Dynamic protection method and system based on micro-isolation and environment perception

By employing a dynamic protection method based on micro-segmentation and environment awareness, the system assesses and groups terminal risks in real time, issues dynamic control and collection commands, solves the problem of internal terminal management in virtualized networks, and achieves efficient internal network traffic management and resource optimization.

CN116260614BActive Publication Date: 2025-11-18BEIJING VRV SOFTWARE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211615174.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-14
Publication Date
2025-11-18
Estimated Expiration
2042-12-14

AI Technical Summary

Technical Problem

Existing technologies struggle to achieve complete control over internal terminals in virtualized network environments, neglecting internal threats, and the monitoring of individual terminals by environmental awareness systems leads to resource waste.

Method used

A dynamic protection method based on micro-segmentation and environmental awareness is adopted. Risk assessment is carried out by collecting comprehensive information from terminals, multi-level grouping and comprehensive risk assessment are performed, and dynamic control and collection instructions are issued to achieve real-time intranet traffic control and resource adjustment.

Benefits of technology

It enables timely control of internal threats, reduces resource waste, improves network security level, ensures that important information consumes more resources and non-important information consumes less resources, forming an efficient dynamic protection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116260614B_ABST
    Figure CN116260614B_ABST
Patent Text Reader

Abstract

The embodiment of the present disclosure discloses a dynamic protection method and system based on micro-isolation and environment perception, wherein the method comprises: collecting initial all-around information of a terminal; performing risk assessment on the terminal based on the information to obtain a corresponding independent risk assessment result; performing multi-level grouping on the terminal to obtain multi-level grouping information of the terminal; obtaining a comprehensive risk assessment result of the terminal based on the independent risk assessment result and the multi-level grouping information, and performing dynamic control on the internal network flow and dynamic adjustment on the information collection resource of the terminal in real time; through the present application, risk assessment of each terminal and multiple linkage terminals can be performed in real time, real-time single-terminal resource occupation change and related multi-terminal strategy linkage are realized, terminal abnormality setting is monitored in real time, control and precise control of internal network flow can be triggered and executed in time, efficient dynamic protection of network security is realized, and network security level is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security maintenance technology, and in particular to a dynamic protection method and system based on micro-segmentation and environment awareness. Background Technology

[0002] The emergence of virtualization technologies such as cloud computing and storage has brought new security challenges to the field of enterprise network security. Large amounts of data are forwarded through virtual switches in virtualized network environments, blurring the boundaries of network security. The vast number of network assets and complex network communications have also put enormous pressure on enterprises to manage and control security in real time.

[0003] On the one hand, traditional designated protection schemes based on fixed network boundaries can play a certain role in improving the control of internal and external network environments, but they are difficult to achieve their due role in managing the data transmitted between internal networks. Existing micro-segmentation technologies mainly rely on the monitoring and feedback of network data, such as threat intelligence (botnets, worms, viruses, etc.) and related intelligence, but ignore the threat situation of internal terminals themselves, failing to achieve complete control over internal traffic. At the same time, due to the lag in threat intelligence and other information, when new threat information is discovered, the corresponding entity may have already spread throughout the internal network, and such latent threats are generally not taken into consideration.

[0004] On the other hand, through environmental sensing and other terminal information collection and control systems, it is theoretically possible to control all types of terminals and monitor all detailed information of all terminals at the same time. However, comprehensive monitoring of the underlying layer of a single terminal is a huge waste of terminal or virtual resources. Summary of the Invention

[0005] In view of this, the present disclosure provides a dynamic protection method and system based on micro-segmentation and environmental awareness, which can perform risk assessment of each terminal and multiple linked terminals in real time, realize real-time changes in single-terminal resource usage and related multi-terminal policy linkage, monitor terminal anomalies in real time, and promptly trigger execution control and precise control of intranet traffic, thereby achieving efficient dynamic protection of network security and improving network security level.

[0006] In a first aspect, embodiments of this disclosure provide a dynamic protection method based on micro-segmentation and environmental awareness, specifically including the following steps:

[0007] The initial comprehensive information from the acquisition terminal;

[0008] Based on the initial comprehensive information, a risk assessment is performed on the terminal to obtain the corresponding independent risk assessment results;

[0009] The terminal is grouped into multiple levels to obtain the multi-level grouping information of the terminal;

[0010] Based on the independent risk assessment results and the comprehensive risk assessment results of the multi-level group information acquisition terminal;

[0011] Based on the comprehensive risk assessment results, dynamic control instructions and dynamic data collection instructions are issued to dynamically control intranet traffic and dynamically adjust information collection resources for terminals.

[0012] Optionally, the initial comprehensive information includes physical information, hardware information, malicious information, security configuration information, vulnerability information, information on critical system objects, browser information, behavioral information, network information, system account information, and system environment information.

[0013] Optionally, the independent risk assessment results include the physical information assessment results Q. i1 Hardware Information Evaluation Results Q i2 Malicious Information Assessment Results Q i3 Security configuration information assessment results Q i4 Vulnerability information assessment results Q i5 System object information evaluation results Q i6 Browser information evaluation results Q i7 Behavioral information assessment results Q i8 Network information assessment results Q i9 System account information assessment results Q i10 System environment information assessment results Q i11 And the initial total evaluation result Q i ;

[0014] Q i =Q i1 +Q i2 +Q i3 +Q i4 +Q i5 +Q i6 +Q i7 +Q i8 +Q i9 +Q i10 +Q i11 ;

[0015] i∈[1,n], where n is the number of terminals.

[0016] Optionally, the multi-level grouping specifically includes the following steps:

[0017] A clustering algorithm is used to group the n terminals in the bottom layer to obtain the first level. The first level includes A1 first-level terminals, and each first-level terminal includes a1 terminals, where 1 < a1 < A.

[0018] Determine whether there is an intranet connection between the A1 primary terminals in the first level. If there is, continue grouping; if not, end grouping.

[0019] When A in the (M+1)th level M+1 When there is no intranet connection between M+1 level terminals, grouping is stopped; wherein, a single M+1 level terminal includes a M+1 One M-level terminal;

[0020] 0 < a M+1 <M; 1≤M.

[0021] Optionally, the comprehensive risk assessment result is M. i :

[0022]

[0023] D ji Let D be the distance between the j-th terminal and the i-th terminal, 0 < D. ji <1;

[0024] 1≤j≤n; j <i<n。

[0025] Optionally, the dynamic control instructions include a first control instruction, a second control instruction, and a third control instruction;

[0026] The control level of the second control instruction is higher than that of the first control instruction; the control level of the third control instruction is higher than that of the second control instruction.

[0027] Optionally, the dynamic control is a trigger execution module;

[0028] The execution module includes a first control module, a second control module, and a third control module;

[0029] When M i When ∈[0.3M0,0.5M0], the first control module is triggered to execute the first control instruction;

[0030] When M i When ∈(0.5M0,0.8M0), the second control module is triggered to execute the second control instruction;

[0031] When M i When ∈[0.8M0,∞), the third control module is triggered to execute the third control instruction;

[0032] M0 is the preset evaluation threshold.

[0033] Optionally, when M i∈(0.5M0+nk,0.5M0+(n+1)k), disconnect the intranet connection between the terminal at level mn and other terminals in the same group at the same level;

[0034] n∈[0,m-1];

[0035] k = 0.3M0 / m, where m is the number of levels in the multi-level grouping.

[0036] Optionally, the first control command is a device alarm;

[0037] The second control command is network isolation;

[0038] The third control command is system lock.

[0039] Optionally, the dynamic acquisition command triggers the information acquisition module group to acquire corresponding information;

[0040] The information collection module group includes a physical information module, a hardware information module, a malicious information module, a security configuration information module, a vulnerability information module, a system key object information module, a browser information module, a behavior information module, a network information module, a system account information module, and a system environment information module.

[0041] Optionally, the dynamic adjustment of the information collection resources includes the resource proportion P. i Dynamic adjustment and data acquisition tilt St i Dynamic adjustment;

[0042] The resource proportion P i The dynamic adjustment is as follows:

[0043] When M i When ∈[0.3M0,0.5M0], P i =1.5P0;

[0044] When M i When ∈(0.5M0,0.8M0), P i =2P0;

[0045] When M i When ∈[0.8M0,∞), P i =2.5P0;

[0046] P0 is the preset initial percentage;

[0047] The data acquisition tilt St i The dynamic adjustment is based on the resource ratio of the terminal to dynamically allocate resources to each information collection module in real time.

[0048] St1=P i ×Qi1 / Q i St1 represents the tilt angle collected by the physical information module.

[0049] St2=P i ×Q i2 / Q i St2 represents the tilt angle acquired by the hardware information module.

[0050] St3=P i ×Q i3 / Q i St3 represents the tilt angle of the malicious information module.

[0051] St4=P i ×Q i4 / Q i St4 is the tilt angle collected by the security configuration information module.

[0052] St5=P i ×Q i5 / Q i St5 represents the tilt angle for the vulnerability information module.

[0053] St6=P i ×Q i6 / Q i St6 represents the tilt angle for the system's key object information module.

[0054] St7=P i ×Q i7 / Q i St7 is the tilt angle collected by the browser's information module.

[0055] St8=P i ×Q i8 / Q i St8 represents the tilt angle collected by the behavior information module.

[0056] St9=P i ×Q i9 / Q i St9 represents the tilt angle collected by the network information module.

[0057] St 10 =P i ×Q i10 / Q i ;St 10 The tilt angle is collected for the system account information module;

[0058] St 11 =P i ×Q i11 / Q i ;St 11The tilt angle is collected for the system environment information module.

[0059] Optionally, when M i ∈(0, 0.3M0), P i =0.9 t P0;

[0060] t is M i The number of times the value falls within this range consecutively; t≥1.

[0061] Secondly, embodiments of this disclosure also provide a dynamic protection system integrating micro-segmentation and environmental awareness, comprising:

[0062] The data acquisition module is configured to collect initial omnidirectional information from the terminal.

[0063] An independent risk assessment module is configured to perform a risk assessment on the terminal based on the initial comprehensive information to obtain a corresponding independent risk assessment result.

[0064] The multi-level grouping module is configured to perform multi-level grouping of terminals in order to obtain multi-level grouping information of the terminals.

[0065] The comprehensive risk assessment module is configured to be based on the independent risk assessment results and the comprehensive risk assessment results of the multi-level grouping information acquisition terminal;

[0066] The dynamic execution module is configured to issue dynamic control commands and dynamic collection commands based on the comprehensive risk assessment results, so as to dynamically control the internal network traffic of the terminal and dynamically adjust the information collection resources.

[0067] Thirdly, this disclosure also provides an electronic device that adopts the following technical solution:

[0068] The electronic device includes:

[0069] At least one processor; and,

[0070] A memory communicatively connected to the at least one processor; wherein,

[0071] The memory stores instructions that can be executed by the at least one processor, which enables the at least one processor to perform any of the above-described dynamic protection methods based on micro-segmentation and environment awareness.

[0072] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing computer instructions for causing a computer to execute any of the above-described dynamic protection methods based on micro-segmentation and environment awareness.

[0073] 1) The dynamic protection method based on micro-segmentation and environmental awareness disclosed in this application can perform risk assessment of a single terminal and multiple linked terminals in real time, so as to carry out real-time changes in single-terminal resource usage and related multi-terminal policy linkage, effectively reduce the pressure on each terminal during operation, avoid waste of resources, monitor terminal anomalies in real time, and trigger control in a timely manner to prevent the spread of unknown threats, thus forming an efficient dynamic protection system.

[0074] 2) The dynamic protection method based on micro-segmentation and environmental awareness disclosed in this application obtains the risk results of terminals in real time through the issuance of dynamic control commands, identifies threat information in real time, triggers the execution of corresponding control measures, prevents the spread within the intranet, and performs different degrees of network isolation or connectivity according to different levels of grouping, achieving precise control of intranet traffic. Through the issuance of dynamic collection commands, related multi-terminal policies are linked in real time to dynamically adjust the intranet traffic occupied by terminals, achieving precise control of the resource usage weight of individual terminals. Based on the detection results, the resource usage of individual terminals is changed in real time, effectively avoiding resource waste. Simultaneously, based on the real-time adjustment of individual terminal resource usage, the tilt of the underlying multi-dimensional information collection of individual terminals is dynamically adjusted to ensure that important information occupies more resources and unimportant information occupies fewer resources, thereby freeing up more resources for the terminal and enabling the terminal to have a matching dynamic collection intensity.

[0075] The above description is merely an overview of the technical solution disclosed herein. In order to better understand the technical means of this disclosure and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0076] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0077] Figure 1 This is a logic flowchart of the dynamic protection method based on micro-segmentation and environmental awareness in this application.

[0078] Figure 2 This is a schematic diagram of a specific embodiment of the multi-level grouping in this application.

[0079] Figure 3 This is a schematic diagram of the integrated micro-segmentation and environmental awareness dynamic protection system in this application.

[0080] Figure 4This is a schematic block diagram of an electronic device provided in an embodiment of the present disclosure. Detailed Implementation

[0081] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0082] It should be understood that the following specific examples illustrate the implementation of this disclosure, and those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0083] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.

[0084] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this disclosure. The drawings only show the components related to this disclosure and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0085] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0086] Reference Figure 1 The first aspect of this application discloses a dynamic protection method based on micro-segmentation and environmental awareness, comprising:

[0087] Collect initial comprehensive information from each terminal;

[0088] Based on this initial comprehensive information, a risk assessment is conducted on each terminal to obtain the corresponding independent risk assessment results;

[0089] Each terminal is grouped into multiple levels to obtain the multi-level grouping information for each terminal;

[0090] Based on the independent risk assessment results and the multi-level grouping information, a comprehensive risk assessment result for each terminal is obtained. Then, dynamic control instructions and dynamic data collection instructions are issued to dynamically control intranet traffic and dynamically adjust information collection resources for each terminal.

[0091] Specifically, by issuing dynamic control commands, the risk results of each terminal are obtained in real time, threat information is identified in real time, and corresponding control measures are triggered to prevent the spread of the virus within the intranet. At the same time, different levels of network isolation or connectivity are implemented according to different levels of grouping, so as to achieve precise control of intranet traffic.

[0092] By issuing dynamic collection commands, relevant multi-terminal strategies are linked in real time to dynamically adjust the intranet traffic occupied by each terminal. This enables precise control of resource usage weight for individual terminals, and resource usage for each terminal is changed in real time based on detection results, effectively avoiding resource waste. Simultaneously, based on the real-time adjustment of individual terminal resource usage, the tilt of the underlying multi-dimensional information collection for each terminal is dynamically adjusted to ensure that important information occupies more resources and less important information occupies fewer resources, thus freeing up more resources for each terminal and ensuring that each terminal has a matching dynamic collection intensity.

[0093] The dynamic protection method based on micro-segmentation and environmental awareness disclosed in this application enables real-time risk assessment of individual terminals and multiple interconnected terminals. This allows for real-time changes in single-terminal resource usage and related multi-terminal policy linkages, effectively reducing the pressure on each terminal during operation, avoiding resource waste, real-time monitoring of terminal anomalies, and timely triggering of control measures to prevent the spread of unknown threats, thus forming a highly efficient dynamic protection system.

[0094] Specifically, the method includes: step S100, collecting initial omnidirectional information of each terminal at a moderate frequency, and uploading the initial omnidirectional information of each terminal to the data center, which is used for data storage and exchange; under the execution of this strategy, the resources of each terminal will not be significantly occupied.

[0095] Among them, moderate frequency means that the memory resource usage of various types of terminals does not exceed 50%.

[0096] Initial comprehensive information includes one or more of the following: physical information, hardware information, malicious information, security configuration information, vulnerability information, information on critical system objects, browser information, behavioral information, network information, system account information, and system environment information.

[0097] In step S200, a risk assessment is performed through the environmental risk perception module, and each terminal is grouped into multiple levels through the micro-isolation multi-level grouping module to obtain the multi-level grouping information of each terminal; wherein, both the environmental risk perception module and the micro-isolation multi-level grouping module are connected to the data center signal.

[0098] The environmental awareness risk module enables risk assessment of each terminal and outputs the assessment results; the micro-segmentation multi-level grouping module describes the connection relationship between terminals, so as to dynamically output the linkage strategy between terminals caused by changes in the risk assessment results of individual terminals.

[0099] In this application, the environmental awareness risk module is used to perform risk assessment on each terminal based on the initial comprehensive information of each terminal, so as to obtain the corresponding independent risk assessment result.

[0100] In this embodiment, the independent risk assessment results include the physical information assessment results Q. i1 Hardware Information Evaluation Results Q i2 Malicious Information Assessment Results Q i3 Security configuration information assessment results Q i4 Vulnerability information assessment results Q i5 System object information evaluation results Q i6 Browser information evaluation results Q i7 Behavioral information assessment results Q i8 Network information assessment results Q i9 System account information assessment results Q i10 System environment information assessment results Q i11 And the initial total evaluation result Q i .

[0101] Q i =Q i1 +Q i2 +Q i3 +Q i4 +Q i5 +Q i6 +Q i7 +Q i8 +Q i9 +Q i10 +Q i11 ; i∈[1,n], where n is the number of terminals.

[0102] The environmental awareness risk module has eleven threat intelligence databases, including physical information threat intelligence database, hardware information threat intelligence database, malicious information threat intelligence database, security configuration information threat intelligence database, vulnerability information threat intelligence database, system object information threat intelligence database, browser information threat intelligence database, behavioral information threat intelligence database, network information threat intelligence database, system account information threat intelligence database, and system environment information threat intelligence database.

[0103] Q ij For each dimension of information evaluation results, when evaluated as a score, Q i <100 points; j∈[1, 11]; That is, the total weight of the resources occupied by the eleven different types of information is 1.

[0104] Specifically, based on the level of the collected information in its corresponding threat intelligence database, appropriate adaptation is performed. The value of ; the information threat intelligence database includes a first risk level and a second risk level, and the level of the first risk level is higher than the level of the second risk level; when the collected information falls into the first risk level, In other words, the threat information corresponding to the first risk level is relatively serious and is subject to a "one-vote veto" system; when the collected information falls into the second risk level,

[0105] Specifically, The environmental awareness risk module, based on the collected physical information, determines the number of times the physical information matches in the physical information threat intelligence database, and thus obtains the physical information assessment result Q. i1 R1 represents the weight of resources used when collecting physical information in the initial all-round information; U1 represents the total number of physical threat information in the physical information threat intelligence database; and u1 represents the number of hits of physical information in the physical information threat intelligence database.

[0106] The physical information threat intelligence database includes a first physical risk level and a second physical risk level, with the first physical risk level being higher than the second physical risk level; when the collected physical information falls into the first physical risk level, In other words, the threat information corresponding to the first physical risk level is relatively serious and is subject to a "one-vote veto" system; in this case, the proportion of quantity is not considered, and it is directly judged as the highest risk. When the collected physical information falls into the second physical risk level...

[0107] Specifically, The environmental risk perception module, based on the collected hardware information, determines the number of times the hardware information matches in the hardware information threat intelligence database, and thus obtains the hardware information assessment result Q. i2R2 represents the weight of resources used when collecting hardware information in the initial all-round information; U2 represents the total number of hardware threat information in the hardware information threat intelligence database; and u2 represents the number of hits of hardware information in the hardware information threat intelligence database.

[0108] The hardware information threat intelligence database includes a first hardware risk level and a second hardware risk level, with the first hardware risk level being higher than the second hardware risk level; when the collected hardware information falls into the first hardware risk level, The first hardware risk level corresponds to a relatively serious threat and is subject to a "one-vote veto" system; when the collected hardware information falls into the second hardware risk level,

[0109] Specifically, The environmental risk perception module, based on the collected malicious information, determines the number of times the malicious information matches in the malicious information threat intelligence database, and thus obtains the malicious information assessment result Q. i3 R3 represents the weight of resources used when malicious information is collected in the initial comprehensive information; U3 represents the total number of malicious threat information in the malicious information threat intelligence database; and u3 represents the number of times malicious information is hit in the malicious information threat intelligence database.

[0110] The malicious information threat intelligence database includes a first malicious risk level and a second malicious risk level, with the first malicious risk level being higher than the second malicious risk level; when collected malicious information falls into the first malicious risk level, The first level of malicious risk corresponds to a relatively serious threat, and is subject to a "one-vote veto" system; when the collected malicious information falls into the second level of malicious risk,

[0111] Specifically, The environmental risk awareness module, based on the collected security configuration information, determines the number of times the security configuration information matches in the security configuration information threat intelligence database, and then obtains the security configuration information assessment result Q. i4 R4 represents the weight of resources used when collecting security configuration information in the initial comprehensive information; U4 represents the total number of security configuration threat information items in the security configuration information threat intelligence database; and u4 represents the number of times the security configuration information is matched in the security configuration information threat intelligence database.

[0112] The security configuration information threat intelligence database includes a first security configuration risk level and a second security configuration risk level, with the first security configuration risk level being higher than the second security configuration risk level; when the collected security configuration information falls into the first security configuration risk level, In other words, the threat information corresponding to the first security configuration risk level is relatively serious and is subject to a "one-vote veto" system; when the collected security configuration information falls into the second security configuration risk level,

[0113] Specifically, The environment awareness and risk module, based on the collected vulnerability information, determines the number of times a vulnerability is matched in the vulnerability information threat intelligence database, and then obtains the vulnerability information assessment result Q. i5 R5 represents the weight of resources used when collecting vulnerability information in the initial comprehensive information collection; U5 represents the total number of vulnerability threat information in the vulnerability information threat intelligence database; and u5 represents the number of vulnerability information hits in the vulnerability information threat intelligence database.

[0114] The vulnerability information threat intelligence database includes a first vulnerability risk level and a second vulnerability risk level, with the first vulnerability risk level being higher than the second vulnerability risk level; when the collected vulnerability information falls into the first vulnerability risk level, In other words, the threat information corresponding to the first vulnerability risk level is relatively serious and is subject to a "one-vote veto" system; when the collected vulnerability information falls into the second vulnerability risk level,

[0115] Specifically, The environmental awareness and risk module, based on the collected information on critical system objects, determines the number of times this information matches the threat intelligence database for critical system objects, and thus obtains the assessment result Q for the critical system object information. i6 R6 represents the weight of resources used when collecting information on critical system objects in the initial comprehensive information; U6 represents the total number of all critical system object threat information in the critical system object information threat intelligence database; and u6 represents the number of times critical system object information is hit in the critical system object information threat intelligence database.

[0116] The system's critical object information threat intelligence database includes a first-level risk level and a second-level risk level for critical objects in the system. The risk level of the first-level critical object is higher than that of the second-level critical object. When the collected information about a critical object falls within the first-level risk level, In other words, if the risk level of a key object in the first system corresponds to a relatively serious threat, it is subject to a "one-vote veto" system; when the collected information on a key object in the system falls into the risk level of a key object in the second system,

[0117] Specifically, The environmental risk awareness module, based on collected browser information, determines the number of times the browser information matches in the browser information threat intelligence database, and thus obtains the browser information assessment result Q.i7 R7 represents the weight of resources used when collecting browser information in the initial comprehensive information collection; U7 represents the total number of browser threat information in the browser information threat intelligence database; and u7 represents the number of hits of browser information in the browser information threat intelligence database.

[0118] The browser information threat intelligence database includes a first browser risk level and a second browser risk level, with the first browser risk level being higher than the second browser risk level; when collected browser information falls into the first browser risk level, In other words, the threat information corresponding to the first browser risk level is relatively serious, and it is subject to a "one-vote veto" system; when the collected browser information falls into the second browser risk level,

[0119] Specifically, The environmental awareness risk module, based on the collected behavioral information, determines the number of times the behavioral information matches the behavioral information threat intelligence database, and thus obtains the behavioral information assessment result Q. i8 R8 represents the weight of resources used when collecting behavioral information in the initial comprehensive information; U8 represents the total number of behavioral threat information items in the behavioral information threat intelligence database; and u8 represents the number of hits of behavioral information in the behavioral information threat intelligence database.

[0120] The behavioral information threat intelligence database includes a first behavioral risk level and a second behavioral risk level, with the first behavioral risk level being higher than the second behavioral risk level; when the collected behavioral information falls into the first behavioral risk level, In other words, the first behavior level corresponds to a relatively serious threat, which is subject to a "one-vote veto" system; when the collected behavior information falls into the second behavior level,

[0121] Specifically, The environmental risk perception module, based on the collected network information, determines the number of times the network information matches in the network information threat intelligence database, and thus obtains the network information assessment result Q. i9 R9 represents the weight of resources used when collecting network information in the initial comprehensive information collection; U9 represents the total number of network threat information in the network information threat intelligence database; and u9 represents the number of network information hits in the network information threat intelligence database.

[0122] The network information threat intelligence database includes a first network risk level and a second network risk level, with the first network risk level being higher than the second network risk level; when the collected network information falls into the first network risk level, The first level of network risk corresponds to a relatively serious threat and is subject to a "one-vote veto" system; when the collected network information falls into the second level of network risk,

[0123] Specifically, The environmental risk awareness module, based on the collected system account information, determines the number of times each system account information matches in the system account information threat intelligence database, and thus obtains the system account information assessment result Q. i10 ;R 10 U represents the weight of resources used when collecting system account information during the initial comprehensive information gathering process. 10 u represents the total number of system account threat information entries in the system account information threat intelligence database. 10 This represents the number of times system account information is matched in the system account information threat intelligence database.

[0124] The system account information threat intelligence database includes a first system account risk level and a second system account risk level, with the first system account risk level being higher than the second system account risk level; when collected system account information falls within the first system account risk level, In other words, the threat information corresponding to the first system account risk level is relatively serious and is subject to a "one-vote veto" system; when the collected system account information falls into the second system account risk level,

[0125] Specifically, The environmental awareness and risk module, based on the collected system environmental information, determines the number of times the system environmental information matches in the system environmental information threat intelligence database, and then obtains the system environmental information assessment result Q. i11 ;R 11 U represents the weight of resources used when collecting system environment information during the initial comprehensive information gathering process. 11 u represents the total number of system environment threat information entries in the system environment information threat intelligence database. 11 This represents the number of times system environment information is matched in the system environment information threat intelligence database.

[0126] The system environment information threat intelligence database includes a first system environment risk level and a second system environment risk level, with the first system environment risk level being higher than the second system environment risk level; when the collected system environment information falls within the first system environment risk level, In other words, the threat information corresponding to the first system environment risk level is relatively serious and is subject to a "one-vote veto" system; when the collected system environment information falls into the second system environment risk level,

[0127] Specifically, refer to Figure 2The steps for performing multi-level grouping in the micro-segmentation multi-level grouping module are as follows:

[0128] 1) A clustering algorithm is used to group the n terminals in the bottom layer to obtain the first level; the first level includes A1 first-level terminals, and each first-level terminal includes a1 terminals, 1 < a1 < A; there is no grouping of the n terminals in the bottom layer.

[0129] Determine whether there is an intranet connection between the A1 level terminals in the first level. If there is, continue grouping; otherwise, end grouping.

[0130] 2) The A1 primary terminals in the first level are grouped by clustering algorithm to obtain the second level; the second level includes A2 secondary terminals, and each secondary terminal includes a2 primary terminals, where 0 < a2 < A1.

[0131] Determine whether there is an intranet connection between the A2 secondary terminals in the second level. If there is, continue grouping; otherwise, end grouping.

[0132] 3) Clustering algorithm is used to analyze A in the Mth level. M Grouping M-level terminals to obtain the (M+1)th level, the (M+1)th level includes A M+1 There are M+1 level terminals, each of the M+1 level terminals including a M+1 There are M-level terminals, 0 < a M+1 <M; 1≤M.

[0133] When A in the (M+1)th level M+1 When there is no intranet connection between M+1 level terminals, grouping is stopped.

[0134] It should be noted that the number of terminals in each group can be the same or different. This application does not limit the number of terminals in each group. The multi-level grouping information output by the micro-segmentation multi-level grouping module exists as a terminal attribute, but it is not fixed. The grouping will be continuously and dynamically updated according to the reported network connectivity.

[0135] When it is an intranet, the network information includes IP address and port information; when it is an external network, the network information includes website address and domain name information.

[0136] In step S300, the independent risk assessment results output by the environmental awareness risk module and the multi-level grouping information output by the micro-segmentation multi-level grouping module are both transmitted to the data center; then, the data center transmits the independent risk assessment results and multi-level grouping information to the policy center, and obtains the comprehensive risk assessment result M for each terminal through the policy center. i The strategy center is connected to the data center via a signal.

[0137] Among them, D ji Let D be the distance between the j-th terminal and the i-th terminal, 0 < D. ji <1; 1≤j≤n; j <i<n。

[0138] In step S400, the policy center issues dynamic control instructions and dynamic collection instructions to dynamically control intranet traffic and dynamically adjust information collection resources for each terminal.

[0139] Specifically, the strategy center uses dynamic control commands to trigger execution modules to perform different levels of network isolation and connectivity in real time. The execution modules include a first control module, a second control module, and a third control module. When the first control module, the second control module, or the third control module is triggered by the dynamic control commands, the corresponding first control command, the second control command, or the third control command is executed. The control level of the second control command is higher than that of the first control command; the control level of the third control command is higher than that of the second control command.

[0140] In this embodiment, the first control instruction, the second control instruction, and the third control instruction refer to the device alarm instruction, the network isolation instruction, and the terminal lock instruction, respectively. That is, the execution module includes the device alarm module, the network isolation module, and the terminal control module, and the device alarm module, the network isolation module, and the terminal control module are all connected to the policy center via signals.

[0141] When M i When the value is ∈[0.3M0,0.5M0], the device alarm module is triggered to issue a device alarm, that is, the strategy center triggers the device alarm module to execute the device alarm command.

[0142] When M i When ∈(0.5M0,0.8M0), the network isolation module is triggered to perform network isolation for the corresponding terminal, that is, the policy center triggers the network isolation module to execute the network isolation command.

[0143] When M i When ∈[0.8M0,∞), the terminal management module is triggered to lock the corresponding terminal's system, that is, the policy center triggers the terminal management module to execute the terminal lock command.

[0144] M0 is the preset evaluation threshold.

[0145] Furthermore, when M i ∈(0.5M0+nk,0.5M0+(n+1)k), disconnect the intranet connection between the terminal at level mn and other terminals in the same group at the same level; where n∈[0,m-1]; k=0.3M0 / m, m is the number of levels in the multi-level group.

[0146] Specifically, when M i ∈(0.5M0,0.5M0+k), disconnect the intranet connection between the m-th level of this terminal and other terminals in the same group;

[0147] When M i ∈(0.5M0+k,0.5M0+2k), disconnect the terminal's (m-1)th level from the intranet connections of other terminals in the same group;

[0148] When M i ∈(0.5M0+(m-1)k,0.8M0), disconnect this terminal from all intranet terminals.

[0149] It should be noted that the network isolation here is not a one-size-fits-all approach, but rather based on the idea of ​​multi-level grouping and micro-segmentation, separating the internal and external networks, and so on, until the terminal loses connection with all internal network terminals.

[0150] Furthermore, the external network connection can be set to block external network access when it reaches 0.6M0.

[0151] The strategy center issues dynamic collection commands to trigger the information collection module group to collect corresponding information. In this embodiment, the information collection module group includes a physical information module, a hardware information module, a malicious information module, a security configuration information module, a vulnerability information module, a system key object information module, a browser information module, a behavior information module, a network information module, a system account information module, and a system environment information module.

[0152] Dynamic adjustment of information collection resources includes resource proportion P i Dynamic adjustment and data acquisition tilt St i Dynamic adjustment;

[0153] Of which, the resource proportion P i The dynamic adjustments are specifically divided into the following categories:

[0154] When M i When ∈[0.3M0,0.5M0], P i =1.5P0;

[0155] When M i When ∈(0.5M0,0.8M0), P i =2P0;

[0156] When M i When ∈[0.8M0,∞), P i =2.5P0;

[0157] P0 is the preset initial percentage, and the resource percentage P iThis refers to the proportion of terminal resources occupied by the information collection module group for each terminal.

[0158] When M i ∈(0, 0.3M0), P i =0.9 t P0, through dynamic updates, gradually releases more resources; where t is M. i The number of times the value falls within this range consecutively; t≥1.

[0159] When t > 5000, it indicates that the terminal consistently occupies relatively few resources. In order to release more resources for the terminal, let P... i =1.5P0, collect information from various dimensions within the terminal, re-execute the risk assessment steps of this application, and obtain dynamically updated M. i Then, regarding the M i Make a judgment if M i ∈(0, 0.3M0), let t = 1, P i =0.9 t P0 is executed repeatedly to increase the identification of threat information missed due to low collection granularity. At the same time, after continuously falling into the smallest range, the presence of the terminal in the information collection process is reduced, while ensuring the normal operation of the terminal.

[0160] Data Acquisition Tilt St i The dynamic adjustment is based on the resource ratio of each terminal, and the resources of each information collection module are dynamically allocated in real time. The specific allocation scheme is as follows:

[0161] St1=P i ×Q i1 / Q i St1 represents the tilt angle collected by the physical information module;

[0162] St2=P i ×Q i2 / Q i St2 represents the tilt angle collected by the hardware information module;

[0163] St3=P i ×Q i3 / Q i St3 represents the tilt angle of the malicious information module.

[0164] St4=P i ×Q i4 / Q i St4 is the tilt angle collected by the security configuration information module;

[0165] St5=P i ×Q i5 / Q iSt5 represents the tilt angle of the vulnerability information module.

[0166] St6=P i ×Q i6 / Q i St6 represents the tilt angle for the system's key object information module.

[0167] St7=P i ×Q i7 / Q i St7 represents the tilt angle collected by the browser's information module;

[0168] St8=P i ×Q i8 / Q i St8 represents the tilt angle collected by the behavior information module;

[0169] St9=P i ×Q i9 / Q i St9 represents the tilt angle collected by the network information module;

[0170] St 10 =P i ×Q i10 / Q i St 10 The tilt angle is collected for the system account information module;

[0171] St 11 =P i ×Q i11 / Q i St 11 The tilt angle is collected for the system environment information module.

[0172] By monitoring the data acquisition tilt, the resources occupied by less important modules can be detected in real time. Through dynamic detection and judgment, the resource allocation of information acquisition sub-modules in each terminal can be adjusted in real time to improve the operating efficiency of the intranet, ensuring that important modules have a larger share of resources, thereby achieving fast and efficient operation of the whole system.

[0173] It should be noted that the micro-segmentation multi-level grouping module in this application can also group all terminals at the bottom layer based on data transmission between devices using a grouping algorithm, and assign a unique ID to the obtained hierarchical group for differentiation. Based on the derived first-level grouping, data transmission between groups is statistically analyzed, and then the second-level grouping is constructed using a grouping algorithm; this process continues until a suitable number of groups and grouping levels are constructed. Note that the grouping information of each terminal at different levels is not static and will dynamically change based on subsequently reported terminal information; each terminal is grouped using a micro-segmentation grouping model based on its network information.

[0174] Furthermore, during the execution of the embodiments, the physical information evaluation results, hardware information evaluation results, malicious information evaluation results, security configuration information evaluation results, vulnerability information evaluation results, system object information evaluation results, browser information evaluation results, behavioral information evaluation results, network information evaluation results, system account information evaluation results, system environment information evaluation results, initial overall evaluation results, and comprehensive risk evaluation results can all be the corresponding scores.

[0175] During real-time monitoring and dynamic control, when the score corresponding to the comprehensive risk assessment result begins to rise, B1 is executed;

[0176] B1) The strategy center issues more granular collection strategies to the terminal and simultaneously synchronizes this information to the environmental awareness risk module;

[0177] B2) The environmental risk perception module changes the corresponding processing logic based on the synchronized information to achieve more accurate and stricter scoring;

[0178] B3) When the score rises to a certain threshold, the network between the top-level groups will be disconnected; the specific implementation method is that the policy center issues the corresponding isolation policy to each terminal, and the gateway on each terminal will execute the corresponding operation.

[0179] B4) If the comprehensive risk assessment result output by the environmental awareness risk module under the new logic continues to rise, it will trigger the network disconnection between the next level groups to achieve further network isolation; at the same time, the policy center will issue more granular information collection strategies to the terminals with rising scores and related terminals closely associated with them, such as terminals in the same group at the lowest level; the environmental awareness risk module will also change its data processing logic for the data reported by the above terminals.

[0180] B5) Administrators can use the deduction categories provided by the environmental risk perception module to specifically fix the deduction items of the deducting terminals, and reduce the overall score of the environmental risk perception module by using the data re-reported by the terminals.

[0181] When the score starts to decrease, execute C1;

[0182] C1) The strategy center issues coarser-grained collection strategies to the terminals to reduce the encroachment on the internal resources of each terminal during the collection of various types of information; at the same time, the information is synchronized to the environmental awareness risk module.

[0183] C2) The environmental risk perception module changes the corresponding processing logic based on the synchronized information to achieve more accurate scoring;

[0184] C3) When the score drops to a certain threshold, if there is a disconnection in the network at different levels, the network connection will be re-allowed between the lowest level groups; the specific implementation method is that the policy center issues the corresponding connectivity policy to each terminal.

[0185] C4) If the environmental risk perception module score continues to decrease under the new logic, it will trigger the reconnection of the network between higher-level groups until the network connection between the top-level groups is achieved; at the same time, the policy center will issue a coarser-grained information collection policy to the corresponding terminals, and the environmental risk perception module will also change its data processing logic accordingly.

[0186] Existing solutions, in order to achieve accurate information collection and control of terminals, collect a large amount of various information from each terminal, resulting in a significant waste of terminal resources. The solution disclosed in this application flexibly configures the ratio of information to be collected from each terminal, greatly reducing resource waste. At the same time, it can obtain the status of each terminal in real time, promptly detect abnormal information, and trigger corresponding control policies in real time, realizing real-time monitoring, analysis, and control of each terminal. This prevents the threat posed by abnormal information from spreading within the intranet, achieving dynamic network security protection, effectively improving network security level, and achieving efficient resource utilization.

[0187] When an anomalies occur, the monitoring and control of the terminal are strengthened as the degree of anomaly increases. At the same time, to prevent the terminal from having a hidden impact on other terminals associated with it, different levels of grouping are implemented through artificial intelligence based on the degree of connectivity. Different blocking methods are adopted for different levels of grouping to prevent the spread of unknown threats as much as possible, achieve timely risk control, and effectively prevent the spread of threat information on the internal network while achieving precise control of internal network traffic.

[0188] Reference Figure 3 The second aspect of this application discloses a dynamic protection system integrating micro-segmentation and environmental awareness, comprising:

[0189] The acquisition module (i.e., the information acquisition module group) is configured to collect initial omnidirectional information from each terminal;

[0190] The independent risk assessment module (i.e., the environmental awareness risk module) is configured to perform risk assessment on each terminal based on initial comprehensive information in order to obtain the corresponding independent risk assessment results.

[0191] The multi-level grouping module (i.e., the micro-segmentation multi-level grouping module) is configured to perform multi-level grouping on each terminal in order to obtain the multi-level grouping information of each terminal.

[0192] The comprehensive risk assessment module is configured to obtain the comprehensive risk assessment results for each terminal based on independent risk assessment results and multi-level grouping information;

[0193] The dynamic execution module is configured to issue dynamic control and collection commands based on the comprehensive risk assessment results, so as to dynamically control the intranet traffic of each terminal and dynamically adjust the information collection resources.

[0194] In this embodiment, the strategy center includes a comprehensive risk assessment module and a dynamic execution module, which are used to issue control and information collection strategies to all terminals.

[0195] Furthermore, the collected data can be stored and exchanged through the data center, or the environmental risk perception module and the micro-segmentation multi-level grouping module can be connected to the strategy center for information transmission.

[0196] Specifically, the execution module is triggered by the issued dynamic control command to dynamically control the intranet traffic of each terminal; the information collection module group is triggered by the issued dynamic collection command to dynamically adjust the information collection resources.

[0197] A third aspect of this application discloses an electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor to enable the at least one processor to perform the aforementioned dynamic protection method based on micro-segmentation and environment awareness.

[0198] The fourth aspect of this application discloses a computer-readable storage medium, characterized in that the computer-readable storage medium stores computer instructions for causing a computer to execute the aforementioned dynamic protection method based on micro-segmentation and environment awareness.

[0199] An electronic device according to embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), a hard disk, flash memory, etc.

[0200] The processor may be a central processing unit (CPU) or other processing unit with data processing and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. In one embodiment of this disclosure, the processor is used to execute computer-readable instructions stored in the memory, causing the electronic device to perform all or part of the steps of the aforementioned dynamic protection methods based on micro-segmentation and environment awareness in the embodiments of this disclosure.

[0201] Those skilled in the art will understand that, in order to solve the technical problem of how to achieve a good user experience, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included within the protection scope of this disclosure.

[0202] like Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure. It illustrates a structural schematic diagram suitable for implementing the electronic device in the embodiment of the present disclosure. Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0203] like Figure 4 As shown, an electronic device may include a processing unit (such as a central processing unit, graphics processing unit, etc.) that can perform various appropriate actions and processes based on a program stored in read-only memory (ROM) or a program loaded from a storage device into random access memory (RAM). The RAM also stores various programs and data required for the operation of the electronic device. The processing unit, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.

[0204] Typically, the following devices can be connected to the I / O interface: input devices, such as sensors or visual information acquisition devices; output devices, such as displays; storage devices, such as magnetic tapes or hard drives; and communication devices. Communication devices allow electronic devices to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 4Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.

[0205] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, all or part of the steps of the dynamic protection method based on micro-segmentation and environment awareness according to embodiments of this disclosure are performed.

[0206] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0207] A computer-readable storage medium according to embodiments of the present disclosure stores non-transitory computer-readable instructions. When these non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the aforementioned dynamic protection methods based on micro-segmentation and environment awareness according to embodiments of the present disclosure are performed.

[0208] The aforementioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or portable hard drive), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).

[0209] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0210] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0211] In this disclosure, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, devices, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as "comprising," "including," "having," etc., are open-ended terms meaning "including but not limited to," and are used interchangeably with them. The terms "or" and "and" as used herein refer to the terms "and / or," and are used interchangeably with them unless the context clearly indicates otherwise. The term "such as" as used herein refers to the phrase "such as but not limited to," and is used interchangeably with it.

[0212] Additionally, as used herein, the “or” used in a list of items beginning with “at least one” indicates a separate list, such that a list of, for example, “at least one of A, B, or C” means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word “exemplary” does not imply that the described example is preferred or better than other examples.

[0213] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0214] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0215] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0216] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A dynamic protection method based on micro-segmentation and environmental awareness, characterized in that, The method includes the following steps: The initial comprehensive information of the collection terminal includes one or more of the following: physical information, hardware information, malicious information, security configuration information, vulnerability information, system key object information, browser information, behavior information, network information, system account information, and system environment information. Based on the initial comprehensive information, a risk assessment is performed on the terminal to obtain the corresponding independent risk assessment results; The terminals are grouped into multiple levels to obtain multi-level grouping information. Specifically, this includes: grouping the n terminals in the bottom layer to obtain a first level; the first level includes... Each primary terminal includes a primary terminal. One terminal, 1 < <n; Determine the first level If an intranet connection exists between the first-level terminals, continue grouping; otherwise, end grouping. For the M-level terminals... The M-level terminals are grouped to obtain the (M+1)th level, which includes... Each M+1 level terminal includes... One M-level terminal, 0 < < , 1≤M; when in the (M+1)th level When there is no intranet connection between M+1 level terminals, grouping is stopped; The comprehensive risk assessment result of the terminal is obtained based on the independent risk assessment results and the multi-level grouping information; the comprehensive risk assessment result is... : ; For the first The terminal and the first The distance between terminals, 0 < <1; ; , For the first Independent risk assessment results for each terminal For the first Independent risk assessment results for each terminal; Based on the comprehensive risk assessment results, dynamic control instructions and dynamic data collection instructions are issued to dynamically control the intranet traffic of the terminal and dynamically adjust the information collection resources.

2. The dynamic protection method based on micro-segmentation and environmental awareness according to claim 1, characterized in that, The independent risk assessment results include physical information assessment results. Hardware information assessment results Malicious information assessment results Security configuration information assessment results Vulnerability information assessment results System object information evaluation results Browser information evaluation results Behavioral information assessment results Network information assessment results System account information evaluation results System environment information assessment results and initial overall assessment results ; ; , where n is the number of terminals.

3. The dynamic protection method based on micro-segmentation and environmental awareness according to claim 1, characterized in that, The dynamic control instructions include a first control instruction, a second control instruction, and a third control instruction; the control level of the second control instruction is higher than that of the first control instruction; the control level of the third control instruction is higher than that of the second control instruction. The dynamic acquisition command triggers the information acquisition module group to collect corresponding information. The information acquisition module group includes a physical information module, a hardware information module, a malicious information module, a security configuration information module, a vulnerability information module, a system key object information module, a browser information module, a behavior information module, a network information module, a system account information module, and a system environment information module. The dynamic control is a trigger execution module; the execution module includes a first control module, a second control module, and a third control module; when When this occurs, the first control module is triggered to execute the first control instruction; when When this occurs, the second control module is triggered to execute the second control instruction; when When this occurs, the third control module is triggered to execute the third control instruction; in, The preset evaluation threshold; The first control command is a device alarm; The second control command is network isolation; The third control command is system lock.

4. The dynamic protection method based on micro-segmentation and environmental awareness according to claim 3, characterized in that, The dynamic adjustment of information collection resources includes resource allocation. Dynamic adjustment and data acquisition tilt Dynamic adjustment; The proportion of resources The dynamic adjustment is as follows: when , = t is The number of times consecutively falling within this range; t≥1 when hour, =1.5 ; when hour, =2 ; when hour, =2.5 ; This is the preset initial percentage; The data acquisition tilt The dynamic adjustment is based on the resource ratio of the terminal to dynamically allocate resources to each information collection module in real time. / ; The tilt angle is collected for the physical information module; / ; The tilt angle is collected for the hardware information module; / ; The tilt angle is collected for the malicious information module; / ; The tilt angle is collected by the security configuration information module; / ; The tilt angle is collected for the vulnerability information module; / ; To collect tilt information for the system's key object information module; / ; Collect tilt angle data for the browser's information module; / ; The tilt angle is collected for the behavior information module; / ; The tilt angle is collected for the network information module; / ; The tilt angle is collected for the system account information module; / ; The tilt angle is collected for the system environment information module.

5. A dynamic protection system integrating micro-isolation and environmental sensing, characterized in that, include: The data acquisition module is configured to collect initial omnidirectional information from the terminal. The initial comprehensive information includes one or more of the following: physical information, hardware information, malicious information, security configuration information, vulnerability information, information on critical system objects, browser information, behavioral information, network information, system account information, and system environment information. An independent risk assessment module is configured to perform a risk assessment on the terminal based on the initial comprehensive information to obtain a corresponding independent risk assessment result. A multi-level grouping module is configured to perform multi-level grouping of terminals to obtain multi-level grouping information of the terminals. Specifically, it includes: grouping the n terminals in the bottom layer to obtain a first level; the first level includes... Each primary terminal includes a primary terminal. One terminal, 1 < <n; Determine the first level If an intranet connection exists between the first-level terminals, continue grouping; otherwise, end grouping. For the M-level terminals... The M-level terminals are grouped to obtain the (M+1)th level, which includes... Each M+1 level terminal includes... One M-level terminal, 0 < < , 1≤M; when in the (M+1)th level When there is no intranet connection between M+1 level terminals, grouping is stopped; The comprehensive risk assessment module is configured to base its assessment on the independent risk assessment results and the comprehensive risk assessment results from the multi-level grouping information acquisition terminal; the comprehensive risk assessment results are... : ; For the first The terminal and the first The distance between terminals, 0 < <1; ; , For the first Independent risk assessment results for each terminal For the first Independent risk assessment results for each terminal; The dynamic execution module is configured to issue dynamic control commands and dynamic collection commands based on the comprehensive risk assessment results, so as to dynamically control the internal network traffic of the terminal and dynamically adjust the information collection resources.

6. An electronic device, characterized in that, The electronic device includes: at least one processor; and, A memory that is communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the dynamic protection method based on micro-segmentation and environment awareness as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the dynamic protection method based on micro-segmentation and environment awareness as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Safety protection system, method and equipment and storage medium

    CN109995794A

  • Security scheduling method and system for virtual micro-isolation network

    CN111273995A

  • Risk early warning method

    CN114091042A

  • Risk assessment data processing method and device, equipment, medium and program product

    CN114970679A