A security management policy generation method and system
By identifying and processing abnormal messages in security management strategies, and using intelligent message extension models to generate more accurate security management strategies, the accuracy and reliability issues of security management strategy generation in existing technologies are resolved, and efficient thread safety management is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU BOYITE INTELLIGENT INFORMATION TECH CO LTD
- Filing Date
- 2022-11-29
- Publication Date
- 2026-04-17
AI Technical Summary
In existing technologies, abnormal messages may occur during the generation of security management strategies, making it difficult to guarantee the accuracy and reliability of thread safety management results.
By obtaining the current thread session policy set of the first thread security quantification result, identifying message nodes that differ between two consecutive sessions, using global analysis indicators to obtain abnormal messages, and processing them through an intelligent message extension model, a current thread session policy set of the second thread security quantification result is generated, thereby improving the accuracy and reliability of security management results.
The current thread session policy set generates accurate and reliable thread safety quantification results, ensuring the accuracy and credibility of thread safety management results and avoiding the need for separate analysis.
Smart Images

Figure CN116094752B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data generation technology, and more specifically, to a method and system for generating security management strategies. Background Technology
[0002] With the continuous development of computer networks, global informatization has become a major trend in human development. However, this rapid development has also brought significant cybersecurity risks to enterprises. To mitigate these risks, companies are deploying various security products to ensure network information security.
[0003] Currently, in industrial production, as users pay increasing attention to safety management strategies, accurately generating such strategies remains a difficult technical problem to overcome in existing technologies. Furthermore, the presence of abnormal messages within the safety management strategies undermines the accuracy and reliability of thread safety management results. Summary of the Invention
[0004] In view of this, this application provides a method and system for generating security management strategies.
[0005] Firstly, a method for generating security management policies is provided, applied to a policy generation system, the method comprising at least:
[0006] Obtain the first current thread session policy set of the first thread security quantization result; obtain message nodes in the first current thread session policy set where two consecutive current thread sessions differ, and obtain abnormal messages of global analysis indication between the two consecutive current thread sessions through the message nodes;
[0007] A second current thread session policy set is obtained by using the first current thread session policy set and the exception message to obtain a second thread safety quantification result; the second thread safety quantification result exceeds the first thread safety quantification result; the thread safety management result is determined by using the second current thread session policy set.
[0008] In one standalone embodiment, the second current thread session policy set, which obtains the second thread security quantization result through the first current thread session policy set and the exception message, includes:
[0009] From the multiple sets of session events in the first current thread session policy set, obtain every two consecutive sets of session events;
[0010] From the several analysis indicator tags in the abnormal message, obtain the corresponding analysis indicator tags for the differences between each pair of consecutive session events;
[0011] By using each pair of consecutive session events and the corresponding analysis indicator labels, the relative difference results of each pair of session events are obtained.
[0012] Based on the relative difference results of the differences between each pair of session events, message expansion processing is performed on each pair of session events to obtain the second current thread session strategy set.
[0013] In one standalone embodiment, obtaining message nodes where two consecutive sets of current thread sessions differ from each other in the first current thread session policy set includes:
[0014] From the first current thread session strategy set, two consecutive sets of session events and the message node clusters bound to the two sets of session events are extracted;
[0015] The message node is obtained by binding the message node clusters to the two sets of session events respectively.
[0016] In one standalone embodiment, obtaining two consecutive sets of abnormal messages for global analysis indications between current thread sessions through the message node includes: obtaining processing results in the processing model corresponding to the message node; obtaining abnormal messages for corresponding analysis indications through the processing results; and marking the abnormal messages for global analysis indications.
[0017] In one standalone embodiment, the anomalous message includes: a message node for analysis indication loading, a location for analysis indication loading, and / or a tag for analysis indication loading; the tag for analysis indication loading is used to characterize the tag that changes in the difference tags between the two sets of session events.
[0018] In one standalone embodiment, the step of performing message expansion processing on each pair of session events based on the relative difference results of the differences between each pair of session events to obtain the second current thread session strategy set includes: performing weighted processing on each pair of session events based on the relative difference results of the differences between each pair of session events to obtain transition labels that expand the differences between each pair of session events.
[0019] In one standalone embodiment, the method further includes: after expanding the transition label based on the difference between every two sets of session events, forming an updated session event set from the two sets of session events and the transition label, and determining the updated session event set as the second current thread session strategy set.
[0020] In one standalone embodiment, the step of obtaining the second current thread session strategy set based on the first current thread session strategy set and the exception message to obtain the second thread security quantification result includes: loading the first current thread session strategy set and the exception message into an intelligent message extension model; processing the first current thread session strategy set and the exception message through the intelligent message extension model to output the second current thread session strategy set to obtain the second thread security quantification result.
[0021] In one standalone implementation, the first current thread session policy set consists of a first session event queue, and the exception message consists of an analysis indicator tag queue. Based on this, the second current thread session policy set, obtained by processing the first current thread session policy set and the exception message through the intelligent message extension model to output the second thread security quantification result, includes:
[0022] Two consecutive sets of session event messages are obtained from the first session event queue; several analysis indicator tag messages corresponding to the two consecutive sets of session event messages are obtained from the analysis indicator tag queue; convolution processing is performed on the two consecutive sets of session event messages and the several analysis indicator tag messages respectively to obtain the convolution processing result;
[0023] The weighted average result is obtained by the convolution processing result; the weighted average result is used to weight the two consecutive groups of session event messages to obtain a transition message that expands the two consecutive groups of session event messages; wherein, obtaining the weighted average result by the convolution processing result includes: obtaining the relative difference result of the differences between the two consecutive groups of session event messages by the convolution processing result, and decomposing the relative difference result into a weighted average result corresponding to each key node to obtain several weighted average results.
[0024] In one independently implemented embodiment, the step of weighting the two consecutive groups of session event messages using the weighted average result to obtain a transition message that expands the two consecutive groups of session event messages includes: based on the two consecutive groups of session event messages being a first session event message and a second session event message, performing identification processing on the first session event message using a first weighted average result to obtain a first identification result, performing identification processing on the second session event message using a second weighted average result to obtain a second identification result; and concatenating the first identification result and the second identification result to obtain the transition message.
[0025] Secondly, a security management policy generation system is provided, including a processor and a memory that communicate with each other. The processor is used to retrieve a computer program from the memory and implement the above-mentioned method by running the computer program.
[0026] This application provides a method and system for generating a security management strategy, which involves: obtaining a first current thread session strategy set based on a first thread security quantification result; obtaining message nodes in the first current thread session strategy set where two consecutive sets of current thread sessions differ, and obtaining an exception message indicating a global analysis between the two consecutive sets of current thread sessions through the message nodes; obtaining a second current thread session strategy set based on a second thread security quantification result through the first current thread session strategy set and the exception message; and determining a thread security management result based on the second current thread session strategy set if the second thread security quantification result exceeds the first thread security quantification result. This application obtains an exception message indicating a global analysis between two consecutive sets of current thread sessions by using message nodes showing differences between two consecutive sets of current thread sessions in the first current thread session policy set (the current thread session policy set with poor thread safety quantification results). Then, using the first current thread session policy set (the current thread session policy set with poor thread safety quantification results) and this exception message, a second current thread session policy set with second thread safety quantification results (the current thread session policy set with better thread safety quantification results) can be obtained accurately and reliably without separate analysis. This ensures the accuracy and reliability of thread safety management results. Attached Figure Description
[0027] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 This is a flowchart illustrating a security management strategy generation method provided in an embodiment of this application.
[0029] Figure 2 This is a block diagram of a security management strategy generation device provided in an embodiment of this application.
[0030] Figure 3 This is an architecture diagram of a security management strategy generation system provided in an embodiment of this application. Detailed Implementation
[0031] To better understand the above technical solutions, the technical solutions of this application will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of this application and the specific features in the embodiments are detailed descriptions of the technical solutions of this application, rather than limitations on the technical solutions of this application. In the absence of conflict, the embodiments of this application and the technical features in the embodiments can be combined with each other.
[0032] Please see Figure 1 This paper illustrates a method for generating a security management strategy, which may include the technical solutions described in steps 101-103 below.
[0033] Step 101: Obtain the first current thread session policy set based on the first thread security quantization result.
[0034] The first current thread session policy set of the first thread-safe quantization result can be the current thread session policy set of the poorer thread-safe quantization result.
[0035] For example, the current thread session in the current thread session policy set can exist by recording data, thus forming a continuous record data queue.
[0036] Step 102: Obtain message nodes in the first current thread session policy set where there are differences between two consecutive groups of current thread sessions, and obtain the abnormal messages of the global analysis indication between the two consecutive groups of current thread sessions through the message nodes.
[0037] For example, abnormal messages in the global analysis indication can be obtained by analyzing the messages collected by the thread, that is, by collecting messages from two consecutive sets of message nodes that differ from each other in the current thread session.
[0038] Step 103: Obtain the second current thread session policy set based on the first current thread session policy set and the exception message. If the second thread security quantification result exceeds the first thread security quantification result, determine the thread security management result based on the second current thread session policy set.
[0039] The second current thread session policy set of the second thread safety quantization result can be the current thread session policy set of the better thread safety quantization result.
[0040] For example, by using two consecutive sets of session events (such as a session event queue with poor thread safety quantization results) and the analysis indication thread messages between the two sets of session events, a generation label with differences between the two sets of session events is obtained (such as a label with difference binding). This label basically covers the abnormal messages of the global analysis indication between the two sets of session events. It is used as a transition for extended processing to obtain a better thread safety quantization result current thread session strategy set.
[0041] Using this application, the AI thread (extended processing) and the analysis unit (analysis instruction thread) jointly complete data expansion. By identifying message nodes in the first current thread session policy set (the current thread session policy set with poor thread safety quantification results) where two consecutive current thread sessions differ, an abnormal message indicating a global analysis between the two consecutive current thread sessions can be obtained. Through the first current thread session policy set (the current thread session policy set with poor thread safety quantification results) and this abnormal message, a second current thread session policy set (the current thread session policy set with better thread safety quantification results) can be obtained. Thus, the current thread session policy set with better thread safety quantification results can be accurately and reliably obtained without separate analysis, ensuring the accuracy and reliability of thread safety management results.
[0042] In an alternative embodiment, obtaining message nodes in two consecutive sets of current thread sessions that differ from each other in the first current thread session policy set includes: extracting two consecutive sets of session events and message node clusters bound to the two sets of session events from the first current thread session policy set, and obtaining message nodes in two consecutive sets of current thread sessions that differ from each other through the message node clusters bound to the two sets of session events.
[0043] In an alternative embodiment, obtaining two consecutive sets of exception messages for global analysis indicators between current thread sessions via a message node includes: acquiring the processing result in the processing model corresponding to the message node, obtaining the exception message for the corresponding analysis indicator through the processing result, and marking the exception message for the global analysis indicator. The exception message includes: the message node where the analysis indicator was loaded, the location where the analysis indicator was loaded, and / or the tag for the analysis indicator loading.
[0044] For example, two consecutive sets of session events can be designated as a first session event and a second session event, respectively bound to message node clusters designated as a first message node cluster and a second message node cluster. Then, the message nodes where the current thread sessions differ can be obtained from the first and second message node clusters. The processing result in the corresponding processing model of this message node is obtained, and the corresponding analysis indicator's exception message is derived from this processing result. The exception messages of the analysis indicators with differing processing results are collected, and several collected exception messages of analysis indicators are marked to obtain the global analysis indicator's exception message. This exception message includes: the message node on which the analysis indicator is loaded, the location where the analysis indicator is loaded, and / or the tag on which the analysis indicator is loaded. For the tag on which the analysis indicator is loaded, this tag is used to indicate the tag that has changed in the difference tags of the two sets of session events.
[0045] The security management policy generation method of this application embodiment may specifically include the following:
[0046] Step 201: Obtain the first current thread session policy set based on the first thread security quantization result.
[0047] The first current thread session policy set of the first thread-safe quantization result can be the current thread session policy set of the poorer thread-safe quantization result.
[0048] Step 202: Obtain message nodes in the first current thread session policy set where there are differences between two consecutive groups of current thread sessions, and obtain the abnormal message of global analysis indication between the two consecutive groups of current thread sessions through the message nodes.
[0049] For example, you can obtain abnormal messages (or analyze abnormal messages or analyze indicator abnormal messages) by analyzing the messages collected by the thread, that is, by collecting messages from two consecutive sets of message nodes that differ from each other in the current thread session.
[0050] Step 203: Obtain every two consecutive sets of session events from the multiple sets of session events in the first current thread session strategy set.
[0051] Step 204: From the several analysis indicator labels in the abnormal message, obtain the corresponding analysis indicator labels for each pair of consecutive session events that are different.
[0052] Step 205: By using each pair of consecutive session events and corresponding analysis indicator labels, obtain the relative difference results for each pair of session events that show differences.
[0053] For example, from two consecutive sets of labels and the analysis indication message between the two sets, the processing steps within the message node segment are analyzed, and a relative difference result corresponding to the existence difference between the two sets of labels is generated.
[0054] Step 206: Based on the relative difference results of the differences between each pair of session events, perform message expansion processing on each pair of session events to obtain the second current thread session strategy set.
[0055] For example, by using the relative difference results that exist, the two sets of transmitted tags can be weighted to obtain the final expanded tags.
[0056] Through steps 203-206 above, a second current thread session strategy set can be obtained by using the first current thread session strategy set and the exception message to obtain the second thread safety quantization result. The second thread safety quantization result exceeds the first thread safety quantization result, and can be a better current thread session strategy set.
[0057] In an alternative embodiment, message expansion processing is performed on each pair of session events based on the relative difference results of the differences between each pair of session events to obtain the second current thread session strategy set, including: weighting each pair of session events based on the relative difference results of the differences between each pair of session events to obtain a transition label (final expansion label) that expands the differences between each pair of session events.
[0058] In an alternative embodiment, the security management policy generation method further includes: after expanding the transition label based on the difference between every two sets of session events, forming an updated session event set from every two sets of session events and the transition label, and determining the updated session event set as the second current thread session policy set.
[0059] The security management policy generation method of this application embodiment obtains a second current thread session policy set of the second thread security quantification result through a first current thread session policy set and an exception message, including the following:
[0060] Step 301: Load the first current thread session strategy set and exception messages into the smart message extension model.
[0061] Step 302: Process the first current thread session strategy set and exception messages through the intelligent message extension model, and output the second current thread session strategy set to obtain the second thread security quantification result.
[0062] For example, the intelligent message extension model is an extension unit. The current thread session with the poor thread safety quantification result and the analysis indication message of the corresponding application scenario are loaded into the extension unit to realize the extension processing of the current thread session and obtain the accurate current thread session policy set.
[0063] Through steps 301-302 above, the first current thread session policy set (the current thread session with a poor thread safety quantization result) and the analysis instruction message for the corresponding application scenario collected by the analysis instruction thread are loaded into the extension unit to realize the extended processing of the current thread session. The resulting second current thread session policy set is the accurate current thread session policy set (the current thread session with a better thread safety quantization result). This achieves the goal of obtaining a current thread session policy set with a better thread safety quantization result from a current thread session policy set with a poor thread safety quantization result through reliable extended processing.
[0064] In an alternative embodiment, based on the first current thread session policy set consisting of a first session event queue and the exception message consisting of an analysis indicator tag queue, the first current thread session policy set and the exception message are processed by an intelligent message expansion model to output a second current thread session policy set that yields a second thread safety quantification result. This includes: obtaining two consecutive sets of session event messages from the first session event queue; obtaining several analysis indicator tag messages corresponding to the two consecutive sets of session event messages from the analysis indicator tag queue; performing convolution processing on the two consecutive sets of session event messages and the several analysis indicator tag messages respectively to obtain a convolution processing result; obtaining a bound weighted average result through the convolution processing result; and performing weighted processing on the two consecutive sets of session event messages respectively through the weighted average result to obtain a transition message that expands the two consecutive sets of session event messages. The several analysis indicator tag messages are used as an example. For instance, the exception message of the analysis indicator thread loaded by the thread is generated by depolarizing according to the message nodes between the two sets of session events (message nodes consisting of the interval between the two sets of session events) according to 12 sets of message nodes, and then superimposing them to generate 12 sets of analysis indicator tag messages. This set of analysis indicator labels essentially covers global exception messages between the two sets of session events.
[0065] In an alternative embodiment, obtaining the bound weighted average result through the convolution processing result includes: obtaining the relative difference result of two consecutive groups of session event messages through the convolution processing result, and decomposing the relative difference result into a weighted average result corresponding to each key node to obtain several weighted average results.
[0066] In an alternative embodiment, the two consecutive groups of session event messages are weighted using a weighted average result to obtain a transition message that extends the two consecutive groups of session event messages. This includes: based on the first and second session event messages, the first weighted average result is used to identify the first session event message to obtain a first identification result; a second weighted average result is used to identify the second session event message to obtain a second identification result. The first and second identification results are then concatenated to obtain the transition message (transition tag).
[0067] For example, an analysis indicator thread is used as an optimization process, simultaneously collecting analysis indicator messages for the current thread session with poor thread safety quantization results and the corresponding application scenario. An intelligent message expansion model is constructed, loading abnormal messages containing global analysis indicators within message node segments where there are differences between two consecutive sets of session events. This thread can serve as an expansion unit. Accurate data expansion is achieved through the processing of this loaded message by the expansion unit. This thread consists of the following two parts:
[0068] (1) From the first current thread session policy set, obtain one of two consecutive sets of tags and the exception message indicating the global analysis between the two sets of session events, and analyze the message node indicating the difference between the two sets of session events. The analysis process of the message node indicating the difference between the two sets of session events can generate a relative difference result equivalent to the difference between the two sets of session events.
[0069] (2) By weighting the two groups of session events based on the relative difference results of the existence difference between the two groups of session events, the final extended label can be obtained. According to this fusion data extension method, the transition of the existence difference extension binding for each pair of consecutive session events is extended. After the extension transition, the updated session event set is composed of each pair of consecutive session events and the transition of its existence difference extension binding, which is the second current thread session strategy set.
[0070] In this embodiment, the first current thread session strategy set can be a session event queue with poor thread safety quantization results. By analyzing the indication thread, it can collect abnormal messages of global analysis indications for the corresponding application scenario. It can use two sets of consecutive session events and the global abnormal messages between the two sets of session events to predict the abnormal messages that are different. Then, it can use the abnormal messages to generate transition tags in order to complete the extension requirements of better thread safety quantization results.
[0071] Based on the above, please refer to the following: Figure 2 A security management policy generation device 200 is provided, which is applied to a security management policy generation system. The device includes:
[0072] The message analysis module 210 is used to obtain the first current thread session policy set of the first thread security quantization result; obtain message nodes in the first current thread session policy set where two consecutive current thread sessions differ; and obtain abnormal messages of global analysis indication between the two consecutive current thread sessions through the message nodes.
[0073] The result determination module 220 is used to obtain a second current thread session strategy set with a second thread safety quantification result through the first current thread session strategy set and the exception message; the second thread safety quantification result exceeds the first thread safety quantification result; and the thread safety management result is determined through the second current thread session strategy set.
[0074] Based on the above, please refer to the following: Figure 3 The present invention illustrates a security management policy generation system 300, comprising a processor 310 and a memory 320 that communicate with each other. The processor 310 is used to read computer programs from the memory 320 and execute them to implement the above-described method.
[0075] Based on the above, a computer-readable storage medium is also provided, on which a computer program stored implements the above method during runtime.
[0076] In summary, based on the above scheme, a first current thread session policy set is obtained to achieve the first thread safety quantification result; message nodes showing differences between two consecutive sets of current thread sessions are obtained from the first current thread session policy set, and abnormal messages indicating global analysis between the two consecutive sets of current thread sessions are obtained through the message nodes; a second current thread session policy set is obtained to achieve the second thread safety quantification result through the first current thread session policy set and the abnormal messages; if the second thread safety quantification result exceeds the first thread safety quantification result, the thread safety management result is determined through the second current thread session policy set. This application obtains an exception message indicating a global analysis between two consecutive sets of current thread sessions by using message nodes showing differences between two consecutive sets of current thread sessions in the first current thread session policy set (the current thread session policy set with poor thread safety quantification results). Then, using the first current thread session policy set (the current thread session policy set with poor thread safety quantification results) and this exception message, a second current thread session policy set with second thread safety quantification results (the current thread session policy set with better thread safety quantification results) can be obtained accurately and reliably without separate analysis. This ensures the accuracy and reliability of thread safety management results.
[0077] It should be understood that the systems and modules described above can be implemented in various ways. For example, in some embodiments, the systems and modules can be implemented by hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated-design hardware. Those skilled in the art will understand that the methods and systems described above can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The systems and modules of this application can be implemented not only by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., but also by software executed by various types of processors, or by a combination of the aforementioned hardware circuits and software (e.g., firmware).
[0078] It should be noted that different embodiments may produce different beneficial effects. In different embodiments, the beneficial effects may be any one or a combination of the above, or any other possible beneficial effects.
[0079] The basic concepts have been described above. Obviously, for those skilled in the art, the detailed disclosure above is merely illustrative and does not constitute a limitation of this application. Although not explicitly stated herein, those skilled in the art may make various modifications, improvements, and corrections to this application. Such modifications, improvements, and corrections are suggested in this application, and therefore remain within the spirit and scope of the exemplary embodiments of this application.
[0080] Furthermore, this application uses specific terms to describe embodiments of the application. For example, "an embodiment," "one embodiment," and / or "some embodiments" refer to a particular feature, structure, or characteristic associated with at least one embodiment of the application. Therefore, it should be emphasized and noted that "an embodiment," "one embodiment," or "an alternative embodiment" mentioned twice or more in different locations in this specification do not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of the application can be appropriately combined.
[0081] Furthermore, those skilled in the art will understand that aspects of this application can be described and illustrated through several patentable types or situations, including any new and useful combination of processes, machines, products, or substances, or any new and useful improvements thereof. Accordingly, aspects of this application can be implemented entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. All of the above hardware or software may be referred to as a “data block,” “module,” “engine,” “unit,” “component,” or “system.” Furthermore, aspects of this application may manifest as a computer product located on one or more computer-readable media, the product including computer-readable program code.
[0082] Computer storage media may contain a propagated data signal containing computer program code, for example, on baseband or as part of a carrier wave. This propagated signal may take various forms, including electromagnetic, optical, and suitable combinations thereof. Computer storage media can be any computer-readable medium other than a computer-readable storage medium, which can be connected to an instruction execution system, apparatus, or device to enable communication, propagation, or transmission of a program for use. The program code located on the computer storage medium can be propagated through any suitable medium, including radio, cable, fiber optic cable, RF, or similar media, or any combination of the above media.
[0083] The computer program code required for the operation of each part of this application can be written in any one or more programming languages, including object-oriented programming languages such as Java, Scala, Smalltalk, Eiffel, JADE, Emerald, C++, C#, VB.NET, Python, etc., conventional procedural programming languages such as C, Visual Basic, Fortran 2003, Perl, COBOL 2002, PHP, ABAP, dynamic programming languages such as Python, Ruby, and Groovy, or other programming languages. This program code can run entirely on the user's computer, or as a standalone software package on the user's computer, or partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer through any network, such as a local area network (LAN) or wide area network (WAN), or connected to an external computer (e.g., via the Internet), or in a cloud computing environment, or used as a service such as Software as a Service (SaaS).
[0084] Furthermore, unless expressly stated in the claims, the order of processing elements and sequences, the use of numbers and letters, or other names described in this application are not intended to limit the order of the processes and methods of this application. Although the foregoing disclosure has discussed some currently considered useful embodiments of the invention through various examples, it should be understood that such details are for illustrative purposes only, and the appended claims are not limited to the disclosed embodiments; rather, the claims are intended to cover all modifications and equivalent combinations that conform to the substance and scope of the embodiments of this application. For example, while the system components described above can be implemented using hardware devices, they can also be implemented solely through software solutions, such as installing the described system on existing servers or mobile devices.
[0085] Similarly, it should be noted that, in order to simplify the description of the present application and thus aid in the understanding of one or more embodiments of the invention, the foregoing description of the embodiments of the present application sometimes combines multiple features into a single embodiment, drawing, or description thereof. However, this disclosure method does not imply that the subject matter of the application requires more features than those mentioned in the claims. In fact, the embodiments contain fewer features than all the features of the single embodiments disclosed above.
[0086] In some embodiments, numbers describing the quantity of components and attributes are used. It should be understood that such numbers used in the description of embodiments are sometimes modified by the terms "approximately," "approximately," or "generally." Unless otherwise stated, "approximately," "approximately," or "generally" indicates that the numbers are open to adaptive variation. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, which may be changed depending on the desired characteristics of individual embodiments. In some embodiments, numerical parameters are taken into account a specified number of significant digits and employ a general method of digit reservation. Although the numerical ranges and parameters used to confirm their breadth of application in some embodiments of this application are approximate values, in specific embodiments, such values are set as precisely as feasible.
[0087] For each patent, patent application, patent application publication, and other material such as articles, books, specifications, publications, and documents referenced in this application, the entire contents of that patent are incorporated herein by reference. This excludes historical application documents that are inconsistent with or conflict with the content of this application, as well as documents that limit the broadest scope of the claims in this application (currently or subsequently appended to this application). It should be noted that if there are any inconsistencies or conflicts between the descriptions, definitions, and / or terminology used in the supplementary materials of this application and the content of this application, the descriptions, definitions, and / or terminology used in this application shall prevail.
[0088] Finally, it should be understood that the embodiments described in this application are merely illustrative of the principles of the embodiments of this application. Other modifications may also fall within the scope of this application. Therefore, alternative configurations of the embodiments of this application are considered as examples and not limitations, and are regarded as consistent with the teachings of this application. Accordingly, the embodiments of this application are not limited to the embodiments explicitly described and illustrated in this application.
[0089] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A security management policy generation method characterized by comprising: Applied to a policy generation system, the method includes at least: Obtain the first current thread session policy set from the first thread-safe quantization result; Obtain message nodes where two consecutive sets of current thread sessions differ from each other in the first current thread session policy set, and obtain abnormal messages of global analysis indication between the two consecutive sets of current thread sessions through the message nodes; The second current thread session strategy set is obtained by using the first current thread session strategy set and the exception message to obtain the second thread security quantification result; The second thread safety quantization result exceeds the first thread safety quantization result; The thread safety management result is determined by the second current thread session policy set; The second current thread session policy set, which obtains the second thread security quantification result through the first current thread session policy set and the exception message, includes: From the multiple sets of session events in the first current thread session policy set, obtain every two consecutive sets of session events; From the several analysis indicator tags in the abnormal message, obtain the corresponding analysis indicator tags for the differences between each pair of consecutive session events; By using each pair of consecutive session events and the corresponding analysis indicator labels, the relative difference results of the differences between each pair of session events are obtained; Based on the relative difference results of the differences between each pair of session events, message expansion processing is performed on each pair of session events to obtain the second current thread session strategy set.
2. The method of claim 1, wherein, The step of obtaining message nodes in the first current thread session policy set where two consecutive sets of current thread sessions differ includes: From the first current thread session strategy set, two consecutive sets of session events and the message node clusters bound to the two sets of session events are extracted; The message node is obtained by binding the message node clusters to the two sets of session events respectively.
3. The method of claim 1, wherein, The exception messages obtained through the message node, which are two consecutive sets of global analysis indications between the current thread sessions, include: Obtain the processing result in the processing model corresponding to the message node; The abnormal message corresponding to the analysis indication is obtained from the processing result, and the abnormal message of the global analysis indication is marked.
4. The method of claim 2, wherein, The abnormal messages include: Analyze the message node that indicates loading, analyze the location of the loading indicator, and / or analyze the tag that indicates loading; The analysis indicates the loaded tags, which are used to characterize the tags that change in the difference tags between the two sets of session events.
5. The method of claim 1, wherein, The second current thread session strategy set is obtained by performing message expansion processing on each pair of session events based on the relative difference results of the differences between each pair of session events, including: By weighting the relative differences between each pair of session events, a transition label is obtained that expands the differences between each pair of session events.
6. The method as described in claim 5, characterized in that, The method further includes: After expanding the transition label based on the difference between each pair of session events, an updated session event set is formed by each pair of session events and the transition label, and the updated session event set is determined as the second current thread session strategy set.
7. The method of claim 6, wherein, The second current thread session policy set, which obtains the second thread security quantification result through the first current thread session policy set and the exception message, includes: Load the first current thread session strategy set and the exception message into the intelligent message extension model; The intelligent message extension model processes the first current thread session strategy set and the abnormal message to output the second current thread session strategy set, which yields the second thread security quantification result.
8. The method of claim 7, wherein, Based on the first current thread session policy set consisting of a first session event queue and the exception message consisting of an analysis indicator tag queue, the second current thread session policy set, which is obtained by processing the first current thread session policy set and the exception message through the intelligent message extension model and outputting the second thread security quantification result, includes: Retrieve two consecutive sets of session event messages from the first session event queue; From the analysis indicator tag queue, obtain several analysis indicator tag messages corresponding to the two consecutive groups of session event messages; The two consecutive groups of session event messages and the plurality of analysis indicator label messages are respectively subjected to convolution processing to obtain the convolution processing result; The weighted average result is obtained from the convolution processing result; The weighted average result is used to weight the two consecutive groups of session event messages to obtain a transition message that expands the two consecutive groups of session event messages. The step of obtaining the bound weighted average result through the convolution processing result includes: The convolution processing result yields a relative difference result indicating that the two consecutive groups of session event messages differ. The relative difference result is then decomposed into a weighted average result corresponding to each key node to obtain several weighted average results. The step of weighting the two consecutive groups of session event messages using the weighted average result to obtain a transition message that expands the two consecutive groups of session event messages includes: The two consecutive sets of session event messages are based on the first session event message and the second session event message. The first weighted average result is used to identify the first session event message to obtain the first identification result, and the second weighted average result is used to identify the second session event message to obtain the second identification result. The first identification result and the second identification result are concatenated to obtain the transition message.
9. A security policy generation system characterized by comprising: The method includes a processor and a memory that communicate with each other, the processor being configured to retrieve a computer program from the memory and to implement the method of any one of claims 1-8 by running the computer program.
Citation Information
Patent Citations
Fault-tolerant strategy selection method and system for intelligent edge computing gatekeeper
CN113986589A