records in the historical access behavior state vector sequence, the corresponding synaptic connection path is added to the candidate access response path set; For each synaptic connection path in the candidate access response path set, the activation potential value of the corresponding synaptic connection path is determined based on the activation state value of the current access behavior node, the synaptic connection weight value of the synaptic connection path, and the number of appearances of the target access behavior node in the historical access behavior state vector sequence.

5. The system security access control method based on deep learning and dynamic risk perception according to claim 1 is characterized in that: Applying the Winner-Take-All selection mechanism to the candidate access response path set and generating an access control decision path specifically includes: Extracting the activation potential value corresponding to each synaptic connection path in the candidate access response path set, and constructing a potential vector set containing all activation potential values; Normalizing the potential vector set to obtain a normalized activation potential value set, where the normalized activation potential value is used to represent the relative activation strength of the synaptic connection path; Set the Winner-Take-All competition threshold, screen the synaptic connection paths whose normalized activation potential values ​​are not lower than the Winner-Take-All competition threshold, and the screening results constitute the competition path subset; In the subset of competing pathways, the synaptic connection pathway with the largest normalized activation potential value is identified and marked as the preferred access response pathway; An access control decision path is constructed based on the access behavior nodes and their sequence relationship contained in the preferred access response path. The access control decision path is a unique path sequence connecting the starting access behavior node and the target access behavior node.

6. The system security access control method based on deep learning and dynamic risk perception according to claim 1 is characterized in that: Access control operations are performed according to the access control decision path, and access risk tags and behavior evolution tags are generated based on the access behavior state vector and the access control decision path. Specifically, the following are included: Extracting the synaptic connection path between the starting access behavior node and the target access behavior node in the access control decision path, and determining the access control policy type corresponding to the synaptic connection path; Execute corresponding access control operations based on the access control policy type. Access control operations include allowing access, denying access, restricting access, and requesting multi-factor authentication. Perform a joint analysis of the access behavior state vector and the access control decision path, calculate the behavior deviation between the access behavior state vector and the target access behavior node, and determine the risk level of the access request based on the behavior deviation; Generate an access risk tag based on the risk level of the access request. The access risk tag is used to indicate whether there are potential threats and abnormal patterns in the access behavior; Detect the changing trend of the synaptic connection weight values ​​in the access control decision path, and evaluate the evolution direction and magnitude of the behavior path based on the update frequency of the access behavior state vector; A behavior evolution mark is generated according to the change trend of the synaptic connection weight value and the change rate of the access behavior state vector. The behavior evolution mark represents the structural adjustment characteristics of the behavior path in the behavior evolution map.

7. The system security access control method based on deep learning and dynamic risk perception according to claim 1 is characterized in that: The adjusting of the response threshold for selecting the candidate access response path set based on the access risk mark and the updating of the weight value of the corresponding synaptic connection relationship in the access behavior evolution graph based on the behavior evolution mark specifically include: Extracting the risk level parameter contained in the access risk tag, and determining whether the risk level parameter is higher than the risk adjustment condition corresponding to the response threshold currently used to screen the candidate access response path set; When the risk level parameter satisfies the risk adjustment condition, the response threshold for screening the candidate access response path set is adjusted according to the numerical magnitude of the risk level; Obtaining the behavior evolution mark generated by the access control operation, and identifying the path structure change trend indicated in the behavior evolution mark; Based on the path structure change trend reflected in the behavior evolution mark, the synaptic connection path related to the corresponding change trend in the access behavior evolution map is determined, and the synaptic connection weight value corresponding to the synaptic connection path is updated.

Citation Information

Cited By

  • Power grid data security protection method and system

    CN121770902A