A network security defense mechanism evaluation method, system, device and medium

By evaluating network defense mechanisms using a multi-layer neural network model and an adaptive weighted algorithm, this approach addresses the lack of a global perspective in existing technologies. It enables quantitative evaluation and optimization suggestions for the synergistic effect of multi-layer defense mechanisms, thereby enhancing the flexibility and responsiveness of network security defense.

CN119276614BActive Publication Date: 2025-11-04STATE GRID FUJIAN ELECTRIC POWER RES INST +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411656496.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-11-04
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

Existing cybersecurity assessment methods lack a holistic perspective and fail to fully consider the synergistic effects between multi-layered defense mechanisms. In particular, the assessment effectiveness of traditional defense mechanisms is limited in complex enterprise network environments.

Method used

A defense mechanism scoring model trained with a multi-layer neural network model, combined with an adaptive weighting algorithm, analyzes the feature information of various defense mechanisms to generate quantitative evaluation results, and dynamically adjusts them based on real-time situational data to provide optimization suggestions.

Benefits of technology

It enables comprehensive and objective assessment in complex, multi-layered network environments, quickly identifies defensive weaknesses and proposes optimization suggestions, improving the flexibility and responsiveness of network security defenses. It is particularly suitable for enterprise networks, cloud computing environments, and the Internet of Things.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276614B_ABST
    Figure CN119276614B_ABST
Patent Text Reader

Abstract

The application discloses a network security defense mechanism evaluation method, system, device and medium, comprising: analyzing various defense mechanisms in a current network system, and extracting feature information of the defense mechanisms of the current network system; inputting the feature information of the defense mechanisms of the current network system into a trained defense mechanism scoring model, and obtaining an evaluation result of the defense mechanisms of the current network system, so that the method, system, device and medium can fully consider the synergistic effect between multiple defense mechanisms to evaluate the network security defense mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of computer network and information security, and relates to a network security defense mechanism evaluation method, system, device and medium. BACKGROUND

[0002] Under the background of digital transformation, enterprise network security defense mechanisms are facing increasingly complex challenges. With the continuous evolution of network attack technology, the diversity and complexity of network attack methods have significantly increased. Attackers use zero-day vulnerabilities, advanced persistent threats (APTs), DDoS, and other methods to launch attacks on network systems. Traditional defense methods such as firewalls, intrusion detection systems (IDS), access control lists (ACL), and others are still widely used, but their effectiveness is limited when facing these advanced threats.

[0003] Existing network security evaluation methods usually analyze single defense mechanisms, lack a global perspective, and cannot fully consider the synergy between multiple defense mechanisms. Especially in complex enterprise network environments, defense mechanisms are often distributed across different levels, making it difficult to comprehensively evaluate the effectiveness of each defense mechanism. SUMMARY

[0004] The purpose of the present application is to overcome the shortcomings of the prior art and provide a network security defense mechanism evaluation method, system, device and medium that can fully consider the synergy between multiple defense mechanisms to evaluate network security defense mechanisms.

[0005] To achieve the above purpose, the present application adopts the following technical solutions:

[0006] In one aspect of the present application, the network security defense mechanism evaluation method comprises:

[0007] Analyzing various defense mechanisms in the current network system and extracting feature information of the defense mechanisms of the current network system;

[0008] Inputting the feature information of the defense mechanisms of the current network system into the trained defense mechanism scoring model to obtain an evaluation result of the defense mechanisms of the current network system.

[0009] The network security defense mechanism evaluation method further improves in that:

[0010] Further, the various defense mechanisms in the current network system include, but are not limited to, firewalls, IDS, ACL, and endpoint security policies.

[0011] Further, the feature information of the defense mechanism of the current network system includes but is not limited to: configuration parameters of the defense mechanism, actual running status, execution effect of the strategy, device redundancy and traffic monitoring data.

[0012] Further, the defense mechanism scoring model is trained based on a multi-layer neural network model.

[0013] Further, the loss function of the defense mechanism scoring model in the training process is:

[0014]

[0015] Wherein, S i is the real score, is the predicted score, and n is the number of defense mechanisms.

[0016] Further, the defense mechanism scoring model is trained based on an adaptive weighting algorithm, wherein the weights of each defense mechanism in the defense mechanism scoring model are updated through the adaptive weighting algorithm, that is:

[0017]

[0018] Wherein, η is the learning rate, and L is the loss function.

[0019] In the second aspect of the present application, the network security defense mechanism evaluation system comprises:

[0020] An analysis module is configured to analyze various defense mechanisms in the current network system and extract feature information of the defense mechanisms of the current network system.

[0021] An evaluation module is configured to input the feature information of the defense mechanisms of the current network system into the trained defense mechanism scoring model to obtain an evaluation result of the defense mechanisms of the current network system.

[0022] Further improvement of the network security defense mechanism evaluation system is that:

[0023] Further, the loss function of the defense mechanism scoring model in the training process is:

[0024]

[0025] Wherein, S i is the real score, is the predicted score, and n is the number of defense mechanisms.

[0026] The computer device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the network security defense mechanism evaluation method when executing the computer program.

[0027] The computer readable storage medium stores a computer program, and the computer program implements the steps of the network security defense mechanism evaluation method when executed by a processor.

[0028] The present application has the following beneficial effects:

[0029] The network security defense mechanism evaluation method, system, device and medium analyze various defense mechanisms in the current network system, extract feature information of the defense mechanisms of the current network system, and consider multiple network defense mechanisms. BRIEF DESCRIPTION OF DRAWINGS

[0030] The accompanying drawings, which form a part of the specification, are included to provide a further understanding of the application and are incorporated herein in conjunction with the description of the application. The embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0031] Figure 1 The schematic diagram of the present application is shown in the figure;

[0032] Figure 2 The method flowchart of the present application is shown in the figure. DETAILED DESCRIPTION

[0033] In order to better understand the present application by those skilled in the art, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments, and are not intended to limit the scope of the present application. In addition, in the following description, the description of known structures and technologies is omitted to avoid unnecessary confusion of the concepts disclosed in the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should fall within the scope of the present application.

[0034] The structural schematic diagram according to the disclosed embodiment is shown in the accompanying drawings. The drawings are not drawn to scale, in which some details are exaggerated for the purpose of clarity and some details can be omitted. The shapes of various regions, layers and the relative size and position relationship therebetween shown in the drawings are only exemplary, and in practice, they can be deviated due to manufacturing tolerance or technical limitation, and regions / layers with different shapes, sizes and relative positions can be additionally designed according to actual needs by those skilled in the art.

[0035] Embodiment one

[0036] With reference to Figure 1 and Figure 2 , the network security defense mechanism evaluation method of the present application comprises the following steps:

[0037] 1) Defense mechanism analysis and feature extraction;

[0038] Each type of defense mechanism in the network system is comprehensively analyzed, and multi-dimensional feature information is extracted, the defense mechanism including firewall, IDS, ACL, endpoint security policy, and the multi-dimensional feature information including configuration parameters, actual running status, policy execution effect, device redundancy and traffic monitoring data of the defense mechanism. Through the extraction of multi-dimensional feature information, the actual state of the current network security defense can be more accurately reflected, that is:

[0039] X = [x1, x2, …, x n ]

[0040] Wherein, X is a feature vector, x1, x2, …, x n is the feature information of different defense mechanisms, for example, firewall rule complexity and IDS matching rate.

[0041] 2) Constructing a feature vector matrix;

[0042] According to the multi-dimensional feature information, a feature vector matrix is constructed, which is a structured representation of the defense mechanism under multi-dimensional information, reflecting the feature parameters of each defense mechanism. Through this structure, each type of security defense mechanism in the network can be uniformly and quantitatively described, which is convenient for subsequent scoring model training and evaluation.

[0043] To ensure the comprehensiveness of the defense mechanism evaluation, the network defense features are extracted from multiple dimensions in the present application, including but not limited to the following features:

[0044] 21) Firewall rule:

[0045] Complexity: number of rules, hierarchical depth of rule chain.

[0046] Coverage: Whether it effectively covers all parts of the network.

[0047] Update Frequency: Whether regular updates are timely and accurate.

[0048] 22) Intrusion Detection / Prevention System (IDS / IPS) Policy:

[0049] Rule Match Rate: The ratio of successfully detected intrusion events to actual events.

[0050] False Positive and False Negative Rate: The rate of false positives for unrelated events and the rate of missed real attacks.

[0051] Response Delay: The response time after intrusion detection.

[0052] 23) Access Control List (ACL):

[0053] Entry Number: The number of entries in the ACL and its complexity.

[0054] Execution Efficiency: The processing speed and execution effect of the ACL.

[0055] Coverage: Whether it covers all critical network devices and nodes.

[0056] 24) Endpoint Security Policy:

[0057] Execution Rate: The actual execution rate of the endpoint security policy.

[0058] Threat Protection: Whether sufficient terminal virus and malware protection measures are configured.

[0059] Security Patch Management: Whether terminal patches are installed and updated in a timely manner.

[0060] 25) Encryption Protocol Usage:

[0061] Usage Rate: Whether sufficient encryption protocols such as TLS1.2 or higher are used.

[0062] Encryption Strength: The security of the encryption algorithm used, such as AES-256.

[0063] Encryption Coverage: Whether all sensitive communication channels are encrypted.

[0064] 26) Patch Management Status:

[0065] Timeliness: Whether system and software patches are updated in a timely manner.

[0066] Coverage: Whether patches are applied to all critical system components and devices.

[0067] Security Assessment: Whether the effects of the patches can resist known security threats.

[0068] According to the above method, a feature vector matrix is generated, each row of the matrix representing a feature vector of a defense mechanism, and the columns in the feature vector matrix representing different dimensions of the features, i.e., the feature vector matrix is represented as:

[0069]

[0070] where m is the number of features of the defense mechanism. The feature vector matrix can be used as input data for the scoring model in the subsequent steps to quantify and compare the security of different defense mechanisms.

[0071] To ensure that the feature vectors of the defense mechanisms can be effectively processed, the defense features need to be standardized when constructing the matrix to ensure that the magnitudes of the values of different dimension features are consistent. The standardization formula is:

[0072]

[0073] where x ij is the original feature value, μ j and σ j are the mean and standard deviation of the jth feature, and x i ′ j is the standardized feature value. Through standardization, the data in the feature vector matrix will be adjusted to a normal distribution with a mean of 0 and a standard deviation of 1, so as to effectively train the subsequent machine learning model.

[0074] In addition to the feature data of the current network defense mechanism, the importance of historical data in defense mechanism evaluation cannot be ignored. The system can analyze past security incidents, attack behaviors and the effects of defense measures, combine these data with the current network security situation, and build a more accurate defense evaluation model.

[0075] The introduction of historical data can be done in the following ways:

[0076] Time weighting mechanism: Add time weight to historical data, the closer to the current time, the greater the weight, so as to ensure that the current network security situation can be combined when evaluating.

[0077] Anomaly detection logs: historical security incidents, log information of abnormal traffic, etc., as additional feature input, so as to evaluate the effect of defense mechanisms in dealing with specific attacks.

[0078] 3) Build a scoring model;

[0079] The defense mechanism scoring model is constructed by an optimized multi-index evaluation model. Specifically, feature information extracted from various security defense mechanisms is used to construct a representative feature vector, and then a machine learning algorithm (such as a multi-layer neural network model) is used to train the model to evaluate the effectiveness and security of various defense mechanisms in the network.

[0080] The basic process of the scoring model is as follows:

[0081] 31) Feature extraction;

[0082] According to the extracted network defense mechanism feature information, a multi-dimensional feature vector matrix X is formed, wherein each vector corresponds to a specific defense mechanism, such as a firewall, an intrusion detection system (IDS), a network access control list (ACL), an endpoint security policy, etc.

[0083] 32) Model construction;

[0084] A multi-layer neural network scoring model is constructed, wherein the input layer is the feature vector X, the hidden layer performs nonlinear transformation, and the output layer generates the scoring result, i.e.:

[0085] y = f(WX + b)

[0086] Where y is the scoring result, W is the weight matrix, X is the input feature vector, b is the bias term, and f is the activation function, usually the ReLU activation function. The parameters of the model are trained multiple times to make the scoring result close to the true defense effect.

[0087] 3) Training and optimization of the defense mechanism scoring model;

[0088] Through multiple iterations of model training, the weights of the defense mechanism scoring model are gradually adjusted, and the mean square error (MSE) is used as the loss function to measure the scoring error, i.e.:

[0089]

[0090] Where S i is the true score, is the predicted score, and n is the number of defense mechanisms. The parameters of the defense mechanism scoring model are updated by the gradient descent method or the Adam optimization algorithm to optimize the defense mechanism scoring model.

[0091] 4) Real-time scoring and comprehensive situation assessment;

[0092] The feature information of the defense mechanism of the current network is input into the trained defense mechanism scoring model to generate an evaluation result of the defense mechanism of the current network, and the security posture of the overall network is comprehensively evaluated. This process not only includes the evaluation of a single defense mechanism, but also comprehensively considers the synergistic effect of multiple defense levels and mechanisms, thereby providing a score of the overall security posture.

[0093] The specific scoring method can be represented as:

[0094]

[0095] wherein S total is the overall security posture score, S i is the score of a single defense mechanism, w i is the importance weight of the defense mechanism. Through this method, the effects of different defense mechanisms can be quantified and integrated to obtain the final overall defense capability score.

[0096] In addition, the present application can also combine real-time security posture data, such as abnormal traffic monitoring logs, attack event alarms, network traffic behavior anomalies, etc., to combine static scoring and dynamic scoring to obtain a more comprehensive defense effect.

[0097] The dynamic posture score is:

[0098] S dynamic = α·S static + β·A(t)

[0099] wherein S dynamic is the dynamic security posture score, S static is the static score, A(t) is real-time posture data, and α and β are the weighting coefficients of static and dynamic scores, respectively. Through dynamic monitoring, the system can adjust the score according to the real-time network security situation.

[0100] 5) Optimization suggestions and improvement strategies are generated;

[0101] Based on the evaluation results of each defense mechanism, optimization suggestions are automatically generated, and defense improvement strategies are provided.

[0102] The defense improvement strategies can include the following:

[0103] 51) Firewall rules: If the score is low, the system can suggest increasing the complexity and accuracy of the rules, or adjusting the rule configuration according to the real-time traffic pattern.

[0104] 52) IDS / IPS strategy: For low-scoring intrusion detection / prevention systems, machine learning-driven anomaly detection algorithms can be introduced to improve rule matching rate and response speed.

[0105] 53) ACL improvement: For poorly scored Access Control Lists (ACLs), optimization of their entry quantity and coverage can be suggested to reduce false positives or negatives.

[0106] 54) Endpoint security policy: If the endpoint security policy is not effective, it is recommended to increase the strength of terminal encryption, virus protection, and vulnerability patch management.

[0107] 55) Encryption protocol upgrade: For low-scoring encryption policies, the system may suggest upgrading from weaker encryption protocols (such as TLS1.0) to stronger protocols (such as TLS1.3 or AES-256).

[0108] The generation of specific optimization suggestions uses a scoring threshold-based algorithm. When the score of a certain defense mechanism is below a certain threshold, the corresponding improvement strategy suggestion is triggered. The priority of the improvement scheme is sorted based on the weight of the scoring model for different defense mechanisms and their importance.

[0109] 6) Algorithm details and optimization strategies;

[0110] The present application combines adaptive weighting algorithm with neural network scoring model to achieve high efficiency and flexibility of defense mechanism evaluation. By adaptively adjusting the weight of each defense mechanism, the scoring model is more suitable for real-time network defense conditions, ensuring the accuracy and applicability of the evaluation.

[0111] Adaptive weighting algorithm:

[0112] 61) Initialize weights: In model initialization, assign initial weights ω i to each defense mechanism, where ω i Adjust according to the importance of the defense mechanism and specific business requirements. The initial allocation formula of the weight is:

[0113]

[0114] 62) Feature scoring: Based on the previously extracted feature vector matrix, the scoring model will output the initial score S i of each defense mechanism.

[0115] 63) Weight adjustment: Dynamically adjust the weight through the adaptive formula to respond to real-time network situation and defense effect:

[0116]

[0117] Where η is the learning rate and L is the loss function. By minimizing L, the scoring results of each defense mechanism are optimized.

[0118] Multi-layer neural network model:

[0119] In the scoring model, a multi-layer neural network (MLP) is used to process the feature vector matrix, the input layer is the network defense feature, the middle layer is multiple hidden layers, the activation function is ReLU, the output layer is the scoring result, and the specific neural network is:

[0120] y = σ(WX + b)

[0121] Where σ is the activation function, W is the weight matrix, X is the input feature vector, and b is the bias term. Through multiple iterations of training, the model parameters are adjusted to obtain the optimal defense mechanism score.

[0122] Through these steps and algorithms, accurate evaluation of network security defense mechanisms can be achieved, and practical optimization suggestions for improving defense are provided.

[0123] The present application can be widely applied to enterprise networks, cloud computing environments, Internet of Things and edge computing, and is particularly suitable for evaluating and optimizing multi-level defense systems. By comprehensively analyzing and scoring the feature information of each defense mechanism, weak links in defense can be quickly identified, and optimization suggestions can be provided, thereby helping enterprises improve their network security protection capabilities.

[0124] In addition, the dynamic situation assessment function of the present application enables network administrators to monitor the network security state in real time and quickly take countermeasures when attacks occur, greatly improving the flexibility and response capability of network defense, which is of great significance for defending complex attacks such as APT (Advanced Persistent Threat) and DDoS attacks.

[0125] The present application has the following characteristics:

[0126] Comprehensiveness: considers multiple network defense mechanisms and can evaluate in complex multi-level network environments;

[0127] Objectivity: through an optimized multi-index evaluation model, objective and quantitative evaluation results can be provided;

[0128] Practicality: based on the evaluation results, specific optimization suggestions are generated, which helps to improve the network defense mechanism and improve the overall security.

[0129] Example two

[0130] The network security defense mechanism evaluation system described in the present application comprises:

[0131] An analysis module for analyzing various defense mechanisms in the current network system and extracting feature information of the defense mechanisms of the current network system;

[0132] An evaluation module is configured to input the feature information of the defense mechanism of the current network system into the trained defense mechanism scoring model to obtain an evaluation result of the defense mechanism of the current network system.

[0133] The network security defense mechanism evaluation system further has the following improvements:

[0134] Further, the loss function of the defense mechanism scoring model in the training process is as follows:

[0135]

[0136] wherein S i is a real score, is a predicted score, and n is the number of defense mechanisms.

[0137] The division of the modules in the embodiments of the present application is illustrative, and is merely a logical function division. In actual implementation, another division manner can be used. In addition, the function modules in each embodiment of the present application can be integrated in one processor, or can be physically separated, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software function module.

[0138] Embodiment three

[0139] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the network security defense mechanism evaluation method are implemented, for example, including: analyzing each type of defense mechanism in a current network system, and extracting feature information of the defense mechanism of the current network system; inputting the feature information of the defense mechanism of the current network system into a trained defense mechanism scoring model to obtain an evaluation result of the defense mechanism of the current network system. The memory can include a memory, for example, a high-speed random access memory, and can also include a non-volatile memory, for example, at least one disk memory. The processor, network interface, and memory are connected to each other through an internal bus, which can be an industry standard architecture bus, a peripheral component interconnect standard bus, an extended industry standard structure bus, etc. The bus can be divided into an address bus, a data bus, and a control bus. The memory is used to store programs, and specifically, the programs can include program codes, and the program codes include computer operation instructions. The memory can include a memory and a non-volatile memory, and provides instructions and data to the processor.

[0140] Embodiment four

[0141] A computer readable storage medium stores a computer program, the computer program is executed by a processor to implement steps of the network security defense mechanism evaluation method, for example, comprising: analyzing each type of defense mechanism in a current network system, and extracting feature information of the defense mechanism of the current network system; inputting the feature information of the defense mechanism of the current network system into a trained defense mechanism scoring model, and obtaining an evaluation result of the defense mechanism of the current network system. Specifically, the computer readable storage medium includes but is not limited to, for example, volatile memory and / or non-volatile memory. The volatile memory can include random access memory (RAM) and / or cache memory, etc. The non-volatile memory can include read-only memory (ROM), hard disk, flash memory, optical disc, magnetic disc, etc.

[0142] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0143] The present application is described with reference to flowcharts and / or block diagrams according to the methods, devices (systems), and computer program products of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that performs the functions specified in one or more flows and / or blocks.

[0144] These computer program instructions can also be stored in a computer readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including instruction apparatus, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that performs the functions specified in one or more flows and / or blocks.

[0145] These computer program instructions can also be loaded into a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 one or more flowcharts and / or blocks

[0146] Finally, it should be noted that the above-mentioned embodiments are merely used to illustrate the technical solutions of the present application, rather than limit the technical solutions of the present application. Although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that the specific embodiments of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.

Claims

1. A method for evaluating network security defense mechanisms, the method comprising: The method comprises the following steps: analyzing various defense mechanisms in a current network system and extracting feature information of the defense mechanisms in the current network system; inputting the feature information of the defense mechanisms in the current network system into a trained defense mechanism scoring model to obtain an evaluation result of the defense mechanisms in the current network system; the feature information of the defense mechanisms in the current network system includes but is not limited to configuration parameters, actual operating conditions, execution effects of policies, device redundancy, and traffic monitoring data of the defense mechanisms; the defense mechanism scoring model is trained based on a multi-layer neural network model; a loss function of the defense mechanism scoring model in the training process is: wherein, is the true score, is the predicted score, n is the number of defense mechanisms; the defense mechanism scoring model is trained based on an adaptive weighting algorithm, wherein the weights of the defense mechanisms in the defense mechanism scoring model are updated through the adaptive weighting algorithm, that is: wherein, is the learning rate, and L is the loss function.

2. The network security defense mechanism evaluation method of claim 1, wherein, the various defense mechanisms in the current network system include but are not limited to firewalls, IDSs, ACLs, and endpoint security policies.

3. A cyber-security defense mechanism evaluation system, characterized by, The method comprises the following steps: a analyzing module is configured to analyze various defense mechanisms in a current network system and extract feature information of the defense mechanisms in the current network system; an evaluation module is configured to input the feature information of the defense mechanisms in the current network system into a trained defense mechanism scoring model to obtain an evaluation result of the defense mechanisms in the current network system; the feature information of the defense mechanisms in the current network system includes but is not limited to configuration parameters, actual operating conditions, execution effects of policies, device redundancy, and traffic monitoring data of the defense mechanisms; the defense mechanism scoring model is trained based on a multi-layer neural network model; a loss function of the defense mechanism scoring model in the training process is: wherein, is the true score, is the predicted score, n is the number of defense mechanisms; the defense mechanism scoring model is trained based on an adaptive weighting algorithm, wherein the weights of the defense mechanisms in the defense mechanism scoring model are updated through the adaptive weighting algorithm, that is: wherein, is the learning rate, and L is the loss function.

4. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, the processor executes the computer program to realize the steps of the network security defense mechanism evaluation method according to any one of claims 1-2.

5. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 4. The computer program is executed by the processor to realize the steps of the network security defense mechanism evaluation method according to any one of claims 1-2.

Citation Information

Patent Citations

  • Quantitative evaluation method for network security defense system, and network security evaluation platform

    CN109660561A

  • Security defense method and network security equipment

    CN114710331A