Network terminal security agent method, device, computer equipment and storage medium
By using a network terminal security proxy method, trusted authentication and dynamic security protection of terminal identities are achieved, solving the problems of over-generalization of trust and lag in protection in traditional terminal protection models, and providing a terminal security monitoring and protection solution for complex network systems.
Patent Information
- Application Number
- CN202511422637.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-09-30
AI Technical Summary
Traditional endpoint protection relies on a "perimeter protection + static trust" model, which leads to over-generalization of trust, lagging protection, inability to cope with zero-day vulnerabilities and advanced persistent threats, and vulnerability of endpoints to infection, resulting in the spread of malicious code. This makes it difficult to meet the security needs of digital transformation.
By employing a network endpoint security proxy approach, and deploying security proxy clients and proxy servers, trusted identity authentication is performed, a security baseline vector is constructed, endpoint status is monitored and analyzed in real time, response and recovery action plans are generated, security policies are dynamically adjusted, and multiple security components work together to handle threats.
It achieves trusted authentication of terminal identity, dynamically protects terminal environment and behavior, supports multi-agent collaborative linkage to form closed-loop security protection, and is suitable for terminal security monitoring and protection in complex network systems.
Smart Images

Figure CN120896796B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network information security technology, and in particular to network terminal security proxy methods, devices, computer equipment and storage media. Background Technology
[0002] As digital transformation progresses across industries, traditional perimeter protection models are becoming increasingly inadequate in addressing new types of cyber threats. Numerous endpoints are scattered across branches and outlets, and operator roles are complex (frontline operators, suppliers, administrators, etc.). External or internal attackers can easily breach the traditional "three-piece set" of defenses—firewalls, antivirus software, and intrusion detection systems—through endpoint devices (such as tampered business software or unauthorized peripherals), threatening the security of core network systems.
[0003] Traditional endpoint protection relies on the "perimeter protection + static trust" model, which has the following core flaws: over-generalization of trust, once an endpoint is authenticated, it gains full trust, allowing attackers to move laterally using compromised endpoints; lagging protection, relying on post-incident detection, which cannot deal with zero-day vulnerabilities and advanced persistent threats (APTs); and endpoints becoming a weak link, as dispersed endpoints lack unified management and are easily breached by malicious peripherals and tampered software.
[0004] Once an endpoint is infected, malicious code can spread through the trusted network to core servers, triggering the "weakest link" effect and causing incidents such as data leaks and network paralysis. Traditional perimeter-based add-on network security architectures are no longer sufficient to meet the needs of digital transformation, and effective means are needed to prevent disasters caused by unintentional or unauthorized endpoint operations. Summary of the Invention
[0005] To address the aforementioned technical problems, this invention provides a network terminal security proxy method, employing the following technical solution, including:
[0006] This includes a security agent client deployed on the endpoint system and a proxy server deployed in the security management center, comprising the following steps:
[0007] Trusted identity authentication is performed on network terminals and user identities accessing the system. Once authentication is successful, the security agent collects multi-dimensional terminal information.
[0008] Based on the multi-dimensional terminal information, a security baseline vector is constructed for each terminal through AI machine learning.
[0009] The terminal's current real-time data is converted into a state vector that can be compared with the security baseline vector. The vector deviation between the state vector and the security baseline vector is calculated, and the vector deviation is analyzed.
[0010] Based on the analysis of the vector deviation, combined with the knowledge base and AI reasoning, specific and executable response and recovery action plan documents are automatically generated, transforming abstract security threats into specific operational instructions;
[0011] The security agent coordinates the execution of the operation instructions issued by the proxy server and works in conjunction with multiple security components to process the operation instructions;
[0012] Based on the state vector after processing, the security baseline vector is dynamically adjusted so that the system can learn from each security event and continuously optimize.
[0013] Preferably, the step of performing trusted identity authentication on the network terminal and user identity of the access system, and then having the security agent collect multi-dimensional terminal information after successful authentication, specifically includes:
[0014] When the agent client starts or reconnects, multi-factor fusion authentication is performed on both the terminal device itself and the operating user.
[0015] After successful identity authentication, the security agent collects static, dynamic, and behavioral data of the terminal according to a predetermined policy;
[0016] The collected heterogeneous data is standardized in format and then compressed and encrypted through a secure channel before being reported to the proxy server.
[0017] Preferably, the step of constructing a security baseline vector for each terminal based on the multi-dimensional terminal information and through AI machine learning specifically includes:
[0018] The multi-dimensional terminal information is associated and integrated, and features are extracted.
[0019] Based on the extracted features, the security baseline vector is constructed for each terminal using AI machine learning.
[0020] Preferably, the step of converting the terminal's current real-time data into a state vector that can be compared with the security baseline vector, calculating the vector deviation between the state vector and the security baseline vector, and analyzing the vector deviation specifically includes:
[0021] Process the real-time data stream continuously reported by the security agent;
[0022] The processed real-time data stream is transformed into a state vector that can be compared with the security baseline vector;
[0023] Calculate the vector deviation between the state vector and the safety baseline vector, analyze the vector deviation, and determine the risk level and trigger alarms.
[0024] Preferably, the step of automatically generating specific and executable response and recovery action plan documents based on the analysis results of the vector deviation, combined with a knowledge base and AI reasoning, and transforming abstract security threats into specific operational instructions, specifically includes:
[0025] Based on the analysis of the vector deviation, and combined with the knowledge base and AI reasoning, the cause of the deviation is inferred.
[0026] Based on the inferred causes of the deviation, select the most appropriate single or multiple actions from the response measure library and arrange their execution order;
[0027] The planned response measures are packaged into specific response recovery action plan operation instructions.
[0028] Preferably, the step of the security agent collaboratively executing the operation instructions issued by the proxy server and coordinating with multiple security components to handle the operation instructions specifically includes:
[0029] The security agent receives the action plan from the server via the YD-SOMN protocol and performs parsing and verification.
[0030] The security agent invokes or notifies other security software to coordinate and link multiple security components to jointly execute security operation instructions.
[0031] The execution results and the post-execution system status are fed back to the proxy server, forming a closed loop.
[0032] Preferably, the step of dynamically adjusting the security baseline vector based on the processed state vector, enabling the system to learn from each security event and continuously optimize, specifically includes:
[0033] Within a preset time period after the response action is executed, the real-time status vector of the terminal is continuously monitored, the deviation between the status vector after the action and the safety baseline vector is calculated, and it is confirmed whether the risk score has been reduced to below the safety threshold.
[0034] If it is confirmed that the risk score has dropped below the safety threshold, the stable state vector after the treatment is used as a new normal sample to update the safety baseline vector.
[0035] To address the aforementioned technical problems, this invention also provides a network terminal security proxy device, comprising a security proxy client deployed on a terminal system and a proxy server deployed in a security management center, employing the following technical solution:
[0036] The data collection module is used to perform trusted identity authentication on network terminals and user identities accessing the system. Once authentication is successful, the security agent collects multi-dimensional terminal information.
[0037] A construction module is used to build a security baseline vector for each terminal based on the multi-dimensional terminal information and through AI machine learning.
[0038] The analysis module is used to convert the terminal's current real-time data into a state vector that can be compared with the security baseline vector, calculate the vector deviation between the state vector and the security baseline vector, and analyze the vector deviation.
[0039] The generation module is used to automatically generate specific and executable response and recovery action plan documents based on the results of the analysis of the vector deviation, combined with the knowledge base and AI reasoning, thereby transforming abstract security threats into specific operational instructions;
[0040] The processing module is used to coordinate with the security agent to execute the operation instructions issued by the proxy server, and to coordinate with multiple security components to process the operation instructions.
[0041] The optimization module is used to dynamically adjust the security baseline vector based on the processed state vector, so that the system can learn from each security event and continuously optimize.
[0042] To address the aforementioned technical problems, the present invention also provides a computer device that employs the technical solution described below, comprising a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the aforementioned network terminal security proxy method.
[0043] To address the aforementioned technical problems, the present invention also provides a computer-readable storage medium, which employs the technical solution described below. The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the aforementioned network terminal security proxy method.
[0044] Compared with existing technologies, the present invention has the following main advantages: It ensures the trustworthiness of terminal network identities based on PKI identity authentication, enabling trusted terminal identity authentication; it generates dynamic security baselines based on static configuration management and dynamic workflows, achieving security protection for the terminal environment and behavior; it supports collaborative linkage of multiple security components such as agents based on a unified security policy of the security management center; it features a closed-loop execution process of trusted identity authentication—state and behavior detection—baseline generation—task planning and response recovery; and it can guarantee the security of terminal identities, environments, and behaviors, making it suitable for security monitoring and protection applications of PC terminals, mobile terminals, cloud terminals, IoT terminals, etc., in complex network systems. Attached Figure Description
[0045] To more clearly illustrate the solutions in this invention, the accompanying drawings used in the description of the embodiments of this invention will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0046] Figure 1 This is a flowchart of an embodiment of the network terminal security proxy method of the present invention;
[0047] Figure 2 This is an exemplary system architecture diagram in which the present invention can be applied;
[0048] Figure 3 This is a flowchart of the security proxy operation used in the network terminal security proxy method of the present invention;
[0049] Figure 4 This is a schematic diagram of the structure of an embodiment of the network terminal security proxy device of the present invention;
[0050] Figure 5 This is a schematic diagram of the structure of an embodiment of the computer device of the present invention. Detailed Implementation
[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the specification is for the purpose of describing particular embodiments only and is not intended to limit the invention; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings are used to distinguish different objects and not to describe a particular order.
[0052] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0053] To enable those skilled in the art to better understand the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings.
[0054] It should be noted that the network terminal security proxy method provided in the embodiments of the present invention is generally executed by a server / terminal device, and correspondingly, the network terminal security proxy device is generally set in the server / terminal device.
[0055] It should be understood that the number of terminal devices, networks, and servers is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be used.
[0056] Example 1
[0057] Please refer to Figure 1 The flowchart illustrates an embodiment of the network terminal security proxy method of the present invention. The network terminal security proxy method includes the following steps:
[0058] Step S1: Perform trusted identity authentication on the network terminals and user identities accessing the system. Once authentication is successful, the security agent collects multi-dimensional terminal information.
[0059] In this embodiment, the electronic device (e.g., a server / terminal device) on which the network terminal security proxy method runs can receive network terminal security proxy requests via wired or wireless connection. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAXX connections, Zigbee connections, UWB (ultra-wideband) connections, and other currently known or future-developed wireless connection methods.
[0060] The purpose of step S1 is to ensure the legitimacy of the terminals and users accessing the system and to provide a comprehensive and high-quality data source for subsequent analysis.
[0061] Multidimensional terminal information includes, but is not limited to, static, dynamic, and behavioral data of the terminal.
[0062] In this embodiment, step S1, which involves performing trusted identity authentication on the network terminal and user identity accessing the system, and then having the security agent collect multi-dimensional terminal information after successful authentication, may specifically include the following steps:
[0063] S11 performs multi-factor fusion authentication on both the terminal device and the user when the agent client starts up or reconnects.
[0064] Authentication can be performed using a two-way certificate authentication method: using the PKI system, the security agent and the proxy server exchange digital certificates to verify the identities of both parties.
[0065] Then, hardware fingerprint binding is performed, collecting the unique identifier of the terminal hardware (such as the key in the TPM chip, CPU serial number, motherboard ID, etc.) and binding it with the terminal certificate to prevent the certificate from being copied to other devices.
[0066] Biometric identification of user behavior, integrating behavioral biometric analysis (such as keystroke rhythm and mouse movement pattern), can be used as a continuous or secondary authentication method in addition to passwords.
[0067] The purpose of step S11 is to ensure the trustworthiness of the access entity and prevent unauthorized terminals or users from impersonating others to access the network.
[0068] S12: After successful identity authentication, the security agent collects static, dynamic, and behavioral data of the terminal according to a predetermined strategy.
[0069] Collect static configuration information by calling operating system APIs (such as WMI for Windows, sysfs / proc for Linux), reading the registry, and scanning the list of installed software to obtain information such as system version, patch status, installed applications, service configuration, and network configuration.
[0070] Monitor real-time status information, including system performance counters (CPU, memory, disk, network traffic), process list, network connection status, login session information, etc.
[0071] Terminal workflow behavior is recorded using lightweight EDR technology, which records serialized behavioral data such as process creation chains, file access sequences, network access destinations and ports to characterize the user's normal operating habits.
[0072] In practice, state and behavior detection can utilize the firewall, intrusion detection, vulnerability scanning, configuration management, security isolation, and network measurement functions provided by the tool engine integrated into the security management center to detect the terminal environment, terminal behavior, and real-time operational status information of the terminal. Specifically, this includes:
[0073] Static configuration information of the terminal environment: CPU and memory parameters, storage information, operating system information, file system information, installed components, services, applications, network card configuration, hardware and software interface configuration, etc.
[0074] Terminal behavior information: User behavior, including user login and logout operations, business system startup and logout operations, database access and other behaviors; System behavior, including system upgrades, service startup and shutdown, etc.; Network behavior, including network connection establishment, port access, IP address access, data transmission, etc.
[0075] Real-time status information: mainly includes real-time recorded system logs, CPU and memory utilization, real-time network communication traffic, user status, service running status, business application status, etc.
[0076] The purpose of step S12 is to allow the security agent to collect the terminal's static, dynamic, and behavioral data comprehensively and with low interference, according to a predetermined strategy, after successful identity authentication.
[0077] S13 unifies the format of the collected heterogeneous data and reports it to the proxy server after compression and encryption through a secure channel.
[0078] Build a data standardization engine to format the collected raw data according to a predefined schema (such as JSON Schema, Protocol Buffers) and unify timestamps, field names and numerical units.
[0079] Perform data compression and encryption, using efficient compression algorithms such as Zstandard or LZ4 to reduce bandwidth consumption. Utilize the encryption module built into the YD-SOMN protocol (such as AES-GCM-based symmetric encryption) to encrypt the data.
[0080] Set up reliable transmission mechanisms, such as ACK confirmation and breakpoint resumption mechanisms, to ensure that data can be delivered to the proxy server completely and orderly even in unreliable network environments.
[0081] The purpose of step S13 is to unify the format of the collected heterogeneous data, compress and encrypt it through a secure channel, and then report it to the proxy server to ensure the integrity, confidentiality, and availability of the data.
[0082] In practice, trusted identity authentication primarily relies on hardware cryptographic machines, hardware USB digital certificates, and PKI+CPK authentication methods to ensure the trustworthiness of network terminal users, devices, and other entities. The specific methods are as follows:
[0083] Leveraging the PKI and other cryptographic infrastructure systems of the security management center, the system provides corresponding functions such as password generation, encryption / decryption algorithms, and X.509 / CPK authentication. The security agent scans the USB hardware card to identify and verify the inserted hardware USB node card device information, ensuring the legitimacy of the terminal in the network. It primarily uses a hardware-level trusted root identity anchoring mechanism (a root trusted key generated by the agent server's CA center). This is achieved by binding the physical node card (USB-KEY number) and the terminal device's fingerprint (PIN code) together, forming the basis for generating a digital certificate. The agent server's certification center generates the digital certificate key information, which is then embedded in the hardware USB card, ensuring a one-to-one correspondence between the device and the USB card. X.509 two-way authentication, CPK authentication, and challenge-response methods are employed to authenticate the terminal device and user, ensuring the trustworthiness of the terminal device, user, and node.
[0084] Step S2: Based on the multi-dimensional terminal information, construct a security baseline vector for each terminal through AI machine learning.
[0085] The purpose of step S2 is to use the historical data collected in step S1 to build a dynamic and personalized security baseline vector for each terminal (or similar terminal group) through AI machine learning, rather than relying on a rigid and uniform compliance policy.
[0086] In this embodiment, step S2, which involves constructing a security baseline vector for each terminal based on the multi-dimensional terminal information using AI machine learning, may specifically include the following steps:
[0087] S21, the multi-dimensional terminal information is associated and integrated, and feature extraction is performed.
[0088] First, data association is performed using graph databases or association rules to link entities such as processes, files, network connections, and users, forming a terminal behavior graph.
[0089] Then feature extraction is performed: statistical features (such as the startup frequency of a process in a specific time period, average network traffic), temporal features (such as the periodicity of the behavior pattern), and semantic features (such as whether the accessed file path is sensitive) are extracted from the behavior sequence.
[0090] Finally, feature vectorization is performed: the extracted features are quantified and combined into a high-dimensional feature vector, which is then used as input to the AI model.
[0091] The purpose of step S21 is to correlate and integrate the reported static, dynamic, and behavioral data, and extract features that are meaningful for distinguishing between normal and abnormal behaviors.
[0092] S22, Based on the extracted features, construct the security baseline vector for each terminal through AI machine learning.
[0093] Clustering algorithms such as K-Means and DBSCAN are used to cluster historical behavioral data, and frequently co-occurring behavioral patterns are identified as normal clusters.
[0094] Anomaly detection algorithms, such as support vector machines or isolated forests, are used to establish a boundary model of the normal range, and data points outside the boundary are considered anomalies.
[0095] A safety baseline vector is generated by saving the core parameters of the learned normal patterns (such as cluster centers, model weights, and behavior rules) to form the safety baseline vector for the terminal. This vector is dynamic and can be updated periodically.
[0096] In practice, external compliance requirements such as industry standards and corporate security strategies can be intelligently integrated into the dynamic baseline generated by AI to form a customized security baseline that takes into account both individual behavioral habits and organizational security requirements.
[0097] If a policy rule engine is used, compliance requirements (such as "must install a certain antivirus software" or "prohibit the use of FTP protocol") can be encoded into executable rules.
[0098] Knowledge graph fusion is performed to integrate compliance policies with behavioral graphs learned by AI. For example, server nodes that are prohibited from access by compliance policies should be marked as high-risk in the baseline, even if they appear to be common operations.
[0099] The weighted baseline vector assigns weights to different feature dimensions in the baseline vector. Features related to compliance requirements have higher weights to ensure the mandatory nature of the policy.
[0100] In some optional implementations of this embodiment, baseline generation is primarily based on an AI engine, employing a fusion of static configuration management and dynamic workflow information. Based on a five-layer knowledge graph comprising "compliance standards - terms - asset type static configuration items - dynamic workflow," corresponding integrated security baseline information is generated as training data (training library) for the AIGC model. The specific method for generating security baselines through AI training is as follows:
[0101] Step 1: Perform compliance information analysis.
[0102] The compliance clause parsing module analyzes standard documents such as Cybersecurity Classified Protection 2.0, Closed-Loop Protection, and Confidentiality Assessment, breaking down natural language clauses (such as "auditing of important user operations should be implemented") into quantifiable configuration items (such as "audit scope: administrator login, file permission modification; audit content: operator, time, IP, operation result"). Quantifiable configuration items are represented by the following symbols:
[0103] , .
[0104] Step 2: Generate a static configuration baseline.
[0105] A static configuration baseline is generated based on the static configuration information of the terminal environment, and is represented by the following symbols: , .
[0106] Step 3: Workflow baseline generation.
[0107] Based on the terminal behavior information, a workflow baseline is generated, represented by the following symbols: .
[0108] Step 4: Generate the basic security baseline.
[0109] By integrating compliance information, static baselines, and workflow baselines, a security baseline is generated:
[0110] .
[0111] Specifically, the generation is based on the AIGC model, which is based on the Transformer architecture. To address the challenge of understanding long texts generated using the security baseline, the following optimizations are made:
[0112] First, optimize the activation function.
[0113] The activation function in the original model's feedforward network (FFN) is replaced from ReLU with the Mish activation function, as shown in the formula: ,in, The output of the activation function. : Input value, Hyperbolic tangent function : Softplus function, i.e. , : Natural constant (approximately 2.71828).
[0114] The smooth non-linearity of the Mish activation function improves upon the problem of ReLU discarding all negative values, which leads to all zeros in the model output. Compared to the Swish function, Mish has no parameters and is easier to use when performance is similar.
[0115] Secondly, loss function optimization is performed.
[0116] The original model uses the autoregressive cross-entropy loss function, which suffers from exposure bias. The optimization method is as follows:
[0117] During training, using probability Using real preceding tokens, with probability Use the preceding token generated by the model. Probability As the number of training steps decreases linearly from 1 to 0, the model gradually adapts to the scenario of "continuing to generate with its own predictions," narrowing the gap between training and inference.
[0118] Third, optimize the normalization layer.
[0119] The original model's LayerNorm (layer normalization) is changed to RMSNorm (root mean square normalization), with the following formula: ,in, Input vector, Dimension of a vector : The root mean square value of the input vector A very small positive number (e.g.) This is used to prevent the denominator from being zero and to increase numerical stability. : Learnable scaling parameter vector (gain). : The sum of squares of the elements of a vector.
[0120] RMSNorm omits the learnable offset parameter in LayerNorm. It uses a mean calculation method, which requires less computation and is suitable for computationally intensive safety baseline generation models.
[0121] Using the generated AIGC model, information is collected from the security agent terminal. Automatically generate the corresponding security baseline The main steps in the mission planning and response recovery phase are as follows:
[0122] First, establish a security proxy connection: the security proxy is interconnected with the proxy server of the security management and control platform integrated with the security management center.
[0123] Next, information is reported: the terminal agent reports the generated baseline information and real-time status information to the agent server.
[0124] Finally, risk analysis and strategy generation are performed: the proxy server combines the system network composition and the security requirements of business applications to comprehensively analyze the system risk situation and security posture, and generate security protection strategies.
[0125] The specific steps are as follows: Generate a state vector based on real-time state information:
[0126] Calculate the baseline vector With state vector The angle between : ,in, : Angle between the baseline vector and the state vector (unit: degrees). :vector and dot product, :vector The modulus (norm). :vector The modulus (norm). Inverse cosine function.
[0127] According to the included angle Determine the risk level and initiate response strategies: If Risk is acceptable; no response will be given. Low-level risk: Initiate Level III response strategy (block the risk-related processes and services for the corresponding user, and close the corresponding port). If... Medium risk; activate Level II response strategy (block the corresponding user's access permissions and isolate the user). High risk: Initiate Level I response strategy (block the network connection of the corresponding risk terminal and isolate the risk terminal).
[0128] Policy delivery: The proxy server delivers security policies to the terminal system and related collaborative security components such as firewalls and network isolation systems to execute corresponding response measures.
[0129] Closed-loop execution: The endpoint security agent and security components accept the security policy and collaboratively execute response measures. After execution, they continuously check whether the risk is within an acceptable range. If it is not met, the risk is continuously reported to the proxy server for cyclical protection and control until the overall system security risk is under control.
[0130] The purpose of step S22 is to automatically learn the normal behavior patterns of the terminal and generate a baseline model without pre-labeling malicious samples. This is crucial for discovering unknown threats.
[0131] Step S3: Convert the current real-time data of the terminal into a state vector that can be compared with the security baseline vector, calculate the vector deviation between the state vector and the security baseline vector, and analyze the vector deviation.
[0132] The purpose of step S3 is to convert the terminal's current real-time data into a state vector that can be compared with the baseline, and to calculate the degree of deviation from the normal baseline through a scientific algorithm, thereby quantifying the terminal's security risks.
[0133] In this embodiment, step S3, which involves converting the terminal's current real-time data into a state vector that can be compared with the security baseline vector, calculating the vector deviation between the state vector and the security baseline vector, and analyzing the vector deviation, may specifically include the following steps:
[0134] S31 processes the real-time data stream continuously reported by the security agent.
[0135] Stream processing engines such as Flink or Spark Streaming are used to perform real-time aggregation, filtering, and windowing calculations on the reported events.
[0136] Perform real-time feature calculations, applying the same feature engineering logic as when generating the baseline, but operating on the real-time data stream to calculate the feature values for the current window period.
[0137] Construct a state vector by combining the real-time calculated feature values into a real-time state vector with the same dimension as the safety baseline vector.
[0138] The purpose of step S31 is to quickly process the real-time data stream continuously reported by the security agent and generate a snapshot of the current moment.
[0139] S32, the processed real-time data stream is transformed into a state vector that can be compared with the security baseline vector.
[0140] Distance metric algorithms can be used to calculate the distance between the state vector and the baseline vector in high-dimensional space. Algorithms used include, but are not limited to, Euclidean distance, cosine similarity, and Mahalanobis distance (which can consider the correlation between features).
[0141] Alternatively, a probability estimation algorithm can be used to calculate the probability of the current state vector appearing based on the probability model (such as a Gaussian mixture model) established during the baseline generation stage. The lower the probability, the higher the deviation.
[0142] Then, a weighted comprehensive score is calculated. Combining the weights set in step S23, the deviation of different feature dimensions is weighted and averaged to obtain a comprehensive risk score (e.g., 0-100 points).
[0143] The purpose of step S32 is to quantitatively assess the difference between the real-time status and the safety baseline, and to obtain a quantifiable risk score.
[0144] S33, calculate the vector deviation between the state vector and the safety baseline vector, analyze the vector deviation, and determine the risk level and trigger an alarm.
[0145] Threshold setting and dynamic adjustment: preset risk thresholds (e.g., low risk: <30, medium risk: 30-70, high risk: >70). The thresholds can also be dynamically adjusted based on historical false alarms to reduce noise.
[0146] Perform alarm correlation and aggregation, using rule engines or complex event processing methods to aggregate multiple related low-level alarms into a single high-level event (such as "abnormal login attempt following port scan"), thereby improving alarm quality.
[0147] The alarm information is encapsulated by packaging information such as deviation score, triggering feature dimension, and associated process / user into a structured alarm event for further decision-making.
[0148] The function of step S33 is to classify the current security status of the terminal according to the deviation score, and to determine whether a security alarm needs to be generated and the level of the alarm.
[0149] Step S4: Based on the analysis results of the vector deviation, combined with the knowledge base and AI reasoning, a specific and executable response and recovery action plan document is automatically generated, transforming the abstract security threat into specific operational instructions.
[0150] In this embodiment, step S4, based on the analysis results of the vector deviation, and combined with the knowledge base and AI inference, automatically generates a specific and executable response and recovery action plan document, transforming the abstract security threat into specific operational instructions. This may specifically include the following steps:
[0151] S41. Based on the analysis of the vector deviation, and in conjunction with the knowledge base and AI reasoning, the cause of the deviation is inferred.
[0152] First, attack chain mapping is performed, matching alarm information with attack frameworks such as Cyber Kill Chain and MITRE ATT&CK to identify the stage the attacker is in and the tactics and techniques they are using.
[0153] Then, a graph database query is performed. In the terminal behavior graph, the graph is traversed starting from the alarm entity to find the suspicious parent process, network connection, etc. associated with it, and to locate the root cause.
[0154] Then, a causal reasoning model is constructed, and a lightweight causal discovery algorithm is applied to analyze the causal relationships between multiple alarm events and identify the core problem points.
[0155] The purpose of step S41 is to analyze alarm events, infer the root cause of deviations, and provide a basis for accurate response.
[0156] S42, based on the inferred causes of the deviation analysis, select the most suitable single or multiple actions from the response measure library and arrange their execution order.
[0157] The SOAR script library is used to predefine response scripts for different attack scenarios. For example, the "ransomware response script" includes steps such as isolating the network, terminating the process, and creating file backups.
[0158] The platform integrates tool engines and command-line or API interfaces for various security tools, such as firewalls, EDR, and vulnerability scanners, to ensure that the generated plans can be executed.
[0159] An action orchestrator is used to arrange the actions of multiple tools according to their dependencies and execution conditions, forming a directed acyclic graph workflow based on script logic.
[0160] The purpose of step S42 is to select the most suitable single or multiple actions from the response measure library based on the root cause analysis results, and to arrange their execution order.
[0161] S43 encapsulates the prepared response measures into specific response recovery action plan operation instructions.
[0162] Practical plan generation templates can be used to describe action plans using standard JSON or XML templates, including information such as target terminal, actions to be performed, parameters, and execution order.
[0163] Conduct business impact analysis, and combine CMDB (Configuration Management Database) information to determine whether response actions (such as restarting services or isolating networks) will affect critical business operations, and provide an impact scope assessment.
[0164] The purpose of step S43 is to encapsulate the orchestrated response measures into a specific response and recovery action plan, and to estimate the potential impact of the plan on business, ensuring that the response action does not outweigh the security incident itself.
[0165] Step S5: The security agent coordinates with the agent server to execute the operation instructions issued by the agent server and works in conjunction with multiple security components to process the operation instructions.
[0166] The purpose of step S5 is to ensure that the action plan issued by the proxy server can be executed accurately and reliably by the security proxy, and to coordinate with other security components on the terminal to complete the response task.
[0167] In this embodiment, step S5, where the security agent collaboratively executes the operation instructions issued by the proxy server, and coordinates with multiple security components to process the operation instructions, may specifically include the following steps:
[0168] S51, the security agent receives the action plan from the server via the YD-SOMN protocol and performs parsing and verification.
[0169] The secure communication client implements the client portion of the YD-SOMN protocol, responsible for receiving encrypted policy files and performing decryption and integrity verification.
[0170] A policy parser is used to parse the action plan JSON / XML file and convert it into instruction objects that the security agent can understand.
[0171] Perform permission and security checks, examine the signature of the command to ensure its source is trustworthy, and verify whether the content of the command is within the scope of the agent's permissions to prevent the execution of malicious commands.
[0172] S52, the security agent calls or notifies other security software to coordinate and link multiple security components to jointly execute security operation instructions.
[0173] Using local API calls, functions can be directly invoked through the operating system's security center API or the open APIs of third-party security software (such as adding firewall rules through the Windows Filtering Platform).
[0174] Inter-process communication (IPC) mechanisms such as named pipes and sockets are used to communicate with other security daemons and transmit instructions.
[0175] Execute system commands. For basic operations (such as terminating a process or disabling an account), directly execute system commands with the corresponding permissions.
[0176] The purpose of step S52 is to invoke or notify other security software (such as personal firewalls, host intrusion prevention systems (HIPS), and antivirus software) to jointly perform security actions.
[0177] S53 feeds back the execution results and the system status after execution to the proxy server, forming a closed loop.
[0178] Using a command executor, the security agent builds a secure command execution environment to prevent vulnerabilities such as command injection.
[0179] Execution status monitoring: Monitor the execution status (in progress, successful, failed) of each action in real time.
[0180] The results are sent back, and the execution result log and the system snapshot after execution (such as whether the process was terminated or whether the network connection was disconnected) are reported to the server again through the YD-SOMN protocol.
[0181] Step S6: Based on the processed state vector, dynamically adjust the security baseline vector so that the system can learn from each security event and continuously optimize.
[0182] In this embodiment, step S6, dynamically adjusting the security baseline vector based on the processed state vector, so that the system can learn from each security event and continuously optimize, may specifically include the following steps:
[0183] S61, within a preset time period after the response action is executed, continuously monitor the real-time status vector of the terminal, calculate the deviation between the status vector after the action and the safety baseline vector, and confirm whether the risk score has dropped below the safety threshold.
[0184] The purpose of step S61 is to assess whether the response action plan has successfully eliminated the threat and restored the endpoint to normal status.
[0185] Perform post-event status monitoring, continuously monitoring the terminal's real-time status vector within a preset time period, such as one week, after the response action is executed.
[0186] The deviation is recalculated to determine the degree of deviation between the post-treatment state vector and the baseline, and to confirm whether the risk score has been reduced to below the safety threshold.
[0187] Use the validation rule engine to define validation rules, such as "do not reappear after process termination" or "abnormal external connections disappear", and automatically determine whether the handling was successful.
[0188] S62, if it is confirmed that the risk score has dropped below the safety threshold, then the stable state vector after the treatment is used as a new normal sample to update the safety baseline vector.
[0189] Using online learning or incremental learning algorithms, new normal data is input into the baseline AI model, and the model parameters are fine-tuned without retraining the entire model, allowing the baseline to evolve over time.
[0190] Update the knowledge base by storing the attack patterns and effective response measures of this incident as new cases to enrich the system's experience.
[0191] Perform baseline version management, version control of security baseline vectors, and allow rollback to the previous stable version when problems occur during baseline updates.
[0192] In practical implementation, further strategy optimization and iteration can be carried out to summarize the efficiency of the entire handling process, optimize response scripts and threshold settings, and improve the level and speed of automation in dealing with similar events in the future: analyze the complete event log from alarm to recovery to find bottlenecks or redundant steps in the process; use A / B testing and simulation to test the new response strategy in a sandbox environment, compare its effect with the old strategy, and select the best one for deployment; then perform meta-strategy adjustment, and automatically adjust global risk judgment thresholds, alarm aggregation rules and other meta-strategy parameters based on historical data to achieve system self-optimization.
[0193] Figure 2 This is an exemplary system architecture diagram in which the present invention can be applied. For example... Figure 2 As shown, the main modules and their main functions are described below:
[0194] The physical terminals suitable for security agent installation mainly include PC terminals, mobile terminals, cloud terminals, and IoT terminals, providing terminal operating systems and corresponding computing environments.
[0195] The security agent installed on the aforementioned terminal performs a closed-loop security protection function, cyclically executing identity authentication, state and behavior detection, baseline generation, task planning, and response recovery. This corresponds to four modules: authenticator, detector, generator, and executor, which are interconnected and interact with the PKI cryptographic infrastructure, tool engine, AI engine, and proxy server, respectively.
[0196] The authenticator implements sub-functions of user authentication, device authentication, and node authentication;
[0197] The detector implements sub-functions of terminal environment detection, behavior detection, and state detection by calling an integrated toolset;
[0198] The generator implements sub-functions such as static configuration baseline generation, workflow generation, and safe baseline generation that integrates static configuration and workflow by calling the AI engine;
[0199] The actuator connects and interacts with the agent server of the security management center to achieve sub-functions of collaborative control and response recovery. This includes reporting the information required by the agent server, receiving security control policies and corresponding response measures issued by the agent server, and automatically responding to security events and alarms and restoring the system to reduce terminal risks to an acceptable level.
[0200] The security management center, interconnected with the endpoint security agent, integrates PKI-based cryptographic infrastructure, tool engine, AI engine, and proxy servers related to security management and control.
[0201] The cryptographic infrastructure provides cryptographic support services for the PKI system, mainly including modules such as the Security Authentication System (CA), Certificate Distribution and Management System (RA), Key Management Center (KMC), Certificate / Revocation List Storage and Distribution System (LDAP), and cryptographic machines. It features functions such as user application, application review, certificate issuance, certificate revocation, key management, user management, and system management. It can perform cryptographic services such as certificate application, certificate distribution, certificate download, certificate revocation, certificate update, certificate status query, key recovery, and hardware computation of cryptographic algorithms such as SM1, SM2, SM3, and SM4.
[0202] The tool engine integrates a set of tools related to terminal environment information collection and status detection, mainly including functions such as firewall, intrusion detection, vulnerability scanning, configuration management, security gateway, security isolation, vulnerability scanning, and network measurement, to realize the collection of terminal environment information and the detection of the real-time operating status of the terminal.
[0203] The AI engine serves as the core support for the endpoint security baseline generation system, equipped with a dedicated AIGC model deeply optimized based on the Transformer architecture. In this patented system, the AI engine does not operate independently but is deeply embedded in the collaborative scheduling system of the security management center. Under the unified policy scheduling of the security management center, it opens up call capabilities to the endpoint security agent through standardized API interfaces, meeting the needs of real-time generation of a large number of heterogeneous endpoint security baselines.
[0204] The proxy server is primarily based on a PKI system, tool engine, and AI engine. It is centrally managed by a security management and control platform, receiving information from multiple distributed security proxies. After security risk analysis and comprehensive processing, it generates security control policies, which are then automatically executed by each security agent to handle and block security incidents, reducing their risk to an acceptable level. This achieves the goals of distributed deployment, centralized management, automation, and intelligent security control, meeting the high reliability, high efficiency, and continuous security operation requirements of complex system network terminals. Supported by a high-computing platform, it employs PDRR models, time-division and space-division control models, and risk degradation models. It mainly includes functional modules such as a security management module, a security monitoring and auditing module, a configuration management module, a situational awareness module, and a continuous security evolution module, possessing adaptive comprehensive detection, analysis, and security management and control capabilities.
[0205] Figure 3 This is a flowchart illustrating the security proxy operation used in the network terminal security proxy method of the present invention. Figure 3 As shown, the security agent operation process mainly includes the following steps:
[0206] 1) The terminal initializes the terminal security agent while network connection is prohibited;
[0207] 2) If the security agent fails its own integrity check, the user will be prompted to reinstall the security agent.
[0208] 3) If the check passes, perform security agent identity authentication to ensure the legitimacy of the security agent. This step requires opening a network connection on the terminal to interact with the proxy server; and the proxy server calls the cryptographic service function of the PKI cryptographic infrastructure to complete the authentication based on the terminal's external USB hardware digital certificate, using the X.509 and CPK authentication process.
[0209] 4) If the security agent's identity is trusted, the security agent will start normally. If startup fails, return to step 2) above;
[0210] 5) When the security agent starts normally, it begins a closed-loop security protection process: trusted terminal identity authentication, status and behavior detection, baseline generation, and task planning and response recovery. This includes trusted terminal identity authentication, terminal environment, behavior and status detection, security baseline generation, and task planning and response recovery. During this process, it needs to call the PKI cryptographic integration facilities, various detection tool engines (firewall, intrusion detection, antivirus, security gateway, isolation, vulnerability scanning, etc.), AI engine, and proxy server that integrates the security management and control platform, etc., integrated by the security management center.
[0211] 6) Real-time terminal security monitoring.
[0212] The beneficial effects of implementing this embodiment are as follows: It ensures the trustworthiness of the terminal's network identity based on PKI identity authentication, enabling trusted terminal identity authentication; it generates a dynamic security baseline based on static configuration management and dynamic workflow, achieving security protection for the terminal environment and behavior; it supports collaborative linkage of multiple security components such as agents based on a unified security policy of the security management center; it features a closed-loop execution process of trusted identity authentication—state and behavior detection—baseline generation—task planning and response recovery; and it can guarantee the security of the terminal's identity, environment, and behavior, making it suitable for security monitoring and protection application scenarios of PC terminals, mobile terminals, cloud terminals, IoT terminals, etc., in complex network systems.
[0213] This invention can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This invention can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0214] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).
[0215] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0216] Example 2
[0217] Further reference Figure 4 As a response to the above Figure 1 The present invention provides an embodiment of a network terminal security proxy device, which is similar to the method shown. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0218] like Figure 4As shown, the network terminal security proxy device 70 described in this embodiment includes a security proxy client deployed on the terminal system and a proxy server deployed in the security management center. It also includes a collection module 71, a construction module 72, an analysis module 73, a generation module 74, a processing module 75, and an optimization module 76, wherein:
[0219] The data acquisition module 71 is used to perform trusted identity authentication on network terminals and user identities accessing the system. After successful authentication, the security agent collects multi-dimensional terminal information.
[0220] Module 72 is used to construct a security baseline vector for each terminal based on the multi-dimensional terminal information and through AI machine learning.
[0221] Analysis module 73 is used to convert the terminal's current real-time data into a state vector that can be compared with the security baseline vector, calculate the vector deviation between the state vector and the security baseline vector, and analyze the vector deviation.
[0222] The generation module 74 is used to automatically generate specific and executable response and recovery action plan documents based on the results of the analysis of the vector deviation, combined with the knowledge base and AI reasoning, so as to transform the abstract security threat into specific operation instructions;
[0223] The processing module 75 is used to coordinate with the security agent to execute the operation instructions issued by the agent server, and to coordinate with multiple security components to process the operation instructions.
[0224] The optimization module 76 is used to dynamically adjust the security baseline vector based on the processed state vector, so that the system can learn from each security event and continuously optimize.
[0225] The beneficial effects of implementing this embodiment are as follows: It ensures the trustworthiness of the terminal's network identity based on PKI identity authentication, enabling trusted terminal identity authentication; it generates a dynamic security baseline based on static configuration management and dynamic workflow, achieving security protection for the terminal environment and behavior; it supports collaborative linkage of multiple security components such as agents based on a unified security policy of the security management center; it features a closed-loop execution process of trusted identity authentication—state and behavior detection—baseline generation—task planning and response recovery; and it can guarantee the security of the terminal's identity, environment, and behavior, making it suitable for security monitoring and protection application scenarios of PC terminals, mobile terminals, cloud terminals, IoT terminals, etc., in complex network systems.
[0226] Example 3
[0227] To address the aforementioned technical problems, embodiments of the present invention also provide a computer device. Please refer to [link / reference needed]. Figure 5 , Figure 5 This is a basic structural block diagram of the computer device in this embodiment.
[0228] The aforementioned computer device 8 includes a memory 81, a processor 82, and a network interface 83 that are interconnected via a system bus. It should be noted that only the computer device 8 with components 81, 82, and 83 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the computer device described herein is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0229] The aforementioned computer devices can be desktop computers, laptops, handheld computers, and cloud servers, among other computing devices. These devices can facilitate human-computer interaction with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.
[0230] The aforementioned memory 81 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the aforementioned memory 81 may be an internal storage unit of the aforementioned computer device 8, such as the hard disk or memory of the computer device 8. In other embodiments, the aforementioned memory 81 may also be an external storage device of the aforementioned computer device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 8. Of course, the aforementioned memory 81 may also include both the internal storage unit and its external storage device of the aforementioned computer device 8. In this embodiment, the aforementioned memory 81 is typically used to store the operating system and various application software installed on the aforementioned computer device 8, such as computer-readable instructions for network terminal security proxy methods. In addition, the aforementioned memory 81 can also be used to temporarily store various types of data that have been output or will be output.
[0231] In some embodiments, the processor 82 described above may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 82 is typically used to control the overall operation of the computer device 8. In this embodiment, the processor 82 is used to execute computer-readable instructions stored in the memory 81 or to process data, for example, to execute computer-readable instructions of the network terminal security proxy method described above.
[0232] The network interface 83 may include a wireless network interface or a wired network interface, which is typically used to establish a communication connection between the computer device 8 and other electronic devices.
[0233] The beneficial effects of implementing this embodiment are as follows: It ensures the trustworthiness of the terminal's network identity based on PKI identity authentication, enabling trusted terminal identity authentication; it generates a dynamic security baseline based on static configuration management and dynamic workflow, achieving security protection for the terminal environment and behavior; it supports collaborative linkage of multiple security components such as agents based on a unified security policy of the security management center; it features a closed-loop execution process of trusted identity authentication—state and behavior detection—baseline generation—task planning and response recovery; and it can guarantee the security of the terminal's identity, environment, and behavior, making it suitable for security monitoring and protection application scenarios of PC terminals, mobile terminals, cloud terminals, IoT terminals, etc., in complex network systems.
[0234] Example 4
[0235] The present invention also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the network terminal security proxy method described above.
[0236] The beneficial effects of implementing this embodiment are as follows: It ensures the trustworthiness of the terminal's network identity based on PKI identity authentication, enabling trusted terminal identity authentication; it generates a dynamic security baseline based on static configuration management and dynamic workflow, achieving security protection for the terminal environment and behavior; it supports collaborative linkage of multiple security components such as agents based on a unified security policy of the security management center; it features a closed-loop execution process of trusted identity authentication—state and behavior detection—baseline generation—task planning and response recovery; and it can guarantee the security of the terminal's identity, environment, and behavior, making it suitable for security monitoring and protection application scenarios of PC terminals, mobile terminals, cloud terminals, IoT terminals, etc., in complex network systems.
[0237] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0238] Obviously, the embodiments described above are merely some embodiments of the present invention, not all embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms; rather, these embodiments are provided to provide a more thorough and complete understanding of the disclosure of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the patent protection scope of this invention.
Claims
1. A network terminal security proxy method, characterized in that, This includes a security agent client deployed on the endpoint system and a proxy server deployed in the security management center, comprising the following steps: Trusted identity authentication is performed on network terminals and user identities accessing the system. Once authentication is successful, the security agent collects multi-dimensional terminal information. Based on the multi-dimensional terminal information, a security baseline vector is constructed for each terminal through AI machine learning. The terminal's current real-time data is converted into a state vector that can be compared with the security baseline vector. The vector deviation between the state vector and the security baseline vector is calculated, and the vector deviation is analyzed. Based on the analysis of the vector deviation, combined with the knowledge base and AI reasoning, specific and executable response and recovery action plan documents are automatically generated, transforming abstract security threats into specific operational instructions; The security agent coordinates the execution of the operation instructions issued by the proxy server and works in conjunction with multiple security components to process the operation instructions; Based on the state vector after processing, the security baseline vector is dynamically adjusted so that the system can learn from each security event and continuously optimize.
2. The network terminal security proxy method according to claim 1, characterized in that, The steps of performing trusted identity authentication on network terminals and users accessing the system, and collecting multi-dimensional terminal information by the security agent after successful authentication, specifically include: When the agent client starts or reconnects, multi-factor fusion authentication is performed on both the terminal device itself and the operating user. After successful identity authentication, the security agent collects static, dynamic, and behavioral data of the terminal according to a predetermined policy; The collected heterogeneous data is standardized in format and then compressed and encrypted through a secure channel before being reported to the proxy server.
3. The network terminal security proxy method according to claim 1, characterized in that, The step of constructing a security baseline vector for each terminal based on the multi-dimensional terminal information and through AI machine learning specifically includes: The multi-dimensional terminal information is associated and integrated, and features are extracted. Based on the extracted features, the security baseline vector is constructed for each terminal using AI machine learning.
4. The network terminal security proxy method according to claim 1, characterized in that, The steps of converting the terminal's current real-time data into a state vector that can be compared with the security baseline vector, calculating the vector deviation between the state vector and the security baseline vector, and analyzing the vector deviation specifically include: Process the real-time data stream continuously reported by the security agent; The processed real-time data stream is transformed into a state vector that can be compared with the security baseline vector; Calculate the vector deviation between the state vector and the safety baseline vector, analyze the vector deviation, and determine the risk level and trigger alarms.
5. The network terminal security proxy method according to claim 1, characterized in that, The step of automatically generating specific and executable response and recovery action plan documents based on the analysis results of the vector deviation, combined with knowledge base and AI reasoning, and transforming abstract security threats into specific operational instructions, specifically includes: Based on the analysis of the vector deviation, and combined with the knowledge base and AI reasoning, the cause of the deviation is inferred. Based on the inferred causes of the deviation, select the most appropriate single or multiple actions from the response measure library and arrange their execution order; The planned response measures are packaged into specific response recovery action plan operation instructions.
6. The network terminal security proxy method according to claim 1, characterized in that, The steps of the security agent collaboratively executing the operation instructions issued by the proxy server and coordinating with multiple security components to handle the operation instructions specifically include: The security agent receives the action plan from the server via the YD-SOMN protocol and performs parsing and verification. The security agent invokes or notifies other security software to coordinate and link multiple security components to jointly execute security operation instructions. The execution results and the post-execution system status are fed back to the proxy server, forming a closed loop.
7. The network terminal security proxy method according to any one of claims 1 to 6, characterized in that, The step of dynamically adjusting the security baseline vector based on the processed state vector, enabling the system to learn from each security event and continuously optimize, specifically includes: Within a preset time period after the response action is executed, the real-time status vector of the terminal is continuously monitored, the deviation between the status vector after the action and the safety baseline vector is calculated, and it is confirmed whether the risk score has been reduced to below the safety threshold. If it is confirmed that the risk score has dropped below the safety threshold, the stable state vector after the treatment is used as a new normal sample to update the safety baseline vector.
8. A network terminal security proxy device, comprising a security proxy client deployed on a terminal system and a proxy server deployed in a security management center, characterized in that, include: The data collection module is used to perform trusted identity authentication on network terminals and user identities accessing the system. Once authentication is successful, the security agent collects multi-dimensional terminal information. A construction module is used to build a security baseline vector for each terminal based on the multi-dimensional terminal information and through AI machine learning. The analysis module is used to convert the terminal's current real-time data into a state vector that can be compared with the security baseline vector, calculate the vector deviation between the state vector and the security baseline vector, and analyze the vector deviation. The generation module is used to automatically generate specific and executable response and recovery action plan documents based on the results of the analysis of the vector deviation, combined with the knowledge base and AI reasoning, thereby transforming abstract security threats into specific operational instructions; The processing module is used to coordinate with the security agent to execute the operation instructions issued by the proxy server, and to coordinate with multiple security components to process the operation instructions. The optimization module is used to dynamically adjust the security baseline vector based on the processed state vector, so that the system can learn from each security event and continuously optimize.
9. A computer device, characterized in that, The device includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the network terminal security proxy method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the network terminal security proxy method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
System and method for terminal agent based threat monitoring and data leakage prevention
CN106845272A
Equipment access authentication method and device, equipment and storage medium
CN119182599A