Intelligent linkage strategy generation and optimization method and device for multiple safety devices and medium

By collecting and standardizing information from multiple security devices in real time, a dynamic weighted graph structure model is constructed to perform conflict detection and optimization strategy generation. This solves the problems of data heterogeneity and strategy conflict among multiple security devices, and achieves efficient and reliable generation and optimization of security linkage strategies.

CN121098536APending Publication Date: 2025-12-09GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511101740.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

The collaborative operation among multiple security devices suffers from problems such as high data heterogeneity, frequent policy conflicts, delayed response, and insufficient verification, resulting in low security management efficiency.

Method used

Real-time collection of information from multiple security devices and standardized processing are performed to construct a security event association model with a dynamic weighted graph structure. Conflict detection and optimization strategy generation are conducted, and phased push execution is adopted, along with attack simulation verification.

Benefits of technology

It improves the accuracy and completeness of data collection from multiple security devices, ensures the adaptability and reliability of strategies, and enhances the response speed and overall defense efficiency of security linkage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098536A_ABST
    Figure CN121098536A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent linkage strategy generation and optimization method and device for multiple safety devices and a medium, and belongs to the technical field of linkage of the multiple safety devices. Comprising the five steps of multi-safety-device information collection and standardization processing, safety event association model construction, initial linkage strategy generation, strategy optimization and dynamic adjustment and strategy deployment and verification, in the information collection stage, device types, states, protocols and network topology attributes are obtained in real time, abnormities are marked through a data verification sub-module, and re-collection is triggered; unstructured data is converted into structured data based on a preset protocol, field-level verification is supported, data accuracy and integrity are guaranteed, a dynamic weighted graph structure is adopted in association model construction to represent equipment nodes and event paths, node attributes contain real-time state indexes, edge attributes contain transmission probabilities and time delay parameters, and the real-time state indexes of the equipment nodes and the event paths of the equipment nodes are obtained. And a node health degree evaluation mechanism is set, graph structure reconstruction is triggered when the node health degree is lower than a threshold value, and equipment association and event propagation characteristics are accurately described.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of multi-security device linkage, and particularly relates to an intelligent linkage strategy generation and optimization method for multi-security devices, a device and a medium. BACKGROUND

[0002] With the complication of network environment and the diversification of security threats, the types of security devices deployed by enterprises or organizations are increasing, such as intrusion prevention systems and terminal security management systems, etc. These devices usually come from different manufacturers, adopt differentiated protocols and interfaces, and the formats and standards of device state, event data and other information are not unified, which leads to the key challenge of security management for the coordinated linkage between multi-security devices.

[0003] In the prior art, the information collection and processing of multi-security devices often have the problems of insufficient data accuracy and lack of integrity, lack of effective abnormal data marking and re-sampling mechanism, and easy deviation of subsequent analysis due to data errors; at the same time, the unstructured data of different devices are difficult to process in a unified format, the data standardization degree is low, and the subsequent model construction efficiency is affected; in the aspect of security event correlation modeling, the traditional model usually adopts a static or simple structure, which cannot accurately depict the real-time state correlation and event propagation characteristics between devices, leading to the disconnection of the model and the actual network environment; and the model lacks dynamic adjustment capability when the device state is abnormal or fails, and the effectiveness of the correlation analysis is difficult to maintain; in the linkage strategy generation link, the existing technology usually relies on fixed rules, lacks a dynamic matching mechanism based on real-time correlation model, and the response speed of high-threat events is slow; the rule library design is simple, lacks a cooperative action sequence, a time window constraint and a fault tolerance mechanism, has poor coordination and weak fault tolerance when multiple devices are linked, and lacks rule template conflict detection, which easily leads to strategy conflicts; in the aspect of strategy optimization, the existing method is usually oriented to a single target, lacks a multi-target hybrid optimization mechanism, and does not combine multi-source feedback to dynamically adjust parameters, which has poor strategy adaptability and low resource utilization rate; when the strategy is deployed, one-time push easily causes impact on the device cluster, affecting the deployment stability; the verification link relies on subjective evaluation, lacks simulation verification of typical security event scenarios, and the verification result log is incomplete and has low visualization, which is difficult to support strategy analysis and problem tracing, and therefore an intelligent linkage strategy generation and optimization method for multi-security devices is proposed. SUMMARY

[0004] In view of the above problems, the present application is proposed.

[0005] Therefore, one object of the present application is to solve the problems of high data heterogeneity, frequent strategy conflicts, response lag and insufficient verification in the coordinated defense of multi-security devices, to realize intelligent, adaptive and highly reliable security linkage strategy generation and optimization, and to improve the overall defense efficiency and accuracy.

[0006] To solve the above technical problems, the application provides the following technical solutions: a multi-security device-oriented intelligent linkage strategy generation and optimization method, which comprises,

[0007] Real-time collection of multi-security device information and standardized processing; construction of a security event correlation model based on the standardized multi-security device information to reflect the device running state in real time; conflict detection of a preset rule library to generate an initial linkage strategy according to the security event correlation model; optimization of the initial strategy based on the real-time collected multi-security device information to obtain an optimized strategy and set a multi-source feedback mechanism for parameter adjustment; deployment of the optimized strategy to a target device cluster, and execution of a deployment operation by using a phased push and attack simulation verification.

[0008] As a preferred scheme of the multi-security device-oriented intelligent linkage strategy generation and optimization method, the real-time collection of multi-security device information and standardized processing comprises real-time collection of multi-security device information and compression processing.

[0009] An abnormal data re-sampling mechanism is set.

[0010] Field checking is performed based on a preset protocol conversion data structure after no abnormal data.

[0011] As a preferred scheme of the multi-security device-oriented intelligent linkage strategy generation and optimization method, the construction of a security event correlation model to reflect the device running state in real time comprises,

[0012] Construction of a security event correlation model based on standardized device information and representation by a dynamic weighted graph structure.

[0013] A health degree evaluation mechanism is set in the dynamic weighted graph structure to determine whether to perform graph structure reconstruction.

[0014] The preferred technical scheme in the embodiment of the application has the following beneficial effects: the dynamic weighted graph structure is adopted, the model is adaptively reconstructed through a node health degree evaluation mechanism, and the accuracy of event correlation and the model robustness in a complex network environment are improved.

[0015] As a preferred scheme of the multi-security device-oriented intelligent linkage strategy generation and optimization method, the conflict detection of a preset rule library to generate an initial linkage strategy comprises,

[0016] Dynamic matching of a preset rule library by a strategy engine based on the security event correlation model.

[0017] The preset rule library is divided into a plurality of strategy template sets, and conflict detection of the plurality of strategy template sets is performed to determine the strategy priority.

[0018] The initial linkage strategy is generated by determining the execution order of the priority.

[0019] As a preferred scheme of the intelligent linkage strategy generation and optimization method for multiple security devices, the priority sorting includes determining the action execution order by a priority sorting algorithm.

[0020] The priority sorting algorithm introduces a device load balancing mechanism. When two or more devices need to perform cooperative actions, the action distribution proportion is dynamically adjusted according to the real-time resource occupancy rate.

[0021] When the device resource occupancy rate exceeds a preset threshold, the secondary action is automatically degraded, and the execution of the key action is prioritized.

[0022] As a preferred scheme of the intelligent linkage strategy generation and optimization method for multiple security devices, the optimized strategy is obtained and a multi-source feedback mechanism is set to adjust the parameters.

[0023] Based on the real-time running data during the running of the initial linkage strategy, the initial generated linkage strategy is optimized by a hybrid optimization algorithm. The hybrid optimization algorithm introduces a simulated annealing mechanism in the mutation operation of the genetic algorithm, sets an annealing temperature parameter, and balances the breadth of global search and the speed of local convergence through temperature change.

[0024] The target parameters of the optimization operation include execution efficiency parameters, resource occupancy rate parameters, and disposal success rate parameters.

[0025] The optimization process sets a multi-source feedback mechanism to drive parameter adjustment operations by fusing feedback information. The multi-source feedback mechanism includes user behavior feedback, collects administrator intervention records through a security operation center, and inputs the artificially adjusted strategy parameters as the initial population of the optimization algorithm.

[0026] As a preferred scheme of the intelligent linkage strategy generation and optimization method for multiple security devices, the deployment operation is performed by adopting a staged pushing method and attack simulation verification is performed.

[0027] The optimized linkage strategy is deployed to the target device cluster, and the deployment operation is performed by adopting a staged pushing method.

[0028] A typical security event scenario is generated by an attack simulation engine. The attack simulation engine automatically generates test cases including attack path variation mechanisms and defense strategy coverage evaluation indexes based on historical security event data. The attack simulation engine again constructs a test scenario by an automatic test case generation module.

[0029] The verification index includes a response time parameter, a linkage consistency parameter and an exception handling capability parameter; and the verification process automatically generates a log file including timestamp information, device identification information and action result information;

[0030] The log file is played back visually, the visual playback performs difference analysis through a policy, automatically identifies deviation nodes and generates a cause analysis report by comparing actual execution logs with expected action sequences, and the report includes device state snapshots and event transmission path backtracking.

[0031] The preferred technical scheme in the embodiment of the application has the beneficial effects that: the staged pushing and attack simulation verification are adopted to ensure the reliability of the policy in actual deployment, and the visual log playback function provides intuitive basis for policy improvement.

[0032] Another object of the application is to provide a multi-security device-oriented intelligent linkage policy generation and optimization system.

[0033] To solve the above technical problems, the application provides the following technical scheme: a multi-security device-oriented intelligent linkage policy generation and optimization system, comprising a data processing module, a policy generation module and a policy optimization module.

[0034] The data processing module collects multi-security device information in real time and performs standardized processing.

[0035] The policy generation module constructs a security event correlation model based on the standardized multi-security device information to reflect device running states in real time, and performs conflict detection on a preset rule library to generate an initial linkage policy.

[0036] The policy optimization module optimizes the initial policy based on the real-time collected multi-security device information to obtain an optimized policy, sets a multi-source feedback mechanism for parameter adjustment, deploys the optimized policy to a target device cluster, adopts staged pushing to perform deployment operations and performs attack simulation verification.

[0037] The application provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the multi-security device-oriented intelligent linkage policy generation and optimization method when executing the computer program.

[0038] The application provides a computer readable storage medium having a computer program stored thereon, wherein the computer program implements the steps of the multi-security device-oriented intelligent linkage policy generation and optimization method when executed by a processor.

[0039] The application has the following beneficial effects: in the multi-security device information collection and standardized processing of the application, the device type, state, protocol and network topology attribute are collected in real time, the abnormal data is marked and the re-collection mechanism is combined with the data verification submodule, so that the accuracy and integrity of the collected data can be effectively guaranteed, and the deviation of subsequent analysis caused by data errors can be avoided;

[0040] By converting the unstructured data into structured data through the preset protocol and supporting field-level verification, the unified format processing of different device data is realized, the standardization of data processing and the efficiency of subsequent model construction are improved, in the security event correlation model construction step, the dynamic weighted graph structure is used to represent the device nodes and event paths, the node attribute contains real-time state indicators, and the edge attribute contains transmission probability and time delay parameters, which can more accurately depict the correlation between devices and the event propagation characteristics, so that the model is more suitable for the actual network environment;

[0041] The node health evaluation mechanism and the function of triggering graph structure reconstruction when the health degree is lower than the threshold value ensure that the model can be dynamically adjusted when the device state is abnormal or faulty, and the effectiveness of correlation analysis is maintained, in the initial linkage strategy generation step, based on the correlation model, the strategy engine dynamically matches the rule library divided according to the threat level, preferentially matches the high-threat template, and determines the action execution order through the priority sorting algorithm, which can realize the rapid response of high-threat events;

[0042] The coordinated action sequence, time window constraint and fault tolerance mechanism contained in the rule library ensure the coordination, timeliness and fault tolerance capability of multi-device linkage, and the rule template conflict detection avoids the contradiction between strategies, improves the feasibility of the strategy, in the strategy optimization and dynamic adjustment step, the initial strategy is optimized by the hybrid optimization algorithm with the execution efficiency, resource occupancy rate and disposal success rate as the target, and combined with the multi-source feedback mechanism to drive parameter adjustment, which can continuously optimize the strategy performance, so that it is more suitable for the changes of the actual operation environment, improves the execution effect and resource utilization rate of the strategy, in the strategy deployment and verification step, the optimized strategy is pushed to the target device cluster in stages, which can reduce the impact of deployment on the device cluster and ensure the stability of deployment;

[0043] The attack simulation engine generates typical security event scenarios to verify the response time, linkage consistency and abnormal processing capability, which can objectively evaluate the actual effect of the strategy, and the verification result automatically generates a log containing timestamp, device identifier and action result and supports visual playback, which provides detailed basis for subsequent strategy analysis and problem tracing, and improves the transparency and traceability of strategy verification. BRIEF DESCRIPTION OF DRAWINGS

[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.

[0045] Figure 1 The overall flowchart of the intelligent linkage strategy generation and optimization method for multiple security devices is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0046] In order to make the above-mentioned objects, features and advantages of the present application more apparent and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort should be within the protection scope of the present application.

[0047] Embodiment 1, refer to Figure 1 For an embodiment of the present application, the embodiment provides an intelligent linkage strategy generation and optimization method for multiple security devices, which comprises the following steps.

[0048] S100, real-time collection of multiple security device information and standardized processing.

[0049] S200, construction of a security event correlation model based on the standardized multiple security device information to reflect the device running state in real time.

[0050] S300, conflict detection of a preset rule library according to the security event correlation model to generate an initial linkage strategy.

[0051] S400, optimization of the initial strategy based on the real-time collected multiple security device information to obtain an optimized strategy and set a multi-source feedback mechanism for parameter adjustment.

[0052] S500, deployment of the optimized strategy to a target device cluster, execution of a deployment operation by adopting a staged push, and attack simulation verification.

[0053] It should be noted that there are significant defects in data layer collection, such as inaccuracy, poor integrity, and low standardization, which lead to analysis deviation and inefficient model construction; the model layer is static and rigid, and cannot reflect real-time correlation and dynamic changes, resulting in distorted analysis and failure in fault conditions; the strategy generation relies on fixed rules, lacks dynamic matching, conflict detection, and fault-tolerant design, resulting in slow response, poor coordination, and contradictory strategies; the strategy optimization has a single target orientation, lacks multi-source feedback, and has poor adaptability and low resource utilization; the deployment is a one-time push that impacts system stability; and the verification relies on subjective evaluation, lacks simulation, incomplete logs, and weak visualization, making it difficult to objectively evaluate and trace problems. These defects collectively result in security defense lag, distortion, contradiction, failure, resource waste, and high deployment risk, severely weakening the overall protection capability.

[0054] Therefore, to address the above problems, through the steps of S100-S500, real-time collection and standardization ensure data quality, dynamic correlation model-based accurate depiction of real-time state, conflict detection to generate initial strategies to avoid contradictions, combination of real-time data and multi-source feedback to optimize strategies to improve adaptability and resource efficiency, and phased deployment and attack simulation verification to ensure stability and effectiveness, forming a closed-loop optimization, significantly improving the automation and intelligence level of security defense and overall resilience.

[0055] Embodiment 2, with reference to Figure 1 As an embodiment of the present application, the embodiment provides a multi-security device-oriented intelligent linkage strategy generation and optimization method, comprising:

[0056] In the embodiment of the present application, the real-time collection of multi-security device information and the standardization processing in S100 include the following steps S101-S103:

[0057] S101, real-time collection of multi-security device information and compression processing.

[0058] Specifically, the real-time collection operation is performed by the information collection module of the multi-security device, and the collection content includes device type attributes, device state attributes, device protocol attributes, and device network topology attributes;

[0059] The original data collected is losslessly compressed by the data compression submodule, and the compression algorithm dynamically adjusts the compression ratio according to the current data characteristics to balance the compression efficiency and data retention requirements. Key metadata fields are retained during the compression process to ensure the traceability of core information for subsequent processing.

[0060] In summary, lossless compression reduces data transmission and storage overhead, dynamic adjustment of compression ratio adapts to different data characteristics of different scenarios, retention of key metadata fields provides a complete information basis for subsequent standardization processing, and improves the efficiency and reliability of data collection and processing.

[0061] S102, set an abnormal data resampling mechanism.

[0062] Set data verification, mark the collected data as abnormal, and trigger the resampling mechanism when abnormal data is detected.

[0063] Real-time complete collection of device information and automatic correction of abnormal data are realized to ensure the quality of the basic data for subsequent strategy generation.

[0064] In an embodiment of the application, S103, field verification based on a preset protocol conversion data structure is performed after no abnormal data, including the following steps A1-A2:

[0065] A1, based on a preset protocol, unstructured data is converted into structured data, and the preset protocol includes field-level verification function;

[0066] A2, field-level verification is performed on the converted structured data, and the verification rule includes mandatory field detection to ensure that key fields are not missing, data type matching detection to verify that the field data type meets the expectation, and business logic correlation detection to check whether the logical relationship between fields is reasonable;

[0067] In an optional embodiment, the field verification in S103 can be, unstructured data is directly converted into structured data using a fixed protocol template, JSON or XML data is mapped to a fixed table structure, and only mandatory field detection is performed on the converted structured data to check whether key fields are missing, but data type matching detection and business logic correlation detection are omitted.

[0068] In another optional embodiment, the field verification in S103 can also be, unstructured data is converted into structured data using a standard data conversion tool, regular expression library is called to perform mandatory field detection and data type matching detection on the structured data, only the existence and basic type of the field are verified, but business logic correlation detection is omitted, and in a complex business logic scenario, the correlation error between fields cannot be detected.

[0069] In summary, the field-level verification ensures the integrity, type correctness and business logic consistency of the structured data, avoids subsequent processing exceptions caused by data errors, and improves the quality and reliability of data standardization processing; Real-time complete collection of device information and automatic correction of abnormal data are realized to ensure the quality of the basic data for subsequent strategy generation.

[0070] In an embodiment of the application, S200, based on the standardized multi-security device information, a security event correlation model is constructed to reflect the device running state in real time, including the following steps S201-S202:

[0071] S201, constructing a security event correlation model based on standardized device information and representing the model through a dynamic weighted graph structure.

[0072] The security event correlation model is constructed based on the standardized device information, and the model includes logical correlation relationships, trigger condition parameters, and response priority parameters.

[0073] The security event correlation model is represented by a dynamic weighted graph structure, and the graph structure includes device nodes and event paths, wherein the device node attributes include real-time state indicators, and the edge attributes of the event paths include transmission probability parameters and time delay parameters.

[0074] S202, setting a health degree evaluation mechanism in the dynamic weighted graph structure to determine whether to perform graph structure reconstruction.

[0075] The graph structure includes a node health degree evaluation mechanism, and the node health degree is calculated by comprehensively considering device response delay, data packet loss rate, and service availability indicators. When the health degree evaluation value of the device node is lower than a preset threshold, a graph structure reconstruction operation is triggered.

[0076] In summary, the node health degree evaluation mechanism reflects the real-time device running state, and the dynamic reconstruction of the graph structure can avoid model failure caused by node abnormalities, improve the accuracy and adaptability of the security event correlation model, and enhance the fault tolerance of the system to device state changes.

[0077] In the embodiments of the present application, S300, according to the security event correlation model, conflict detection is performed on the preset rule library to generate an initial linkage strategy, including the following steps S301-S303:

[0078] S301, based on the completed security event correlation model, performing a dynamic matching operation through a strategy engine, and the matching object is a preset rule library;

[0079] In the embodiments of the present application, S302, the preset rule library is divided into a plurality of strategy template sets, and conflict detection is performed on the plurality of strategy template sets to determine the strategy priority, including the following steps B1-B4:

[0080] B1, the preset rule library is divided into a plurality of strategy template sets according to threat levels, and each strategy template set includes a cooperative action sequence, a time window constraint parameter, and a fault tolerance mechanism parameter;

[0081] B2, the preset rule library supports strategy template conflict detection function, when the action sequences of a plurality of strategy templates exist execution sequence conflict, a preset conflict resolution rule library is called;

[0082] B3, the priority is determined through the preset conflict resolution rule library, and the conflict resolution rule includes a device importance weight and an event urgency weight.

[0083] B4, determining a strategy priority according to the device importance weight and the event urgency weight, and finally generating an initial linkage strategy without conflict.

[0084] In an optional embodiment, the conflict detection in S302 can be that the preset rule base is divided into multiple strategy template sets according to device type attributes, each set containing exclusive cooperative action sequences, time window constraints and fault tolerance parameters of the device of the type; action sequence conflicts are detected within the same device type strategy template set first, and cross-group detection is only performed when there is no conflict in the group; the conflict resolution rule base only retains the device importance weight, and the event urgency weight parameter is cancelled; the strategy is directly executed in descending order of device importance weight, and the initial linkage strategy is generated, but it is not suitable for complex threat scenarios.

[0085] In another optional embodiment, the conflict detection in S302 can also be that the strategy template set is divided into three levels of immediate response, fast response and regular response according to the time window constraint parameter; only the action sequence conflicts of the strategy templates within the same level are detected, and the cross-level strategies are defaulted to have no conflict; the conflict resolution rule base only retains the event urgency weight, and the device importance weight is cancelled; the strategies of the same level are executed according to the event urgency weight, and the initial linkage strategy is generated, but high-urgency low-risk events may occupy critical device resources.

[0086] By avoiding contradictions in multi-strategy execution through conflict detection, the priority is determined by combining device importance and event urgency, critical device and emergency event are prioritized for response, and the effectiveness and execution efficiency of linkage strategy are improved.

[0087] In the embodiments of the application, S303, the initial linkage strategy is generated by determining the execution order of the strategy according to the priority, including the following steps C1-C3:

[0088] C1, the strategy generation process matches the strategy template set corresponding to the high threat level first, and determines the action execution order through a priority sorting algorithm;

[0089] C2, the priority sorting algorithm introduces a device load balancing mechanism, when multiple devices need to execute cooperative actions, the action distribution proportion is dynamically adjusted according to real-time resource occupancy rate;

[0090] C3, if the real-time resource occupancy rate of the device exceeds a preset threshold, the secondary action is automatically degraded for execution, and the execution of the key action is prioritized;

[0091] In an optional embodiment, the priority sorting in S303 can be that a high-threat-level policy template set is preferentially selected to generate a sequence of actions to be executed; a fixed polling sequence is adopted to allocate actions to devices that need to be cooperatively executed; a polling weight is preset according to a historical average resource occupancy rate of the devices; and a real-time monitoring is performed on the resource occupancy rate of the devices, if a sampling value of a certain device exceeds a threshold value for three times in succession, the non-critical action of the device is skipped, only the critical action is executed and is marked as a restricted state, until the resource returns to normal, but the sudden load fluctuation cannot be dynamically responded to, and the execution of the critical action is delayed.

[0092] In another optional embodiment, the priority sorting in S303 can also be that the policy template sets are filtered according to the threat levels; a fixed action execution quota is preset for each device, the quota is allocated according to the principle that the high-threat action preferentially occupies the quota, and when the quota is exhausted, the new action of the device is suspended, when the usage rate of the quota of the device exceeds 80%, only the critical action is executed for the subsequent actions, until the next quota resetting period, but the static quota cannot adapt to the real-time resource change.

[0093] In summary, by dynamically adjusting the action allocation ratio, the device overload is avoided, the resource occupancy rate threshold triggers the degradation mechanism to ensure that the critical action is preferentially executed, and the stability of the device resource utilization and the policy execution is improved.

[0094] Through the policy template sets divided according to the threat levels and the conflict detection mechanism, it is ensured that effective response strategies are preferentially generated in a high-threat scenario, and the compatibility between the policy templates is ensured.

[0095] In the embodiments of the present application, the initial policy is optimized based on the real-time collected multi-security device information in S400 to obtain an optimized policy and set a multi-source feedback mechanism for parameter adjustment, including the following steps S401-S404:

[0096] S401, based on the real-time running data in the policy running stage, a hybrid optimization algorithm is used to perform optimization operation on the initially generated linkage policy;

[0097] S402, in the mutation operation of the genetic algorithm, a simulated annealing mechanism is introduced, an annealing temperature parameter is set, the parameter is dynamically adjusted with the number of optimization iterations, the temperature change is used to balance the breadth of global search and the speed of local convergence, and finally an optimized linkage policy is generated;

[0098] The simulated annealing mechanism is combined with the genetic algorithm, the global search capability is retained and the local convergence efficiency is improved, the temperature parameter is dynamically adjusted to adapt to the requirements of different optimization stages, and the quality and efficiency of the policy optimization are improved.

[0099] S403, the target parameters of the optimization operation include an execution efficiency parameter, a resource occupancy rate parameter and a disposal success rate parameter;

[0100] In an embodiment of the present application, S404, the optimization process sets a multi-source feedback mechanism, including the following steps D1-D3:

[0101] D1, the multi-source feedback mechanism contains user behavior feedback by fusing feedback information to drive parameter adjustment operations, collects administrator intervention records through a security operation center, and inputs artificially adjusted strategy parameters as initial populations of optimization algorithms;

[0102] D2, the multi-source feedback mechanism collects user behavior feedback;

[0103] D3, the multi-source feedback mechanism collects administrator intervention records through a security operation center, and inputs artificially adjusted strategy parameters as initial populations of optimization algorithms to provide experience guidance for the optimization process;

[0104] In an optional embodiment, the multi-source feedback mechanism in S403 can be that the security operation center collects records of manual adjustments of the strategy execution by administrators, extracts modified strategy parameters and their adjustment directions, locates corresponding strategy templates in a preset rule library according to the manual adjustment records, directly dynamically corrects execution weight coefficients of the templates, and inputs the rule library after the weight is updated into a genetic algorithm combined with simulated annealing, but relies on high-frequency manual intervention, and adjustment hysteresis is significant in an automated scenario.

[0105] In another optional embodiment, the multi-source feedback mechanism in S403 can also be that user behavior feedback and administrator intervention records are collected, filtered through a lightweight rule engine, converted into boundary constraint conditions of optimization algorithms, and mixed optimization algorithms are executed to search within preset constraint ranges to generate optimized strategies, but implicit associated parameters in complex scenarios are difficult to effectively constrain.

[0106] The initial population input of the optimization algorithm is combined with the experience of manual adjustment by administrators to improve the initial quality and convergence speed of the optimization algorithm, so that the strategy optimization is more in line with actual operation and maintenance requirements.

[0107] In summary, through the mixed optimization algorithm and the multi-source feedback mechanism, continuous optimization of strategy parameters is realized, and strategy performance is improved in multiple dimensions such as execution efficiency, resource occupation, and disposal success rate.

[0108] In an embodiment of the present application, S500, the optimized strategy is deployed to the target device cluster, a phased push execution deployment operation is adopted, and attack simulation verification is performed, including the following steps S501-S504:

[0109] S501, the optimized linkage strategy is deployed to the target device cluster, and a phased push execution deployment operation is adopted.

[0110] S502, generating a typical security event scenario through an attack simulation engine, the attack simulation engine constructing a test scenario through an automatic test case generation module, the module automatically generating a test case according to historical security event data, containing an attack path variation mechanism (simulating diversified changes of an attack path) and a defense strategy coverage evaluation index (quantifying the defense capability of a strategy against an attack);

[0111] The attack path variation mechanism simulates the complexity of a real attack, the coverage evaluation index quantifies the defense effect of a strategy, and the overall strategy verification efficiency and reliability are improved.

[0112] S503, the verification index in the attack simulation verification contains a response time parameter, a linkage consistency parameter and an abnormality handling capability parameter;

[0113] S504, the verification process automatically generates a log file containing timestamp information, device identification information and action result information, and the log file supports a visual playback function;

[0114] The visual playback supports strategy execution difference analysis, automatically identifies deviation nodes and generates a cause analysis report by comparing actual execution logs with expected action sequences, and the report contains a device state snapshot (records the device state when the deviation occurs) and an event transmission path backtracking (restores the event processing flow) cause analysis report.

[0115] In summary, the strategy execution deviation is quickly located through difference analysis, the device state snapshot and the path backtracking provide detailed analysis basis, the problem root cause is located and the strategy is optimized, and the efficiency of strategy verification and adjustment is improved.

[0116] Embodiment 3 is an embodiment of the present application, and the above is a schematic scheme of the intelligent linkage strategy generation and optimization method for multiple security devices. It should be noted that the technical scheme of the intelligent linkage strategy generation and optimization system for multiple security devices belongs to the same concept as the technical scheme of the intelligent linkage strategy generation and optimization method for multiple security devices described above. The technical scheme of the intelligent linkage strategy generation and optimization system for multiple security devices in this embodiment is not described in detail, and the details can be referred to the description of the technical scheme of the intelligent linkage strategy generation and optimization method for multiple security devices.

[0117] The embodiment also provides an intelligent linkage strategy generation and optimization system for multiple security devices, which comprises a data processing module, a strategy generation module and a strategy optimization module.

[0118] The data processing module acquires multiple security device information in real time and performs standardized processing;

[0119] The strategy generation module constructs a security event correlation model based on the standardized multi-security device information to reflect the device running state in real time, and generates an initial linkage strategy by performing conflict detection on a preset rule library according to the security event correlation model;

[0120] The strategy optimization module optimizes the initial strategy based on the real-time collected multi-security device information to obtain an optimized strategy, sets a multi-source feedback mechanism to perform parameter adjustment, deploys the optimized strategy to a target device cluster, and performs attack simulation verification.

[0121] The embodiment also provides an electronic device suitable for the case of the multi-security device-oriented intelligent linkage strategy generation and optimization method, including a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the multi-security device-oriented intelligent linkage strategy generation and optimization method proposed in the above embodiment.

[0122] The embodiment also provides a storage medium having a computer program stored thereon, and the program is executed by a processor to realize the multi-security device-oriented intelligent linkage strategy generation and optimization method proposed in the above embodiment.

[0123] The storage medium proposed in the embodiment and the implementation of the multi-security device-oriented intelligent linkage strategy generation and optimization method proposed in the above embodiment belong to the same inventive concept, and the technical details not described in detail in the embodiment can be referred to the above embodiment, and the embodiment has the same beneficial effects as the above embodiment.

[0124] Through the above description of the embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and necessary general hardware, and of course can be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a FLASH, a hard disk or an optical disk, etc., including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of various embodiments of the present application.

[0125] It should be noted that the above examples are only used to illustrate the technical solutions of the present application but not to limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or equivalently replaced, without departing from the spirit and scope of the technical solutions of the present application, and all the modifications and equivalents should be included in the scope of the claims of the present application.

Claims

1. A method for generating and optimizing intelligent linkage strategies for multiple security devices, characterized in that: include, Real-time collection and standardized processing of information from multiple security devices; A security event correlation model is built based on standardized information from multiple security devices to reflect the real-time operating status of the devices. Based on the security event association model, conflict detection is performed on the preset rule base to generate an initial linkage strategy; The initial strategy is optimized based on real-time collected information from multiple security devices to obtain the optimized strategy, and a multi-source feedback mechanism is set up to adjust the parameters. The optimization strategy was deployed to the target device cluster, and the deployment operation was carried out in stages and attack simulation verification was performed.

2. The intelligent linkage strategy generation and optimization method for multiple security devices as described in claim 1, characterized in that: The real-time acquisition and standardized processing of information from multiple security devices includes, Real-time collection of information from multiple security devices, followed by compression processing; Set up a mechanism for re-collecting abnormal data; After confirming the absence of abnormal data, the data structure is transformed based on a preset protocol for field validation.

3. The intelligent linkage strategy generation and optimization method for multiple security devices as described in claim 2, characterized in that: The construction of the security event correlation model to reflect the real-time operating status of equipment includes, A security event correlation model is constructed based on standardized equipment information and represented by a dynamic weighted graph structure; In a dynamically weighted graph structure, a health assessment mechanism is set up to determine whether to reconstruct the graph structure.

4. The intelligent linkage strategy generation and optimization method for multiple security devices as described in claim 3, characterized in that: The step of performing conflict detection on a preset rule base to generate an initial linkage strategy includes... Based on a security event association model, a policy engine dynamically matches a preset rule base. The preset rule base is divided into multiple strategy template sets, and conflict detection of multiple strategy template sets is performed to determine the strategy priority; The initial linkage strategy is generated by determining the execution order of the strategy through priority sorting.

5. The method for generating and optimizing intelligent linkage strategies for multiple security devices as described in claim 4, characterized in that: The priority sorting includes determining the execution order of actions using a priority sorting algorithm; The priority sorting algorithm introduces a device load balancing mechanism. When two or more devices need to perform collaborative actions, the action allocation ratio is dynamically adjusted according to the real-time resource utilization rate. When the device resource utilization rate exceeds the preset threshold, it will automatically downgrade to execute secondary actions and prioritize the execution of critical actions.

6. The method for generating and optimizing intelligent linkage strategies for multiple security devices as described in claim 5, characterized in that: The process of obtaining the optimized strategy and setting a multi-source feedback mechanism for parameter adjustment includes... Based on the real-time running data of the initial linkage strategy, the initial linkage strategy is optimized by a hybrid optimization algorithm. The hybrid optimization algorithm introduces a simulated annealing mechanism into the mutation operation of the genetic algorithm, sets the annealing temperature parameter, and balances the breadth of the global search with the speed of local convergence through temperature changes. The target parameters for optimization operations include execution efficiency parameters, resource utilization parameters, and processing success rate parameters. The optimization process incorporates a multi-source feedback mechanism, which drives parameter adjustment by integrating feedback information. This mechanism includes user behavior feedback and collects administrator intervention records through the security operations center. The manually adjusted strategy parameters are used as the initial population input for the optimization algorithm.

7. The method for generating and optimizing intelligent linkage strategies for multiple security devices as described in claim 6, characterized in that: The step of employing a phased push deployment operation and performing attack simulation verification includes... The optimized linkage strategy is deployed to the target device cluster, and the deployment operation is performed in stages. Typical security incident scenarios are generated by the attack simulation engine. The attack simulation engine automatically generates test cases based on historical security incident data, including attack path mutation mechanisms and defense strategy coverage evaluation indicators. The attack simulation engine then builds test scenarios again through the automated test case generation module. The verification metrics include response time parameters, linkage consistency parameters, and anomaly handling capability parameters; the verification process automatically generates log files containing timestamp information, device identification information, and action result information; The log files are visualized and replayed. The visualization and replay analyzes the differences in policy execution. By comparing the actual execution logs with the expected action sequence, deviation nodes are automatically identified and a cause analysis report is generated. The report includes a device status snapshot and an event transmission path backtracking.

8. A system for generating and optimizing intelligent linkage strategies for multiple security devices, employing the method for generating and optimizing intelligent linkage strategies for multiple security devices as described in any one of claims 1 to 7, characterized in that, include: Data processing module, strategy generation module, and strategy optimization module; The data processing module collects information from multiple security devices in real time and performs standardized processing. The strategy generation module constructs a security event association model based on standardized multi-security device information to reflect the device operating status in real time. Based on the security event association model, it performs conflict detection on the preset rule base to generate initial linkage strategies. The strategy optimization module optimizes the initial strategy based on real-time collected information from multiple security devices to obtain the optimized strategy. It also sets up a multi-source feedback mechanism to adjust parameters, deploys the optimized strategy to the target device cluster, and performs the deployment operation in stages and conducts attack simulation verification.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the intelligent linkage strategy generation and optimization method for multiple security devices as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the intelligent linkage strategy generation and optimization method for multiple security devices as described in any one of claims 1 to 7.