A distributed network security automation intelligent compliance system

By introducing distributed architecture and intelligent compliance determination modules into the network security system, the problems of inefficient compliance detection and high risk of single point failure are solved, and efficient and intelligent compliance detection and dynamic response capabilities are achieved.

CN119628970BActive Publication Date: 2025-05-30BEIJING HUIERTE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510151452.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-30
Estimated Expiration
2045-02-11

AI Technical Summary

Technical Problem

In the prior art, network security compliance detection is inefficient, high risk of single point failure, lack of adaptability, and lagging rule updates and response mechanisms, so it is impossible to quickly respond to complex cyber attack patterns and dynamic changes in compliance requirements.

Method used

Design a network security automation intelligent compliance system based on distributed architecture, including distributed node deployment module, data acquisition and processing module, compliance rule database and update module, intelligent compliance judgment module and dynamic risk response module, and improve detection efficiency and accuracy through distributed algorithms, dynamic rule updates, intelligent evaluation and real-time response mechanisms.

Benefits of technology

It significantly improves the efficiency and accuracy of network security compliance detection, reduces the risk of single point of failure, realizes dynamic rule updates and intelligent evaluation, and enhances the flexibility and effectiveness of network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119628970B_ABST
    Figure CN119628970B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of new generation information technologies, and discloses a distributed network security automation intelligent compliance system. Among them, the distributed node deployment module uses a distributed algorithm to allocate compliance detection tasks to each node; the data collection and processing module automatically collects network logs, user behaviors, and traffic data; the compliance rule library and update module conducts compliance determination according to the multi-dimensional dynamic rule matching method; the intelligent compliance determination module conducts multi-level evaluation of network compliance through a distributed deep learning model; the dynamic risk response module calculates the real-time response priority, triggers the corresponding response mechanism based on the priority, and at the same time supports the generation of automated emergency strategies. The present invention realizes efficient detection and dynamic response of network compliance through intelligent technologies, and provides an efficient, intelligent, and reliable solution for network security management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of new generation information technology, and more particularly, to a distributed network security automation intelligent compliance system. Background Art

[0002] With the rapid development of network technology and the continuous improvement of informatization level, network security has become an important issue that needs to be urgently solved in all walks of life in society. Traditional network security compliance detection methods usually adopt a centralized architecture, and a single central node is used to monitor and evaluate the security compliance of the entire network. However, this method has many limitations, mainly manifested as low detection efficiency, high single-point failure risk, and lack of adaptability to large-scale distributed network environments. In addition, the update of the compliance detection rule base often relies on manual operations, which cannot quickly respond to emerging network security threats, and the rule matching is mostly static, making it difficult to cope with complex network attack patterns and dynamically changing compliance requirements. At the same time, most traditional risk response mechanisms rely on preset fixed strategies and lack the ability of real-time dynamic adjustment and optimization, resulting in the inability of network security management to respond to network security events in a timely and effective manner.

[0003] Therefore, the development of a distributed architecture-based network security automation intelligent compliance system, combined with dynamic rule updates, intelligent evaluation, and real-time response mechanisms, has become an urgent need to improve the efficiency and accuracy of network security compliance detection. Summary of the Invention

[0004] There is an urgent practical need to build a network security automation intelligent compliance system that integrates dynamic rule updates, intelligent evaluation, and real-time response mechanisms to improve the efficiency and accuracy of network security compliance detection. In view of this, the present invention proposes a distributed network security automation intelligent compliance system, aiming to solve the problems of low efficiency of network security compliance detection, high single-point failure risk, lack of adaptability, and lagging rule update and response mechanisms in the prior art. This system can improve the detection efficiency and accuracy through the collaborative work of distributed nodes, while reducing the risk of single-point failure. It can update the compliance detection rule base in real time, quickly adapt to new network security threats, and through an intelligent evaluation mechanism, dynamically match complex network attack patterns and changing compliance requirements. In addition, the real-time response mechanism can dynamically adjust and optimize the risk response strategy according to the real-time situation of network security events, so as to achieve more flexible and effective network security management.

[0005] The present invention proposes a distributed network security automation intelligent compliance system, including a distributed node deployment module, a data collection and processing module, a compliance rule base and update module, an intelligent compliance determination module, and a dynamic risk response module;

[0006] Among them, the distributed node deployment module is configured to use a distributed algorithm to allocate compliance detection tasks to each node, and connect to the data collection and processing module through a communication interface to coordinate the collection tasks of each node;

[0007] The data collection and processing module is configured to automatically collect and process network logs, user behaviors, and traffic data, and transmit the processed standardized data to the compliance rule library and update module through a data transmission interface;

[0008] The compliance rule library and update module is configured to store and update multi-dimensional dynamic rules, perform compliance determination based on the received standardized data, and transmit the determination result to the intelligent compliance determination module;

[0009] The intelligent compliance determination module is configured to perform multi-level evaluation of compliance through a distributed deep learning model, and feedback the evaluation result to the compliance rule library and update module to optimize the rule library, and at the same time send the evaluation result to the dynamic risk response module;

[0010] The dynamic risk response module is configured to calculate the real-time response priority according to the evaluation result of the intelligent compliance determination module, and trigger the corresponding response mechanism based on the priority; the dynamic risk response module is also configured to support the generation of automated emergency strategies, calculate the optimal response path through a multi-objective optimization algorithm, and return the emergency strategy to the distributed node deployment module to dynamically adjust the node task allocation scheme and achieve closed-loop optimization.

[0011] Preferably, the distributed node deployment module calculates the task weights of each node through the following distributed task allocation formula to dynamically allocate compliance detection tasks:

[0012] ;

[0013] Where, W i represents the task allocation weight of the i-th node; R i represents the computing resource utilization rate of the i-th node; R j represents the computing resource utilization rate of the j-th node; j represents the index variable, and the range is 1 - n; n represents the total number of distributed nodes; L i represents the current task load of the i-th node; T represents the total task volume.

[0014] Preferably, the data collection and processing module performs multi-dimensional noise reduction processing on the collected network logs, user behaviors, and traffic data through the following formula:

[0015] ;

[0016] Among them, D(t) represents the original data at time t; D′(t) represents the denoised data at time t; M represents the number of samples within the sliding window; D k (t) represents the data value at the k-th sampling point.

[0017] Preferably, the compliance rule library and the update module perform compliance determination through a dynamic rule matching algorithm, and its correlation score is calculated by the following formula:

[0018] ;

[0019] Among them, S k represents the matching correlation score of rule k; R ik represents the degree of compliance of the i-th parameter under rule k; p represents the total number of parameters required for rule matching.

[0020] Preferably, the intelligent compliance determination module performs multi-level evaluation through a distributed deep learning model, and its model evaluation formula is as follows:

[0021] ;

[0022] Among them, C represents the compliance evaluation result; σ represents the Sigmoid function; L represents the number of layers of the deep learning model; W i and b i respectively represent the weight and bias of the i-th layer; X i represents the input data; ReLU(x)=max(0,x) represents the rectified linear unit activation function.

[0023] Preferably, the dynamic risk response module calculates the real-time response priority through the following formula and triggers the corresponding response mechanism based on the priority:

[0024] ;

[0025] Among them, P r represents the risk response priority; V represents the severity score of the risk; E represents the exposure degree; λ represents the dynamic adjustment factor; T r represents the expected response time; ϵ represents a minimum value to avoid a zero denominator.

[0026] Preferably, the dynamic risk response module uses a multi-objective optimization algorithm to generate an optimal response path, and its objective function is as follows:

[0027] ;

[0028] Among them, T represents the time required for the response; R represents the degree of risk reduction; C represents the response cost; α, β, and γ respectively represent the objective weight coefficients.

[0029] Preferably, the system supports multi-threaded task scheduling optimization, and its scheduling efficiency is evaluated by the following formula:

[0030] ;

[0031] where E s represents the task scheduling efficiency; L i represents the total load of the i-th task; T i represents the completion time of the i-th task; and n represents the total number of tasks.

[0032] Preferably, the compliance rule library and the update module optimize the rule library through an incremental learning mechanism, and its optimization increment calculation formula is:

[0033] ;

[0034] where ΔR represents the rule library optimization increment; ω k represents the weight of rule k; , are the scoring values before and after the update of rule k respectively; and q represents the number of updated rules.

[0035] Preferably, the system optimizes the overall compliance through a closed-loop feedback mechanism, and its feedback adjustment formula is as follows:

[0036] ;

[0037] where F t , F t-1 represent the feedback adjustment values at times t and t-1 respectively; η represents the feedback adjustment rate; Rt and R t−1 represent the compliance evaluation values at times t and t−1 respectively.

[0038] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0039] High efficiency and reliability: The system uses a distributed algorithm for task allocation, effectively avoiding the risk of single-point failure and significantly improving the efficiency of compliance detection and the reliability of the system.

[0040] Dynamic rule adaptive update: Through multi-dimensional dynamic rule matching and incremental learning mechanism, the system can automatically update the rule library according to the latest network security threats, thus enhancing the timeliness and accuracy of compliance detection.

[0041] Intelligent compliance evaluation: This research uses a distributed deep learning model to conduct multi-level evaluations of compliance, which can handle complex network behaviors and achieve more comprehensive compliance judgments.

[0042] Response mechanism optimization: Based on dynamic priority calculation and multi-objective optimization algorithms, the system can generate optimal emergency response strategies in real time, significantly improving the efficiency of risk management and emergency response.

[0043] Closed-loop optimization ability: The system dynamically adjusts task allocation, rule base update, and response strategies through a feedback mechanism to ensure continuous optimization of network security management. Brief Description of the Drawings

[0044] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0045] Figure 1 It is a functional block diagram of the distributed network security automation intelligent compliance system of the present invention. Detailed Embodiments

[0046] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.

[0047] Refer to Figure 1 , this embodiment provides a distributed network security automation intelligent compliance system, including a distributed node deployment module, a data collection and processing module, a compliance rule base and update module, an intelligent compliance determination module, and a dynamic risk response module;

[0048] Among them, the distributed node deployment module is configured to allocate compliance detection tasks to each node using a distributed algorithm and connect to the data collection and processing module through a communication interface to coordinate the collection tasks of each node;

[0049] The data collection and processing module is configured to automatically collect and process network logs, user behaviors, and traffic data, and transmit the processed standardized data to the compliance rule base and update module through a data transmission interface;

[0050] The compliance rule library and update module are configured to store and update multi-dimensional dynamic rules, perform compliance judgments based on the received standardized data, and transfer the judgment results to the intelligent compliance judgment module;

[0051] The intelligent compliance judgment module is configured to perform multi-level evaluations of compliance through a distributed deep learning model, and feedback the evaluation results to the compliance rule library and update module to optimize the rule library, while sending the evaluation results to the dynamic risk response module;

[0052] The dynamic risk response module is configured to calculate the real-time response priority according to the evaluation results of the intelligent compliance judgment module and trigger the corresponding response mechanism based on the priority; the dynamic risk response module is also configured to support the generation of automated emergency strategies, calculate the optimal response path through a multi-objective optimization algorithm, and return the emergency strategies to the distributed node deployment module to dynamically adjust the node task allocation scheme and achieve closed-loop optimization.

[0053] It can be seen that this embodiment proposes a network security automated intelligent compliance system based on a distributed architecture. The system consists of multiple key modules, including a distributed node deployment module, a data collection and processing module, a compliance rule library and update module, an intelligent compliance judgment module, and a dynamic risk response module;

[0054] In this embodiment, the distributed node deployment module is designed to use advanced distributed algorithms to allocate compliance detection tasks to each network node, and is connected to the data collection and processing module through a communication interface to ensure that the nodes can execute the collection tasks in a coordinated manner;

[0055] The data collection and processing module is given the ability to automatically collect network logs, user behaviors, and traffic data, and can process these data. The processed standardized data will be transmitted to the compliance rule library and update module through a data transmission interface;

[0056] The compliance rule library and update module is responsible for storing and periodically updating a series of multi-dimensional dynamic rules. It will perform compliance judgments based on the received standardized data and transfer the judgment results to the intelligent compliance judgment module;

[0057] The intelligent compliance judgment module then uses a distributed deep learning model to conduct in-depth multi-level evaluations of compliance. The evaluation results will not only be fed back to the compliance rule library and update module to help optimize the rule library, but also be sent to the dynamic risk response module;

[0058] The dynamic risk response module calculates the real-time response priority based on the evaluation results of the intelligent compliance determination module and triggers the corresponding response mechanism according to this priority. In addition, the dynamic risk response module also has the ability to support the generation of automated emergency strategies. It calculates the optimal response path through a multi-objective optimization algorithm and returns these emergency strategies to the distributed node deployment module, thereby dynamically adjusting the node task allocation scheme and achieving the closed-loop optimization of the entire system.

[0059] It can be understood that the advantage of this embodiment lies in its ability to significantly improve the automation and intelligence level of network security compliance. Through distributed node deployment, the system can efficiently utilize network resources to achieve comprehensive monitoring and compliance detection of a large-scale network environment. At the same time, the automated collection and processing capabilities of the data collection and processing module ensure the accuracy and timeliness of data, providing a solid foundation for compliance determination. The dynamic update mechanism of the compliance rule library and update module enables the system to promptly respond to new compliance requirements and threats, improving the flexibility and adaptability of the system. The intelligent compliance determination module conducts multi-level evaluations through deep learning models, not only improving the accuracy of compliance determination but also being able to discover potential compliance risks, providing strong support for the enterprise's network security management. The real-time response and automated emergency strategy generation capabilities of the dynamic risk response module further enhance the system's ability to respond to network security incidents and reduce the enterprise's security risks. In summary, the distributed-based network security automation intelligent compliance system of this embodiment provides an efficient, intelligent, and flexible network security compliance solution for enterprises.

[0060] In some embodiments of the present application, the distributed node deployment module calculates the task weights of each node through the following distributed task allocation formula and dynamically allocates compliance detection tasks:

[0061] ;

[0062] where W i represents the task allocation weight of the i-th node; R i represents the computing resource utilization rate of the i-th node; R j represents the computing resource utilization rate of the j-th node; j represents an index variable with a range of 1 - n; n represents the total number of distributed nodes; L i represents the current task load of the i-th node; T represents the total task volume.

[0063] It can be understood that this embodiment proposes an innovative distributed task allocation formula for dynamically adjusting the task weights of each node, thereby optimizing the allocation of compliance detection tasks. In this formula, Wi represents the task allocation weight of the i-th node, which is calculated based on the computing resource utilization rate (Ri) and the current task load (Li) of the node. At the same time, the formula also considers the computing resource utilization rate (Rj) of other nodes (j) to ensure the fairness and efficiency of task allocation. The total task volume (T) is used as a benchmark to evaluate the proportion of tasks that each node should undertake. In this way, the system can intelligently adjust the task allocation scheme according to the real-time status of each node and the overall task requirements, thereby maximizing resource utilization and task execution efficiency. This innovation not only enhances the flexibility and response speed of the system but also provides a more reliable and efficient network security compliance solution for enterprises.

[0064] In some embodiments of the present application, the data acquisition and processing module performs multi-dimensional noise reduction processing on the collected network logs, user behaviors, and traffic data through the following formula:

[0065] ;

[0066] where D(t) represents the original data at time t; D′(t) represents the noise-reduced data at time t; M represents the number of samples within the sliding window; D k (t) represents the data value of the k-th sampling point.

[0067] It can be understood that this embodiment also proposes a unique multi-dimensional noise reduction processing method for improving the accuracy and efficiency of the data acquisition and processing module. In this method, D(t) represents the original data at time t, which may contain various noises and interferences. To obtain clearer and more accurate data, the system adopts a noise reduction processing process to generate D′(t), that is, the noise-reduced data at time t. This process utilizes a sliding window technique, where M represents the number of samples within the sliding window. By considering multiple sampling points within the window (D k (t) represents the data value of the k-th sampling point), the system can effectively smooth the data and reduce the interference of noise. This method can not only improve the accuracy of the data but also optimize the efficiency and reliability of subsequent compliance determination. By combining this multi-dimensional noise reduction processing technology, the network security automated intelligent compliance system of this embodiment can further improve its automation and intelligence level and provide a more accurate and efficient network security compliance management solution for enterprises.

[0068] In some embodiments of the present application, the compliance rule library and update module perform compliance determination through a dynamic rule matching algorithm, and its correlation score is calculated by the following formula:

[0069] ;

[0070] where S k represents the matching relevance score of rule k; R ik represents the degree of compliance of the i-th parameter under rule k; p represents the total number of parameters required for rule matching.

[0071] It can be understood that this embodiment also proposes an advanced dynamic rule matching algorithm for improving the accuracy and efficiency of compliance determination. In this algorithm, S k represents the matching relevance score of rule k, which is calculated based on the weights (W i ) of multiple parameters and the degree of compliance (R ik ) of these parameters under rule k. The weight of each parameter reflects its importance in compliance determination, while the degree of compliance measures the matching degree between the actual data and the rule requirements. By comprehensively considering these parameters, the system can give a comprehensive score for evaluating whether network behavior or data complies with compliance requirements. In addition, the algorithm also considers the total number of parameters (p) required for rule matching to ensure the comprehensiveness and accuracy of the evaluation. This dynamic rule matching algorithm not only improves the precision of compliance determination but also enhances the adaptability and flexibility of the system. As the network environment and compliance requirements change, the system can automatically adjust the rule matching strategy to ensure the timeliness and accuracy of compliance determination. This innovation enables the network security automation intelligent compliance system of this embodiment to better adapt to the complex and changing network environment and provide more comprehensive and efficient compliance management support for enterprises.

[0072] In some embodiments of the present application, the intelligent compliance determination module performs multi-level evaluation through a distributed deep learning model, and its model evaluation formula is as follows:

[0073] ;

[0074] where C represents the compliance evaluation result; σ represents the Sigmoid function; L represents the number of layers of the deep learning model; W i , b i respectively represent the weight and bias of the i-th layer; X i represents the input data; ReLU(x)=max(0,x) represents the rectified linear unit activation function.

[0075] It can be understood that this embodiment also proposes an innovative distributed deep learning model for multi-level compliance assessment. In this model, C represents the compliance assessment result, which is obtained through a series of complex calculations and aims to accurately reflect whether network behavior or data complies with compliance requirements. To achieve this goal, the system adopts the Sigmoid function (σ), which can map the input value to between 0 and 1 and is thus used for binary classification problems, i.e., compliance or non-compliance. In addition, the model also considers the number of layers (L) of the deep learning model. Each layer has its specific weight (Wi) and bias (bi), and these parameters are continuously optimized during the training process to improve the accuracy and generalization ability of the model. The input data (Xi) is passed through the model layer by layer, and each layer uses the rectified linear unit activation function (ReLU(x)=max(0,x)) for non-linear transformation to enhance the expressive ability of the model. This multi-level assessment method not only improves the accuracy of compliance determination but also enables the system to automatically learn and adapt to new compliance requirements. By combining the advantages of distributed computing, the network security automation intelligent compliance system of this embodiment can efficiently process a large amount of network data, conduct compliance assessment in real time, and provide more timely and reliable compliance management services for enterprises.

[0076] In some embodiments of the present application, the dynamic risk response module calculates the real-time response priority through the following formula and triggers the corresponding response mechanism based on the priority:

[0077] ;

[0078] where P r represents the risk response priority; V represents the severity score of the risk; E represents the exposure degree; λ represents the dynamic adjustment factor; T r represents the expected response time; ϵ represents a minimum value to avoid a zero denominator.

[0079] It can be understood that this embodiment also proposes an efficient dynamic risk response mechanism for quickly responding when a network security event occurs. In this mechanism, P r represents the priority of risk response, which is calculated comprehensively based on multiple factors and aims to ensure that the system can give priority to handling the most important and urgent risk events. The severity score (V) of the risk is an important indicator to measure the potential harm degree of the risk, which reflects the losses or impacts that may be caused once the risk occurs. The exposure degree (E) considers the scope or the number of audiences that the risk event may affect to evaluate the extensiveness and potential impact of the risk. The dynamic adjustment factor (λ) allows the system to flexibly adjust the risk response priority according to factors such as the current network environment, resource status, or business priority. The expected response time (T r)(ϵ) is an important parameter for the system to evaluate the time required to process risk events. It helps the system reasonably allocate resources and ensure a response within the shortest time. To avoid the denominator being zero, the system also introduces a minimum value (ϵ). Through this dynamic risk response mechanism, the network security automation intelligent compliance system of this embodiment can evaluate the priority of risk events in real time and automatically trigger corresponding response measures, such as isolating the affected network area, notifying the security team for emergency handling, or starting the backup system. This efficient response mechanism not only improves the security of the system but also ensures the continuity and stability of enterprise business.

[0080] In some embodiments of the present application, the dynamic risk response module uses a multi-objective optimization algorithm to generate an optimal response path, and its objective function is as follows:

[0081] ;

[0082] where T represents the time required for the response; R represents the degree of risk reduction; C represents the response cost; α, β, and γ respectively represent the objective weight coefficients.

[0083] It can be understood that this embodiment also proposes a method for generating a dynamic risk response path based on a multi-objective optimization algorithm. In this method, T represents the time required for the response, which is a key indicator to measure the response speed. The shorter the time, the faster the system can respond to risk events and reduce potential damage. R represents the degree of risk reduction, which reflects the control and mitigation effect of the response measures on risk events. The higher the degree of risk reduction, the better the protection effect of the system. C represents the response cost, covering various inputs such as human, material, and financial resources. The lower the cost, the stronger the economy and practicality of the system. To balance these three objectives, the system introduces objective weight coefficients (α, β, and γ), which respectively represent the importance of time, risk reduction degree, and cost in the overall optimization. By adjusting these weight coefficients, the system can generate an optimal response path according to different business requirements and risk preferences. This multi-objective optimization algorithm not only improves the rationality and effectiveness of the response path but also enables the system to achieve the optimal security benefit with limited resources.

[0084] In some embodiments of the present application, the system supports multi-threaded task scheduling optimization, and its scheduling efficiency is evaluated by the following formula:

[0085] ;

[0086] where E s represents the task scheduling efficiency; L i represents the total load of the i-th task; T i represents the completion time of the i-th task; n represents the total number of tasks.

[0087] It is understandable that this embodiment also proposes an optimization method for multi-threaded task scheduling, aiming to improve the processing capacity and response speed of the system in a high-concurrency environment. In this method, E s represents the efficiency of task scheduling and is an important indicator for measuring system performance. It comprehensively considers the load (L i ) and completion time (T i ) of each task. Through reasonable task allocation and scheduling strategies, the system can efficiently process multiple concurrent tasks. L i reflects the occupation of system resources by tasks. The higher the load, the higher the requirements of the task on the system. T i measures the speed at which the system processes tasks. The shorter the time, the stronger the processing capacity of the system. By calculating the average load and completion time of all tasks and combining the total number of tasks (n), the system can evaluate the current task scheduling efficiency. This multi-threaded task scheduling optimization method not only improves the concurrent processing capacity of the system but also ensures the stability and reliability of the system under high load. Through this optimization, the network security automation intelligent compliance system of this embodiment can better adapt to the complex and changing network environment and provide more comprehensive and efficient security protection for enterprises.

[0088] In some embodiments of the present application, the compliance rule library and the update module optimize the rule library through an incremental learning mechanism, and its optimization increment calculation formula is:

[0089] ;

[0090] where ΔR represents the optimization increment of the rule library; ω k represents the weight of rule k; , are the scoring values before and after the update of rule k respectively; q represents the number of updated rules.

[0091] It is understandable that this embodiment also proposes a compliance rule library optimization method based on an incremental learning mechanism. In this method, ΔR represents the optimization increment of the rule library and is a key indicator for measuring the update effect of the rule library. It calculates the optimization degree of the rule library during the update process by evaluating the weight (ω k ) and comparing the scores (the scoring values before and after the update) of each rule. ω kIt reflects the importance of the rule in the overall rule library. The higher the weight, the greater the impact of the rule on the system decision. The comparison of the scoring values before and after the update intuitively demonstrates the improvement in the effect brought by the rule update. By comprehensively considering the number of updated rules (q) and the optimization increment of each rule, the system can accurately evaluate the overall optimization effect of the rule library. This incremental learning mechanism not only improves the timeliness and accuracy of the rule library but also enables the system to continuously learn and evolve, better adapting to the ever-changing network security threats. Through this optimization, the network security automation intelligent compliance system of this embodiment can ensure the accuracy and effectiveness of the compliance rules, further enhancing the enterprise's network security protection ability.

[0092] In some embodiments of the present application, the system optimizes the overall compliance through a closed-loop feedback mechanism, and its feedback adjustment formula is as follows:

[0093] ;

[0094] where, F t and F t-1 respectively represent the feedback adjustment values at time t and t - 1; η represents the feedback adjustment rate; Rt, R t−1 respectively represent the compliance evaluation values at time t and t−1.

[0095] It can be understood that this embodiment also proposes an overall compliance optimization method based on a closed-loop feedback mechanism. In this method, F t and F t-1 respectively represent the feedback adjustment values at time t and t - 1, which reflect the adjustment and optimization of the compliance status by the system at different time points. By comparing these two values, the system can evaluate the change trend of compliance over time and make corresponding adjustments accordingly. η represents the feedback adjustment rate, which determines the sensitivity and speed of the system's response to changes in compliance. R t and R t-1 respectively represent the compliance evaluation values at time t and t - 1, which are obtained by comprehensively checking and evaluating the compliance status of the system and are key indicators for measuring the compliance level of the system.

[0096] By introducing a closed-loop feedback mechanism, the system can monitor and evaluate its own compliance status in real time. Once a deviation or deficiency is found, it immediately starts the feedback adjustment process and quickly restores and improves the compliance level by adjusting the system configuration, optimizing the strategy, or enhancing the protection measures. This mechanism not only enhances the system's self-repair and self-optimization capabilities but also ensures that the system always maintains a high level of compliance and security during long-term operation. Through this optimization, the network security automation intelligent compliance system of this embodiment can provide more stable and reliable network security protection for the enterprise.

[0097] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0098] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0099] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0100] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that it is still possible to modify the specific implementation manners of the present invention or make equivalent replacements. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

Claims

1. A distributed network security automated intelligent compliance system, characterized in that: It includes distributed node deployment module, data collection and processing module, compliance rule base and update module, intelligent compliance determination module and dynamic risk response module; Wherein, the distributed node deployment module is configured to use a distributed algorithm to distribute compliance detection tasks to each node, and is connected to the data acquisition and processing module through a communication interface to coordinate the acquisition tasks of each node; The data collection and processing module is configured to automatically collect and process network logs, user behavior and traffic data, and transmit the processed standardized data to the compliance rule library and update module through a data transmission interface; The compliance rule library and update module is configured to store and update multi-dimensional dynamic rules, perform compliance determination based on received standardized data, and transmit the determination results to the intelligent compliance determination module; The intelligent compliance determination module is configured to perform multi-level compliance assessment through a distributed deep learning model, and feed back the assessment results to the compliance rule base and update module to optimize the rule base, and send the assessment results to the dynamic risk response module; The dynamic risk response module is configured to calculate the real-time response priority according to the evaluation result of the intelligent compliance determination module, and trigger the corresponding response mechanism based on the priority; the dynamic risk response module is also configured to support automatic emergency strategy generation, calculate the optimal response path through a multi-objective optimization algorithm, and return the emergency strategy to the distributed node deployment module to dynamically adjust the node task allocation plan to achieve closed-loop optimization; The distributed node deployment module calculates the task weight of each node through the following distributed task allocation formula and dynamically allocates compliance detection tasks: ; Among them, W i represents the task allocation weight of the i-th node; R i represents the computing resource utilization of the i-th node; R j represents the computing resource utilization of the jth node; j represents an index variable ranging from 1 to n; n represents the total number of distributed nodes; L i represents the current task load of the i-th node; T represents the total task volume; The data collection and processing module performs multi-dimensional noise reduction processing on the collected network logs, user behavior and traffic data through the following formula: ; Where D(t) represents the original data at time t; D′(t) represents the denoised data at time t; M represents the number of samples in the sliding window; D k (t) represents the data value of the kth sampling point.

2. The distributed network security automation intelligent compliance system according to claim 1 is characterized in that: The compliance rule base and update module perform compliance determination through a dynamic rule matching algorithm, and the relevance score is calculated by the following formula: ; Among them, S k represents the matching relevance score of rule k; R ik It indicates the degree of compliance of the i-th parameter under rule k; p indicates the total number of parameters required for rule matching.

3. The distributed network security automation intelligent compliance system according to claim 2 is characterized in that: The intelligent compliance determination module performs multi-level evaluation through a distributed deep learning model, and its model evaluation formula is as follows: ; Where C represents the compliance assessment result; σ represents the Sigmoid function; L represents the number of layers of the deep learning model; W i 、b i Represent the weight and bias of the i-th layer respectively; X i Represents input data; ReLU(x)=max(0,x) represents the rectified linear unit activation function.

4. The distributed network security automation intelligent compliance system according to claim 3 is characterized in that: The dynamic risk response module calculates the real-time response priority using the following formula and triggers the corresponding response mechanism based on the priority: ; Among them, P r represents the risk response priority; V represents the risk severity score; E represents the exposure level; λ represents the dynamic adjustment factor; T r represents the expected response time; ϵ represents the minimum value that avoids the denominator being zero.

5. The distributed network security automation intelligent compliance system according to claim 4 is characterized in that: The dynamic risk response module uses a multi-objective optimization algorithm to generate the optimal response path, and its objective function is as follows: ; Among them, T represents the time required for response; R represents the degree of risk reduction; C represents the response cost; α, β, and γ represent the target weight coefficients respectively.

6. The distributed network security automation intelligent compliance system according to claim 5 is characterized in that: The system supports multi-threaded task scheduling optimization, and its scheduling efficiency is evaluated by the following formula: ; Among them, E s Indicates the task scheduling efficiency; L i represents the total load of the i-th task; T i represents the completion time of the i-th task; n represents the total number of tasks.

7. The distributed network security automation intelligent compliance system according to claim 6 is characterized in that: The compliance rule base and update module optimize the rule base through an incremental learning mechanism, and the optimization increment calculation formula is: ; Among them, ΔR represents the optimization increment of the rule base; ω k represents the weight of rule k; , are the score values ​​of rule k before and after updating; q represents the number of updated rules.

8. The distributed network security automation intelligent compliance system according to claim 7 is characterized in that: The system optimizes overall compliance through a closed-loop feedback mechanism, and its feedback adjustment formula is as follows: ; Among them, F t 、F t-1 They represent the feedback adjustment values ​​at time t and t-1 respectively; η represents the feedback adjustment rate; Rt, R t−1 denote the compliance evaluation values ​​at time t and t−1 respectively.

Citation Information

Patent Citations

  • Information security risk assessment system based on block chain

    CN118965458A

  • Computer network security analysis system and method based on big data

    CN119094225A

  • Intelligent compliance risk assessment and monitoring system

    CN119182592A