A self-evolving network security defense strategy generation and dynamic deployment method

Through the self-evolving network security defense strategy generation and dynamic deployment methods, the challenges of data processing, feature extraction, threat identification and policy deployment in the existing technology are solved, and efficient and intelligent network security defense is achieved.

CN119561793BActive Publication Date: 2025-05-16NANJING HEDUN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510126855.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-05-16
Estimated Expiration
2045-01-27

AI Technical Summary

Technical Problem

Existing cybersecurity defense technologies are difficult to effectively deal with complex and changeable cyber attacks, especially in data processing, feature extraction, threat identification and policy deployment.

Method used

The self-evolving network security defense strategy generation and dynamic deployment method is adopted. By obtaining multi-source heterogeneous data, the optimization feature matrix is ​​constructed, the threat association matrix is ​​generated, the threat characteristics are extracted and pattern clustered, the threat propagation characteristics are analyzed, the optimal defense strategy is generated, and the dynamic deployment and feedback optimization are carried out.

Benefits of technology

Accurate threat awareness and automatic identification are achieved, and can accurately predict threat development trends and generate optimal defense strategies, which improves the intelligence level and adaptability of the defense system, and can better deal with complex and changeable network security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561793B_ABST
    Figure CN119561793B_ABST
Patent Text Reader

Abstract

The present invention discloses a self-evolving network security defense strategy generation and dynamic deployment method, including: obtaining multi-dimensional data such as original network traffic data, generating an optimized feature matrix through adaptive interval division and symbolic conversion; constructing a feature graph structure based on the optimized feature matrix, extracting threat features using a graph neural network and an attention mechanism, and generating a threat pattern set; analyzing threat propagation features according to a threat assessment indicator set and a threat association matrix, and generating a threat propagation graph; generating an initial defense strategy set based on the threat assessment result, and generating an optimized defense strategy set through dependency analysis and conflict elimination. The present invention improves the intelligence level and protection effect of network security defense through adaptive feature extraction and dynamic strategy optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the field of network security, and in particular to a self-evolving network security defense strategy generation and dynamic deployment method. Background Art

[0002] As network security threats become increasingly complex and intelligent, traditional static defense strategies and fixed deployment solutions have become difficult to cope with diverse network attacks. Modern network environments are facing complex attack forms such as advanced persistent threats (APTs), zero-day vulnerability attacks, and distributed denial of service (DDoS). These attacks are highly concealed, long-lasting, and highly harmful. Therefore, studying adaptive network security defense strategy generation and dynamic deployment methods has important theoretical and practical significance for improving network security protection capabilities and ensuring the safe and stable operation of network systems.

[0003] At present, network security defense strategy generation mainly adopts methods based on rule matching, expert experience and simple machine learning. The rule matching method uses predefined feature libraries and rule sets to identify threats and generate defense strategies, but the rule updates are lagging and the generalization ability is limited. The expert experience-based method relies on security experts to manually formulate defense strategies. Although it is highly targeted, it is difficult to meet the needs of rapid response in large-scale network environments. The simple machine learning-based method builds classification or clustering models by training historical data, but often only focuses on feature extraction from a single data source and lacks the ability to integrate and analyze multi-dimensional data. In terms of policy deployment, static deployment or simple dynamic adjustment solutions are mainly used, which lack the ability to adapt to changes in the network environment.

[0004] The existing technical solutions have the following specific problems: First, at the data processing level, the normalization of multi-source heterogeneous data often adopts a unified scale conversion rule, ignoring the differences in the distribution characteristics of data in different dimensions, resulting in unsatisfactory feature extraction effects. For example, network traffic data may be distributed in a long tail, while device status data may be close to a normal distribution. The unified processing method leads to limited feature expression capabilities. Secondly, in the feature learning process, the multi-layer feature fusion of the graph convolutional neural network has a dimension mismatch problem, which affects the model's expression ability and learning effect. For example, due to the mismatch of feature dimensions at different layers, direct addition or splicing will cause information loss; third, in terms of threat propagation modeling, directly using the correlation strength as the transition probability of the Markov chain violates the basic principles of probability theory and affects the accuracy of propagation prediction; fourth, in the feature transmission process, there is a lack of a systematic management mechanism for optimizing the mapping of feature matrices to graph structures, resulting in the loss of some feature information; finally, in the strategy deployment link, there is a lack of a complete verification mechanism and feedback optimization process, making it difficult to ensure the reliability and effectiveness of the deployment strategy. These technical problems seriously restrict the intelligence level and protection effect of network security defense systems. Summary of the invention

[0005] The purpose of the invention is to provide a self-evolving network security defense strategy generation and dynamic deployment method, in order to solve at least one technical problem existing in the prior art.

[0006] The technical solution is a self-evolving network security defense strategy generation and dynamic deployment method, comprising the following steps:

[0007] S1, obtain the original network traffic data, system log data, device status data and user behavior data, and generate an optimized feature matrix through adaptive interval division and symbolic conversion;

[0008] S2. Based on the optimized feature matrix, a feature graph structure is constructed. Based on the feature graph structure, a threat association matrix is ​​generated through a graph neural network and an attention mechanism. According to the threat association matrix, threat features are extracted and pattern clustering is performed to generate a threat pattern set.

[0009] S3, obtaining a threat pattern set, constructing a multi-dimensional evaluation index according to a preset evaluation rule, and generating a threat evaluation index set; based on the threat evaluation index set and the threat association matrix, analyzing the propagation characteristics of the threat, and obtaining a threat propagation graph;

[0010] S4. Obtain a threat assessment indicator set and a threat propagation diagram, and generate an initial defense strategy set according to a preset optimization rule; based on the initial defense strategy set, perform conflict detection and optimization processing to obtain an optimized defense strategy set.

[0011] Beneficial effects: The present invention establishes an accurate threat perception foundation, realizes automatic identification of threat patterns, can accurately predict threat development trends, generate optimal defense strategies, and realize adaptive adjustment of strategies; it not only solves the problems of data heterogeneity, feature extraction difficulties, inaccurate threat identification, and strategy conflicts in traditional defense methods, but also improves the intelligence level and adaptability of the defense system through continuous learning and optimization; compared with traditional static defense solutions, it can better cope with complex and changeable network security threats and provide more accurate and efficient defense capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 It is a flow chart of the present invention.

[0013] Figure 2 This is a flow chart of step S1 of the present invention.

[0014] Figure 3 This is a flow chart of step S2 of the present invention.

[0015] Figure 4 This is a flow chart of step S3 of the present invention.

[0016] Figure 5 This is a flow chart of step S4 of the present invention.

[0017] Figure 6 This is a flow chart of step S5 of the present invention. DETAILED DESCRIPTION

[0018] The following is a more detailed description of the present application in conjunction with specific embodiments, such as the process of generating an optimized feature matrix through adaptive interval division and symbolic conversion; and the process of generating a threat association matrix based on a feature graph structure through a graph neural network and an attention mechanism. Figure 1 As shown, the present application proposes a self-evolving network security defense strategy generation and dynamic deployment method, comprising the following steps:

[0019] S1. Obtaining original network traffic data, system log data, device status data, and user behavior data, and generating a normalized multidimensional data matrix; based on the normalized multidimensional data matrix, determining a numerical interval division rule, and generating symbol sequence data and a transition probability matrix; based on the symbol sequence data and the transition probability matrix, obtaining an optimized feature matrix;

[0020] S2. Based on the optimized feature matrix, construct a feature node set and edge weight relationship to generate a feature graph structure; based on the feature graph structure, extract node feature information; based on the node feature information, calculate the degree of association between nodes to obtain a threat association matrix; based on the threat association matrix, extract threat features and perform pattern clustering to generate a threat pattern set;

[0021] S3, obtaining a threat pattern set, constructing a multi-dimensional evaluation index according to a preset evaluation rule, and generating a threat evaluation index set; based on the threat evaluation index set and the threat association matrix, analyzing the propagation characteristics of the threat, and obtaining a threat propagation graph;

[0022] S4. Obtain a threat assessment indicator set and a threat propagation diagram, and generate an initial defense strategy set according to a preset optimization rule; based on the initial defense strategy set, perform conflict detection and optimization processing to obtain an optimized defense strategy set.

[0023] like Figure 2 As shown, according to one aspect of the present application, step S1 is further:

[0024] S11, collecting original network traffic data, system log data, device status data and user behavior data, and converting the original network traffic data, system log data, device status data and user behavior data into normalized data according to a preset normalization processing rule; based on the normalized data, constructing a multidimensional data collection matrix to generate a normalized multidimensional data matrix; wherein each column of the multidimensional data collection matrix corresponds to a data source;

[0025] S12, mapping the values ​​in the normalized multidimensional data matrix to a preset k value interval to generate symbol sequence data; according to the symbol sequence data, calculating the conversion relationship between adjacent symbols to generate a transition probability matrix; based on the transition probability matrix, calculating the sequence entropy value and complexity index to obtain a symbol feature matrix; wherein k is a natural number greater than 1;

[0026] S13, obtaining a symbol feature matrix, and constructing a distance measurement matrix according to a preset reference distribution; based on the distance measurement matrix, calculating a transmission planning scheme, and generating transmission planning data; optimizing and adjusting the symbol feature matrix according to the transmission planning data, and obtaining an optimized feature matrix.

[0027] In one embodiment of the present application, the original network traffic data F, system log data L, device status data D, and user behavior data U are obtained, and a multidimensional data acquisition matrix C = [F, L, D, U] is constructed, each column represents a data source, and a normalized multidimensional data matrix M is output. Based on the normalized multidimensional data matrix M, the data space is divided into k intervals by the principle of equal probability, and a symbol mapping function μ is generated; the time series is converted into a symbol sequence: S = {s1, s2, ..., s n}, where s i ∈A (A is a symbol set); construct a sequence transition probability matrix P, p ij Represents the transition probability from symbol i to j; calculates the normalized symbol entropy H = -∑p i log(p i) / log(k); construct the symbol sequence complexity index C = H×(1-H), and output the symbol feature matrix SFM. Based on the symbol feature matrix SFM, construct the source distribution P(x) and the reference distribution Q(x), and design the distance metric matrix D, d ij Represents the distance between the i-th and j-th states; solves the optimal transmission planning problem: min<γ, D>, where γ is the transmission plan; modifies the data based on the transmission plan γ and outputs the optimized feature matrix OFM.

[0028] This embodiment realizes the unified representation and feature extraction of heterogeneous data sources through normalization and symbolic conversion of multi-dimensional data. Specifically, the data from different sources are standardized by using preset normalization rules, which solves the scale inconsistency problem of heterogeneous data such as network traffic, system logs, device status and user behavior; then, the data is symbolized by constructing a transition probability matrix, which not only retains the essential characteristics of the data but also reduces the complexity of the data; finally, the feature matrix is ​​optimized and adjusted through the transmission planning scheme to improve the expression ability and discrimination of the features. This embodiment not only solves the problem of difficulty in fusion of heterogeneous data in traditional methods, but also reduces the computational complexity of subsequent analysis through symbolic processing and optimization adjustment, while ensuring the validity of the features. Compared with traditional methods, it can better capture the time series features and state transition features in the data, providing a more reliable data basis for subsequent threat identification and defense strategy generation.

[0029] According to one aspect of the present application, step S12 is further:

[0030] S121. Based on the normalized multidimensional data matrix, calculate the distribution characteristics of the data and generate the data distribution characteristics; according to the data distribution characteristics, use the maximum entropy principle to determine the optimal number of intervals and generate interval quantity parameters; based on the interval quantity parameters and the data distribution characteristics, use the equal frequency binning method to divide the numerical intervals and obtain the interval boundary sequence;

[0031] S122. Based on the interval boundary sequence and the normalized multidimensional data matrix, a mapping function from numerical values ​​to symbols is constructed; according to the mapping function, the data is converted to generate an initial symbol sequence; the information entropy of the initial symbol sequence is calculated to obtain the sequence information entropy; based on the sequence information entropy, the mapping function is optimized and adjusted to generate symbol sequence data;

[0032] S123, based on the symbol sequence data, counting the occurrence frequency of adjacent symbol pairs to generate a frequency statistical matrix; based on the frequency statistical matrix, calculating the conditional probability to obtain the initial transition probability; performing Laplace smoothing on the initial transition probability to generate a transition probability matrix;

[0033] S124. Based on the transition probability matrix, the stationary distribution probability of each state is calculated to obtain a state probability vector; based on the state probability vector and the transition probability matrix, a normalized entropy value is calculated to generate a sequence entropy value; based on the sequence entropy value, the sequence complexity is calculated to obtain a complexity index;

[0034] S125. Construct a feature vector based on the sequence entropy value, complexity index and transition probability matrix; normalize the feature vector to generate a normalized feature vector; organize the normalized feature vector into a matrix form to generate a symbolic feature matrix.

[0035] In one embodiment of the present application, the maximum entropy principle is used to determine the optimal number of intervals: the information entropy optimization formula H(X) = -∑(p(i)·log p(i)) + λ·(∑p(i) - 1) + α·k; wherein p(i) is the probability distribution of the i-th interval; log p(i) is the logarithm with base 2; λ is the Lagrange multiplier, which is used to constrain the probability sum to 1; α is the regularization coefficient to prevent the k value from being too large; i is the interval index, and the value range is [1, k]; k is the optimal number of intervals to be determined; H(X) is the information entropy of the system; the gradient ascent method is used to solve the k value: k(t+1) = k(t) + η·ΨH / Ψk, wherein η is the learning rate, t is the number of iterations, and Ψ is the partial derivative.

[0036] The equal frequency binning method is used to divide the numerical interval into the following specific interval division formula: D(k) = ∑|F(i) - N / k| 2 ; where F(i) is the number of samples in the i-th interval; N is the total number of samples; k is the number of intervals; i is the interval index, ranging from [1, k]; D(k) is the uniformity measure; the interval boundary is determined by minimizing D(k): B(i) = Q((i / k)·N), where Q is the quantile function of the data and B(i) is the boundary value of the i-th interval.

[0037] The information entropy of the initial symbol sequence is calculated as follows: The sequence information entropy calculation formula is E(S) = -∑(p(si)·log p(si)) + β·∑|p(si) - p(si-1)|; where p(si) is the probability of occurrence of symbol si; log p(si) is the logarithm with base 2; β is the smoothing coefficient, which is used to suppress drastic changes in probability; i is the symbol index; E(S) is the information entropy of the sequence; si is the i-th symbol; si-1 is the previous symbol; the mapping function is optimized by maximizing E(S).

[0038] The specific frequency of occurrence of adjacent symbol pairs is as follows: The frequency statistics formula is F(i, j) = ∑I(st=i & st+1=j) + Δ·B(i, j); where I() is the indicator function, which is 1 if the condition is met and 0 otherwise; st, st+1 are the symbols at adjacent moments; Δ is the smoothing coefficient; B(i, j) is the prior knowledge matrix; i, j are symbol indexes; F(i, j) is the smoothed transition frequency; The statistical reliability of sparse data is improved by introducing prior knowledge.

[0039] The Laplace smoothing of the initial transfer probability is as follows: the smoothing probability calculation formula P'(j|i) = (C(i, j) + Δ) / (C(i) + Δ·|V|); where C(i, j) is the count of symbol i transferring to symbol j; C(i) is the total count of symbol i; Δ is the smoothing parameter, and the default value is 1; |V| is the symbol table size; i, j are symbol indexes; P'(j|i) is the smoothed transfer probability; the zero probability problem is avoided by introducing the smoothing parameter Δ.

[0040] The stationary distribution probability of each state is calculated as follows: Stationary distribution calculation formula π = π·P + μ·(I - P+ U) -1 ; Where π is the stationary distribution probability vector; P is the transition probability matrix; I is the identity matrix; U is a matrix with all elements set to 1; μ is the convergence parameter, taking the value (0, 1); (I - P + U) -1 Inverse the matrix; iterate until ||π(t+1) - π(t)|| < ε, where ε is the convergence threshold and t is the number of iterations.

[0041] This embodiment solves the complexity problem of high-dimensional data processing by implementing an adaptive data symbolization conversion and feature extraction mechanism. First, the optimal number of intervals is determined by the maximum entropy principle to achieve adaptive binning of data; then, the numerical data is converted into a symbol sequence through a mapping function to reduce the complexity of the data; then, the transition probability and entropy value of the symbol sequence are calculated to capture the dynamic characteristics of the data; finally, a symbol feature matrix is ​​generated through feature combination to achieve effective feature representation. This embodiment not only reduces the computational complexity, but also retains the essential characteristics and time series relationships of the data. By introducing entropy and complexity indicators, the expressive power of features is enhanced, providing a more reliable feature basis for subsequent threat identification. Compared with traditional feature extraction methods, it can better balance computational efficiency and feature expression capabilities.

[0042] In another embodiment of the present application, S121 is further as follows: obtaining a normalized multidimensional data matrix, calculating the distribution characteristics of the data for each dimension separately, and generating a dimension distribution feature set; for each dimension, based on its data distribution characteristics, constructing an information entropy evaluation function, which considers the local density and global distribution of the data; finding the optimal number of intervals that maximizes the information entropy of each dimension through iterative search, and generating a dimension adaptive interval parameter set; based on the dimension adaptive interval parameter set, adopting an adaptive binning strategy for each dimension, and obtaining a multidimensional interval boundary sequence. Among them, a smaller number of intervals is used for sparsely distributed dimensions, and a larger number of intervals is used for densely distributed dimensions, to ensure that the data characteristics of each dimension can be reasonably expressed.

[0043] This embodiment achieves accurate characterization and feature extraction of multidimensional data by introducing a dimension-adaptive interval division mechanism. First, the distribution characteristics are calculated independently for each dimension to avoid mutual interference between dimensions; then, the optimal number of intervals is adaptively determined for each dimension based on the information entropy evaluation function, which solves the problem of feature loss caused by the traditional fixed number of intervals; finally, the dimensions with different density distributions are differentiated through an adaptive binning strategy to improve the accuracy of feature representation. This embodiment not only overcomes the problem of unreasonable interval division of multidimensional data in traditional methods, but also improves the accuracy of feature extraction by considering the local density and global distribution characteristics of the data. For sparsely distributed dimensions, a smaller number of intervals is used to avoid the problem of data sparsity caused by over-segmentation; for densely distributed dimensions, a larger number of intervals is used to ensure the full expression of important features. Through this adaptive mechanism, the essential characteristics of the data are maintained and the efficiency of feature extraction is improved.

[0044] According to one aspect of the present application, step S13 is further:

[0045] S131, based on the symbolic feature matrix, calculating the empirical distribution characteristics of the data to generate empirical distribution data; based on a preset ideal Gaussian distribution, constructing a reference distribution model to obtain reference distribution data; according to the empirical distribution data and the reference distribution data, calculating the distribution difference to generate a distribution difference vector;

[0046] S132, constructing a pairwise distance calculation function based on the distribution difference vector; using the pairwise distance calculation function, calculating the point pair distances in the feature space to obtain an initial distance matrix; normalizing the initial distance matrix to generate a distance metric matrix;

[0047] S133, constructing a transmission cost model based on the distance metric matrix and generating a cost coefficient matrix; constructing a linear programming problem based on the cost coefficient matrix; solving the linear programming problem using an improved simplex method and generating transmission planning data;

[0048] S134, based on the transmission planning data, calculating the optimal transmission path to obtain a transmission path set; constructing a feature mapping function according to the transmission path set to generate a feature mapping matrix; based on the feature mapping matrix, transforming the symbol feature matrix to obtain an initial optimization matrix;

[0049] S135. Based on the initial optimization matrix, calculate the distribution deviation before and after optimization to generate deviation index data; perform local fine-tuning based on the deviation index data to obtain an adjustment parameter set; based on the adjustment parameter set, perform fine-tuning on the initial optimization matrix to generate an optimized feature matrix.

[0050] In one embodiment of the present application, the improved simplex method is specifically: the transmission planning objective function Min F(X) = Σ i=1 n Σ j=1 m cij·xij + λ·H(X); where H(X) = -Σ i=1 n Σ j=1 m (xij / S)·log(xij / S) is the entropy regularization term, S=Σ i=1 n Σ j=1 m xij; cij is the transmission cost matrix element; xij is the transmission amount from feature i to j; λ is the entropy regularization coefficient; n, m are the feature dimensions; the constraint condition is: Σ j=1 m xij=ai,Σ i=1 n xij=bj, xij≥0, ai is the source distribution, bj is the target distribution. By introducing the entropy regularization term, the degradation phenomenon of the traditional simplex method is avoided and the solution stability is improved.

[0051] This embodiment achieves improved accuracy and effectiveness of feature representation by establishing a feature optimization and transmission planning mechanism. First, a reference model is constructed based on the ideal distribution to calculate the difference between the actual distribution and the ideal distribution; then the data relationship in the feature space is quantified through the distance metric matrix; then the transmission planning algorithm is used to optimize the feature distribution and reduce the distribution deviation; finally, the optimized feature representation is obtained through feature mapping and fine-tuning. This embodiment not only improves the discrimination of features, but also ensures the stability of the optimization process by considering the overall structure of feature distribution. By introducing adaptive feature mapping and local fine-tuning mechanisms, the optimized features can better reflect the essential characteristics of the data. Compared with traditional feature selection and dimensionality reduction methods, it can improve the expression efficiency and discrimination ability of features while maintaining feature integrity.

[0052] like Figure 3 As shown, according to one aspect of the present application, step S2 is further:

[0053] S21, taking each feature in the optimized feature matrix as a node, constructing a feature node set; based on the feature node set, calculating the association strength between nodes, and generating an edge weight matrix; based on the edge weight matrix and a preset association threshold, determining the connection relationship between nodes, and generating an adjacency matrix; based on the edge weight matrix and the adjacency matrix, constructing a feature graph structure;

[0054] S22. Based on the feature graph structure, extract the feature information of each node and generate a node feature matrix; perform graph convolution operation on the node feature matrix to obtain the node hidden layer features; calculate the attention coefficient between nodes based on the node hidden layer features; perform weighted aggregation on the node hidden layer features according to the attention coefficient to generate a threat association matrix;

[0055] S23. Based on the threat association matrix, construct a threat feature space; based on the threat feature space, calculate the similarity relationship between threat patterns and generate a pattern similarity matrix; perform spectral clustering operation on the pattern similarity matrix to obtain the threat pattern grouping result; according to the threat pattern grouping result, integrate relevant feature information to generate a threat pattern set.

[0056] In one embodiment of the present application, based on the optimized feature matrix OFM, a feature node set V = {v1, v2, ..., v n}, each node represents a security feature; construct the edge weight matrix W, w ij Represents the strength of association between nodes i and j; constructs the graph adjacency matrix A = {a ij}, where a ij = 1 means that nodes i and j are connected, and the feature graph structure G is obtained. Based on the feature graph structure G and the node feature matrix X, a graph convolution operation is constructed: H l+1 =σ(D -1 / 2 AD -1 / 2 H l W l ), where H l+1 is the feature matrix of the l+1th layer, σ is the activation function; the attention mechanism is introduced: α ij = softmax(LeakyReLU(a T [Wh_i||Wh_j])), T is the transpose, a is the weight vector in the attention mechanism, and Wh_i is the result of linear transformation of the feature vector of node i; aggregate node information: h_i' = σ(∑ j∈N_i α ijWh_j), where N_i is the set of neighbor nodes of node i; output threat correlation matrix TCM. Based on the threat correlation matrix TCM, construct the threat pattern feature space Ω, calculate the pattern similarity matrix S, s ij Represents the similarity between patterns i and j, applies the spectral clustering algorithm to group the patterns, and obtains the threat pattern set TPS.

[0057] This embodiment realizes the automatic extraction and pattern clustering of threat features. First, based on the optimized feature matrix, a feature node set and edge weight relationship are established to construct a feature graph structure with powerful expression ability; then, the graph convolution operation and attention mechanism are used to automatically learn the deep correlation relationship between nodes, overcoming the limitation that traditional methods are difficult to capture complex network security threat patterns; finally, the threat patterns are automatically grouped through the spectral clustering method to achieve accurate identification of threat patterns. This embodiment can automatically adapt to the dynamic changes of the network environment and improve the accuracy and robustness of threat identification. At the same time, through the introduction of the attention mechanism, the model's perception ability of key threat features is improved, and the false alarm rate and missed alarm rate are reduced. Compared with the traditional rule-based threat identification method, this embodiment has stronger generalization ability and adaptability.

[0058] According to one aspect of the present application, step S22 is further:

[0059] S221, obtaining node feature data in the feature graph structure, extracting attribute information of each node, and generating a node attribute vector; dimensional alignment of the node attribute vector to obtain aligned feature data; organizing the aligned feature data into a matrix form to generate a node feature matrix;

[0060] S222. Based on the node feature matrix, construct a Laplace operator to generate a Laplace matrix; perform eigendecomposition on the Laplace matrix to obtain an eigenvalue sequence and an eigenvector matrix; based on the eigenvalue sequence and the eigenvector matrix, construct a Chebyshev polynomial filter to generate a graph convolution kernel;

[0061] S223, based on the graph convolution kernel and the node feature matrix, perform graph convolution operation to obtain initial hidden layer features; perform nonlinear transformation on the initial hidden layer features to generate activation feature data; use a residual connection mechanism to combine the data in the node feature matrix and the activation feature data to obtain the node hidden layer features;

[0062] S224, based on the node hidden layer features, calculating the similarity scores between the node pairs and generating a similarity matrix; normalizing the similarity matrix to obtain an initial attention coefficient; based on the initial attention coefficient, using the pre-stored temperature parameter to adjust the attention distribution and generate an attention coefficient matrix;

[0063] S225. Based on the attention coefficient matrix and the node hidden layer features, a weighted sum operation is performed to obtain aggregated feature data; the aggregated feature data is scaled normalized to generate a normalized feature matrix; the normalized feature matrix is ​​converted into an association strength representation to generate a threat association matrix.

[0064] In one embodiment of the present application, the Chebyshev polynomial filter is constructed as follows: filter design formula h(λ) = ∑(θk·Tk(λ*)); wherein Tk(x) is a k-order Chebyshev polynomial; λ* is a normalized eigenvalue in the range [-1, 1]; θk is a filter coefficient; k is the polynomial order; h(λ) is a frequency response function; λ is a Laplace matrix eigenvalue; by minimizing ||h(λ) - g(λ)|| 2 Determination coefficient, g(λ) is the target frequency response.

[0065] The residual connection mechanism is specifically: the feature fusion formula F(l+1) = σ(W·GCN(F(l))) + γ·F(l); where F(l) is the l-th layer feature; W is the weight matrix; GCN() is the graph convolution operation; σ is the activation function; γ is the residual coefficient, taking the value [0, 1]; l is the layer index; F(l+1) is the fused feature; and the proportion of the original feature and the convolution feature is balanced by adaptively adjusting γ.

[0066] The specific method of using temperature parameters to adjust attention distribution is as follows: the attention calculation formula is A(i, j) = softmax(sim(i, j) / τ + M(i, j)); where sim(i, j) is the similarity between nodes i and j; τ is the temperature parameter, which controls the smoothness of the distribution; M(i, j) is the position encoding matrix; i, j are node indexes; A(i, j) is the attention coefficient; softmax is the normalization function; the focus of attention is controlled by dynamically adjusting the τ value.

[0067] This embodiment realizes the automatic extraction and correlation analysis of threat features through deep graph neural networks and attention mechanisms. First, a node feature matrix is ​​constructed to uniformly represent the attribute information of the nodes; then, the local feature patterns of the nodes are extracted through graph convolution operations; then, the attention mechanism is used to weightedly aggregate the features of different nodes; finally, a threat correlation matrix that reflects the correlation between nodes is generated. This embodiment can not only automatically capture complex network structure features, but also realize dynamic weighting of key features through the attention mechanism. By introducing the residual connection mechanism, the gradient vanishing problem in deep networks is solved and the learning ability of the model is improved. Compared with traditional artificial feature engineering methods, it can better adapt to the dynamic changes of the network environment and provide more accurate threat feature representation.

[0068] In another embodiment of the present application, S223 is specifically: obtaining the graph convolution kernel and the node feature matrix, constructing a feature dimension mapping layer, which is responsible for maintaining the consistency of the feature dimension before and after the graph convolution; performing the graph convolution operation to obtain the initial hidden layer features; designing a feature alignment module to ensure that the initial hidden layer features match the original feature dimensions; performing a nonlinear transformation on the initial hidden layer features to generate activated feature data; constructing a dimension-adaptive residual connection module, which first checks the dimensions of the original features and the activated features. If they are inconsistent, they are adjusted through a learnable linear transformation to ensure that the dimensions match before performing feature combination to finally obtain the node hidden layer features.

[0069] This embodiment solves the dimension mismatch problem in the graph convolution process by establishing a feature dimension mapping layer and an adaptive residual connection mechanism. First, a feature dimension mapping layer is introduced to ensure the consistency of feature dimensions before and after graph convolution; then, the dimension matching of hidden layer features and original features is achieved through the feature alignment module; finally, a dimension adaptive residual connection module is used to automatically adjust the feature dimension through a learnable linear transformation. This embodiment not only ensures the accuracy of feature fusion, but also improves the adaptability of the model through a learnable conversion mechanism. Compared with the traditional simple truncation or padding method, this adaptive mechanism can better maintain the semantic information of the features, while improving the expressiveness and generalization performance of the model.

[0070] According to one aspect of the present application, step S23 is further:

[0071] S231, obtaining a threat association matrix, extracting threat feature vectors, and generating a feature vector set; performing dimensionality reduction processing on the feature vector set to obtain reduced-dimensionality feature data; constructing a metric space based on the reduced-dimensionality feature data, and generating feature space parameters.

[0072] S232, acquiring feature space parameters and feature vector sets, constructing kernel function mapping rules, and generating a kernel mapping matrix; calculating the similarity between vector pairs in the kernel mapping matrix to obtain initial similarity data; adaptively adjusting the initial similarity data to generate a pattern similarity matrix.

[0073] S233, obtaining a pattern similarity matrix, calculating a Laplace matrix, and obtaining a normalized Laplace matrix; performing eigenvalue decomposition on the normalized Laplace matrix to generate an eigenvalue sequence and an eigenvector group; determining an optimal number of clusters according to the eigenvalue sequence to obtain clustering parameters.

[0074] S234, obtaining clustering parameters and feature vector groups, using an improved k-means algorithm for clustering, and obtaining an initial clustering result; calculating a silhouette coefficient of the initial clustering result, and generating clustering evaluation data; optimizing clustering boundaries based on the clustering evaluation data, and obtaining threat pattern grouping.

[0075] S235, obtaining threat pattern groups, extracting representative features of each group, and obtaining a pattern feature set; calculating the importance weight of each feature in the pattern feature set, and generating a feature weight vector; combining pattern features according to the feature weight vector, and generating a threat pattern set.

[0076] In one embodiment of the present application, the improved k-means algorithm is specifically: clustering objective function Min J = Σ k=1 K Σ xi∈Ck (||xi-μk|| 2 + α·Sk + β·Dk); where Sk = Σ xi,xj∈Ck sim(xi,xj) / |Ck| 2 is the similarity within the cluster, sim(xi,xj) is the sample similarity; Dk =Σ l≠k (Σ xi∈Ck Σxj∈Cl sim(xi,xj)) / (|Ck|·|Cl|) is the distance between clusters; μk is the center of the kth cluster; Ck is the kth cluster; |Ck| is the number of samples contained in the cluster; α, β are the balance coefficients; K is the number of clusters. By optimizing both the intra-cluster similarity and the inter-cluster distance, the accuracy of threat pattern clustering is improved.

[0077] The specific rules for constructing kernel function mapping are: Kernel mapping function K(x, y) = exp(-||xy|| 2 / 2σ 2 ) + ρ·cos(ω·<x,y>); x, y are feature vectors; σ is the Gaussian kernel width; ρ is the periodic kernel coefficient; ω is the frequency parameter; ||xy|| is the Euclidean distance; <x,y> is the vector inner product; K(x,y) is the kernel similarity; the feature expression ability is enhanced by combining the Gaussian kernel and the periodic kernel.

[0078] The silhouette coefficient of the initial clustering result is calculated as follows: The silhouette coefficient calculation formula is S(i) = (b(i) - a(i)) / max(a(i), b(i)); where a(i) is the average distance between sample i and other samples in the same cluster; b(i) is the average distance between sample i and the samples in the nearest neighboring cluster; i is the sample index; S(i) is the silhouette coefficient of sample i, ranging from [-1, 1]; max() is the maximum value function; the overall silhouette coefficient is the average of the silhouette coefficients of all samples: S_avg = (1 / n)·∑S(i), where n is the total number of samples.

[0079] This embodiment obtains the threat association matrix and extracts the threat feature vector, generates a feature vector set, and performs dimensionality reduction processing on it, which can effectively reduce the dimension of the data, retain important feature information, and help improve the efficiency of subsequent analysis and processing; by constructing the kernel function mapping rule, generating the kernel mapping matrix, and calculating the similarity between vector pairs, the similarity between different threat features can be accurately measured; the initial similarity data is adaptively adjusted to generate the pattern similarity matrix, which helps to improve the accuracy of similarity calculation; by calculating the Laplace matrix and performing eigenvalue decomposition, generating eigenvalue sequences and eigenvector groups, the inherent structure and pattern of the data can be revealed; determining the optimal number of clusters based on the eigenvalue sequence helps to optimize the clustering results; using the improved k-means algorithm for clustering, calculating the silhouette coefficient of the initial clustering results, and generating clustering evaluation data, the clustering results can be effectively evaluated and optimized, and the accuracy and stability of clustering can be improved. By extracting the representative features of each group, calculating the importance weight of the features, and combining the pattern features to generate a threat pattern set, different threat patterns can be accurately identified and described, providing strong support for threat detection and defense.

[0080] like Figure 4 As shown, according to one aspect of the present application, step S3 is further:

[0081] S31, obtaining a threat pattern set and pre-stored historical threat data, and constructing an evaluation indicator system according to a preset evaluation dimension; based on the evaluation indicator system, assigning a weight coefficient to each evaluation indicator to generate an indicator weight vector; based on the indicator weight vector, calculating a comprehensive evaluation score; based on the comprehensive evaluation score and the evaluation indicator system, generating a threat assessment indicator set;

[0082] S32. Based on the threat association matrix and the threat assessment indicator set, calculate the propagation probability between threat nodes and generate a propagation probability matrix; based on the propagation probability matrix, use the improved shortest path algorithm to calculate the key propagation path; based on the key propagation path and the threat assessment indicator set, calculate the node risk value; based on the key propagation path and the node risk value, generate the propagation path risk assessment result; based on the propagation path risk assessment result, construct a threat propagation graph.

[0083] In one embodiment of the present application, based on the threat pattern set TPS and the historical threat data H, an evaluation index set I = {i1, i2, ..., i k}, construct the indicator weight vector w = {w1, w2, ..., w k}, calculate the comprehensive evaluation score: s = ∑w i i i , output the threat assessment indicator set TES. Based on the threat correlation matrix TCM and the threat assessment indicator set TES, construct the propagation probability matrix P, pij Represents the probability of a threat spreading from i to j; the improved Dijkstra algorithm is used to calculate the critical propagation path and evaluate the path risk value: r = ∏p ij × ∑s i , where ∏ is the product operator, and the output is the threat propagation graph TPG.

[0084] In another embodiment of the present application, the improved shortest path algorithm is specifically: edge weight calculation function W(e) = -log(P(e))·(1 + γ·V(e)); wherein P(e) is the propagation probability of edge e; V(e) = σ(ΔR(e) / Rmax) is the risk change function, σ is the sigmoid function; ΔR(e) is the risk increment caused by edge e; Rmax is the maximum risk threshold; γ is the risk weight coefficient; the total path cost Cost(p) = Σ e∈p W(e). The propagation probability and risk factors are integrated into the edge weight calculation to realize the risk-aware path search.

[0085] This embodiment achieves accurate threat assessment and propagation path prediction by establishing a multi-dimensional evaluation index system and a threat propagation analysis model. First, a set of threat assessment indicators covering multiple dimensions is constructed, which comprehensively considers factors such as the degree of harm, propagation scope, and impact duration of the threat; then, the propagation characteristics of the threat are analyzed to accurately predict the diffusion path of the threat; finally, an accurate threat propagation map is generated through shortest path algorithm optimization and risk assessment. This embodiment not only improves the accuracy of threat assessment, but also can predict the evolution trend of threats, providing a scientific basis for the formulation of defense strategies. Compared with traditional static evaluation methods, it can better cope with complex and changing network security threats and provide more targeted defense recommendations.

[0086] According to one aspect of the present application, step S32 is further:

[0087] S321, based on the threat association matrix and the threat assessment indicator set, extract the association strength data between the nodes to generate an association strength vector; according to the association strength vector, construct a Markov chain model to obtain a state transfer matrix; normalize the state transfer matrix to generate a propagation probability matrix;

[0088] S322, based on the propagation probability matrix, calculating the edge weight coefficient, generating the edge weight matrix; constructing a directed weighted graph model to obtain a network topology structure; based on the network topology structure and the edge weight matrix, constructing a heuristic search rule, generating a path search parameter;

[0089] S323, based on the path search parameters and the network topology, using the improved Dijkstra algorithm to perform path search to obtain a candidate path set; calculating the propagation probability of each path in the candidate path set to generate a path probability vector; based on the path probability vector, screening the key propagation path to obtain a key path set;

[0090] S324, based on the critical path set and the threat assessment indicator set, calculating the cumulative risk value of the nodes on the path, generating a node risk matrix; based on the node risk matrix, evaluating the diffusion range of the path propagation, obtaining diffusion range data; combining the node risk matrix and the diffusion range data, generating a risk assessment result;

[0091] S325. Based on the risk assessment results, a graph structure representation model is constructed to generate a graph structure template; the risk assessment results are mapped to the graph structure template to obtain node attribute data; based on the key path set, the propagation path information is extracted; the node attribute data and the propagation path information are integrated to generate a threat propagation graph.

[0092] In one embodiment of the present application, the improved Dijkstra algorithm is specifically: path search cost function Cost(p) = α·L(p) + β·R(p) + γ·T(p); where L(p) = Σ (vi,vj)∈p w(vi, vj) is the path length, w(vi, vj) is the edge weight; R(p) = Π (vi,vj)∈p (1-r(vi, vj)) is the path reliability, r(vi, vj) is the edge reliability; T(p) = max (vi,vj)∈p t(vi, vj) is the propagation delay, t(vi, vj) is the edge delay; α, β, γ are the path evaluation weight coefficients, and α+β+γ=1; vi, vj are the adjacent nodes in path p; p is the candidate path. Based on the traditional Dijkstra algorithm, the single edge weight is expanded into a multi-dimensional evaluation index, and a more accurate propagation path search is achieved by comprehensively considering the path length, reliability and delay.

[0093] The Markov chain model is constructed based on the association strength vector as follows: the state transition probability calculation formula is P(j|i) =R(i, j)·exp(-λ·d(i, j)) / Z(i); where R(i, j) is the association strength between nodes i and j; d(i, j) is the topological distance between nodes; λ is the attenuation coefficient; Z(i) is the normalization factor; i, j are node indexes; P(j|i) is the transition probability; and the remote propagation probability is adjusted by the distance attenuation term.

[0094] The specific heuristic search rules are constructed as follows: the heuristic function calculation formula is h(n) = α·c(n) + β·r(n) +γ·d(n, t); where c(n) is the actual cost from the starting point to node n; r(n) is the risk assessment value of node n; d(n, t) is the estimated distance from node n to target t; α, β, γ are weight coefficients; n is the current node; h(n) is the heuristic evaluation value; the search efficiency and path quality are balanced by dynamically adjusting the weight.

[0095] The cumulative risk value of the nodes on the path is calculated as follows: Risk accumulation formula R(p) = ∑(w(i)·r(i)·∏(1-m(j))); where w(i) is the importance weight of node i; r(i) is the inherent risk value of node i; m(j) is the mitigation coefficient of node j; i is the node index on the path; j is the index of the node before i; R(p) is the cumulative risk value of path p; The actual risk is calculated by considering the cumulative effect of defense measures.

[0096] This embodiment can effectively analyze the propagation path and mode of threats in the network by extracting the correlation strength data between nodes, constructing a Markov chain model, and generating a propagation probability matrix, which helps to identify and predict potential threat propagation paths and improve network security protection capabilities. The improved Dijkstra algorithm is used to search for paths, obtain a set of candidate paths, calculate the propagation probability of each path, and screen out key propagation paths. The paths that have the greatest impact on network security can be accurately identified, which is convenient for taking targeted protection measures. Based on the key path set and the threat assessment indicator set, the cumulative risk value of the nodes on the path is calculated, and the diffusion range of the path propagation is evaluated. The risk level and threat diffusion range of each node in the network can be comprehensively evaluated, providing a basis for formulating protection strategies. By constructing a graph structure representation model, generating a graph structure template, and mapping the risk assessment results to the graph structure template, a threat propagation graph is generated, which can intuitively display the propagation path and impact range of threats in the network, which is convenient for security personnel to monitor and analyze. This embodiment can comprehensively and accurately identify and evaluate the threat propagation path and risk level in the network through threat association analysis, path search, risk assessment and graph structure representation.

[0097] In another embodiment of the present application, S321 further comprises: obtaining a threat association matrix and a threat assessment indicator set, extracting the association strength data between nodes, and generating an initial association strength vector; constructing an association strength standardization module to convert the association strength into a valid transition probability to ensure that the Markov property is satisfied; specifically, first performing a sigmoid transformation on the association strength to map the value range to the (0, 1) interval, and then normalizing the outbound edge probability of each node to ensure that the sum of the outbound edge probabilities is 1; constructing a Markov chain model based on the standardized transition probability to obtain a state transfer matrix that conforms to probability theory; finally, performing a stationarity test on the state transfer matrix to ensure the validity of the model and generate a propagation probability matrix.

[0098] This embodiment achieves accurate threat propagation modeling by introducing association strength standardization and Markov chain validity verification mechanism. First, the association strength is sigmoid transformed and normalized to ensure the validity of the transition probability; then the Markov chain model is constructed through the standardized transition probability to ensure the theoretical correctness of the model; finally, the reliability of the model is ensured through a stationarity test. This embodiment not only solves the theoretical defect of directly using association strength as the transition probability in the traditional method, but also improves the accuracy and reliability of the propagation model through normalization and validity verification. Compared with traditional methods, it can more accurately describe the propagation characteristics of threats.

[0099] like Figure 5 As shown, according to one aspect of the present application, step S4 is further:

[0100] S41, obtain a threat assessment indicator set and a threat propagation graph, construct a defense cost matrix and a set of constraints; calculate the objective function value according to the defense cost matrix; based on the objective function value and the set of constraints, use the interior point method to perform optimization calculation to obtain the optimal defense plan; generate an initial defense strategy set according to the optimal defense plan;

[0101] S42. Based on the initial defense strategy set, analyze the dependencies between strategies and construct a strategy dependency graph; detect circular dependencies in the strategy dependency graph and generate dependency data; eliminate strategy conflicts according to preset priority rules and dependency data to obtain conflict elimination results; based on the conflict elimination results, optimize and adjust the initial defense strategy set to generate an optimized defense strategy set.

[0102] In one embodiment of the present application, based on the threat assessment index set TES and the threat propagation graph TPG, an objective function is constructed: f(x) = min(∑c i x i ), where c i For defense cost, x iis the selection variable of the i-th defense strategy; set the constraint conditions: g(x)≤b, h(x) = 0; where b is the threshold or upper limit in the constraint conditions; use the interior point method to solve the optimal defense strategy and output the initial defense strategy set IDS. Based on the initial defense strategy set IDS, construct the strategy dependency graph D = (V, E), where V is the node set in the strategy dependency graph and E is the edge set in the strategy dependency graph; use the improved Tarjan algorithm to detect circular dependencies, apply the strategy priority rule to resolve conflicts, and output the optimized defense strategy set ODS.

[0103] This embodiment realizes efficient and feasible defense strategy generation. First, a defense strategy optimization model is constructed based on the interior point method, which comprehensively considers multiple factors such as defense effect, resource consumption and operation constraints; then, through policy dependency graph analysis and conflict detection, the executability of the generated strategy is ensured; finally, a priority-based conflict elimination mechanism is adopted to generate the optimal defense strategy set. This embodiment not only solves the policy conflict problem in the traditional defense strategy generation method, but also can find the optimal defense plan under the constraints of limited resources. By introducing dynamic optimization and adaptive adjustment mechanisms, the generated defense strategy has stronger adaptability and feasibility. Compared with the traditional rule-based strategy generation method, this embodiment can better balance the defense effect and resource consumption.

[0104] According to one aspect of the present application, step S41 is further:

[0105] S411. Obtain a threat assessment indicator set and a threat propagation graph, establish a resource consumption mapping function, and generate a resource cost vector; calculate the correlation strength between defense operations to obtain an operation correlation matrix; construct a joint cost model based on the resource cost vector and the operation correlation matrix to generate a defense cost matrix.

[0106] S412, obtain the defense cost matrix, establish system resource limitation rules, and generate a resource constraint vector; set the execution timing requirements of the defense operation to obtain the timing constraint matrix; construct the defense effect guarantee conditions and generate an effect constraint set; combine the resource constraint vector, timing constraint matrix and effect constraint set to generate a constraint condition set.

[0107] S413, obtaining a defense cost matrix, constructing a linear objective function, and obtaining an initial objective function; introducing a defense effect balance term, and generating a balance coefficient vector; adjusting the initial objective function according to the balance coefficient vector, and generating an objective function value.

[0108] S414, obtaining the objective function value and the constraint condition set, initializing the interior point parameters, and generating an initial search point; constructing a barrier function to obtain a barrier parameter set; performing interior point iteration based on the barrier parameter set and the initial search point to generate an optimal defense solution.

[0109] S415, obtaining an optimal defense solution, parsing the defense operation sequence, and obtaining an operation sequence table; setting defense rule parameters and generating a rule parameter set; constructing a defense strategy according to the operation sequence table and the rule parameter set, and generating an initial defense strategy set.

[0110] In one embodiment of the present application, the joint cost model is constructed as follows: the cost calculation formula C(S) = ∑(ci·xi) + φ·∑∑(wij·xi·xj); wherein ci is the resource cost of a single defense strategy i; xi is the execution indicator variable (0 / 1) of strategy i; wij is the association strength between strategies i and j; φ is the association weight coefficient; i, j are strategy indexes; C(S) is the overall cost; and the synergy between strategies is considered through quadratic terms.

[0111] The barrier function is constructed as follows: barrier function formula B(x, μ) = f(x) - μ·∑log(-gi(x)); where f(x) is the original objective function; gi(x) is the inequality constraint function; μ is the barrier parameter; i is the constraint index; x is the decision variable vector; B(x, μ) is the objective function with barrier term; log() is the natural logarithm; the interior point method iteration is realized by gradually reducing μ: μ(k+1) = σ·μ(k), σ is the shrinkage factor.

[0112] By establishing a resource consumption mapping function and a resource cost vector, this embodiment can effectively evaluate and optimize the resource consumption of defense operations, thereby improving resource utilization efficiency. By calculating the correlation strength between defense operations and constructing an operation correlation matrix, the relationship between defense operations can be better understood and optimized, thereby formulating a more effective defense strategy. By constructing a joint cost model and a defense cost matrix, resource consumption and defense effect can be comprehensively considered, thereby formulating a defense plan with the lowest comprehensive cost. By establishing system resource restriction rules and generating resource constraint vectors, it can be ensured that defense operations are performed within system resource restrictions, thereby avoiding resource waste and system overload. By setting the execution timing requirements of defense operations and constructing defense effect guarantee conditions, it can be ensured that defense operations are performed in time and achieve the expected effect, thereby improving the reliability of defense effects. By constructing a linear objective function and introducing a defense effect balance term, the best balance point between resource consumption and defense effect can be found, thereby formulating an optimal defense plan. By performing interior point iteration, the optimal solution can be found under complex constraints, thereby improving the optimization effect of the defense plan. By parsing the defense operation sequence and setting defense rule parameters, an initial defense strategy set can be generated, thereby providing guidance for actual defense operations.

[0113] According to one aspect of the present application, step S42 is further:

[0114] S421, obtaining an initial defense strategy set, extracting the strategy operation sequence, and generating a strategy operation matrix; analyzing the pre- and post-operations relationships in the strategy operation matrix to obtain a relationship constraint set; constructing a directed graph structure based on the relationship constraint set to generate a strategy dependency graph.

[0115] S422, obtaining a strategy dependency graph, extracting node connection relationships in the graph, and generating a connection relationship matrix; using an improved Tarjan algorithm to decompose the connection relationship matrix into strongly connected components to obtain a component set; analyzing the cyclic dependency paths in the component set to generate dependency relationship data.

[0116] S423, obtaining dependency data, constructing a policy priority evaluation model, and obtaining a priority calculation rule; scoring conflicting policies according to the priority calculation rule to generate a policy scoring matrix; establishing a policy ranking based on the policy scoring matrix to obtain a priority sequence.

[0117] S424, obtaining priority sequence and dependency data, identifying conflicting policy pairs, and generating a conflict policy table; selecting policies in the conflict policy table according to the priority sequence to obtain policy selection results; eliminating circular dependencies based on the policy selection results, and generating a conflict elimination plan.

[0118] S425, obtaining a conflict elimination solution, extracting policy items that need to be adjusted, and generating an adjustment policy set; optimizing policy parameters in the adjustment policy set to obtain parameter optimization results; reconstructing defense policies according to the parameter optimization results to generate an optimized defense policy set.

[0119] In one embodiment of the present application, the improved Tarjan algorithm is specifically as follows: dependency strength calculation function Dep(i, j) = ω1·Ov(i, j) + ω2·Pr(i, j) + ω3·Tm(i, j); wherein Ov(i, j) = |Res(i)∩Res(j)| / |Res(i)∪Res(j)| is the resource overlap, Res(x) is the resource set used by policy x; Pr(i, j) is the policy priority correlation; Tm(i, j) is the timing correlation; ω1, ω2, ω3 are weight coefficients and Σωk=1; strong connected component determination threshold τ(C) = min{Dep(i, j) | i, j∈C}, C is the policy subset. By introducing multi-dimensional dependency strength calculation, the accuracy of policy cyclic dependency detection is improved.

[0120] The specific strategy priority evaluation model is constructed as follows: priority scoring formula P(s) = ω1·E(s) + ω2·(1 / C(s)) + ω3·(1 / D(s)) + ω4·U(s); where E(s) is the expected effect of strategy s; C(s) is the execution cost; D(s) is the dependency complexity; U(s) is the urgency; ω1, ω2, ω3, ω4 are weight coefficients and the sum is 1; s is the strategy index; P(s) is the comprehensive priority score; and the strategy execution order is determined through multi-dimensional evaluation.

[0121] This embodiment achieves optimization and conflict handling of defense strategies through policy dependency analysis and conflict elimination mechanisms. First, a policy dependency graph is constructed to analyze the correlation between strategies; then, circular dependencies are detected and potential conflicts are identified through the Tarjan algorithm; then, policy conflicts are resolved based on the priority evaluation model; finally, the final defense strategy set is generated through parameter optimization. This embodiment can not only accurately identify complex policy dependencies, but also automatically eliminate conflicts through a priority mechanism. By introducing a policy scoring and parameter optimization mechanism, the rationality and effectiveness of the conflict elimination process are ensured. Compared with traditional manual processing methods, it can more efficiently handle conflict problems in large-scale policy sets, improving the efficiency and reliability of policy generation.

[0122] In another embodiment of the present application, step S426 is also included: obtaining an optimized defense strategy set and constructing a strategy verification environment, which includes the main features and key security attributes of a real network; designing a multi-dimensional verification indicator system, including aspects such as strategy effectiveness, resource consumption, deployment impact, and security benefits; performing strategy simulation tests in the verification environment and collecting strategy execution effect data; grading strategies according to the verification results, optimizing or eliminating strategies that fail the verification; and generating a strategy verification report as an important basis for subsequent strategy evaluation and deployment.

[0123] This embodiment achieves reliability verification and quality assurance of the defense strategy by establishing a multi-dimensional strategy verification system. First, a verification environment that simulates real network characteristics is constructed; then the strategy effect is comprehensively evaluated through a multi-dimensional verification indicator system; finally, the strategy is optimized and adjusted based on the verification results. This embodiment not only provides an objective evaluation of the strategy effect, but also ensures the reliability of the deployment strategy through simulation testing and hierarchical management. Compared with direct deployment, this pre-verification mechanism can effectively reduce the risk of strategy deployment and improve the reliability of the defense system.

[0124] According to one aspect of the present application, it also includes step S5, obtaining an optimized defense strategy set, evaluating the strategy effectiveness according to a preset evaluation system, and generating a strategy evaluation result; based on the strategy evaluation result, building a deployment plan to obtain a final deployment plan; obtaining real-time monitoring data, performing optimization adjustments based on the real-time monitoring data and the final deployment plan, and generating optimization feedback data.

[0125] S51, obtaining an optimized defense strategy set, and constructing an evaluation environment according to a preset evaluation index system; performing verification tests on the defense strategies in the optimized defense strategy set in the evaluation environment, and recording evaluation index data; calculating a comprehensive effect score based on the evaluation index data; and generating a strategy evaluation result according to the comprehensive effect score;

[0126] S52. Based on the policy evaluation results and the optimized defense policy set, extract the policy score, deployment cost and risk factor, and calculate the deployment priority; determine the deployment sequence based on the deployment priority and the pre-stored system resource status; analyze the policy dependency according to the deployment sequence, and generate a deployment execution plan; generate a final deployment plan based on the deployment execution plan;

[0127] S53. Acquire the real-time monitoring data generated by the system, and based on the real-time monitoring data and the final deployment plan, collect the effect data after the strategy deployment; calculate the deviation value between the effect data and the preset expected target; dynamically adjust the strategy parameters according to the deviation value to obtain the adjustment result; generate optimization feedback data based on the adjustment result.

[0128] In one embodiment of the present application, based on the optimized defense strategy set ODS, an evaluation index system E = {e1, e2, ..., e m}, build a simulation environment S to verify the strategy and calculate the comprehensive effect score: score = ∑w i e i , w iis the weight of the evaluation index, and the strategy evaluation result SER is output. Based on the strategy evaluation result SER and the optimized defense strategy set ODS, the deployment priority is calculated: p = f(score, cost, risk), f(score, cost, risk) is the function for calculating the deployment priority, and the priority of each defense strategy is determined based on the comprehensive effect score (score), cost (cost) and risk (risk). Construct the deployment sequence: t = g(p, resource), g( ) is the function for constructing the deployment sequence, resource is the available resource; generate the deployment plan: plan = h(t, dependency), h( ) is the function for generating the deployment plan, dependency is the strategy dependency, and output the final deployment plan FDP. Based on the final deployment plan FDP and the real-time monitoring data RTD, the deployment effect data is collected, the optimization target deviation is calculated, the strategy parameters are updated, and the optimization feedback data OFD is generated.

[0129] This embodiment realizes dynamic optimization and adaptive adjustment of defense strategies by establishing a complete strategy evaluation and deployment framework. First, the strategy effect is evaluated and a scientific evaluation system is established; then a detailed deployment plan is formulated based on the evaluation results to ensure the smooth implementation of the strategy; finally, the dynamic adjustment of the strategy is realized through real-time monitoring and feedback optimization mechanism. This embodiment not only ensures the effectiveness of the defense strategy, but also can adjust the strategy parameters in time according to environmental changes and attack evolution. By establishing a complete monitoring-evaluation-adjustment feedback loop, the adaptive capability and defense effect of the defense system are improved. Compared with the traditional static deployment method, this embodiment can better cope with complex and changing network security threats.

[0130] According to one aspect of the present application, step S52 is further:

[0131] S521. Obtain the strategy evaluation results and optimize the defense strategy set, extract the strategy evaluation score, and generate a strategy score vector; calculate the resource consumption of the strategy deployment to obtain a cost estimation matrix; evaluate the risk level of the strategy deployment and generate a risk factor set; construct a comprehensive evaluation model based on the strategy score vector, cost estimation matrix and risk factor set to obtain the deployment priority.

[0132] S522, obtain deployment priority, collect the current resource usage status of the system, generate a resource status matrix; calculate resource scheduling constraints to obtain a scheduling constraint set; build a timing optimization model based on the resource status matrix and the scheduling constraint set to generate an initial deployment timing.

[0133] S523, obtain the initial deployment timing, analyze the dependency relationship between the strategies, and obtain the dependency constraint graph; adjust the deployment order according to the dependency constraint graph to generate the adjusted timing data; perform conflict detection on the adjusted timing data to obtain a timing conflict set; optimize the deployment timing based on the timing conflict set to generate the final deployment timing.

[0134] S524. Obtain the final deployment timing, formulate execution rules for policy deployment, and generate an execution rule set; arrange deployment tasks according to the execution rule set to obtain a task schedule; design a synchronization mechanism between tasks and generate synchronization control parameters; construct an execution plan based on the task schedule and synchronization control parameters to obtain a deployment execution plan.

[0135] S525. Obtain a deployment execution plan, design monitoring indicators for the deployment process, and generate a monitoring indicator set; construct a rollback mechanism for the deployment process and obtain a rollback strategy table; formulate an emergency response plan and generate an emergency plan set; integrate the deployment execution plan, monitoring indicator set, rollback strategy table, and emergency plan set to generate a final deployment plan.

[0136] In one embodiment of the present application, the comprehensive evaluation model is constructed as follows: Evaluation function formula V(s) = α·Sc(s) + β·exp(-λ·Co(s)) + γ·(1-Ri(s)) η ; Where Sc(s) is the evaluation score of strategy s; Co(s) is the normalized cost; Ri(s) is the risk coefficient; α, β, γ are weight coefficients; λ is the cost sensitivity; η is the risk aversion; s is the strategy index; V(s) is the comprehensive evaluation value; multiple evaluation dimensions are balanced through nonlinear transformation.

[0137] The specific construction of the timing optimization model is as follows: the timing optimization objective function T(x) = min(∑(ti·xi) + θ·max(0, R(t)-Rmax)); where ti is the execution time of strategy i; xi is the deployment decision variable (0 / 1); R(t) is the resource occupancy at time t; Rmax is the resource upper limit; θ is the penalty coefficient; i is the strategy index; t is the time index; T(x) is the overall timing cost; the constraints include: dependency Di·xi ≤ Dj·xj, resource limit ∑(ri·xi) ≤ Rmax.

[0138] This embodiment achieves efficient deployment and dynamic adjustment of defense strategies by establishing a complete deployment optimization and execution control mechanism. First, the deployment priority is determined by comprehensively considering the strategy score, cost and risk factors; then the deployment sequence is optimized based on the system resource status; then the rationality of the deployment sequence is ensured through dependency constraint analysis; finally, a complete monitoring and rollback mechanism is established to ensure the reliability of the deployment. This embodiment not only takes into account the characteristics of the strategy itself, but also includes the influence of system resources and environmental constraints, ensuring the stability and controllability of the deployment process. By introducing emergency plans and rollback mechanisms, the fault tolerance and reliability of the deployment process are improved. Compared with traditional static deployment methods, it can better adapt to changes in the network environment and provide more flexible and reliable strategy deployment capabilities.

[0139] In another embodiment of the present application, step S2 also includes S20: obtaining an optimized feature matrix, first constructing a feature index table, and classifying the features in the matrix according to type, importance, and relevance; designing a feature selector, and determining how different features are represented in the graph structure according to their functions; for features representing node attributes, directly mapping them to node features; for features representing relationships, converting them to edge weights; for features representing global attributes, constructing a global context vector. In this way, it is ensured that all information in the optimized feature matrix can be fully utilized in the feature graph structure.

[0140] This embodiment achieves effective utilization and complete transfer of features by establishing a feature classification index and mapping mechanism. First, a feature index table is constructed to achieve systematic management of features; then, the feature selector is used to determine the representation of the feature in the graph structure according to the feature type; finally, a multi-level mapping mechanism is used to ensure full utilization of all feature information. This embodiment not only solves the problem of information loss during feature transfer, but also improves the efficiency of feature utilization through a reasonable feature mapping strategy. Compared with simple feature transfer, this embodiment can better maintain the integrity and availability of features.

[0141] In another embodiment of the present application, step S12 may also be: extracting spatiotemporal features based on the normalized multidimensional data matrix, specifically: constructing a multidimensional time series matrix T = [t1, t2, ..., t n ], introduces an adaptive step size parameter λ, dynamically adjusts the time elasticity, and optimizes the time complexity: adopts the Fast Dynamic Time Warping (FastDTW) variant to reduce the complexity from O(n 2 ) is reduced to O(n); output time series feature matrix TSM1. Or based on the standardized multidimensional data vector M, the time series is converted into a symbol sequence: S = {s1, s2, ..., sn}, construct the transition probability matrix P, calculate the symbol entropy H and complexity C, and output the time series feature matrix TSM2. Or based on the standardized multidimensional data vector M, select the optimal wavelet basis function φ(t), perform multi-scale decomposition to obtain the coefficient matrix W, extract the energy feature E and frequency feature F, and output the time series feature matrix TSM3.

[0142] Step S13 is: based on the time series feature matrix, generate an optimized feature matrix. Specifically: based on the time series feature matrix TSM, calculate according to the optimal transport (OT) theory: construct the source distribution P and the target distribution Q, construct the cost matrix C, solve the optimal transmission mapping T, and output the optimized feature matrix OFM1. Or based on the time series feature matrix TSM, calculate through the maximum mean difference (MMD): select the kernel function K(x, y), calculate the distribution difference in the feature space, construct an adaptive threshold τ, and output the optimized feature matrix OFM2. Or based on the time series feature matrix TSM, select the convex function f(t), calculate the divergence D_f(P||Q) between the probability distributions, construct the optimization objective function J, and output the optimized feature matrix OFM3.

[0143] The present invention introduces a dimension-adaptive interval division mechanism for the problem of normalization of multi-source heterogeneous data, specifically: independently calculate the data distribution characteristics for each dimension to identify the data characteristics of different dimensions; use the maximum entropy principle to dynamically determine the optimal number of intervals k for each dimension; based on the data density distribution characteristics, an adaptive binning strategy is adopted for different dimensions, taking into account the unique distribution characteristics of each dimension, avoiding the information loss caused by the unified scale conversion; by introducing an adaptive interval division method based on the maximum entropy principle, the normalization strategy can be dynamically adjusted according to the data distribution characteristics. In view of the problem of feature dimension mismatch in graph convolution, a feature dimension alignment mechanism is constructed, specifically including: constructing a feature dimension mapping layer to ensure the consistency of dimensions before and after graph convolution; designing a feature alignment module to achieve dimensional matching between hidden layer features and original features; introducing a dimension-adaptive residual connection module to adjust the dimensions through a learnable linear transformation; this ensures dimensional matching in the feature fusion process and improves the learning effect of the model; through a graph convolution filter based on Chebyshev polynomials and introducing a residual connection mechanism, adaptive fusion of features of different layers is achieved. In view of the problem of Markov chain modeling of threat propagation, the Markov chain modeling process is improved, including: sigmoid transformation of correlation strength, mapping the value range to the interval (0, 1); normalizing the outbound probability of each node to ensure that the probability sum is 1; introducing a stationarity test mechanism to verify the effectiveness of the model. This improvement ensures the theoretical correctness and practicality of the Markov chain model; considering the distance decay Markov chain model construction method, and designing a heuristic search rule based on multiple factors. In view of the problem of mapping feature matrix to graph structure, feature management and mapping mechanisms are added, including: constructing a feature index table to realize the classification management of features; designing a feature selector to determine the representation method according to the feature type; establishing a three-level mapping mechanism: node attribute mapping, edge weight mapping and global context mapping. This systematic feature management and mapping scheme ensures the complete transmission of feature information; constructing a feature mapping optimization method based on optimal transmission theory to ensure the efficient transmission of feature information. In response to the lack of a policy deployment verification mechanism, a complete verification mechanism has been established, including: building a verification environment that simulates real network characteristics; designing a multi-dimensional verification indicator system; implementing policy simulation testing and hierarchical management; establishing an optimization adjustment and feedback mechanism. This verification mechanism ensures the reliability and effectiveness of the deployment strategy; and improving the reliability of the defense strategy by establishing a complete policy evaluation system and dynamic optimization process, including three links: effect evaluation, deployment planning, and feedback optimization.

[0144] The present invention realizes the intelligence and adaptability of network security defense by constructing a complete self-evolutionary defense framework of data processing-feature extraction-threat analysis-strategy generation-dynamic deployment. First, through multi-dimensional data fusion and feature optimization, an accurate threat perception foundation is established; then, using graph neural networks and deep learning technology, the automatic identification of threat patterns is realized; then, through multi-dimensional evaluation and propagation analysis, the threat development trend is accurately predicted; then, the optimal defense strategy is generated through optimization algorithms; finally, a dynamic deployment and feedback optimization mechanism is established to achieve adaptive adjustment of the strategy. The present invention forms a closed-loop self-evolutionary system, which not only solves the problems of data heterogeneity, feature extraction difficulties, inaccurate threat identification, and policy conflicts in traditional defense methods, but also improves the intelligence level and adaptability of the defense system through continuous learning and optimization. Compared with traditional static defense schemes, the present invention can better cope with complex and changeable network security threats and provide more accurate and efficient defense capabilities.

[0145] The preferred embodiments of the present invention are described in detail above; however, the present invention is not limited to the specific details in the above embodiments. Within the technical concept of the present invention, various equivalent transformations can be made to the technical solutions of the present invention, and these equivalent transformations all belong to the protection scope of the present invention.

Claims

1. A self-evolving network security defense strategy generation and dynamic deployment method, characterized in that: The steps include: S1, obtain the original network traffic data, system log data, device status data and user behavior data, and generate an optimized feature matrix through adaptive interval division and symbolic conversion; S2. Construct a feature graph structure based on the optimized feature matrix; Based on the feature graph structure, the threat association matrix is ​​generated through graph neural network and attention mechanism; According to the threat association matrix, threat features are extracted and pattern clustering is performed to generate a threat pattern set; S3, obtaining a threat pattern set, constructing a multi-dimensional evaluation index according to a preset evaluation rule, and generating a threat evaluation index set; based on the threat evaluation index set and the threat association matrix, analyzing the propagation characteristics of the threat, and obtaining a threat propagation graph; S4, obtaining a threat assessment indicator set and a threat propagation graph, generating an initial defense strategy set according to a preset optimization rule; performing conflict detection and optimization processing based on the initial defense strategy set to obtain an optimized defense strategy set; S5. Obtain an optimized defense strategy set, evaluate the strategy effect according to a preset evaluation system, and generate a strategy evaluation result; Based on the strategy evaluation results, build a deployment plan to obtain the final deployment solution; Obtain real-time monitoring data, make optimization adjustments based on the real-time monitoring data and the final deployment plan, and generate optimization feedback data.

2. According to claim 1, a self-evolving network security defense strategy generation and dynamic deployment method is characterized in that: Step S1 is further as follows: S11, collecting original network traffic data, system log data, device status data and user behavior data, converting the original network traffic data, system log data, device status data and user behavior data into normalized data according to a preset normalization processing rule; constructing a multidimensional data collection matrix based on the normalized data to generate a normalized multidimensional data matrix; Wherein each column of the multidimensional data acquisition matrix corresponds to a data source; S12, mapping the values ​​in the normalized multidimensional data matrix to k preset value intervals to generate symbol sequence data; According to the symbol sequence data, the conversion relationship between adjacent symbols is calculated to generate a transition probability matrix; Based on the transition probability matrix, the sequence entropy value and complexity index are calculated to obtain the symbol feature matrix; Where k is a natural number greater than 1; S13, obtaining a symbol feature matrix, and constructing a distance measurement matrix according to a preset reference distribution; Based on the distance metric matrix, the transmission planning scheme is calculated to generate transmission planning data; According to the transmission planning data, the symbol characteristic matrix is ​​optimized and adjusted to obtain the optimized characteristic matrix.

3. A self-evolving network security defense strategy generation and dynamic deployment method according to claim 2, characterized in that: Step S2 is further as follows: S21, taking each feature in the optimized feature matrix as a node and constructing a feature node set; Based on the feature node set, the association strength between nodes is calculated to generate an edge weight matrix; based on the edge weight matrix and the preset association threshold, the connection relationship between nodes is determined to generate an adjacency matrix; Construct the feature graph structure based on the edge weight matrix and adjacency matrix; S22, based on the feature graph structure, extract feature information of each node and generate a node feature matrix; Perform graph convolution operation on the node feature matrix to obtain the node hidden layer features; Based on the hidden layer features of the nodes, calculate the attention coefficient between nodes; According to the attention coefficient, the node hidden layer features are weighted and aggregated to generate a threat association matrix; S23. Construct threat feature space based on threat association matrix; Based on the threat feature space, the similarity relationship between threat patterns is calculated to generate a pattern similarity matrix; Perform spectral clustering operation on the pattern similarity matrix to obtain the threat pattern grouping results; According to the threat pattern grouping results, relevant feature information is integrated to generate a threat pattern set.

4. A self-evolving network security defense strategy generation and dynamic deployment method according to claim 3, characterized in that: Step S3 is further as follows: S31, obtaining a threat pattern set and pre-stored historical threat data, and constructing an evaluation index system according to a preset evaluation dimension; based on the evaluation index system, assigning a weight coefficient to each evaluation index, and generating an index weight vector; and calculating a comprehensive evaluation score according to the index weight vector; Generate a threat assessment indicator set based on the comprehensive assessment score and assessment indicator system; S32, based on the threat association matrix and the threat assessment indicator set, calculating the propagation probability between threat nodes and generating a propagation probability matrix; Based on the propagation probability matrix, an improved shortest path algorithm is used to calculate the key propagation path; Calculate the node risk value based on the key propagation path and threat assessment indicator set; Generate the risk assessment results of the propagation path based on the key propagation paths and node risk values; Construct a threat propagation map based on the risk assessment results of the propagation path.

5. A self-evolving network security defense strategy generation and dynamic deployment method according to claim 4, characterized in that: Step S4 is further as follows: S41, obtain a threat assessment indicator set and a threat propagation graph, construct a defense cost matrix and a set of constraints; calculate the objective function value according to the defense cost matrix; based on the objective function value and the set of constraints, use the interior point method to perform optimization calculation to obtain the optimal defense plan; generate an initial defense strategy set according to the optimal defense plan; S42. Based on the initial defense strategy set, analyze the dependencies between strategies and construct a strategy dependency graph; Detecting circular dependencies in the policy dependency graph and generating dependency data; Eliminate policy conflicts based on preset priority rules and dependency data to obtain conflict elimination results; Based on the conflict elimination results, the initial defense strategy set is optimized and adjusted to generate an optimized defense strategy set.

6. A self-evolving network security defense strategy generation and dynamic deployment method according to claim 5, characterized in that: Step S12 is further as follows: S121. Based on the normalized multidimensional data matrix, calculate the distribution characteristics of the data and generate the data distribution characteristics; according to the data distribution characteristics, use the maximum entropy principle to determine the optimal number of intervals and generate interval quantity parameters; based on the interval quantity parameters and the data distribution characteristics, use the equal frequency binning method to divide the numerical intervals and obtain the interval boundary sequence; S122, constructing a mapping function from numerical values ​​to symbols based on the interval boundary sequence and the normalized multidimensional data matrix; converting the data according to the mapping function to generate an initial symbol sequence; Calculate the information entropy of the initial symbol sequence to obtain the sequence information entropy; Based on the sequence information entropy, the mapping function is optimized and adjusted to generate symbol sequence data; S123, based on the symbol sequence data, counting the occurrence frequency of adjacent symbol pairs to generate a frequency statistics matrix; Based on the frequency statistics matrix, the conditional probability is calculated to obtain the initial transition probability; Perform Laplace smoothing on the initial transition probability to generate a transition probability matrix; S124. Based on the transition probability matrix, the stationary distribution probability of each state is calculated to obtain a state probability vector; based on the state probability vector and the transition probability matrix, a normalized entropy value is calculated to generate a sequence entropy value; based on the sequence entropy value, the sequence complexity is calculated to obtain a complexity index; S125. Construct a feature vector based on the sequence entropy value, complexity index and transition probability matrix; Normalizing the feature vector to generate a normalized feature vector; Organize the normalized eigenvectors into a matrix form to generate a symbolic eigenmatrix.

7. A self-evolving network security defense strategy generation and dynamic deployment method according to claim 5, characterized in that: Step S13 is further as follows: S131, based on the symbolic feature matrix, calculating the empirical distribution characteristics of the data to generate empirical distribution data; based on a preset ideal Gaussian distribution, constructing a reference distribution model to obtain reference distribution data; according to the empirical distribution data and the reference distribution data, calculating the distribution difference to generate a distribution difference vector; S132, constructing a pairwise distance calculation function based on the distribution difference vector; using the pairwise distance calculation function, calculating the point pair distances in the feature space to obtain an initial distance matrix; Normalize the initial distance matrix to generate a distance metric matrix; S133, constructing a transmission cost model based on the distance metric matrix and generating a cost coefficient matrix; Based on the cost coefficient matrix, a linear programming problem is constructed; The improved simplex method is used to solve the linear programming problem and generate transmission planning data; S134, calculating the optimal transmission path based on the transmission planning data to obtain a transmission path set; According to the transmission path set, a feature mapping function is constructed to generate a feature mapping matrix; Based on the feature mapping matrix, the symbolic feature matrix is ​​transformed to obtain an initial optimization matrix; S135. Based on the initial optimization matrix, calculate the distribution deviation before and after optimization to generate deviation index data; perform local fine-tuning based on the deviation index data to obtain an adjustment parameter set; based on the adjustment parameter set, perform fine-tuning on the initial optimization matrix to generate an optimized feature matrix.

8. A self-evolving network security defense strategy generation and dynamic deployment method according to claim 5, characterized in that: Step S22 is further as follows: S221, obtaining node feature data in the feature graph structure, extracting attribute information of each node, and generating a node attribute vector; performing dimension alignment on the node attribute vector to obtain aligned feature data; Organizing the alignment feature data into a matrix form to generate a node feature matrix; S222. Based on the node feature matrix, construct a Laplace operator to generate a Laplace matrix; perform eigendecomposition on the Laplace matrix to obtain an eigenvalue sequence and an eigenvector matrix; Based on the eigenvalue sequence and eigenvector matrix, a Chebyshev polynomial filter is constructed to generate a graph convolution kernel; S223, based on the graph convolution kernel and the node feature matrix, perform a graph convolution operation to obtain initial hidden layer features; perform a nonlinear transformation on the initial hidden layer features to generate activation feature data; The residual connection mechanism is used to combine the data in the node feature matrix and the activated feature data to obtain the node hidden layer features; S224, based on the node hidden layer features, calculating the similarity scores between the node pairs and generating a similarity matrix; Normalize the similarity matrix to obtain the initial attention coefficient; Based on the initial attention coefficient, the attention distribution is adjusted using the pre-stored temperature parameter to generate an attention coefficient matrix; S225, performing a weighted sum operation based on the attention coefficient matrix and the node hidden layer features to obtain aggregated feature data; The aggregated feature data is scaled and normalized to generate a normalized feature matrix; the normalized feature matrix is ​​converted into an association strength representation to generate a threat association matrix.

9. A self-evolving network security defense strategy generation and dynamic deployment method according to claim 5, characterized in that: Step S32 is further as follows: S321, based on the threat association matrix and the threat assessment indicator set, extract the association strength data between the nodes to generate an association strength vector; according to the association strength vector, construct a Markov chain model to obtain a state transfer matrix; normalize the state transfer matrix to generate a propagation probability matrix; S322. Based on the propagation probability matrix, calculate the edge weight coefficient and generate the edge weight matrix; construct a directed weighted graph model to obtain the network topology structure; Based on the network topology and edge weight matrix, heuristic search rules are constructed to generate path search parameters; S323, based on the path search parameters and the network topology, using the improved Dijkstra algorithm to perform path search to obtain a candidate path set; calculating the propagation probability of each path in the candidate path set to generate a path probability vector; based on the path probability vector, screening the key propagation path to obtain a key path set; S324, based on the critical path set and the threat assessment indicator set, calculating the cumulative risk value of the nodes on the path, and generating a node risk matrix; Based on the node risk matrix, the diffusion range of the path propagation is evaluated to obtain the diffusion range data; Combine the node risk matrix and diffusion range data to generate risk assessment results; S325. Based on the risk assessment results, a graph structure representation model is constructed to generate a graph structure template; Map the risk assessment results into the graph structure template to obtain node attribute data; Based on the key path set, the propagation path information is extracted; the node attribute data and propagation path information are integrated to generate a threat propagation graph.

Citation Information

Patent Citations

  • Main body state recognition method and device based on multi-dimensional model fusion framework

    CN115374836A

  • Computer network intelligent analysis platform based on big data

    CN118965172A