Multi-level information security policy generation method based on knowledge graph

By introducing a multi-level information security strategy generation method based on knowledge graphs in network security protection, combining meta-learning, GAN and deep reinforcement learning algorithms, the shortcomings of traditional protection measures in the face of complex and unknown attacks are solved, and more efficient, intelligent and adaptive network security protection is achieved.

CN119728302BActive Publication Date: 2025-05-06HEFEI UNIV OF TECH

Patent Information

Application Number
CN202510221193.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-06
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

Traditional cybersecurity protection measures are difficult to effectively deal with complex, unknown and rapidly changing cyber attacks, especially in large-scale and high-frequency attack scenarios, resulting in unsatisfactory protection and increased security vulnerabilities.

Method used

A multi-level information security strategy generation method based on knowledge graph is adopted, combining meta-learning, generative adversarial network (GAN) and deep reinforcement learning algorithms to dynamically evaluate and optimize multi-level security protection strategies to achieve real-time adjustment and adaptive optimization.

Benefits of technology

It significantly improves the intelligence, adaptability and real-time response capabilities of the protection system, can quickly adapt to new attack modes, effectively respond to unknown threats, and improves the real-time and comprehensive capabilities of protection strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728302B_ABST
    Figure CN119728302B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-level information security strategy generation method based on a knowledge graph, comprising the following steps: S1, collecting multimodal data from multiple security data sources to generate a standardized data set; S2, constructing and dynamically updating a multi-level knowledge graph based on the standardized data set; S3, using a graph neural network to identify security threats and generate an assessment report based on the multi-level knowledge graph; S4, analyzing the spatiotemporal characteristics of security events and predicting the evolution trend of threats; S5, optimizing protection strategies based on a graph attention network and adjusting them in combination with a real-time feedback mechanism; S6, using a generative adversarial network to simulate attack scenarios and optimize the security protection strategy generation process; S7, based on the optimized protection strategy, using a meta-learning algorithm to further adjust and optimize. The present invention provides an intelligent, dynamically adjusted network security protection strategy generation and optimization solution by combining meta-learning, graph neural networks and generative adversarial networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a multi-level information security strategy generation method based on a knowledge graph. Background Art

[0002] With the rapid development of information technology, network security has become an important guarantee for various information systems and network services. Traditional network protection strategies mainly rely on static firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and virus scanning software to identify and defend against known network attacks. However, with the increasing complexity and concealment of network attacks, as well as the continuous changes in the network environment, traditional security protection measures have gradually exposed many shortcomings. These traditional protection measures are often difficult to effectively respond to new, complex, and unknown attacks, especially in the face of large-scale, high-frequency attack scenarios. The protection effect is often difficult to achieve expectations, resulting in a large number of security vulnerabilities and potential network security threats.

[0003] Existing network security protection technologies are usually based on matching rules and features, and use pre-set rule sets to determine whether there is malicious activity. However, this static defense method lacks effective response capabilities to unknown attack methods. Attackers are often able to bypass the detection of these static rules by constantly changing attack methods, encrypting communications, and other means. Therefore, the existing detection methods based on feature matching have poor detection capabilities for unknown attacks, resulting in the lag of protection measures and insufficient response capabilities.

[0004] In addition, traditional network protection strategies usually operate independently and lack a multi-level and multi-dimensional protection coordination mechanism. In a complex network environment, security protection measures are usually deployed in a distributed manner, making it difficult to effectively share information and coordinate strategies between layers. Attackers may further expand the scope of attack by breaking through loopholes in a certain level of protection system, resulting in a significant decrease in the overall security of the system. Existing protection measures are often isolated and fail to achieve dynamic adjustment and coordinated optimization of protection systems at all levels.

[0005] As cyber threats become more diverse and complex, advanced technologies such as artificial intelligence and machine learning are gradually being applied to the field of cybersecurity. These technologies can identify and classify complex security incidents by mining potential security threats and attack patterns from massive amounts of data. However, existing artificial intelligence methods usually rely on a large amount of training data, and the model training process requires a lot of time and computing resources. Especially in the face of changing network environments and security threats, existing training models are difficult to adapt quickly and update in real time, which affects the real-time and effectiveness of protection strategies.

[0006] In addition, although methods such as deep learning and reinforcement learning have achieved remarkable results in image recognition, natural language processing and other fields, their application in network security still faces some technical challenges. For example, deep learning models require a large amount of labeled data for training, and the model's interpretability is poor, which makes its judgment of abnormal behavior and policy adjustment process in network security relatively opaque. In addition, the application of reinforcement learning in network security usually relies on a large number of experimental processes and simulations, which is time-consuming and consumes a lot of computing resources. Therefore, how to use these technologies to effectively improve the intelligence and adaptability of protection strategies, while ensuring that the model can respond quickly in a changing network environment, has become an urgent problem to be solved.

[0007] In order to solve the above problems, in recent years, research based on advanced algorithms such as meta-learning, generative adversarial networks (GANs), and deep reinforcement learning has gradually emerged. Meta-learning is a technology that allows the system to quickly adapt to new tasks through a small amount of sample data, and has great application potential. However, the current network security protection strategy based on meta-learning is still in the exploratory stage. How to combine the meta-learning algorithm with the evaluation and optimization of the protection strategy and ensure its practical application in large-scale and dynamic environments is still a challenging problem.

[0008] In addition, Generative Adversarial Network (GAN), as a deep learning technology that uses adversarial training between generators and discriminators, can simulate different types of attack scenarios and provide effective data support for the evaluation of protection strategies. However, existing GAN models are mostly used in areas such as image generation and data enhancement. When used in network security, there are still problems such as the diversity of generated samples, training difficulty, and model stability.

[0009] Therefore, how to provide a multi-level information security policy generation method based on knowledge graph is an urgent problem that technicians in this field need to solve. Summary of the invention

[0010] One purpose of the present invention is to propose a multi-level information security strategy generation method based on knowledge graph. By fully combining meta-learning, generative adversarial network (GAN) and deep reinforcement learning algorithm, the present invention describes in detail how to use these technologies to dynamically evaluate and optimize multi-level security protection strategies and improve the intelligence level of network security protection systems. The method can quickly adapt to new attack modes and automatically adjust protection strategies through real-time feedback mechanisms to effectively respond to security threats in the network environment.

[0011] The innovation of this invention is that by introducing a meta-learning algorithm, the protection system can quickly adapt to new security threats with limited samples; by using a generative adversarial network to simulate multiple attack scenarios, it provides more diverse data support for the evaluation of protection strategies; at the same time, combined with a deep reinforcement learning algorithm and an adaptive optimization mechanism, it can perform real-time optimization and adjustment in a constantly changing network environment. Through the combination of these technologies, the present invention realizes intelligent strategy generation and optimization, and improves the adaptability and real-time performance of the protection strategy.

[0012] The present invention has the following advantages: first, it has the ability to quickly adapt to new attacks and can dynamically adjust the protection strategy according to real-time feedback; second, through the multi-level knowledge graph and security strategy collaboration mechanism, the comprehensive capability of the protection system is improved; finally, the combination of generative adversarial networks and deep reinforcement learning is adopted, so that the protection strategy can be continuously optimized to ensure the security and stability of the network system.

[0013] A multi-level information security policy generation method based on a knowledge graph according to an embodiment of the present invention includes the following steps:

[0014] S1. Collect multimodal data from multiple secure data sources, preprocess the multimodal data, and generate a standardized data set;

[0015] S2. Based on the standardized data set, build a multi-level knowledge graph and dynamically update the multi-level knowledge graph;

[0016] S3. Based on the constructed multi-level knowledge graph, a multi-scale graph neural network is used to identify potential security threats, and the severity of the threat is evaluated according to the threat characteristics to generate a security threat assessment report;

[0017] S4. Based on the security threat assessment report, analyze the temporal and spatial characteristics of security events, generate a temporal and spatial characteristic matrix, and predict the evolution trend of threats;

[0018] S5. Based on the predicted threat evolution trend, combined with the multi-level knowledge graph and the assessed security threat characteristics, the graph attention network algorithm is introduced to generate and optimize the security protection strategy, and the real-time feedback mechanism is combined to dynamically adjust the strategy;

[0019] S6. Use generative adversarial networks to simulate different attack scenarios, evaluate the effectiveness of security protection strategies, and optimize the security protection strategy generation process;

[0020] S7. Based on the optimized security protection strategy, further adjustment and optimization are performed using a meta-learning algorithm.

[0021] Optionally, the multi-level knowledge graph includes a feature layer, a relationship layer and a policy layer, the feature layer is used to extract key security features, the relationship layer is used to describe the relationships and dependencies between different data, and the policy layer is used to generate protection strategies based on security threats and risk assessments.

[0022] Optionally, the S3 specifically includes:

[0023] S31. Based on the constructed multi-level knowledge graph, extract entity nodes and their relationships related to security threats, including the connections between devices, users, applications, and network nodes, and perform attribute analysis on nodes and edges to generate input data sets for security threat identification;

[0024] S32. Use a multi-scale graph neural network to analyze the multi-level knowledge graph, use the multi-scale information of the graph to embed nodes, and calculate the implicit representation vector of each node:

[0025] ;

[0026] in, Indicates the The node representation of the layer, Indicates the The node representation of the layer, For the figure The scaled normalized adjacency matrix, For the The weight matrix of the scale, For the The weighting coefficient of the scale, is the regulating factor, represents the element-wise product, is the activation function, is the scale number;

[0027] S33. Based on the obtained node representation vector, the correlation between each node and the potential security threat is calculated, and the severity of the threat is evaluated by calculating the weighted sum between the nodes using the security threat scoring model:

[0028] ;

[0029] in, For the The representation vector of each node, and is the weighting coefficient, and is the learned weight matrix, A threat score for each node, is the total number of nodes;

[0030] S34. Based on the calculated security threat score, a threshold judgment method is applied to classify the threat. If the threat score exceeds a preset threshold, the node is identified as a high-risk threat, and a security threat assessment report is generated, which includes threat type, impact scope, and priority information.

[0031] S35. Combined with the spatiotemporal feature extraction algorithm, the changing characteristics of nodes in time and space are analyzed to further optimize the security threat assessment results and generate a dynamic security threat assessment model:

[0032] ;

[0033] in, is the normalized adjacency matrix, is the graph attention network, is the spatial feature embedding, is a recurrent neural network, is the temporal feature embedding, is the regulating factor, is the node representation vector.

[0034] Optionally, the S4 specifically includes:

[0035] S41. Based on the generated security threat assessment report, extract the time characteristics and spatial characteristics of the security threat and generate a time-space characteristic matrix, wherein the time characteristics include the occurrence time, duration and frequency of the threat event, and the spatial characteristics include the path and range of the threat source propagation in the network;

[0036] S42, using a spatiotemporal graph convolutional autoencoder to process the spatiotemporal feature matrix, and perform deep embedding and compression of the spatiotemporal features. The mathematical expression of the spatiotemporal graph convolutional autoencoder is:

[0037] ;

[0038] in, For the The spatiotemporal representation of layer nodes, For the The spatiotemporal representation of layer nodes, For the The adjacency matrix of the scale, For the The weighting coefficient of the scale, For the The weight matrix of the scale, is the regulating factor, is the activation function, is the autoencoder part, is the encoder weight parameter, is the number of multi-scales;

[0039] S43. Based on the calculated spatiotemporal representation vector, a graph convolution adaptive long short-term memory network is used to capture the dependencies in the spatiotemporal sequence and generate spatiotemporal feature prediction results:

[0040] ;

[0041] in, is the hidden state at the current moment, For the moment The hidden state of is the total number of nodes, For Node The space-time representation vector of is the spatiotemporal characteristics of the current moment, is the adaptive attention coefficient between nodes, It is the graph convolution adaptive attention mechanism, is the weight matrix, is bias;

[0042] S44, based on the spatiotemporal feature prediction results, adjust the policy priority, and generate the time series prediction results of future threat events by comprehensively analyzing the historical data and the current threat prediction results;

[0043] S45. Use a multi-scale spatiotemporal optimization model based on spatiotemporal optimization reinforcement learning algorithm to further optimize the threat prediction results:

[0044] ;

[0045] in, For the The optimization parameters at the moment, is the learning rate, is the spatiotemporal loss function with respect to the parameters The gradient of For the moment training data, is the discount factor, is the space-time reward difference, For the The optimization parameters at the moment, is the spatiotemporal loss function.

[0046] Optionally, the S5 specifically includes:

[0047] S51. Based on the predicted threat evolution trend, combined with the constructed multi-level knowledge graph and the assessed security threat characteristics, generate a multi-level security protection strategy, including security protection measures at different levels of the network layer, device layer, and application layer, and perform preliminary configuration of the strategy;

[0048] S52. A multi-level protection strategy optimization algorithm based on a graph convolutional network is used to optimize the generated security protection strategy. The mathematical expression of the optimization algorithm is:

[0049] ;

[0050] in, For the The representation of layer protection strategy, For the The adjacency matrix of the scale, For the The weighting coefficient of the scale, For the The weight matrix of the scale, is the regulating factor, is the activation function, is the penalty term in the strategy optimization process, is the scale number, is the penalty coefficient;

[0051] S53. According to the optimized protection strategy, dynamic adjustment is performed based on the deep deterministic policy gradient algorithm:

[0052] ;

[0053] in, is the updated strategy parameter, are the parameters of the current strategy, is the learning rate, For the moment Rewards, is the discount factor, For the current state and of value, For the current state and of value, is the gradient operation, For the current strategy, For the expected operation;

[0054] S54. Combine the obtained optimization strategy and use the multi-objective optimization algorithm to schedule and coordinate each level in the security strategy:

[0055] ;

[0056] in, is the comprehensive loss function, For the The weight of the target, For the The loss function of the target, For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, Indicates the minimum operation. Indicates the number of all optimized objectives;

[0057] S55. Based on the generated optimized protection strategy, preliminary execution is performed and the effectiveness of the protection measures is monitored, and rapid feedback on the applicability of the strategy is provided through a real-time data collection and analysis system.

[0058] Optionally, the S6 specifically includes:

[0059] S61. Based on the generated security protection strategy and combined with real-time network security data, a generative adversarial network is used to simulate different attack scenarios to evaluate the performance of the current protection strategy under different attack modes:

[0060] ;

[0061] in, is the loss function for adversarial training, is a real data sample, is the generated noise sample, is the distribution of real data, To generate the data distribution, is the output of the discriminator, is the generated sample output by the generator, is a logarithmic function, For the expected operation, is the judgment result of the discriminator on the samples generated by the generator;

[0062] S62. Based on the evaluation results, analyze the weaknesses and loopholes of the current strategy, determine the security protection measures that need to be optimized, and generate security optimization suggestions:

[0063] ;

[0064] in, Optimize the score for the strategy, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, The number of targets;

[0065] S63. According to the optimized protection strategy, dynamic adjustment is performed using a dual-objective deep reinforcement learning algorithm:

[0066] ;

[0067] in, For dual target depth The loss function for learning, For the current state and actions of value, Status and actions of value, is the discount factor, For at the moment Rewards, For the expected operation, To take the minimum value operation;

[0068] S64. Refine and adjust the protection strategy through the model-based adaptive strategy network in reinforcement learning:

[0069] ;

[0070] in, is the loss function of the adaptive strategy network, For the The weight of a strategy, For the The loss of a strategy, is the adaptive parameter, For the The adaptive adjustment function of the strategy, For the The state of the strategy, is the target number;

[0071] S65. Based on the optimized protection strategy, combined with the real-time data of network environment and security threats, an adaptive risk assessment model is used to verify the effectiveness of the current protection strategy and dynamically adjust the parameters in the protection measures:

[0072] ;

[0073] in, is the output of the adaptive risk assessment model, is the coordination factor, For policy coordination constraints, is the risk assessment value, For the The loss function of the target is is the risk adjustment factor.

[0074] Optionally, the S7 specifically includes:

[0075] S71. According to the optimized protection strategy, the execution effect of the protection strategy is evaluated using a dynamic strategy evaluation model based on multi-dimensional spatiotemporal data:

[0076] ;

[0077] in, Evaluate the loss for the strategy, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, For the The spatiotemporal stability factor of each target, For the The spatiotemporal characteristics of the target, The number of targets;

[0078] S72. Based on the evaluation results, the adaptive optimization method based on the meta-learning algorithm is used to adjust each level of the protection strategy:

[0079] ;

[0080] in, Optimizing loss for meta-learning, For the The loss function of the target is For the The coordination factor of the target, For the The adaptive adjustment function of the target, For the The risk adjustment factor for each target is For the The risk assessment value of a target, To find the minimum operation;

[0081] S73. Based on the strategy optimized by meta-learning, the protection strategy is fine-tuned by combining historical data and real-time feedback mechanism:

[0082] ;

[0083] in, is the updated protection strategy parameter. is the current protection strategy parameter, is the learning rate, For the status Take action Instant feedback rewards, is the gradient operation of the protection strategy, is the feedback weighting coefficient, is the feedback adjustment factor;

[0084] S74. According to the fine-tuned protection strategy, the protection strategy is globally optimized using a dynamic game optimization algorithm:

[0085] ;

[0086] in, Optimize the loss function for the game, To regulate the factors of cooperation and competition in the game, For the expected operation, To find the maximum value, For the current state and actions of value;

[0087] S75. According to the globally optimized protection strategy, the final optimized security strategy is executed and long-term monitoring is performed. The protection security strategy can respond to new security threats and make adaptive adjustments.

[0088] The beneficial effects of the present invention are:

[0089] The present invention solves the limitations of traditional network security protection strategies in dealing with complex and security threats by introducing a combination of meta-learning algorithms, generative adversarial networks (GANs) and deep reinforcement learning. Through this innovative combination of technologies, the present invention significantly improves the intelligence, adaptability and real-time response capabilities of the protection system. In the face of rapidly evolving network attacks, traditional rule matching and static protection strategies are often unable to effectively identify and respond to unknown threats, while the present invention can quickly adapt to new attack patterns with limited sample data through meta-learning algorithms, thereby greatly improving the defense capabilities of the protection system.

[0090] In addition, the present invention uses a generative adversarial network to simulate a variety of attack scenarios and provides a variety of data support for the evaluation of protection strategies. This process enables the strategy to not only defend against known attacks, but also effectively respond to various potential and unknown forms of attack. The introduction of a generative adversarial network improves the training effect of the model, making it more robust and adaptable, and provides a more comprehensive and reliable evaluation method for network protection strategies.

[0091] By combining deep reinforcement learning algorithms and adaptive optimization mechanisms, the present invention further optimizes the adjustment process of the protection strategy. In actual operation, the protection strategy can be automatically adjusted according to real-time feedback, thereby ensuring that the strategy always maintains high efficiency and effectiveness in a dynamically changing network environment. This adaptive optimization mechanism enables the protection strategy to not only resist current attacks, but also respond promptly to possible future attacks, greatly improving the long-term stability of the network security system.

[0092] In summary, the present invention has greatly enhanced the intelligence, real-time and adaptive capabilities of network security protection strategies by combining advanced artificial intelligence technologies, especially meta-learning, generative adversarial networks and deep reinforcement learning. The protection system can maintain efficient response in the ever-changing threat environment, improve the comprehensive ability and adaptability of network security protection, ensure the long-term stable operation of the system, and provide strong protection for more complex security threats in the future. BRIEF DESCRIPTION OF THE DRAWINGS

[0093] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0094] Figure 1 This is a flow chart of the multi-level information security strategy generation method based on knowledge graph proposed by the present invention;

[0095] Figure 2 This is a schematic diagram of the adaptive optimization process based on the meta-learning algorithm for the multi-level information security policy generation method based on the knowledge graph proposed in the present invention. DETAILED DESCRIPTION

[0096] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.

[0097] refer to Figure 1 and Figure 2 , a multi-level information security policy generation method based on knowledge graph includes the following steps:

[0098] S1. Collect multimodal data from multiple secure data sources, preprocess the multimodal data, and generate a standardized data set;

[0099] S2. Based on the standardized data set, build a multi-level knowledge graph and dynamically update the multi-level knowledge graph;

[0100] S3. Based on the constructed multi-level knowledge graph, a multi-scale graph neural network is used to identify potential security threats, and the severity of the threat is evaluated according to the threat characteristics to generate a security threat assessment report;

[0101] S4. Based on the security threat assessment report, analyze the temporal and spatial characteristics of security events, generate a temporal and spatial characteristic matrix, and predict the evolution trend of threats;

[0102] S5. Based on the predicted threat evolution trend, combined with the multi-level knowledge graph and the assessed security threat characteristics, the graph attention network algorithm is introduced to generate and optimize the security protection strategy, and the real-time feedback mechanism is combined to dynamically adjust the strategy;

[0103] S6. Use generative adversarial networks to simulate different attack scenarios, evaluate the protection effect of security protection strategies, and optimize the security protection strategy generation process;

[0104] S7. Based on the optimized security protection strategy, further adjustment and optimization are performed using a meta-learning algorithm.

[0105] In this embodiment, the multi-level knowledge graph includes a feature layer, a relationship layer and a strategy layer. The feature layer is used to extract key security features, the relationship layer is used to describe the relationships and dependencies between different data, and the strategy layer is used to generate protection strategies based on security threats and risk assessments.

[0106] In this implementation, S3 specifically includes:

[0107] S31. Based on the constructed multi-level knowledge graph, extract entity nodes and their relationships related to security threats, including the connections between devices, users, applications, and network nodes, and perform attribute analysis on nodes and edges to generate input data sets for security threat identification;

[0108] S32. Use a multi-scale graph neural network to analyze the multi-level knowledge graph, use the multi-scale information of the graph to embed nodes, and calculate the implicit representation vector of each node:

[0109] ;

[0110] in, Indicates the The node representation of the layer, Indicates the The node representation of the layer, For the figure The scaled normalized adjacency matrix, For the The weight matrix of the scale, For the The weighting coefficient of the scale, is the regulating factor, represents the element-wise product, is the activation function, is the scale number;

[0111] S33. Based on the obtained node representation vector, the correlation between each node and the potential security threat is calculated, and the severity of the threat is evaluated by calculating the weighted sum between the nodes using the security threat scoring model:

[0112] ;

[0113] in, For the The representation vector of each node, and is the weighting coefficient, and is the learned weight matrix, A threat score for each node, is the total number of nodes;

[0114] S34. Based on the calculated security threat score, a threshold judgment method is applied to classify the threat. If the threat score exceeds a preset threshold, the node is identified as a high-risk threat, and a security threat assessment report is generated, which includes threat type, impact scope, and priority information.

[0115] S35. Combined with the spatiotemporal feature extraction algorithm, the changing characteristics of nodes in time and space are analyzed to further optimize the security threat assessment results and generate a dynamic security threat assessment model:

[0116] ;

[0117] in, is the normalized adjacency matrix, is the graph attention network, is the spatial feature embedding, is a recurrent neural network, is the temporal feature embedding, is the regulating factor, is the node representation vector.

[0118] In this implementation manner, the S4 specifically includes:

[0119] S41. Based on the generated security threat assessment report, extract the time characteristics and spatial characteristics of the security threat and generate a time-space characteristic matrix, wherein the time characteristics include the occurrence time, duration and frequency of the threat event, and the spatial characteristics include the path and range of the threat source propagation in the network;

[0120] S42, using a spatiotemporal graph convolutional autoencoder to process the spatiotemporal feature matrix, and perform deep embedding and compression of the spatiotemporal features. The mathematical expression of the spatiotemporal graph convolutional autoencoder is:

[0121] ;

[0122] in, For the The spatiotemporal representation of layer nodes, For the The spatiotemporal representation of layer nodes, For the The adjacency matrix of the scale, For the The weighting coefficient of the scale, For the The weight matrix of the scale, is the regulating factor, is the activation function, is the autoencoder part, is the encoder weight parameter, is the number of multi-scales;

[0123] S43. Based on the calculated spatiotemporal representation vector, a graph convolution adaptive long short-term memory network is used to capture the dependencies in the spatiotemporal sequence and generate spatiotemporal feature prediction results:

[0124] ;

[0125] in, is the hidden state at the current moment, For the moment The hidden state of is the total number of nodes, For Node The space-time representation vector of is the spatiotemporal characteristics of the current moment, is the adaptive attention coefficient between nodes, It is the graph convolution adaptive attention mechanism, is the weight matrix, is bias;

[0126] S44, based on the spatiotemporal feature prediction results, adjust the policy priority, and generate the time series prediction results of future threat events by comprehensively analyzing the historical data and the current threat prediction results;

[0127] S45. Use a multi-scale spatiotemporal optimization model based on spatiotemporal optimization reinforcement learning algorithm to further optimize the threat prediction results:

[0128] ;

[0129] in, For the The optimization parameters at the moment, is the learning rate, is the spatiotemporal loss function with respect to the parameter The gradient of For the moment training data, is the discount factor, is the space-time reward difference, For the The optimization parameters at the moment, is the spatiotemporal loss function.

[0130] In this implementation manner, S5 specifically includes:

[0131] S51. Based on the predicted threat evolution trend, combined with the constructed multi-level knowledge graph and the assessed security threat characteristics, generate a multi-level security protection strategy, including security protection measures at different levels of the network layer, device layer, and application layer, and perform preliminary configuration of the strategy;

[0132] S52. A multi-level protection strategy optimization algorithm based on a graph convolutional network is used to optimize the generated security protection strategy. The mathematical expression of the optimization algorithm is:

[0133] ;

[0134] in, For the The representation of layer protection strategy, For the The adjacency matrix of the scale, For the The weighting coefficient of the scale, For the The weight matrix of the scale, is the regulating factor, is the activation function, is the penalty term in the strategy optimization process, is the scale number, is the penalty coefficient;

[0135] S53. According to the optimized protection strategy, dynamic adjustment is performed based on the deep deterministic policy gradient algorithm:

[0136] ;

[0137] in, is the updated strategy parameter, are the parameters of the current strategy, is the learning rate, For the moment Rewards, is the discount factor, For the current state and of value, For the current state and of value, is the gradient operation, For the current strategy, For the expected operation;

[0138] S54. Combine the obtained optimization strategy and use the multi-objective optimization algorithm to schedule and coordinate each level in the security strategy:

[0139] ;

[0140] in, is the comprehensive loss function, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, Indicates the minimum operation. Indicates the number of all optimized objectives;

[0141] S55. Based on the generated optimized protection strategy, preliminary execution is performed and the effectiveness of the protection measures is monitored, and rapid feedback on the applicability of the strategy is provided through a real-time data collection and analysis system.

[0142] In this implementation manner, S6 specifically includes:

[0143] S61. Based on the generated security protection strategy and combined with real-time network security data, a generative adversarial network is used to simulate different attack scenarios to evaluate the performance of the current protection strategy under different attack modes:

[0144] ;

[0145] in, is the loss function for adversarial training, is a real data sample, is the generated noise sample, is the distribution of real data, To generate the data distribution, is the output of the discriminator, is the generated sample output by the generator, is a logarithmic function, For the expected operation, is the judgment result of the discriminator on the samples generated by the generator;

[0146] S62. Based on the evaluation results, analyze the weaknesses and loopholes of the current strategy, determine the security protection measures that need to be optimized, and generate security optimization suggestions:

[0147] ;

[0148] in, Optimize the score for the strategy, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, The number of targets;

[0149] S63. According to the optimized protection strategy, dynamic adjustment is performed using a dual-objective deep reinforcement learning algorithm:

[0150] ;

[0151] in, For dual target depth The loss function for learning, For the current state and actions of value, Status and actions of value, is the discount factor, For at the moment Rewards, For the expected operation, To take the minimum value operation;

[0152] S64. Refine and adjust the protection strategy through the model-based adaptive strategy network in reinforcement learning:

[0153] ;

[0154] in, is the loss function of the adaptive strategy network, For the The weight of a strategy, For the The loss of a strategy, is the adaptive parameter, For the The adaptive adjustment function of the strategy, For the The state of the strategy, is the target number;

[0155] S65. Based on the optimized protection strategy, combined with the real-time data of network environment and security threats, an adaptive risk assessment model is used to verify the effectiveness of the current protection strategy and dynamically adjust the parameters in the protection measures:

[0156] ;

[0157] in, is the output of the adaptive risk assessment model, is the coordination factor, For policy coordination constraints, is the risk assessment value, For the The loss function of the target is is the risk adjustment factor.

[0158] In this implementation manner, the S7 specifically includes:

[0159] S71. According to the optimized protection strategy, the execution effect of the protection strategy is evaluated using a dynamic strategy evaluation model based on multi-dimensional spatiotemporal data:

[0160] ;

[0161] in, Evaluate the loss for the strategy, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, For the The spatiotemporal stability factor of each target, For the The spatiotemporal characteristics of the target, The number of targets;

[0162] S72. Based on the evaluation results, the adaptive optimization method based on the meta-learning algorithm is used to adjust each level of the protection strategy:

[0163] ;

[0164] in, Optimizing loss for meta-learning, For the The loss function of the target is For the The coordination factor of the target, For the The adaptive adjustment function of the target, For the The risk adjustment factor for each target is For the The risk assessment value of a target, To find the minimum value operation;

[0165] S73. Based on the strategy optimized by meta-learning, the protection strategy is fine-tuned by combining historical data and real-time feedback mechanism:

[0166] ;

[0167] in, is the updated protection strategy parameter. is the current protection strategy parameter, is the learning rate, For the status Take action Instant feedback rewards, is the gradient operation of the protection strategy, is the feedback weighting coefficient, is the feedback adjustment factor;

[0168] S74. According to the fine-tuned protection strategy, the protection strategy is globally optimized using a dynamic game optimization algorithm:

[0169] ;

[0170] in, Optimize the loss function for the game, To regulate the factors of cooperation and competition in the game, For the expected operation, To find the maximum value, For the current state and actions of value;

[0171] S75. According to the globally optimized protection strategy, the final optimized security strategy is executed and long-term monitoring is performed. The protection security strategy can respond to new security threats and make adaptive adjustments.

[0172] Embodiment 1:

[0173] In order to verify the feasibility of the present invention in implementation, the present invention is applied to the network security protection system of a large financial enterprise. The enterprise operates multiple data centers worldwide, involving a large amount of user and financial transaction data. Therefore, its network security faces a variety of complex attack threats, including DDoS attacks, data leakage, malware, and phishing. In order to cope with the ever-changing attack methods, traditional protection measures have been difficult to meet the needs of efficient and intelligent network security. Based on this, the enterprise decided to adopt the multi-level information security policy generation method based on knowledge graph proposed in the present invention to improve the intelligence and adaptability of its network protection.

[0174] In the enterprise's network environment, we first collect multimodal data such as network traffic data, device status data, user behavior data, and historical security event logs, and then clean, standardize, and format the data to form a standardized data set. These data provide a reliable basis for subsequent security policy evaluation and generation.

[0175] Next, the core method of the present invention, the multi-level information security policy generation method based on the knowledge graph, is applied in this environment. First, by constructing a multi-level knowledge graph, combining the internal security protection needs of the enterprise with external security threat intelligence, security protection strategies at different levels are generated. The strategies at each level take into account different attack types and protection measures. For example, at the network layer, the knowledge graph takes into account the abnormal traffic monitoring and protection of the IP layer, while at the application layer, it takes into account the protection against attacks such as SQL injection and cross-site scripting. The knowledge graph integrates and optimizes these protection measures to form a global protection strategy.

[0176] Then, based on the generative adversarial network, the present invention simulated a number of different attack scenarios, including DDoS attacks, SQL injections, malware propagation, etc., and evaluated the performance of the current protection strategy under these attack modes. Through adversarial training, the protection strategy is further optimized to enhance its adaptability to unknown attacks. In addition, combined with the meta-learning algorithm, the present invention enables the protection strategy to quickly adjust and generate new protection strategies based on limited sample data in the face of new attack types. The introduction of this meta-learning effectively improves the intelligence and real-time response capabilities of the protection strategy.

[0177] During the implementation process, the protection strategy is also optimized by deep reinforcement learning algorithms. The reinforcement learning algorithm automatically adjusts the protection measures by real-time monitoring of network traffic and system status. For example, when the system detects abnormal traffic, the protection strategy will automatically update its protection rules to quickly respond to the attack and ensure that the network is not damaged. This process is achieved through the policy gradient algorithm. After multiple trainings, the protection strategy can respond in real time when facing new attack scenarios and continuously optimize its protection capabilities.

[0178] In actual applications, the network security protection system of the enterprise has shown significant improvements after the intelligent protection strategy optimization method of the present invention is enabled. For example, when facing a DDoS attack, the system can detect and intercept abnormal traffic within 2 seconds after the attack begins, significantly reducing the impact of the attack on the business. In contrast, the protection system before application usually takes more than 10 seconds to complete identification and response, and the protection effect is poor.

[0179] Table 1 Comparison data of network security protection effects

[0180]

[0181] By comparing the data in the table, it can be seen that after applying the protection strategy optimization method of the present invention, the network security protection capability of the enterprise has been significantly improved. First, the attack recognition rate has increased from 80% to 95%, an increase of 15%. This shows that the system's ability to identify attacks has been greatly enhanced and can better respond to various threats. Secondly, the false alarm rate has dropped from 12% to 3%, and the false alarm rate has dropped from 10% to 2%, an increase of 9% and 8% respectively, which shows the system's significant improvement in reducing false alarms and false alarms, and improving the accuracy of the protection strategy.

[0182] In terms of protection strategy response time, the optimized strategy response speed has been greatly improved, from 10 seconds before application to 2 seconds, an increase of 8 seconds, ensuring that attacks can be intercepted more quickly. In addition, system stability has also been improved from 90% to 99%, enhancing the reliability of the system in a dynamic environment.

[0183] Finally, the protection system optimization time was shortened from 120 minutes to 30 minutes, an increase of 90 minutes, indicating that the optimized protection system can respond to new security threats more quickly. In summary, the protection strategy optimization method of the present invention significantly improves the network security protection capability and enhances the real-time, stability and accuracy of the protection system.

[0184] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.

Claims

1. A multi-level information security policy generation method based on knowledge graph, characterized in that: The steps include: S1. Collect multimodal data from multiple secure data sources, preprocess the multimodal data, and generate a standardized data set; S2. Based on the standardized data set, build a multi-level knowledge graph and dynamically update the multi-level knowledge graph; S3. Based on the constructed multi-level knowledge graph, a multi-scale graph neural network is used to identify potential security threats, and the severity of the threat is evaluated according to the threat characteristics to generate a security threat assessment report; S4. Based on the security threat assessment report, analyze the temporal and spatial characteristics of security events, generate a temporal and spatial characteristic matrix, and predict the evolution trend of threats; S5. Based on the predicted threat evolution trend, combined with the multi-level knowledge graph and the assessed security threat characteristics, the graph attention network algorithm is introduced to generate and optimize the security protection strategy, and the real-time feedback mechanism is combined to dynamically adjust the strategy; S6. Use generative adversarial networks to simulate different attack scenarios, evaluate the effectiveness of security protection strategies, and optimize the security protection strategy generation process; S7. Based on the optimized security protection strategy, further adjustment and optimization are performed using a meta-learning algorithm; The S5 specifically includes: S51. Based on the predicted threat evolution trend, combined with the constructed multi-level knowledge graph and the assessed security threat characteristics, generate a multi-level security protection strategy, including security protection measures at different levels of the network layer, device layer, and application layer, and perform preliminary configuration of the strategy; S52. A multi-level protection strategy optimization algorithm based on a graph convolutional network is used to optimize the generated security protection strategy. The mathematical expression of the optimization algorithm is: ; in, For the The representation of layer protection strategy, For the The adjacency matrix of the scale, For the The weighting coefficient of the scale, For the The weight matrix of the scale, is the regulating factor, is the activation function, is the penalty term in the strategy optimization process, is the scale number, is the penalty coefficient; S53. According to the optimized protection strategy, dynamic adjustment is performed based on the deep deterministic policy gradient algorithm: ; in, is the updated strategy parameter, are the parameters of the current strategy, is the learning rate, For the moment Rewards, is the discount factor, For the current state and of value, For the current state and of value, is the gradient operation, For the current strategy, For the expected operation; S54. Combine the obtained optimization strategy and use the multi-objective optimization algorithm to schedule and coordinate each level in the security strategy: ; in, is the comprehensive loss function, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, Indicates the minimum operation. Indicates the number of all optimized objectives; S55. Based on the generated optimized protection strategy, preliminary execution is performed and the effectiveness of the protection measures is monitored, and rapid feedback on the applicability of the strategy is provided through a real-time data collection and analysis system.

2. The method for generating a multi-level information security strategy based on a knowledge graph according to claim 1 is characterized in that: The multi-level knowledge graph includes a feature layer, a relationship layer and a strategy layer. The feature layer is used to extract key security features, the relationship layer is used to describe the relationships and dependencies between different data, and the strategy layer is used to generate protection strategies based on security threats and risk assessments.

3. The method for generating a multi-level information security strategy based on a knowledge graph according to claim 1 is characterized in that: The S3 specifically includes: S31. Based on the constructed multi-level knowledge graph, extract entity nodes and their relationships related to security threats, including the connections between devices, users, applications, and network nodes, and perform attribute analysis on nodes and edges to generate input data sets for security threat identification; S32. Use a multi-scale graph neural network to analyze the multi-level knowledge graph, use the multi-scale information of the graph to embed nodes, and calculate the implicit representation vector of each node: ; in, Indicates the The node representation of the layer, Indicates the The node representation of the layer, For the figure The scaled normalized adjacency matrix, For the The weight matrix of the scale, For the The weighting coefficient of the scale, is the regulating factor, represents the element-wise product, is the activation function, is the scale number; S33. Based on the obtained node representation vector, the correlation between each node and the potential security threat is calculated, and the severity of the threat is evaluated by calculating the weighted sum between the nodes using the security threat scoring model: ; in, For the The representation vector of each node, and is the weighting coefficient, and is the learned weight matrix, A threat score for each node, is the total number of nodes; S34. Based on the calculated security threat score, a threshold judgment method is applied to classify the threat. If the threat score exceeds a preset threshold, the node is identified as a high-risk threat, and a security threat assessment report is generated, which includes threat type, impact scope, and priority information. S35. Combined with the spatiotemporal feature extraction algorithm, the changing characteristics of nodes in time and space are analyzed to further optimize the security threat assessment results and generate a dynamic security threat assessment model: ; in, is the normalized adjacency matrix, is the graph attention network, is the spatial feature embedding, is a recurrent neural network, is the temporal feature embedding, is the regulating factor, is the node representation vector.

4. The method for generating a multi-level information security strategy based on a knowledge graph according to claim 1 is characterized in that: The S4 specifically includes: S41. Based on the generated security threat assessment report, extract the time characteristics and spatial characteristics of the security threat and generate a time-space characteristic matrix, wherein the time characteristics include the occurrence time, duration and frequency of the threat event, and the spatial characteristics include the path and range of the threat source propagation in the network; S42, using a spatiotemporal graph convolutional autoencoder to process the spatiotemporal feature matrix, and perform deep embedding and compression of the spatiotemporal features. The mathematical expression of the spatiotemporal graph convolutional autoencoder is: ; in, For the The spatiotemporal representation of layer nodes, For the The spatiotemporal representation of layer nodes, For the The adjacency matrix of the scale, For the The weighting coefficient of the scale, For the The weight matrix of the scale, is the regulating factor, is the activation function, is the autoencoder part, is the encoder weight parameter, is the number of multi-scales; S43. Based on the calculated spatiotemporal representation vector, a graph convolution adaptive long short-term memory network is used to capture the dependencies in the spatiotemporal sequence and generate spatiotemporal feature prediction results: ; in, is the hidden state at the current moment, For the moment The hidden state of is the total number of nodes, For Node The space-time representation vector of is the spatiotemporal characteristics of the current moment, is the adaptive attention coefficient between nodes, It is the graph convolution adaptive attention mechanism, is the weight matrix, is bias; S44, based on the spatiotemporal feature prediction results, adjust the policy priority, and generate the time series prediction results of future threat events by comprehensively analyzing the historical data and the current threat prediction results; S45. Use a multi-scale spatiotemporal optimization model based on spatiotemporal optimization reinforcement learning algorithm to further optimize the threat prediction results: ; in, For the The optimization parameters at the moment, is the learning rate, is the spatiotemporal loss function with respect to the parameter The gradient of For the moment training data, is the discount factor, is the space-time reward difference, For the The optimization parameters at the moment, is the spatiotemporal loss function.

5. The method for generating a multi-level information security strategy based on a knowledge graph according to claim 1 is characterized in that: The S6 specifically includes: S61. Based on the generated security protection strategy and combined with real-time network security data, a generative adversarial network is used to simulate different attack scenarios to evaluate the performance of the current protection strategy under different attack modes: ; in, is the loss function for adversarial training, is a real data sample, is the generated noise sample, is the distribution of real data, To generate the data distribution, is the output of the discriminator, is the generated sample output by the generator, is a logarithmic function, For the expected operation, is the judgment result of the discriminator on the samples generated by the generator; S62. Based on the evaluation results, analyze the weaknesses and loopholes of the current strategy, determine the security protection measures that need to be optimized, and generate security optimization suggestions: ; in, Optimize the score for the strategy, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, The number of targets; S63. According to the optimized protection strategy, dynamic adjustment is performed using a dual-objective deep reinforcement learning algorithm: ; in, For dual target depth The loss function for learning, For the current state and actions of value, Status and actions of value, is the discount factor, For at the moment Rewards, For the expected operation, To take the minimum value operation; S64. Refine and adjust the protection strategy through the model-based adaptive strategy network in reinforcement learning: ; in, is the loss function of the adaptive strategy network, For the The weight of a strategy, For the The loss of a strategy, is the adaptive parameter, For the The adaptive adjustment function of the strategy, For the The state of the strategy, is the target number; S65. Based on the optimized protection strategy, combined with the real-time data of network environment and security threats, an adaptive risk assessment model is used to verify the effectiveness of the current protection strategy and dynamically adjust the parameters in the protection measures: ; in, is the output of the adaptive risk assessment model, is the coordination factor, For policy coordination constraints, is the risk assessment value, For the The loss function of the target is is the risk adjustment factor.

6. The method for generating a multi-level information security strategy based on a knowledge graph according to claim 1 is characterized in that: The S7 specifically includes: S71. According to the optimized protection strategy, the execution effect of the protection strategy is evaluated using a dynamic strategy evaluation model based on multi-dimensional spatiotemporal data: ; in, Evaluate the loss for the strategy, For the The weight of the target, For the The loss function of the target is For the The coordination factor of the target, For the The strategic coordination constraints of the objectives, For the The spatiotemporal stability factor of each target, For the The spatiotemporal characteristics of the target, The number of targets; S72. Based on the evaluation results, the adaptive optimization method based on the meta-learning algorithm is used to adjust each level of the protection strategy: ; in, Optimizing loss for meta-learning, For the The loss function of the target is For the The coordination factor of the target, For the The adaptive adjustment function of the target, For the The risk adjustment factor for each target is For the The risk assessment value of a target, To find the minimum value operation; S73. Based on the strategy optimized by meta-learning, the protection strategy is fine-tuned by combining historical data and real-time feedback mechanism: ; in, is the updated protection strategy parameter. is the current protection strategy parameter, is the learning rate, For the status Take action Instant feedback rewards, is the gradient operation of the protection strategy, is the feedback weighting coefficient, is the feedback adjustment factor; S74. According to the fine-tuned protection strategy, the protection strategy is globally optimized using a dynamic game optimization algorithm: ; in, Optimize the loss function for the game, To regulate the factors of cooperation and competition in the game, For the expected operation, To find the maximum value, For the current state and actions of value; S75. According to the globally optimized protection strategy, the final optimized security strategy is executed and long-term monitoring is performed. The protection security strategy can respond to new security threats and make adaptive adjustments.

Citation Information

Patent Citations

  • Defense method for adversarial learning in combination with transfer learning

    CN118710950A

  • Network attack and defense decision support method and system based on artificial intelligence

    CN119155099A

Cited By

  • Enterprise information security defense strategy generation method based on adaptive rule engine

    CN120979728A