Network operation and maintenance environment risk assessment method and system based on mimicry security technology
By employing a network operation and maintenance environment risk assessment method based on mimicry security technology, which combines data collection, mimicry analysis, and heterogeneous twin models, the problems of lagging threat identification and insufficient risk assessment in network operation and maintenance environments are solved. This enables dynamic threat identification and accurate risk assessment, thereby improving the level of intelligence in network security.
Patent Information
- Application Number
- CN202510050725.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2045-01-13
AI Technical Summary
Existing technologies are insufficient to effectively address dynamic, diverse, and intelligent threats in network operation and maintenance environments. Threat identification is lagging, overall risk assessment is inadequate, and response measures are not intelligent enough, resulting in insufficient timeliness and accuracy of network defense.
A network operation and maintenance environment risk assessment method based on mimicry security technology is adopted. Through data collection, real mimicry analysis and active challenge mimicry analysis, abnormal feature data and disturbance response data are extracted, and a heterogeneous twin model is constructed for data fusion and risk quantification assessment to generate the optimal response strategy.
It enables dynamic threat simulation and identification, improves the comprehensiveness and accuracy of threat identification, provides accurate risk assessment results, and generates optimal response strategies through multi-objective optimization algorithms, thereby enhancing the security and intelligence level of the network operation and maintenance environment.
Smart Images

Figure CN119892461B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network operation and maintenance supervision technology, and in particular to a method and system for risk assessment of network operation and maintenance environment based on mimicry security technology. Background Technology
[0002] As network operation and maintenance environments become increasingly complex, traditional security protection methods (such as static defense and rule-matching detection technologies) are struggling to effectively address new types of network attacks, especially dynamic, diverse, and intelligent threats. This is because existing technologies (Chinese invention patent, publication number: CN117834305B, title: A Network Operation and Maintenance Environment Assessment System Based on Mimicry Security Technology) mostly employ single-indicator monitoring and static evaluation methods, relying on fixed security policies or feature-based threat identification mechanisms. They cannot simulate complex attack scenarios in real time, nor can they perform effective dynamic feedback and control, leading to the following shortcomings:
[0003] Threat identification lag: Due to reliance on static analysis, dynamic threats cannot be identified quickly;
[0004] Insufficient global risk assessment: Lack of cross-level data correlation and modeling leads to inaccurate risk assessment;
[0005] The response measures are not intelligent enough: they cannot generate dynamic and optimal response strategies based on risk assessment results, resulting in insufficient timeliness and accuracy of network defense. Summary of the Invention
[0006] To address the numerous problems existing in the prior art, this invention provides a network operation and maintenance environment risk assessment method and system based on mimicry security technology. This invention extracts abnormal feature data and disturbance response data in the network operation and maintenance environment through data collection, real mimicry analysis and proactive challenge mimicry analysis, and performs data fusion and risk quantification assessment through a cross-layer correlation mapping model to generate the optimal response strategy, realize dynamic risk identification and real-time optimization of network security status, and improve network security monitoring and response capabilities.
[0007] A network operation and maintenance environment risk assessment method based on mimicry security technology includes the following steps:
[0008] Data is collected and preprocessed in the network operation and maintenance environment, and the collected data is deduplicated, time-aligned and standardized to generate standardized security data.
[0009] Based on the standardized security data, real anomaly feature data and virtual disturbance response data are extracted through real mimicry analysis and active challenge mimicry analysis, respectively. The real anomaly feature data and virtual disturbance response data are then fused to generate associated threat feature data.
[0010] Based on the associated threat feature data, a heterogeneous twin model is constructed to perform state modeling, threat modeling and resource modeling, and risk assessment data is generated through data fusion and risk quantification assessment algorithms.
[0011] Based on the risk assessment data, an optimal response strategy is generated through a multi-objective optimization algorithm. The optimal response strategy includes flow control, node isolation, and resource scheduling. The optimal response strategy is then executed, and strategy execution feedback data is collected. The feedback data is then transmitted back to the heterogeneous twin model for risk status update and optimization through a feedback control mechanism.
[0012] Preferably, the data in the network operation and maintenance environment includes network traffic data, user behavior data, and system log data. When deduplicating the collected data, the data identification information is compared based on a hash deduplication algorithm to remove duplicate data. When aligning the collected data by time, the data source time is aligned based on a timestamp synchronization mechanism, and the deduplicated and time-aligned data is converted into standardized security data in a unified format through a standardization algorithm.
[0013] Preferably, the realistic mimicry analysis uses a deep behavior matching algorithm to extract abnormal features from network traffic data, user behavior data, and system log data. The deviation value of the abnormal features is calculated using the following formula:
[0014]
[0015] Where D represents the abnormal deviation value; X i represents the actual value of the i-th data point; M represents the reference value in the normal behavior template; n represents the number of data points.
[0016] Preferably, the proactive challenge mimicry analysis generates disturbance response data through a dynamic disturbance engine, and the disturbance response data includes simulated abnormal data packets, virtual vulnerability triggering operations, and disguised user operations.
[0017] Preferably, when fusing real anomaly feature data and virtual disturbance response data, the feature weights are dynamically adjusted using an adaptive fusion method. The formula for calculating the feature fusion weights is as follows:
[0018]
[0019] Among them, W i T represents the fusion weight of the i-th feature; i represents the baseline weight value of the i-th feature; n represents the number of features.
[0020] Preferably, the heterogeneous twin model includes state modeling, threat modeling, and resource modeling, wherein state modeling generates node state mapping data through network node health parameters, threat modeling generates threat propagation paths based on associated threat feature data, and resource modeling generates node resource adaptation state data based on resource load distribution.
[0021] Preferably, risk assessment data, including risk level, impact range and quantitative score, is generated by fusing state modeling data, threat modeling data and resource modeling data through a cross-layer correlation mapping model.
[0022] Preferably, the risk quantification assessment uses a risk quantification assessment algorithm to quantify and analyze the state modeling data, threat modeling data, and resource modeling data to calculate the risk level. The risk level R is determined by the following formula:
[0023] R = α·S + β·W + γ·L
[0024] Where R represents the risk level; S represents the risk score of the state modeling data; W represents the risk score of the threat modeling data; L represents the risk score of the resource modeling data; and α, β, and γ are the weighting coefficients for risk assessment.
[0025] Preferably, the risk assessment results and execution feedback data are fed back to the heterogeneous twin model through a feedback control mechanism to dynamically update the network node status, threat propagation path and resource load distribution, thereby optimizing the risk quantification assessment results.
[0026] A system for implementing the network operation and maintenance environment risk assessment method based on mimicry security technology, comprising:
[0027] The data acquisition and preprocessing module is used to acquire and preprocess data in the network operation and maintenance environment, and to perform deduplication, time alignment and standardization on the data to generate standardized security data.
[0028] The mimicry analysis module is used to extract real anomaly feature data and virtual disturbance response data based on the standardized security data through real mimicry analysis and active challenge mimicry analysis, respectively, and to fuse the real anomaly feature data and virtual disturbance response data to generate associated threat feature data.
[0029] The heterogeneous twin modeling module is used to construct a heterogeneous twin model based on the associated threat feature data, perform state modeling, threat modeling and resource modeling, and generate risk assessment data through data fusion and risk quantification assessment algorithms;
[0030] The optimal response strategy generation module is used to generate an optimal response strategy based on the risk assessment data using a multi-objective optimization algorithm. The optimal response strategy includes flow control, node isolation, and resource scheduling.
[0031] The strategy execution and feedback control module is used to execute the optimal response strategy, collect strategy execution feedback data, and transmit the feedback data back to the heterogeneous twin model through the feedback control mechanism to dynamically update the risk status.
[0032] Compared with the prior art, the advantages and beneficial effects of the present invention are as follows:
[0033] This invention utilizes mimicry security technology to achieve dynamic threat simulation and identification, enabling rapid extraction of abnormal feature data and virtual response data, thereby improving the comprehensiveness and accuracy of threat identification.
[0034] This invention achieves data fusion of state modeling, threat modeling, and resource modeling through a cross-layer correlation mapping model, quantitatively assesses risk levels, and provides accurate risk assessment results;
[0035] This invention generates the optimal response strategy through a multi-objective optimization algorithm, realizing flow control, node isolation and resource scheduling, and achieves dynamic updating and optimization of risk status through a feedback control mechanism;
[0036] This invention improves the security and intelligence of the network operation and maintenance environment through dynamic evaluation throughout the entire process, effectively addressing complex security threats. Attached Figure Description
[0037] Figure 1 This is a schematic flowchart of the method of the present invention;
[0038] Figure 2 This is a schematic diagram of the feedback control mechanism in this invention;
[0039] Figure 3 This is a schematic diagram illustrating the multi-objective optimization strategy generation in this invention;
[0040] Figure 4 This is a schematic diagram of risk quantification assessment in this invention;
[0041] Figure 5 This is a structural block diagram of the system of the present invention. Detailed Implementation
[0042] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation.
[0043] like Figure 1 As shown, a network operation and maintenance environment risk assessment method based on mimicry security technology includes the following steps:
[0044] Data is collected and preprocessed in the network operation and maintenance environment, and the collected data is deduplicated, time-aligned and standardized to generate standardized security data.
[0045] Preferably, the data in the network operation and maintenance environment includes network traffic data, user behavior data, and system log data. When deduplicating the collected data, the data identification information is compared based on a hash deduplication algorithm to remove duplicate data. When aligning the collected data by time, the data source time is aligned based on a timestamp synchronization mechanism, and the deduplicated and time-aligned data is converted into standardized security data in a unified format through a standardization algorithm.
[0046] In this invention, collecting and preprocessing data in the network operation and maintenance environment, and performing deduplication, time alignment and standardization on the collected data are the basic steps to realize network operation and maintenance environment risk assessment based on mimicry security technology, aiming to ensure the accuracy, consistency and standardization of data.
[0047] Data in the network operation and maintenance environment includes network traffic data, user behavior data, and system log data. This data is acquired through a distributed data acquisition module. Network traffic data is extracted in real time by traffic capture tools to extract data packets, traffic paths, and traffic intensity. User behavior data is analyzed based on user operation logs to determine access behavior and operation patterns. System log data is extracted from operation and maintenance system logs to extract fault information, error records, and resource usage.
[0048] The collected data first undergoes deduplication. A hash deduplication algorithm is used to uniquely determine the data's identifiers (e.g., data ID, timestamp, or content hash value), eliminating duplicate data and preventing data redundancy from interfering with subsequent processing. Next, the collected data is time-aligned. A timestamp synchronization mechanism unifies data from different sources along the time dimension, addressing time offset issues that exist during multi-data source collection. This process specifically includes attaching high-precision timestamps to the data and adjusting the time axis mapping during data preprocessing to ensure data synchronization and alignment. Finally, the deduplicated and time-aligned data is standardized using a standardization algorithm. This is achieved through numerical normalization or standardization transformation, converting data from different sources into standardized security data in a unified format. This eliminates differences in scale, units, and numerical distribution, making the data comparable and consistent, providing stable data input for subsequent risk assessment analysis. Through this preprocessing workflow, the obtained standardized security data possesses high accuracy, consistency, and completeness, effectively supporting subsequent real-world mimicry analysis and proactive challenge mimicry analysis, improving the reliability and efficiency of data application in risk assessment.
[0049] Based on the standardized security data, real anomaly feature data and virtual disturbance response data are extracted through real mimicry analysis and active challenge mimicry analysis, respectively. The real anomaly feature data and virtual disturbance response data are then fused to generate associated threat feature data.
[0050] Based on the standardized security data, this invention extracts real anomaly feature data and virtual disturbance response data through two key steps: real mimicry analysis and active challenge mimicry analysis. These data are then fused to generate associated threat feature data, thereby providing accurate threat feature input for subsequent risk assessment.
[0051] Realistic mimicry analysis involves deep behavioral matching and feature analysis of standardized security data in a network operations and maintenance environment to identify abnormal features that deviate significantly from normal behavior. For example, path analysis of network traffic data can extract abnormal access paths; operation sequence comparison of user behavior data can extract abnormal command sequences; and error detection of system log data can identify frequently occurring fault logs. The extraction of these deviation features is based on the matching deviation between normal behavior templates and current observation data, ensuring that real abnormal feature data can accurately reflect abnormal situations in the actual operations and maintenance environment.
[0052] Active challenge mimicry analysis injects simulated anomalies and challenge data into the network operation and maintenance environment through a dynamic disturbance engine. This includes simulating abnormal network traffic, triggering virtual vulnerabilities, and simulating user operations to induce potential risks and threats in the network system. This allows the acquisition of virtual disturbance response data under simulated disturbance conditions. For example, specific data packet disturbances can be introduced into network traffic data to observe changes in node traffic distribution, or virtual vulnerabilities can be triggered in system resource data and system log responses can be recorded to obtain the system's response characteristics under abnormal disturbances.
[0053] Real anomaly feature data and virtual disturbance response data are extracted from actual network environments and simulated anomaly environments, respectively. In this invention, these two types of data are associated through a multi-dimensional feature mapping and weight fusion method. Specifically, the data dimensions of real anomaly features and virtual response features are uniformly mapped, highly related feature items are selected through a similarity matching algorithm, and the feature fusion ratio is dynamically adjusted by an adaptive weight allocation mechanism to generate associated threat feature data.
[0054] The generation of associated threat feature data can effectively aggregate abnormal behaviors in real environments and response features under simulated challenges, thereby improving the ability to identify potential threats. On the other hand, by integrating threat features from multiple sources, a more comprehensive threat feature description can be constructed, reducing the limitations and misjudgment rate caused by feature extraction from a single data source. This provides highly accurate and confident input data for subsequent heterogeneous twin modeling, thereby enhancing the overall effectiveness and accuracy of network operation and maintenance environment risk assessment.
[0055] Preferably, the realistic mimicry analysis uses a deep behavior matching algorithm to extract abnormal features from network traffic data, user behavior data, and system log data. The deviation value of the abnormal features is calculated using the following formula:
[0056]
[0057] Where D represents the abnormal deviation value; X i represents the actual value of the i-th data point; M represents the reference value in the normal behavior template; n represents the number of data points.
[0058] In this invention, realistic mimicry analysis, through a deep behavior matching algorithm, extracts abnormal features from network traffic data, user behavior data, and system log data. This is a crucial step in assessing network operation and maintenance environment risks. Its core lies in identifying anomalous features that significantly deviate from normal behavior patterns through deep comparison of behavioral characteristics, thereby revealing potential security threats in the network operation and maintenance environment. Specifically, network traffic data is analyzed by examining packet transmission paths, traffic intensity, and access timing; user behavior data is analyzed by examining user operation commands, login frequency, and access paths; and system log data is analyzed by extracting fault information and error records from the logs. These are all compared with normal behavior templates to identify feature points deviating from the normal state. During implementation, the deep behavior matching algorithm quantifies the degree of anomaly by calculating the deviation value between observed data and normal template data. This deviation value is calculated using the following formula:
[0059]
[0060] The principle behind this formula is that by subtracting each observation from the normal template data item by item and summing the absolute values, the overall deviation between the current data and the normal behavior pattern can be effectively quantified. When the deviation value D exceeds a preset threshold, the data is considered to have abnormal characteristics and requires further threat analysis. In practical applications, deep behavior matching algorithms can construct normal behavior templates for different scenarios to perform comprehensive feature comparisons on network traffic, user behavior, and system log data. For example, when the access path in network traffic data shows multiple abnormal jumps compared to the normal template, the operation sequence in user behavior data deviates from the normal access pattern, or a large number of consecutive error records appear in the system logs, the algorithm will capture these abnormal data points and confirm the significance of the anomaly through deviation value calculation.
[0061] The advantage of extracting anomalous features through realistic mimicry analysis lies in its ability to accurately identify potential security threats in network operation and maintenance environments, especially abnormal behaviors hidden within normal data streams. These anomalous features can be quantified, providing data support for subsequent threat modeling and risk assessment. Furthermore, the calculation and quantification of deviation values effectively eliminates the interference of data noise on anomaly detection, improving the accuracy and robustness of anomalous feature extraction. Overall, the realistic mimicry analysis in this invention, through deep behavior matching algorithms and deviation value quantification, achieves efficient identification and accurate quantification of potential risks in network operation and maintenance environments, providing a strong foundation for risk assessment based on mimicry security technology.
[0062] Preferably, the proactive challenge mimicry analysis generates disturbance response data through a dynamic disturbance engine, and the disturbance response data includes simulated abnormal data packets, virtual vulnerability triggering operations, and disguised user operations.
[0063] In this invention, proactive challenge mimicry analysis injects perturbation factors into the network operation and maintenance environment through a dynamic perturbation engine, generating perturbation response data. This induces the manifestation of potential security threats, further identifying and extracting the response characteristics of the network system under abnormal challenge conditions. The core function of the dynamic perturbation engine is to proactively trigger abnormal behaviors or vulnerability responses in the network environment by constructing simulated abnormal scenarios, thereby obtaining the change characteristics of network traffic data, user behavior data, and system log data under specific perturbation conditions. Specifically, the perturbation response data includes three categories: simulated abnormal data packets, virtual vulnerability triggering operations, and disguised user operations.
[0064] Simulated anomalous data packets are sent to the target network system via a dynamic perturbation engine. These packets include abnormal traffic loads, unexpected protocol traffic, and data content that does not conform to normal communication standards. For example, a large number of disguised high-concurrency requests are introduced into network traffic to simulate a DDoS attack scenario. By observing the traffic response, data loss rate, and latency changes of network nodes, response characteristics of the anomalous traffic are extracted. Secondly, virtual vulnerability triggering operations are performed by the dynamic perturbation engine to simulate specific vulnerability triggering mechanisms in the network system or application, inducing the system to exhibit abnormal states when responding to virtual threats. For example, by sending carefully crafted malicious input or simulating file read / write operations to the system, phenomena such as abnormal system resource consumption, incorrect log recording, or process crashes are triggered, thereby capturing vulnerability response characteristics in the system log data. Finally, spoofed user operations are performed by simulating the access behavior and operation paths of real users, introducing abnormal operation sequences or spoofing identities to access the system, in order to verify the abnormal response of the system when handling unexpected user behavior. For example, by simulating multiple users logging in simultaneously, submitting abnormal operation commands, or frequently switching access paths, the system is induced to record abnormal user behavior data, including the number of abnormal accesses, the frequency of operation path jumps, and command error responses.
[0065] The principle of proactive challenge mimicry analysis is to actively apply external disturbances through a dynamic perturbation engine, thereby revealing potential threats hidden in normal data flows and capturing their response characteristics in network traffic, system resources, and user behavior. This process combines dynamic data generation, real-time monitoring, and feature extraction technologies to ensure the efficiency and accuracy of perturbation generation and data capture. Compared to passive monitoring methods, the advantage of proactive challenge mimicry analysis lies in its ability to actively introduce perturbations, trigger potential threats, and discover hidden risks that are difficult to identify using traditional detection methods. Especially when facing unknown threats or zero-day vulnerabilities, it can quickly verify the system's security status and protection capabilities. Furthermore, by simulating various abnormal scenarios (such as DDoS attacks, vulnerability exploitation, and user abuse) and extracting corresponding response data, it provides high-quality input data for subsequent threat feature fusion and modeling, effectively improving the comprehensiveness and accuracy of network operation and maintenance environment risk assessment. Overall, proactive challenge mimicry analysis, through dynamic perturbation, exposes potential risks in network operation and maintenance systems in challenging environments, providing crucial support for generating high-confidence threat response characteristics.
[0066] Example 1: Simulating a DDoS attack scenario. In a network operations and maintenance environment, the dynamic disturbance engine constructs a simulated DDoS attack scenario by sending high-concurrency request traffic to the target network system. These request packets include:
[0067] High-frequency repetitive requests: Simulating the behavior of legitimate users frequently accessing specific services;
[0068] Non-standard protocol data packets: Sending abnormal data packets that do not conform to normal network protocols;
[0069] Large data packet transmission: Simulates large-scale file upload or download operations, consuming network bandwidth.
[0070] During this process, the dynamic perturbation engine monitors the response status of network nodes in real time, including network traffic load, packet loss rate, latency, and resource utilization, thereby extracting abnormal network response characteristics. For example, when traffic exceeds normal thresholds, nodes may exhibit increased response latency, data loss, or excessive system resource load. These abnormal characteristics are captured and used as virtual perturbation response data, which is then further used for fusion analysis with real abnormal data. This method effectively verifies the system's protection capabilities against high-concurrency abnormal traffic and exposes potential network bottlenecks and security vulnerabilities.
[0071] Example 2: Virtual Vulnerability Triggering and System Crash Detection. A dynamic perturbation engine injects specific simulated vulnerability attack operations into the target operation and maintenance system or application to trigger a potential vulnerability response. For example:
[0072] Input validation vulnerability: This vulnerability simulates common SQL injection attacks by submitting specific SQL injection statements to the database.
[0073] Buffer overflow vulnerability: Inputting a data packet of an unexpected length into the system can trigger a buffer overflow.
[0074] Unauthorized file access: Simulates user access to unauthorized directories or files on the system, inducing the system to trigger abnormal warning logs.
[0075] During the execution of the above operations, the dynamic perturbation engine records real-time response data of the system, including system log error records, abnormal CPU and memory usage, process crashes, and file access error information. For example, when a buffer overflow vulnerability is triggered, the system may record continuous error logs, CPU usage may rise rapidly, service may be interrupted, and an abnormal response may be returned. These abnormal characteristics will be extracted as virtual perturbation response data to verify the stability and security of the system under vulnerability exploitation scenarios and to provide data support for vulnerability remediation.
[0076] Example 3: Simulated Abnormal User Behavior Detection. In a network operation and maintenance environment, the dynamic disturbance engine challenges and verifies the security of user behavior by simulating abnormal operations by disguised users. Specifically, this includes:
[0077] Frequent login failures: Simulate a fake user repeatedly attempting to log in to the system, triggering account lockout or security warnings;
[0078] Abnormal path access: Constructing abnormal operation path sequences, such as accessing hidden management backends or unauthorized pages;
[0079] High-frequency instruction execution: Simulates a user executing the same or illegal instructions consecutively within a short period of time.
[0080] In this scenario, the dynamic perturbation engine captures system response data, including the number of failed login attempts, the frequency of operation path jumps, and instruction execution error records. Taking frequent login failures as an example, when an account repeatedly enters the wrong password, the system automatically triggers a security protection mechanism, generating an abnormal access log and recording account status lock information. This data will be extracted as virtual perturbation response data, used for comparison and analysis with normal user operation behavior data, thereby identifying the characteristic patterns of abnormal user operations and improving the ability to detect spoofed users.
[0081] Example 4: Simulation of Anomalies in Multi-Node Resource Occupation. The dynamic disturbance engine verifies the resource scheduling stability of a multi-node system by simulating resource contention operations. For example:
[0082] Sending resource requests to multiple nodes simultaneously, such as for large file transfers or virtual resource allocation;
[0083] Simulate node failure or single-node overload and observe the resource rescheduling process in the system.
[0084] During the simulation, the dynamic perturbation engine records real-time status data of node resources, including resource utilization, task allocation latency, and recovery time of failed nodes. For example, when a node fails in the simulation, the system may reschedule resources to other nodes, but the overall task latency will increase. This resource status data allows for the evaluation of the system's recovery capabilities and load balancing effectiveness under abnormal resource contention scenarios.
[0085] Preferably, when fusing real anomaly feature data and virtual disturbance response data, the feature weights are dynamically adjusted using an adaptive fusion method. The formula for calculating the feature fusion weights is as follows:
[0086]
[0087] Among them, W i T represents the fusion weight of the i-th feature; i represents the baseline weight value of the i-th feature; n represents the number of features.
[0088] In this invention, fusing real anomaly feature data and virtual disturbance response data is a crucial step in achieving high-precision generation of correlated threat features. The core of this approach lies in dynamically adjusting feature weights through an adaptive fusion method, thereby ensuring the effective fusion and quantification of threat features from different data sources. Specifically, real anomaly feature data consists of abnormal behavioral features extracted from actual network operation and maintenance environments through realistic mimicry analysis, including network traffic path deviations, abnormal user operation commands, and system log error records. Virtual disturbance response data, on the other hand, consists of system response features induced under simulated challenge conditions through proactive challenge mimicry analysis, including abnormal traffic loads, abnormal resource utilization, and virtual vulnerability triggering features. These two types of data differ in their sources, characteristics, and importance. To more effectively represent the overall impact of potential threat features, an adaptive fusion method is needed to assign weights and uniformly quantify different features.
[0089] The core principle of the adaptive fusion method lies in dynamically adjusting the fusion weights of each feature based on the baseline weights of the feature data. The formula for calculating the feature fusion weights is as follows:
[0090] In the specific implementation process, the first step is to perform a unified dimensional mapping on the real anomaly feature data and the virtual disturbance response data to ensure the comparability of feature data from different sources in terms of dimensions and scale. Then, an adaptive fusion algorithm is used to assign weight benchmark values T to each feature. iCalculations are performed; for example, for abnormal path characteristics in network traffic, their weight baseline value can be determined based on the frequency of abnormal traffic occurrence or traffic deviation value; for virtual vulnerability trigger characteristics in system log data, different weights can be assigned based on the severity level of error logs or the number of fault triggers. Finally, the fusion weight W of each feature is dynamically calculated using the above formula. i The real anomaly features and virtual disturbance response features are then weighted and fused according to their respective weight ratios to generate associated threat feature data.
[0091] By dynamically adjusting the weights in the adaptive fusion method, the importance of feature data can be adaptively allocated, enhancing the ability to express key threat features while reducing the interference of secondary features on the overall analysis results. For example, in a certain network environment, traffic deviations in real anomaly feature data are significant, while resource utilization anomalies in virtual disturbance response data are also prominent. The adaptive fusion method dynamically assigns higher fusion weights based on the weight baseline values of these two types of features, thereby ensuring that the two types of key features dominate the final fusion result.
[0092] The effect of this fusion process is that it organically combines anomaly features from the real environment with disturbance response features under simulated challenges, forming more representative and comprehensive related threat feature data, providing high-quality input for subsequent risk assessment and response strategy generation. Compared to traditional simple feature weighting methods, the adaptive fusion method of this invention, by dynamically adjusting feature weights, has stronger adaptability and accuracy. It can optimize weights in real time according to the importance of different features, improving the expressive power and credibility of the fused data in threat identification and modeling. Simultaneously, through the quantitative calculation of feature weights, the system can more accurately capture the main feature sources of potential risks, significantly improving the accuracy and efficiency of network operation and maintenance environment risk assessment.
[0093] Based on the associated threat feature data, a heterogeneous twin model is constructed to perform state modeling, threat modeling and resource modeling, and risk assessment data is generated through data fusion and risk quantification assessment algorithms.
[0094] Based on the aforementioned associated threat characteristic data, this invention constructs a heterogeneous twin model to achieve state modeling, threat modeling, and resource modeling of the network operation and maintenance environment. It then generates risk assessment data through data fusion and risk quantification algorithms to comprehensively evaluate the system's current risk status and potential threat characteristics. The core function of the heterogeneous twin model in this invention is to reproduce the actual operating state of the network operation and maintenance environment through a virtual-real combined modeling approach, establishing a multi-dimensional characteristic representation of the network environment, thereby achieving comprehensive modeling and analysis of system state, threat propagation paths, and resource scheduling.
[0095] State modeling primarily involves generating node state mapping data by real-time quantification of the health status, traffic load, and system resource utilization of network nodes. In practice, the system dynamically monitors network traffic data and node performance parameters (such as response time, packet loss rate, and load rate), using historical normal state data as a benchmark to quantify the health of network nodes. For example, when a node's load rate exceeds a set threshold or its packet loss rate increases significantly, the state modeling module marks the node as being in an abnormal state and generates state risk characteristic data.
[0096] Threat modeling analyzes the propagation paths and impact range of threats in a network operations environment by correlating threat characteristic data. By correlating anomalous features (such as traffic deviation paths, abnormal user operations, and system fault logs), the system employs a graph-based modeling approach to describe threat propagation paths, specifically including the threat impact relationships between nodes and the calculation of propagation costs. For example, by calculating the length and cost of the risk propagation path from an anomalous node to other nodes, high-risk propagation links are identified, thereby determining the scope of threat impact and key nodes. This modeling approach can clearly depict the propagation process of potential threats in the network, providing path-level quantitative threat data for risk assessment.
[0097] Resource modeling primarily focuses on the distribution of system resources (including computing resources, storage resources, and network bandwidth), quantifying resource load status and adaptability. By monitoring resource utilization, task allocation status, and inter-node resource scheduling, it generates resource adaptability characteristic data. For example, when a node's resource utilization reaches saturation, the resource modeling module marks the node's resource risk and analyzes the potential impact of uneven resource allocation on network operation and maintenance, thus providing foundational data support for subsequent optimized scheduling.
[0098] After completing state modeling, threat modeling, and resource modeling, the system uses data fusion and risk quantification assessment algorithms to integrate and analyze the modeling data, ultimately generating risk assessment data. Data fusion employs a cross-layer correlation mapping method to uniformly quantify state data, threat path data, and resource distribution data, ensuring comparability and consistency of data from different sources in risk assessment. The risk quantification assessment algorithm uses a multi-objective weighted calculation method to quantify and assess the overall risk level of the system. For example, it weights the node health from the state modeling results, the propagation path risk from the threat modeling results, and the resource load risk from the resource modeling results, combining these weights to generate the final risk assessment data, used to measure the system's current risk status and potential security vulnerabilities.
[0099] By constructing a heterogeneous twin model, this invention achieves virtual-real mapping and dynamic modeling of the network operation and maintenance environment. It comprehensively captures multidimensional characteristics of the system in terms of abnormal states, threat propagation, and resource scheduling, generating high-precision risk assessment data. Compared with traditional single-dimensional risk assessment methods, the heterogeneous twin model possesses stronger expressive power and adaptability. It can discover potential risks through multidimensional data fusion and dynamic modeling, and provide key decision-making basis for the subsequent generation of optimal response strategies, greatly improving the accuracy, comprehensiveness, and executability of network operation and maintenance environment risk assessment.
[0100] Preferably, the heterogeneous twin model includes state modeling, threat modeling, and resource modeling, wherein state modeling generates node state mapping data through network node health parameters, threat modeling generates threat propagation paths based on associated threat feature data, and resource modeling generates node resource adaptation state data based on resource load distribution.
[0101] In this invention, the heterogeneous twin model achieves comprehensive risk assessment of the network operation and maintenance environment through three core modules: state modeling, threat modeling, and resource modeling. The principle of the heterogeneous twin model is to construct a virtual mirror of the network operation and maintenance system, dynamically modeling and mapping the state parameters, threat characteristics, and resource distribution in the real network environment. This forms a multi-dimensional mapping and correlation analysis of the network operation and maintenance environment, providing data support and decision-making basis for risk assessment and optimization. The following details the principles and applications of each modeling module from the perspective of specific implementation and effects, and illustrates its actual operation process with examples.
[0102] State modeling generates node state mapping data based on network node health parameters. Its main function is to quantify the health status of network nodes in real time and identify abnormal situations during node operation. Node health parameters include metrics such as network node load rate, packet loss rate, response time, and CPU utilization. In implementation, the system collects and analyzes real-time performance data for each network node, comparing the collected node parameters with health thresholds to generate node health indicators. For example, if a node's load rate consistently exceeds 90% or its packet loss rate is significantly higher than a preset threshold, the node is marked as "high-risk." Through state modeling, the system generates node state mapping data, including the health status, anomaly markers, and operational trends of each node, used to identify critical risk nodes and provide foundational data for subsequent threat and resource modeling.
[0103] Threat modeling generates threat propagation paths based on associated threat characteristic data, focusing on analyzing the propagation process and impact range of potential threats within a network. Using a graph-based modeling approach, network nodes are treated as vertices, and communication relationships between nodes as edges. This is combined with associated threat characteristic data (such as abnormal traffic paths, user operation deviations, and system log fault records) to generate threat propagation paths. For example, upon detecting abnormal traffic deviations at a node, the system analyzes its communication paths with other nodes, calculates the cost and path length of threat propagation, identifies other potentially affected nodes, and generates a threat propagation graph. During this process, the threat propagation paths are dynamically updated; for instance, when a threat node switches communication paths, the system adjusts the threat propagation graph in real time to ensure the accuracy of risk analysis. The results of threat modeling include propagation paths, a list of affected nodes, and propagation intensity data, providing support for subsequent risk quantification assessments and the generation of optimal response strategies.
[0104] Resource modeling generates node resource adaptation status data based on resource load distribution. Its main function is to quantify the resource allocation and load status of each node in the network operation and maintenance system, and to analyze the adaptability and risks of resource distribution. Resource modeling generates a resource load distribution map by real-time monitoring of each node's computing resources (CPU, memory usage), storage resources, and network bandwidth usage. For example, if a node's CPU utilization is close to 100%, while neighboring nodes have lower resource utilization, the resource modeling module will mark the current resource distribution as "unbalanced" and generate node resource adaptability data, including resource utilization, load balancing coefficients, and resource anomaly markers. This data is used to analyze the system's resource scheduling efficiency and adaptability, identify potential resource bottlenecks and overload risks, and provide data support for resource scheduling optimization.
[0105] Example: In a distributed network operation and maintenance environment, the system comprehensively analyzes the network's risk status through state modeling, threat modeling, and resource modeling. During state modeling, the system monitors the health parameters of nodes A, B, and C in real time. It detects that node A's load rate reaches 95% and its packet loss rate is 8%, significantly exceeding normal thresholds, thus marking node A as a high-risk node. During threat modeling, the system further analyzes the communication paths between node A and other nodes, discovering that node A is sending abnormal traffic to node B, and node B is experiencing response delays. Through threat propagation path modeling, the system calculates the length and cost of the threat propagation path from node A to node C, determining that node C may also be affected. During resource modeling, the system analyzes the resource load distribution of nodes A, B, and C, finding that node A's resource load is too high, while nodes B and C have low resource utilization. The system marks the current resource distribution as unbalanced and generates node resource adaptation status data.
[0106] State modeling identifies high-risk states for node A, threat modeling dynamically generates threat propagation paths from node A to node C, and resource modeling analyzes the resource load issues of node A. Finally, comprehensive risk assessment data for nodes A, B, and C is generated, including node health status, threat propagation paths, and resource load adaptability. This assessment data provides decision support for generating optimal response strategies, such as reducing traffic pressure on node A through traffic control or allocating tasks to nodes B and C through resource scheduling, thereby effectively reducing the overall system risk.
[0107] Preferably, risk assessment data, including risk level, impact range and quantitative score, is generated by fusing state modeling data, threat modeling data and resource modeling data through a cross-layer correlation mapping model.
[0108] In this invention, the fusion of state modeling data, threat modeling data, and resource modeling data through a cross-layer correlation mapping model is a key step in achieving network operation and maintenance environment risk assessment. Its core lies in performing unified correlation analysis and quantitative evaluation of modeling data from different dimensions, thereby generating risk assessment data including risk level, impact scope, and quantitative score. The design of the cross-layer correlation mapping model overcomes the limitations of single-source data analysis, achieving comprehensiveness and accuracy in risk assessment through multi-dimensional data fusion, and providing comprehensive risk situation awareness and decision support for network operation and maintenance systems.
[0109] In its implementation, the cross-layer association mapping model uses data fusion and quantitative evaluation algorithms to process the modeling data. First, state modeling data provides health status information for network nodes, including parameters such as node load rate, response time, and packet loss rate. Threat modeling data describes threat propagation paths and their impact range, including abnormal nodes, propagation links, and risk propagation intensity. Resource modeling data reflects the resource load and adaptability of each node, including resource utilization, task allocation, and resource scheduling status. These three types of data undergo unified data dimension standardization in the cross-layer association mapping model to ensure consistency in scale and dimensions across different data sources.
[0110] The core principle of the cross-layer association mapping model is to achieve unified data analysis through cross-dimensional feature association and weight fusion. First, based on the association mapping mechanism, the system correlates abnormal node information in state modeling data with propagation paths in threat modeling data to determine the key role of abnormal state nodes in the threat propagation chain. Simultaneously, combined with resource modeling data, it analyzes the impact of the resource load of abnormal nodes on the overall system stability. For example, if a high-risk node (state modeling) is located on an important communication link (threat modeling) and its resources are nearing saturation (resource modeling), the system will mark this node as a high-priority risk node. During this process, the cross-layer association mapping model dynamically allocates weights to data from each dimension, adjusting the weight parameters according to the actual impact of risk factors, ultimately generating risk assessment data, including risk level, impact range, and quantitative score.
[0111] Risk levels are calculated using a quantitative assessment algorithm, comprehensively considering multiple indicators such as node status, threat propagation intensity, and resource load adaptability. For example, by weighting node health scores, threat propagation path lengths, and resource load scores, an overall risk level score is determined, thus classifying the system into risk levels (e.g., high, medium, and low). The impact range is determined by the threat propagation path modeling results, describing the number of network nodes and propagation links that the risk may affect, ensuring the system can intuitively identify the scope of risk propagation. The quantitative score provides a numerical output of the risk level, offering a quantifiable risk measurement standard for subsequent risk response and optimization.
[0112] In an example, in a complex network operation and maintenance environment, the system first detects abnormal health parameters of nodes A, B, and C through state modeling. Node A's load rate exceeds 95%, node B's response time continues to increase, and node C's data packet loss rate significantly increases. Next, the threat modeling module analyzes and discovers an abnormal traffic propagation path between nodes A and B, further determining that node B propagates abnormal traffic to node C, forming a threat propagation link. Simultaneously, the resource modeling module detects that node A's resource utilization is close to saturation, while the resource scheduling of nodes B and C is unbalanced. Through a cross-layer correlation mapping model, the system performs correlation analysis between node state anomalies, threat propagation paths, and resource load distribution, dynamically adjusting the weights of each data dimension to generate the following risk assessment data: Node A is marked as a "high-risk node," its influence scope includes nodes B and C, and the propagation path weight accounts for 60% of the overall risk score; the overall network operation and maintenance environment risk level is assessed as "high risk," with a risk quantification score of 87 points (risk score ranges from 0-100, with higher scores indicating greater risk).
[0113] Through the above embodiments, the cross-layer correlation mapping model plays a core role in multi-dimensional data fusion and correlation analysis, successfully identifying risk source nodes, propagation paths, and resource load status, and quantifying the overall risk level and impact scope. Compared with traditional single-dimensional risk assessment methods, this invention achieves dynamic correlation and quantitative assessment of three types of data—status, threat, and resources—through the cross-layer correlation mapping model, possessing higher accuracy and comprehensiveness. It can provide intuitive and quantitative risk assessment results for network operation and maintenance environments, supporting the formulation of subsequent risk response and optimization control strategies.
[0114] like Figure 2 As shown, based on the risk assessment data, an optimal response strategy is generated through a multi-objective optimization algorithm. The optimal response strategy includes flow control, node isolation, and resource scheduling. The optimal response strategy is then executed, and strategy execution feedback data is collected. The feedback data is then transmitted back to the heterogeneous twin model for risk status update and optimization through a feedback control mechanism.
[0115] like Figure 3 As shown, the core of the multi-objective optimization algorithm lies in weighing and solving multiple evaluation metrics to ensure that the generated response strategy achieves an optimal balance among different objectives. Specifically, the input data is the risk assessment results, including risk level, threat propagation path, node status, and resource load. By analyzing this risk assessment data, the system identifies key objectives that need optimization, such as node load balancing, threat isolation priority, and traffic control paths. The multi-objective optimization algorithm calculates the optimal solution by establishing an objective function and combining constraints with network resource allocation rules.
[0116] Flow control alleviates the pressure on high-load nodes and prevents network congestion and performance degradation by adjusting the transmission paths and traffic distribution of network packets. Specific implementation methods include replanning traffic forwarding paths based on abnormal traffic path information in risk assessment data, prioritizing the redirection of abnormal traffic to low-load nodes, or rate limiting non-critical data flows. For example, when high-risk traffic is detected at a node, the system will dynamically modify the routing table and replan the traffic path to reduce the load on that node.
[0117] Node isolation temporarily removes high-risk nodes from the network through physical or logical isolation to block further threat propagation. Based on risk assessment data of threat propagation paths, the system identifies key nodes in the threat propagation process and implements isolation strategies. For example, it may block the node's external communication through firewall rules or logically separate the node from the main network using virtualization technology, ensuring it no longer affects other normal nodes. For instance, if a node is detected continuously propagating abnormal data packets, the system will generate a node isolation policy, temporarily shutting down the node's network interface or transferring it to an isolation zone for troubleshooting.
[0118] Resource scheduling aims to optimize the allocation of computing and storage resources among network nodes, resolve resource load imbalances, and improve the overall system efficiency. Based on the resource load distribution in the resource modeling data, the system identifies overloaded nodes and dynamically migrates some tasks to nodes with idle resources. For example, the system uses virtual machine migration technology to schedule some computing tasks from node A to nodes B and C with lower loads, thereby achieving resource load balancing and improving the system's adaptability and stability.
[0119] After executing the optimal response strategy, the system dynamically evaluates the strategy's effectiveness by monitoring feedback data in real time. This feedback data is then fed back to the heterogeneous twin model for updating and optimizing the risk status. The feedback control mechanism includes real-time monitoring of traffic status, node isolation effectiveness, and resource load changes. For example, it detects whether network congestion is alleviated after traffic redirection, whether threat propagation is blocked after node isolation, and whether system load is balanced after resource scheduling. This feedback data is then passed back to the system as optimization parameters to further adjust the optimization strategy, forming an adaptive dynamic risk response closed loop. For instance, if the system detects that node load remains high after executing a resource scheduling strategy, it will call back the optimization model, readjust task migration paths, and further balance resource allocation.
[0120] Example: In a network operations environment, the system detects that node A is under high load, and there is a threat of abnormal traffic propagating to nodes B and C. Based on risk assessment data, the system generates the following optimal response strategy using a multi-objective optimization algorithm:
[0121] Flow control: Re-plan the traffic path of node A, forward non-critical data flows to node D, and reduce the load on node A;
[0122] Node isolation: Temporarily isolate node A from the external network to prevent the further propagation of abnormal traffic;
[0123] Resource scheduling: Dynamically migrate computing tasks on node A to nodes B and C with idle resources to achieve load balancing.
[0124] After the strategy was executed, the system monitored the traffic status and task load distribution of node A through a feedback control mechanism. It found that the load rate of node A dropped significantly, abnormal traffic propagation stopped, and the overall load balance of the system improved by 15% after resource scheduling. The feedback data was sent back to the heterogeneous twin model to update the risk status of node A, and the threat propagation path and resource allocation scheme were further optimized and adjusted.
[0125] Preferred, such as Figure 4As shown, the risk quantification assessment uses a risk quantification assessment algorithm to quantify and analyze state modeling data, threat modeling data, and resource modeling data to calculate the risk level. The risk level R is determined by the following formula:
[0126] R = α·S + β·W + γ·L
[0127] Where R represents the risk level; S represents the risk score of the state modeling data; W represents the risk score of the threat modeling data; L represents the risk score of the resource modeling data; and α, β, and γ are the weighting coefficients for risk assessment.
[0128] State modeling data S provides a risk score for the health status of network nodes, including a comprehensive score of indicators such as node load rate, data packet loss rate, and response time, reflecting the operational health of the nodes. Threat modeling data W represents the risk score for threat propagation paths, quantifying the degree of propagation and scope of potential threats in the network, including indicators such as the number of threat nodes, propagation link length, and propagation intensity. Resource modeling data L represents the risk score for resource load distribution, measuring the utilization efficiency and imbalance of computing resources, storage resources, and network bandwidth in the system. The risk quantification assessment algorithm weighted and fused these three types of risk scores to obtain the overall risk level R.
[0129] The implementation of risk quantification assessment first requires preprocessing the data from state modeling, threat modeling, and resource modeling. This involves normalizing the indicator values of each data type to a unified dimensional range, typically using linear normalization to ensure comparability of data from different sources in the risk assessment. Then, the system calculates a weighted average of the risk scores for the three types of data based on risk weighting coefficients α, β, and γ to obtain the overall system risk level R. For example, when S = 0.8 (poor node health), W = 0.7 (widespread threat propagation), and L = 0.5 (moderate resource load), and the system sets the weighting coefficients to α = 0.5, β = 0.3, and γ = 0.2, the following formula can be used to calculate:
[0130] R=0.5·0.8+0.3·0.7+0.2·0.5=0.71
[0131] The system converts the risk level RRR into a visual risk level category, for example: R>0.8 is high risk, 0.5≤R≤0.8 is medium risk, and R<0.5 is low risk.
[0132] Example: In a complex network operation and maintenance environment, the system detects abnormal health statuses of nodes A, B, and C through state modeling. Node A has a load rate as high as 95%, node B has a packet loss rate of 7%, and node C has a response time of 200ms, with a state risk score S = 0.8. The threat modeling module analyzes that abnormal traffic is propagating from node A to node B, forming a high-cost threat path, with a threat risk score W = 0.75. The resource modeling module monitors that node A's resource utilization is close to saturation, while the resource distribution of nodes B and C is uneven, with a resource risk score L = 0.6. The system combines weighting coefficients α = 0.4, β = 0.4, and γ = 0.2 to calculate the overall risk level using a risk quantification assessment algorithm.
[0133] R=0.4·0.8+0.4·0.75+0.2·0.6=0.74
[0134] Based on the calculation results, the system assesses the current network operation and maintenance environment as "medium risk" and further analyzes that node A is the main source of risk. The threat propagation path from node A to node B has a high risk intensity, and the uneven distribution of resources is an important factor affecting the overall risk.
[0135] Through a risk quantification assessment algorithm, this invention achieves quantitative fusion analysis of state modeling, threat modeling, and resource modeling data. It can dynamically and accurately calculate the overall risk level of the system, clarify the main sources and scope of impact of risks, and provide a quantitative basis for risk assessment of the network operation and maintenance environment. Compared with traditional risk assessment methods, this invention, through multi-dimensional data fusion and dynamic weight adjustment, possesses higher accuracy and flexibility. It can dynamically optimize risk indicators according to the actual system state, ensuring a high degree of match between risk assessment results and the actual system state. Simultaneously, through risk level quantification and visual classification, the system can intuitively display the risk situation to operation and maintenance personnel, providing decision support for the generation of subsequent optimal response strategies, and significantly improving the security protection capabilities and risk management level of the network operation and maintenance environment.
[0136] Preferably, the risk assessment results and execution feedback data are fed back to the heterogeneous twin model through a feedback control mechanism to dynamically update the network node status, threat propagation path and resource load distribution, thereby optimizing the risk quantification assessment results.
[0137] The core principle of the feedback control mechanism lies in the real-time collection and analysis of execution feedback data to quantitatively evaluate the current system state and the effectiveness of the execution strategy, and then transmitting the updated data back to the heterogeneous twin model to achieve dynamic iterative updates of the model state. Specifically, after executing the optimal response strategy, the system monitors changes in network node status, threat propagation paths, and resource load distribution in real time. By collecting node health parameters (such as load rate, response time, and data packet loss rate), threat propagation links (such as propagation path length and propagation cost), and resource utilization status (such as CPU utilization and storage utilization), execution feedback data is generated.
[0138] These feedback data are transmitted back to the heterogeneous twin model through a feedback control mechanism, which is used to dynamically update the three types of modeling of the network operation and maintenance environment:
[0139] Dynamic updates to network node status: Based on node health parameters in the feedback data, the operating status of each node is reassessed, and the status modeling data is updated. For example, if the load rate of a node drops significantly after implementing a traffic control strategy, the system will mark the node as "recovered to normal" and update the node health status mapping data.
[0140] Dynamic updates to threat propagation paths: Threat propagation paths are dynamically adjusted based on changes in the threat propagation chain in the feedback data. For example, after isolating a high-risk node, if the system detects that an abnormal traffic path has been successfully blocked, the threat propagation path will be recalculated and updated to ensure that the impact range of the current threat is accurately quantified.
[0141] Dynamic updates to resource load distribution: Based on resource utilization data from feedback, the system updates resource modeling data in real time to reflect the latest resource allocation status of each node. For example, if task migration is successful after the resource scheduling strategy is executed and the node resource load tends to be balanced, the system will record the change in resource utilization of that node and update the resource load distribution mapping.
[0142] Through the aforementioned dynamic updates, the system can recalculate the risk quantification assessment results, generate more accurate risk levels and impact ranges, and provide updated data support for the next round of optimization strategies.
[0143] Example: In a network operation and maintenance environment, based on the risk quantification assessment results, the system executed the optimal response strategy: traffic redirection for node A, logical isolation for node B, and task load scheduling from node C to node D. After executing the strategy, the system monitored the status of each node in real time through a feedback control mechanism and detected the following changes:
[0144] The load rate of node A dropped from 95% to 70%, and the packet loss rate returned to the normal range;
[0145] After node B was isolated, the system detected that the threat propagation path terminated at node B, and the abnormal traffic stopped propagating to other nodes;
[0146] The computing tasks of node C were successfully migrated to node D. The CPU utilization of node C dropped from 90% to 50%, and the resource allocation became more balanced.
[0147] The system sends the aforementioned execution feedback data back to the heterogeneous twin model to dynamically update the state modeling, threat modeling, and resource modeling.
[0148] In the state modeling data, the health status of node A is updated to "restored to normal", node B is marked as "isolated state", and the resource utilization status of node C is remarked as "load balanced".
[0149] In the threat modeling data, the original propagation path has been adjusted to a terminated state, and the system records that the scope of threat impact has been reduced to isolated node B;
[0150] In the resource modeling data, the resource load status of nodes C and D is reassessed to form the latest resource allocation mapping.
[0151] Based on the updated modeling data, the system re-evaluates the risk quantification and calculates a new risk level using a risk quantification algorithm. Due to the effective execution of traffic control, node isolation, and resource scheduling, the overall risk level has decreased from "high risk" to "medium risk," and the risk score has dropped from 0.85 to 0.6.
[0152] like Figure 5 As shown, a system for implementing the network operation and maintenance environment risk assessment method based on mimicry security technology includes:
[0153] The data acquisition and preprocessing module is used to collect and preprocess data from the network operation and maintenance environment. It performs deduplication, time alignment, and standardization on the data to generate standardized security data. This module collects network traffic data, user behavior data, and system log data from the network operation and maintenance environment, and generates standardized security data through deduplication, time alignment, and standardization. Here, a hash deduplication algorithm is used to remove duplicate data, a timestamp synchronization mechanism is used to achieve data time alignment, and a standardization algorithm unifies the data format, providing high-quality input for subsequent analysis.
[0154] The mimicry analysis module, based on the standardized security data, extracts real anomaly feature data and virtual disturbance response data through realistic mimicry analysis and proactive challenge mimicry analysis, respectively. It then fuses the real anomaly feature data and virtual disturbance response data to generate associated threat feature data. Based on the standardized security data, the module extracts two types of data: real anomaly feature data and virtual disturbance response data through realistic mimicry analysis and proactive challenge mimicry analysis. Real mimicry analysis identifies anomaly features using a deep behavior matching algorithm, while proactive challenge mimicry analysis generates simulated anomaly data packets and virtual vulnerability trigger responses using a dynamic disturbance engine. The two types of data are fused to generate associated threat feature data, achieving multi-dimensional feature extraction and correlation analysis of threats.
[0155] The heterogeneous twin modeling module is used to construct a heterogeneous twin model based on the associated threat feature data, performing state modeling, threat modeling, and resource modeling, and generating risk assessment data through data fusion and risk quantification assessment algorithms. This module constructs a heterogeneous twin model based on the associated threat feature data, performing state modeling (network node health status), threat modeling (threat propagation paths), and resource modeling (node resource distribution). Through data fusion and risk quantification assessment algorithms, the module outputs risk assessment data, including risk level, impact range, and quantitative score, providing the system with accurate risk assessment results.
[0156] The optimal response strategy generation module is used to generate an optimal response strategy based on the risk assessment data using a multi-objective optimization algorithm. The optimal response strategy includes flow control, node isolation, and resource scheduling. Based on the risk assessment data, the module uses a multi-objective optimization algorithm to weigh system performance objectives and generate an optimal response strategy that includes flow control, node isolation, and resource scheduling, thereby ensuring the restoration and stable operation of network security.
[0157] The strategy execution and feedback control module is used to execute the optimal response strategy, collect strategy execution feedback data, and transmit the feedback data back to the heterogeneous twin model through a feedback control mechanism to dynamically update the risk status. After executing the optimal response strategy, the system collects strategy execution feedback data and transmits it back to the heterogeneous twin model through the feedback control mechanism to dynamically update the network node status, threat propagation paths, and resource load distribution, thereby achieving adaptive iterative optimization of the model and improving the real-time performance and accuracy of risk assessment.
[0158] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A network operation and maintenance environment risk assessment method based on mimicry security technology, characterized in that, Includes the following steps: Data is collected and preprocessed in the network operation and maintenance environment, and the collected data is deduplicated, time-aligned and standardized to generate standardized security data. Based on the standardized security data, real anomaly feature data and virtual disturbance response data are extracted through real mimicry analysis and active challenge mimicry analysis, respectively. The real anomaly feature data and virtual disturbance response data are then fused to generate associated threat feature data. The realistic mimicry analysis extracts abnormal features from network traffic data, user behavior data, and system log data using a deep behavior matching algorithm. The deviation value of these abnormal features is calculated using the following formula: in, Indicates abnormal deviation values; Indicates the first The actual value of each data point; This represents a reference value in the normal behavior template; Indicates the number of data points; The proactive challenge mimicry analysis generates disturbance response data through a dynamic disturbance engine. The disturbance response data includes simulated abnormal data packets, virtual vulnerability triggering operations, and disguised user operations. The real-world mimicry analysis identifies anomalous features that deviate significantly from normal behavior by performing deep behavioral matching and feature analysis on standardized security data in the network operation and maintenance environment. It extracts abnormal access paths by performing path analysis on network traffic data, extracts abnormal command sequences by comparing user behavior data with operation sequences, and identifies frequently occurring fault logs by detecting errors in system log data. The extraction of deviation features is based on the matching deviation between the normal behavior template and the currently observed data. This real-world anomalous feature data reflects abnormal situations in the actual operation and maintenance environment. The network traffic data is analyzed by examining the data packet transmission path, traffic intensity, and access timing; the user behavior data is analyzed by examining the user's operation commands, login frequency, and access path; and the system log data is analyzed by extracting fault information and error records from the logs and comparing them with normal behavior templates to identify feature points that deviate from the normal state. The deep behavior matching algorithm quantifies the degree of anomaly by calculating the deviation between observed data and normal template data; it quantifies the overall deviation between the current data and the normal behavior pattern by calculating the difference between each item of observed data and normal template data, and accumulating the absolute values; when the deviation value... If the data exceeds a preset threshold, it is determined that the data has abnormal characteristics and further threat analysis is performed. The deep behavior matching algorithm constructs normal behavior templates in different scenarios and performs comprehensive feature comparison of network traffic, user behavior and system log data. Based on the associated threat feature data, a heterogeneous twin model is constructed, and state modeling, threat modeling, and resource modeling are performed on the heterogeneous twin model to obtain state modeling data, threat modeling data, and resource modeling data. The state modeling data, threat modeling data, and resource modeling data are then fused, and risk assessment data is generated through a risk quantification assessment algorithm. Based on the risk assessment data, an optimal response strategy is generated through a multi-objective optimization algorithm. The optimal response strategy includes flow control, node isolation, and resource scheduling. The optimal response strategy is then executed, and strategy execution feedback data is collected. The feedback data is then transmitted back to the heterogeneous twin model for risk status update and optimization through a feedback control mechanism.
2. The network operation and maintenance environment risk assessment method based on mimicry security technology according to claim 1, characterized in that, The data in the network operation and maintenance environment includes network traffic data, user behavior data, and system log data. When deduplicating the collected data, the data identification information is compared based on the hash deduplication algorithm to remove duplicate data. When aligning the collected data by time, the data source is aligned based on a timestamp synchronization mechanism, and the deduplicated and time-aligned data is converted into standardized and secure data in a unified format using a standardization algorithm.
3. The network operation and maintenance environment risk assessment method based on mimicry security technology according to claim 1, characterized in that, When fusing real anomaly feature data and virtual disturbance response data, the feature weights are dynamically adjusted using an adaptive fusion method. The formula for calculating the feature fusion weights is as follows: in, Indicates the first The fusion weights of the features; Indicates the first The baseline weight values for each feature; Indicates the number of features.
4. The network operation and maintenance environment risk assessment method based on mimicry security technology according to claim 1, characterized in that, The heterogeneous twin model includes state modeling, threat modeling, and resource modeling. State modeling generates node state mapping data through network node health parameters, threat modeling generates threat propagation paths based on associated threat feature data, and resource modeling generates node resource adaptation state data based on resource load distribution.
5. The network operation and maintenance environment risk assessment method based on mimicry security technology according to claim 1, characterized in that, The risk quantification assessment uses a risk quantification assessment algorithm to quantify and analyze state modeling data, threat modeling data, and resource modeling data to calculate the risk level. Determined by the following formula: in, Indicates the risk level; This represents the risk score of the state modeling data; This represents a risk score based on threat modeling data; This represents the risk score of the resource modeling data; These are the weighting coefficients for risk assessment.
6. The network operation and maintenance environment risk assessment method based on mimicry security technology according to claim 5, characterized in that, The risk assessment results and execution feedback data are fed back to the heterogeneous twin model through a feedback control mechanism to dynamically update the network node status, threat propagation path and resource load distribution, thereby optimizing the risk quantification assessment results.
7. A system for implementing the network operation and maintenance environment risk assessment method based on mimicry security technology as described in any one of claims 1-6, characterized in that, include: The data acquisition and preprocessing module is used to acquire and preprocess data in the network operation and maintenance environment, and to perform deduplication, time alignment and standardization on the data to generate standardized security data. The mimicry analysis module is used to extract real anomaly feature data and virtual disturbance response data based on the standardized security data through real mimicry analysis and active challenge mimicry analysis, respectively, and to fuse the real anomaly feature data and virtual disturbance response data to generate associated threat feature data. The heterogeneous twin modeling module is used to construct a heterogeneous twin model based on the associated threat feature data, perform state modeling, threat modeling and resource modeling, and generate risk assessment data through data fusion and risk quantification assessment algorithms; The optimal response strategy generation module is used to generate an optimal response strategy based on the risk assessment data using a multi-objective optimization algorithm. The optimal response strategy includes flow control, node isolation, and resource scheduling. The strategy execution and feedback control module is used to execute the optimal response strategy, collect strategy execution feedback data, and transmit the feedback data back to the heterogeneous twin model through the feedback control mechanism to dynamically update the risk status.
Citation Information
Patent Citations
A network operation and maintenance environment assessment system based on mimic security technology
CN117834305B
Multi-dimensional network security operation and maintenance protection management system and method
CN117240594A
Cloud-based, scalable, advanced analytics platform for analyzing complex medical risk data and providing dedicated electronic trigger signals for triggering risk-related activities in the context of medical risk-transfer, and method thereof
US20230386655A1