System defense capability improvement method, device, equipment, medium and program product

By configuring multi-layered camouflage protection at the system and application levels, and transferring core assets when critical layers are breached, the shortcomings of traditional system defense methods against new attacks and zero-day vulnerabilities are addressed, thereby improving the system's defense capabilities and security.

CN118264445BActive Publication Date: 2026-01-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410338298.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-22
Publication Date
2026-01-16
Estimated Expiration
2044-03-22

AI Technical Summary

Technical Problem

Traditional system defense methods are ineffective in dealing with new types of attacks and zero-day vulnerabilities, making it difficult to improve the system's defense capabilities.

Method used

The first security policy is configured at the system level to form the first protection layer, which is used to disguise the core assets for the first time. After the first protection layer is breached, the second security policy at the application level is activated to provide a second disguise and protection. When the second protection layer is breached, an emergency mechanism is established to transfer the core assets in order to simulate the behavior and appearance of the system and increase the difficulty for attackers.

Benefits of technology

This enhances the system's security and resilience, making it more difficult for attackers to discover and attack the real system, thus reducing losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118264445B_ABST
    Figure CN118264445B_ABST
Patent Text Reader

Abstract

The present disclosure provides a system defense capability improvement method, which can be applied to the technical field of information security and the technical field of financial technology. The system defense capability improvement method comprises: in response to the system being attacked, obtaining security requirements and threat intelligence of the system; determining the attack surface and core assets of the system according to the security requirements and the threat intelligence; for the attack surface, configuring a first security policy based on the system layer to obtain a first protection layer, wherein the first protection layer is used for the first camouflage of the core assets; in response to the first protection layer being broken, configuring a second security policy based on the application layer to obtain a second protection layer, wherein the second protection layer is used for the second camouflage of the core assets; and in response to the second protection layer being broken, establishing an emergency mechanism to transfer the core assets. The present disclosure also provides a system defense capability improvement device, equipment, medium and program product.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of information security and the technical field of financial technology, and more particularly to a system defense capability improvement method, device, equipment, medium and program product. BACKGROUND

[0002] In today's highly developed information technology environment, systems are facing increasingly complex and concealed attack threats, but traditional system defense methods are usually based on fixed rules and firewall technologies, which cannot effectively deal with new attacks and zero-day vulnerabilities. SUMMARY

[0003] In view of the above problems, the present disclosure provides a system defense capability improvement method, device, equipment, medium and program product.

[0004] According to a first aspect of the present disclosure, a system defense capability improvement method is provided, comprising: in response to a system being attacked, obtaining security requirements and threat intelligence of the system; determining an attack surface and core assets of the system according to the security requirements and the threat intelligence; for the attack surface, configuring a first security policy based on a system layer to obtain a first defense layer, wherein the first defense layer is used to perform a first camouflage on the core assets; in response to the first defense layer being broken, configuring a second security policy based on an application layer to obtain a second defense layer, wherein the second defense layer is used to perform a second camouflage on the core assets; and in response to the second defense layer being broken, establishing an emergency mechanism to transfer the core assets.

[0005] According to an embodiment of the present disclosure, configuring a first security policy based on a system layer to obtain a first defense layer comprises: building a system hardware platform using heterogeneous computing hardware; in response to the system hardware platform being built, deploying a system running architecture using a loosely coupled architecture; and in response to the system running architecture being deployed, building a system software platform using a microservice architecture and an event-driven architecture.

[0006] According to an embodiment of the present disclosure, deploying a system running architecture using a loosely coupled architecture comprises: dividing the system into a plurality of independent modules, wherein the plurality of independent modules are deployed using a mixed mode of physical machines, virtualization and containerization; based on the plurality of independent modules, creating a plurality of independent virtual network environments; and based on the plurality of independent virtual network environments, configuring an automated scheduling mechanism, wherein the automated scheduling mechanism is used to randomly allocate resources and modify network configurations and network parameters according to system requirements.

[0007] According to an embodiment of the present disclosure, building a system software platform using a microservice architecture and an event-driven architecture comprises: building a system software platform using a microservice architecture based on online services; and building a system software platform using an event-driven architecture based on low real-time requirement services.

[0008] According to an embodiment of the present disclosure, the second security policy is configured based on an application layer, and the second defense layer is obtained based on the second security policy, including: obtaining a real application access element; generating a virtual application access element for disguising the real application access element according to the real application access element; and performing obfuscation processing on network traffic running the virtual application access element.

[0009] According to an embodiment of the present disclosure, the real application access element includes: a user identity, system data, and a running environment, and the virtual application access element for disguising the real application access element is generated according to the real application access element, including: generating a virtual user identity for disguising a real user identity according to the real user identity; generating a virtual system data for disguising a real system data according to the real system data; and generating a virtual running environment for disguising a real running environment according to the real running environment.

[0010] According to an embodiment of the present disclosure, the network traffic running the virtual application access element is obfuscated, including: enhancing the confidentiality of the network traffic according to encryption technology; increasing the complexity of the network traffic according to a confused packet method; and generating simulated network traffic according to real network traffic to hide the real application access element.

[0011] According to an embodiment of the present disclosure, in response to the second defense layer being breached, an emergency mechanism is established to transfer the core assets, including: dynamically adjusting the first security policy and / or the second security policy, and monitoring the security state of the core assets in real time; establishing a response mechanism for security incidents and system vulnerabilities, and controlling abnormal behavior and potential attacks in the system; and transferring the core assets based on the response mechanism.

[0012] According to an embodiment of the present disclosure, the response mechanism is established for security incidents and system vulnerabilities, and the abnormal behavior and potential attacks in the system are controlled, including: performing real-time logging on the abnormal behavior and potential attacks; performing intrusion detection on the system and starting the first security policy for automatic resistance; and performing mitigation processing on the core assets leaked due to the abnormal behavior and potential attacks.

[0013] According to an embodiment of the present disclosure, the method further includes: in response to completing a round of attack and defense, reviewing and upgrading the current system; and periodically evaluating the effectiveness of the current system defense strategy and improving the current system defense strategy according to the evaluation results.

[0014] According to an embodiment of the present disclosure, the effectiveness of the current system defense strategy is periodically evaluated, and the current system defense strategy is improved according to the evaluation results, including: periodically performing defense drills and tests to maintain the effectiveness of the defense strategy; and periodically updating the defense strategy to adapt to changing threats and attack technologies.

[0015] According to an embodiment of the present disclosure, periodically performing defense drills and tests to maintain the effectiveness of the defense strategy includes periodically performing simulated attacks and penetration tests to maintain the effectiveness of the defense strategy.

[0016] According to an embodiment of the present disclosure, periodically updating the defense strategy to adapt to changing threats and attack techniques includes periodically updating defense tools, fixing vulnerabilities, and improving mimicry strategies to adapt to changing threats and attack techniques.

[0017] The second aspect of the present disclosure provides a system defense capability improvement apparatus, comprising: an acquisition module configured to acquire security requirements and threat intelligence of the system in response to the system being attacked; a determination module configured to determine an attack surface and core assets of the system according to the security requirements and the threat intelligence; a first configuration module configured to configure a first security strategy based on a system layer to obtain a first defense layer for the attack surface, wherein the first defense layer is used to perform a first camouflage for the core assets; a second configuration module configured to configure a second security strategy based on an application layer to obtain a second defense layer in response to the first defense layer being broken, wherein the second defense layer is used to perform a second camouflage for the core assets; and an establishment module configured to establish an emergency mechanism to transfer the core assets in response to the second defense layer being broken.

[0018] The third aspect of the present disclosure provides an electronic device, comprising: one or more processors; a memory configured to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to perform the system defense capability improvement method described above.

[0019] The fourth aspect of the present disclosure further provides a computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the system defense capability improvement method described above.

[0020] The fifth aspect of the present disclosure further provides a computer program product comprising a computer program that, when executed by a processor, implements the system defense capability improvement method described above.

[0021] The system defense capability improvement method, device, equipment, medium and program product provided by the present disclosure improve the security and resistance of the system by configuring a first security policy from the system level to form a first defense layer for the first camouflage protection of the core assets of the system, and if the attacker breaks through the first defense layer of the system level by various means, the protection of the application level is enabled, that is, a second security policy is configured from the application level to form a second defense layer for the second camouflage protection of the core assets of the system, and if the second defense layer of the application level is broken, an emergency mechanism is established to transfer the core assets in the first time to minimize the loss. Since the protections of the system level and the application level can simulate the behavior and appearance of the system, and use the randomness and unpredictability of the system to resist network attacks, it is difficult for the attacker to find and attack the real system, so the security and resistance of the system are improved. BRIEF DESCRIPTION OF DRAWINGS

[0022] The above and other objects, features and advantages of the present disclosure will become more apparent from the following description of embodiments of the present disclosure taken in conjunction with the accompanying drawings, in which:

[0023] Figure 1 An application scenario diagram of the system defense capability improvement method, device, equipment, medium and program product according to an embodiment of the present disclosure is schematically shown;

[0024] Figure 2 A flowchart of the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0025] Figure 3 A flowchart of obtaining a first defense layer based on a system level configuration of a first security policy in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0026] Figure 4 A flowchart of deploying a system running architecture by using a loose coupling architecture in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0027] Figure 5 A flowchart of building a system software platform by using a micro-service architecture and an event-driven architecture in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0028] Figure 6 A flowchart of obtaining a second defense layer based on an application level configuration of a second security policy in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0029] Figure 7A flowchart illustrating a process of generating virtual application access elements according to real application access elements in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0030] Figure 8 A flowchart illustrating a process of performing obfuscation processing on network traffic in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0031] Figure 9 A flowchart illustrating a process of establishing an emergency mechanism to transfer core assets in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0032] Figure 10 A flowchart illustrating a process of establishing a response mechanism to control abnormal behavior and potential attacks in the system in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0033] Figure 11 A flowchart illustrating a process of upgrading the system after completing a round of attack defense in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0034] Figure 12 A flowchart illustrating a process of periodically evaluating the effectiveness of the current system defense strategy in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0035] Figure 13 A schematic diagram of the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown;

[0036] Figure 14 A structural block diagram of the system defense capability improvement apparatus according to an embodiment of the present disclosure is schematically shown; and

[0037] Figure 15 A block diagram of an electronic device suitable for implementing the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0038] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. It should be understood, however, that the description which follows is merely exemplary and is not intended to limit the scope of the present disclosure. In the following detailed description of embodiments of the present disclosure, numerous specific details are set forth in order to provide a thorough understanding of the embodiments. However, it will be apparent to one skilled in the art that one or more embodiments can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring aspects of the present disclosure.

[0039] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used herein, the terms "comprises", "comprising", "includes", "including" and the like are specifically intended to be open-ended and to mean that other features, steps, operations, and / or components can be added.

[0040] All terms used herein, including technical and scientific terms, have the meanings commonly understood by one of ordinary skill in the art unless otherwise defined. It should be noted that the terms used herein are to be interpreted as having a meaning that is consistent with the context of the specification, and should not be interpreted in an idealized or overly formal way.

[0041] In situations where similar terminology is used, such as "at least one of A, B, and C is used in the context of "a system having at least one of A, B, and C," generally such terminology is to be interpreted that the system includes one or more of A or B or C or any combination of the items A, B, and C (e.g., the system includes A alone, B alone, C alone, A and B in combination, A and C in combination, B and C in combination, or A, B, and C in combination, etc.).

[0042] It should be noted that the system defense capability improvement method and device of the present disclosure can be used to improve the system defense capability in the financial field, and can also be used to improve the system defense capability in any field other than the financial field. The application field of the system defense capability improvement method and device of the present disclosure is not limited.

[0043] In the technical solutions of the present application, the user information (including but not limited to user personal information, user image information, user equipment information such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards, necessary security measures are taken, public order and good customs are not violated, and corresponding operation entrances are provided for users to choose authorization or refusal.

[0044] In the scenario of using personal information for automated decision-making, the method, device and system provided by the embodiment of the present application provide corresponding operation entrances for the user to choose to agree or refuse the automated decision-making result; if the user chooses to refuse, the expert decision-making process is entered. The expression "automated decision-making" here refers to the activity of automatically analyzing, evaluating the behavior habits, interests and hobbies, or economic, health, credit status of an individual through a computer program, and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by personnel who are engaged in a certain field of work, have specialized experience, knowledge and skills, and have reached a certain professional level.

[0045] The embodiment of the disclosure provides a system defense capability improvement method, comprising: in response to the system being attacked, obtaining security requirements and threat intelligence of the system; determining an attack surface and a core asset of the system according to the security requirements and the threat intelligence; for the attack surface, configuring a first security strategy based on a system layer to obtain a first defense layer, wherein the first defense layer is used for performing first camouflage on the core asset; in response to the first defense layer being broken, configuring a second security strategy based on an application layer to obtain a second defense layer, wherein the second defense layer is used for performing second camouflage on the core asset; and in response to the second defense layer being broken, establishing an emergency mechanism to transfer the core asset.

[0046] The system defense capability improvement method, device, equipment, medium and program product provided by the disclosure form a first defense layer by configuring a first security strategy from a system layer, perform first camouflage protection on the core asset of the system, when the system is attacked, under normal circumstances, the attacker is difficult to locate the position of the real key asset through the camouflage of the first defense layer, if the attacker breaks through the first defense layer of the system layer by various means, the protection of the application layer is enabled, that is, a second defense layer is formed by configuring a second security strategy from the application layer, the core asset of the system is protected by second camouflage, if the second defense layer of the application layer is broken, an emergency mechanism is established to transfer the core asset in the first time, so as to minimize the loss, because the protection of the system layer and the application layer can simulate the behavior and appearance of the system, and the randomness and unpredictability of the system are used to resist network attacks, so that the attacker is difficult to find and attack the real system, therefore, the security and resistance of the system are improved.

[0047] Figure 1 The application scenario diagram of the system defense capability improvement method according to the embodiment of the disclosure is schematically shown.

[0048] As Figure 1 shown, the application scenario 100 according to the embodiment can include terminal devices 101, 102, and 103. A network 104 is a medium that provides a communication link between the terminal devices 101, 102, and 103 and a server 105. The network 104 can include various connection types, such as wired, wireless communication links, or optical fiber cables, etc.

[0049] A user can use the terminal devices 101, 102, and 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0050] The terminal devices 101, 102, and 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smartphones, tablet computers, laptop computers, desktop computers, and the like.

[0051] The server 105 can be a server providing various services, such as a background management server supporting websites browsed by users using the terminal devices 101, 102, and 103 (only as an example). The background management server can perform analysis and the like on received user requests and the like, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0052] It should be noted that the system defense capability improvement method provided by the embodiments of the present disclosure can generally be executed by the server 105. Accordingly, the system defense capability improvement apparatus provided by the embodiments of the present disclosure can generally be arranged in the server 105. The system defense capability improvement method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, and 103 and / or the server 105. Accordingly, the system defense capability improvement apparatus provided by the embodiments of the present disclosure can also be arranged in a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, and 103 and / or the server 105.

[0053] It should be understood that, Figure 1 The number of terminal devices, networks, and servers in the system is only illustrative. According to the needs of implementation, there can be any number of terminal devices, networks, and servers.

[0054] The system defense capability improvement method of the embodiments of the present disclosure will be described in detail below based on the scenario described in the foregoing. Figure 1 Figures 2-13 The system defense capability improvement method of the embodiments of the present disclosure will be described in detail below based on the scenario described in the foregoing.

[0055] Figure 2 A flowchart of the system defense capability improvement method according to the embodiments of the present disclosure is schematically shown.

[0056] As shown in Figure 2 The system defense capability improvement of this embodiment includes operations S210-S250, and the system defense capability improvement method can be executed by a server.

[0057] In operation S210, in response to the system being attacked, the security requirements and threat intelligence of the system are obtained.

[0058] In this embodiment, the security situation of the system is monitored in real time, and when the system is attacked, the security requirements and threat intelligence of the system are collected and analyzed in the first place to understand the threats and risks faced by the system. ​

[0059] In operation S220, the attack surface and core assets of the system are determined according to the security requirements and threat intelligence.

[0060] In this embodiment, the attack surface of the system is determined according to the security requirements and threat intelligence, and the core assets in the system are identified and evaluated for focused protection.

[0061] In operation S230, a first security policy is configured based on the system layer for the attack surface to obtain a first protection layer, wherein the first protection layer is used for the first time to camouflage the core assets.

[0062] In this embodiment, after locking the attack surface, the first security policy is configured based on the system layer, for example, the system can be upgraded for security protection from three aspects of hardware, architecture and software, which is used for the first time to camouflage the core assets and increase the difficulty of intrusion by attackers.

[0063] In operation S240, in response to the first protection layer being broken, a second security policy is configured based on the application layer to obtain a second protection layer, wherein the second protection layer is used for the second time to camouflage the core assets.

[0064] In this embodiment, under normal circumstances, through the camouflage of the first protection layer, it is difficult for attackers to locate the position of the real key assets. If the attacker breaks through the first protection layer of the system layer by various means, the protection of the application layer is enabled, that is, the second security policy is configured from the application layer to form the second protection layer, and the core assets of the system are protected for the second time to improve the security of the system.

[0065] In operation S250, in response to the second protection layer being broken, an emergency mechanism is established to transfer the core assets.

[0066] In this embodiment, if the second protection layer is also broken by the attacker, an emergency mechanism is established to transfer the core assets in the first time to minimize the loss. The specific transfer method can be to immediately stop the current container or virtual machine providing external services, and then start the related services in another environment.

[0067] According to the system defense ability improving method provided by the embodiment of the present disclosure, a first security policy is configured from a system level to form a first defense layer, and the core assets of the system are protected for the first time. When the system is attacked, the attacker is difficult to locate the position of the real key assets under the normal condition of passing through the first defense layer of the camouflage. If the attacker breaks through the first defense layer of the system level by various means, the protection of the application level is enabled, that is, a second security policy is configured from the application level to form a second defense layer, and the core assets of the system are protected for the second time. If the second defense layer of the application level is broken, an emergency mechanism is established to transfer the core assets in the first time to minimize the loss. Since the protection of the system level and the application level can simulate the behavior and appearance of the system, the randomness and unpredictability of the system are used to resist network attacks, so that the attacker is difficult to find and attack the real system, and thus the security and resistance ability of the system are improved.

[0068] Figure 3 A flowchart of obtaining a first defense layer based on a system level configuration of a first security policy in the system defense ability improving method according to the embodiment of the present disclosure is schematically shown.

[0069] As Figure 3 shown, the system defense ability improvement of this embodiment includes operation S310 to operation S330.

[0070] In operation S310, a system hardware platform is built by using heterogeneous computing hardware.

[0071] In operation S320, in response to the completion of the system hardware platform building, a system running architecture is deployed by using a loose coupling architecture.

[0072] In operation S330, in response to the completion of the system running architecture deployment, a system software platform is built by using a micro-service architecture and an event-driven architecture.

[0073] In this embodiment, the first defense layer is obtained based on the system level configuration of the first security policy, which contains three aspects, namely, hardware aspect, architecture aspect and software aspect.

[0074] Hardware aspect: in the hardware setting aspect, different modules of the system select multiple hardware platforms and devices, and the same module adopts heterogeneous computing hardware in different scenarios, for example, a graphic processing unit (GPU) and a tensor processing unit (TPU) can be used for large model operation.

[0075] A graphics processing unit (GPU), also known as a display core, a visual processor, or a display chip, is a microprocessor specially designed to perform image and graphics related operations on personal computers, workstations, game consoles, and some mobile devices (such as tablets and smartphones). GPU reduces the dependence of the display card on the CPU and performs part of the work originally performed by the CPU, especially when using the core technology of GPU in 3D graphics processing. The core technologies include hardware T&L (geometry conversion and lighting processing), cubic environment material mapping and vertex mixing, texture compression and bump mapping, double texture four-pixel 256-bit rendering engine, etc. The hardware T&L technology can be said to be the symbol of GPU.

[0076] A tensor processing unit (TPU) is a special chip (ASIC) customized by Google for machine learning, designed specifically for Google's deep learning framework TensorFlow. Compared with a graphics processing unit (GPU), a TPU uses low-precision (8-bit) calculations to reduce the number of transistors used in each operation. Reducing precision has little effect on the accuracy of deep learning, but it can significantly reduce power consumption and speed up operations. In addition, TPU uses a systolic array design to optimize matrix multiplication and convolution operations, reducing I / O operations. In addition, TPU uses a larger on-chip memory to reduce access to DRAM, thereby greatly improving performance.

[0077] In terms of architecture, a loose-coupled architecture is used to enable flexible combination and replacement between modules.

[0078] In terms of software, different software architecture styles are adopted, such as microservices architecture and event-driven architecture. Various programming languages and technologies are selected during development and programming to adapt to different needs and scenarios. Different development frameworks and libraries are used in different modules of the same user's home, so that when attacked, not all functions are damaged.

[0079] In this embodiment, by configuring security policies from the three aspects of hardware, architecture, and software, a comprehensive protection layer can be formed to effectively defend against various threats.

[0080] Figure 4 A flowchart of deploying a system running architecture using a loose-coupled architecture in a system defense capability improvement method according to an embodiment of the present disclosure is schematically shown.

[0081] As Figure 4As shown, the system defense capability improvement of this embodiment includes operation S410 to operation S430.

[0082] In operation S410, the system is divided into a plurality of independent modules, wherein the plurality of independent modules are deployed in a mixed manner of physical machines, virtualization and containerization.

[0083] In operation S420, based on the plurality of independent modules, a plurality of independent virtual network environments are created.

[0084] In operation S430, based on the plurality of independent virtual network environments, an automated scheduling mechanism is configured, wherein the automated scheduling mechanism is used to randomly allocate resources and modify network configurations and network parameters according to system requirements.

[0085] In this embodiment, the protection at the software level is further improved. The system is divided into a plurality of independent modules, and the plurality of independent modules are deployed in a mixed manner of physical machines, virtualization and containerization. In addition, a plurality of virtual network environments are created using virtualization technology and containerization technology. Each network environment is independent and isolated. Different types of network devices and technologies are used in the network, such as wired networks and wireless networks, LANs (Local Area Networks) and WANs (Wide Area Networks), various firewalls and routers, etc. to increase the complexity and diversity of the network, making it difficult for attackers to find targets.

[0086] A local area network (Local Area Network, abbreviated as LAN) generally covers an area of a few thousand meters in diameter. Its characteristics of easy installation, cost savings, and easy expansion make it widely used in various offices. A local area network can realize file management, application software sharing, printer sharing, etc. During use, by maintaining the security of the local area network, the data security can be effectively protected, and the normal and stable operation of the local area network can be ensured.

[0087] A wide area network (Wide Area Network, abbreviated as WAN) is also known as an external network or public network. It is a long-distance network that connects different local area networks or metropolitan area networks. It usually spans a large physical range and covers an area from tens of kilometers to thousands of kilometers. It can connect multiple regions, cities and countries, or span several continents and provide long-distance communication to form an international long-distance network. A wide area network is not equivalent to the Internet.

[0088] On this basis, an automated and intelligent scheduling mechanism is introduced, such as random network configuration, random change of network configuration and parameters (which can include IP address, subnet mask, routing rules, etc.), to adapt to the complexity brought by heterogeneity and diversity. This can increase the dynamics and uncertainty of the network, making it difficult for attackers to predict the operating state of the network.

[0089] Figure 5 A flowchart of building a system software platform using a microservice architecture and an event-driven architecture in a system defense capability improvement method according to an embodiment of the present disclosure is shown.

[0090] As Figure 5 shown, the system defense capability improvement of this embodiment includes operation S510 to operation S520.

[0091] In operation S510, a system software platform is built using a microservice architecture based on online services.

[0092] In operation S520, a system software platform is built using an event-driven architecture based on low real-time requirement services.

[0093] In this embodiment, according to the characteristics and requirements of different services, appropriate software architecture styles are selected to design and develop each module or service in the system, which can improve the flexibility and scalability of the system, including microservice architecture and event-driven architecture.

[0094] Microservice architecture: Microservice architecture splits an application into multiple small, independently running services, each with its own business function, which can be independently deployed, scaled and updated, suitable for online services that require rapid iteration, easy expansion and maintenance, and can improve the flexibility, scalability and reliability of the system.

[0095] Event-driven architecture: Event-driven architecture triggers and executes different functions by processing events, and services communicate and coordinate through events, suitable for scenarios that do not require high real-time performance but need to respond to specific events, such as asynchronous message processing and log processing. This architecture helps to reduce the coupling between services and improve the flexibility and scalability of the system.

[0096] Figure 6 A flowchart of obtaining a second defense layer based on application layer configuration of a second security policy in a system defense capability improvement method according to an embodiment of the present disclosure is shown.

[0097] As Figure 6 shown, the system defense capability improvement of this embodiment includes operation S610 to operation S630.

[0098] In operation S610, real application access elements are obtained.

[0099] In operation S620, virtual application access elements for disguising real application access elements are generated according to real application access elements.

[0100] In operation S630, network traffic running virtual application access elements is obfuscated.

[0101] In this embodiment, the real application access elements are obtained, and then virtual application access elements are generated according to the real application access elements to camouflage the real application access elements, so as to confuse the attacker and make it difficult for the attacker to distinguish the real application access elements and the virtual application access elements. The network traffic running the virtual application access elements is further processed to have camouflage and randomness, so that the attacker is difficult to analyze and attack the network.

[0102] Figure 7 A flowchart of generating virtual application access elements according to real application access elements in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown.

[0103] As shown in Figure 7 , the system defense capability improvement of this embodiment includes operation S710 to operation S730.

[0104] In this embodiment, the real application access elements may include, for example, user identity, system data, and running environment.

[0105] In operation S710, virtual user identity is generated to camouflage real user identity according to the real user identity.

[0106] In operation S720, virtual system data is generated to camouflage real system data according to the real system data.

[0107] In operation S730, virtual running environment is generated to camouflage real running environment according to the real running environment.

[0108] By simulating the real user identity, the virtual user identity is generated to camouflage the real user identity, so that the attacker is difficult to distinguish the real user and the virtual user.

[0109] By simulating the real system data, the virtual system data is generated to camouflage the real system data, so as to confuse the attacker's sight and make it difficult for the attacker to determine the position and value of the real system data.

[0110] By simulating the real running environment, the virtual running environment is generated to camouflage the real running environment, such as simulating different operating systems, software versions, etc., so that the attacker is difficult to determine the real situation of the system.

[0111] Figure 8 A flowchart of processing network traffic in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown.

[0112] As shown in Figure 8 , the system defense capability improvement of this embodiment includes operation S810 to operation S830.

[0113] In operation S810, the confidentiality of network traffic is enhanced according to encryption technology.

[0114] In operation S820, the complexity of network traffic is increased according to the way of confusing data packets.

[0115] In operation S830, simulated network traffic is generated according to real network traffic, and real application access elements are hidden.

[0116] In this embodiment, end-to-end encrypted communication such as SSL / TLS protocol is used to encrypt data transmitted by the network, preventing attackers from stealing sensitive information. The network data packets are confused, which can change the order of the data packets, add fake data or fill the contents of the data packets, so that it is difficult for attackers to accurately identify valid data packets. Simulated network traffic is generated, including false requests, responses and data transmission, so that real network traffic and simulated traffic are mixed together, increasing the difficulty of analysis and detection for attackers.

[0117] Figure 9 The flowchart of establishing an emergency mechanism to transfer core assets in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown.

[0118] As shown in Figure 9 The system defense capability improvement of this embodiment includes operations S910-S930.

[0119] In operation S910, the first security policy and / or the second security policy are dynamically adjusted, and the security state of the core assets is monitored in real time.

[0120] In operation S920, a response mechanism is established for security events and system vulnerabilities, and abnormal behavior and potential attacks in the system are controlled.

[0121] In operation S930, the core assets are transferred based on the response mechanism.

[0122] In this embodiment, the real user identity, system data, running environment and network traffic are protected and disguised by the second protective layer, and it is difficult for attackers to quickly locate and attack the real target. However, if the second protective layer is also broken, the security protection strategy is dynamically adjusted, the security state of the core assets is monitored in real time, and a response mechanism is established to deal with security events and vulnerabilities, so as to timely discover abnormal behavior and potential attacks in the system, dynamically adjust the mimicry defense strategy according to the changes of the threat environment, and continuously maintain the confusion and confusion of the attacker.

[0123] Figure 10 The flowchart of establishing a response mechanism to control abnormal behavior and potential attacks in the system in the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown.

[0124] As Figure 10 shown, the system defense capability improvement of this embodiment includes operation S1010 to operation S1030.

[0125] In operation S1010, abnormal behavior and potential attacks are logged in real time.

[0126] In operation S1020, the system is subjected to intrusion detection and the first security policy is activated for automatic defense.

[0127] In operation S1030, the core assets leaked due to abnormal behavior and potential attacks are mitigated.

[0128] In this embodiment, the establishment of a response mechanism to control abnormal behavior and potential attacks in the system includes real-time logging, intrusion detection and response, event response plan, etc.

[0129] Among them, intrusion detection and response is to identify behaviors that violate security policies, signs of attacks or threats by collecting and analyzing information in computer networks, thereby providing real-time protection against internal attacks, external attacks and misoperations. In this example, the response here refers to the automatic defense operation of the first security policy preset by the system at the software level.

[0130] The event response plan contains documents of structured methods for handling and mitigating the consequences of security incidents, network attacks and data breaches.

[0131] Figure 11 The flowchart schematically shows the process of upgrading the system after completing a round of attack defense in the system defense capability improvement method according to the embodiment of the present disclosure.

[0132] As Figure 11 shown, the system defense capability improvement of this embodiment includes operation S1110 to operation S1120.

[0133] In operation S1110, in response to completing a round of attack defense, the current system is reviewed and upgraded.

[0134] In operation S1120, the effectiveness of the current system defense strategy is periodically evaluated, and improvements are made based on the evaluation results.

[0135] In this embodiment, after completing a round of attack defense, the existing system needs to be reviewed and upgraded, the effectiveness of the existing system defense strategy is periodically evaluated, and improvements are made based on the evaluation results. Through multi-level and multi-angle defense measures, combined with emergency response mechanism and continuous improvement mechanism, the defense capability of the system can be greatly improved, the loss caused by the attack on the system can be reduced, and the stability and security of the system can be ensured.

[0136] Figure 12 A flowchart illustrating periodic evaluation of effectiveness of current system defense strategy in the system defense capability improvement method according to an embodiment of the present disclosure is shown.

[0137] As shown in Figure 12 The system defense capability improvement of this embodiment includes operations S1210-S1220.

[0138] In operation S1210, defense drills and tests are conducted periodically to maintain the effectiveness of the defense strategy.

[0139] In operation S1220, the defense strategy is updated periodically to adapt to changing threats and attack techniques.

[0140] In this embodiment, the effectiveness of the current system defense strategy is periodically evaluated and improved based on the evaluation results, which can be completed in two aspects. First, defense drills and tests are conducted periodically to maintain the effectiveness of the defense strategy. Second, the defense strategy is updated periodically to adapt to changing threats and attack techniques.

[0141] According to an embodiment of the present disclosure, periodically conducting defense drills and tests to maintain the effectiveness of the defense strategy includes periodically conducting simulated attacks and penetration tests to maintain the effectiveness of the defense strategy.

[0142] According to an embodiment of the present disclosure, periodically updating the defense strategy to adapt to changing threats and attack techniques includes periodically updating defense tools, fixing vulnerabilities, and improving mimicry strategies to adapt to changing threats and attack techniques.

[0143] Figure 13 A schematic diagram of the system defense capability improvement method according to an embodiment of the present disclosure is shown.

[0144] As shown in Figure 13 The principle of the system defense capability improvement method of the present embodiment is as follows:

[0145] In response to an attack on the system, the security requirements and threat intelligence of the system are obtained, and the attack surface and core assets of the system are determined based on the security requirements and threat intelligence.

[0146] For the attack surface, a first security policy is configured from the system level to form a first defense layer, and the core assets of the system are protected for the first time.

[0147] Among them, the first security policy based on the system level configuration can be configured from the hardware aspect, the architecture aspect and the software aspect.

[0148] Hardware: In terms of hardware settings, different modules of the system select multiple hardware platforms and devices, and the same module uses heterogeneous computing hardware in different scenarios, such as using a graphics processing unit (GPU) and a tensor processing unit (TPU) for large model operations.

[0149] Architecture: After completing the hardware level setting, in terms of architecture, a loosely coupled architecture is used to enable flexible combination and replacement between modules.

[0150] Software: After completing the hardware and architecture layer settings, in terms of software, different software architecture styles are used, such as using microservice architecture and event-driven architecture. When developing and programming, multiple programming languages and technologies are selected to adapt to different needs and scenarios, and different modules in the same user's home use different development frameworks and libraries, so that when attacked, not all functions are damaged.

[0151] When the system is attacked, the attacker is usually difficult to locate the position of the real key assets through the first layer of protection. If the attacker breaks through the first layer of protection at the system level by various means, the application level protection is enabled, that is, the second security policy is configured at the application level to form the second layer of protection, and the core assets of the system are protected for the second time.

[0152] Among them, the second security policy configured based on the application level can hide the real application access elements by virtualizing the application access elements (such as user identity, system data and running environment) to generate virtual application access elements, and the network traffic is processed by confusion.

[0153] If the second layer of protection at the application level is broken, an emergency mechanism is established to transfer the core assets in the first time to minimize losses. Since the protection at the system level and the application level can simulate the behavior and appearance of the system, and use the randomness and unpredictability of the system to resist network attacks, it is difficult for attackers to find and attack the real system, thereby improving the security and resistance of the system.

[0154] Based on the above system defense capability improvement method, the present disclosure also provides a system defense capability improvement device. The following will be described in detail Figure 14 The device is described in detail.

[0155] Figure 14 The structure block diagram of the system defense capability improvement device according to the embodiment of the present disclosure is schematically shown.

[0156] As Figure 14As shown, the system defense capability improving apparatus 1400 of this embodiment includes an obtaining module 1410, a determining module 1420, a first configuring module 1430, a second configuring module 1440, and an establishing module 1450.

[0157] The obtaining module 1410 is configured to obtain security requirements and threat intelligence of the system in response to the system being attacked. In an embodiment, the obtaining module 1410 can be configured to perform operation S210 described above, and details are not repeated here.

[0158] The determining module 1420 is configured to determine an attack surface and core assets of the system according to the security requirements and the threat intelligence. In an embodiment, the determining module 1420 can be configured to perform operation S220 described above, and details are not repeated here.

[0159] The first configuring module 1430 is configured to configure a first security policy based on a system layer to obtain a first defense layer for the attack surface, where the first defense layer is configured to perform a first camouflage for the core assets. In an embodiment, the first configuring module 1430 can be configured to perform operation S230 described above, and details are not repeated here.

[0160] The second configuring module 1440 is configured to configure a second security policy based on an application layer to obtain a second defense layer in response to the first defense layer being broken, where the second defense layer is configured to perform a second camouflage for the core assets. In an embodiment, the second configuring module 1440 can be configured to perform operation S240 described above, and details are not repeated here.

[0161] The establishing module 1450 is configured to establish an emergency mechanism to transfer the core assets in response to the second defense layer being broken. In an embodiment, the establishing module 1450 can be configured to perform operation S250 described above, and details are not repeated here.

[0162] The system defense capability improving apparatus according to the embodiments of the present disclosure can form a first defense layer by configuring a first security policy from a system layer, perform a first camouflage defense for core assets of the system, and in the case of an attack on the system, the attacker is difficult to locate the position of the real key assets through the camouflage of the first defense layer. If the attacker breaks through the first defense layer of the system layer by various means, the defense of the application layer is enabled, that is, a second defense layer is formed by configuring a second security policy from the application layer, a second camouflage defense is performed for the core assets of the system, and if the second defense layer of the application layer is broken, an emergency mechanism is established to transfer the core assets in the first time to minimize the loss. Since the defenses of the system layer and the application layer can simulate the behavior and appearance of the system, the randomness and unpredictability of the system are used to resist network attacks, so that the attacker is difficult to find and attack the real system, and thus the security and resistance of the system are improved.

[0163] According to an embodiment of the present disclosure, any of the modules of the acquiring module 1410, the determining module 1420, the first configuring module 1430, the second configuring module 1440 and the establishing module 1450 can be combined in one module, or any of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of the modules can be combined with at least part of the functions of the other modules, and implemented in one module. According to an embodiment of the present disclosure, at least one of the acquiring module 1410, the determining module 1420, the first configuring module 1430, the second configuring module 1440 and the establishing module 1450 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on board, a system on package, an application specific integrated circuit (ASIC), or any other reasonable manner of hardware or firmware that can be integrated or packaged with a circuit, or implemented in any one of software, hardware and firmware or in a proper combination of any of the foregoing. Alternatively, at least one of the acquiring module 1410, the determining module 1420, the first configuring module 1430, the second configuring module 1440 and the establishing module 1450 can be at least partially implemented as a computer program module that can perform the corresponding functions when the computer program module is run.

[0164] Figure 15 A block diagram of an electronic device suitable for implementing the system defense capability improvement method according to an embodiment of the present disclosure is schematically shown.

[0165] As shown in Figure 15 The electronic device 1500 according to an embodiment of the present disclosure includes a processor 1501 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1502 or loaded from a storage portion 1508 into a random access memory (RAM) 1503. The processor 1501 can include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor and / or a related chipset, and / or a special-purpose microprocessor (such as an application specific integrated circuit (ASIC)), and the like. The processor 1501 can also include an on-board memory for cache use. The processor 1501 can include a single processing unit or a plurality of processing units for performing different actions of the method processes according to embodiments of the present disclosure.

[0166] In the RAM 1503, various programs and data required for the operation of the electronic device 1500 are stored. The processor 1501, the ROM 1502, and the RAM 1503 are connected to each other via the bus 1504. The processor 1501 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 1502 and / or the RAM 1503. It should be noted that the programs can also be stored in one or more memories other than the ROM 1502 and the RAM 1503. The processor 1501 can also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0167] According to an embodiment of the present disclosure, the electronic device 1500 can further include an input / output (I / O) interface 1505, which is also connected to the bus 1504. The electronic device 1500 can further include one or more of the following components connected to the I / O interface 1505: an input part 1506 including a keyboard, a mouse, etc.; an output part 1507 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage part 1508 including a hard disk, etc.; and a communication part 1509 including a network interface card such as a LAN card, a modem, etc. The communication part 1509 performs communication processing via a network such as the Internet. A drive 1510 is also connected to the I / O interface 1505 as necessary. A removable medium 1511 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 1510 as necessary, so that a computer program read out therefrom is installed in the storage part 1508 as necessary.

[0168] The present disclosure also provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments; or can exist separately without being assembled into the device / apparatus / system. The above computer readable storage medium carries one or more programs, when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0169] According to an embodiment of the present disclosure, the computer readable storage medium can be a nonvolatile computer readable storage medium, for example, can include, but is not limited to, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof. In the present disclosure, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer readable storage medium can include one or more memories, such as the ROM 1502 and / or the RAM 1503 described above, and / or one or more memories other than the ROM 1502 and the RAM 1503.

[0170] Embodiments of the present disclosure also include a computer program product including a computer program containing program codes for executing the methods shown in the flowcharts. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the item recommendation method provided by the embodiments of the present disclosure.

[0171] The above-described functions defined in the system / device of the embodiments of the present disclosure are performed when the computer program is executed by the processor 1501. According to an embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by computer program modules.

[0172] In one embodiment, the computer program can rely on a tangible storage medium such as an optical storage device, a magnetic storage device, etc. In another embodiment, the computer program can also be transmitted, distributed, and downloaded in the form of a signal on a network medium, and be downloaded and installed through the communication part 1509, and / or installed from the detachable medium 1511. The program codes contained in the computer program can be transmitted by any appropriate network medium, including but not limited to wireless, wired, etc., or any appropriate combination thereof.

[0173] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 1509, and / or installed from the detachable medium 1511. When the computer program is executed by the processor 1501, the above-described functions defined in the system of the embodiments of the present disclosure are performed. According to an embodiment of the present disclosure, the system, device, apparatus, module, unit, etc. described above can be implemented by computer program modules.

[0174] According to embodiments of the present disclosure, program code of the computer program for performing the methods provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages, and can be implemented in a computer program product. Specifically, the computer program can be implemented in a high-level procedural and / or object-oriented programming language, and / or in assembly / machine language. The programming language includes, but is not limited to, Java, C++, python, “C” language, or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's device, and partly on a remote computing device, or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider (ISP).

[0175] The computer program product of the present disclosure can be a computer program product, which is a machine-readable medium (or computer readable medium) having stored therein a sequence of instructions readable, by one or more processors of a computer system, the instructions being executable by the one or more processors to cause the computer system to execute the method of the present disclosure. The instructions can be software instructions stored in memory (e.g., memory 120 of the computer system) and implemented as software programs to perform the method of the present disclosure. The computer program product can also be a machine- readable medium (or computer readable medium) having stored therein a sequence of instructions executable by a processor of a computer system to cause the computer system to perform the method of the present disclosure. The machine-readable medium (or computer readable medium) can include, but is not limited to, floppy diskettes, optical disks, CD-ROMs (compact disc-read only memories), and magneto-optical disks, ROMs (read only memories), RAMs (random access memories), EPROMs (erasable programmable read only memories), EEPROMs (electrically erasable programmable read only memories), magnetic or optical cards, flash memory, or any other type of media suitable for storing electronic instructions.

[0176] It will be appreciated by persons skilled in the art that features of various embodiments and / or claims of the present disclosure can be combined or / and integrated with one another, even though such combinations or integrations are not expressly disclosed in the present disclosure. In particular, features of various embodiments and / or claims of the present disclosure can be combined and / or integrated with one another, without departing from the spirit and scope of the present disclosure. All such combinations and / or integrations are within the scope of the present disclosure.

[0177] The above describes embodiments of the present disclosure. However, these embodiments are merely for illustrative purposes, and are not intended to limit the scope of the present disclosure. Although each embodiment is described above separately, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Those skilled in the art can make various substitutions and modifications without departing from the scope of the present disclosure, and these substitutions and modifications should all fall within the scope of the present disclosure.

Claims

1. A system defense capability enhancement method, characterized by, The method comprises: in response to the system being attacked, obtaining security requirements and threat intelligence of the system; determining the attack surface and core assets of the system according to the security requirements and the threat intelligence; for the attack surface, configuring a first security policy based on the system layer to obtain a first protection layer, comprising: building a system hardware platform by using heterogeneous computing hardware; in response to the completion of building the system hardware platform, deploying a system running architecture by using a loosely coupled architecture; in response to the completion of deploying the system running architecture, building a system software platform by using a micro-service architecture and an event-driven architecture, wherein the first protection layer is used to perform a first camouflage for the core assets; in response to the first protection layer being broken, configuring a second security policy based on the application layer to obtain a second protection layer, comprising: obtaining real application access elements; generating virtual application access elements for camouflaging the real application access elements according to the real application access elements; performing obfuscation processing on network traffic running the virtual application access elements, wherein the second protection layer is used to perform a second camouflage for the core assets; in response to the second protection layer being broken, establishing an emergency mechanism to transfer the core assets.

2. The method of claim 1, wherein, The deployment of the system running architecture by using the loosely coupled architecture comprises: dividing the system into a plurality of independent modules, wherein the plurality of independent modules are deployed by mixing physical machines, virtualization and containerization; based on the plurality of independent modules, creating a plurality of independent virtual network environments; based on the plurality of independent virtual network environments, configuring an automatic scheduling mechanism, wherein the automatic scheduling mechanism is used to randomly allocate resources and modify network configurations and network parameters according to system requirements.

3. The method of claim 1, wherein, The building of the system software platform by using the micro-service architecture and the event-driven architecture comprises: based on online services, building the system software platform by using the micro-service architecture; based on low real-time requirement services, building the system software platform by using the event-driven architecture.

4. The method of claim 1, wherein, The real application access elements comprise user identity, system data and running environment, wherein generating virtual application access elements for camouflaging the real application access elements according to the real application access elements comprises: generating virtual user identity for camouflaging the real user identity according to the real user identity; generating virtual system data for camouflaging the real system data according to the real system data; generating virtual running environment for camouflaging the real running environment according to the real running environment.

5. The method of claim 1, wherein, The obfuscation processing on network traffic running the virtual application access elements comprises: enhancing the confidentiality of the network traffic according to encryption technology; increasing the complexity of the network traffic according to the obfuscated packet method; generating simulated network traffic according to real network traffic to hide the real application access elements.

6. The method of claim 1, wherein, The establishment of the emergency mechanism to transfer the core assets in response to the second protection layer being broken comprises: dynamically adjusting the first security policy and / or the second security policy to monitor the security state of the core assets in real time; establishing a response mechanism for security incidents and system vulnerabilities to control abnormal behaviors and potential attacks in the system; transferring the core assets based on the response mechanism.

7. The method of claim 6, wherein, The response mechanism for security incidents and system vulnerabilities, controlling abnormal behavior and potential attacks in the system includes: Real-time logging of the abnormal behavior and the potential attacks; Intrusion detection of the system and automatic resistance by activating the first security policy; Mitigation of the core assets leaked due to the abnormal behavior and the potential attacks.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Reviewing and upgrading the current system in response to completing a round of attack defense; Periodically evaluating the effectiveness of the current system defense strategy and improving it based on the evaluation results.

9. The method of claim 8, wherein, The periodic evaluation of the effectiveness of the current system defense strategy and the improvement based on the evaluation results include: Periodically conducting defense drills and tests to maintain the effectiveness of the defense strategy; Periodically updating the defense strategy to adapt to changing threats and attack techniques.

10. The method of claim 9, wherein, The periodic defense drills and tests to maintain the effectiveness of the defense strategy include: Periodically conducting simulated attacks and penetration tests to maintain the effectiveness of the defense strategy.

11. The method of claim 9, wherein, The periodic updating of the defense strategy to adapt to changing threats and attack techniques includes: Periodically updating defense tools, fixing vulnerabilities, and improving mimicry strategies to adapt to changing threats and attack techniques.

12. A system defense capability enhancement apparatus characterized by comprising: The apparatus includes: An acquisition module for acquiring security requirements and threat intelligence of the system in response to the system being attacked; A determination module for determining the attack surface and core assets of the system based on the security requirements and the threat intelligence; A first configuration module for configuring a first security policy based on the system layer for the attack surface to obtain a first defense layer, including: building a system hardware platform using heterogeneous computing hardware; in response to the system hardware platform being built, deploying a system running architecture using a loosely coupled architecture; in response to the system running architecture being deployed, building a system software platform using a microservices architecture and an event-driven architecture, wherein the first defense layer is used to disguise the core assets for the first time; A second configuration module for configuring a second security policy based on the application layer in response to the first defense layer being breached to obtain a second defense layer, including: acquiring real application access elements; generating virtual application access elements for disguising the real application access elements based on the real application access elements; and obfuscating network traffic running the virtual application access elements, wherein the second defense layer is used to disguise the core assets for the second time; An establishment module for establishing an emergency mechanism to transfer the core assets in response to the second defense layer being breached.

13. An electronic device comprising: one or more processors; a storage device for storing one or more computer programs, characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1-11.

14. A computer readable storage medium having stored thereon computer programs / instructions, characterized in that, The computer program / instructions are executed by the processor to implement the steps of the method according to any one of claims 1-11.

15. A computer program product comprising computer programs / instructions, characterized in that, The computer program / instructions are executed by the processor to implement the steps of the method according to any one of claims 1-11. The computer program / instructions are executed by the processor to implement the steps of the method according to any one of claims 1-11.

Citation Information

Patent Citations

  • Attack analyzer, attack analysis method and storage medium

    CN115134109A

  • Dynamic cheating defense method based on attacker behavior analysis and evaluation

    CN117061184A