Network security isolation method, computer device and storage medium

By using quantum computing frameworks and machine learning models for network threat detection and isolation, the problem that static isolation strategies cannot cope with complex threats is solved, and efficient and dynamic network security protection is achieved.

CN119449406BActive Publication Date: 2025-11-18BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411559805.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-04
Publication Date
2025-11-18
Estimated Expiration
2044-11-04

AI Technical Summary

Technical Problem

Existing static isolation strategies and rules are unable to effectively cope with the rapid changes and diversification of network threats, resulting in reduced network protection reliability.

Method used

A quantum computing framework is used to extract features from network monitoring data, a quantum machine learning model is used for threat detection, a dynamic isolation strategy is generated when a threat is detected, and a self-healing mechanism is used for repair operations.

Benefits of technology

It enables higher-dimensional threat pattern capture and rapid detection, improves the effectiveness of isolation strategies and the resilience and adaptability of the system, and ensures business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449406B_ABST
    Figure CN119449406B_ABST
Patent Text Reader

Abstract

The application discloses a network security isolation method, a computer device and a storage medium, and relates to the technical field of network security, which can realize more accurate and efficient threat detection. If a security threat exists, the influence object of the security threat is determined, an isolation strategy is generated according to the type of the influence object, the isolation strategy is dynamically generated, the isolation strategy is more in line with the characteristics of the influence object, the effectiveness of the isolation strategy is improved, and if the security threat is removed, a repair operation is performed on the influence object based on a self-recovery mechanism, the flexibility and adaptability of the system can be improved, and the continuity of business can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a network security isolation method, a computer device and a storage medium. BACKGROUND

[0002] With the increasing complexity and diversification of network attack means, the traditional network security isolation method relying on static isolation strategy and rules has been difficult to respond to the rapid changes and new threats, reducing the reliability of network protection. SUMMARY

[0003] The embodiments of the present application provide a network security isolation method, a computer device and a storage medium, feature extraction is performed on network monitoring data based on a quantum computing framework to obtain target feature data, and a quantum machine learning model is used to determine whether there is a security threat in a target network according to the target feature data, so as to more accurately and efficiently perform threat detection.

[0004] In a first aspect, a network security isolation method is provided, including: collecting network monitoring data from a target network according to a target data type; performing feature extraction on the network monitoring data based on a quantum computing framework to obtain target feature data; using a quantum machine learning model to determine whether there is a security threat in the target network according to the target feature data; if the security threat exists, determining an impact object of the security threat, generating an isolation strategy according to a type of the impact object; performing an isolation operation on the impact object according to the isolation strategy; and if the security threat is removed, performing a repair operation on the impact object based on a self-healing mechanism.

[0005] In a second aspect, a computer readable storage medium is provided, which stores a computer program / instruction, and the computer program / instruction is executed by a processor to implement the steps of the network security isolation method according to the first aspect.

[0006] In a third aspect, a computer program product is provided, which includes a computer program / instruction, and the computer program / instruction is executed by a processor to implement the steps of the network security isolation method according to the first aspect.

[0007] By applying the above technical solution, the network monitoring data is subjected to feature extraction based on a quantum computing framework to obtain target feature data; a quantum machine learning model is used to determine whether there is a security threat in the target network according to the target feature data, which can capture complex threat patterns in higher dimensions and quickly detect potential threats, thereby achieving more accurate and efficient threat detection. If there is a security threat, the impact object of the security threat is determined, and an isolation strategy is generated according to the type of the impact object, so as to dynamically generate the isolation strategy and make the isolation strategy more in line with the characteristics of the impact object, thereby improving the effectiveness of the isolation strategy. Moreover, if the security threat is removed, a repair operation is performed on the impact object based on a self-healing mechanism, which can improve the flexibility and adaptability of the system and improve the continuity of the business. BRIEF DESCRIPTION OF DRAWINGS

[0008] In order to more clearly illustrate the technical solutions of the present application, the drawings needed in the following embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0009] Figure 1 Flowchart of the network security isolation method of the embodiment of the present application;

[0010] Figure 2 Flowchart of the network security isolation method of another embodiment of the present application;

[0011] Figure 3 Flowchart of determining the quantum machine learning model of the embodiment of the present application;

[0012] Figure 4 Flowchart of updating the quantum machine learning model of the embodiment of the present application;

[0013] Figure 5 Schematic diagram of the zero trust architecture;

[0014] Figure 6 Structural block diagram of the computer device of the embodiment of the present application. DETAILED DESCRIPTION

[0015] The various schemes and features of the present application are described herein with reference to the accompanying drawings.

[0016] It should be understood that various modifications can be made to the embodiments of the present application. Therefore, the above description should not be regarded as limiting, but only as an example of the embodiments. Those skilled in the art will think of other modifications within the scope and spirit of the present application.

[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the application and, together with the general description of the application given above, and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0018] These and other characteristics of the present application will become apparent from the following description and the associated drawings, wherein the preferred forms of the application are given, by way of non-limiting examples.

[0019] It should also be understood that, although the present application has been described above with reference to particular means, materials and embodiments, the present application is by no means limited to the particulars described and as such extends to all alternative constructions falling within the scope of the application.

[0020] The above and other aspects, features and advantages of the present application will become apparent from the following detailed description, taken in conjunction with the accompanying drawings, which illustrate by way of non-limiting examples various embodiments of the present application.

[0021] Specific embodiments of the present application are described hereinafter, by way of non-limiting examples; however, it should be understood that the application is not limited to the particular embodiments described, as such can be practiced with modification and alteration, and is not limited by the details of the description.

[0022] The description herein can use the phrases "in one embodiment," "in another embodiment," "in yet another embodiment," or "in at least one embodiment," which can refer to one or more of the same or different embodiments of the application.

[0023] The network security isolation method of the embodiment of the present application extracts features from network monitoring data based on a quantum computing framework to obtain target feature data; determines whether there is a security threat in the target network according to the target feature data by using a quantum machine learning model, can capture complex threat patterns in higher dimensions, and can quickly detect potential threats, thereby realizing more accurate and efficient threat detection. If there is a security threat, the impact object of the security threat is determined, and an isolation strategy is generated according to the type of the impact object, so as to dynamically generate the isolation strategy, make the isolation strategy more in line with the characteristics of the impact object, improve the effectiveness of the isolation strategy, and if the security threat is removed, perform a repair operation on the impact object based on a self-healing mechanism, which can improve the flexibility and adaptive ability of the system and improve the continuity of the business.

[0024] As shown in Figure 1 the following steps are included:

[0025] Step S101: Collect network monitoring data from the target network according to the target data type.

[0026] In this embodiment, the target data type can be determined based on the tasks or activities existing in the target network. The target data type may include one or more data types such as network traffic, user behavior logs, and system events. Specifically, network monitoring data conforming to the target data type can be collected by writing data collection scripts, deploying sensors, agents, or data collectors, or by utilizing API interfaces, ensuring comprehensive coverage of all activities in the target network.

[0027] In some embodiments of this application, after obtaining network monitoring data, preprocessing is also included to improve the accuracy of the network monitoring data. Preprocessing may include, for example, cleaning, standardization, noise reduction, and feature extraction. Specifically, algorithms such as denoising algorithms, feature scaling algorithms, and feature extraction algorithms can be used to clean, deduplicate, normalize, and transform the data to ensure the quality and consistency of the network monitoring data.

[0028] Step S102: Based on the quantum computing framework, feature extraction is performed on the network monitoring data to obtain target feature data.

[0029] In this embodiment, network monitoring data is input into a quantum computing framework. Based on the characteristics of quantum superposition and quantum entanglement in the quantum computing framework, useful feature patterns (such as potential attack features) are quickly identified to obtain target feature data.

[0030] Step S103: Using a quantum machine learning model, determine whether there is a security threat in the target network based on the target feature data.

[0031] In this embodiment, a quantum machine learning model for threat detection is pre-trained. This model combines the unique characteristics of quantum computing (such as quantum superposition and quantum entanglement) with the pattern recognition capabilities of classical machine learning, enabling it to achieve faster processing speeds and better performance than traditional machine learning algorithms in solving specific problems. The quantum machine learning model can include any of the following: Quantum Support Vector Machine (Quantum SVM), Quantum Neural Network (QNN), etc. This embodiment utilizes the quantum machine learning model to capture complex threat patterns in higher dimensions, and can even identify subtle anomalies in advanced persistent threats (APTs). The efficient processing power of quantum algorithms allows for detailed analysis of real-time traffic in isolated systems, enabling early detection of potential attack behaviors.

[0032] The target feature data is input into the quantum machine learning model, and whether a security threat exists in the target network is determined according to an output result of the quantum machine learning model. The quantum machine learning model can automatically classify and identify different types of security threats, such as malware attacks, abnormal traffic, denial-of-service attacks (DDoS), unauthorized access, data leakage, and the like.

[0033] In step S104, if the security threat exists, an affected object of the security threat is determined, and an isolation strategy is generated according to a type of the affected object.

[0034] In this embodiment, the type of the affected object can include any one of an application, a device, an operating system, a network area, and the like. For example, the affected object can be one or more applications, one or more devices, or one or more network areas. The isolation strategy is generated according to the type of the affected object to isolate the affected object.

[0035] In step S105, an isolation operation is performed on the affected object according to the isolation strategy.

[0036] The isolation operation is performed on the affected object according to the isolation strategy to prevent the security threat from spreading to other applications, other devices, other network areas, and the like. The isolation operation can include one or more of adjusting a network partition of the affected object, adjusting a firewall configuration of the affected object, logically isolating the affected object, adjusting an access control policy of the affected object, and the like.

[0037] In step S106, if the security threat is removed, a repair operation is performed on the affected object based on a self-healing mechanism.

[0038] In this embodiment, the self-healing mechanism is established in advance. If the security threat is removed, the repair operation is performed on the affected object based on the self-healing mechanism. Specifically, the self-healing mechanism integrates the previously isolated affected object into the system to ensure normal operation. This process is subjected to strict security verification to ensure that the system is in a secure state, thereby significantly improving the resilience and adaptability of the system. After the security threat is removed, the self-healing mechanism can quickly restore the normal operation of the isolated affected object, helping the network to automatically recover when attacked or malfunctioning, maintaining the security and normal operation of the system, and ensuring the continuity of critical business.

[0039] The network security isolation method of the embodiment of the present application collects network monitoring data from the target network according to the target data type, extracts features of the network monitoring data based on a quantum computing framework to obtain target feature data, determines whether there is a security threat in the target network according to the target feature data by using a quantum machine learning model, can capture complex threat patterns in higher dimensions and quickly detect potential threats, thereby realizing more accurate and efficient threat detection. If there is a security threat, the impact object of the security threat is determined, and an isolation strategy is generated according to the type of the impact object, so as to dynamically generate an isolation strategy, make the isolation strategy more in line with the characteristics of the impact object, improve the effectiveness of the isolation strategy, and if the security threat is removed, perform a repair operation on the impact object based on a self-healing mechanism, which can improve the flexibility and adaptive ability of the system and improve the continuity of the business.

[0040] In some embodiments of the present application, performing a repair operation on the impact object based on a self-healing mechanism includes at least one of the following:

[0041] Identifying and replacing tampered system files in the impact object;

[0042] Automatically restoring the security configuration of the impact object;

[0043] If the security threat belongs to malware or a virus, automatically removing or isolating infected files in the impact object;

[0044] If the security threat belongs to a system vulnerability, automatically applying a patch corresponding to the system vulnerability in the impact object.

[0045] In the embodiment, if there are tampered system files in the impact object, the self-healing mechanism can identify and replace the tampered system files to restore the system files of the impact object to normal. If the security configuration of the impact object has changed, the self-healing mechanism can automatically restore the security configuration. If the security threat belongs to malware or a virus, the self-healing mechanism can automatically remove or isolate infected files in the impact object. If the security threat belongs to a system vulnerability, the self-healing mechanism can automatically apply a patch corresponding to the system vulnerability in the impact object to repair the corresponding system vulnerability.

[0046] It can be understood that, according to the degree of security threat, the repair operation performed on the affected object based on the self-recovery mechanism can be one or more, for example, after the security threat is removed, for an affected object, the self-recovery mechanism identifies and replaces the tampered system file in the affected object; and automatically restores the security configuration of the affected object. Alternatively, the security threat belongs to malware or virus, and there are tampered system files and infected files in the affected object, then the self-recovery mechanism identifies and replaces the tampered system file in the affected object, and automatically removes or isolates the infected file in the affected object.

[0047] By adopting at least one of a plurality of repair operations to perform the modification operation on the affected object, a more flexible and accurate repair operation is realized.

[0048] In some embodiments of the present application, the isolation strategy is generated according to the type of the affected object, comprising:

[0049] If the type of the affected object is a device or an application, the isolation strategy includes isolating the affected object from other systems to prevent the security threat from spreading to other parts of the network;

[0050] If the type of the affected object is a network area, the isolation strategy includes creating a virtual isolation zone for isolating the network area to isolate the network area.

[0051] In this embodiment, the type of the affected object includes devices, applications, network areas, etc. If the type of the affected object is a device or an application, the corresponding device or application needs to be isolated to prevent the security threat from spreading to other parts of the network. If the type of the affected object is a network area, the corresponding network area needs to be isolated, specifically, a virtual isolation zone is created for isolating the network area to isolate the network area.

[0052] By adopting the corresponding isolation strategy according to the type of the affected object, the isolation strategy is matched with the characteristics of the affected object, ensuring the effectiveness of the isolation strategy.

[0053] In some embodiments of the present application, after performing the isolation operation on the affected object according to the isolation strategy, as shown in Figure 2 The method further comprises the following steps:

[0054] Step S107, collecting post-isolation network data related to the affected object.

[0055] In this embodiment, the post-isolation network data can include one or more of network traffic, user behavior logs, system events, etc. related to the affected object, so as to evaluate the isolation effect and the impact on normal business according to the post-isolation network data.

[0056] Step S108, if the isolated network data meets a policy adjustment condition, adjusting the isolation policy.

[0057] In this embodiment, the policy adjustment condition can include at least one of the following: the abnormal network data related to the influence object still exists in the isolated network data; and the isolated network data represents an impact on normal business. The adjustment of the isolation policy includes at least one of the following: performing a further isolation operation; and adjusting the isolation range corresponding to the isolation policy.

[0058] By adjusting the isolation policy when the isolated network data meets the policy adjustment condition, the dynamic adjustment of the isolation policy is realized, so that the isolation policy is more in line with the actual situation of the influence object or the current network environment, and the effectiveness and accuracy of the isolation policy are ensured.

[0059] In some embodiments of the present application, as shown in Figure 3 The determination process of the quantum machine learning model includes the following steps:

[0060] Step S201, obtaining historical network data within a preset time period.

[0061] In this embodiment, the quantum machine learning model is obtained by training the initial quantum machine learning model using the historical network data within the preset time period. The preset time period can be, for example, one month or half a month. The historical network data can include one or more of the data types of network traffic, user behavior logs, system events, etc. The historical network data can be collected by writing a data collection script, deploying a sensor, an agent or a data collector, or using an API interface, etc.

[0062] Step S202, preprocessing the historical network data according to a target preprocessing process to generate a training data set.

[0063] In this embodiment, by preprocessing the historical network data according to the target preprocessing process, the data quality and consistency of the historical network data can be ensured. The preprocessing can include cleaning, standardization, noise reduction and feature extraction, and specifically, de-noising algorithms, feature scaling algorithms, feature extraction algorithms, etc. can be used to clean, remove duplicates, normalize and convert data. After preprocessing the historical network data, a training data set is generated, which contains normal behavior samples and known attack samples.

[0064] Step S203, performing feature extraction on the training data set based on the quantum computing framework to obtain sample target feature data.

[0065] In this embodiment, the training data set is input into the quantum computing framework, and the quantum superposition state and quantum entanglement characteristics of the quantum computing framework are used to extract features of the training data set to obtain sample target feature data.

[0066] In step S204, the initial quantum machine learning model is trained based on the target quantum algorithm according to the sample target feature data.

[0067] In this embodiment, after obtaining the sample target feature data, the sample target feature data is input into the initial quantum machine learning model, and the initial quantum machine learning model is trained based on the target quantum algorithm.

[0068] The target quantum algorithm can be a quantum search algorithm, which is a new algorithm for computing using quantum mechanical properties and can efficiently search for specific elements in an unordered database. The quantum search algorithm can be, for example, a Grover algorithm. Training the initial quantum machine learning model based on the target quantum algorithm can find a global optimal solution in a shorter time, thereby accelerating the convergence of the initial quantum machine learning model.

[0069] In step S205, the quantum machine learning model is obtained when the training completion condition is met.

[0070] In this embodiment, the training completion condition can be a target iteration number, or the recognition accuracy of the model can reach a target accuracy.

[0071] The training data set is extracted by the quantum computing framework, and the initial quantum machine learning model is trained based on the target quantum algorithm according to the sample target feature data, thereby realizing efficient and accurate determination of the quantum machine learning model.

[0072] In some embodiments of the present application, after performing the isolation operation on the influence object according to the isolation policy, as shown in Figure 4 the following steps are further included:

[0073] In step S206, feedback data after performing the isolation operation is collected, and the feedback data includes at least one of the success rate of isolation, the false positive rate, and the false negative rate.

[0074] In this embodiment, after performing the isolation operation on the influence object according to the isolation policy, feedback data is collected, and the quantum machine learning model is updated through the feedback data. The feedback data includes at least one of the success rate of isolation, the false positive rate, and the false negative rate.

[0075] In step S207, the feedback data is added to the training data set to generate a new training data set.

[0076] In this embodiment, the feedback data is added to the training data set to generate a new training data set, so that the new training data set covers the data related to the current isolation operation.

[0077] In step S208, the quantum machine learning model is retrained based on the new training data set to update the quantum machine learning model.

[0078] In this embodiment, the new training data set is feature extracted based on the quantum computing framework to obtain new sample target feature data. Based on the target quantum algorithm, the quantum machine learning model is retrained according to the new sample target feature data to optimize the parameters of the quantum machine learning model, thereby updating the quantum machine learning model.

[0079] The new training data set is generated by the feedback data after the isolation operation, which realizes the continuous optimization of the quantum machine learning model, so that the quantum machine learning model can adapt to new threat forms, and improves the identification ability and response speed of the quantum machine learning model to security threats.

[0080] In some embodiments of the present application, the isolation strategy conforms to the zero trust architecture.

[0081] In this embodiment, under the zero trust architecture, it is assumed that there may be threats inside and outside the network, and any network traffic, device or user inside and outside the network is not trusted. All access must be authenticated and authorized. Through the zero trust architecture, network security isolation is strengthened, and through fine-grained access management, dynamic monitoring and continuous verification, the security of the network is significantly enhanced. Any device or user must go through a strict verification process to access network resources, thereby further improving the effectiveness of the isolation strategy.

[0082] As shown in Figure 5 The schematic diagram of the zero trust architecture is shown in Figure 5 As shown in

[0083] The core components of the zero trust architecture include a control and management module and a policy enforcement point. The control and management module is composed of an identity verification, a policy engine and a policy manager. The identity verification is used to verify the identity of a subject / device and determine whether the identity is legal. The policy engine is mainly responsible for comprehensive analysis of multi-dimensional risk information and finally decides whether to grant the specified access subject access to the object. The policy manager is responsible for establishing a logical connection between the access subject and the object, generating a credential for the subject to access the object, and communicating with the policy enforcement point to execute the policy through the policy enforcement point. The policy enforcement point determines whether to allow the subject / device to access the target resource according to the policy issued by the policy manager, and can be played by multiple components such as terminal agent and gateway.

[0084] In some embodiments of the present application, after performing the repair operation on the affected object based on the self-healing mechanism, the operation data related to all threat detection, policy generation and isolation execution are recorded, and the operation data are used to generate an auditable log. All related activity logs are recorded and stored using a log management system (such as SIEM) to ensure the transparency and traceability of system operation; the logs are periodically designed and analyzed by security audit tools and AI analysis to identify potential weaknesses in the system and provide optimization suggestions.

[0085] The network security isolation method of the embodiments of the present application can ensure that the system can be seamlessly integrated with the existing security infrastructure of the enterprise (such as firewall, IDS / IPS, SIEM) by using open API, modular design and compatibility protocol, and can work with traditional security tools to form a more powerful defense system.

[0086] For example, the target network can be the internal network of a bank, and the network monitoring data can be the traffic between various branch agencies and departments. Feature extraction is performed on the traffic between the various branch agencies and departments based on the quantum computing framework to obtain target feature data; a quantum machine learning model is used to determine whether there is a security threat in the internal network of the bank according to the target feature data; if an abnormal traffic pattern of a branch agency is detected (which may be caused by a malicious software infection), the network of the branch is automatically isolated, and the traffic is directed to the isolation area to prevent the threat from spreading to the entire bank network. If the security threat is removed, the infected files in the affected object are automatically removed or isolated, and the corresponding security configuration is restored. At the same time, the network data after isolation is collected, and the isolation strategy is dynamically adjusted according to the business needs of different departments to ensure that normal business is not affected.

[0087] The target network can also be a cloud computing platform. On a cloud computing platform, different tenants typically share the same physical resources, but each tenant's data and applications need to be strictly isolated to prevent data breaches or cross-tenant attacks. Network monitoring data can measure the network behavior of each tenant. Based on a quantum computing framework, feature extraction is performed on the network behavior of each tenant to obtain target feature data. Using a quantum machine learning model, the existence of security threats in the bank's internal network is determined based on the target feature data. If a tenant's application experiences abnormal traffic (such as a DDoS attack), the tenant is automatically isolated, and its access to shared resources is restricted. If the security threat is eliminated, a self-healing mechanism identifies and replaces the tampered system files of the corresponding tenant. Simultaneously, isolated network data is collected, and the isolation strategy is dynamically adjusted based on the isolated network data to adapt to the dynamic needs of each tenant, ensuring the overall security and stability of the cloud platform.

[0088] The target network can also be an enterprise network. Large enterprises typically have multiple departments and branches. Preventing malicious behavior by internal employees or lateral movement by external attackers after intrusion is a significant challenge for enterprise network security. Network monitoring data can be employee network behavior. Based on a quantum computing framework, features of each employee's network behavior are extracted to obtain target feature data. Using a quantum machine learning model, the presence of security threats within the bank's internal network is determined based on the target feature data. If abnormal activity is detected (such as data breach attempts or unauthorized access), the relevant employee's terminal device is automatically isolated, and their access permissions are restricted. If the security threat is eliminated, the security configuration of the relevant employee's terminal device is automatically restored based on a self-healing mechanism. Simultaneously, isolated network data is collected, and the isolation strategy is dynamically adjusted based on this data to balance security requirements and business efficiency, ensuring the overall security of the enterprise network.

[0089] The network security isolation method in this application embodiment has the following beneficial effects:

[0090] 1) Enhanced Threat Detection Accuracy: The introduction of quantum machine learning models enables more accurate identification and classification of cyber threats, especially when dealing with complex and emerging threats. By learning from large amounts of data, quantum machine learning models can discover anomalous patterns and identify hidden threats. For example, they can detect zero-day attacks and advanced persistent threats (APTs), which are often undetectable by traditional methods.

[0091] 2) Real-time dynamic response and automated isolation: Quantum machine learning models enable network security systems to automatically perform isolation operations the moment a threat is detected, without human intervention. This real-time response capability effectively shortens the time attackers are present in the network, preventing further threat spread. Once abnormal traffic is detected in the network, the system can automatically isolate infected devices or users, preventing attackers from further infiltrating the network through lateral movement.

[0092] 3) Reduced human error and improved operational efficiency: Automated threat detection and isolation reduce reliance on human judgment, thereby lowering the risk of human error. Simultaneously, the system can operate 24 / 7, ensuring the continued effectiveness of network security measures. In complex enterprise networks, quantum machine learning models can replace security experts in many demanding monitoring and response tasks, improving overall operational efficiency.

[0093] 4) Continuous Learning and Adaptation to Emerging Threats: The quantum machine learning model can autonomously update and optimize detection strategies over time by continuously learning from new network data and threat intelligence. This continuous learning capability enables the system to adapt to new and evolving network threats. When faced with a new attack method, the system can analyze the characteristics of that attack method and update existing detection and isolation strategies to ensure effective responses to similar threats in the future.

[0094] 5) Enhancing the comprehensiveness and scalability of network security: Quantum machine learning models can integrate multiple data sources and security tools to form a comprehensive security protection system applicable to network environments of varying sizes and complexities. This scalability ensures that effective network security isolation solutions can be deployed by both small businesses and large organizations. In large-scale enterprise networks or cloud computing environments, quantum machine learning models can monitor and isolate threats in multiple regions or among multiple tenants in real time, ensuring the overall security of the network.

[0095] 6) Enhanced Internal Threat Protection: Quantum machine learning models can better monitor and analyze internal user behavior, detect potential internal threats, and take timely isolation measures. This helps prevent malicious actions by insiders or security incidents caused by compromised internal devices. When the system detects abnormal behavior from an internal user, it can quickly reduce that user's access permissions to a minimum, protecting sensitive data from potential threats.

[0096] This application also proposes a network security isolation device, comprising: a collection module for collecting network monitoring data from a target network according to the target data type; an acquisition module for extracting features from the network monitoring data based on a quantum computing framework to obtain target feature data; a determination module for determining whether a security threat exists in the target network based on the target feature data using a quantum machine learning model; a generation module for determining the affected objects of the security threat if the security threat exists, and generating an isolation strategy based on the type of the affected objects; an isolation module for performing isolation operations on the affected objects according to the isolation strategy; and a self-healing module for performing repair operations on the affected objects based on a self-healing mechanism if the security threat is eliminated.

[0097] The network security isolation device in this application embodiment extracts features from network monitoring data using a quantum computing framework to obtain target feature data. Utilizing a quantum machine learning model, it determines whether a security threat exists in the target network based on the target feature data. This allows for the capture of complex threat patterns at a higher dimension and rapid detection of potential threats, resulting in more accurate and efficient threat detection. If a security threat exists, the device identifies the affected objects and generates isolation strategies based on the type of affected objects. This dynamic generation of isolation strategies better matches the characteristics of the affected objects, improving their effectiveness. Furthermore, if the security threat is eliminated, a self-healing mechanism is used to repair the affected objects, enhancing the system's resilience and adaptability, and improving business continuity.

[0098] In specific application scenarios, the self-healing module is specifically used to perform at least one of the following: identify and replace the tampered system files in the affected object; automatically restore the security configuration of the affected object; if the security threat is malware or a virus, automatically remove or isolate the infected files in the affected object; if the security threat is a system vulnerability, automatically apply patches corresponding to the system vulnerability in the affected object.

[0099] In specific application scenarios, the generation module is specifically used for: if the type of the affected object is a device or application, the isolation strategy includes isolating the affected object from other systems to prevent security threats from spreading to other parts of the network; if the type of the affected object is a network area, the isolation strategy includes creating a virtual isolation zone for isolating the network area to isolate the network area.

[0100] In specific application scenarios, an adjustment module is also included, which is used to: collect isolated network data related to the affected object; and adjust the isolation strategy if the isolated network data meets the policy adjustment conditions.

[0101] In specific application scenarios, the process of determining the quantum machine learning model includes: acquiring historical network data within a preset time period; preprocessing the historical network data according to the target preprocessing process to generate a training dataset; extracting features from the training dataset based on the quantum computing framework to obtain sample target feature data; training the initial quantum machine learning model based on the target quantum algorithm and the sample target feature data; and obtaining the quantum machine learning model when the training completion conditions are met.

[0102] In specific application scenarios, an update module is also included, which is used to: collect feedback data after performing isolation operations, the feedback data including at least one of isolation success rate, false alarm rate, and false negative rate; add the feedback data to the training dataset to generate a new training dataset; and retrain the quantum machine learning model based on the new training dataset to update the quantum machine learning model.

[0103] In specific application scenarios, the isolation strategy conforms to a zero-trust architecture.

[0104] This application also proposes a computer device, such as... Figure 6 As shown, it includes a memory, a processor, and a computer program stored in the memory, the processor executing the computer program to implement the steps of the network security isolation method as described in various embodiments of this application.

[0105] The computer device in this application embodiment can be a terminal or other devices besides a terminal. For example, the computer device can be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. The embodiments disclosed in this disclosure do not impose specific limitations.

[0106] The memory may include RAM (Random Access Memory) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0107] The processors mentioned above can be general-purpose processors, including CPUs, NPs (Network Processors), etc.; they can also be DSPs (Digital Signal Processors), ASICs (Application Specific Integrated Circuits), FPGAs (Field Programmable Gate Arrays), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0108] This application also proposes a computer-readable storage medium storing a computer program / instructions thereon, which, when executed by a processor, implements the steps of the network security isolation method as described in the various embodiments of this application.

[0109] This application also proposes a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the network security isolation method as described in the various embodiments of this application.

[0110] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0111] The above embodiments are merely exemplary embodiments of this application and are not intended to limit this application. The scope of protection of this application is defined by the claims. Those skilled in the art can make various modifications or equivalent substitutions to this application within its substance and scope of protection, and such modifications or equivalent substitutions should also be considered to fall within the scope of protection of this application.

Claims

1. A network security isolation method, characterized in that, include: Collect network monitoring data from the target network based on the target data type; Based on a quantum computing framework, feature extraction is performed on the network monitoring data to obtain target feature data. Using a quantum machine learning model, the existence of security threats in the target network is determined based on the target feature data. If the security threat exists, determine the affected objects of the security threat, and generate an isolation strategy based on the type of the affected objects; Isolation operations are performed on the affected objects according to the isolation strategy; If the security threat is eliminated, a repair operation is performed on the affected objects based on a self-healing mechanism.

2. The network security isolation method as described in claim 1, characterized in that, Perform repair operations on the affected object based on a self-healing mechanism, including at least one of the following: Identify and replace the tampered system files in the affected objects; Automatically restore the security configuration of the affected objects; If the security threat is malware or a virus, automatically remove or quarantine the infected files in the affected objects; If the security threat is a system vulnerability, a patch corresponding to the system vulnerability is automatically applied to the affected objects.

3. The network security isolation method as described in claim 1, characterized in that, Generate an isolation policy based on the type of the affected object, including: If the affected object is a device or application, the isolation strategy includes isolating the affected object from other systems to prevent the security threat from spreading to other parts of the network; If the affected object is a network region, the isolation strategy includes creating a virtual isolation zone to isolate the network region.

4. The network security isolation method as described in claim 1, characterized in that, After performing isolation operations on the affected objects according to the isolation policy, the method further includes: Collect isolated network data related to the affected objects; If the isolated network data meets the policy adjustment conditions, the isolation policy is adjusted.

5. The network security isolation method as described in claim 1, characterized in that, The process of determining the quantum machine learning model includes: Acquire historical network data within a preset time period; The historical network data is preprocessed according to the target preprocessing procedure to generate a training dataset; Based on the quantum computing framework, feature extraction is performed on the training dataset to obtain sample target feature data; Based on the target quantum algorithm, the initial quantum machine learning model is trained according to the target feature data of the sample; The quantum machine learning model is obtained when the training completion conditions are met.

6. The network security isolation method as described in claim 5, characterized in that, After performing isolation operations on the affected objects according to the isolation policy, the method further includes: Collect feedback data after performing isolation operations, including at least one of isolation success rate, false alarm rate, and false negative rate; The feedback data is added to the training dataset to generate a new training dataset; The quantum machine learning model is retrained based on the new training dataset to update the quantum machine learning model.

7. The network security isolation method as described in claim 1, characterized in that, The isolation strategy conforms to a zero-trust architecture.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the network security isolation method as described in any one of claims 1-7.

9. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the network security isolation method as described in any one of claims 1-7.

10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the network security isolation method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Network threat isolation method and device, equipment and storage medium

    CN117675276A

  • Network risk identification method and device, equipment and storage medium

    CN118820673A