A dynamic network security defense method and system based on big data

By constructing multidimensional feature vectors and adaptive response functions, and dynamically adjusting defense strategies, the problem of defending against unknown attacks and advanced threats in existing technologies has been solved, realizing intelligent and dynamic protection of network security systems.

CN119835017BActive Publication Date: 2025-12-02SHENZHEN QIYU TECH IND CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411848457.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-12-02
Estimated Expiration
2044-12-16

AI Technical Summary

Technical Problem

Existing cybersecurity protection methods are insufficient to deal with unknown attacks or advanced persistent threats, and their reliance on manually maintained signature databases leads to slow response times and difficulty in quickly adapting to new attack scenarios.

Method used

The big data-based dynamic network security defense method constructs multi-dimensional feature vectors, calculates dynamic threat assessment indices, generates adaptive response functions, dynamically adjusts defense strength, and optimizes it through multi-level linkage defense mechanisms.

Benefits of technology

It has improved the ability to detect and defend against unknown attacks and advanced threats, optimized resource management, enabled continuous self-optimization and responsiveness of the system, and enhanced defense efficiency and flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835017B_ABST
    Figure CN119835017B_ABST
Patent Text Reader

Abstract

This invention relates to a dynamic network security defense method and system based on big data, belonging to the field of big data technology. The method includes: constructing a multi-dimensional feature vector based on real-time collected network traffic data, system logs, and user behavior data; calculating a dynamic threat assessment index based on the multi-dimensional feature vector; generating an adaptive response function based on the dynamic threat assessment index; determining a dynamic adjustment function for defense strength based on the adaptive response function, and executing multi-level coordinated defense based on the dynamic adjustment function; evaluating the defense effectiveness of the multi-level coordinated defense through a defense effectiveness evaluation model to obtain corresponding evaluation results; and continuously optimizing the executed multi-level coordinated defense based on the evaluation results. This invention can improve the dynamism and effectiveness of network defense.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of big data technology, and in particular to a dynamic network security defense method, system, electronic device, and non-transitory computer-readable storage medium based on big data. Background Technology

[0002] With the increasing complexity and evolution of cyberattacks, the importance of cybersecurity protection is becoming increasingly prominent. Currently, mainstream cybersecurity protection methods mainly include static defense and rule-based intrusion detection systems (IDS). These methods identify potential security threats by monitoring and analyzing network traffic, combined with predefined rules and threat signature databases. In addition, some defense systems utilize firewalls, sandbox technology, and Security Information and Event Management (SIEM) platforms for comprehensive security protection to improve the detection capability of known threats.

[0003] However, static defense methods are insufficient to cope with unknown attacks or advanced persistent threats (APTs), which often exploit zero-day vulnerabilities or complex multi-stage attack strategies to bypass rule detection. Secondly, rule-based methods rely heavily on timely updates to signature databases, often resulting in a slow response to rapidly changing threat landscapes. Furthermore, the extensive manual intervention required for signature database construction hinders their ability to quickly adapt to new attack scenarios, thus limiting their defensive capabilities. In practical applications, existing systems often fail to provide effective protection against high-frequency and diverse attack behaviors due to a lack of dynamic adjustment capabilities. Summary of the Invention

[0004] This invention addresses the technical problems existing in the prior art by providing a big data-based dynamic network security defense method, system, electronic device, and non-transitory computer-readable storage medium that can improve the dynamism and effectiveness of network defense.

[0005] The technical solution of the present invention to solve the above-mentioned technical problems is as follows:

[0006] This invention provides a dynamic network security defense method based on big data, the method comprising:

[0007] A multidimensional feature vector is constructed based on real-time collected network traffic data, system logs, and user behavior data.

[0008] Based on the multidimensional feature vector, the dynamic threat assessment index is calculated;

[0009] Generate an adaptive response function based on the dynamic threat assessment index;

[0010] The dynamic adjustment function for defense strength is determined based on the adaptive response function, and multi-level coordinated defense is executed based on the dynamic adjustment function for defense strength.

[0011] The defense effectiveness of the multi-level linked defense is evaluated using a defense effectiveness evaluation model, and the corresponding evaluation results are obtained.

[0012] Based on the evaluation results, the implemented multi-level coordinated defense will be continuously optimized.

[0013] Optionally, calculating the dynamic threat assessment index based on the multidimensional feature vector includes:

[0014] From the multidimensional feature vector, obtain the weight and risk level of each feature;

[0015] Obtain multiple attack similarity metrics;

[0016] Obtain the relevant time decay factor and observation period for evaluation;

[0017] The dynamic threat assessment index is calculated by processing the weight and risk of each feature, each attack similarity index, the time decay factor, and the observation period based on the first adjustment coefficient, the second adjustment coefficient, the third adjustment coefficient, and the fourth adjustment coefficient.

[0018] Optionally, the dynamic threat assessment index is expressed as:

[0019]

[0020] Wherein, DTI is the Dynamic Threat Assessment Index, ω i V is the weight of the i-th feature. i S is the risk level of the i-th feature. j is the j-th attack similarity index, t is the time decay factor, T is the observation period, and α, β, γ, and λ are the first, second, third, and fourth adjustment coefficients, respectively.

[0021] Optionally, generating an adaptive response function based on the dynamic threat assessment index includes:

[0022] Obtain the dynamic threat assessment index and priority for each type of threat in the network;

[0023] Obtain the historical response results for each successful response to each of the aforementioned threats;

[0024] Obtain the nonlinear adjustment exponent, learning rate, and system resource constraint factor used to generate the adaptive response function;

[0025] The adaptive response function is generated based on the dynamic threat assessment index and priority of each type of threat, the historical response effect of each successful response to each type of threat, the nonlinear adjustment index, the learning rate, and the system resource constraint factor.

[0026] Optionally, the adaptive response function is expressed as:

[0027]

[0028] Where ARF is the adaptive response function, and DTI is the adaptive response function. k P is the dynamic threat assessment index for the k-th type of threat. k This is the priority of the threat, R i denoted as the historical response effect of the i-th time, m is the nonlinear adjustment exponent, η is the learning rate, and Ω is the system resource constraint factor.

[0029] Optionally, determining the dynamic adjustment function of defense strength based on the adaptive response function includes:

[0030] Obtain the time window function used to characterize the time dependence of defense strength;

[0031] Obtain a set of defense measures that include multiple defensive measures;

[0032] Each defensive measure is processed according to the cost coefficient, the adaptive function is processed according to the sensitivity parameter, and combined with the time window function to obtain the dynamic adjustment function of the defense strength.

[0033] Optionally, the defense effectiveness of the multi-level linked defense is evaluated using a defense effectiveness evaluation model to obtain corresponding evaluation results, including:

[0034] The number of events experienced within the period for obtaining the defense effectiveness assessment;

[0035] Obtain a balancing factor to control the weight between defensive effectiveness and losses, as well as an effectiveness decay coefficient that is important for long-term defensive effectiveness;

[0036] Obtain the loss caused by the current event, and the maximum acceptable loss;

[0037] The evaluation result is determined based on the number of events, the efficiency decay coefficient of the balance factor, the loss caused by the current event, and the maximum acceptable loss.

[0038] Optionally, the step of continuously optimizing the implemented multi-level coordinated defense based on the evaluation results includes:

[0039] The calculation parameters in the dynamic threat assessment index, the adaptive response function, the defense strength dynamic adjustment function, and the defense effectiveness assessment model are adaptively adjusted to obtain optimized dynamic threat assessment index, adaptive response function, defense strength dynamic adjustment function, and defense effectiveness assessment model;

[0040] The weights of each feature are optimized using machine learning algorithms to obtain the optimized features;

[0041] The defense strategy threshold is dynamically updated based on the optimized dynamic threat assessment index, adaptive response function, defense strength dynamic adjustment function, and defense effectiveness assessment model, as well as the optimized features.

[0042] Optionally, the method further includes:

[0043] The threat knowledge base is updated based on the assessment results to obtain the updated threat knowledge base;

[0044] The updated defense strategy base is updated based on the updated threat knowledge base to obtain the updated defense strategy base.

[0045] Based on the updated threat knowledge base and the updated defense strategy base, the system response mechanism and resource scheduling strategy are optimized.

[0046] This invention also provides a big data-based dynamic network security defense system, the system comprising:

[0047] The data acquisition module is used to construct multi-dimensional feature vectors based on real-time collected network traffic data, system logs, and user behavior data.

[0048] The threat assessment module is used to calculate a dynamic threat assessment index based on the multidimensional feature vector.

[0049] The threat response module is used to generate an adaptive response function based on the dynamic threat assessment index;

[0050] The network defense module is used to determine the dynamic adjustment function of defense strength based on the adaptive response function, and to execute multi-level linkage defense based on the dynamic adjustment function of defense strength;

[0051] The defense assessment module is used to evaluate the defense effectiveness of the multi-level linked defense through the defense effectiveness assessment model and obtain the corresponding assessment results.

[0052] The defense optimization module is used to continuously optimize the executed multi-level linkage defense based on the evaluation results.

[0053] In addition, to achieve the above object, the present invention further provides an electronic device, comprising: a memory for storing a computer software program; a processor for reading and executing the computer software program, thereby implementing a network security dynamic defense method based on big data as described above.

[0054] In addition, to achieve the above object, the present invention further provides a non-transitory computer-readable storage medium, in which a computer software program is stored, and when the computer software program is executed by a processor, a network security dynamic defense method based on big data as described above is implemented.

[0055] The beneficial effects of the present invention are as follows:

[0056] (1) Based on the dynamic threat assessment index (DTI), the present invention can comprehensively consider the multi-dimensional characteristics, time decay and similarity of attacks, so that when facing unknown or new attacks, it can dynamically adjust the defense strategy, timely identify and respond to complex attacks such as advanced persistent threats (APT), enhance the system's ability to identify variant attacks, complex attacks and advanced persistent threats, and significantly improve the security of the system.

[0057] (2) The present invention generates a defense strategy through the adaptive response function (ARF), which can be dynamically adjusted according to the threat assessment result and the historical response effect. By weighing the threat priority, resource constraints and historical response effect, the system can generate the best defense strategy instead of relying on a fixed rule base, thereby reducing human intervention. The defense strategy can be adjusted in real time according to the change of the attack situation, improving the defense efficiency and response speed.

[0058] (3) The defense intensity dynamic adjustment function (DDAF) designed by the present invention takes into account factors such as time window, measure cost and defense sensitivity, and realizes multi-level linkage defense. This mechanism continuously optimizes the intensity and countermeasures of each level of defense to ensure that the defense system can provide timely and accurate protection when facing various attack methods. It can improve the flexibility and anti-strike ability of the defense system, while optimizing the use of defense resources and avoiding unnecessary resource waste.

[0059] In summary, through dynamic threat assessment, multi-dimensional data analysis, adaptive defense strategy generation and multi-level linkage defense mechanism, the present invention provides a flexible, efficient and intelligent network security protection method. Its beneficial effects are mainly reflected in: improving the detection and defense capabilities against unknown attacks and advanced threats; optimizing resource management to ensure defense efficiency; achieving continuous self-optimization and应变能力 of the system. Making network security protection more intelligent and dynamic, and being able to maintain high-efficiency protection capabilities when dealing with complex and continuously evolving network threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 A flowchart illustrating a dynamic network security defense method based on big data provided by this invention;

[0061] Figure 2 A schematic diagram of the structure of a big data-based dynamic network security defense system provided by the present invention;

[0062] Figure 3 A schematic diagram of a possible hardware structure of an electronic device provided by the present invention;

[0063] Figure 4 This is a schematic diagram of the hardware structure of a possible computer-readable storage medium provided by the present invention. Detailed Implementation

[0064] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0065] In the description of this invention, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the stated features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0066] In the description of this invention, the term "for example" is used to mean "used as an example, illustration, or description." Any embodiment described as "for example" in this invention is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use the invention. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that the invention can be made without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid obscuring the description of the invention with unnecessary detail. Therefore, the invention is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed herein.

[0067] Please see Figure 1 The present invention provides a flowchart of a dynamic network security defense method based on big data, comprising the following steps:

[0068] Step 201: Construct a multi-dimensional feature vector based on real-time collected network traffic data, system logs, and user behavior data.

[0069] First, the system can collect data from three main sources in real time:

[0070] Network traffic data includes information about all data packets generated during network communication, such as source IP, destination IP, protocol type, port number, transport layer protocol, packet size, and traffic direction. This data helps the system understand the characteristics of network traffic and identify potentially abnormal traffic.

[0071] System logs are log files generated by the operating system, applications, security systems, etc., and include information such as system events (e.g., startup, shutdown, abnormal situations), file access, user logins, and service status. System logs provide important clues for analyzing internal system behavior and potential security risks.

[0072] User behavior data includes user activity logs within the system, such as login time, accessed resources, entered commands, and performed actions. This data reflects normal user behavior patterns and can be used to identify abnormal activities inconsistent with normal behavior.

[0073] After collecting the above data, it is necessary to clean, standardize, and extract features to ensure that the generated feature vectors can effectively represent the current network environment and be used by threat assessment models (such as DTI). This process removes useless information or noise, such as duplicate, missing, or poorly formatted data, ensuring data quality. Cleaned data is more reliable and can aid in subsequent modeling and analysis.

[0074] Then, convert various types of data (such as network traffic, log information, and user behavior) into a unified standard format to eliminate the influence of units. For example, timestamps can be converted into time intervals, and the size of data packets can be standardized to a certain range.

[0075] Then, by analyzing the raw data, key features representing the current system state are extracted. Common features include:

[0076] Network traffic characteristics include traffic rate, protocol distribution, packet size distribution, and peak traffic. These characteristics can help detect abnormal traffic in the network and identify behaviors such as DDoS attacks and port scanning.

[0077] System log characteristics include the frequency of system events, the error log ratio, the number of user logins and logouts, and the access frequency of specific resources. These characteristics help determine whether the system experiences security incidents such as unauthorized access, privilege escalation, or vulnerability exploitation.

[0078] User behavior characteristics include the regularity of user login times, the types of resources accessed, and the frequency and type of operations performed. These characteristics are used to build a baseline model of normal user behavior, and then to identify abnormal user behavior (such as brute-force attacks, account hijacking, etc.).

[0079] After data cleaning, standardization, and feature extraction, a set of representative features is obtained, which constitute a multidimensional feature vector. Assuming that n features have been collected (e.g., network traffic rate, frequency of user behavior, etc.), the feature vector F can be expressed as: F = {f1, f2, ..., f...} n}

[0080] Where f1, f2, ..., f n These represent features extracted from different data sources (network traffic, system logs, user behavior). These features may be discrete values ​​(such as the frequency of occurrence of a specific protocol type) or continuous values ​​(such as traffic rate, time difference, etc.).

[0081] Each feature represents a specific aspect of the data, and there may be some correlation between these features. For example, network traffic volume and system load may be correlated, and abnormal user behavior may affect specific events in the system logs.

[0082] In some embodiments, the generated multidimensional feature vector can serve as the basis for subsequent Dynamic Threat Assessment (DTI) and defense strategy generation, helping the system identify threats and respond adaptively. Specific functions include:

[0083] Threat detection: By comparing real-time collected feature vectors with existing threat patterns, the system can promptly detect potential threats. For example, if network traffic characteristics are abnormal, or if multiple erroneous accesses appear in the system logs, the system can determine whether an attack is occurring.

[0084] Model Training and Optimization: In dynamic threat assessment, feature vectors are used to build threat assessment models (such as DTI). As new data is continuously added, the model can be continuously updated, improving the accuracy and response speed of threat detection.

[0085] Response and Optimization: Through the Adaptive Response Function (ARF) and the Dynamic Defense Strength Adjustment Function (DDAF), changes in feature vectors can influence the adjustment of defense strategies. For example, if abnormal user behavior occurs, the system may increase the priority of certain defense measures.

[0086] Multi-dimensional analysis: Different data sources and characteristics provide different perspectives on cybersecurity incidents, helping the system analyze from multiple dimensions and ensuring a more comprehensive defense mechanism.

[0087] Over time, network traffic, system logs, and user behavior change. Therefore, multidimensional feature vectors need to be dynamically updated based on new data to reflect the latest cybersecurity landscape. This update process may include: the dimensionality of the feature vectors may need to be expanded as new attack methods or security requirements emerge; certain features may become more important at certain points in time, requiring adjustments based on the actual situation; and the system can dynamically adjust feature extraction strategies and data collection methods based on feedback from the Defense Effectiveness Evaluation Model (DEM) to further improve the system's intelligence level.

[0088] This invention constructs a multi-dimensional feature vector based on real-time collected network traffic, system logs, and user behavior data. Through data cleaning, standardization, and feature extraction, a high-dimensional feature set is formed. These features provide crucial data support for subsequent threat assessment, attack detection, response decisions, and defense strategy optimization. By continuously updating and optimizing these feature vectors, the system can more accurately identify security threats, implement more efficient defense measures, and ultimately improve the real-time performance and intelligence of network security protection.

[0089] Step 202: Calculate the dynamic threat assessment index based on the multidimensional feature vector.

[0090] In some embodiments, step 202 may include:

[0091] From the multidimensional feature vector, obtain the weight and risk level of each feature;

[0092] Obtain multiple attack similarity metrics;

[0093] Obtain the relevant time decay factor and observation period for evaluation;

[0094] The dynamic threat assessment index is calculated by processing the weight and risk of each feature, each attack similarity index, the time decay factor, and the observation period based on the first adjustment coefficient, the second adjustment coefficient, the third adjustment coefficient, and the fourth adjustment coefficient.

[0095] In some embodiments, the dynamic threat assessment index can be expressed as:

[0096]

[0097] Wherein, DTI is the Dynamic Threat Assessment Index, ω i V is the weight of the i-th feature. i S is the risk level of the i-th feature. j is the j-th attack similarity index, t is the time decay factor, T is the observation period, and α, β, γ, and λ are the first, second, third, and fourth adjustment coefficients, respectively.

[0098] In practice, DTI stands for Dynamic Threat Assessment Index, which represents the overall severity of threats in the current network environment and serves as the basis for defense system decisions.

[0099] ω i This represents the weight of the i-th feature, indicating the degree of influence of that feature on the overall threat assessment. Different features may have different levels of importance in threat assessment, therefore, it is necessary to assign appropriate weights to each feature.

[0100] V i This represents the risk level of the i-th feature, indicating the correlation or degree of danger between the feature and the potential threat. Features may originate from network traffic, user behavior, system logs, etc. Features with higher risk levels indicate that the behavior or event may pose a greater security risk.

[0101] S j This is the j-th attack similarity metric, representing the degree of similarity between the current threat and known attacks. Attack similarity can be calculated by comparing historical attack patterns and threat features in a signature database. The higher the similarity, the more likely the threat is to be a known attack type.

[0102] t is the time decay factor, where older data has a lower weight, representing the timeliness of the data. Over time, the influence of older data gradually weakens; therefore, the time decay factor is used to simulate the mechanism by which older data reduces its impact on threat assessment.

[0103] T is the observation period, representing the time window considered when calculating threat assessments. Generally, the system defines the observation period based on the actual frequency of threat occurrences.

[0104] α, β, γ, and λ are the first, second, third, and fourth adjustment coefficients, respectively. The first adjustment coefficient adjusts the overall scale of the formula, affecting the range of the entire threat assessment index. The second adjustment coefficient adjusts the influence of the similarity product term, ensuring that the weight of the similarity index in threat assessment is appropriately adjusted. The third adjustment coefficient adjusts the influence of the time decay term, ensuring that the system can respond appropriately to threat assessments based on the timeliness of the data. The fourth adjustment coefficient controls the rate of time decay, determining the rate at which the threat index decays over time.

[0105] ω i ·V i This section reflects the importance of each feature in threat assessment. Each threat source is determined by multiple features, such as the frequency of network traffic, the temporal distribution of abnormal access, and patterns of user behavior. For different features, the system assigns a weight ω based on their impact on the potential threat. i Meanwhile, Vi This represents the hazard level of a feature. A higher hazard level indicates a stronger correlation between the feature and known threats, and therefore a greater contribution to threat assessment. If V i ω represents a specific traffic pattern in the network (such as port scanning), while ω i If the value represents the contribution of this feature to the overall threat, then the result of this item indicates the overall risk of this feature.

[0106] This section calculates the combined impact of all attack similarity metrics through multiplication. j Let be the similarity index of the j-th attack, representing the similarity between the current threat and known attacks. log(S) j Using a logarithmic function, it is emphasized that attack types with high similarity will have a more significant impact on threat assessment.

[0107] As an example only, if S j Let S represent the feature matching degree between the current attack and a known attack. If the matching degree is 0.8, then log(S) = ... j The similarity is log(0.8), representing the degree of matching between the current threat and known threats. A higher similarity indicates that the attack is more likely to be a known threat, and the system needs to pay close attention to it.

[0108] The time decay factor is used to simulate the phenomenon that data gradually loses its validity over time. t is time, T is the observation period, and λ is an adjustment coefficient that determines the rate of time decay. As data ages, threat assessments become less effective due to the use of older, outdated threat data. This time decay mechanism ensures that cybersecurity systems can respond promptly to new attacks without compromising detection effectiveness by over-relying on historical data.

[0109] As an example only, assuming the threat occurred two days ago, if λ is 1 and the observation period T is 7 days, then the time decay factor is: This indicates that the impact of data from the past two days will be reduced compared to real-time data by this factor.

[0110] α, β, γ, and λ can be adjusted according to actual needs to balance the impact of different components on threat assessment. For example, α can determine the magnitude of the overall assessment index, β controls the contribution of similarity to the assessment result, and γ adjusts the impact of time decay on the assessment result. λ is used to precisely control the decay rate to ensure that the threat assessment can reflect the latest data and attack situation in a timely manner. As an example, in a specific network environment, it may be necessary to increase the weight of β to strengthen the impact of attack similarity, while decreasing α to make the impact of feature weights on threat assessment more moderate. These adjustments help the system dynamically optimize defense strategies based on actual threat scenarios.

[0111] The purpose of the DTI formula is to combine multiple dynamic factors (such as feature risk, attack similarity, time decay, etc.) to form a comprehensive assessment model that can flexibly respond to threats in the current network environment.

[0112] ω i ·V i This section highlights the importance of each feature in the current threat assessment, ensuring that high-risk features can effectively influence defense strategies.

[0113] S j By dynamically calculating the similarity of attacks, the system can identify and respond to known threats, avoid over-reliance on rule bases, and improve its ability to protect against unknown attacks.

[0114] The time decay factor ensures the system's sensitivity to the latest threats and avoids erroneous defense decisions caused by outdated data.

[0115] In summary, the DTI formula can accurately reflect the comprehensive assessment of threats in the current network environment, providing real-time and dynamic decision-making basis for defense systems and ensuring that network protection measures can always cope with constantly evolving attack threats.

[0116] Step 203: Generate an adaptive response function based on the dynamic threat assessment index.

[0117] In some embodiments, step 203 may include:

[0118] Obtain the dynamic threat assessment index and priority for each type of threat in the network;

[0119] Obtain the historical response results for each successful response to each of the aforementioned threats;

[0120] Obtain the nonlinear adjustment exponent, learning rate, and system resource constraint factor used to generate the adaptive response function;

[0121] The adaptive response function is generated based on the dynamic threat assessment index and priority of each type of threat, the historical response effect of each successful response to each type of threat, the nonlinear adjustment index, the learning rate, and the system resource constraint factor.

[0122] In some embodiments, the adaptive response function can be expressed as:

[0123]

[0124] Where ARF is the adaptive response function, and DTI is the adaptive response function. k P is the dynamic threat assessment index for the k-th type of threat. k This is the priority of the threat, Ri denoted as the historical response effect of the i-th time, m is the nonlinear adjustment exponent, η is the learning rate, and Ω is the system resource constraint factor.

[0125] In practice, ARF stands for Adaptive Response Function, and DTI stands for Direct Response Function. k P is the dynamic threat assessment index for the k-th type of threat. k This is the priority of the threat, R i η is the effect of the i-th historical response, m is the nonlinear adjustment exponent that controls the sensitivity of the response function, η is the learning rate that represents the sensitivity of the system to historical responses, and Ω is the system resource constraint factor that ensures that the response is reasonably allocated under resource constraints.

[0126] This section reflects a weighted sum of comprehensive assessment indices and priorities for various threats, incorporating Dynamic Threat Assessment Indices (DTI) for different threat types. k ) and threat priority (P k ).

[0127] DTI k P is the dynamic threat assessment index for the k-th type of threat, representing the severity, risk level, and potential harm of this type of threat. It is usually derived from the aforementioned threat assessment formula. k This represents the priority of the k-th threat category, reflecting its importance relative to other threats. Priority is typically determined by a combination of factors, including threat type, potential impact of the attack, and attack source. Generally, higher-priority threats will consume a larger share of system resources.

[0128] The DTI (Different Threat Indices) is used to assess different threats. k Its priority P k By summing the products, the system can comprehensively consider the strength of the defense response based on the severity and priority of each threat when facing multiple threats.

[0129] This section introduces m, a nonlinear adjustment index, to nonlinearly adjust the weighted summation of the threat assessment results. By adjusting the value of m, the sensitivity of the defense response to the threat assessment results can be controlled.

[0130] The value of 'm' controls the sensitivity of the response function. When 'm' > 1, the overall threat assessment value amplifies the impact on the response strength; conversely, when 'm' < 1, it has a suppressive effect. By adjusting this index, the defense system can respond more strongly to high-priority threats and less strongly to low-priority threats.

[0131] As an example only, if m = 2, then DTI k and P kThe weighted sum is squared, meaning the system's response to high-risk, high-priority threats will be significantly enhanced. Conversely, if m is less than 1, the response to threat assessment will be more conservative.

[0132] This item represents the system's adaptability to historical response effects, reflecting how the system adjusts its current defense strategy based on past defense responses.

[0133] R i This represents the effect of the i-th historical response, and is an evaluation of the past responses of the defense system. It typically reflects the feedback of the system's effectiveness after each defense response, such as the success rate of blocking attacks and the false alarm rate.

[0134] η is the learning rate, representing how sensitive the system is to historical responses. A larger η indicates that the system is more inclined to adjust its current defense strategy based on historical responses. A smaller learning rate means that the system relies more on assessments of current threats than on historical data.

[0135] Through accumulated R i The system can determine the effectiveness of certain defensive measures and adjust its response accordingly in subsequent threat responses. For example, if a defensive measure against a certain type of attack was effective in the past, the system may increase its response strength when facing similar attacks in the future; conversely, if a defensive response was unsuccessful in the past, the system may reduce the intensity of that response or optimize the response strategy.

[0136] As an example only, if R i This indicates the success rate of responding to a certain type of attack in the past five times. This item optimizes defense decisions by accumulating historical feedback and adapts to different attack patterns.

[0137] Ω represents the system resource constraint factor, which ensures that the response strength of the defense strategy conforms to the limitations of system resources and avoids excessive consumption of system resources. This factor typically considers resource constraints such as the system's computing power, bandwidth, and storage capacity.

[0138] Ω ensures that defense responses are allocated reasonably when system resources are limited. An excessively strong response may exhaust system resources, leading to insufficient defense against other threats, or causing the system to become resource saturated, thereby affecting the overall defense effectiveness.

[0139] As an example only, if the system has limited available resources (such as bandwidth, computing power, etc.), Ω may decrease, which may result in a moderate reduction in the response to certain high-priority threats to avoid system overload.

[0140] By integrating threat assessment indices, historical response effectiveness, non-linear adjustment indices, and resource constraint factors, ARF provides a flexible approach to dynamically adjust defense response strength based on real-time threats, historical system feedback, and resource status. Specifically:

[0141] via DTI k and P k The combination of [various factors] allows the system to prioritize different threats appropriately, ensuring the strongest response to the most severe threats. The introduction of [variable name] enables the system to flexibly adjust its response sensitivity to threat assessments, enhancing its ability to respond to specific threats. This is achieved through historical response performance (R...). i Through feedback from η and adjustments to η, the system can adjust its strategy based on the performance of past defense measures, further improving defense efficiency. Ω ensures that the defense response does not exceed the system's resource limits, guaranteeing the sustainability of defense measures.

[0142] In summary, the ARF of this invention enables network security systems to make the most suitable defense response in real time and dynamically based on the current threat situation, historical feedback and system resources, ensuring the efficiency of the defense strategy and the stability of the system.

[0143] Step 204: Determine the dynamic adjustment function of defense strength based on the adaptive response function, and execute multi-level linkage defense based on the dynamic adjustment function of defense strength.

[0144] In some embodiments, step 204 may include:

[0145] Obtain the time window function used to characterize the time dependence of defense strength;

[0146] Obtain a set of defense measures that include multiple defensive measures;

[0147] Each defensive measure is processed according to the cost coefficient, the adaptive function is processed according to the sensitivity parameter, and combined with the time window function to obtain the dynamic adjustment function of the defense strength.

[0148] In some embodiments, the defense strength dynamic adjustment function can be expressed as:

[0149]

[0150] Where DDAF is the dynamic adjustment function of defense strength, θ is the time window function, representing the time dependence of defense strength, and M i It is the i-th item in the set of defensive measures, C i ψ is the cost coefficient of the measures, ψ is the sensitivity parameter that controls the degree to which defense adjustments respond to threat assessments, and ARF is the adaptive response function, which serves as the core input for adjusting defense strength.

[0151] The part ∫(ARF·θ)dt describes the change of defense strength over time, where θ represents the time window function used to capture the time dependence of defense strength.

[0152] θ is a time window function, representing how defense strength changes over time. It typically reflects the defense system's ability to adapt to threat assessment and response strength over time. In practical applications, the time window function can be modeled using linear, exponential, or decaying methods. Introducing a time window function helps the system gradually adjust its defense strength in the face of persistent threats, ensuring efficient resource utilization and sustained defense response.

[0153] For example, the intensity of a certain threat may gradually weaken over a certain period of time, at which point the time window function θ may show a decaying trend to reduce the defense intensity; while when the threat continues to increase, the time window function may gradually increase the defense response intensity.

[0154] As an adaptive response function, the ARF is multiplied by the time window function θ as a time-dependent adjustment factor, indicating that the strength of the defense depends not only on the current threat assessment (provided by the ARF) but also on the changes in the defense system's response over time.

[0155] The integral operation represents a process where the defense system continuously adjusts its defense strength according to a time window function θ over a period of time, ensuring the balance and adaptability of the defense over time. For example, the system might increase its defense strength to cope with the growth of threats during a certain period, and then gradually reduce its defense strength as the threats weaken.

[0156] This section combines different defense measures and their cost coefficients to dynamically adjust the defense strength based on the sensitivity of the defense.

[0157] M i This represents the i-th item in the set of defense measures. These measures can be firewalls, intrusion detection systems, sandboxing techniques, content filtering, etc. Each defense measure has its specific implementation method and strategy.

[0158] C i This is the cost coefficient of the i-th defensive measure, typically representing the resource consumption, computational cost, or other operational costs required to implement it. The cost coefficient reflects the implementation cost of the defensive measure; a higher cost coefficient means that the measure may require a larger resource investment. The system will consider allocating resources rationally during the defense process to avoid resource waste.

[0159] For example, some defense measures may be very precise, but require a lot of computing resources or bandwidth. In this case, the system needs to evaluate its cost-effectiveness and whether it is worthwhile to invest resources.

[0160] tanh(ψ·ARF) is a hyperbolic tangent function (tanh) used to adjust the sensitivity of the defense response. By introducing the tanh function, the system can incorporate nonlinear effects when the defense strength is adjusted. ψ is a sensitivity parameter that controls the sensitivity of the defense system to changes in threat assessment (ARF).

[0161] A larger ψ value indicates that the system is more sensitive to changes in the ARF value. The larger the ARF (i.e., the stronger the threat), the more pronounced the response of defensive measures, and vice versa. By adjusting ψ, the system can flexibly adjust the strength of defensive measures according to the current threat intensity.

[0162] The tanh(ψ·ARF) function combines ARF and ψ to adjust the system's defense strength in a nonlinear manner. The hyperbolic tangent function (tanh) is characterized by the following: when the ARF value is large, the increase in defense strength tends to plateau, avoiding overreaction; while when the ARF value is small, the defense strength increases rapidly, helping the system cope with weaker but potential threats.

[0163] As an example, a high ARF indicates a very serious current threat. In this case, ψ will ensure an enhanced response to defensive measures. Conversely, when the threat is low, the output of tanh(ψ·ARF) is smaller, and the system will moderately reduce the strength of its defenses to conserve resources and avoid excessive resource consumption.

[0164] By combining the above factors, the DDAF model makes defense strength adjustment more flexible and dynamic. Specifically, by introducing a time window function, the system can dynamically adjust defense strength according to the persistence of the threat, avoiding overreaction or waste of resources. Through M... i C i The system considers the costs and effectiveness of different defense measures, ensuring that defense decisions are not only effective but also make rational use of resources. By adjusting the sensitivity of the defense response using ψ, the system can make fine-grained adjustments based on the strength of the threat and the historical response results, ensuring the efficiency and adaptability of the defense system.

[0165] Overall, the DDAF formula effectively and dynamically adjusts the defense strength through two main components—the time window function and the adjustment of defense measures and cost coefficients.

[0166] The time window function (θ) ensures that the defense response gradually adapts to the threat situation over time, effectively avoiding excessive resource consumption and unnecessary overreaction. The combination of defensive measures and cost coefficients allows the system to consider the resource consumption of each defensive measure when adjusting defense strength, thus allocating resources rationally. Nonlinear adjustment (through tanh(ψ·ARF)) ensures that defensive measures respond with fine precision according to changes in threat strength, thereby improving defense effectiveness. The introduction of the sensitivity parameter (ψ) enables the defense system to flexibly adjust defense strength based on threat assessment results, ensuring effective response to different threats.

[0167] In summary, the DDAF of this invention provides an efficient and flexible dynamic defense adjustment mechanism that can automatically adjust the defense strength according to real-time threats and system status, thereby optimizing network security protection.

[0168] Step 205: Evaluate the defense effectiveness of the multi-level linked defense using the defense effectiveness evaluation model to obtain the corresponding evaluation results.

[0169] In some embodiments, step 205 may include:

[0170] The number of events experienced within the period for obtaining the defense effectiveness assessment;

[0171] Obtain a balancing factor to control the weight between defensive effectiveness and losses, as well as an effectiveness decay coefficient that is important for long-term defensive effectiveness;

[0172] Obtain the loss caused by the current event, and the maximum acceptable loss;

[0173] The evaluation result is determined based on the number of events, the efficiency decay coefficient of the balance factor, the loss caused by the current event, and the maximum acceptable loss.

[0174] In some embodiments, the defense effectiveness evaluation model can be expressed as:

[0175]

[0176] Where DEM is the defense effectiveness assessment model, and N is the number of events within the assessment period. It is a balancing factor that controls the weight between defensive effectiveness and losses. i The loss is caused by the current event, L max It represents the maximum acceptable loss, and ρ is the effectiveness decay coefficient, reflecting the focus on long-term defense effectiveness.

[0177] N represents the number of events the defense system experiences during the defense assessment period. An "event" can be a cyberattack, abnormal behavior, or a security vulnerability, etc. This item calculates the total number of various threats or attack events encountered by the defense system within a certain time period. By considering multiple events, the assessment model can synthesize the defense effect of all events. The more events, the more representative and reliable the overall assessment effect.

[0178] It is a balancing factor used to control the weighting between defensive effectiveness and losses. Defensive effectiveness and losses are often interrelated, but in some cases, the severity of certain losses may require more attention. The introduction of this factor allows the system to weight the contributions of defensive effectiveness and losses according to the specific circumstances.

[0179] By adjusting With a value that allows the system to focus more on the defensive effect (when...) When it is large) or loss (when (When the damage is relatively small). For example, when the defense is effective, the impact of the damage can be reduced appropriately, while when the damage is significant, more attention can be paid to the damage.

[0180] generally, The value range is from 0 to 1. If A value close to 1 indicates a higher weight for the defensive effect; a value close to 0 indicates a higher weight for the loss.

[0181] This section measures the ratio between the Defence Response (ARF) and the Threat Assessment Index (DTI). The ARF represents the defense system's response based on threat assessment and resource availability, while the DTI is an overall assessment index of the threat. The ratio of these two metrics reflects the effectiveness and appropriateness of the defense system's response.

[0182] If the defense response is high relative to the threat assessment (large ARF, small DTI), the ratio will be large, indicating that the defense response is effective against the threat. Conversely, if the defense response is weak or the threat assessment is high, the system response may be insufficient, resulting in a small ratio.

[0183] This section uses the logarithm of the comparison values ​​to ensure a smoother measurement of the defense effect within a certain range. With... As the ratio increases, the improvement in defensive effectiveness gradually decreases, thus avoiding overreaction. At smaller ratios, the improvement in defensive effectiveness is more significant, ensuring timely response to minor threats.

[0184] This section measures the loss caused by the current event (L)i ) and the system's maximum acceptable loss (L max The ratio between L and ). i L represents the loss caused by a specific event. max It is the maximum acceptable loss defined during system design.

[0185] L i Losses are losses caused by a specific event and may include a variety of factors such as financial losses, data breaches, and damage to reputation.

[0186] L max This is the maximum loss threshold that the system can withstand when faced with losses. Exceeding this threshold may result in irreversible consequences for the system.

[0187] This indicates the proportion of the current event's loss to the maximum acceptable loss. If the loss is very small (L... i A value close to 0 indicates good defense and minimal losses; a value close to 1 indicates that the defense is effective and the losses are small. i Approaching L max If the value is close to 0, it indicates that the defense has failed to effectively mitigate the losses.

[0188] ρ is the effectiveness decay coefficient, used to control the degree of decay in long-term defense effectiveness. This coefficient is introduced to reflect the importance of long-term defense effectiveness in the model, that is, whether the defense system can still maintain its effectiveness when facing long-term, persistent threats.

[0189] A larger ρ value indicates that the system is more sensitive to long-term defense effectiveness and pays more attention to the effectiveness of continuous defense. A smaller ρ value indicates that the system pays less attention to long-term defense effectiveness and may rely more on short-term defense response.

[0190] By introducing ρ, the model can distinguish between effective short-term defense strategies and their long-term effects. Over the long term, defense systems may need to adjust according to changes in the threat landscape, and ρ helps assess the effectiveness of long-term defense strategies.

[0191] Two parts of the formula and A comprehensive measure of defense effectiveness considers both the effectiveness of the defense response relative to the threat assessment and the ratio of the damage caused by the current event to the maximum acceptable loss.

[0192] As a balancing factor, it adjusts the relative importance between defensive effectiveness and losses. If the system places greater emphasis on defensive effectiveness, then... If the value is close to 1, then more attention should be paid to loss control.

[0193] pass The system assesses the damage caused by the current event to ensure that the defense system limits the damage while minimizing the impact on normal operation.

[0194] By introducing ρ, the system can effectively balance long-term and short-term defense effectiveness when evaluating its defensive capabilities. The system's emphasis on long-term effectiveness ensures its continued effectiveness under persistent threats.

[0195] Ultimately, the DEM result is an overall performance indicator of the defense system during the evaluation period. This evaluation result provides data support for subsequent defense strategy optimization, adjustment, and resource allocation.

[0196] This invention, through this DEM model, enables the defense system to base its operations on Defense Response (ARF), Threat Assessment (DTI), and Loss (L). i ) and maximum acceptable loss (L max Factors such as these are considered to comprehensively evaluate the defense effectiveness, and strategies are optimized and adjusted based on the evaluation results. DEM not only focuses on the current defense effectiveness but also makes reasonable adjustments based on the long-term effectiveness decay of the defense, thereby improving the flexibility and effectiveness of the overall defense system.

[0197] Step 206: Based on the evaluation results, continuously optimize the implemented multi-level coordinated defense.

[0198] In some embodiments, step 206 may include:

[0199] The calculation parameters in the dynamic threat assessment index, the adaptive response function, the defense strength dynamic adjustment function, and the defense effectiveness assessment model are adaptively adjusted to obtain optimized dynamic threat assessment index, adaptive response function, defense strength dynamic adjustment function, and defense effectiveness assessment model;

[0200] The weights of each feature are optimized using machine learning algorithms to obtain the optimized features;

[0201] The defense strategy threshold is dynamically updated based on the optimized dynamic threat assessment index, adaptive response function, defense strength dynamic adjustment function, and defense effectiveness assessment model, as well as the optimized features.

[0202] In this implementation, the adaptive adjustment and machine learning optimization process is the core of improving the system's defense capabilities and response efficiency. By optimizing the calculation parameters in the Dynamic Threat Assessment Index (DTI), Adaptive Response Function (ARF), Defense Strength Dynamic Adjustment Function (DDAF), and Defense Effectiveness Assessment Model (DEM), the system can continuously adjust its defense strategy according to changes in the network environment, thereby improving defense effectiveness. The following is a detailed explanation of this process:

[0203] During system operation, the network environment and attack situation are constantly changing. Therefore, the original calculation parameters need to be dynamically adjusted according to the actual situation to ensure the continuous effectiveness of the defense system. Specifically, the system will adaptively adjust the following four important calculation parameters:

[0204] The adjustment coefficients (α, β, γ, λ) in the DTI formula control the degree of influence of different factors in threat assessment. In actual operation, attack patterns and system states are constantly changing, so these coefficients should be dynamically adjusted based on real-time information such as historical attack data, current network traffic, and system load. For example, if a certain feature has a significant impact on threat assessment, the corresponding weight coefficients (α, β, γ) can be increased, thereby making the role of that feature more prominent in threat assessment.

[0205] In some embodiments, these coefficients can be dynamically adjusted based on the accuracy of each threat assessment through a real-time monitoring and feedback mechanism. For example, the system can adjust the coefficients through regression analysis of historical data or optimization algorithms to improve assessment accuracy.

[0206] An ARF (Advanced Reinforcement Response Framework) includes several parameters, such as the nonlinear adjustment exponent (m), learning rate (η), and resource constraint factor (Ω). These parameters directly influence the formulation of defense strategies. For example, the learning rate η controls the system's sensitivity to historical responses; if the attack situation changes rapidly, the system may need a higher learning rate to quickly adjust its response strategy. Online learning or reinforcement learning algorithms can be used to analyze historical response performance (R0). i The feedback is optimized to enable the response function to respond more accurately to different types of threats.

[0207] The time window function (θ), sensitivity parameter (ψ), and measure cost coefficient (C) in the DDAF formula i Parameters such as sensitivity (ψ) can affect the effectiveness of defense measures. For example, if cyberattacks occur frequently, the sensitivity parameter ψ may need to be increased to make the system respond more quickly and sensitively to threats. These parameters can be adjusted by analyzing historical defense performance and using machine learning methods to improve the adaptability and effectiveness of defense strategies. Adaptive optimization algorithms, such as genetic algorithms and particle swarm optimization, can be used to optimize these parameters.

[0208] Balance factor in DEM Performance attenuation coefficient (ρ), loss ratio Parameters such as these will affect the evaluation results of defense effectiveness. These parameters need to be dynamically adjusted according to changes in the network environment and attack patterns. They can also be adjusted based on historical defense effectiveness feedback. For example, if the defense system has not experienced a serious attack for a long period, the effectiveness decay coefficient (ρ) can be appropriately reduced to improve its defense capabilities against future attacks.

[0209] In this invention, optimizing feature weights using machine learning algorithms is a crucial means of improving threat assessment and defense effectiveness. Machine learning can automatically analyze the impact of different features and optimize their weights based on real-time data.

[0210] By analyzing real-time collected data, machine learning algorithms can identify which features (such as network traffic, system logs, and user behavior) are strongly correlated with security threats and which features contribute significantly to the accuracy of threat assessment. The system can dynamically adjust the weight of each feature, ensuring that important features receive more attention in the assessment and improving defense effectiveness.

[0211] Labeled attack and normal datasets can be used to automatically optimize feature weights through training algorithms (such as decision trees, support vector machines, neural networks, etc.). Machine learning models can be trained on historical datasets to learn which features are more important in threat assessment.

[0212] When labeled data is unavailable, clustering algorithms (such as K-means, DBSCAN, etc.) or dimensionality reduction algorithms (such as PCA) can be used to identify the inherent structure of the data and automatically discover and adjust feature weights. Based on feedback from the network defense system, the system can use reinforcement learning to adjust feature weights and defense strategies to maximize defense effectiveness.

[0213] After improving the threat assessment and defense response mechanisms through adaptive adjustment and machine learning optimization, the system will dynamically update the threshold of the defense strategy based on the new dynamic threat assessment index, the optimized response function, and the defense strength adjustment function, ensuring that the system can cope with the ever-changing attack situation.

[0214] Thresholds in a defense strategy determine the strength and time of the system's response to different types of threats. For example, some high-threat attacks may require immediate and strong defensive measures, while low-threat attacks can be addressed with a moderate response. Optimized dynamic threat assessment indices and adaptive response functions can help determine reasonable thresholds, thereby ensuring the effective allocation of resources.

[0215] Based on the optimized threat assessment results and response strategies, the system adjusts the defense strategy thresholds in real time. For example, when a new type of attack occurs, the system automatically calculates the most suitable defense threshold by evaluating its threat index, similarity index, and historical response performance, thereby adjusting defense measures more accurately.

[0216] When new attack patterns emerge, the system can automatically adjust its defense behavior by dynamically updating defense policy thresholds. For example, if a zero-day attack or APT attack is identified, the system will raise the threshold for that attack category, making the defense policy more stringent; if it is a known attack with a good response history, the threshold can be lowered to reduce resource waste.

[0217] In summary, this invention continuously optimizes the performance of the network defense system by adaptively adjusting computational parameters, optimizing feature weights based on machine learning, and dynamically updating defense strategy thresholds. The system adjusts the threat assessment model and defense mechanisms based on real-time data and feedback, thereby improving its responsiveness to unknown attacks and rapidly changing threats, ensuring that network security protection is always at its best.

[0218] In some embodiments, the method of this application may further include:

[0219] The threat knowledge base is updated based on the assessment results to obtain the updated threat knowledge base;

[0220] The updated defense strategy base is updated based on the updated threat knowledge base to obtain the updated defense strategy base.

[0221] Based on the updated threat knowledge base and the updated defense strategy base, the system response mechanism and resource scheduling strategy are optimized.

[0222] In practice, a threat knowledge base can contain information on various known threats, such as attack types, attack methods, attack targets, and attacker behavior patterns. As new threats emerge, the threat knowledge base needs to be dynamically updated based on the latest assessment results. The specific process is as follows:

[0223] Real-time calculations using models such as the Dynamic Threat Assessment Index (DTI), Adaptive Response Function (ARF), and Dynamic Defense Strength Adjustment Function (DDAF) can determine the threat level and attack type in the current network environment. The assessment results can include threat characteristics (such as attack source, attack method, attack strength, and attack target) and their potential impact on the system.

[0224] When the system identifies new types of attacks or unknown attack patterns, the evaluation results are fed back to the threat knowledge base. Through technologies such as machine learning, the system can extract and analyze these new attack characteristics, updating the threat data in the knowledge base in a timely manner.

[0225] By analyzing historical attack events and feedback, the system can optimize the description and classification of known threats. For example, if the characteristic pattern of a certain attack changes, the system can adjust the identifier or definition of that attack type in the knowledge base.

[0226] The system integrates new attack patterns, variants, or the evolution of known attacks into the threat knowledge base through automated learning mechanisms (such as incremental learning and reinforcement learning). This ensures that the threat knowledge base remains up-to-date, enabling the defense system to promptly identify and defend against new attacks.

[0227] The updated threat knowledge base not only contains the latest attack information, but also has higher accuracy and identification capabilities, enabling the system to better analyze and respond to new and known threats.

[0228] The defense strategy repository stores defense strategies for different threats. For different types of attacks, the repository provides various defense methods and emergency response measures. Updates to the defense strategy repository are based on new information from the threat knowledge base, and the specific process is as follows:

[0229] Mapping Threat Types to Defense Strategies: Each new threat type or threat characteristic is mapped to a corresponding defense strategy. By analyzing data from threat assessment results, the defense strategy library can dynamically adjust existing strategies, add new strategies, or optimize existing strategies.

[0230] Optimization of defense strategies: For example, if the threat knowledge base is updated to target new variants of a certain attack, the defense strategy base will update its defense measures according to the characteristics of the new variant. For instance, if the system detects that an attack is carried out through a specific protocol, the defense strategy base will provide corresponding protocol blocking strategies.

[0231] Machine learning algorithms can automatically optimize defense strategies based on new attack characteristics and threat assessment results. For example, if historical data shows that a certain defense strategy is ineffective against a specific attack, the system can automatically adjust or replace that strategy.

[0232] After the threat knowledge base is updated, the defense strategy base automatically adjusts its defense measures based on the latest data in the threat knowledge base to ensure the effectiveness and relevance of the defense measures. The updated defense strategy base can cope with a wider range of attack scenarios and reduce false positives and false negatives.

[0233] Updates to the threat knowledge base and defense strategy base provide the foundation for optimizing the system's response mechanism and resource scheduling. The system's response mechanism and resource scheduling strategies need to be dynamically adjusted based on the effectiveness of defense measures, the urgency of the attack, and available resources. The specific steps are as follows:

[0234] Response Priority Adjustment: Based on new threat types and updated defense strategies, the system will reassess the priority of different threats. The system will determine the priority attack types to respond to based on each threat's Dynamic Threat Assessment Index (DTI) and the countermeasures in the defense strategy library. For example, high-risk APT attacks or zero-day attacks will be prioritized.

[0235] Real-time response adjustments: The updated threat knowledge base provides more accurate threat identification information, and the defense strategy library offers more targeted defense measures. The system can dynamically adjust response intensity and strategies based on real-time threat assessment results. For example, when the system detects a change in attack patterns, defense measures will automatically adjust to minimize the damage caused by the attack.

[0236] Resource Allocation and Scheduling: Resource scheduling strategies need to ensure that limited computing, bandwidth, and storage resources are rationally allocated among multiple defense tasks. When facing multiple concurrent threats, the system optimizes resource allocation based on attack assessments in the threat knowledge base and the requirements of defense measures in the defense strategy base. For example, the system may allocate more resources to high-priority attack response tasks to ensure that the system can respond to threats in the most effective way.

[0237] Dynamic resource scheduling: During the defense process, the system may need to dynamically adjust resource allocation based on the attack intensity and complexity. For example, defending against complex intrusions may require more computing resources for data analysis, while defending against simple denial-of-service attacks may require fewer resources. The system will optimize resource scheduling based on the threat level and defense effectiveness.

[0238] In summary, this invention updates the threat knowledge base and defense strategy base, and optimizes the system's response mechanism and resource scheduling strategy based on these updates, enabling the entire system to achieve automatic adaptation and real-time optimization. Updating the threat knowledge base ensures the system's ability to identify new types of attacks, updating the defense strategy base ensures that the system's threat response strategies are more accurate and efficient, and the optimized response mechanism and resource scheduling strategy ensure that the system can rationally allocate computing resources while providing efficient defense, thereby improving defense effectiveness and ultimately achieving dynamic, intelligent, and automated defense capabilities.

[0239] Please see Figure 2 , Figure 2 This invention provides a schematic diagram of the structure of a big data-based dynamic network security defense system.

[0240] like Figure 2 As shown in the figure, the big data-based dynamic network security defense system proposed in this embodiment of the invention includes:

[0241] The data acquisition module 301 is used to construct a multi-dimensional feature vector based on real-time collected network traffic data, system logs and user behavior data;

[0242] Threat assessment module 302 is used to calculate a dynamic threat assessment index based on the multidimensional feature vector;

[0243] Threat response module 303 is used to generate an adaptive response function based on the dynamic threat assessment index;

[0244] The network defense module 304 is used to determine the dynamic adjustment function of the defense strength based on the adaptive response function, and to execute multi-level linkage defense based on the dynamic adjustment function of the defense strength;

[0245] The defense evaluation module 305 is used to evaluate the defense effect of the multi-level linkage defense through the defense effectiveness evaluation model and obtain the corresponding evaluation results.

[0246] The defense optimization module 306 is used to continuously optimize the executed multi-level linkage defense based on the evaluation results.

[0247] Please see Figure 3 , Figure 3 A schematic diagram illustrating an embodiment of the electronic device provided in this invention. For example... Figure 3 As shown, an embodiment of the present invention provides an electronic device 400, including a memory 410, a processor 420, and a computer program 411 stored in the memory 410 and executable on the processor 420. When the processor 420 executes the computer program 411, it performs the following steps:

[0248] A multidimensional feature vector is constructed based on real-time collected network traffic data, system logs, and user behavior data.

[0249] Based on the multidimensional feature vector, the dynamic threat assessment index is calculated;

[0250] Generate an adaptive response function based on the dynamic threat assessment index;

[0251] The dynamic adjustment function for defense strength is determined based on the adaptive response function, and multi-level coordinated defense is executed based on the dynamic adjustment function for defense strength.

[0252] The defense effectiveness of the multi-level linked defense is evaluated using a defense effectiveness evaluation model, and the corresponding evaluation results are obtained.

[0253] Based on the evaluation results, the implemented multi-level coordinated defense will be continuously optimized.

[0254] Please see Figure 4 , Figure 4This is a schematic diagram illustrating an embodiment of a computer-readable storage medium provided by an embodiment of the present invention. For example... Figure 4 As shown, this embodiment provides a computer-readable storage medium 500 on which a computer program 411 is stored. When the computer program 411 is executed by a processor, it performs the following steps:

[0255] A multidimensional feature vector is constructed based on real-time collected network traffic data, system logs, and user behavior data.

[0256] Based on the multidimensional feature vector, the dynamic threat assessment index is calculated;

[0257] Generate an adaptive response function based on the dynamic threat assessment index;

[0258] The dynamic adjustment function for defense strength is determined based on the adaptive response function, and multi-level coordinated defense is executed based on the dynamic adjustment function for defense strength.

[0259] The defense effectiveness of the multi-level linked defense is evaluated using a defense effectiveness evaluation model, and the corresponding evaluation results are obtained.

[0260] Based on the evaluation results, the implemented multi-level coordinated defense will be continuously optimized.

[0261] It should be noted that the descriptions of each embodiment in the above embodiments have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0262] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0263] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1A system that specifies functions in one or more boxes.

[0264] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including an instruction set implemented in a process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0265] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0266] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.

[0267] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A dynamic network security defense method based on big data, characterized in that, The method includes: Based on real-time collected network traffic data, system logs, and user behavior data, a multi-dimensional feature vector is constructed. The user behavior data includes login time, accessed resources, entered commands, and performed operations. Based on the multidimensional feature vector, the dynamic threat assessment index is calculated; Generate an adaptive response function based on the dynamic threat assessment index; The dynamic adjustment function for defense strength is determined based on the adaptive response function, and multi-level coordinated defense is executed based on the dynamic adjustment function for defense strength. The defense effectiveness of the multi-level linked defense is evaluated using a defense effectiveness evaluation model, and the corresponding evaluation results are obtained. Based on the evaluation results, the implemented multi-level coordinated defense will be continuously optimized. The calculation of the dynamic threat assessment index based on the multidimensional feature vector includes: From the multidimensional feature vector, obtain the weight and risk level of each feature; Obtain multiple attack similarity metrics; Obtain the relevant time decay factor and observation period for evaluation; Based on the first adjustment coefficient, the second adjustment coefficient, the third adjustment coefficient, and the fourth adjustment coefficient, the weight and risk of each feature, each attack similarity index, the time decay factor, and the observation period are processed to calculate the dynamic threat assessment index. The dynamic threat assessment index is expressed as: in, It is a dynamic threat assessment index. It is the weight of the i-th feature. It is the risk level of the i-th feature. This is the j-th attack similarity index, t is the time decay factor, and T is the observation period. These are the first adjustment coefficient, the second adjustment coefficient, the third adjustment coefficient, and the fourth adjustment coefficient.

2. The big data-based dynamic network security defense method according to claim 1, characterized in that, The step of generating an adaptive response function based on the dynamic threat assessment index includes: Obtain the dynamic threat assessment index and priority for each type of threat in the network; Obtain the historical response results for each successful response to each of the aforementioned threats; Obtain the nonlinear adjustment exponent, learning rate, and system resource constraint factor used to generate the adaptive response function; The adaptive response function is generated based on the dynamic threat assessment index and priority of each type of threat, the historical response effect of each successful response to each type of threat, the nonlinear adjustment index, the learning rate, and the system resource constraint factor.

3. The big data-based dynamic network security defense method according to claim 2, characterized in that, The adaptive response function is expressed as follows: in, It is an adaptive response function. It is the dynamic threat assessment index for the k-th type of threat. This is the priority of the threat. This represents the historical response effect of the i-th time, where m is the nonlinear adjustment exponent. It's the learning rate. It is a system resource constraint factor.

4. The big data-based dynamic network security defense method according to claim 3, characterized in that, The step of determining the dynamic adjustment function of defense strength based on the adaptive response function includes: Obtain the time window function used to characterize the time dependence of defense strength; Obtain a set of defense measures that include multiple defensive measures; Each defensive measure is processed according to the cost coefficient, the adaptive function is processed according to the sensitivity parameter, and combined with the time window function to obtain the dynamic adjustment function of the defense strength.

5. The big data-based dynamic network security defense method according to claim 4, characterized in that, The defense effectiveness of the multi-level linked defense is evaluated using a defense effectiveness evaluation model to obtain corresponding evaluation results, including: The number of events experienced within the period for obtaining the defense effectiveness assessment; Obtain a balancing factor to control the weight between defensive effectiveness and losses, as well as an effectiveness decay coefficient that is important for long-term defensive effectiveness; Obtain the loss caused by the current event, and the maximum acceptable loss; The evaluation result is determined based on the number of events, the efficiency decay coefficient of the balance factor, the loss caused by the current event, and the maximum acceptable loss.

6. The big data-based dynamic network security defense method according to claim 5, characterized in that, The step of continuously optimizing the implemented multi-level coordinated defense based on the evaluation results includes: The calculation parameters in the dynamic threat assessment index, the adaptive response function, the defense strength dynamic adjustment function, and the defense effectiveness assessment model are adaptively adjusted to obtain optimized dynamic threat assessment index, adaptive response function, defense strength dynamic adjustment function, and defense effectiveness assessment model; The weights of each feature are optimized using a machine learning algorithm to obtain the optimized features; The defense strategy threshold is dynamically updated based on the optimized dynamic threat assessment index, adaptive response function, defense strength dynamic adjustment function, and defense effectiveness assessment model, as well as the optimized features.

7. The big data-based dynamic network security defense method according to claim 6, characterized in that, The method further includes: The threat knowledge base is updated based on the assessment results to obtain the updated threat knowledge base. The updated defense strategy base is updated based on the updated threat knowledge base to obtain the updated defense strategy base. Based on the updated threat knowledge base and the updated defense strategy base, the system response mechanism and resource scheduling strategy are optimized.

8. A dynamic network security defense system based on big data, characterized in that, The system includes: The data acquisition module is used to construct multi-dimensional feature vectors based on real-time collected network traffic data, system logs, and user behavior data. The user behavior data includes login time, accessed resources, entered commands, and performed operations. The threat assessment module is used to calculate a dynamic threat assessment index based on the multidimensional feature vector. The threat response module is used to generate an adaptive response function based on the dynamic threat assessment index. The network defense module is used to determine the dynamic adjustment function of defense strength based on the adaptive response function, and to execute multi-level linkage defense based on the dynamic adjustment function of defense strength; The defense evaluation module is used to evaluate the defense effectiveness of the multi-level linked defense through the defense effectiveness evaluation model and obtain the corresponding evaluation results. The defense optimization module is used to continuously optimize the executed multi-level linkage defense based on the evaluation results. The calculation of the dynamic threat assessment index based on the multidimensional feature vector includes: From the multidimensional feature vector, obtain the weight and risk level of each feature; Obtain multiple attack similarity metrics; Obtain the relevant time decay factor and observation period for evaluation; Based on the first adjustment coefficient, the second adjustment coefficient, the third adjustment coefficient, and the fourth adjustment coefficient, the weight and risk of each feature, each attack similarity index, the time decay factor, and the observation period are processed to calculate the dynamic threat assessment index. The dynamic threat assessment index is expressed as: in, It is a dynamic threat assessment index. It is the weight of the i-th feature. It is the risk level of the i-th feature. This is the j-th attack similarity index, t is the time decay factor, and T is the observation period. These are the first adjustment coefficient, the second adjustment coefficient, the third adjustment coefficient, and the fourth adjustment coefficient.

Citation Information

Patent Citations

  • Network security protection method and system

    CN117879970A