A Priority Asynchronous Processing Method and System for Network Security
By integrating multiple data sources to evaluate packet threat levels in real time and adjust processing priorities dynamically, and using machine learning algorithms for multi-dimensional evaluation, the problem of insufficient response capabilities of existing network security systems in the face of new attacks is solved, and more efficient network security protection is achieved.
Patent Information
- Application Number
- CN202411520404.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-29
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2044-10-29
AI Technical Summary
The existing network security protection system lacks response capabilities when facing new and complex attacks, and has lag in traffic processing and priority management, so it cannot adapt to dynamic changes in the network environment in real time.
Through integrated intrusion detection systems, user behavior analysis and network traffic monitoring, each packet’s threat level is evaluated in real time and its processing priorities are dynamically adjusted based on the threat level. Advanced machine learning algorithms are used to conduct multi-dimensional dynamic evaluation, timely identify high-risk data packets and prioritize processing.
It significantly improves the system's response ability to new and complex attacks, enhances the overall security of the network, and optimizes the packet processing efficiency, solving the main defects in traditional network security systems.
Smart Images

Figure CN119402257B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and particularly relates to a method and system for priority asynchronous processing for network security. Background Art
[0002] With the rapid development of information technology, network security issues have become increasingly prominent and have become a major challenge faced by various organizations and enterprises. Existing network security protection systems usually rely on methods of static rules and signature recognition, and these methods are extremely vulnerable when facing new types of attacks. For example, traditional intrusion detection systems (IDS) and firewalls can often only detect known threats, and their response capabilities are extremely insufficient for zero-day attacks or complex hybrid attacks. In addition, there are obvious lags in traffic processing and priority management in existing systems, and they cannot adapt to the dynamic changes of the network environment in real time. When many network devices encounter high traffic or sudden attacks, it is difficult to effectively distinguish critical data packets from low-priority data packets, resulting in delays in important data processing and affecting the overall security and availability of the system. In addition, various factors in the network environment (such as user behavior, traffic patterns, etc.) are often ignored, and the impact of these factors on threat assessment is not fully considered, resulting in reduced pertinence and effectiveness of defense measures. These shortcomings make existing network security solutions difficult to meet the rapidly changing network environment and diverse attack forms. Summary of the Invention
[0003] The object of the present invention is to design a method and system for priority asynchronous processing for network security, which integrates multiple data sources (such as intrusion detection systems, user behavior analysis, and network traffic monitoring), evaluates the threat level of each data packet in real time, and dynamically adjusts its processing priority accordingly.
[0004] To achieve the above object, in the first aspect of the present invention, a method for priority asynchronous processing for network security is provided, and the method includes:
[0005] S1. Collect real-time data by using a stream processing framework, preprocess the real-time data, and output the preprocessed data. The preprocessed data is a data set, and the data set includes selected features and labels for each feature;
[0006] S2. Combine the selected features into a feature data set and a corresponding label data set, design a weighted scoring algorithm for the feature data set and the corresponding label data set, calculate the weight of each feature by analyzing the mutual information of the features and the historical attack detection rate, obtain a weighted feature set for each feature according to the weight of each feature, then construct a threat classification model to calculate the threat score of each feature, and obtain the threat level of each feature by comparing the threat score of each feature with a dynamic threshold;
[0007] S3. Assign a priority weight to each data packet based on the threat level of each feature, combined with the current network load status, historical processing records, and current security risks. Then, adjust the priority weight of each data based on the weighted feature set of each feature and the real-time network status. Finally, arrange the data packets in descending order of priority to generate a final priority processing queue, ensuring that threats with higher priorities are processed first;
[0008] Among them, the S3 specifically includes:
[0009] S301. Introduce an influence factor ξ according to the threat level of each feature i , and assign a priority weight P to each data packet L , ensuring that the data packet with the highest threat can obtain the highest processing priority;
[0010] S302. Calculate a priority value V according to the priority weight P assigned to each data packet L in combination with the weight of each feature. Design an adjustment mechanism based on the real-time network status for the preliminary priority value, ensuring that the processing order is dynamically adjusted during high loads, and output a dynamically adjusted priority value V' after passing through the adjustment mechanism based on the real-time network status i ; i ;
[0011] S303. Arrange the data packets in descending order of the calculated dynamic priority value V' i to generate a final priority processing queue Q final ; Among them, the priority processing queue Q final includes the dynamic priority value V' of each data packet i , the weight f of the feature w and the corresponding threat level;
[0012] S4. Execute a collaborative response mechanism, specifically:
[0013] Monitor the status information of each node in the network. The status information includes the current processing capacity, load, and response delay. When a certain node detects a high-threat data packet, the current node generates a threat notification packet and broadcasts this threat information to other nodes. When other nodes receive the threat notification packet from the current node, other nodes will dynamically adjust the priority in their processing queues based on their own status and the received threat information. After completing the priority adjustment, other nodes update their priority processing queue Q j , and rearrange the task processing order based on the new priority value. After other nodes complete the threat response, they generate a feedback information packet and send it back to the central controller and other relevant nodes; Among them, the high-threat data packet is the dynamic priority value V'i Exceed the preset threshold θ;
[0014] S5. After the collaborative response is triggered, each node needs to execute its priority queue Q j for high-threat data packets, and preferentially process the data packets with the highest priority V j ″. After each node completes the task processing, it generates feedback information and feeds it back to the central controller and other collaborative nodes. The central controller adjusts the future priority allocation, resource scheduling, and node collaboration strategy according to the feedback information provided by each node and in combination with the historical processing results;
[0015] S6. Perform adaptive learning according to the feedback information in combination with the historical feedback information.
[0016] Furthermore, the real-time data includes: network traffic and potential attack behaviors in the network traffic, user behavior patterns and abnormal behaviors in the user behavior patterns, real-time network data packets;
[0017] The preprocessing includes: data cleaning and standardization processing, using mutual information measure to evaluate the correlation between each feature and the label for the data after standardization processing, where the label is normal traffic or attack traffic, selecting the top k features with higher correlation, and then performing PCA dimensionality reduction processing on the selected features, and finally outputting the preprocessed data.
[0018] Furthermore, the weighted scoring algorithm is expressed as follows:
[0019] W i = α·I(F i , Y)+β·T i +γ·R i
[0020] where I(F i , Y) is the mutual information between the feature F i and the label Y, reflecting the contribution of the feature to attack recognition; T i is the attack detection rate of the feature F i in the historical data; R i is a regularization term, indicating the stability of the feature F i in the most recent time window, and is calculated as the reciprocal of the feature change rate; α, β, γ are weight coefficients to ensure the balance between stability and contribution;
[0021] The threat classification model is constructed as follows:
[0022] Select decision tree, random forest, and support vector machine as the basic classifiers, and output the threat score S of each sample. The calculation formula is:
[0023]
[0024] Among them, C m (F w ) represents the classification result of the m-th base classifier on the weighted feature set F w , and M is the number of base classifiers;
[0025] Add a regularization term R to the threat classification model S , which is used to adjust the sensitivity of the model to abnormal samples. The calculation formula of the corrected score S' is:
[0026] S' = S - λ·R S
[0027] Among them, λ is a hyperparameter, and R S is the ratio of abnormal classification of the model in historical data.
[0028] Furthermore, after calculating the threat score of each feature, use a dynamic threshold calculation mechanism based on the ROC curve, which is expressed as follows:
[0029] θ = median(S') + k·std(S') + δ
[0030] Among them, δ is a specific adjustment factor, which depends on the change of the attack pattern in the recent period. By comparing the current threat score S' with the dynamic threshold θ, the threat level L of each sample is obtained, and its definition is:
[0031]
[0032] Furthermore, according to the threat level of each feature, introduce an influence factor ξ i , and assign a priority weight P L to each data packet, and the specific assignment is as follows:
[0033]
[0034] Among them, P low , P medium , P high is a preset basic priority value; ξ i is an influence factor, and its definition is:
[0035]
[0036] Among them, λ is a regulation coefficient of the historical processing load, and η(t) represents the network load of the current system, ensuring that the system can adjust the priority more sensitively under high load;
[0037] According to the priority weight P assigned to each data packet L Combine the weight of each feature to calculate the priority value Vi , is set as follows:
[0038]
[0039] Among them, W j is the weight of feature f w (j); f w (j) is the value of the j-th weighted feature; φ is a regularization term, representing the confidence adjustment term for high-weight features; Z is a normalization constant used to adjust the priority value V i to a reasonable scale range;
[0040] The preliminary priority value is combined with the dynamic environment of the network, and an adjustment mechanism based on the real-time network state is designed to ensure that the processing order is dynamically adjusted under high load, and the dynamic priority value V' adjusted by the adjustment mechanism based on the real-time network state is output i , which is expressed as follows:
[0041] V' i = V i + Δ(t)·θ(t)
[0042] Among them, Δ(t) is an adjustment coefficient that changes in real time, calculated based on the current network load, network security situation, and packet arrival; θ(t) is a security adjustment coefficient that is dynamically updated according to the traffic and threat type;
[0043] The change trend of the adjustment coefficient Δ(t) that changes in real time is that when the load increases, the value of Δ(t) increases, and the packets with high priority are processed first.
[0044] Furthermore, the threat notification packet T i contains the key features, priority, source, status of the current node, and threat confidence of the current node; the threat confidence λ of the current node i represents its urgency for this threat, and the calculation formula is:
[0045]
[0046] Among them, R i (t) is the response time of the node;
[0047] When other nodes receive the threat notification packet from a node, the node will dynamically adjust the priority in its processing queue based on its own status and the received threat information, which is expressed as follows:
[0048] According to the load, capacity of node j, and the received threat confidence λ i it is adjusted to a new priority value V j ″, and the calculation is as follows:
[0049]
[0050] Among them, V' i is the dynamic priority value reported by node i; is the current load factor of node j, which is used to balance the node processing capacity and avoid high-load nodes receiving more high-priority tasks; λ i is the threat confidence level of node i.
[0051] Furthermore, after adjusting the new priority value V j ″, a dynamic resource allocation algorithm is introduced for the node:
[0052] The node dynamically adjusts the available resource amount R j (t) according to the threat level and the current load, and the calculation formula is:
[0053]
[0054] Among them, is the maximum available resource amount of node j; α is an adjustment parameter used to control the allocation rate of the response resources; V j ″ is the adjusted priority, and θ is the threshold of resource allocation.
[0055] Furthermore, the S5 specifically includes:
[0056] S501. In the collaborative response trigger, the current node needs to dynamically allocate resources according to the current load status S j (t). Each node, based on its processing capacity C j (t) and the load condition L j (t), allocates resources to the data packet P i , and at the same time introduces a dynamic adjustment factor ρ j (t) to adjust the available resources according to the load change;
[0057] S502. After each node completes the task processing, it generates feedback information, and at the same time adds an execution quality score to quantify the node task processing efficiency, which is expressed as follows:
[0058]
[0059] Among them, μ j (t) is the execution quality score, V j ″(i) is the final priority value of the current task, R j (t) is the resource consumption during the task execution, and D j (t) is the delay of the task processing;
[0060] S503. According to the obtained execution quality score μ j (t), the central controller adjusts the priority setting of the next task, which is expressed as follows:
[0061]
[0062] where β is the optimization step coefficient, controlling the amplitude of priority adjustment; λ j (t) is the result of emergency handling of the task, reflecting whether the task is successfully processed; θ' is the priority adjustment threshold, and the priority is adjusted according to this threshold;
[0063] At the same time, optimize the future resource allocation strategy according to the resource consumption of each task. According to the resource consumption R j (t) in the feedback information, adjust the resource configuration of future tasks, which is expressed as follows:
[0064]
[0065] where γ is the resource optimization step coefficient; R j (t) is the resource consumption during task processing; V j ″(i) is the priority value of the task, reflecting its importance; ζ is the desired resource consumption ratio to ensure that the resource utilization rate remains within a reasonable range.
[0066] Furthermore, the said S6 specifically includes:
[0067] S601. Summarize the feedback data received by all nodes and design a feedback matrix M to store it;
[0068] S602. Optimize the priority of tasks through historical data and resource utilization conditions, and use an adaptive adjustment mechanism to update future task strategies;
[0069] S603. Update the feedback matrix M using incremental learning;
[0070] S604. Introduce a feature optimization mechanism to dynamically identify new threat patterns and adapt, which is expressed as follows:
[0071]
[0072] where ΔW f represents the feature weight update amount; λ f represents the feature learning rate; L f represents the processing failure rate of this feature in historical tasks; T f represents the total number of times this feature is processed; ∈ represents a constant to prevent division by zero.
[0073] In a second aspect of the present invention, a priority asynchronous processing system for network security is provided. The system includes:
[0074] A network data collection module for collecting real-time data by using a stream processing framework, preprocessing the real-time data, and outputting the preprocessed data. The preprocessed data is a data set, and the data set includes selected features and labels for each feature;
[0075] A feature weighting module for forming a feature data set and a corresponding label data set from the selected features, designing a weighted scoring algorithm for the feature data set and the corresponding label data set, calculating the weight of each feature by analyzing the mutual information and historical attack detection rate of the features, obtaining a weighted feature set for each feature according to the weight of each feature, then constructing a threat classification model to calculate the threat score of each feature, and obtaining the threat level of each feature by comparing the threat score of each feature with a dynamic threshold;
[0076] A priority processing module for assigning a priority weight to each data packet according to the threat level of each feature in combination with the current network load status, historical processing records, and current security risks, then adjusting the priority weight of each data according to the weighted feature set of each feature and the real-time network status, and finally arranging the data packets in descending order of priority to generate a final priority processing queue, ensuring that high-threat packets with high priority are processed first;
[0077] Among them, the priority processing module specifically performs the following:
[0078] S301. According to the threat level of each feature, introduce an influence factor ξ i , and assign a priority weight P L to each data packet to ensure that the data packet with the highest threat can obtain the highest processing priority;
[0079] S302. Calculate a priority value V L by combining the priority weight P i assigned to each data packet with the weight of each feature, design an adjustment mechanism based on the real-time network status for the preliminary priority value, ensure that the processing order is dynamically adjusted under high load, and output a dynamically adjusted priority value V' i after being adjusted by the adjustment mechanism based on the real-time network status;
[0080] S303. Arrange the data packets in descending order of the calculated dynamically adjusted priority value V' i to generate a final priority processing queue Q final ; among them, the priority processing queue Q final includes the dynamically adjusted priority value V' of each data packeti The weight f of the feature w and the corresponding threat level;
[0081] A collaborative processing module for executing a collaborative response mechanism, specifically:
[0082] Monitor the status information of each node in the network. The status information includes the current processing capacity, load, and response latency. When a node detects a high-threat data packet, the current node generates a threat notification packet and broadcasts this threat information to other nodes. When other nodes receive the threat notification packet from the current node, other nodes will dynamically adjust the priority in their processing queues based on their own status and the received threat information. After completing the priority adjustment, other nodes update their priority processing queue Q j , and rearrange the task processing order based on the new priority value. After other nodes complete the threat response, they generate a feedback information packet and feedback it to the central controller and other relevant nodes; where the high-threat data packet is the dynamic priority value V′ i exceeds the preset threshold θ;
[0083] A node processing module for each node to execute its priority queue Q after the collaborative response is triggered j for the high-threat data packets in it, and preferentially process the data packets with the highest priority V j ″. After each node completes the task processing, it generates feedback information and feeds it back to the central controller and other collaborative nodes. The central controller adjusts the future priority allocation, resource scheduling, and node collaboration strategy based on the feedback information provided by each node and in combination with the historical processing results;
[0084] An adaptive optimization module for performing adaptive optimization based on the feedback information in combination with historical feedback information.
[0085] The beneficial technical effects of the present invention are at least as follows:
[0086] The present invention integrates multiple data sources (such as intrusion detection systems, user behavior analysis, and network traffic monitoring), evaluates the threat level of each data packet in real time, and dynamically adjusts its processing priority accordingly. Different from traditional static methods, the present invention uses advanced machine learning algorithms to perform dynamic evaluation in multiple dimensions, timely identify high-risk data packets and prioritize their processing. This mechanism significantly improves the system's response ability to new and complex attacks. At the same time, the present invention also introduces a multi-node collaborative attack response mechanism. When an abnormal traffic is detected by a certain node, it can automatically notify other nodes and share threat scenario information, so as to achieve a rapid collaborative response. This integrated innovation not only enhances the overall security of the network, but also optimizes the data packet processing efficiency, effectively solves the main defects in traditional network security systems, and provides new ideas for building a more secure and flexible network environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0087] The present invention will be further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the following drawings.
[0088] Figure 1 It is a flowchart of a priority asynchronous processing method for network security according to the present invention.
[0089] Figure 2 It is a framework diagram of a priority asynchronous processing system for network security according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0090] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present invention, and should not be construed as a limitation to the present invention.
[0091] In one or more embodiments, as Figure 1 shown, a priority asynchronous processing method for network security is disclosed, and the method includes the following steps S1-S6:
[0092] S1. Collect real-time data through the use of a stream processing framework, preprocess the real-time data, and output the preprocessed data. The preprocessed data is a data set, and the data set includes selected features and labels for each feature.
[0093] Specifically, identifying multiple key data sources is the first step to achieve comprehensive monitoring. Specific data sources include:
[0094] Intrusion Detection System (IDS): Monitors network traffic and detects potential attack behaviors.
[0095] User Behavior Analysis (UBA): Analyzes user behavior patterns and identifies abnormal activities.
[0096] Network traffic monitoring device: Captures and analyzes network packets in real time.
[0097] By using a stream processing framework (such as Apache Kafka or Apache NiFi), an efficient real-time data collection pipeline can be established. The output of data collection can be expressed as:
[0098]
[0099] where D i represents the i-th data source, and n is the number of data sources. Each data source sends data to the data pipeline regularly to ensure the real-time nature and integrity of the data stream. For each data source, the corresponding collection strategy needs to be defined, such as the collection frequency and data format (JSON, CSV, etc.).
[0100] Furthermore, before the data enters the subsequent processing stage, it must be cleaned to eliminate irrelevant information and noise. The specific steps include:
[0101] Duplicate removal: Identifies and deletes duplicate data to avoid interference with the analysis results caused by the same data.
[0102] Missing value handling: Uses interpolation methods (such as linear interpolation or K-nearest neighbor interpolation) to fill in missing values to ensure data integrity. For example, for the missing value of feature X j can be linearly interpolated through the following formula:
[0103]
[0104] where X j ' is the interpolated value, and are the known values before and after this feature respectively.
[0105] Normalization: Normalizes the feature data using Z-score to eliminate the dimensional differences between different features. The formula is:
[0106]
[0107] where Z j is the normalized value, X j is the original value, μ j is the mean of feature j, and σ jis the standard deviation of feature j. Through standardization, the data ranges of all features are compressed to a similar scale, ensuring that different features contribute equally to the model in subsequent analysis.
[0108] Furthermore, to improve the analysis efficiency and accuracy, key features related to network security threats need to be extracted from the cleaned data. The steps of feature selection include:
[0109] Correlation assessment: Use the mutual information measure (MutualInformation) to evaluate the correlation between each feature and the label (such as normal traffic or attack traffic). Select the top k features with higher correlations. For example, calculate the mutual information through the following formula:
[0110]
[0111] where P(x,y) is the joint probability distribution of feature X and label Y, and P(x) and P(y) are their respective marginal probability distributions.
[0112] Feature extraction: Further process the selected features, such as using principal component analysis (PCA) for dimensionality reduction to reduce the feature dimension and retain the most important information. PCA can calculate the principal components through the following steps:
[0113] Z = XW
[0114] where Z is the feature matrix after dimensionality reduction, X is the standardized feature matrix, and W is the weight matrix containing the principal components.
[0115] Furthermore, store the processed data in a high-performance structured database (such as PostgreSQL or Elasticsearch) for fast query and access during subsequent analysis. The output format of the storage process is D clean , whose structure contains the selected feature set F and its corresponding label information, in the form of:
[0116] D clean = {(f1,y1),(f2,y2),…,(f k ,y k )}
[0117] where f i represents the selected feature, and y i is the label (normal or abnormal) of each sample. By ensuring that the data output format matches the input requirements of the subsequent steps (threat level assessment), it lays the foundation for the efficient processing of the system in the future.
[0118] Through the above detailed steps, the data collection and preprocessing solution ensures high-quality input data for subsequent threat assessment. This solution not only addresses the problems of data redundancy and low quality in the background art, but also lays a solid foundation for the entire patent solution, enabling subsequent analysis to accurately and effectively identify and respond to cyberattacks.
[0119] S2. Combine the selected features to form a feature dataset and a corresponding label dataset. Design a weighted scoring algorithm for the feature dataset and the corresponding label dataset. By analyzing the mutual information and historical attack detection rate of the features, calculate the weight of each feature. Obtain the weighted feature set of each feature based on the weight of each feature, and then construct a threat classification model to calculate the threat score of each feature. Compare the threat score of each feature with the dynamic threshold to obtain the threat level of each feature.
[0120] Specifically, to improve the accuracy of threat assessment, weights need to be assigned to the features first. The present invention designs a weighted scoring algorithm (WeightedScoringAlgorithm), and calculates the weight W of each feature by analyzing the mutual information and historical attack detection rate of the features. i . The formula is as follows:
[0121] W i = α·I(F i , Y)+β·T i +γ·R i
[0122] Wherein, I(F i , Y) is the mutual information between the feature F i and the label Y, reflecting the contribution of the feature to attack recognition. T i is the attack detection rate of the feature F i in the historical data. R i is a regularization term, indicating the stability of the feature F i in the most recent time window, and is calculated as the reciprocal of the feature change rate. α, β, γ are weight coefficients, usually set to 0.4, 0.4, 0.2 to ensure the balance between stability and contribution.
[0123] Next, the calculation method of the weighted feature set F w is as follows:
[0124]
[0125] Wherein, F i is the i-th feature in the feature set F. W i is the corresponding feature weight. n is the total number of features.
[0126] Further, after obtaining the weighted feature set, an ensemble learning method is used to construct a threat classification model, combining multiple base classifiers to improve the detection ability. Decision tree, random forest, and support vector machine (SVM) are selected as the base classifiers. The model output is the threat score S for each sample, and the calculation formula is:
[0127]
[0128] where C m (F w ) represents the classification result of the m-th base classifier on the weighted feature set F w , and M is the number of base classifiers. To further improve the robustness of the model, the present invention introduces a regularization term R S , which is used to adjust the sensitivity of the model to abnormal samples. The corrected score calculation formula is:
[0129] S' = S - λ·R S
[0130] where λ is a hyperparameter, and R S is the ratio of abnormal classification of the model in historical data. The output of this step is the dynamically updated threat score S', ensuring accuracy and flexibility.
[0131] Further, the dynamically adjusted threshold mechanism helps to flexibly respond to threats according to real-time data and historical patterns. The present invention uses a dynamic threshold calculation mechanism based on the ROC curve, and the formula is:
[0132] θ = median(S') + k·std(S') + δ
[0133] where δ is a specific adjustment factor, which depends on the change of attack patterns in the recent period. For example, it can be adjusted based on the number of recent attack events. By comparing the current threat score S' with the dynamic threshold θ, the threat level L for each sample is obtained, and its definition is:
[0134]
[0135] This step provides a clear basis for subsequent priority processing, ensuring timely response to high threat levels.
[0136] Finally, the threat level L of each sample is stored together with its corresponding weighted feature F w for subsequent priority processing. The output format is D threat , which contains the following structure:
[0137] D threat = {(f w , L) | f w ∈F w, L ∈ {low, medium, high}}
[0138] This structure ensures that subsequent steps can quickly adjust the priority of network traffic processing according to the threat level, improving the overall network security.
[0139] Through this threat level assessment scheme, combined with feature importance weighting, ensemble learning classification, and dynamic threshold adjustment, the accuracy and response speed of threat recognition have been effectively improved. This scheme directly solves the problems of inaccurate threat recognition and lagging response in the background technology, provides a solid foundation for subsequent priority processing, and ensures the security and stability of the network environment.
[0140] S3. Assign priority weights to each packet according to the threat level of each feature, combined with the current network load status, historical processing records, and current security risks. Then, adjust the priority weights of each data according to the weighted feature set of each feature and the real-time network status. Finally, the packets are sorted from high to low according to the priority to generate the final priority processing queue, ensuring that high-threat packets are processed first.
[0141] Specifically, first, the present invention assigns a priority weight P L to each packet. This weight is determined according to the threat level L to ensure that high-threat packets can obtain higher processing priorities. Different from the conventional priority assignment strategy, the present invention introduces an innovative impact factor ξ i to capture the urgency of processing each packet. This impact factor combines the network load status, historical processing records, and current security risks. The priority weight assignment formula:
[0142]
[0143] where P low , P medium , P high are preset basic priority values. For example, P low = 1, P medium = 3, P high = 5. ξ i is the impact factor, defined as:
[0144]
[0145] where λ is the adjustment coefficient of the historical processing load (such as 0.5), and η(t) represents the network load of the current system, ensuring that the system can adjust the priority more sensitively under high load. By introducing the impact factor, it is ensured that the system can still give priority to processing high-threat traffic during peak hours.
[0146] Further, after calculating the priority weight of each data packet, it is necessary to combine it with the data packet feature F w for more accurate priority adjustment. To this end, the present invention designs a new priority calculation formula, which integrates the weighted features and the previous threat level results to ensure that traffic with high-risk features is processed preferentially. Priority value calculation formula:
[0147]
[0148] where P L is the priority weight corresponding to the threat level calculated in the previous step. W j is the weight of feature f w (j) (from the feature weighting in step 2). f w (j) is the value of the j-th weighted feature. φ is a regularization term, representing the confidence adjustment term for high-weight features, to avoid the over-amplification effect of certain features in high-threat situations. Z is a normalization constant used to adjust the priority value V i to a reasonable scale range. Through this formula, the system can accurately evaluate the urgency of each data packet, making the priority not only depend on the threat level but also combine the feature weighting and the interaction between features. This innovative regularization term φ solves the problem of a single feature overly dominating the priority in traditional solutions.
[0149] Further, during the operation of the system, as the network environment changes continuously (such as load fluctuations or the emergence of new threats), it is necessary to dynamically adjust the priority queue. The present invention designs an adjustment mechanism based on the real-time network state to ensure that the system can still flexibly adjust the processing order under high load. This mechanism dynamically adjusts the influence factor ξ i and the regularization term φ to update the priority queue in real time. Priority adjustment formula:
[0150] V' i = V i + Δ(t)·θ(t)
[0151] where Δ(t) is an adjustment coefficient that changes in real time, calculated based on the current network load, network security situation, and data packet arrival rate. The change trend of Δ(t) is that when the system load increases, the value of Δ(t) increases, accelerating the processing of high-priority data packets. θ(t) is a security adjustment coefficient that is dynamically updated according to the traffic and threat types. For example, during a large-scale DDoS attack, the system will increase the weight of θ(t) to ensure that processing resources are preferentially allocated to the traffic related to this threat. This formula ensures that the system can dynamically adjust the priority according to the real-time network state, ensuring that the system can still reasonably allocate resources in sudden attack and high-load scenarios. Through this mechanism, the system has higher adaptability.
[0152] Further, according to the calculated dynamic priority value V' i , arrange the data packets in descending order of the priority value to generate the final priority processing queue Q final . Through continuous update and scheduling of this queue, it is ensured that high-threat traffic is processed preferentially, reducing latency. Queue processing structure:
[0153] Q final ={(f w ,V' i )|f w ∈F w ,V' i ∈V' i}
[0154] The processing queue Q final ensures that each data packet is processed according to the real-time priority, enabling high-threat and high-importance traffic to pass through preferentially. Especially in the attack and high network load environment, this dynamic adjustment mechanism can greatly improve the network's ability to cope with emergencies.
[0155] Through the above dynamic priority adjustment scheme, combined with the influence factor, regularization term, and dynamic adjustment mechanism, the system can not only process traffic according to the threat level preferentially but also adapt to environmental changes under high load. This scheme significantly improves the system's adaptive ability to sudden attacks and busy networks, ensuring that high-priority tasks are quickly responded to.
[0156] S4. Execute the collaborative response mechanism.
[0157] Specifically, the system first continuously monitors the status information of each node in the network. The status of each node reflects the current processing capacity, load, and response latency. Define the status of node i as S i (t), including the following variables:
[0158] S i (t)=(L i (t),C i (t),R i (t))
[0159] Among them, L i (t) represents the load of node i, indicating the number of data packets currently being processed or the system resource usage rate, and the value range is 0≤L i (t)≤1. C i (t) represents the processing capacity of node i, indicating the maximum load that the node can withstand, usually a fixed value of the node resource configuration. R i (t) represents the response time of node i, indicating the time delay from receiving data to processing completion at the current node. The node status S i(t) is updated once per cycle Δt and broadcast to other nodes via the message bus. The system can judge the health status and resource availability of each node through these status information, providing a basis for subsequent collaborative adjustment.
[0160] Furthermore, when a certain node i detects a high-threat data packet (i.e., the V' i value exceeds a certain threshold θ), this node will generate a threat notification packet T i , and broadcast this threat information to other nodes. The notification packet T i contains the key features, priority, source, and the current status of the current node of the threat, in the form of:
[0161] T i =(f w ,V' i ,S i (t),t trigger ,λ i )
[0162] Among them, f w represents the data packet feature vector of high-priority threats. V' i represents the priority score of this threat data packet (the calculation result from step 3). S i (t) represents the current status information of node i, including load, processing capacity, and response latency. t trigger represents the timestamp when this threat event is triggered. λ i represents the threat confidence of this node, indicating the urgency of the threat to it. The calculation formula is:
[0163]
[0164] This formula introduces the response time R i (t) as a regularization term to ensure that when the response latency of the node is large, its threat confidence is appropriately adjusted to avoid unnecessary resource allocation.
[0165] Furthermore, when node j receives the threat notification packet T i from node i, node j will dynamically adjust the priority in its processing queue based on its own status S j (t) and the received threat information. To improve resource utilization efficiency, the system designs a weighted priority adjustment algorithm to adjust the priority value V i ″ according to the load, capacity of node j, and the received threat confidence λ j :
[0166]
[0167] Among them, V' iThe threat priority reported for node i. The current load factor of node j, which is used to balance the node processing capacity and avoid high-load nodes from receiving more high-priority tasks. λ i The threat confidence level of node i. This priority weighting adjustment mechanism ensures that node j will not receive too many high-priority tasks in a high-load state, avoids resource exhaustion of a single node, and ensures optimal allocation of the processing capacity of the entire network.
[0168] Further, after completing the priority adjustment, node j updates its priority queue Q j , and rearranges the task processing order based on the new priority V j ″ To improve the collaborative response efficiency, the present invention introduces a dynamic resource allocation algorithm for nodes. Nodes dynamically adjust the available resource amount R j (t) according to the threat level and the current load. The calculation formula is:
[0169]
[0170] where is the maximum available resource amount of node j. α is an adjustment parameter used to control the allocation rate of response resources. V j ″ is the adjusted priority, and θ is the threshold of resource allocation. This formula uses the sigmoid function to achieve adaptive allocation of resources, ensuring that the resource allocation rises rapidly in the case of high threats and remains stable in the case of low threats. Through this dynamic resource allocation algorithm, each node can flexibly allocate resources according to the threat level, avoid resource waste, and ensure that high-threat traffic receives sufficient processing resources.
[0171] Further, after the node completes the threat response, it generates a feedback information packet F j , and feeds it back to the central controller and other relevant nodes. The structure of the feedback packet is:
[0172] F j =(T i ,V j ″,R j (t),t complete )
[0173] where T i represents the original threat notification packet. V j ″ represents the final processed priority of node j. R j (t) represents the resource allocation status of the node during processing. t complete represents the timestamp when the processing is completed. The central controller analyzes the feedback information packet F j, which can optimize the global resource scheduling strategy and optimize the future collaborative response mechanism based on historical data. For example, when the system discovers that certain nodes have low response efficiency in specific threat scenarios, it can reallocate their weights or adjust the resource allocation strategy of that node.
[0174] Through this collaborative response mechanism, the system can flexibly and efficiently process high-threat traffic among multiple nodes. Through node status monitoring, threat notification, priority weighting adjustment, dynamic resource allocation, and feedback mechanisms, it ensures that the system can adaptively adjust, optimize resource utilization, and minimize the latency of threat response. This solution is specifically targeted at the real-time collaborative processing requirements in network security scenarios, and solves the problems of slow response and uneven resource allocation among nodes in the existing technology.
[0175] S5. After the collaborative response is triggered, each node needs to execute the high-threat data packets in its priority queue Q j and give priority to processing the data packets with the highest priority V j ″. After each node completes the task processing, it generates feedback information and feeds it back to the central controller and other collaborative nodes. The central controller adjusts the future priority allocation, resource scheduling, and node collaboration strategy based on the feedback information provided by each node and in combination with the historical processing results.
[0176] Specifically, after the collaborative response is triggered, each node needs to execute the high-threat data packets in its priority queue Q j and give priority to processing the data packets with the highest priority V j ″. During the threat response process, the node needs to dynamically allocate resources according to the current load status S j (t) to ensure efficient task completion.
[0177] Among them, the response processing mechanism is: each node processes the data packet P j based on its processing capacity C j (t) and load condition L i . The present invention introduces a weighted task processing model to ensure that tasks with different priorities can be fairly and reasonably allocated resources. The task processing formula is:
[0178]
[0179] Where: P j (t) is the processing resource allocated by node j to the task at time t; V j ″(i) is the adjusted priority of task i (output by step 4). R j (t) is the current available resource amount of node j. L j(t) is the current load level of node j, reflecting the resource occupancy of the node. α is the regularization term, which is used to balance the load pressure of the node and avoid the decline of system performance caused by excessive load on a single node.
[0180] The design of this formula ensures that at high loads, both the priority of tasks and the processing resources can dynamically adapt to the current network environment. For nodes with high loads (a node refers to a computing unit or server in the system), the α term increases the difficulty of task processing, making resources more inclined to be allocated to low-load nodes to avoid overall system overload.
[0181] Among them, the resource dynamic adjustment mechanism is as follows: To ensure that high-priority tasks can obtain sufficient resource support in the case of burst traffic, the resource allocation mechanism of the node must have an adaptive ability. A dynamic adjustment factor ρ j (t) is introduced, and its role is to adjust the available resources according to the load change of the system. The resource dynamic adjustment formula is:
[0182] R j '(t) = R j (t) · (1 + ρ j (t))
[0183] Among them, R j '(t) is the amount of resources after dynamic adjustment. Among them, λ j (t) represents the urgency of the task, and D j (t) represents the current delay of the system. By combining urgency and delay, the system can ensure that high-priority tasks are still processed in a timely manner in high-load scenarios. Through this resource adjustment mechanism, the system can dynamically allocate resources according to different task characteristics, achieve efficient utilization of resources and rapid response of tasks, which is particularly important in the case of large-scale threats or network congestion.
[0184] Furthermore, after each node completes task processing, it needs to generate feedback information and feedback the processing results, resource consumption, and delay situation to the central controller and other collaborative nodes. The structure of the feedback information set F j is as follows:
[0185] F j = (V j ″(i), R j (t), D j (t), λ j (t), μ j (t))
[0186] Among them, V j ″(i) is the final priority of task i. R j (t) is the resource consumption during task execution. D j(t) is the delay of task processing. λ j (t) is the result of task urgency processing, where the value of 1 indicates successful processing and 0 indicates failed processing. μ j (t) is the evaluation of the execution quality of the task. It is scored based on resource consumption and processing duration to ensure that the system can track the execution quality of each task.
[0187] Furthermore, the execution quality score μ j (t) aims to provide quantitative feedback to the system regarding task processing efficiency. The formula is as follows:
[0188]
[0189] This score reflects the overall performance of the node during task execution. The higher the value, the more effectively the task has been processed with less resource consumption and shorter delay. By collecting the execution quality of all nodes, the central controller can identify potential performance bottlenecks and optimize future resource allocation strategies.
[0190] Furthermore, the key role of the feedback mechanism is to continuously optimize future response strategies through historical data. The system adjusts future priority allocation, resource scheduling, and node collaboration strategies based on the feedback information F j provided by each node, in combination with historical processing results.
[0191] Among them, based on the feedback execution quality score μ j (t), the central controller can adjust the priority setting of the next task. In particular, for tasks that have failed or have poor processing effects, the system can dynamically increase their priority to ensure faster processing when similar threats appear next time. The optimization formula is:
[0192]
[0193] Among them, β is the optimization step coefficient, which controls the amplitude of priority adjustment. λ j (t) is the result of task urgency processing, reflecting whether the task has been successfully processed. μ j (t) is the execution quality score, reflecting the processing efficiency of the task. θ is the priority adjustment threshold, and the system adjusts the priority based on this threshold. Through this optimization formula, the system can automatically increase the priority of tasks with low processing efficiency and optimize future response decisions.
[0194] Furthermore, the system not only needs to optimize the priority but also optimize future resource allocation strategies according to the resource consumption of each task. Based on the resource consumption R j (t) in the feedback information, the system can adjust the resource configuration of future tasks:
[0195]
[0196] Among them, γ is the resource optimization step coefficient. R j (t) is the resource consumption during task processing. V j ″(i) is the priority of the task, reflecting its importance. ζ is the desired resource consumption ratio of the system, ensuring that the resource utilization rate of the system remains within a reasonable range. By analyzing the relationship between resource consumption and task priority, the system can optimize future resource allocation strategies, avoid resource waste, and ensure that high-priority tasks receive higher resource support.
[0197] Furthermore, with the continuous accumulation of feedback information for each task processing, the system gradually forms a long-term learning mechanism. By analyzing historical feedback data, the system can gradually establish a complex threat model and self-optimize through an incremental learning algorithm:
[0198] Incremental learning model: According to the feedback of each task processing, the system adjusts the feature weights and threat model, gradually improving the accuracy of response decisions.
[0199] Feedback-driven optimization: Combining the execution quality and resource allocation information in the feedback, the system dynamically adjusts its parameters after each processing to optimize future response decisions.
[0200] The long-term learning mechanism ensures that the system can self-adjust and optimize when facing continuously changing network threats, gradually improving the network protection ability.
[0201] S6. Perform adaptive learning based on the feedback information in combination with historical feedback information.
[0202] Specifically, first, the system aggregates the feedback data F received from all nodes j , and these data include the task processing information, resource consumption, response delay, and processing results of each node. Through these historical feedbacks, the system can construct the execution history record of each node for global optimization. The present invention designs a feedback matrix M to store this information:
[0203]
[0204] Among them, V i represents the priority of data packet i. R i represents the resources consumed when processing task i. D i represents the delay. λ i represents the task success flag (1 means success, 0 means failure). μ i represents the processing efficiency score (based on R i and D i ).
[0205] Furthermore, by extracting features from the feedback matrix of historical tasks, the system can identify which tasks require more resources or higher priorities. For example, by statistically analyzing λ i and μ i the system can filter out tasks that have failed multiple times or have low processing efficiency and mark them as tasks that need to be optimized with priority.
[0206] Furthermore, during the long-term operation of the system, it is necessary to dynamically adjust the priorities and processing strategies of each task to ensure the rationality of resource allocation. The present invention optimizes the priorities of tasks through historical data and uses an adaptive adjustment mechanism to update future task strategies. Priority optimization formula:
[0207]
[0208] where represents the priority of task i in the next cycle. α represents the optimization step size, which controls the amplitude of priority adjustment. λ i represents a flag indicating whether the task is processed successfully. μ i represents the processing efficiency score. θ represents the ideal score threshold expected by the system. The core idea of this optimization formula is to dynamically adjust the priorities of tasks according to the success rate and processing efficiency of the tasks. If μ i is lower than the system expectation, it indicates that there is a bottleneck in task processing and the priority V i needs to be increased to ensure that such tasks can be processed faster next time. Feature weight update formula:
[0209]
[0210] where W f,i represents the feature weight of task i (such as IP address, traffic characteristics, etc.). β represents the learning rate, which controls the update speed of the feature weight. μ i represents the processing efficiency score, which reflects the task processing effect. R i represents the resource consumption of the task. D i represents the task processing delay. ζ represents the expected score of the feature, ensuring that the feature weight is not over-adjusted. Through this formula, the system can dynamically adjust the features (such as network traffic characteristics, historical attack patterns, etc.) that affect processing efficiency, thereby optimizing future response decisions. This solves the problem in traditional solutions of over-reliance on static features and difficulty in coping with ever-changing threat scenarios.
[0211] Furthermore, in addition to priority optimization, the system also needs to adjust the future resource allocation strategy according to the resource utilization situation. The present invention designs an adaptive resource scheduling mechanism based on feedback data to ensure the optimal allocation of system resources. Adaptive resource adjustment formula:
[0212]
[0213] Among them, represents the amount of resources allocated to node j in the next cycle. γ represents the resource adjustment coefficient. V i represents the priority of task i. R j represents the resource consumption of the current task. D j represents the delay of the current task. This mechanism ensures the dynamic balance of resource allocation. When processing high-priority tasks, the node can flexibly adjust its resource allocation according to historical feedback, ensuring that the system can allocate more resources when dealing with emergency tasks.
[0214] Furthermore, the system needs to gradually optimize the decision-making model in continuous historical data relying on Incremental Learning. Through incremental learning, the system can adapt to new network threats and security scenarios without reconstructing the model. Incremental learning model:
[0215]
[0216] Among them, M represents the current feedback matrix; η represents the learning rate, which controls the model update amplitude. μ represents the processing quality score of the current task. V represents the task priority. λ represents the flag indicating whether the task is processed successfully. Through incremental learning, the system can gradually correct its threat detection and response model, ensuring that it can detect and process new types of network attacks more quickly and accurately in the future. This solves the problem of processing lag in traditional systems due to outdated threat models and fixed response strategies.
[0217] Furthermore, to ensure that the system optimization and self-learning effect truly improve the processing ability, the system will periodically evaluate the performance of the self-learning algorithm. The core evaluation indicators include:
[0218] Processing efficiency improvement rate: By comparing the average delay and resource consumption of processing tasks, evaluate whether the processing efficiency of the system has improved after self-learning.
[0219] Priority scheduling effect: Analyze whether the priority allocation after multiple optimizations is reasonable, especially whether high-priority tasks have received faster responses.
[0220] Resource utilization improvement: Evaluate the optimization effect of the resource scheduling strategy through the relationship between resource consumption and task success rate.
[0221] The evaluation results will be re-input into the incremental learning model to ensure that the system can further optimize its decision-making process in each cycle.
[0222] Furthermore, to cope with the ever-changing network environment, the system not only needs to adjust priorities and resources during long-term operation, but also continuously optimize the processing weights of task characteristics. The present invention introduces an innovative feature optimization mechanism. By introducing uncommon regularization terms, the system can dynamically identify new threat patterns and adapt to them. Feature optimization formula:
[0223]
[0224] Where, ΔW f represents the feature weight update amount. λ f represents the feature learning rate. L f represents the processing failure rate of this feature in historical tasks. T f represents the total number of processing times of this feature. ∈ represents a constant to prevent division by zero. This formula ensures that the system can automatically detect which features are related to task processing failures and preferentially increase their weights by introducing the feature failure rate L f . This innovative feature optimization mechanism enables the system to adapt to new environments more agilely and quickly when dealing with unknown threats.
[0225] The system optimization and self-learning steps ensure the long-term adaptability of the system when dealing with new threats through the integration of feedback information, the optimization and adjustment of priorities and resources, and the introduction of self-learning algorithms. Through long-term analysis of feedback and model optimization, the system gradually improves its response efficiency and resource utilization rate, forming a closed-loop optimization.
[0226] In a second aspect of the present invention, an embodiment is provided, specifically a priority asynchronous processing system for network security. The system includes:
[0227] A network data collection module 101, which is used to collect real-time data through a stream processing framework, preprocess the real-time data, and output the preprocessed data. The preprocessed data is a data set, and the data set includes selected features and labels for each feature;
[0228] A feature weighting module 102, which is used to form a feature data set and a corresponding label data set from the selected features, design a weighted scoring algorithm for the feature data set and the corresponding label data set, calculate the weight of each feature by analyzing the mutual information of the features and the historical attack detection rate, obtain the weighted feature set of each feature according to the weight of each feature, then construct a threat classification model to calculate the threat score of each feature, and obtain the threat level of each feature by comparing the threat score of each feature with a dynamic threshold;
[0229] The priority processing module 103 is used to assign a priority weight to each data packet according to the threat level of each feature in combination with the current network load status, historical processing records, and current security risks, and then adjust the priority weight of each data according to the weighted feature set of each feature and the real-time network status. Finally, the data packets are arranged in descending order of priority to generate a final priority processing queue, ensuring that good threats with high priority are processed first;
[0230] Among them, the priority processing module specifically executes the following steps:
[0231] S301. According to the threat level of each feature, introduce an influence factor ξ i , and assign a priority weight P to each data packet L , ensuring that the data packet with the highest threat can obtain the highest processing priority;
[0232] S302. According to the priority weight P assigned to each data packet L and combine the weight of each feature to calculate the priority value V i . Design an adjustment mechanism based on the real-time network status by combining the preliminary priority value with the dynamic environment of the network, ensuring that the processing order is dynamically adjusted under high load, and output the dynamically adjusted priority value V' after passing through the adjustment mechanism based on the real-time network status i ;
[0233] S303. According to the calculated dynamically adjusted priority value V' i , arrange the data packets in descending order of the priority value to generate a final priority processing queue Q final ; Among them, the priority processing queue Q final includes the dynamically adjusted priority value V' of each data packet i , the weight f of the feature w and the corresponding threat level;
[0234] The collaborative processing module 104 is used to execute a collaborative response mechanism, specifically:
[0235] Monitor the status information of each node in the network. The status information includes the current processing capacity, load, and response delay. When a certain node detects a high-threat data packet, the current node generates a threat notification packet and broadcasts this threat information to other nodes. When other nodes receive the threat notification packet from the current node, other nodes will dynamically adjust the priority in their processing queues based on their own status and the received threat information. After completing the priority adjustment, other nodes update their priority processing queue Q j, and re - arrange the task processing order based on the new priority value. After other nodes complete the threat response, generate a feedback information packet and feedback it to the central controller and other relevant nodes; wherein, the high - threat data packet has a dynamic priority value V′ i exceeds the preset threshold θ;
[0236] The node processing module 105 is used to execute its priority queue Q for each node after the collaborative response is triggered j for the high - threat data packets in it, and preferentially process the data packet with the highest priority V j ″. After each node completes the task processing, generate feedback information and feedback it to the central controller and other collaborative nodes. The central controller adjusts the future priority allocation, resource scheduling, and node collaboration strategy according to the feedback information provided by each node and in combination with the historical processing results;
[0237] The adaptive optimization module 106 is used to perform adaptive optimization according to the feedback information in combination with the historical feedback information.
[0238] In summary, the present invention proposes a priority dynamic processing and collaborative response system based on intelligent threat situation awareness. The system integrates multiple data sources (such as intrusion detection systems, user behavior analysis, and network traffic monitoring), evaluates the threat level of each data packet in real - time, and dynamically adjusts its processing priority accordingly. Different from traditional static methods, the present invention uses advanced machine learning algorithms to be able to perform dynamic evaluation in multiple dimensions, timely identify high - risk data packets and preferentially process them. This mechanism significantly improves the system's response ability to new and complex attacks. At the same time, the present invention also introduces a multi - node collaborative attack response mechanism. When a node detects abnormal traffic, it can automatically notify other nodes and share threat situation information, thus achieving a fast collaborative response. This integrated innovation not only enhances the overall security of the network, but also optimizes the data packet processing efficiency, effectively solves the main defects in traditional network security systems, and provides new ideas for building a more secure and flexible network environment.
[0239] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.
Claims
1. A priority asynchronous processing method for network security, characterized in that: The method comprises: S1. Collect real-time data by using a stream processing framework, preprocess the real-time data, and output the preprocessed data, where the preprocessed data is a data set, and the data set includes selected features and a label for each feature; S2. The selected features are combined into a feature data set and a corresponding label data set. A weighted scoring algorithm is designed for the feature data set and the corresponding label data set. The weight of each feature is calculated by analyzing the mutual information of the features and the historical attack detection rate. The weighted feature set of each feature is obtained according to the weight of each feature. Then, a threat classification model is constructed to calculate the threat score of each feature. The threat level of each feature is obtained by comparing the threat score of each feature with the dynamic threshold. S3. Assign priority weights to each data packet based on the threat level of each feature combined with the current network load status, historical processing records, and current security risks. Then adjust the priority weight of each data packet based on the weighted feature set of each feature and the real-time network status. Finally, arrange the data packets from high to low priority to generate the final priority processing queue to ensure that high-priority threats are processed first. Wherein, the S3 specifically includes: S301. Introduce impact factor ξ according to the threat level of each feature i , assign a priority weight P to each packet L , ensuring that the highest threat data packets receive the highest processing priority; S302: Allocate priority weight P to each data packet L Combine the weight of each feature to calculate the priority value V i , the priority value V i Combined with the dynamic environment of the network, an adjustment mechanism based on real-time network status is designed to ensure that the processing order is dynamically adjusted when the load is high, and the dynamic priority value V' adjusted by the adjustment mechanism based on real-time network status is output i ; S303, based on the calculated dynamic priority value V′ i , sort the data packets from high to low according to the priority value, and generate the final priority processing queue Q final ; Wherein, the priority processing queue Q final Includes the dynamic priority value V' of each data packet i , the weight of the feature f w and corresponding threat levels; S4. Implement the coordinated response mechanism, specifically: Monitor the status information of each node in the network, which includes the current processing capacity, load and response delay. When a node detects a high-threat data packet, the current node generates a threat notification packet and broadcasts the threat information to other nodes. When other nodes receive the threat notification packet from the current node, they will dynamically adjust the priority of their processing queue based on their own status and the received threat information. After completing the priority adjustment, other nodes update their priority processing queue Q j , and rearrange the task processing order based on the new priority value, and generate a feedback information packet after other nodes complete the threat response, and feed it back to the central controller and other related nodes; wherein the high threat data packet is a dynamic priority value V′ i Exceeding a preset threshold value θ; S5. After the coordinated response is triggered, each node needs to execute its priority queue Q j High-threat packets in the V j After completing the task processing, each node generates feedback information and feeds it back to the central controller and other collaborative nodes. The central controller adjusts the future priority allocation, resource scheduling and node collaboration strategy based on the feedback information provided by each node and the historical processing results. S6. Perform adaptive learning based on the feedback information and historical feedback information.
2. A priority asynchronous processing method for network security according to claim 1, characterized in that: The real-time data includes: network traffic and potential attack behaviors in the network traffic, user behavior patterns and abnormal behaviors in the user behavior patterns, and real-time network data packets; The preprocessing includes: data cleaning and standardization processing, using mutual information measurement to evaluate the correlation between each feature and the label after standardization processing, the label is normal traffic or attack traffic, selecting the top k features with higher correlation, and then performing PCA dimensionality reduction processing on the selected features, and finally outputting the preprocessed data.
3. A priority asynchronous processing method for network security according to claim 1, characterized in that: The weighted scoring algorithm is expressed as follows: W i =α·I(F i ,Y)+β·T i +γ·R i Among them, I(F i ,Y) is the feature F i The mutual information with label Y reflects the contribution of the feature to attack identification; T i For feature F i Attack detection rate in historical data; R i is a regular term, indicating the feature F i The stability in the most recent time window is calculated as the inverse of the feature change rate; α, β, γ are weight coefficients to ensure the balance between stability and contribution; The threat classification model is constructed as follows: Decision tree, random forest and support vector machine are selected as basic classifiers to output the threat score S of each sample. The calculation formula is: Among them, C m (F w ) represents the weighted feature set F of the mth basic classifier w The classification result, M is the number of basic classifiers; Add a regular term R to the threat classification model S , which is used to adjust the model's sensitivity to abnormal samples. The calculation formula for the modified score S′ is: S′=S-λ·R S Among them, λ is a hyperparameter, R S is the ratio of anomaly classifications in historical data by the model.
4. A priority asynchronous processing method for network security according to claim 3, characterized in that: After calculating the threat score of each feature, a dynamic threshold calculation mechanism based on the ROC curve is used, which is expressed as follows: θ=median(S′)+k·std(S′)+δ Among them, δ is a specific adjustment factor, which depends on the change of attack mode in the recent period of time By comparing the current threat score S′ with the dynamic threshold θ, the threat level L of each sample is obtained, which is defined as:
5. A priority asynchronous processing method for network security according to claim 1, characterized in that: According to the threat level of each feature, the impact factor ξ is introduced i , assign a priority weight P to each packet L , the specific allocation is as follows: Among them, P low ,P medium ,P high is the preset basic priority value; i is the impact factor, defined as: Among them, λ is the adjustment coefficient of the historical processing load, η(t) represents the current system network load, ensuring that the system can adjust the priority more sensitively when the load is high; According to each data packet, a priority weight P is assigned L Combine the weight of each feature to calculate the priority value V i , set up as follows: Among them, W j The feature f w The weight of (j); f w (j) is the value of the jth weighted feature; φ is a regularization term, which is expressed as a confidence adjustment term for high-weight features; Z is a normalization constant used to normalize the priority value V i Adjust to a reasonable scale; The priority value V i Combined with the dynamic environment of the network, an adjustment mechanism based on real-time network status is designed to ensure that the processing order is dynamically adjusted when the load is high, and the dynamic priority value V' adjusted by the adjustment mechanism based on real-time network status is output i , which is expressed as follows: V′ i =V i +Δ(t)·θ(t) Among them, Δ(t) is the real-time adjustment coefficient, which is calculated based on the current network load, network security situation and data packet arrival rate; θ(t) is the security adjustment coefficient dynamically updated according to traffic and threat type; The changing trend of the real-time changing adjustment coefficient Δ(t) is that when the load increases, the Δ(t) value increases, and the data packets with high priority are processed first.
6. A priority asynchronous processing method for network security according to claim 1, characterized in that: The threat notification package T i Contains the key features, priority, source, current node status and threat confidence of the current node; the threat confidence of the current node λ i Indicates the urgency of the threat, and the calculation formula is: Among them, R i (t) is the response time of the node; When other nodes receive a threat notification packet from a node, the node will dynamically adjust the priority of its processing queue based on its own state and the received threat information, as shown below: According to the load, capability and received threat confidence λ of node j i Adjust to the new priority value V j ″, calculated as follows: Among them, V′ i The dynamic priority value reported for node i; is the current load factor of node j, which is used to balance the processing capacity of nodes and prevent high-load nodes from receiving more high-priority tasks; i is the threat confidence of node i.
7. A priority asynchronous processing method for network security according to claim 6, characterized in that: According to the new priority value V j After the priority is adjusted, a dynamic resource allocation algorithm is introduced for the node: The node dynamically adjusts the available resources R according to the threat level and current load j (t), the calculation formula is: in, is the maximum available resource of node j; α is the adjustment parameter used to control the allocation rate of response resources; V j ″ is the adjusted priority, θ is the threshold of resource allocation.
8. A priority asynchronous processing method for network security according to claim 1, characterized in that: The S5 specifically includes: S501, in the coordinated response trigger, the current node needs to be based on the current load state S j (t) Dynamically allocate resources, each node based on its processing capacity C j (t) and load condition L j (t), for data packet P i Perform resource allocation and introduce dynamic adjustment factor ρ j (t) Adjust available resources according to load changes; S502, after completing task processing, each node generates feedback information and adds an execution quality score to quantify the node task processing efficiency, which is expressed as follows: Among them, μ j (t) is the execution quality score, V j ″(i) is the final priority value of the current task, R j (t) is the resource consumption during task execution, D j (t) is the delay in task processing; S503. Based on the obtained execution quality score μ j (t), the central controller adjusts the priority setting of the next task, as shown below: Among them, β is the optimization step coefficient, which controls the amplitude of priority adjustment; λ j (t) is the urgency processing result of the task, reflecting whether the task is successfully processed; θ' is the priority adjustment threshold, and the priority is adjusted according to this threshold; At the same time, the resource consumption of each task is used to optimize the future resource allocation strategy, and the resource consumption R in the feedback information is used to optimize the future resource allocation strategy. j (t), adjust the resource allocation of future tasks, expressed as follows: Among them, γ is the resource optimization step coefficient; R j (t) is the resource consumption during task processing; V j ″(i) is the priority value of the task, reflecting its importance; ζ is the expected resource consumption ratio, ensuring that resource utilization remains in a reasonable range.
9. A priority asynchronous processing method for network security according to claim 1, characterized in that: The S6 specifically includes: S601, summarizing the feedback data received by all nodes and designing a feedback matrix M to store it; S602, optimizing the priority of tasks through historical data and resource utilization, and updating future task strategies using an adaptive adjustment mechanism; S603, using incremental learning to update the feedback matrix M; S604: Introduce a feature optimization mechanism to dynamically identify new threat patterns and adapt, as shown below: Where, ΔW f represents the feature weight update amount; λ f represents the feature learning rate; L f represents the processing failure rate of this feature in historical tasks; T f Indicates the total number of times the feature is processed; ∈ indicates a constant to prevent division by zero.
10. A priority asynchronous processing system for network security, characterized in that: The system comprises: The network data collection module is used to collect real-time data by using a stream processing framework, preprocess the real-time data, and output the preprocessed data, wherein the preprocessed data is a data set, and the data set includes selected features and labels for each feature; The feature weighting module is used to group the selected features into feature data sets and corresponding label data sets, design a weighted scoring algorithm for the feature data sets and the corresponding label data sets, calculate the weight of each feature by analyzing the mutual information and historical attack detection rate of the features, obtain the weighted feature set of each feature according to the weight of each feature, and then build a threat classification model to calculate the threat score of each feature, and obtain the threat level of each feature by comparing the threat score of each feature with the dynamic threshold; The priority processing module is used to assign a priority weight to each data packet according to the threat level of each feature combined with the current network load status, historical processing records and current security risks, and then adjust the priority weight of each data according to the weighted feature set of each feature and the real-time network status. Finally, the data packets are arranged from high to low according to priority to generate the final priority processing queue to ensure that high-priority threats are processed first; The priority processing module specifically performs the following steps: S301. Introduce impact factor ξ according to the threat level of each feature i , assign a priority weight P to each packet L , ensuring that the highest threat data packets receive the highest processing priority; S302: Allocate priority weight P to each data packet L Combine the weight of each feature to calculate the priority value V i , the priority value V i Combined with the dynamic environment of the network, an adjustment mechanism based on real-time network status is designed to ensure that the processing order is dynamically adjusted when the load is high, and the dynamic priority value V' adjusted by the adjustment mechanism based on real-time network status is output i ; S303, based on the calculated dynamic priority value V′ i , sort the data packets from high to low according to the priority value, and generate the final priority processing queue Q final ; Wherein, the priority processing queue Q final Includes the dynamic priority value V' of each data packet i , the weight of the feature f w and corresponding threat levels; The collaborative processing module is used to execute the collaborative response mechanism, specifically: Monitor the status information of each node in the network, which includes the current processing capacity, load and response delay. When a node detects a high-threat data packet, the current node generates a threat notification packet and broadcasts the threat information to other nodes. When other nodes receive the threat notification packet from the current node, they will dynamically adjust the priority of their processing queue based on their own status and the received threat information. After completing the priority adjustment, other nodes update their priority processing queue Q j , and rearrange the task processing order based on the new priority value, and generate a feedback information packet after other nodes complete the threat response, and feed it back to the central controller and other related nodes; wherein the high threat data packet is a dynamic priority value V′ i Exceeding a preset threshold value θ; The node processing module is used to execute the priority queue Q of each node after the coordinated response is triggered. j High-threat packets in the V j After completing the task processing, each node generates feedback information and feeds it back to the central controller and other collaborative nodes. The central controller adjusts the future priority allocation, resource scheduling and node collaboration strategy based on the feedback information provided by each node and the historical processing results. The adaptive optimization module is used to perform adaptive optimization according to the feedback information combined with historical feedback information.
Citation Information
Patent Citations
Method for transmitting and sharing threat information based on dynamic attack surface
CN111683057A
Network security monitoring and response system
CN118118258A