Method, device and equipment for deploying mimicry defense network and medium

CN116527518BActive Publication Date: 2026-09-25INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310584292.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-23
Publication Date
2026-09-25
Estimated Expiration
2043-05-23

AI Technical Summary

Technical Problem

然而,随之而来的是网络攻击和安全威胁的不断增多,这些威胁可能导致企业业务的中断、数据泄露或损坏,从而给企业带来重大的经济和声誉损失

Benefits of technology

[0021]上述一个或多个实施例具有如下优点或有益效果:可以利用拓扑自动生成模型根据网络复杂度指标参数,推荐与目标拟态网络属于同一类簇的一个或多个网络拓扑图作为目标拟态网络的部署依据,从而实现目标拟态防御网络的快速部署和动态变更,呈现出全自动化、动态性、异构型以及冗余性的优点,达到增加黑客的信息搜集成本,让其无法摸清真实的网络脉络架构,达到阻断其制定攻击计划的目的。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116527518B_ABST
    Figure CN116527518B_ABST
Patent Text Reader

Abstract

The disclosure provides a deployment method and device of a mimicry defense network, which can be applied to the fields of artificial intelligence and information security technology. The method comprises the following steps: receiving a change instruction, wherein the change instruction comprises a network complexity index parameter; inputting the network complexity index parameter into a virtual asset arrangement subsystem, and obtaining a first network topology graph set corresponding to a target class cluster output by the virtual asset arrangement subsystem, wherein the virtual asset arrangement subsystem comprises a topology automatic generation model constructed based on a graph convolutional neural network, the topology automatic generation model is trained to cluster and divide a collected network topology graph into multiple class clusters, and the target class cluster is one of the multiple class clusters; and deploying a target mimicry defense network based on one network topology graph in the first network topology graph set. The disclosure also provides a training method and device of a topology automatic generation model, as well as an electronic device, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of artificial intelligence and information security, specifically to a method and apparatus for deploying a mimicry defense network, a method and apparatus for training an automatic topology generation model, and an electronic device, storage medium, and program product. Background Technology

[0002] With the widespread adoption of internet technology and digital commerce, businesses are increasingly reliant on networks and information systems for their operations and data. However, this also brings with it a rise in cyberattacks and security threats, which can lead to business disruptions, data breaches, or damage, resulting in significant economic and reputational losses for businesses.

[0003] The current trend of cyberattacks is towards organized, planned, and premeditated attacks, posing a significant challenge to enterprise security. In the battle between cyberattacks and defenses, the first step for hackers is information gathering, which involves collecting all information systems and enterprise data that the target has leaked on the internet. This step is crucial. Information gathering is often lengthy, periodic, and covert. Through this extensive gathering, the network structure of an enterprise can be thoroughly understood, and the attack plan gradually takes shape. This often leaves the victim enterprise unaware of the attack until it is launched, at which point the enterprise's network collapses. Summary of the Invention

[0004] In view of the above problems, this disclosure provides a method and apparatus for deploying a mimicry defense network that can disrupt hackers' information gathering on a company's real network, as well as a method and apparatus for training an automatic topology generation model, and corresponding electronic devices, media and program products.

[0005] A first aspect of this disclosure provides a method for deploying a mimicry defense network. The method includes: receiving a change instruction, wherein the change instruction includes network complexity index parameters; inputting the network complexity index parameters into a virtual asset orchestration subsystem, and obtaining a first set of network topology graphs corresponding to a target cluster output by the virtual asset orchestration subsystem; wherein the virtual asset orchestration subsystem includes an automatic topology generation model constructed based on a graph convolutional neural network, the automatic topology generation model being trained to cluster N collected network topology graphs and divide them into multiple clusters, the target cluster being one of the multiple clusters, and N being an integer greater than 1; and deploying a target mimicry defense network based on a network topology graph from the first set of network topology graphs.

[0006] According to an embodiment of this disclosure, deploying a target mimicry defense network based on a network topology map in the first network topology map set includes: obtaining a second network topology map set consisting of network topology maps of previously deployed mimicry defense networks; removing the intersection of the first network topology map set with the second network topology map set to obtain a candidate network topology map set; and deploying the target mimicry defense network based on a network topology map in the candidate network topology map set.

[0007] According to embodiments of this disclosure, the network complexity index parameters include the feature information of key nodes in the target mimicry defense network and the network topology information of the target mimicry defense network.

[0008] According to embodiments of this disclosure, after inputting the network complexity index parameters into the virtual asset orchestration subsystem, a feature matrix of the target mimicry defense network is obtained based on the feature information of key nodes in the target mimicry defense network; an adjacency matrix of the target mimicry defense network is obtained based on the network topology information of the target mimicry defense network; a target input matrix corresponding to the target mimicry defense network is obtained based on the feature matrix and adjacency matrix of the target mimicry defense network; the target input matrix is ​​input into the graph convolutional neural network, and the graph convolutional neural network is used to extract features from the target mimicry defense network; based on the features of the target mimicry defense network extracted by the graph convolutional neural network, the target mimicry defense network is divided into one of the plurality of clusters, wherein the cluster to which the target mimicry defense network is divided is determined as the target cluster.

[0009] According to embodiments of this disclosure, the number of key nodes in the target mimicry defense network is less than the number of nodes in the network topology information of the target mimicry defense network; wherein, in the target input matrix, the information corresponding to the same node in the feature matrix and adjacency matrix of the target mimicry defense network is concatenated in the same row.

[0010] According to embodiments of this disclosure, deploying the target mimicry defense network based on a network topology map from the first set of network topology maps includes: using the network topology map determined from the first set of network topology maps as the basis for deploying the target mimicry defense network as the target network topology map; obtaining network topology information and node feature information of the target network topology map; obtaining virtual assets in the target mimicry defense network based on the node feature information of the target network topology map; and establishing connection relationships between virtual assets in the target mimicry defense network according to the network topology information of the target network topology map, so as to realize the deployment of the target mimicry defense network.

[0011] According to embodiments of this disclosure, obtaining virtual assets in the target mimicry defense network based on the feature information of nodes in the target network topology includes: searching for virtual assets that match the feature information of nodes in the target network topology from a preset virtual asset library; if a match is found, retrieving the corresponding virtual asset from the virtual asset library; if no match is found, assembling the corresponding virtual asset based on the feature information of nodes in the target network topology.

[0012] According to embodiments of this disclosure, establishing the connection relationship between virtual assets in the target mimicry defense network further includes: setting the virtual assets in the target mimicry defense network to not communicate with assets in the real network according to a network isolation strategy, wherein the target mimicry defense network and the real network belong to the same intranet.

[0013] According to embodiments of this disclosure, the training process of the automatic topology generation model is as follows: acquiring information about the N network topology graphs, wherein the information of each network topology graph includes network topology information and node feature information; processing the information of each of the N network topology graphs to obtain an input matrix corresponding to each network topology graph; and training the automatic topology generation model to cluster the N network topology graphs, specifically including: inputting the input matrix corresponding to each network topology graph into the graph convolutional neural network, using the graph convolutional neural network to extract features from each network topology graph, and clustering the N network topology graphs based on the features extracted by the graph convolutional neural network. The processing of the information of each of the N network topology graphs includes: obtaining a feature matrix for each network topology graph based on the node feature information; obtaining an adjacency matrix for each network topology graph based on the network topology information; and obtaining an input matrix corresponding to each network topology graph based on the feature matrix and adjacency matrix.

[0014] A second aspect of this disclosure provides a training method for an automatic topology generation model. The training method includes: acquiring information from N network topology graphs, wherein the information of each network topology graph includes network topology information and node feature information, and N is an integer greater than 1; processing the information of each of the N network topology graphs to obtain an input matrix corresponding to each network topology graph; and training the automatic topology generation model to cluster the N network topology graphs, specifically including: inputting the input matrix corresponding to each network topology graph into the graph convolutional neural network, using the graph convolutional neural network to extract features from each network topology graph, and clustering the N network topology graphs based on the features extracted by the graph convolutional neural network. The processing of the information of each of the N network topology graphs includes: obtaining a feature matrix for each network topology graph based on the node feature information; obtaining an adjacency matrix for each network topology graph based on the network topology information; and obtaining an input matrix corresponding to each network topology graph based on the feature matrix and adjacency matrix.

[0015] A third aspect of this disclosure provides a deployment apparatus for a mimicry defense network. The apparatus includes a backend management system, a virtual asset orchestration subsystem, and a virtual asset management subsystem. The backend management system is used to receive change instructions, wherein the change instructions include network complexity index parameters. The virtual asset orchestration subsystem is used to input the network complexity index parameters and output a first set of network topology graphs corresponding to a target cluster. The virtual asset orchestration subsystem includes an automatic topology generation model built based on a graph convolutional neural network. This automatic topology generation model, after training, clusters the collected network topology graphs and divides them into multiple clusters, with the target cluster being one of these multiple clusters. The virtual asset management subsystem is used to deploy a target mimicry defense network based on a network topology graph from the first set of network topology graphs.

[0016] According to embodiments of this disclosure, the virtual asset orchestration subsystem is further configured to: obtain a second set of network topology graphs consisting of network topology graphs of previously deployed mimicry defense networks; and remove the intersections with the second set of network topology graphs from the first set of network topology graphs to obtain a candidate set of network topology graphs. The virtual asset management subsystem is further configured to deploy the target mimicry defense network based on a network topology graph from the candidate set of network topology graphs.

[0017] A fourth aspect of this disclosure provides a training apparatus for an automatic topology generation model. The training apparatus includes a data collection unit, a data processing unit, and a model training unit. The data collection unit acquires information from N network topology graphs, where N is an integer greater than 1. The information for each network topology graph includes network topology information and node feature information. The data processing unit processes the information from each of the N network topology graphs to obtain an input matrix corresponding to each network topology graph. The model training unit trains the automatic topology generation model to cluster the N network topology graphs, including: inputting the input matrix corresponding to each network topology graph into the graph convolutional neural network; extracting features from each network topology graph using the graph convolutional neural network; and clustering the N network topology graphs based on the features extracted by the graph convolutional neural network. Specifically, the data processing unit is used to: obtain the feature matrix of each network topology graph based on the feature information of the nodes of each network topology graph; obtain the adjacency matrix of each network topology graph based on the network topology information of each network topology graph; and obtain the input matrix corresponding to each network topology graph based on the feature matrix and adjacency matrix of each network topology graph.

[0018] A third aspect of this disclosure provides an electronic device. The electronic device includes one or more processors and a memory. The memory is used to store one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to perform the above-described method for deploying a mimicry defense network or a method for training an automatic topology generation model.

[0019] A fourth aspect of this disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the above-described method for deploying a mimicry defense network or a method for training an automatic topology generation model.

[0020] The fifth aspect of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method for deploying a mimicry defense network or a method for training an automatic topology generation model.

[0021] The above one or more embodiments have the following advantages or beneficial effects: the automatic topology generation model can be used to recommend one or more network topologies belonging to the same cluster as the target mimicry network based on network complexity index parameters, thereby enabling rapid deployment and dynamic changes of the target mimicry defense network. It exhibits the advantages of full automation, dynamism, heterogeneity, and redundancy, thereby increasing the information gathering cost of hackers, making it impossible for them to figure out the real network architecture, and thus blocking their attack plans. Attached Figure Description

[0022] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0023] Figure 1 The illustration schematically depicts an application scenario of a deployment method, apparatus, device, medium, and program product for a mimicry defense network according to embodiments of the present disclosure;

[0024] Figure 2 The diagram illustrates a visualization of the network topology of a network information system.

[0025] Figure 3 A flowchart illustrating a method for deploying a mimicry defense network according to an embodiment of the present disclosure is shown schematically.

[0026] Figure 4 This schematically illustrates a flowchart of deploying a target mimicry defense network based on a network topology graph set under a target cluster, according to an embodiment of this disclosure.

[0027] Figure 5 A flowchart illustrating a training method for an automatic topology generation model according to an embodiment of the present disclosure is shown schematically.

[0028] Figure 6 A block diagram of a virtual asset orchestration subsystem according to an embodiment of the present disclosure is shown schematically;

[0029] Figure 7 A block diagram of a virtual asset management subsystem according to an embodiment of the present disclosure is shown schematically;

[0030] Figure 8 A flowchart illustrating a method for deploying a mimicry defense network according to another embodiment of the present disclosure is shown schematically;

[0031] Figure 9 A block diagram schematically illustrates a deployment apparatus for a mimicry defense network according to an embodiment of the present disclosure;

[0032] Figure 10 A block diagram schematically illustrates a training apparatus for an automatically generated topology model according to an embodiment of the present disclosure; and

[0033] Figure 11 A block diagram of an electronic device suitable for implementing a method for deploying a mimicry defense network or a method for training an automatic topology generation model according to embodiments of the present disclosure is shown schematically. Detailed Implementation

[0034] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0035] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0036] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0037] When expressions such as "at least one of A, B, and C" are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, systems having only A, only B, only C, A and B, A and C, B and C, and / or systems having A, B, and C, etc.). The terms "first," "second," etc., used herein are for distinction only and have no limiting meaning, and the number of any elements in the accompanying drawings is for illustrative purposes only and not for limitation.

[0038] To prevent hackers from discovering a company's real network structure and launching real-time, lethal attacks on its network systems, this disclosure provides a method, apparatus, device, medium, and program product for deploying a mimicry defense network. The embodiments of this disclosure can create and dynamically modify a mimicry defense network using an automatic topology generation model built on graph convolutional neural networks, interfering with the hacker's information gathering phase. The deployment method and apparatus of the mimicry defense network in this disclosure offer advantages such as full automation, dynamism, heterogeneity, and redundancy in network construction. By continuously modifying the mimicry defense network in response to hacker information gathering, the hacker's information gathering costs are increased, preventing them from understanding the real network architecture and thus hindering their attack plans. Furthermore, by setting the mimicry defense network as a virtual network environment completely isolated from the real network to be protected, network security can be safeguarded without interfering with the smooth operation of normal business operations.

[0039] Furthermore, this disclosure also provides a training method and apparatus for an automatically generated topology model, which trains the automatically generated topology model in the deployment method and apparatus of the mimicry defense network applied in this disclosure embodiment. Thus, this disclosure embodiment can combine deep learning technology and, through data analysis, model training, and other modes, dynamically, heterogeneously, and redundantly generate the network topology map and network node assets of the mimicry defense network, achieving full automation without manual intervention throughout the process, reducing labor costs, and improving network security robustness.

[0040] Figure 1 The illustration schematically depicts an application scenario of a method, apparatus, device, medium, and program product for deploying a mimicry defense network according to embodiments of the present disclosure.

[0041] like Figure 1 As shown, the application scenario includes a back-end management system 100, a virtual asset orchestration subsystem 200, a virtual asset management subsystem 300, and a simulated network environment 400.

[0042] The backend management system 100 is used for user interaction. For example, users can view the current virtual network environment information in the mimicry network environment 400 through the backend management system 100, including but not limited to the network topology diagram of the mimicry defense network deployed in the mimicry network environment 400, the virtual assets of each node, and the characteristic information of the nodes.

[0043] Figure 2 The diagram illustrates a visualization of the network topology of a network information system.

[0044] Combination Figure 2The node's characteristic information includes, but is not limited to, operating system type, server type, application fingerprint, open port status, communication protocol used, IP range, etc.

[0045] Users can trigger the automated creation or modification of the mimicry defense network through the backend management system 100.

[0046] The virtual asset orchestration subsystem 200 may include an automatic topology generation model based on a graph convolutional neural network. The virtual asset orchestration subsystem 200 can receive change instructions for the mimicry defense network sent by the user through the backend management system 100, and output a network topology diagram of the newly deployed mimicry defense network based on these change instructions.

[0047] The virtual asset management subsystem 300 can receive the network topology diagram output by the virtual asset orchestration subsystem 200 and deploy a new mimicry defense network according to the network topology diagram.

[0048] The following will be based on Figure 1 The described scenario provides a detailed description of the deployment method and apparatus for a dynamic defense network according to embodiments of this disclosure. It should be noted that the sequence numbers of each operation in the following methods are merely for descriptive purposes and should not be considered as indicating the execution order of the operations. Unless explicitly stated otherwise, the method need not be executed in the exact order shown.

[0049] Figure 3 A flowchart illustrating a method for deploying a mimicry defense network according to an embodiment of the present disclosure is shown.

[0050] like Figure 3 As shown, the deployment method may include operations S301 to S303.

[0051] First, in operation S301, a change instruction is received, which includes network complexity index parameters.

[0052] Users can send change commands and input network complexity index parameters to the virtual asset orchestration subsystem 200 through the backend management system 100. These network complexity index parameters include the characteristic information of key nodes in the target mimicry defense network and the network topology information of the target mimicry defense network. The network topology information may include, but is not limited to: the number of nodes, the number of edges, degree, clustering coefficient, weight, communication layer structure information, and backend service layer structure information.

[0053] Then, in operation S302, the network complexity index parameters are input to the virtual asset orchestration subsystem 200, and the first network topology graph set corresponding to the target cluster output by the virtual asset orchestration subsystem 200 is obtained.

[0054] The virtual asset orchestration subsystem 200 includes an automatic topology generation model based on a graph convolutional neural network. This automatic topology generation model, after training, clusters the collected network topology graphs and divides them into multiple clusters, with the target cluster being one of these clusters.

[0055] After inputting the network complexity index parameters into the virtual asset orchestration subsystem 200 in operation S302, the feature matrix of the target mimicry defense network can be obtained first based on the feature information of key nodes in the target mimicry defense network, and the adjacency matrix of the target mimicry defense network can be obtained based on the network topology information of the target mimicry defense network. Then, based on the feature matrix and adjacency matrix of the target mimicry defense network, the target input matrix corresponding to the target mimicry defense network can be obtained. For example, the information of the same node corresponding to the feature matrix and adjacency matrix of the target mimicry defense network can be concatenated in the same row. Next, the target input matrix is ​​input into the graph convolutional neural network, which is used to extract features from the target mimicry defense network. Then, the topology automatic generation model can classify the target mimicry defense network into one of multiple clusters based on the features extracted by the graph convolutional neural network. The cluster to which the target mimicry defense network is classified is determined as the target cluster.

[0056] In this way, the topology automatic generation model can be used to find target clusters that belong to the same class as the target mimicry network based on the network complexity index parameters. This allows for the recommendation of the first set of network topologies corresponding to the target clusters, which can then serve as a reference for constructing the target mimicry network.

[0057] In one embodiment, the number of key nodes in the target mimicry defense network provided by the network complexity index parameter is less than the number of nodes in the network topology information of the target mimicry defense network. Thus, the user only needs to provide a small amount of key information about the mimicry defense network to be built through the backend management system 100, and this embodiment of the disclosure can recommend one or more network topologies that meet this key information.

[0058] Next, in operation S303, a target mimicry defense network is deployed based on a network topology map from the first set of network topology maps. For example, the target network topology map selected from the first set of network topology maps is transmitted to the virtual asset management subsystem 300, which then deploys the target mimicry defense network.

[0059] In one embodiment, any network topology can be selected from the first set of network topology maps for deployment. In another embodiment, when there are multiple network topology maps in the first set, the network topology map selected from the first set can be changed periodically or irregularly for deployment, thereby achieving continuous changes in the mimicry defense network architecture and confusing attackers' information gathering on the network system.

[0060] In another embodiment, the network topology graphs in the first set of network topology graphs can be further filtered before deployment. For details, please refer to... Figure 4 The illustration.

[0061] Figure 4 The illustration schematically shows a flowchart of the deployment of a target mimicry defense network based on a network topology graph in a set of network topology graphs under the target cluster in one embodiment of the present disclosure.

[0062] like Figure 4 As shown, according to this embodiment, operation S303 may include operations S3031 to S3033.

[0063] In operation S3031, a second set of network topology graphs is obtained, consisting of network topology graphs of the already deployed mimicry defense networks.

[0064] In operation S3032, the intersection of the first network topology graph set and the second network topology graph set is removed from the first network topology graph set to obtain the candidate network topology graph set.

[0065] In operation S3033, a target mimicry defense network is deployed based on a network topology graph from a set of candidate network topology graphs.

[0066] In this way, the network topology used when deploying the target mimicry defense network must be a network topology that has not been deployed before. The constantly changing network topology and nodes increase the variability of the network, which confuses attackers during the information gathering phase and more effectively protects the security of the enterprise's real business network structure nodes.

[0067] Figure 5 A flowchart illustrating a method for training an automatic topology generation model according to an embodiment of the present disclosure is shown.

[0068] like Figure 5 As shown, the training method for this topology automatic generation model may include operations S501 to S504.

[0069] First, operate S501 to obtain information on N network topology diagrams, where N is an integer greater than 1.

[0070] Next, in operation S502, the information of each of the N network topology graphs is processed to obtain the input matrix corresponding to each network topology graph. The specific processing steps may include operations S5021 to S5023.

[0071] Specifically, in operation S5021, based on the feature information of each node in the network topology graph, the feature matrix of each network topology graph is obtained.

[0072] In operation S5022, based on the network topology information of each network topology graph, the adjacency matrix of each network topology graph is obtained.

[0073] In operation S5023, based on the feature matrix and adjacency matrix of each network topology graph, the input matrix corresponding to each network topology graph is obtained. For example, the information corresponding to the same node in the feature matrix and adjacency matrix of each network topology graph is concatenated in the same row.

[0074] Next, by looping through operations S503 to S504 and fine-tuning the clustering parameters, the topology automatic generation model is trained to cluster N network topology graphs.

[0075] Specifically, in operation S503, the input matrix corresponding to each network topology graph is input to the graph convolutional neural network, and the graph convolutional neural network is used to extract features from each network topology graph.

[0076] When operating S504, a topology automatic generation model is trained based on the features of N network topology graphs extracted by graph convolutional neural networks, and then clusters the N network topology graphs.

[0077] Figure 6 A block diagram of a virtual asset orchestration subsystem according to an embodiment of the present disclosure is shown schematically.

[0078] like Figure 6 As shown, according to this embodiment, the virtual asset orchestration subsystem 200 includes an intelligent topology generation module 210 and an asset assembly module 220. After receiving the network complexity index parameter from the backend management system 100, the virtual asset orchestration subsystem 200 automatically generates a network topology map based on the network complexity index parameter, filters and recommends results, and then feeds the recommended results back to the virtual asset management subsystem 300.

[0079] Specifically, the intelligent topology generation module 210 mainly includes a data collection unit 211, a data processing unit 212, and a model training unit 213.

[0080] Data collection unit 211: It is used to first collect massive amounts of enterprise network information as an initial data asset library, and then extract the network topology map data corresponding to each enterprise network and the feature information of the nodes involved in the network topology map, based on the network structure of each enterprise, and provide it to the data processing unit 212.

[0081] Enterprise network information includes, but is not limited to: basic enterprise information, network business layer structure information (such as topology data of business architecture), communication layer structure information (such as topology data of communication architecture), backend service layer structure information (such as topology data of underlying servers and other devices), and characteristic information of each node (such as operating system type, server type, server fingerprint, application fingerprint, etc.), and enterprise network topology matrix information (such as network nodes, degree, clustering coefficient, weight, etc.).

[0082] The data processing unit 212 is responsible for processing the network topology map data transmitted from the data collection unit 211, as well as the feature information of the nodes involved in the network topology map, through the following steps 2.1 to 2.3.

[0083] Step 2.1: Set each network topology graph s as independent graph data, and take any node in it as the r-th node of the graph data. Then, based on the feature information of the r-th node, the node features of the r-th node itself can be extracted (e.g., as a T-dimensional vector). When the network topology graph s has a total of K nodes, a K*T-dimensional feature matrix A can be obtained.

[0084] Step 2.2: Construct an initial K*K dimensional adjacency matrix B for the network topology graph s. In one embodiment, when the network topology graph s is the network topology graph of the real network to be protected, in order to prevent the automatic topology generation model from learning the network structure of this real network and to prevent recommending the network topology graph of this real network in subsequent recommendations, the coefficient matrix C can be used to adjust the adjacency matrix B of the network topology graph s of the protected real network, thereby enhancing or weakening the feature weights of some nodes in the adjacency matrix B as a whole. In some embodiments, multiple different network structures can also be derived by adjusting the adjacency matrix B of the network topology graph s of the protected real network using multiple different coefficient matrices, serving as learning samples for the automatic topology generation model.

[0085] Step 2.3: Perform symmetric normalization Laplace standardization on the adjacency matrix B finally output in Step 2 to form a dimensionless adjacency matrix B'.

[0086] The model training unit 213 can train the topology automatic generation model through the following steps 3.1 to 3.4.

[0087] Step 3.1: Aggregate the network topology graph s using the K*T dimensional feature matrix A and adjacency matrix B obtained from the data processing unit 212 to form an aggregated graph feature matrix. During aggregation, information corresponding to the same node is concatenated in the same row.

[0088] Step 3.2: Apply the graph convolutional neural network to extract features from the feature matrix of the aggregated graph matrix to obtain the convolutional feature matrix B'' of the feature matrix of the aggregated graph matrix.

[0089] Step 3.3: Use the convolutional feature matrix B'' as input to the clustering algorithm module in the automatic topology generation model. This clustering algorithm module can be, for example, the k-means algorithm.

[0090] Step 3.4 involves optimizing the results in the clustering algorithm module through parameter tuning and other methods to train an automatic topology generation model that meets the clustering accuracy requirements. Simultaneously, the clustering results are output. Examples include the cluster partitioning and weights of the network topology graph: Gs={(G1: weight(s1)), G2: weight(s2)),… , Gs: weight(ss))}, the classification and weights of each node in the network system: Jk= {(J1: weight(k1)), J2: weight(k2)),… , Jk: weight(kk))}, edge weights, and other information.

[0091] The asset assembly module 220 mainly includes a topology adaptive generation unit 221 and a network topology adaptive generation result feedback unit 222.

[0092] The topology adaptive generation unit 221 recommends a network topology graph from multiple clusters clustered by the intelligent topology generation module 210 based on the network complexity index parameters input by the user. Specifically, it first uses the initial configuration parameter information (number of IPs, domain name pool, number of databases, etc.) verified by the intelligent topology generation module 210 as the initial structural range information of the topology adaptive generation unit, and constructs a target feature vector I based on the network complexity index parameters in the change instruction. Then, based on the target feature vector I, it constructs the target input matrix corresponding to the target mimicry defense network expected by the user, which is used as the input to the automatic topology generation model. Based on the clustering results trained by the automatic topology generation model, it divides the target input matrix into clusters, thereby determining the target cluster to which the target mimicry defense network belongs, and then outputs the first network topology graph set M={M1,M2,M3,...} corresponding to the target cluster.

[0093] Network topology adaptive generation result feedback unit 222: It uses the first network topology map set M recommended by the topology adaptive generation unit 221 as the initial feedback list, and simultaneously filters it using the second network topology map set M0, which consists of network topology maps already deployed by the enterprise. Finally, after filtering out the intersection of the first network topology map set M and the second network topology map set M0 from the second network topology map set M, it arbitrarily selects a network topology map as the final target network topology map M', and transmits it to the virtual asset management subsystem 300 for deployment.

[0094] Figure 7 A block diagram of a virtual asset management subsystem 300 according to an embodiment of the present disclosure is shown schematically.

[0095] like Figure 7 As shown, the virtual asset management subsystem 300 may include a template receiving module 310, an asset deployment module 320, and an asset monitoring module 330.

[0096] The template receiving module 310 is responsible for receiving the target network topology map M' and its node information sent by the virtual asset orchestration subsystem 200, and sending it to the asset deployment module 320.

[0097] The asset deployment module 320 can retrieve corresponding virtual assets from the virtual asset library in the mimicry network environment 400 based on node information, and deploy the target mimicry defense network through the target network topology map M'. In one embodiment, the network isolation of virtual assets is fully ensured during the deployment process, that is, the virtual assets are not network reachable from real production business assets.

[0098] The asset monitoring module 330 can monitor all virtual assets deployed in the target mimicry defense network, periodically collect virtual asset information, and display it on the user management interface. Virtual assets also need to periodically report heartbeats and operational information. If a virtual asset unexpectedly stops working, this module will restart or remove the asset according to the user's wishes.

[0099] Figure 8 A flowchart illustrating a method for deploying a mimicry defense network according to another embodiment of the present disclosure is shown.

[0100] like Figure 8 As shown, the deployment method of the mimicry defense network according to this embodiment may include steps S801 to S804.

[0101] Step S804: The user inputs the network complexity index parameters.

[0102] Step S802: Using the trained graph convolutional neural network-based automatic topology generation model, generate the target network topology graph and node information of the network to be constructed.

[0103] Step S803: Obtain virtual assets based on the nodes in the target network topology diagram and deploy them automatically.

[0104] During automated deployment, the network topology information and node characteristic information of the target network topology map are first obtained. Then, based on the node characteristic information of the target network topology map, virtual assets in the target mimicry defense network can be obtained. According to the network topology information of the target network topology map, the connection relationships between the virtual assets in the target mimicry defense network are established to achieve the deployment of the target mimicry defense network. In one embodiment, when establishing the connection relationships between virtual assets in the target mimicry defense network, a network isolation policy can be adopted to prevent the virtual assets in the target mimicry defense network from communicating with assets in the real network (i.e., network unreachable). The target mimicry defense network and the real network belong to the same internal network.

[0105] In one embodiment, when acquiring virtual assets in a target mimicry defense network based on the feature information of nodes in the target network topology, a search can first be conducted in a pre-defined virtual asset library for virtual assets that match the feature information of nodes in the target network topology. If a match is found, the corresponding virtual asset is retrieved from the virtual asset library; otherwise, the corresponding virtual asset is constructed based on the feature information of nodes in the target network topology. This allows for the reuse of virtual assets in the virtual asset library. Newly constructed virtual assets can also be stored in the virtual asset library for later direct retrieval and use.

[0106] Step S804: Monitor the operational status of virtual assets in the newly constructed mimicry defense network and report it to the backend management system. In one embodiment, steps S802-S804 can be repeated periodically to update the network topology and node information through the virtual asset orchestration subsystem 200, and to periodically shuffle and redeploy the structure and nodes of the mimicry defense network. For example, in the aforementioned example, when multiple candidate network topologies remain after filtering out the intersection of the first network topology set M and the second network topology set M0 from the second network topology set M, new network topologies can be transformed periodically through steps S802-S804 to construct the mimicry defense network. This increases the information gathering cost for hackers, making it impossible for them to understand the real network architecture, thereby hindering their attack plans.

[0107] As can be seen, the embodiments of this disclosure can utilize a large amount of real network topology data and combine it with deep learning algorithms for model training to deploy a mimicry defense network. The mimicry defense network constructed in this way possesses dynamism, redundancy, and heterogeneity. Furthermore, the network's variability is increased through periodically changing the network topology and nodes, confusing attackers during the information gathering phase and effectively protecting the security of the enterprise's real business network structure nodes. Moreover, the fully automated process reduces manual costs and increases the attacker's cost, enhancing the defensive capabilities of the enterprise's information systems in network warfare.

[0108] Figure 9 A block diagram of a deployment apparatus 900 for a mimicry defense network according to an embodiment of the present disclosure is shown schematically.

[0109] like Figure 9 As shown, the deployment device 900 of the mimicry defense network may include a backend management system 100, a virtual asset orchestration subsystem 200, and a virtual asset management subsystem 300. The deployment device 900 of the mimicry defense network can perform the aforementioned reference... Figure 3 , Figure 4 and Figure 8 The deployment method of the mimicry defense network is introduced.

[0110] The backend management system 100 is used to receive change instructions, which include network complexity index parameters.

[0111] The virtual asset orchestration subsystem 200 is used to input network complexity index parameters and output a first set of network topology graphs corresponding to the target cluster. The virtual asset orchestration subsystem 200 includes an automatic topology generation model based on a graph convolutional neural network. This model, after training, clusters the collected network topology graphs and divides them into multiple clusters, with the target cluster being one of these clusters.

[0112] In one embodiment, the virtual asset orchestration subsystem 200 is further configured to: obtain a second set of network topology graphs consisting of network topology graphs of already deployed mimicry defense networks; and remove the intersections with the second set of network topology graphs from the first set of network topology graphs to obtain a candidate set of network topology graphs. The virtual asset management subsystem is further configured to deploy a target mimicry defense network based on a network topology graph from the candidate set of network topology graphs.

[0113] The virtual asset management subsystem 300 is used to deploy a target mimicry defense network based on a network topology map in a first set of network topology maps.

[0114] Figure 10 A block diagram of a training apparatus for an automatic topology generation model according to an embodiment of the present disclosure is shown schematically.

[0115] like Figure 10 As shown, the training device 1000 for the automatic topology generation model may include a data collection unit 211, a data processing unit 212, and a model training unit 213. According to embodiments of this disclosure, the training device 1000 can perform reference... Figure 5 The training methods described.

[0116] The data collection unit 211 is used to acquire information from N network topology graphs, where N is an integer greater than 1. The information of each network topology graph includes network topology information and node feature information.

[0117] The data processing unit 212 is used to process the information of each of the N network topology graphs to obtain the input matrix corresponding to each network topology graph. In one embodiment, the data processing unit 212 is specifically used to: obtain the feature matrix of each network topology graph based on the feature information of the nodes of each network topology graph; obtain the adjacency matrix of each network topology graph based on the network topology information of each network topology graph; and obtain the input matrix corresponding to each network topology graph based on the feature matrix and adjacency matrix of each network topology graph.

[0118] The model training unit 213 is used to train the automatic topology generation model to cluster N network topology graphs, including: inputting the input matrix corresponding to each network topology graph into the graph convolutional neural network, using the graph convolutional neural network to extract features from each network topology graph, and clustering the N network topology graphs based on the features extracted by the graph convolutional neural network.

[0119] In one embodiment, the training device 1000 can be integrated into the virtual asset orchestration subsystem 200 of the deployment device 900 of the mimicry defense network, such as... Figure 6 As shown.

[0120] According to embodiments of this disclosure, any multiple modules among the following can be implemented in one module: the backend management system 100, the virtual asset orchestration subsystem 200, the virtual asset management subsystem 300, the intelligent topology generation module 210, the asset assembly module 220, the data collection unit 211, the data processing unit 212, the model training unit 213, the topology adaptive generation unit 221, the network topology adaptive generation result feedback unit 222, the template receiving module 310, the asset deployment module 320, and the asset monitoring module 330; or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the following components—backend management system 100, virtual asset orchestration subsystem 200, virtual asset management subsystem 300, intelligent topology generation module 210, asset assembly module 220, data collection unit 211, data processing unit 212, model training unit 213, topology adaptive generation unit 221, network topology adaptive generation result feedback unit 222, template receiving module 310, asset deployment module 320, and asset monitoring module 330—can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), programmable logic array (PLA), system-on-a-chip, system-on-a-substrate, system-on-package, application-specific integrated circuit (ASIC), or any other reasonable method of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the following components—back-end management system 100, virtual asset orchestration subsystem 200, virtual asset management subsystem 300, intelligent topology generation module 210, asset assembly module 220, data collection unit 211, data processing unit 212, model training unit 213, topology adaptive generation unit 221, network topology adaptive generation result feedback unit 222, template receiving module 310, asset deployment module 320, and asset monitoring module 330—can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.

[0121] Figure 11 A block diagram of an electronic device suitable for implementing a method for deploying a mimicry defense network or a method for training an automatic topology generation model according to embodiments of the present disclosure is shown schematically.

[0122] like Figure 11As shown, an electronic device 1100 according to an embodiment of the present disclosure includes a processor 1101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1102 or a program loaded from a storage portion 1108 into a random access memory (RAM) 1103. The processor 1101 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1101 may also include onboard memory for caching purposes. The processor 1101 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0123] RAM 1103 stores various programs and data required for the operation of electronic device 1100. Processor 1101, ROM 1102, and RAM 1103 are interconnected via bus 1104. Processor 1101 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 1102 and / or RAM 1103. It should be noted that the programs may also be stored in one or more memories other than ROM 1102 and RAM 1103. Processor 1101 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in one or more memories.

[0124] According to embodiments of this disclosure, the electronic device 1100 may further include an input / output (I / O) interface 1105, which is also connected to a bus 1104. The electronic device 1100 may also include one or more of the following components connected to the I / O interface 1105: an input section 1106 including a keyboard, mouse, etc.; an output section 1107 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1108 including a hard disk, etc.; and a communication section 1109 including a network interface card such as a LAN card, modem, etc. The communication section 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to the I / O interface 1105 as needed. A removable medium 1111, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1110 as needed so that computer programs read from it can be installed into the storage section 1108 as needed.

[0125] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0126] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 1102 and / or RAM 1103 and / or one or more memories other than ROM 1102 and RAM 1103 described above.

[0127] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the methods provided in the embodiments of this disclosure.

[0128] When the computer program is executed by the processor 1101, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0129] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 1109, and / or installed from the removable medium 1111. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0130] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 1109, and / or installed from removable medium 1111. When the computer program is executed by processor 1101, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0131] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on a user's computing device, partially on a user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0132] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0133] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined and / or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0134] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A method for deploying a mimicry defense network, comprising: Receive a change instruction, wherein the change instruction includes network complexity index parameters; The network complexity index parameters are input to the virtual asset orchestration subsystem, and a first set of network topology graphs corresponding to the target clusters output by the virtual asset orchestration subsystem is obtained; wherein, the virtual asset orchestration subsystem includes an automatic topology generation model built based on a graph convolutional neural network, the automatic topology generation model is trained to cluster the collected N network topology graphs and divide them into multiple clusters, the target cluster is one of the multiple clusters, and N is an integer greater than 1; and Deploy a target mimicry defense network based on one of the network topology graphs in the first set of network topology graphs.

2. The method according to claim 1, wherein, The deployment of the target mimicry defense network based on a network topology map from the first set of network topology maps includes: Obtain a second set of network topology graphs consisting of network topology graphs of the already deployed mimicry defense networks; The intersection of the first network topology graph set and the second network topology graph set is removed from the first network topology graph set to obtain a candidate network topology graph set; and The target mimicry defense network is deployed based on a network topology graph from the candidate network topology graph set.

3. The method according to claim 1, wherein, The network complexity index parameters include the feature information of key nodes in the target mimicry defense network and the network topology information of the target mimicry defense network.

4. The method according to claim 3, wherein, After the network complexity index parameters are input into the virtual asset orchestration subsystem... Based on the feature information of the key nodes in the target mimicry defense network, the feature matrix of the target mimicry defense network is obtained; Based on the network topology information of the target mimicry defense network, the adjacency matrix of the target mimicry defense network is obtained; Based on the feature matrix and adjacency matrix of the target mimicry defense network, the target input matrix corresponding to the target mimicry defense network is obtained for inputting into the topology automatic generation model; The target input matrix is ​​input into the graph convolutional neural network, and the graph convolutional neural network is used to extract features from the target mimicry defense network; Based on the features of the target mimicry defense network extracted by the graph convolutional neural network, the target mimicry defense network is divided into one of the multiple clusters, wherein the cluster to which the target mimicry defense network is divided is determined as the target cluster.

5. The method according to claim 4, wherein, The number of key nodes in the target mimicry defense network is less than the number of nodes in the network topology information of the target mimicry defense network; wherein, in the target input matrix, the information corresponding to the same node in the feature matrix and adjacency matrix of the target mimicry defense network is concatenated in the same row.

6. The method according to claim 1 or 2, wherein, Deploying the target mimicry defense network based on a network topology map from the first set of network topology maps includes: Using the network topology map determined from the first network topology map set as the basis for the deployment of the target mimicry defense network, as the target network topology map, the network topology information and node feature information of the target network topology map are obtained; Based on the feature information of the nodes in the target network topology, virtual assets in the target mimicry defense network are obtained; Based on the network topology information of the target network topology map, establish the connection relationships between virtual assets in the target mimicry defense network to realize the deployment of the target mimicry defense network.

7. The method according to claim 6, wherein, The acquisition of virtual assets in the target mimicry defense network based on the node feature information of the target network topology includes: Search the preset virtual asset library for virtual assets that match the feature information of the nodes in the target network topology; If found, the corresponding virtual asset is retrieved from the virtual asset library; If no match is found, a corresponding virtual asset is constructed based on the feature information of the nodes in the target network topology graph.

8. The method according to claim 6, wherein, Establishing the connection relationships between virtual assets in the target mimicry defense network also includes: According to the network isolation strategy, the virtual assets in the target mimicry defense network are configured not to communicate with the assets in the real network, wherein the target mimicry defense network and the real network belong to the same internal network.

9. The method according to claim 1, wherein, The training process of the automatic topology generation model is as follows: Obtain information about the N network topology graphs, where the information for each network topology graph includes network topology information and node feature information. Process the information of each of the N network topology graphs to obtain the input matrix corresponding to each network topology graph; as well as Training the automatic topology generation model to cluster the N network topology graphs includes: inputting the input matrix corresponding to each network topology graph into the graph convolutional neural network, using the graph convolutional neural network to extract features from each network topology graph, and clustering the N network topology graphs based on the features extracted by the graph convolutional neural network. The process of processing information for each of the N network topology graphs includes: Based on the feature information of each node in the network topology graph, the feature matrix of each network topology graph is obtained; Based on the network topology information of each network topology graph, the adjacency matrix of each network topology graph is obtained; and Based on the feature matrix and adjacency matrix of each network topology graph, the input matrix corresponding to each network topology graph is obtained.

10. A deployment device for a mimicry defense network, comprising: A backend management system is used to receive change instructions, wherein the change instructions include network complexity index parameters; A virtual asset orchestration subsystem is used to input the network complexity index parameters and output a first set of network topology graphs corresponding to the target cluster; wherein, the virtual asset orchestration subsystem includes an automatic topology generation model built based on a graph convolutional neural network, the automatic topology generation model being trained to cluster N collected network topology graphs and divide them into multiple clusters, the target cluster being one of the multiple clusters, where N is an integer greater than 1; and The virtual asset management subsystem is used to deploy a target mimicry defense network based on a network topology map from the first set of network topology maps.

11. An electronic device, comprising: One or more processors; Memory, used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 9.

12. A computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the method of any one of claims 1 to 9.

13. A computer program product comprising computer program instructions that, when executed by a processor, implement the method of any one of claims 1 to 9.

Citation Information

Patent Citations

  • Risk value prediction method and device, computer equipment and storage medium

    CN115271980A