Network security compliance intelligent protection system for enterprise multi-source data fusion

By designing an intelligent network security compliance protection system for enterprise multi-source data fusion, and using technologies such as SIEM, XDR and LSTM, the problem of insufficient data integration and analysis accuracy in the existing technology is solved, intelligent and automated network protection is achieved, and security compliance and defense capabilities are improved.

CN119966735APending Publication Date: 2025-05-09WUXI INFINITY ZHIAN TECHNOLOGY CO LTD
View PDF 0 Cites 11 Cited by

Patent Information

Application Number
CN202510150261.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-09

Smart Images

  • Figure CN119966735A_ABST
    Figure CN119966735A_ABST
Patent Text Reader

Abstract

The invention discloses a network security compliance intelligent protection system for enterprise multi-source data fusion, and relates to the technical field of network security, a data acquisition module uniformly collects and preprocesses enterprise internal multi-source security data, a data fusion module establishes a threat situation perception model through association analysis, and the security detection precision is improved; the threat detection module carries out threat modeling and calculates threat levels in real time based on SIEM and XDR, the compliance evaluation module further carries out regulation review on security events, the security response module carries out automatic security policy execution in combination with SOAR, and the control optimization module carries out real-time verification on all executed security response measures through a secondary verification mechanism. And based on feedback dynamic optimization SIEM, XDR and SOAR, false alarms are reduced, the intelligent decision-making capability is enhanced, the accuracy, compliance and controllability of system security protection are ensured, and the overall network security toughness of an enterprise is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security compliance intelligent protection system for enterprise multi-source data fusion. Background Art

[0002] Intelligent protection of network security compliance based on multi-source data fusion of enterprises refers to intelligent protection technology that uses multiple data sources (such as logs, traffic, user behavior, threat intelligence, etc.) for comprehensive analysis to ensure enterprise network security and compliance requirements. This system usually relies on artificial intelligence, big data analysis and automated security strategies to monitor and detect enterprise network security risks in real time while complying with various industry standards. Its core goal is to improve threat perception capabilities through intelligent means, automatically respond to network attacks, and reduce the security management burden of enterprises.

[0003] At present, network security protection with multi-source data fusion mainly relies on technologies such as SIEM (Security Information and Event Management) system, XDR (Extended Detection and Response), Zero Trust Architecture, and SOAR (Security Orchestration Automation and Response). These technologies can collect and integrate information from different data sources such as terminals, cloud environments, and business systems, and use machine learning and behavioral analysis methods to detect abnormal activities. For example, SIEM can analyze log data in real time, XDR can realize threat detection at the endpoint and network level, and SOAR can automate the execution of security policies and response processes. The challenges of existing technologies mainly lie in how to efficiently integrate heterogeneous data, improve the accuracy of data analysis, and achieve intelligent and automated network protection while meeting compliance requirements.

[0004] The prior art has the following deficiencies:

[0005] As devices such as industrial control systems (ICS) and the Internet of Things (IoT) are connected to enterprise networks, SOAR may be used to automate security responses that are not limited to the IT field, such as shutting down servers, power systems, access control systems, etc. If SOAR triggers a response in the physical world due to a false alarm or an attacker's manipulation error, it may cause a large-scale power grid trip. For example, an attacker can forge an intrusion alarm to trigger SOAR to shut down power or industrial control equipment, paralyzing factory production. In addition, if SOAR is frequently mistriggered or manipulated by attackers, the company's security team may lose trust in the intelligent protection system, ultimately causing the overall security strategy to fail. For example, if SOAR repeatedly shuts down critical systems, the security team may be forced to intervene manually or even completely disable automated security responses, making the company lose the ability to respond quickly to attacks. Summary of the invention

[0006] The purpose of the present invention is to provide a network security compliance intelligent protection system for enterprise multi-source data fusion to address the shortcomings of the background technology.

[0007] In order to achieve the above-mentioned object, the present invention provides the following technical solutions: an enterprise multi-source data fusion network security compliance intelligent protection system, comprising a data acquisition module, a data fusion analysis module, a threat detection module, a compliance assessment module, a security response module and a control optimization module;

[0008] The data collection module is used to collect security-related data from multiple data sources within the enterprise and format and pre-process the collected security-related data;

[0009] The data fusion module is used to perform correlation analysis on the collected security-related data and establish a threat situation awareness model to improve the detection accuracy of security incidents;

[0010] The threat detection module uses SIEM and XDR technologies to perform threat modeling on the results output by the data fusion analysis module, identify potential security threats, and calculate the threat level in real time;

[0011] The compliance assessment module performs compliance checks on detected security incidents, assesses whether the threats involve compliance risks, and provides audit reports;

[0012] The security response module, combined with the SOAR system, automatically responds to detected security threats within the preset policy framework, including isolating infected devices and adjusting access permissions;

[0013] The control optimization module performs secondary verification on all executed security response measures, and dynamically optimizes SIEM, XDR and SOAR based on the verification feedback results to improve overall protection capabilities.

[0014] Preferably, in the data fusion module, the threat situation awareness model is a random forest model, samples are labeled through known attack data sets and divided into different attack types, the random forest model is trained using a training set, and hyperparameters are adjusted through cross-validation, security indicators are identified through feature importance analysis, and feature selection is optimized to reduce computing resource consumption, and model performance is evaluated using accuracy, recall rate, and F1 score indicators. After training, security incidents in the enterprise network environment are classified.

[0015] Preferably, in the threat detection module, a threat score is used to quantify the severity of a security incident, and the threat score TS is calculated based on the formula:

[0016] TS=W1×Sbehavior+W2×Snetwork+W3×Sintelligence+W4×Historical;

[0017] Among them: Sbehavior is the abnormal degree of user or device behavior; Snetwork is the network communication feature; Sintelligence is the threat intelligence matching degree; Historical is the historical attack record; W1, W2, W3, W4 are weight coefficients;

[0018] If the threat score is between 0 and 30, the danger level is classified as a low risk level, and the response measures include monitoring and logging; if the threat score is between 31 and 70, the danger level is classified as a medium risk level, and the response measures include triggering a security alert and manual review; if the threat score is between 71 and 100, the danger level is classified as a high risk level, and the response measures include immediately blocking the attack.

[0019] Preferably, in the compliance assessment module, a corresponding data sensitivity index is generated by measuring whether the accessed, transmitted or leaked data is sensitive data, which is used to evaluate the compliance impact. The method for obtaining the data sensitivity index is: classify the accessed or leaked data, and assign a sensitivity weight Qd to each type of data, a leakage range impact level range coefficient S, and a data volume example data volume coefficient V. If the data is encrypted, the compliance impact is reduced, so the encryption coefficient E is introduced for adjustment. When not encrypted, the state encryption coefficient E is set to 1.0; when partially encrypted, the state encryption coefficient E is set to 0.6; when strongly encrypted, the state encryption coefficient E is set to 0.3. The calculation formula of the data sensitivity index DSI is: DSI = (Qd×S×V)×E.

[0020] Preferably, the threat duration anomaly index is generated by measuring the impact of the threat duration on compliance. The method for obtaining the threat duration anomaly index is:

[0021] Collect historical threat events recorded by SIEM, XDR, and SOAR, including the duration and compliance impact of each event; use Min-Max normalization, the expression is:

[0022] T real is the original attack duration, T min and T max are the minimum and maximum duration of historical data, T norm is the standardized attack duration data;

[0023] Build an LSTM prediction model. 80% of the attack duration data is used as a training set to train the LSTM prediction model. 20% of the attack duration data is used as a test set to verify the model performance. The sliding window method is used to create training samples. Each input contains the duration T of the past N threat events. t-N:X t =[T t-N , T t-N+1 , ..., T t-1 ]; train the LSTM model, input layer: accept the duration data of the past N attacks, LSTM layer: contains multiple LSTM units to capture time dependencies, fully connected layer: outputs the predicted duration Tpred, activation function: uses ReLU for nonlinear transformation to ensure that the predicted value is positive; use mean square error to measure the prediction error;

[0024] After LSTM training is completed, it is used to predict the normal duration T of a new attack event. pred , and calculate the actual duration T real The deviation from the predicted value is δT, which is expressed as: δT=|T real -T pred |; Calculate the threat duration anomaly index TDAI, the expression is: Where: ∈ is a small value to prevent division by zero errors.

[0025] Preferably, the data sensitivity index and the threat duration anomaly index are converted into a comprehensive feature vector, and the comprehensive feature vector is used as the input of the machine learning model. The machine learning model predicts the compliance risk value label of the security event for each group of comprehensive feature vectors as the prediction target, and minimizes the sum of prediction errors of the compliance risk value labels of all security events as the training target. The machine learning model is trained until the sum of prediction errors reaches convergence, then the model training is stopped, and the compliance risk value of the security event is determined according to the model output results, wherein the machine learning model is a second-order polynomial regression model.

[0026] Preferably, the compliance risk value of the obtained security event is compared with a gradient standard threshold, the gradient standard threshold includes a first standard threshold and a second standard threshold, and the first standard threshold is less than the second standard threshold, and the compliance risk value of the security event is compared with the first standard threshold and the second standard threshold respectively;

[0027] If the compliance risk value of the security incident is greater than the second standard threshold, it means that the compliance risk level of the security incident is high, and a level 1 warning signal is generated; this means that the security incident seriously violates the compliance requirements and immediate measures need to be taken;

[0028] If the compliance risk value of a security incident is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, it means that the compliance risk level of the security incident is medium, and a level 2 warning signal is generated. This means that the security incident involves compliance issues and requires manual review.

[0029] If the compliance risk value of the security incident is less than the first standard threshold, it means that the compliance risk level of the security incident is low. At this time, a third-level warning signal is generated and monitoring continues without immediate intervention.

[0030] Preferably, in the control optimization module, SOAR collects secondary verification feedback after executing the security response, and dynamically optimizes the security strategy based on it. The comprehensive optimization formula is:

[0031] ΔS=λ1·F FP +λ2·F FN +λ3·F RT -λ4·F Eff ; Where: ΔS is the security strategy optimization range, F FP is the false alarm rate, that is, the proportion of normal behaviors misjudged as threats;

[0032] F FN is the false negative rate, i.e. the proportion of real attacks that cannot be detected; F RT F is the response delay, which is the time from threat detection to response completion; Eff is the response efficiency, that is, the proportion of measures taken by SOAR that successfully prevent attacks; λ1, λ2, λ3, and λ4 are adjustment coefficients used to balance the weights of different indicators;

[0033] If the false alarm rate F FP High, indicating that SOAR aggressively blocks normal business, optimizes SIEM rules, and reduces invalid alarms; if the false alarm rate F FN High, indicating that SOAR fails to effectively respond to real threats, optimize XDR strategies, and strengthen network detection.

[0034] In the above technical solution, the technical effects and advantages provided by the present invention are:

[0035] 1. The present invention uses SIEM and XDR to perform intelligent threat scoring, combines the LSTM time series model to calculate the threat duration anomaly index TDAI, and evaluates the compliance impact of data leakage through the data sensitivity index DSI. The system uses a polynomial regression model to predict compliance risks and divides the warning level based on the gradient standard threshold to ensure that security incidents of different levels can receive compliant, efficient and automated responses, while preventing SOAR from mistakenly triggering key business systems.

[0036] 2. The present invention utilizes the control optimization module to adjust SIEM false alarm rules, XDR endpoint detection strategies and SOAR automatic response strategies in real time through a secondary verification feedback mechanism, ensuring that the system reduces false alarms and missed alarms while improving the accuracy and execution efficiency of security responses. This can not only reduce the operational burden of the enterprise security team, but also improve the adaptive capabilities of network defense, enhance the overall security compliance of the enterprise, and reduce the risk of data leakage and business interruption. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0038] Figure 1 It is a system module diagram of the present invention. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0040] For examples, see Figure 1 As shown, the network security compliance intelligent protection system for enterprise multi-source data fusion described in this embodiment includes a data acquisition module, a data fusion analysis module, a threat detection module, a compliance assessment module, a security response module and a control optimization module;

[0041] The data collection module is used to collect security-related data from multiple data sources within the enterprise and format and pre-process the collected security-related data;

[0042] The data fusion module is used to perform correlation analysis on the collected security-related data and establish a threat situation awareness model to improve the detection accuracy of security incidents;

[0043] The threat detection module uses SIEM and XDR technologies to perform threat modeling on the results output by the data fusion analysis module, identify potential security threats, and calculate the threat level in real time;

[0044] The compliance assessment module performs compliance checks on detected security incidents, assesses whether the threats involve compliance risks, and provides audit reports;

[0045] The security response module, combined with the SOAR system, automatically responds to detected security threats within the preset policy framework, including isolating infected devices and adjusting access permissions;

[0046] The control optimization module performs secondary verification on all executed security response measures, and dynamically optimizes SIEM, XDR and SOAR based on the verification feedback results to improve overall protection capabilities.

[0047] In the data acquisition module, the data acquisition module can access a variety of heterogeneous data sources, including but not limited to the following types:

[0048] Log Data: system logs (such as Windows Event Logs, Linux Syslog), application logs (such as Web server, database, mail server logs), authentication logs (such as Active Directory, LDAP authentication logs), security device logs (such as firewalls, intrusion detection / prevention systems IDS / IPS);

[0049] Network Traffic Data: Network packet data (PCAP), NetFlow / IPFIX traffic data, DNS request and response logs, HTTP / HTTPS traffic analysis data;

[0050] User Behavior Data: access control data (such as VPN, RDP, SSH remote access logs), terminal activity logs (such as USB device usage, file access, command execution), abnormal behavior detection data (such as large-scale downloads in a short period of time, remote command execution),

[0051] Threat Intelligence Data: external threat intelligence sources (such as VirusTotal, MITRE ATT&CK, blacklist IP lists), internal security intelligence (such as historical attack patterns, local sandbox analysis results);

[0052] Industrial Control System (ICS) and Internet of Things (IoT) device data: SCADA monitoring data, Modbus, BACnet, OPC-UA device logs, status data of smart sensors and IoT devices.

[0053] According to different data sources, the data collection module supports multiple collection methods:

[0054] Passive collection (Agentless): Monitor traffic through network traffic mirroring (SPAN port), NetFlow / IPFIX, and directly parse server log files (such as ELK, Splunk).

[0055] Active collection (Agent-Based): Deploy agents on terminal devices, servers, or ICS devices to collect logs and API endpoint data (such as SIEM, SOC platform).

[0056] Event push mode: data push through Syslog, Kafka, MQTT, and Webhooks.

[0057] Scheduled polling mode: Use REST API, database query, etc. to collect data regularly.

[0058] The collected raw data is usually in inconsistent formats and may contain redundant and noisy data, so it needs to be formatted and preprocessed, including:

[0059] Data Normalization: Use common security log formats (such as CEF, LEEF, JSON, Syslog) for conversion to ensure a unified data structure; extract key fields (such as timestamp, IP address, user ID, event type) and standardize them.

[0060] Data Cleaning: remove duplicates (such as duplicate security events or network traffic); filter irrelevant data (such as non-security-related system logs); and handle missing values ​​(such as default filling and retroactive completion).

[0061] Timestamp Alignment: Unify the timestamps of different systems (such as time zone conversion, NTP time synchronization) and handle the time drift problem that may exist in the logs.

[0062] Data denoising (Noise Reduction): Filter low-value or high-frequency false alarm events (such as non-critical alarms, normal scanning behaviors); combine AI to perform log noise reduction to reduce the load on the analysis system.

[0063] Data Enrichment & Tagging: Based on the threat intelligence database, known malicious IP addresses, domain names, and file hashes are marked, and combined with user behavior analysis (UBA), risk scores are added to suspicious behaviors.

[0064] After formatting and preprocessing, the data needs to be stored or transferred to a subsequent analysis system, usually in the following ways:

[0065] Local Buffering: Use Kafka, Redis, RabbitMQ, etc. for message queue storage to improve real-time performance; suitable for high-concurrency environments to prevent data loss.

[0066] Centralized Storage: Structured data is stored in databases (such as PostgreSQL and Elasticsearch); unstructured data (such as PCAP and log files) is stored in distributed storage systems (such as Hadoop and S3).

[0067] Encryption and transmission (Secure Transmission): Use TLS / SSL to encrypt log data to prevent man-in-the-middle attacks (MITM); transmit ICS and IoT data through VPN and dedicated secure channels (such as IPSec).

[0068] The data collection module is the core component of enterprise multi-source data fusion. It collects data from different data sources (logs, traffic, user behavior, threat intelligence, ICS / IoT) and performs pre-processing such as standardization, cleaning, denoising, and labeling to ensure the accuracy and reliability of subsequent threat detection and compliance assessment. At the same time, the module must have high security to prevent data from being tampered or contaminated by attackers and ensure the credibility of the intelligent protection system.

[0069] In the data fusion module, data analysis and format standardization are to ensure that data from different sources have a unified format to facilitate subsequent processing.

[0070] Parse data formats (such as JSON, XML, Syslog, CEF, LEEF) of SIEM, XDR, SOAR, and ICS / IoT devices. Unify timestamp formats (such as UTC / GMT) and perform time zone conversion to ensure data time synchronization. Structure unstructured data, such as extracting key fields (IP address, user ID, event type, etc.) from log text. De-duplicate processing to remove redundant logs or event records caused by repeated collection.

[0071] Data cleaning and outlier detection are used to improve data quality, remove irrelevant or erroneous data, and prevent false positives. Delete noise data (such as low-risk operation logs, repeated scan data). Identify and correct outliers (such as incorrect timestamps, IP addresses, user IDs). Filter high-value security events and filter low-impact data through machine learning or rule matching.

[0072] Data correlation analysis is used to correlate events across multiple data sources and identify potential threat patterns. Time window-based event aggregation: Aggregate and analyze related events that occur in a short period of time (such as the same IP accessing multiple systems). Anomaly detection based on user behavior: Combined with UEBA (User Entity Behavior Analysis) technology, detect abnormal login behavior (such as remote login late at night). Identify abnormal access patterns (such as high-frequency access to multiple databases in a short period of time). Analysis based on IP address and geographic location: Combined with threat intelligence data, detect whether malicious IPs are involved in communications. Identify geographic location anomalies (such as the same account logging in from different countries in a short period of time). Analysis based on attack path: Combined with the MITRE ATT&CK framework, analyze the possible action path of the attacker. Identify internal jump attacks (such as spreading from an infected terminal to a server).

[0073] Threat intelligence enhanced analysis is used to combine external threat intelligence to improve attack detection accuracy. Query blacklisted IPs, domain names, and file hash values, and compare related fields in security events. Combine AI to predict attack trends, such as using malware family databases to identify new variants. Combine DNS and URL reputation scores to detect potential phishing or command and control (C2) server communications.

[0074] Among them, the threat situation awareness model is a random forest model; Random Forest is an ensemble learning method based on decision trees, which is suitable for nonlinear and complex threat classification tasks. The training process is as follows:

[0075] Data annotation: Use known attack data sets (such as MITRE ATT&CK, CVE vulnerability database) to annotate samples and classify them into different attack types (such as DDoS, SQL injection, remote code execution, malware infection, etc.).

[0076] Training and cross-validation: Use the training set to train the random forest model and adjust the hyperparameters through cross-validation (such as K-fold cross-validation) to improve generalization ability.

[0077] Model optimization: Identify key security indicators through feature importance analysis and optimize feature selection to reduce computing resource consumption.

[0078] Model evaluation: Use indicators such as accuracy, recall, and F1-score to evaluate model performance and ensure detection accuracy.

[0079] After training is completed, the model can classify security events in the enterprise network environment in real time and identify whether they are malicious behaviors.

[0080] In the threat detection module, the core of threat modeling is to identify potential attack patterns and assess their risk levels through SIEM and XDR combined with multi-source data analysis.

[0081] The data sources received by SIEM and XDR include: SIEM main input data: log data (system, application, authentication, network, ICS / IoT devices, etc.); event log (Windows Event Log, Syslog): network traffic data (NetFlow, DNS request, HTTP / HTTPS access log); threat intelligence data (malicious IP, C2 server, known attack tools). XDR main input data: endpoint detection data (terminal behavior, process execution, file access, registry modification). Network detection data (abnormal traffic, lateral movement, C2 connection); cloud security data (API abuse, cloud storage access, Kubernetes threats).

[0082] Data Correlation Analysis: Identify abnormal high-frequency events in a short period of time (such as 100 consecutive login failures within 1 minute) and combine them with SIEM timestamp data to identify attack behaviors of the same source IP in different time periods.

[0083] Combined with login logs collected by SIEM, abnormal access patterns (such as account theft) can be detected; XDR is combined with endpoint behavior analysis to detect abnormal file access, process execution, etc.

[0084] Use SIEM to match tactics, techniques, and procedures (TTPs); combine XDR data to identify technical means that attackers may use (such as remote code execution and privilege escalation).

[0085] Threat Score is used to quantify the severity of security incidents so that enterprises can reasonably allocate security resources and prioritize high-risk threats. The score calculation method is as follows:

[0086] The threat score can be calculated based on the following formula:

[0087] TS=W1×Sbehavior+W2×Snetwork+W3×Sintelligence+W4×Historical

[0088] ; Among them: Sbehavior: abnormal degree of user or device behavior (such as abnormal login, abnormal command execution). Snetwork: network communication characteristics (such as suspicious traffic patterns, port scanning, C2 connection). Sintelligence: threat intelligence matching degree (such as whether the IP is on the blacklist, whether it matches the known attack pattern). Shistorical: historical attack records (such as whether similar attacks have been encountered before, whether the attack source appears repeatedly). W1, W2, W3, W4 are weight coefficients, which can be determined through historical data analysis.

[0089] If the threat score is between 0 and 30, the risk level is classified as low risk, and the response measures include monitoring and logging; if the threat score is between 31 and 70, the risk level is classified as medium risk, and the response measures include triggering security alerts and manual review; if the threat score is between 71 and 100, the risk level is classified as high risk, and the response measures include immediately blocking the attack. High-risk events (such as ransomware infection and remote command execution) will trigger SOAR for automated defense, while low-risk events (such as non-malicious port scans) will only be logged to reduce the impact of false positives.

[0090] The compliance assessment module performs compliance checks on detected security incidents, assesses whether the threats involve compliance risks, and provides audit reports, including:

[0091] Conduct compliance checks on detected security events to assess whether the threats involve compliance risks, including:

[0092] By measuring whether the data being accessed, transmitted or leaked is sensitive data, a corresponding data sensitivity index is generated to assess the impact of compliance. The data sensitivity index is obtained as follows:

[0093] First, the accessed or leaked data is classified and a sensitivity weight Qd is assigned to each type of data. The higher the weight value, the more sensitive the data is and the greater the compliance risk is.

[0094] The sensitivity weight Qd of internal business data such as corporate emails and financial statement data types is set to 0.4; the sensitivity weight Qd of personal identity information (PII) such as name, ID number, address, and bank account is set to 0.7; the sensitivity weight Qd of medical data such as electronic health records (EHR) and medical records is set to 0.8; the sensitivity weight Qd of critical infrastructure data such as ICS / SCADA control instructions and power network is set to 1.0.

[0095] The scope (Scope, S) of data access or leakage will affect the data sensitivity index. The larger the scope of leakage, the higher the index. The scope coefficient S of the leakage scope is set to 0.2 for internal access only, 0.5 for sharing within the enterprise, 0.8 for sharing outside the enterprise, and 1.0 for extremely high scope leakage scope for public leakage (dark web, Internet).

[0096] The scale of data leakage or access is also a key factor. Large-scale data leakage will significantly increase the sensitivity index. For example, the data volume coefficient V is set to 0.2 for a single user account with less than 10 data items; 0.4 for a small-scale data leakage of 10-100 data items; 0.7 for a large-scale customer data leakage of 100-10,000 data items; and 1.0 for a large-scale enterprise database leakage of more than 10,000 data items.

[0097] If the data is encrypted, the compliance impact is reduced, so the encryption factor E is introduced for adjustment. When the data is not encrypted, the state encryption factor E is set to 1.0; when it is partially encrypted, the state encryption factor E is set to 0.6; when it is strongly encrypted (AES-256), the state encryption factor E is set to 0.3. The calculation formula of the data sensitivity index DSI is: DSI = (Qd × S × V) × E.

[0098] The threat duration anomaly index is generated by measuring the impact of the threat duration on compliance. The threat duration anomaly index is obtained as follows:

[0099] Collect historical threat events recorded by SIEM, XDR, and SOAR, including the duration and compliance impact of each event; since the attack duration data has a large distribution span (from a few seconds to a few hours), use Min-Max normalization, and the expression is:

[0100] T real is the original attack duration (seconds), T min and T max are the minimum and maximum duration of historical data, T norm The normalized attack duration data.

[0101] Build an LSTM prediction model, and use 80% of the attack duration data as a training set to train the LSTM prediction model. 20% of the attack duration data is used as a test set to verify the model performance. LSTM is suitable for time series prediction, so the sliding window method is used to create training samples. Each input contains the duration T of the past N threat events.t-N :

[0102] X t =[T t-N , T t-N+1 , ..., T t-1 ]; train the LSTM model, input layer: accept the duration data of the past N attacks, LSTM layer: contains multiple LSTM units to capture time dependencies, fully connected layer: outputs the predicted duration Tpred, activation function: uses ReLU for nonlinear transformation to ensure that the predicted value is positive; use mean square error to measure the prediction error.

[0103] After LSTM training is completed, it is used to predict the normal duration T of a new attack event. pred , and calculate the actual duration T real The deviation from the predicted value is δT, which is expressed as: δT=|T real -T pred |; Calculate the threat duration anomaly index TDAI, the expression is: Where: ∈ is a small value (such as 1e-5) to prevent division by zero errors.

[0104] The data sensitivity index and the threat duration anomaly index are converted into comprehensive feature vectors, and the comprehensive feature vectors are used as the input of the machine learning model. The machine learning model predicts the compliance risk value label of the security incident with each set of comprehensive feature vectors as the prediction target, and minimizes the sum of prediction errors of the compliance risk value labels of all security incidents as the training target. The machine learning model is trained until the sum of prediction errors converges, and the model training is stopped. The compliance risk value of the security incident is determined according to the model output results, wherein the machine learning model is a second-order polynomial regression model.

[0105] Compare the obtained compliance risk value of the security event with the gradient standard threshold, where the gradient standard threshold includes a first standard threshold and a second standard threshold, and the first standard threshold is less than the second standard threshold, and compare the compliance risk value of the security event with the first standard threshold and the second standard threshold respectively;

[0106] If the compliance risk value of a security incident is greater than the second standard threshold, it indicates that the compliance risk level of the security incident is high, and a level 1 warning signal is generated. This indicates that the security incident seriously violates compliance requirements and immediate measures need to be taken, such as immediately blocking attack traffic, reporting to the regulatory authority (such as GDPR reporting requirements within 72 hours), and triggering SOAR automatic response.

[0107] If the compliance risk value of a security incident is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, it means that the compliance risk level of the security incident is medium, and a level 2 warning signal is generated. This means that the security incident involves compliance issues, but the extent of the impact is uncertain and requires manual review, such as recording logs, notifying security analysts, triggering SIEM rules, and further analysis.

[0108] If the compliance risk value of the security incident is less than the first standard threshold, it means that the compliance risk level of the security incident is low. At this time, a third-level warning signal is generated, indicating that the compliance risk of the security incident is low. Continue to monitor and no immediate intervention is required.

[0109] It should be noted here that the importance of the first-level warning signal is greater than that of the second-level warning signal, and the importance of the second-level warning signal is greater than that of the third-level warning signal. Relevant personnel can take corresponding handling measures according to different warning signal levels.

[0110] The audit report includes: basic information of the event: event ID, timestamp, source IP, target system, associated user account, and geographic location. Security analysis results: data type and sensitivity level involved in the event, event attack time period and duration, and attack behaviors involved in the event (such as SQL injection, data leakage, and malicious file upload).

[0111] Compliance assessment: Violated regulations (such as data breach reporting requirements in Article 33 of the GDPR), compliance measures to be taken (such as notifying the data protection agency within 72 hours and conducting an internal security investigation); and compliance responsibilities (such as IT team, data protection officer (DPO)).

[0112] Risk level and rectification suggestions: comprehensive risk rating of the incident (low, medium, high), recommended security strategies (such as strengthening access control and improving incident response speed), and preventive measures (such as data encryption and enabling zero-trust access control).

[0113] The security response module, combined with the SOAR system, automatically responds to detected security threats within a preset policy framework, including isolating infected devices and adjusting access permissions.

[0114] In order to improve the efficiency of security incident response, the SOAR (Security Orchestration, Automation and Response) system automatically responds to detected security threats under the preset policy framework to ensure the security and compliance of the enterprise network environment. When SIEM and XDR identify abnormal activities, the SOAR system will automatically execute corresponding countermeasures based on the threat level, compliance requirements and the enterprise's preset security policies. These measures include real-time log analysis, attack path tracking, impact scope assessment, and combined with the security policy library to determine the best response plan to ensure the stability of enterprise security operations and business continuity.

[0115] At the specific execution level, the SOAR system can automatically isolate infected devices to prevent the threat from spreading further. When a ransomware infection, malicious code execution, or APT (advanced persistent threat) is detected, SOAR can automatically work with EDR (endpoint detection and response) to immediately cut off the infected terminal's network connection and block communication with malicious IP or C2 (command and control) servers. At the same time, SOAR can send alerts to IT administrators and provide detailed event analysis reports, including behavior logs of infected devices, process activities, and possible attack paths for further investigation and repair.

[0116] In addition, SOAR can automatically adjust access rights to reduce security risks and meet compliance requirements. For example, when abnormal login behavior is detected in a user account (such as access from different countries in a short period of time), SOAR can automatically reduce the account's access rights, require additional authentication (such as MFA), or even temporarily disable the account to prevent data leakage. In ICS (industrial control systems) or cloud environments, SOAR can also dynamically adjust access control lists (ACLs) to restrict high-risk operations and prevent unauthorized execution of instructions. Through these automated response mechanisms, SOAR can not only reduce the workload of the security team, but also greatly improve the speed of incident response and minimize the impact of cyber attacks on the enterprise.

[0117] The control optimization module performs secondary verification on all executed security response measures, and dynamically optimizes SIEM, XDR and SOAR based on the verification feedback results to improve overall protection capabilities.

[0118] After SOAR performs security responses (such as isolating infected devices and adjusting access permissions), the system will collect secondary verification feedback and dynamically optimize security policies based on it. The comprehensive optimization formula is:

[0119] ΔS=λ1·F FP +λ2·F FN +λ3·F RT -λ4·F Eff ; Where: ΔS is the security policy optimization range (adjusting the response rules of SIEM, XDR and SOAR), F FP is the false positive rate, that is, the proportion of normal behaviors misjudged as threats; F FN is the false negative rate, which is the proportion of real attacks that cannot be detected;

[0120] F RT F is the response delay (Response Time), which is the time from threat detection to response completion (seconds);Eff is the response efficiency, that is, the proportion of measures taken by SOAR to successfully prevent attacks; λ1, λ2, λ3, and λ4 are adjustment coefficients used to balance the weights of different indicators (for example, if reducing false alarms is more important than reducing response time, then

[0121] λ1>λ2).

[0122] If the false alarm rate F FP High, indicating that SOAR may be too aggressive in blocking normal business, and SIEM rules need to be optimized to reduce invalid alarms: SIEM new =SIEM old -α·F FP ; where α is the false positive adjustment factor, ensuring that SIEM filters low-risk events. SIEM old SIEM rules before optimization, SIEM new This is the optimized SIEM rule.

[0123] If the underreporting rate F FN High, indicating that SOAR may not be able to effectively respond to real threats, and it is necessary to optimize XDR strategies and strengthen terminal and network detection: XDR new =XDR old +β·F FN ; Where β is the underreporting adjustment coefficient, which improves the XDR detection sensitivity. old This is the XDR strategy before optimization. new This is the optimized XDR strategy.

[0124] In this embodiment, the data acquisition module is responsible for collecting security-related data from multiple data sources within the enterprise (such as logs, traffic, user behavior, etc.), and formatting and preprocessing to ensure data consistency and integrity. The data fusion module establishes a threat situation awareness model by correlating and analyzing data from different sources to improve the detection accuracy of security events. The threat detection module uses SIEM (security information and event management) and XDR (extended detection and response) technologies to perform threat modeling on the fused data, identify potential security threats in real time and calculate their threat levels. The compliance assessment module further performs compliance checks on the detected security events, assesses whether it involves regulatory risks such as GDPR, ISO 27001, NERC-CIP, and generates an audit report. The security response module combines the SOAR (security orchestration, automation and response) system to perform automated responses to security threats under the preset policy framework, including isolating infected devices, adjusting access rights, and other measures to reduce the impact of threats. Finally, the control optimization module re-verifies all executed security response measures, analyzes feedback data, and dynamically optimizes SIEM, XDR, and SOAR to continuously improve the overall protection capabilities of the system, ensure that the enterprise security system has adaptive optimization capabilities, and achieve efficient and accurate network security management.

[0125] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.

[0126] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented by software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state hard disk.

[0127] The above description is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.

Claims

1. An intelligent protection system for network security compliance based on multi-source data fusion of enterprises, characterized by: It includes data acquisition module, data fusion analysis module, threat detection module, compliance assessment module, security response module and control optimization module; The data collection module is used to collect security-related data from multiple data sources within the enterprise and format and pre-process the collected security-related data; The data fusion module is used to perform correlation analysis on the collected security-related data and establish a threat situation awareness model to improve the detection accuracy of security incidents; The threat detection module uses SIEM and XDR technologies to perform threat modeling on the results output by the data fusion analysis module, identify potential security threats, and calculate the threat level in real time; The compliance assessment module performs compliance checks on detected security incidents, assesses whether the threats involve compliance risks, and provides audit reports; The security response module, combined with the SOAR system, automatically responds to detected security threats within the preset policy framework, including isolating infected devices and adjusting access permissions; The control optimization module performs secondary verification on all executed security response measures, and dynamically optimizes SIEM, XDR and SOAR based on the verification feedback results to improve overall protection capabilities.

2. The network security compliance intelligent protection system for enterprise multi-source data fusion according to claim 1 is characterized by: In the data fusion module, the threat situation awareness model is a random forest model. Samples are labeled through known attack data sets and divided into different attack types. The random forest model is trained using a training set, and hyperparameters are adjusted through cross-validation. Security indicators are identified through feature importance analysis, and feature selection is optimized to reduce computing resource consumption. The accuracy, recall rate, and F1 score indicators are used to evaluate the model performance. After training, security incidents in the enterprise network environment are classified.

3. The network security compliance intelligent protection system for enterprise multi-source data fusion according to claim 1 is characterized by: In the threat detection module, the threat score is used to quantify the severity of security incidents. The threat score TS is calculated based on the formula: TS=W1×Sbehavior+W2×Snetwork+W3×Sintelligence+W4xHistorical; Among them: Sbehavior is the abnormal degree of user or device behavior; Snetwork is the network communication feature; Sintelligence is the threat intelligence matching degree; Historical is the historical attack record; W1, W2, W3, W4 are weight coefficients; If the threat score is between 0 and 30, the danger level is classified as low risk, and the response measures include monitoring and logging; If the threat score is between 31 and 70, the risk level is classified as medium risk, and the response measures include triggering a security alert and manual review; If the threat score is between 71 and 100, the danger level is classified as high risk, and the response measures include immediately blocking the attack.

4. The network security compliance intelligent protection system for enterprise multi-source data fusion according to claim 1 is characterized by: In the compliance assessment module, by measuring whether the accessed, transmitted or leaked data is sensitive data, a corresponding data sensitivity index is generated to evaluate the compliance impact. The data sensitivity index is obtained by classifying the accessed or leaked data and assigning a sensitivity weight Qd, a leakage scope impact level range coefficient S, and a data volume example data volume coefficient V to each type of data. If the data is encrypted, the compliance impact is reduced, so the encryption coefficient E is introduced for adjustment. When not encrypted, the state encryption coefficient E is set to 1.0; when partially encrypted, the state encryption coefficient E is set to 0.6; when strongly encrypted, the state encryption coefficient E is set to 0.

3. The calculation formula of the data sensitivity index DSI is: DSI = (Qd × S × V) × E.

5. The network security compliance intelligent protection system for enterprise multi-source data fusion according to claim 4 is characterized by: The threat duration anomaly index is generated by measuring the impact of the threat duration on compliance. The threat duration anomaly index is obtained as follows: Collect historical threat events recorded by SIEM, XDR, and SOAR, including the duration and compliance impact of each event; use Min-Max normalization, the expression is: T real is the original attack duration, T min and T max are the minimum and maximum duration of historical data, T norm is the standardized attack duration data; Build an LSTM prediction model. 80% of the attack duration data is used as a training set to train the LSTM prediction model. 20% of the attack duration data is used as a test set to verify the model performance. The sliding window method is used to create training samples. Each input contains the duration T of the past N threat events. t-N :X t =[T t-N , T t-N+1 , ..., T t-1 ]; train the LSTM model, input layer: accept the duration data of the past N attacks, LSTM layer: contains multiple LSTM units to capture time dependencies, fully connected layer: outputs the predicted duration Tpred, activation function: uses ReLU for nonlinear transformation to ensure that the predicted value is positive; use mean square error to measure the prediction error; After LSTM training is completed, it is used to predict the normal duration T of a new attack event. pred , and calculate the actual duration T real The deviation from the predicted value is δT, which is expressed as: δT=|T real -T pred |; Calculate the threat duration anomaly index TDAI, the expression is: Where: ∈ is a small value to prevent division by zero errors.

6. The network security compliance intelligent protection system for enterprise multi-source data fusion according to claim 5 is characterized by: The data sensitivity index and the threat duration anomaly index are converted into comprehensive feature vectors, and the comprehensive feature vectors are used as the input of the machine learning model. The machine learning model predicts the compliance risk value label of the security incident with each set of comprehensive feature vectors as the prediction target, and minimizes the sum of prediction errors of the compliance risk value labels of all security incidents as the training target. The machine learning model is trained until the sum of prediction errors converges, and the model training is stopped. The compliance risk value of the security incident is determined according to the model output results, wherein the machine learning model is a second-order polynomial regression model.

7. The network security compliance intelligent protection system for enterprise multi-source data fusion according to claim 6 is characterized by: Compare the obtained compliance risk value of the security event with the gradient standard threshold, where the gradient standard threshold includes a first standard threshold and a second standard threshold, and the first standard threshold is less than the second standard threshold, and compare the compliance risk value of the security event with the first standard threshold and the second standard threshold respectively; If the compliance risk value of the security incident is greater than the second standard threshold, it means that the compliance risk level of the security incident is high, and a first-level warning signal is generated; Explain that the security incident seriously violates compliance requirements and requires immediate action; If the compliance risk value of the security incident is greater than or equal to the first standard threshold and less than or equal to the second standard threshold, it means that the compliance risk level of the security incident is medium, and a level 2 warning signal is generated; Explain that the security incident involves compliance issues and requires manual review; If the compliance risk value of the security incident is less than the first standard threshold, it means that the compliance risk level of the security incident is low. At this time, a third-level warning signal is generated and monitoring continues without immediate intervention.

8. The network security compliance intelligent protection system for enterprise multi-source data fusion according to claim 1 is characterized by: In the control optimization module, SOAR collects secondary verification feedback after executing the security response and dynamically optimizes the security strategy based on it. The comprehensive optimization formula is: ΔS = λ1·F FP +λ2·F FN +λ3·F RT -λ4·F Eff ; Where: ΔS is the security strategy optimization range, F FP is the false alarm rate, that is, the proportion of normal behaviors misjudged as threats; F FN is the false negative rate, i.e. the proportion of real attacks that cannot be detected; F RT F is the response delay, which is the time from threat detection to response completion; Eff is the response efficiency, that is, the proportion of measures taken by SOAR that successfully prevent attacks; λ1, λ2, λ3, and λ4 are adjustment coefficients used to balance the weights of different indicators; If the false alarm rate F PP High, indicating that SOAR aggressively blocks normal services, optimizes SIEM rules, and reduces invalid alerts; If the underreporting rate F FN High, indicating that SOAR fails to effectively respond to real threats, optimize XDR strategies, and strengthen network detection.

Citation Information

Cited By

  • Data security event real-time monitoring method and system

    CN120528657A

  • Safe operation system of intelligent computing proprietary cloud center

    CN120675780A

  • Information security detection method

    CN120750614A

  • Threat detection response agent security protection method and system based on terminal deployment

    CN120880798A

  • Terminal deployment-based threat detection response intelligent agent security protection method and system

    CN120880798B