Methods, apparatus, systems, equipment, media and products for secure atomic capability orchestration
By extracting and orchestrating features of secure atomic capabilities, a multi-dimensional feature tag library is constructed. Secure atomic capabilities are then selected and orchestrated according to user intent strategies. This solves the problem in existing technologies where users need to have a deep understanding of secure capabilities, and enables effective responses to complex and ever-changing security risks.
Patent Information
- Application Number
- CN202411308644.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2044-09-19
AI Technical Summary
Existing security capability orchestration methods require users to have a deep understanding of security capabilities, making it difficult to cope with complex and ever-changing cybersecurity threats, and single security products are unable to quickly respond to high-level cyberattacks.
By extracting features from secure atomic capabilities, a multi-dimensional feature tag library is constructed. Based on the user's intent strategy, secure atomic capabilities are selected and orchestrated in the feature tag library to generate an orchestration strategy, without requiring the user to have in-depth knowledge of the secure capabilities.
It enables effective responses to complex and ever-changing security risks without requiring users to have in-depth knowledge of security capabilities, thereby improving the synergy and targeting of security protection.
Smart Images

Figure CN119323022B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a secure atomic capability orchestration method, device, system, equipment, medium and product. BACKGROUND
[0002] With the advent of the cloud network era, virtualization technology enables network architecture to change from a solid closed state to a dynamic open state, and network space boundaries are gradually blurred. At the same time, with the continuous improvement of domestic network security compliance requirements and the acceleration of digital transformation, the application range of information systems is wider, the complexity of systems and the interconnectivity between systems are increasing, and the network security environment faced by enterprises is more complex. At present, various security vendors still provide services in the form of security capabilities, such as security products that simply stack multiple security capabilities to provide security protection against complex network attacks.
[0003] However, in recent years, the network security situation has become increasingly severe, and network attacks have developed from primitive viruses and worm attacks to more extensive attack threats such as targeted malware, advanced persistent threats (APT), coordinated attacks, and the attack means has become multi-level and intelligent. With the high correlation and interdependence of networks, the threat sources are constantly changing, and advanced network attacks are frequent, and a single security product is difficult to quickly respond to the increasingly severe domestic and foreign network security threats, and simply stacked multi-field security products cannot effectively protect against targeted and more intelligent network threats. In order to cope with the above complex and variable security threats, security capability coordination and orchestration is particularly important, but the existing security capability orchestration method requires users to have a deep understanding of various types of security capabilities, and the technical background of the user is required to be high, which greatly hinders the security capability collaborative protection process and makes it difficult to cope with the above complex and variable security risks. SUMMARY
[0004] In view of the problems existing in the prior art, the embodiments of the present application provide a secure atomic capability orchestration method, device, system, equipment, medium and product, which do not require users to have a deep understanding of security capabilities and secure atomic capabilities, and can effectively cope with complex and variable security risks.
[0005] In a first aspect, the embodiments of the present application provide a secure atomic capability orchestration method, comprising:
[0006] performing feature extraction on the secure atomic capabilities to obtain multi-dimensional feature labels of the corresponding secure atomic capabilities, and constructing a feature label library;
[0007] performing intent handling on the security requirements input by the user to obtain a user intent strategy;
[0008] According to the user intention strategy, the safety atomic capability meeting the safety demand of the user is screened out from the feature label library;
[0009] The screened safety atomic capability is arranged to obtain a safety atomic capability arrangement strategy.
[0010] As an improvement of the above scheme, the multi-dimensional feature label comprises: a first-dimensional feature label related to a core function instruction of the safety atomic capability, a second-dimensional feature label related to a strategy template of the safety atomic capability, a third-dimensional feature label related to a category of an IPDRR safety framework to which the safety atomic capability belongs, a fourth-dimensional feature label related to a deployment position of the safety atomic capability, a fifth-dimensional feature label related to a deployment mode of the safety atomic capability, and a sixth-dimensional feature label related to a traffic type of the safety atomic capability.
[0011] As an improvement of the above scheme, the feature extraction of the safety atomic capability obtains a multi-dimensional feature label of the corresponding safety atomic capability, comprising:
[0012] According to the core function description of the safety atomic capability, a core function instruction is extracted as a first-dimensional feature label of the corresponding safety atomic capability;
[0013] A strategy template of the safety atomic capability is extracted from a safety atomic capability strategy management module as a second-dimensional feature label of the corresponding safety atomic capability;
[0014] According to a pre-defined safety atomic capability description and classification, a category of an IPDRR safety framework to which the safety atomic capability belongs is determined, and the category of the IPDRR safety framework to which the safety atomic capability belongs is taken as a third-dimensional feature label;
[0015] All available deployment positions of the safety atomic capability are extracted as a fourth-dimensional feature label of the corresponding safety atomic capability;
[0016] All available deployment modes of the safety atomic capability are extracted as a fifth-dimensional feature label of the corresponding safety atomic capability;
[0017] A traffic type to which the safety atomic capability belongs is extracted as a sixth-dimensional feature label of the corresponding safety atomic capability; wherein, the traffic type comprises a traffic type and a non-traffic type.
[0018] As an improvement of the above scheme, the screening of the safety atomic capability meeting the safety demand of the user from the feature label library according to the user intention strategy comprises:
[0019] According to the pre-set feature tag priority, the user intention strategy is compared with the multi-dimensional feature tags in the feature tag library to hierarchically screen the safe atomic capabilities, and safe atomic capabilities meeting the user intention strategy are obtained.
[0020] The feature tag library comprises multi-dimensional feature tags of the safe atomic capabilities.
[0021] As an improvement of the above scheme, the feature tag priority comprises: the first-dimensional feature tag is high priority, the third-dimensional feature tag and the sixth-dimensional feature tag are medium priority, and the second-dimensional feature tag, the fourth-dimensional feature tag and the fifth-dimensional feature tag are low priority.
[0022] As an improvement of the above scheme, according to the pre-set feature tag priority, the user intention strategy is compared with the multi-dimensional feature tags in the feature tag library to hierarchically screen the safe atomic capabilities, and safe atomic capabilities meeting the user intention strategy are obtained, comprising:
[0023] Taking the information related to the high-priority feature tag in the user intention strategy as a first keyword, it is judged whether there is a safe atomic capability corresponding to the first-dimensional feature tag same as or similar to the first keyword, and a first safe atomic capability list is generated according to the safe atomic capability corresponding to the first-dimensional feature tag similar to the first keyword.
[0024] Taking the information related to the medium-priority feature tag in the user intention strategy as a second keyword, the safe atomic capabilities in the first safe atomic capability list are screened to obtain safe atomic capabilities meeting the user intention strategy.
[0025] According to the information related to the low-priority feature tag in the user intention strategy, the safe atomic capability corresponding to the first-dimensional feature tag same as the first keyword is screened to obtain safe atomic capabilities meeting the user intention strategy.
[0026] As an improvement of the above scheme, taking the information related to the high-priority feature tag in the user intention strategy as a first keyword, it is judged whether there is a safe atomic capability corresponding to the first-dimensional feature tag same as or similar to the first keyword, and a first safe atomic capability list is generated according to the safe atomic capability corresponding to the first-dimensional feature tag similar to the first keyword, the first safe atomic capability list is generated, comprising:
[0027] Taking the information related to the high-priority feature tag in the user intention strategy as a first keyword, the first-dimensional feature tags in the feature tag library are searched.
[0028] In the case where the first dimension feature label identical to the first keyword exists, the security atomic capability corresponding to the first dimension feature label identical to the first keyword is extracted;
[0029] In the case where the first dimension feature label identical to the first keyword does not exist but the first dimension feature label similar to the first keyword exists, the security atomic capability corresponding to the first dimension feature label with the highest similarity to the first keyword is extracted to generate the first security atomic capability list.
[0030] As an improvement of the above scheme, the security atomic capability corresponding to the first dimension feature label identical to the first keyword is screened according to the information about the feature label of low priority in the user intention strategy to obtain the security atomic capability conforming to the user intention strategy, including:
[0031] It is judged whether the security atomic capability corresponding to the first dimension feature label identical to the first keyword conforms to the strategy template, deployment position and deployment mode indicated by the user intention strategy;
[0032] If yes, the security atomic capability corresponding to the first dimension feature label identical to the first keyword is extracted as the security atomic capability conforming to the user intention strategy;
[0033] If no, the security atomic capability corresponding to the first dimension feature label with the highest similarity to the first keyword is extracted as the security atomic capability conforming to the user intention strategy.
[0034] As an improvement of the above scheme, the security atomic capability in the first security atomic capability list is screened with the information about the feature label of medium priority in the user intention strategy as the second keyword to obtain the security atomic capability conforming to the user intention strategy, including:
[0035] A first feature label sub-library is constructed according to the multi-dimensional feature labels of the security atomic capability in the first security atomic capability list;
[0036] The third dimension feature label and the sixth dimension feature label in the first feature label sub-library are searched with the information about the feature label of medium priority in the user intention strategy as the second keyword;
[0037] In the case where the third dimension feature label and the sixth dimension feature label identical to the second keyword exist, the security atomic capability corresponding to the third dimension feature label and the sixth dimension feature label identical to the second keyword is extracted as the security atomic capability conforming to the user intention strategy;
[0038] In the case where there is no third-dimension feature label and sixth-dimension feature label identical to the second keyword, but there is a third-dimension feature label and sixth-dimension feature label similar to the second keyword, extract the safe atomic capabilities with the highest similarity to the second keyword, and generate the second safe atomic capability list;
[0039] In the case where there is no third-dimension feature label and sixth-dimension feature label identical or similar to the second keyword, the first safe atomic capability list is taken as the second safe atomic capability list;
[0040] According to the information related to the low-priority feature label in the user intent strategy, the safe atomic capabilities in the second safe atomic capability list are screened to obtain safe atomic capabilities that meet the user intent strategy.
[0041] As an improvement of the above scheme, the screening of the safe atomic capabilities in the second safe atomic capability list according to the information related to the low-priority feature label in the user intent strategy to obtain safe atomic capabilities that meet the user intent strategy comprises:
[0042] According to the multi-dimension feature labels of the safe atomic capabilities in the second safe atomic capability list, a second feature label sub-library is constructed;
[0043] The second-dimension feature label in the second feature label sub-library is searched with a third keyword indicating a security policy in the user intent strategy;
[0044] In the case where there is a second-dimension feature label identical to the third keyword, it is determined whether the corresponding safe atomic capability meets the deployment location and deployment mode indicated by the user intent strategy;
[0045] If yes, the safe atomic capability corresponding to the second-dimension feature label identical to the third keyword is extracted as the safe atomic capability that meets the user intent strategy;
[0046] If no, the second-dimension feature label in the second feature label sub-library is searched again;
[0047] In the case where there is no second-dimension feature label identical to the third keyword, but there is a second-dimension feature label similar to the third keyword, the safe atomic capability corresponding to the second-dimension feature label similar to the third keyword is extracted, and the extracted safe atomic capabilities are sorted in descending order of similarity to generate a third safe atomic capability list;
[0048] According to the third security atomic capability list, security atomic capabilities meeting the user intention strategy are screened out.
[0049] As an improvement of the above scheme, according to the third security atomic capability list, security atomic capabilities meeting the user intention strategy are screened out, including:
[0050] According to the multi-dimensional feature labels of the security atomic capabilities in the third security atomic capability list, a third feature label sub-library is constructed.
[0051] According to the order of the security atomic capabilities in the third security atomic capability list, the fourth-dimensional feature labels and the fifth-dimensional feature labels in the third feature label sub-library are traversed, and it is judged whether the corresponding security atomic capabilities meet the deployment position and the deployment mode indicated by the user intention strategy.
[0052] In the case that the security atomic capabilities meeting the deployment position and the deployment mode indicated by the user intention strategy are found, the corresponding security atomic capabilities are extracted as the security atomic capabilities meeting the user intention strategy.
[0053] In the case that the security atomic capabilities meeting the deployment position and the deployment mode indicated by the user intention strategy are not found, prompt information indicating that the user adjusts the security demand intention is triggered.
[0054] As an improvement of the above scheme, the method further includes:
[0055] The security demand is subjected to word segmentation processing to obtain an intention keyword.
[0056] The intention keyword is matched and expanded with an annotated keyword in an intention corpus to generate a user intention.
[0057] The user intention is subjected to format processing to obtain the user intention strategy.
[0058] As an improvement of the above scheme, the method further includes:
[0059] According to the security atomic capability arrangement strategy, corresponding security atomic capabilities are called from a security atomic capability resource pool to perform security protection.
[0060] In a second aspect, an embodiment of the present application provides a security atomic capability arrangement device, including:
[0061] A feature extraction module is configured to extract features of security atomic capabilities to obtain multi-dimensional feature labels of the corresponding security atomic capabilities, and construct a feature label library.
[0062] an intention handling module, configured to handle a security requirement input by a user to obtain a user intention strategy;
[0063] a capability screening module, configured to screen a security atomic capability meeting the security requirement of the user from the feature label library according to the user intention strategy;
[0064] a capability arrangement module, configured to arrange the screened security atomic capability to obtain a security atomic capability arrangement strategy.
[0065] In a third aspect, an embodiment of the present application provides a security atomic capability arrangement system, comprising an intention handling layer, an atomic capability arrangement layer and a capability execution layer;
[0066] The intention handling layer is configured to handle a security requirement input by a user to obtain a user intention strategy, and input the user intention strategy to the atomic capability arrangement layer.
[0067] The atomic capability arrangement layer is configured to extract features of a security atomic capability to obtain multi-dimensional feature labels of the corresponding security atomic capability, and construct a feature label library; screen a security atomic capability meeting the security requirement of the user from the feature label library according to the user intention strategy input by the intention handling layer; arrange the screened security atomic capability to obtain a security atomic capability arrangement strategy, and input the security atomic capability arrangement strategy to the capability execution layer.
[0068] The capability execution layer is configured to call a corresponding security atomic capability from a security atomic capability resource pool to perform security protection according to the security atomic capability arrangement strategy input by the atomic capability arrangement layer.
[0069] In a fourth aspect, an embodiment of the present application provides a security atomic capability arrangement device, comprising a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements the security atomic capability arrangement method in any one of the first aspect when executing the computer program.
[0070] In a fifth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, wherein the computer readable storage medium controls a device where the computer readable storage medium is located to execute the security atomic capability arrangement method in any one of the first aspect when the computer program runs.
[0071] In a sixth aspect, an embodiment of the present application provides a computer program product, comprising a computer program / instruction, which implements the security atomic capability arrangement method in any one of the first aspect when executed by a processor.
[0072] Compared with the prior art, the safety atomic capability arrangement method, device, system, equipment, medium and product provided by the embodiment of the application obtain a multi-dimensional feature label of a corresponding safety atomic capability through feature extraction on the safety atomic capability, and construct a feature label library; then dispose the safety requirement input by a user to obtain a user intention strategy; then filter out the safety atomic capability meeting the safety requirement of the user from the feature label library according to the user intention strategy, and arrange the filtered safety atomic capability to obtain a safety atomic capability arrangement strategy, so that the user does not need to have a deep understanding of the safety capability and the safety atomic capability, and only needs to clearly express the safety requirement, and the safety requirement intention of the user can be translated into the user intention strategy, and the arrangement of the safety atomic capability can be completed in combination with the multi-dimensional feature label of the safety atomic capability, and then the safety atomic capability can be effectively arranged to cope with complex and changeable safety risks. BRIEF DESCRIPTION OF DRAWINGS
[0073] In order to more clearly illustrate the technical solutions of the present application, the drawings used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.
[0074] Figure 1 is a flowchart of a safety atomic capability arrangement method provided by the embodiment of the present application;
[0075] Figure 2 is another flowchart of the safety atomic capability arrangement method provided by the embodiment of the present application;
[0076] Figure 3 is a schematic diagram of the multi-dimensional feature label content format of the safety atomic capability provided by the embodiment of the present application;
[0077] Figure 4 is a schematic diagram of the multi-dimensional feature label content of the safety atomic capability provided by the embodiment of the present application;
[0078] Figure 5 is a schematic diagram of the multi-dimensional feature label corresponding to the system vulnerability identification example provided by the embodiment of the present application;
[0079] Figure 6 is a structural block diagram of a safety atomic capability arrangement device provided by the embodiment of the present application;
[0080] Figure 7 is a structural block diagram of a safety atomic capability arrangement system provided by the embodiment of the present application;
[0081] Figure 8is a structural block diagram of a safe atomic capability arrangement device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0082] The technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0083] It can be understood that various numbers involved in the embodiments of the present application are only used for differentiation for convenience of description, and do not limit the scope of the present application. The size of the serial number of each process does not mean the execution order, and the execution order of each process should be determined according to its function and inherent logic.
[0084] In the embodiments of the present application, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. The terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. The element defined by the statement "including" without more limitation does not exclude the presence of additional identical elements in the process, method, article or device including the element. The term "a plurality of or several" means two or more.
[0085] Referring to Figure 1 , Figure 1 is a flowchart of a safe atomic capability arrangement method provided by an embodiment of the present application. The safe atomic capability arrangement method specifically includes:
[0086] S11: performing feature extraction on a safe atomic capability to obtain a multi-dimensional feature label of the corresponding safe atomic capability, and constructing a feature label library;
[0087] S12: performing intention disposal on a safety requirement input by a user to obtain a user intention strategy;
[0088] S13: screening out, according to the user intention strategy, a safe atomic capability meeting the safety requirement of the user from the feature label library;
[0089] S14: arranging the screened safe atomic capability to obtain a safe atomic capability arrangement strategy.
[0090] It should be noted that the safe atomic capability arrangement method described in the embodiments of the present application can be implemented by a server, a computer, etc., and the detailed processes of steps S11-S12 can be referred to Figure 2 , Figure 2 is another flowchart of the safe atomic capability arrangement method provided by the embodiments of the present application. In the embodiments of the present application, the execution process of the safe atomic capability arrangement method can be divided into multiple layers of processing, such as an intention handling layer and an atomic capability arrangement layer. In the intention handling layer, the safe requirements input by the user are handled in terms of intention through natural language processing, etc., to obtain a user intention strategy, and the user intention strategy is issued to the atomic capability arrangement layer. In the atomic capability arrangement layer, it is mainly divided into three parts. One is to abstract and extract the multi-dimensional feature labels of the safe atomic capabilities to construct a feature label library based on the multi-dimensional feature labels. The second is to select the safe atomic capabilities corresponding to the multi-dimensional feature labels that meet the user's safety intention from the feature label library according to the user's intention strategy. The third is to give an arrangement scheme corresponding to the selected safe atomic capabilities based on an atomic capability arrangement template, i.e., a safe atomic capability arrangement strategy.
[0091] The safe atomic capability arrangement strategy is then issued to the capability execution layer, and the following processes are further executed in the capability execution layer:
[0092] According to the safe atomic capability arrangement strategy, the corresponding safe atomic capabilities are called from the safe atomic capability resource pool to execute the security protection, and the capability execution result is returned.
[0093] The safe atomic capability arrangement strategy includes the sequence of safe atomic capability scheduling, a data flow scheme, etc.
[0094] Specifically, the intention handling of the safe requirements input by the user to obtain the user intention strategy includes:
[0095] The safe requirements are processed by word segmentation to obtain intention keywords;
[0096] The intention keywords are matched and expanded with the labeled keywords in the intention corpus to generate a user intention;
[0097] The user intention is processed by formatting to obtain the user intention strategy.
[0098] Exemplarily, the user inputs the security requirement to the intent handling layer for a specified application scenario through a graphical interface or natural language or formatted language, such as a security requirement description expected to be achieved by the user, which usually includes a target asset address, a security protection means, a security protection period, and the like. The intent handling layer includes an intent decomposition module, an intent matching module, an intent formatting module, and an intent corpus in which standard keywords related to security business operations, security capabilities, security policies, and the like are stored. The specific intent handling process is as follows:
[0099] The intent decomposition module is configured to perform word segmentation on the security requirement input by the user to extract intent keywords. For example, the security requirement input by the user in natural language is: “perform a system vulnerability full-scan task on xxx.xxx.xxx at 2:00 every Monday morning”, and the intent keywords of the security requirement after word segmentation are: “every week”, “2:00”, “xxx.xxx.xxx”, “system”, “vulnerability”, and “full-scan”.
[0100] The intent matching module is configured to match the extracted intent keywords with the standard keywords in the intent corpus, to standardize the intent keywords input by the user through the matched standard keywords, and to automatically expand the key information that is not included in the security requirement input by the user but must be indicated. For example, the intent knowledge graph of the standard keywords is constructed, and then the intent keywords of the security requirement are mapped and matched with the intent knowledge graph, to convert the intent keywords of the security requirement input by the user into standard keywords, and to supplement the key information that is not completely expressed by the user in the intent keywords, such as the capability feature information that the user may need and the strategy that should be adopted for the capability. For example, the intent keywords obtained by word segmentation in the above example are matched with the standard keywords in the intent corpus, and are identified as “system”, “vulnerability”, “xxx.xxx.xxx”, “once a week”, “2:00”, and “full-scan”, and the key information to be supplemented is “identification” and “I”, to obtain the complete intent of the user.
[0101] The intent formatting module is configured to translate the matched standard keywords and the expanded key information into a formatted language such as XML, to generate a formatted user intent strategy, and to deliver the formatted user intent strategy to the atomic capability orchestration layer.
[0102] The multi-dimensional feature label can be a six-dimensional feature label, including but not limited to: a first-dimensional feature label related to a core function instruction of the secure atomic capability, a second-dimensional feature label related to a policy template of the secure atomic capability, a third-dimensional feature label related to a belonging IPDRR security framework category of the secure atomic capability, a fourth-dimensional feature label related to a deployment position of the secure atomic capability, a fifth-dimensional feature label related to a deployment mode of the secure atomic capability, a sixth-dimensional feature label related to a traffic type of the secure atomic capability, and the like.
[0103] Specifically, the feature extraction of the secure atomic capability obtains a multi-dimensional feature label of the corresponding secure atomic capability, including:
[0104] According to the core function description of the secure atomic capability, a core function instruction is extracted as a first-dimensional feature label of the corresponding secure atomic capability;
[0105] The policy template of the secure atomic capability is extracted from a secure atomic capability policy management module as a second-dimensional feature label of the corresponding secure atomic capability;
[0106] According to a pre-defined secure atomic capability description and classification, a belonging IPDRR security framework category of the secure atomic capability is determined, and the belonging IPDRR security framework category of the secure atomic capability is taken as a third-dimensional feature label;
[0107] All available deployment positions of the secure atomic capability are extracted as a fourth-dimensional feature label of the corresponding secure atomic capability;
[0108] All available deployment modes of the secure atomic capability are extracted as a fifth-dimensional feature label of the corresponding secure atomic capability;
[0109] The traffic type to which the secure atomic capability belongs is extracted as a sixth-dimensional feature label of the corresponding secure atomic capability; wherein the traffic type includes a traffic type and a non-traffic type.
[0110] Exemplarily, the atomic capability orchestration layer includes a feature label extraction module, a capability screening module, an atomic capability orchestration module, a secure atomic capability set, a feature label library, and a secure atomic capability orchestration template: wherein the feature label extraction module is used for analyzing secure atomic capability features, abstracting a plurality of dimensional feature labels of the secure atomic capability from a function description of the secure atomic capability, and extracting multi-dimensional feature labels of each secure atomic capability to form a feature label library of the secure atomic capability; the feature label library is used for storing multi-dimensional feature labels of each secure atomic capability.
[0111] Embodiments of the present application consider that each security atomic capability has its own characteristics in core function instructions, deployment location, deployment mode, whether it is a traffic type, a policy template, and an IPDRR security framework category to which the security atomic capability belongs. The multi-dimensional feature labels of the security atomic capability are extracted by the above multiple dimensions. The multi-dimensional feature label extraction method of each dimension is described below.
[0112] (1) The first dimension feature label extraction related to the core function instructions of the security atomic capability: the core function instructions, input, and output of the security atomic capability are extracted by referring to the core function description of the security atomic capability. Take active identification and passive identification of the security atomic capability as an example:
[0113] The core function description of active identification is to detect and identify hardware, software, data assets, etc. in the network through automatic scanning means.
[0114] The core function instructions are extracted as: asset, scan, and identify.
[0115] The input is: scan range.
[0116] The output is: asset information.
[0117] The core function description of passive identification is to analyze the asset information by analyzing the traffic of link, network, transmission, and application layer through DPI technology.
[0118] The core function instructions are extracted as: traffic, analysis, and identification.
[0119] The input is: identification strategy.
[0120] The output is: asset information.
[0121] The core function instructions of active identification and passive identification can clearly distinguish the core functions of the two security atomic capabilities, which can be used as the first dimension feature label of the security atomic capability.
[0122] (2) The second dimension feature label extraction related to the policy template of the security atomic capability: the policy template of the security atomic capability can be extracted from the security atomic capability policy management module, which lists the security services that the security atomic capability can provide. Take the system vulnerability identification of the security atomic capability as an example:
[0123] The policy template of system vulnerability identification can be divided into high-risk system vulnerability, medium-high-risk system vulnerability, complete system vulnerability scanning, and regular system vulnerability scanning.
[0124] (3) The third dimension feature label extraction related to the IPDRR security framework category to which the security atomic capability belongs: the IPDRR security framework is identify, protect, detect, response, and recover. The IPDRR security framework category to which the security atomic capability belongs can refer to the existing CCSA industry standard, such as the description of the description and classification of the security atomic capability in the network security product interoperability.
[0125] (4) The fourth dimension feature label extraction related to the deployment location of the security atomic capability: the deployment location of the security atomic capability can be divided into near device end deployment, branch deployment, edge deployment, and center deployment. In this dimension, all reasonable deployment locations of the security atomic capability will be listed.
[0126] (5) The fifth dimension feature label extraction related to the deployment mode of the security atomic capability: the deployment mode of the security atomic capability can be divided into hardware device deployment, virtual deployment, and micro-service deployment. In this dimension, the reasonable deployment mode of the security atomic capability will be listed.
[0127] (6) The sixth dimension feature label extraction related to the traffic type (such as whether the traffic type) to which the security atomic capability belongs: the traffic type security atomic capability, the processing object of the capability is traffic. The non-traffic type security atomic capability, the processing object of the capability is asset, that is, the target asset is scanned, monitored, or audited to complete the security processing.
[0128] It should be noted that the security atomic capability in the pre-constructed security atomic capability set can be extracted by multi-dimensional feature label extraction; the security atomic capability set lists a set of security atomic capabilities that can provide security services. Through the above multi-dimensional feature label extraction, the multi-dimensional feature label content of the security atomic capability can be obtained as shown in Figure 3 Figure 3 The first dimension feature label, the second dimension feature label,..., and the sixth dimension feature label correspond to the first dimension feature label, the second dimension feature label,..., and the sixth dimension feature label, respectively; and the label content is the specific description information of the corresponding dimension feature label. The label content can include multiple label information as shown in Figure 4
[0129] Taking the security atomic capability, system vulnerability identification example as an example, the multi-dimensional feature label extraction of the security atomic capability is as shown in Figure 5 The security atomic capability is shown. The multi-dimensional feature label meaning of the system vulnerability identification is: the system vulnerability identification core function instruction is "system + vulnerability + identification", the strategy template is high-risk system vulnerability, medium and high-risk system vulnerability, complete system vulnerability scanning, and regular system vulnerability scanning. The deployment location is near the device end, branch deployment, edge deployment, and center deployment. The deployment mode supports hardware device deployment, virtual deployment, and micro-service deployment. The IPDRR security framework category is an identification type security atomic capability, and the traffic type is a non-flow type security atomic capability.
[0130] Specifically, the security atomic capability meeting the user's security demand is screened out from the feature label library according to the user's intention strategy, including:
[0131] According to the pre-set feature label priority, the user's intention strategy is compared with the multi-dimensional feature label in the feature label library, and the security atomic capability meeting the user's intention strategy is screened out.
[0132] The feature label library includes multi-dimensional feature labels of each security atomic capability.
[0133] The feature label priority includes: the first dimension feature label is high priority, the third dimension feature label and the sixth dimension feature label are medium priority, and the second dimension feature label, the fourth dimension feature label and the fifth dimension feature label are low priority.
[0134] Further, the security atomic capability meeting the user's intention strategy is obtained by comparing the user's intention strategy with the multi-dimensional feature label in the feature label library according to the pre-set feature label priority, including:
[0135] The information related to the high-priority feature label in the user's intention strategy is taken as the first keyword, it is judged whether there is a security atomic capability corresponding to the first dimension feature label same as or similar to the first keyword, and a first security atomic capability list is generated according to the security atomic capability corresponding to the first dimension feature label similar to the first keyword.
[0136] The information related to the medium-priority feature label in the user's intention strategy is taken as the second keyword, the security atomic capability in the first security atomic capability list is screened, and the security atomic capability meeting the user's intention strategy is obtained.
[0137] According to the information related to the low-priority feature label in the user's intention strategy, the security atomic capability corresponding to the first dimension feature label same as the first keyword is screened, and the security atomic capability meeting the user's intention strategy is obtained.
[0138] Further, the first keyword is the high-priority feature tag related information in the user intention strategy, and it is judged whether there is a safety atomic capability corresponding to the first dimension feature tag same as or similar to the first keyword. The safety atomic capability corresponding to the first dimension feature tag same as the first keyword is generated to form a first safety atomic capability list, which includes:
[0139] The first dimension feature tag in the feature tag library is searched with the first keyword being the high-priority feature tag related information in the user intention strategy.
[0140] In the case that there is a first dimension feature tag same as the first keyword, the safety atomic capability corresponding to the first dimension feature tag same as the first keyword is extracted.
[0141] In the case that there is no first dimension feature tag same as the first keyword, but there is a first dimension feature tag similar to the first keyword, the safety atomic capabilities corresponding to the first dimension feature tags with the highest similarity to the first keyword are extracted to form the first safety atomic capability list.
[0142] Specifically, the safety atomic capability corresponding to the first dimension feature tag same as the first keyword is screened according to the low-priority feature tag related information in the user intention strategy to obtain the safety atomic capability conforming to the user intention strategy, which includes:
[0143] It is judged whether the safety atomic capability corresponding to the first dimension feature tag same as the first keyword conforms to the strategy template, deployment position and deployment mode indicated by the user intention strategy.
[0144] If yes, the safety atomic capability corresponding to the first dimension feature tag same as the first keyword is extracted as the safety atomic capability conforming to the user intention strategy.
[0145] If no, the safety atomic capability corresponding to the first dimension feature tag with the highest similarity to the first keyword is extracted as the safety atomic capability conforming to the user intention strategy.
[0146] Further, the second keyword is the medium-priority feature tag related information in the user intention strategy, and the safety atomic capability in the first safety atomic capability list is screened to obtain the safety atomic capability conforming to the user intention strategy, which includes:
[0147] A first feature tag sub-library is constructed according to the multi-dimensional feature tags of the safety atomic capabilities in the first safety atomic capability list.
[0148] Taking the information related to the feature label of the medium priority in the user intention strategy as a second keyword, the third dimension feature label and the sixth dimension feature label in the first feature label sub-library are searched;
[0149] In the case where the third dimension feature label and the sixth dimension feature label same as the second keyword exist, the security atomic capability corresponding to the third dimension feature label and the sixth dimension feature label same as the second keyword is extracted as the security atomic capability meeting the user intention strategy;
[0150] In the case where the third dimension feature label and the sixth dimension feature label same as the second keyword do not exist but the third dimension feature label and the sixth dimension feature label similar to the second keyword exist, the security atomic capability with the highest similarity to the second keyword is extracted to generate the second security atomic capability list;
[0151] In the case where the third dimension feature label and the sixth dimension feature label same or similar to the second keyword do not exist, the first security atomic capability list is taken as the second security atomic capability list;
[0152] According to the information related to the feature label of the low priority in the user intention strategy, the security atomic capability in the second security atomic capability list is screened to obtain the security atomic capability meeting the user intention strategy.
[0153] Further, the screening of the security atomic capability in the second security atomic capability list according to the information related to the feature label of the low priority in the user intention strategy to obtain the security atomic capability meeting the user intention strategy comprises:
[0154] According to the multi-dimensional feature label of the security atomic capability in the second security atomic capability list, a second feature label sub-library is constructed;
[0155] Taking the security policy indicated by the user intention strategy as a third keyword, the second dimension feature label in the second feature label sub-library is searched;
[0156] In the case where the second dimension feature label same as the third keyword exists, it is determined whether the corresponding security atomic capability meets the deployment position and the deployment mode indicated by the user intention strategy;
[0157] If yes, the security atomic capability corresponding to the second dimension feature label same as the third keyword is extracted as the security atomic capability meeting the user intention strategy;
[0158] If not, re-search the second dimension feature label in the second feature label sub-library;
[0159] In the case where there is no second dimension feature label identical to the third keyword, but there is a second dimension feature label similar to the third keyword, extracting the security atomic capability corresponding to the second dimension feature label similar to the third keyword, and sorting the extracted security atomic capabilities in descending order of similarity to generate a third security atomic capability list;
[0160] According to the third security atomic capability list, screening out the security atomic capability that meets the user intent strategy.
[0161] Further, the screening of the security atomic capability that meets the user intent strategy according to the third security atomic capability list comprises:
[0162] According to the multi-dimensional feature label of the security atomic capability in the third security atomic capability list, a third feature label sub-library is constructed;
[0163] According to the sorting of the security atomic capability in the third security atomic capability list, the fourth and fifth dimension feature labels in the third feature label sub-library are traversed to determine whether the corresponding security atomic capability meets the deployment location and deployment mode indicated by the user intent strategy;
[0164] In the case where the security atomic capability that meets the deployment location and deployment mode indicated by the user intent strategy is found, the corresponding security atomic capability is extracted as the security atomic capability that meets the user intent strategy;
[0165] In the case where the security atomic capability that meets the deployment location and deployment mode indicated by the user intent strategy is not found, a prompt information indicating that the user adjusts the security demand intent is triggered.
[0166] Exemplarily, the detailed process of the security atomic capability arrangement performed by the atomic capability arrangement layer is as follows:
[0167] The user intention strategy issued by the intention handling layer is received by the capability screening module, and feature matching / comparison is performed based on the feature label library to select suitable safety atomic capabilities that meet the user safety demand conditions. First, the priority of the feature labels of the multiple dimensions of the safety atomic capabilities is set, and hierarchical (such as three layers) screening of the safety atomic capabilities is performed according to the priority of the feature labels. In the embodiment of the present application, the first dimension feature label related to the core function is set as a high-priority feature label, the third dimension feature label and the sixth dimension feature label related to the IPDRR safety framework category and whether it is a flow type are set as medium-priority feature labels, and the second dimension feature label, the fourth dimension feature label and the fifth dimension feature label related to the strategy template, the deployment location and the deployment mode are set as low-priority labels.
[0168] The multi-dimensional feature label comparison process of the safety atomic capabilities is as follows:
[0169] Step 1: In the feature label library, the corresponding core function instruction of the high-priority feature label given by the user intention strategy is used as the first keyword to complete the first layer safety atomic capability screening, and step 2 is performed.
[0170] Step 2: If there is a safety atomic capability that is completely consistent with the core function instruction of the safety atomic capability given by the user intention strategy, step 3 is performed. If no completely consistent safety atomic capability is screened out, the safety atomic capabilities with a higher similarity (such as the top N safety atomic capabilities with a higher similarity) to the core function instruction of the user intention strategy are returned to form a first safety atomic capability list, and step 4 is performed.
[0171] Step 3: It is directly compared whether the low-priority feature label corresponding to the safety atomic capability meets the demand indicated by the user intention strategy. If it meets the user intention strategy (such as meeting the feature labels of other dimensions), the safety atomic capability is directly determined to be used, and the screening process is ended. If it does not meet, the safety atomic capability with the highest similarity to the user intention strategy is returned, and the first layer screening process is ended.
[0172] Step 4: The first safety atomic capability list obtained is extracted to construct a first feature label sub-library A, and step 5 is performed.
[0173] Step 5: Based on the first feature label sub-library A, the medium-priority feature label related information given by the user intention strategy is used as the second keyword to complete the second layer safety atomic capability screening, and a second safety atomic capability list that meets the conditions is obtained, and step 6 is performed. If the medium-priority feature label related information is not given in the user intention strategy, the current first safety atomic capability list is maintained, i.e., the first safety atomic capability list is taken as the second safety atomic capability list, and step 6 is performed.
[0174] Step 6: Extract the second security atomic capability list, build the second feature tag sub-library B, and perform step 7.
[0175] Step 7: Based on the second feature tag sub-library B, in the low priority tag, taking the security atomic capability policy template as an example, if there is a security atomic capability that is completely consistent with the policy template given by the user intent policy, step 8 is performed. If not, return the security atomic capability with a higher similarity to the user intent policy (such as the top M with a higher similarity), and perform step 9.
[0176] Step 8: Compare whether the deployment location and deployment method of the security atomic capability can meet the requirements indicated by the user intent policy. If the user intent policy is met, the security atomic capability is directly determined, and the screening process is ended. If not, return to step 7 to continue searching in the second feature tag library sub-B.
[0177] Step 9: According to the order from high to low similarity to the user intent policy, build a third security atomic capability list, and build a third feature tag sub-library C, and perform step 10.
[0178] Step 10: According to the order, compare whether the deployment location and deployment method of the security atomic capability can meet the requirements of the user intent policy. If it is met, the security atomic capability is selected, and the screening process is ended. If not, continue the comparison. If there is still no security atomic capability that meets the condition, return a prompt message to the user to prompt the user to adjust the input content of the security requirement intent.
[0179] The embodiment of the present application can realize multi-layer automatic screening of security atomic capabilities through the multi-dimensional feature tags of security atomic capabilities and the corresponding feature tag priorities, and screen out the security atomic capabilities that best meet the user's intent.
[0180] For the security atomic capabilities screened out as described above, the atomic capability arrangement module combines the screened security atomic capabilities with the arrangement templates of security atomic capabilities, outputs the security atomic capability arrangement strategy that adapts to the user's application scenario for the security atomic capabilities with reference to the arrangement templates, and issues it to the capability execution layer.
[0181] In the arrangement template of the security atomic capability, common arrangement schemes between various security atomic capabilities are listed, and the security atomic capability arrangement strategy that adapts to the user's application scenario can be output for the security atomic capability output by the capability screening module with reference to the arrangement template.
[0182] Then the atomic capability arrangement module combines the screened security atomic capabilities with the security atomic capability arrangement templates, outputs the security atomic capability arrangement scheme that adapts to the user's application scenario for the security atomic capabilities with reference to the arrangement templates, and issues it to the capability execution layer.
[0183] In the capability execution layer, the security atomic capability resource pool refers to the security atomic capability orchestration strategy to call the corresponding security atomic capability, issues the corresponding security policy, and performs security protection to provide corresponding security guarantee. The capability execution result module retains the security atomic capability execution result, and feeds back to the user after all execution is completed.
[0184] Compared with the prior art, the embodiment of the application abstracts the security atomic capability features into multi-dimensional feature labels, analyzes the security intention input by the user, selects the security atomic capability that best meets the user's demand based on the multi-dimensional feature labels of the security atomic capability, and performs security atomic capability orchestration to generate a security atomic capability orchestration strategy, so that the user does not need to have a deep understanding of the security capability and the security atomic capability, and only needs to clearly express the security demand, the user's security demand intention can be translated into the user intention strategy, and the security atomic capability orchestration can be completed in combination with the multi-dimensional feature labels of the security atomic capability, and then the complex and variable security risks can be effectively coped with.
[0185] Referring to Figure 6 , Figure 6 is a structural block diagram of a security atomic capability orchestration device provided by the embodiment of the application, the security atomic capability orchestration device comprises:
[0186] The feature extraction module 11 is configured to perform feature extraction on the security atomic capability to obtain the multi-dimensional feature labels of the corresponding security atomic capability, and construct a feature label library.
[0187] The intention processing module 12 is configured to process the security demand input by the user to obtain a user intention strategy.
[0188] The capability screening module 13 is configured to screen the security atomic capability that meets the security demand of the user from the feature label library according to the user intention strategy.
[0189] The capability orchestration module 14 is configured to orchestrate the screened security atomic capability to obtain a security atomic capability orchestration strategy.
[0190] In an optional embodiment, the multi-dimensional feature labels comprise: a first dimension feature label related to the core function instruction of the security atomic capability, a second dimension feature label related to the strategy template of the security atomic capability, a third dimension feature label related to the IPDRR security framework category to which the security atomic capability belongs, a fourth dimension feature label related to the deployment position of the security atomic capability, a fifth dimension feature label related to the deployment mode of the security atomic capability, and a sixth dimension feature label related to the traffic type of the security atomic capability.
[0191] In an alternative embodiment, the feature extraction module 11 comprises:
[0192] a first dimension feature label extraction unit configured to extract a core function instruction as a first dimension feature label of the corresponding security atomic capability according to the core function description of the security atomic capability;
[0193] a second dimension feature label extraction unit configured to extract a policy template of the security atomic capability as a second dimension feature label of the corresponding security atomic capability from the security atomic capability policy management module;
[0194] a third dimension feature label extraction unit configured to determine an IPDRR security framework category to which the security atomic capability belongs according to a pre-defined security atomic capability description and classification, and take the IPDRR security framework category to which the security atomic capability belongs as a third dimension feature label;
[0195] a fourth dimension feature label extraction unit configured to extract all available deployment locations of the security atomic capability as a fourth dimension feature label of the corresponding security atomic capability;
[0196] a fifth dimension feature label extraction unit configured to extract all available deployment manners of the security atomic capability as a fifth dimension feature label of the corresponding security atomic capability;
[0197] a sixth dimension feature label extraction unit configured to extract a traffic type to which the security atomic capability belongs as a sixth dimension feature label of the corresponding security atomic capability; wherein the traffic type includes a traffic type and a non-traffic type.
[0198] In an alternative embodiment, the capability screening module 13 comprises:
[0199] a capability screening unit configured to compare the user intention policy with the multi-dimensional feature labels in the feature label library according to a pre-set feature label priority, to perform hierarchical screening on the security atomic capabilities, and obtain the security atomic capabilities that meet the user intention policy;
[0200] wherein the feature label library comprises multi-dimensional feature labels of each of the security atomic capabilities.
[0201] In an alternative embodiment, the feature label priority comprises: the first dimension feature label is a high priority, the third dimension feature label and the sixth dimension feature label are a medium priority, and the second dimension feature label, the fourth dimension feature label and the fifth dimension feature label are a low priority.
[0202] In an alternative embodiment, the capability screening unit comprises:
[0203] The first screening sub-unit is configured to take the information about the feature label of high priority in the user intention strategy as a first keyword, determine whether there is a security atomic capability corresponding to a first dimension feature label that is the same as or similar to the first keyword, and generate a first security atomic capability list according to the security atomic capability corresponding to the first dimension feature label that is similar to the first keyword;
[0204] The second screening sub-unit is configured to take the information about the feature label of medium priority in the user intention strategy as a second keyword, screen the security atomic capabilities in the first security atomic capability list, and obtain security atomic capabilities that meet the user intention strategy.
[0205] The third screening sub-unit is configured to screen the security atomic capability corresponding to the first dimension feature label that is the same as the first keyword according to the information about the feature label of low priority in the user intention strategy, and obtain the security atomic capability that meets the user intention strategy.
[0206] In an optional embodiment, the first screening sub-unit includes:
[0207] The first retrieval sub-unit is configured to take the information about the feature label of high priority in the user intention strategy as a first keyword, and retrieve a first dimension feature label in the feature label library.
[0208] The first capability extraction sub-unit is configured to extract the security atomic capability corresponding to the first dimension feature label that is the same as the first keyword in the case that there is the first dimension feature label that is the same as the first keyword.
[0209] The second capability extraction sub-unit is configured to extract the security atomic capability corresponding to the first dimension feature label that is similar to the first keyword in the case that there is no first dimension feature label that is the same as the first keyword but there is the first dimension feature label that is similar to the first keyword, and generate the first security atomic capability list.
[0210] In an optional embodiment, the third screening sub-unit includes:
[0211] The first judgment sub-unit is configured to determine whether the security atomic capability corresponding to the first dimension feature label that is the same as the first keyword meets the strategy template, the deployment position, and the deployment mode indicated by the user intention strategy.
[0212] The third capability extraction sub-unit is configured to extract the security atomic capability corresponding to the first dimension feature label that is the same as the first keyword as the security atomic capability that meets the user intention strategy if the determination result is yes.
[0213] a fourth capability extraction unit, configured to extract, if no, a security atomic capability corresponding to a first dimension feature label with the highest similarity to the first keyword as the security atomic capability conforming to the user intent strategy.
[0214] In an optional embodiment, the second screening subunit includes:
[0215] a first label sublibrary construction subunit, configured to construct a first feature label sublibrary according to the multi-dimensional feature labels of the security atomic capabilities in the first security atomic capability list;
[0216] a second retrieval subunit, configured to take the information related to the medium-priority feature label in the user intent strategy as a second keyword, and perform retrieval on the third dimension feature labels and the sixth dimension feature labels in the first feature label sublibrary;
[0217] a fifth capability extraction unit, configured to extract, in a case where the third dimension feature labels and the sixth dimension feature labels are the same as the second keyword, the security atomic capabilities corresponding to the third dimension feature labels and the sixth dimension feature labels which are the same as the second keyword as the security atomic capabilities conforming to the user intent strategy;
[0218] a sixth capability extraction unit, configured to extract, in a case where the third dimension feature labels and the sixth dimension feature labels are not the same as the second keyword but are similar to the second keyword, the security atomic capabilities with the highest similarity to the second keyword, and generate the second security atomic capability list;
[0219] a seventh capability extraction unit, configured to take the first security atomic capability list as the second security atomic capability list in a case where the third dimension feature labels and the sixth dimension feature labels are not the same as or similar to the second keyword;
[0220] a fourth screening unit, configured to perform screening on the security atomic capabilities in the second security atomic capability list according to the information related to the low-priority feature label in the user intent strategy, and obtain the security atomic capabilities conforming to the user intent strategy.
[0221] In an optional embodiment, the fourth screening unit includes:
[0222] a second label sublibrary construction subunit, configured to construct a second feature label sublibrary according to the multi-dimensional feature labels of the security atomic capabilities in the second security atomic capability list;
[0223] a third search subunit configured to search for a second-dimensional feature label in the second feature label sublibrary according to a third keyword which is a security policy indicated by the user intention strategy;
[0224] a second judgment subunit configured to, in a case where there is a second-dimensional feature label identical to the third keyword, judge whether the corresponding security atomic capability conforms to the deployment location and the deployment manner indicated by the user intention strategy;
[0225] an eighth capability extraction unit configured to, if yes, extract a security atomic capability corresponding to the second-dimensional feature label identical to the third keyword as the security atomic capability conforming to the user intention strategy;
[0226] a ninth capability extraction unit configured to, if no, search for a second-dimensional feature label in the second feature label sublibrary again;
[0227] a tenth capability extraction unit configured to, in a case where there is no second-dimensional feature label identical to the third keyword but there is a second-dimensional feature label similar to the third keyword, extract a security atomic capability corresponding to the second-dimensional feature label similar to the third keyword, sort the extracted security atomic capabilities in descending order of similarity, and generate a third security atomic capability list;
[0228] a security atomic capability screening subunit configured to screen a security atomic capability conforming to the user intention strategy according to the third security atomic capability list.
[0229] In an optional embodiment, the security atomic capability screening subunit comprises:
[0230] a third label sublibrary construction subunit configured to construct a third feature label sublibrary according to the multi-dimensional feature labels of the security atomic capabilities in the third security atomic capability list;
[0231] a third judgment subunit configured to traverse a fourth-dimensional feature label and a fifth-dimensional feature label in the third feature label sublibrary according to the sorting of the security atomic capabilities in the third security atomic capability list, and judge whether the corresponding security atomic capability conforms to the deployment location and the deployment manner indicated by the user intention strategy;
[0232] an eleventh capability extraction unit configured to, in a case where a security atomic capability conforming to the deployment location and the deployment manner indicated by the user intention strategy is found, extract the corresponding security atomic capability as the security atomic capability conforming to the user intention strategy;
[0233] A prompt unit is configured to trigger prompt information indicating that the user adjusts the security requirement intention in a case where no security atomic capability conforming to the deployment position and the deployment mode indicated by the user intention strategy is found.
[0234] In an optional embodiment, the intended treatment module 12 comprises:
[0235] An intention decomposition unit is configured to perform word segmentation on the security requirement to obtain an intention keyword.
[0236] An intention matching unit is configured to match and expand the intention keyword with a labeled keyword in an intention corpus to generate a user intention.
[0237] An intention formatting unit is configured to perform formatting processing on the user intention to obtain the user intention strategy.
[0238] In an optional embodiment, the apparatus further comprises:
[0239] A capability execution module is configured to call a corresponding security atomic capability from a security atomic capability resource pool to perform security protection according to the security atomic capability orchestration strategy.
[0240] It should be noted that the working processes of the various modules in the security atomic capability orchestration apparatus according to the embodiments of the present application can refer to the working processes of the security atomic capability orchestration method according to the embodiments of the present application, and the technical effects achieved are the same as those of the security atomic capability orchestration method according to the embodiments of the present application, which will not be described here again.
[0241] Referring to Figure 7 , Figure 7 is a structural block diagram of a security atomic capability orchestration device provided by the embodiments of the present application. The security atomic capability orchestration system comprises an intention handling layer 21, an atomic capability orchestration layer 22, and a capability execution layer 23.
[0242] The intention handling layer 21 is configured to perform intention handling on the security requirement input by the user to obtain a user intention strategy, and input the user intention strategy to the atomic capability orchestration layer 22.
[0243] The atomic capability orchestration layer 22 is configured to perform feature extraction on the security atomic capability to obtain a multi-dimensional feature label of the corresponding security atomic capability, and construct a feature label library; according to the user intention strategy input by the intention handling layer, screen out a security atomic capability conforming to the security requirement of the user from the feature label library; orchestrate the screened security atomic capability to obtain a security atomic capability orchestration strategy, and input the security atomic capability orchestration strategy to the capability execution layer 23.
[0244] The capability execution layer 23 is configured to invoke corresponding security atomic capability from a security atomic capability resource pool according to a security atomic capability orchestration strategy input by the atomic capability orchestration layer, and execute security protection.
[0245] It should be noted that the working processes of the various layers in the security atomic capability orchestration system described in the embodiments of the present application can refer to the working processes of the security atomic capability orchestration methods described in the above embodiments, and the technical effects achieved are the same as those of the security atomic capability orchestration methods described in the above embodiments, which will not be described here again.
[0246] Referring to Figure 8 , Figure 8 is a structural block diagram of the security atomic capability orchestration device provided by the embodiments of the present application. The security atomic capability orchestration device includes a processor 31, a memory 32, and a computer program stored in the memory 32 and executable on the processor 31. The processor 31 implements the steps in the above various security atomic capability orchestration method embodiments when executing the computer program, such as steps S11-S13.
[0247] For example, the computer program can be divided into one or more modules / units, which are stored in the memory 32 and executed by the processor 31 to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the security atomic capability orchestration device.
[0248] The security atomic capability orchestration device can include, but is not limited to, the processor 31 and the memory 32. Those skilled in the art can understand that the schematic diagram is only an example of the security atomic capability orchestration device and does not limit the security atomic capability orchestration device, which can include more or fewer components than the diagram, or combine certain components, or different components, for example, the security atomic capability orchestration device can also include an input / output device, a network access device, a bus, etc.
[0249] The processor 31 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic components, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The processor 31 is a control center of the security atomic capability arrangement device, and is connected with various parts of the security atomic capability arrangement device through various interfaces and lines.
[0250] The memory 32 can be used to store computer programs and / or modules. The processor 31 realizes various functions of the security atomic capability arrangement device by running or executing the computer programs and / or modules stored in the memory 32, and calling data stored in the memory 32. The memory 32 can mainly include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), etc. The data storage area can store data created according to use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory 32 can include a high-speed random access memory, and can also include a nonvolatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory devices.
[0251] The modules / units integrated by the safety atomic capability arrangement device can be stored in a computer readable storage medium if they are realized in the form of software function units and sold or used as independent products. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware. The computer program can be stored in a computer readable storage medium. When the computer program is executed by the processor 31, the steps of the above-mentioned various method embodiments can be realized. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate forms, etc. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium, etc.
[0252] It should be noted that the above-described device embodiments are merely illustrative, and the units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e., they can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. In addition, the connection relationship between the modules in the device embodiment provided by the present application indicates that there is a communication connection between them, which can be realized as one or more communication buses or signal lines. Those skilled in the art can understand and implement it without creative labor.
[0253] The above is the preferred embodiment of the present application. It should be noted that those skilled in the art can make improvements and refinements without departing from the principles of the present application, and these improvements and refinements are also considered within the scope of protection of the present application.
Claims
1. A method of secure atomic capability orchestration, the method comprising: The method comprises the following steps: feature extraction is performed on the security atomic capability to obtain a multi-dimensional feature label of the corresponding security atomic capability, and a feature label library is constructed; the user's input security requirement is disposed to obtain a user intention strategy; according to the user intention strategy, a security atomic capability meeting the user's security requirement is screened out from the feature label library; the screened security atomic capability is arranged to obtain a security atomic capability arrangement strategy; wherein, the screened security atomic capability is combined with a security atomic capability arrangement template, and the arrangement template is referred to to output a security atomic capability arrangement strategy suitable for the user's application scenario for the security atomic capability; the screening of the security atomic capability meeting the user's security requirement from the feature label library according to the user intention strategy comprises: the user intention strategy is compared with the multi-dimensional feature label in the feature label library according to a pre-set feature label priority, so as to perform hierarchical screening on the security atomic capability and obtain the security atomic capability meeting the user intention strategy; wherein, the feature label library comprises the multi-dimensional feature label of each security atomic capability.
2. The method of claim 1, wherein, the multi-dimensional feature label comprises: a first-dimensional feature label related to a core function instruction of the security atomic capability, a second-dimensional feature label related to a strategy template of the security atomic capability, a third-dimensional feature label related to an IPDRR security framework category to which the security atomic capability belongs, a fourth-dimensional feature label related to a deployment position of the security atomic capability, a fifth-dimensional feature label related to a deployment mode of the security atomic capability, and a sixth-dimensional feature label related to a traffic type of the security atomic capability.
3. The method of claim 2, wherein, the feature extraction performed on the security atomic capability to obtain the multi-dimensional feature label of the corresponding security atomic capability comprises: a core function instruction is extracted according to a core function description of the security atomic capability as a first-dimensional feature label of the corresponding security atomic capability; a strategy template of the security atomic capability is extracted from a security atomic capability strategy management module as a second-dimensional feature label of the corresponding security atomic capability; an IPDRR security framework category to which the security atomic capability belongs is determined according to a pre-defined security atomic capability description and classification, and the IPDRR security framework category to which the security atomic capability belongs is taken as a third-dimensional feature label; all available deployment positions of the security atomic capability are extracted as a fourth-dimensional feature label of the corresponding security atomic capability; all available deployment modes of the security atomic capability are extracted as a fifth-dimensional feature label of the corresponding security atomic capability; a traffic type to which the security atomic capability belongs is extracted as a sixth-dimensional feature label of the corresponding security atomic capability; wherein, the traffic type comprises a traffic type and a non-traffic type.
4. The method of claim 3, wherein, the feature label priority comprises: the first-dimensional feature label is of high priority, the third-dimensional feature label and the sixth-dimensional feature label are of medium priority, and the second-dimensional feature label, the fourth-dimensional feature label and the fifth-dimensional feature label are of low priority.
5. The method of claim 4, wherein, The user intention strategy is compared with multi-dimensional feature labels in the feature label library according to preset feature label priorities, to hierarchically screen the secure atomic capabilities, and obtain secure atomic capabilities conforming to the user intention strategy, including: The information related to the feature label of high priority in the user intention strategy is taken as a first keyword, to determine whether there is a secure atomic capability corresponding to a first-dimensional feature label same as or similar to the first keyword, and generate a first secure atomic capability list according to the secure atomic capability corresponding to the first-dimensional feature label similar to the first keyword; The information related to the feature label of medium priority in the user intention strategy is taken as a second keyword, to screen the secure atomic capabilities in the first secure atomic capability list, and obtain secure atomic capabilities conforming to the user intention strategy; The information related to the feature label of low priority in the user intention strategy is used to screen the secure atomic capability corresponding to the first-dimensional feature label same as the first keyword, and obtain secure atomic capabilities conforming to the user intention strategy.
6. The method of claim 5, wherein, The information related to the feature label of high priority in the user intention strategy is taken as a first keyword, to determine whether there is a secure atomic capability corresponding to a first-dimensional feature label same as or similar to the first keyword, and generate a first secure atomic capability list according to the secure atomic capability corresponding to the first-dimensional feature label similar to the first keyword, including: The information related to the feature label of high priority in the user intention strategy is taken as a first keyword, to search the first-dimensional feature labels in the feature label library; In the case that there is a first-dimensional feature label same as the first keyword, the secure atomic capability corresponding to the first-dimensional feature label same as the first keyword is extracted; In the case that there is no first-dimensional feature label same as the first keyword, but there is a first-dimensional feature label similar to the first keyword, the secure atomic capabilities corresponding to multiple first-dimensional feature labels with the highest similarity to the first keyword are extracted, to generate the first secure atomic capability list.
7. The method of claim 5, wherein the security atomic capability orchestration method is further characterized by, The information related to the feature label of low priority in the user intention strategy is used to screen the secure atomic capability corresponding to the first-dimensional feature label same as the first keyword, and obtain secure atomic capabilities conforming to the user intention strategy, including: It is determined whether the secure atomic capability corresponding to the first-dimensional feature label same as the first keyword conforms to the strategy template, deployment position and deployment mode indicated by the user intention strategy; If yes, the secure atomic capability corresponding to the first-dimensional feature label same as the first keyword is extracted as the secure atomic capability conforming to the user intention strategy; If no, the secure atomic capability corresponding to the first-dimensional feature label with the highest similarity to the first keyword is extracted as the secure atomic capability conforming to the user intention strategy.
8. The method of claim 5, wherein the security atomic capability orchestration method is further characterized by, The step of using the feature tags related to the user intent strategy and their priority as the second keyword to filter the security atomic capabilities in the first security atomic capability list to obtain security atomic capabilities that conform to the user intent strategy includes: Based on the multi-dimensional feature labels of the secure atomic capabilities in the first secure atomic capability list, a first feature label sub-library is constructed. Using the relevant information of the feature tags with medium priority in the user intent strategy as the second keyword, the third-dimensional feature tags and the sixth-dimensional feature tags in the first feature tag sub-library are retrieved; In the case where there are third-dimensional feature tags and sixth-dimensional feature tags that are the same as the second keyword, extract the security atomic capabilities corresponding to the third-dimensional feature tags and sixth-dimensional feature tags that are the same as the second keyword, and use them as security atomic capabilities that conform to the user intent strategy. In the case where there are no third-dimensional feature labels and sixth-dimensional feature labels that are the same as the second keyword, but there are third-dimensional feature labels and sixth-dimensional feature labels that are similar to the second keyword, the security atomic capabilities that are most similar to the second keyword are extracted to generate a second security atomic capability list. In the absence of third-dimensional feature labels and sixth-dimensional feature labels that are the same as or similar to the second keyword, the first list of secure atomic capabilities shall be used as the second list of secure atomic capabilities. Based on the information related to low-priority feature tags in the user intent strategy, the security atomic capabilities in the second security atomic capability list are filtered to obtain the security atomic capabilities that conform to the user intent strategy.
9. The method of claim 8, wherein, The step of filtering the security atomic capabilities in the second list of security atomic capabilities based on the information related to low-priority feature tags in the user intent strategy to obtain security atomic capabilities that conform to the user intent strategy includes: Based on the multidimensional feature labels of the secure atomic capabilities in the second list of secure atomic capabilities, a second feature label sub-library is constructed; Using the security policy indicated by the user intent policy as the third keyword, the second dimension feature tags in the second feature tag sub-library are retrieved; If a second-dimensional feature tag with the same as the third keyword exists, determine whether the corresponding security atomic capability conforms to the deployment location and deployment method indicated by the user intent policy; If so, extract the security atomic capabilities corresponding to the second-dimensional feature tags that are the same as the third keyword, and use them as security atomic capabilities that conform to the user intent strategy; If not, re-search the second-dimensional feature labels in the second feature label sub-library; In the case where there is no second-dimensional feature label that is the same as the third keyword, but there is a second-dimensional feature label that is similar to the third keyword, the security atomic capabilities corresponding to the second-dimensional feature labels that are similar to the third keyword are extracted, and the extracted security atomic capabilities are sorted in order of similarity from high to low to generate a list of third security atomic capabilities. According to the third security atomic capability list, security atomic capabilities meeting the user intention strategy are screened out.
10. The method of claim 9, wherein the security atomic capability orchestration method is further characterized by, According to the third security atomic capability list, security atomic capabilities meeting the user intention strategy are screened out. According to the multi-dimensional feature labels of the security atomic capabilities in the third security atomic capability list, a third feature label sub-library is constructed. According to the order of the security atomic capabilities in the third security atomic capability list, the fourth-dimensional feature labels and the fifth-dimensional feature labels in the third feature label sub-library are traversed to determine whether the corresponding security atomic capabilities meet the deployment location and the deployment mode indicated by the user intention strategy; In the case that the security atomic capabilities meeting the deployment location and the deployment mode indicated by the user intention strategy are found, the corresponding security atomic capabilities are extracted as the security atomic capabilities meeting the user intention strategy; In the case that the security atomic capabilities meeting the deployment location and the deployment mode indicated by the user intention strategy are not found, prompt information indicating that the user adjusts the security demand intention is triggered.
11. The method of claim 1, wherein the security atomic capability orchestration method further comprises: The method further comprises: According to the security atomic capability arrangement strategy, the corresponding security atomic capabilities are called from the security atomic capability resource pool to perform security protection. It comprises: A feature extraction module is configured to extract features of the security atomic capabilities to obtain multi-dimensional feature labels of the corresponding security atomic capabilities and construct a feature label library.
12. The method of claim 1, wherein, An intention processing module is configured to process the security demand input by the user to obtain a user intention strategy. A capability screening module is configured to screen out security atomic capabilities meeting the security demand of the user from the feature label library according to the user intention strategy.
13. A secure atomic capability programming device, characterized in that, A capability arrangement module is configured to arrange the screened security atomic capabilities to obtain a security atomic capability arrangement strategy; wherein, the screened security atomic capabilities are combined with an arrangement template of the security atomic capabilities, and the arrangement template is referred to to output a security atomic capability arrangement strategy adapted to the application scenario of the user for the security atomic capabilities. The capability screening module comprises: A capability screening unit is configured to compare the user intention strategy with the multi-dimensional feature labels in the feature label library according to the pre-set feature label priority to perform hierarchical screening of the security atomic capabilities and obtain the security atomic capabilities meeting the user intention strategy. The feature label library comprises multi-dimensional feature labels of the security atomic capabilities. It comprises: An intention processing layer, an atomic capability arrangement layer and a capability execution layer. The intention processing layer is configured to process the security demand input by the user to obtain a user intention strategy, and input the user intention strategy to the atomic capability arrangement layer. 14. A secure atomic capability orchestration system, comprising: The atomic capability arrangement layer is configured to perform feature extraction on the secure atomic capabilities to obtain multi-dimensional feature labels of the corresponding secure atomic capabilities, and construct a feature label library. According to the user intention strategy input by the intention handling layer, the secure atomic capabilities meeting the security requirements of the user are screened out from the feature label library. The screened secure atomic capabilities are arranged to obtain a secure atomic capability arrangement strategy, and the secure atomic capability arrangement strategy is input to the capability execution layer. The capability execution layer is configured to call corresponding secure atomic capabilities from a secure atomic capability resource pool according to the secure atomic capability arrangement strategy input by the atomic capability arrangement layer to execute security protection; wherein, the screened secure atomic capabilities are combined with an arrangement template of the secure atomic capabilities, and the arrangement template is referred to to output a secure atomic capability arrangement strategy adapted to the application scenario of the user for the secure atomic capabilities. The secure atomic capabilities meeting the security requirements of the user are screened out from the feature label library according to the user intention strategy, and the method comprises the following steps: The user intention strategy is compared with the multi-dimensional feature labels in the feature label library according to a pre-set feature label priority to perform hierarchical screening on the secure atomic capabilities, and secure atomic capabilities meeting the user intention strategy are obtained. The feature label library comprises multi-dimensional feature labels of the secure atomic capabilities.
15. A secure atomic capability orchestration device, comprising: The computer program is stored in the memory and configured to be executed by the processor, and the processor implements the secure atomic capability arrangement method according to any one of claims 1 to 12 when executing the computer program. The computer readable storage medium stores a computer program, wherein the computer program controls the device where the computer readable storage medium is located to execute the secure atomic capability arrangement method according to any one of claims 1 to 12 when the computer program runs.
16. A computer-readable storage medium, characterized in that, The computer program / instruction is executed by the processor to implement the secure atomic capability arrangement method according to any one of claims 1 to 12.
17. A computer program product comprising computer programs / instructions, characterized in that,
Citation Information
Patent Citations
Content tag generation method and device, electronic equipment and storage medium
CN114021577A
Method and device for providing security service and storage medium
CN116126479A