Domain user and cloud desktop user integration method
By establishing a unified user information model and dynamic policy configuration, the consistency and security of identity information between domain users and desktop users are solved. At the same time, by defining a unified security event format and a linkage architecture based on the message bus, seamless linkage and collaborative protection between different security components is achieved, improving the overall identity authentication and security protection level.
Patent Information
- Application Number
- CN202411991510.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-13
AI Technical Summary
In the process of integrating domain users and desktop users, how to ensure the consistency and real-time synchronization of user identity information among multiple systems is a key technical problem. In addition, how to balance the relationship between the granularity of group policy configuration and system performance while meeting data security needs, and how to achieve seamless docking and collaborative linkage between different security components are all technical challenges.
By pre-establishing a unified user information model, the user attributes of each system are mapped into the model, and standardized representation and real-time synchronization of user data between different systems are realized. A dynamic policy configuration method is adopted to adjust the granularity and strictness of the group policy according to the system's real-time performance indicators. Define a unified security event format and data exchange interface, and adopt a linkage architecture based on the message bus to achieve seamless docking and coordinated linkage between various security components.
It realizes the consistency and real-time synchronization of identity information between domain users and cloud desktop users, balances data security and system performance, realizes seamless linkage and collaborative protection between different security components, and improves the success rate of identity authentication and the intelligence level of security protection.
Smart Images

Figure CN119995936A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a method for integrating domain users with cloud desktop users. Background Art
[0002] Problem background:
[0003] When integrating domain and desktop users, ensuring consistent and real-time synchronization of user identity information across multiple systems is a key technical challenge. Because different systems may employ varying user management mechanisms and data storage methods, user information synchronization requires consideration of data conversion, data mapping, and protocol compatibility between different systems. Furthermore, data integrity and consistency must be ensured during the synchronization process to avoid authentication failures caused by user information asynchrony or synchronization delays.
[0004] When using group policies to ensure data security, balancing the granularity of policy configuration with system performance presents a technical challenge. Overly strict and detailed group policy configurations, while maximizing data security, can also lead to decreased system performance and impact the normal operation of business systems. Minimizing the impact of group policies on system performance while meeting data security requirements requires careful technical solution design and a balance between policy configuration, system architecture design, and operations and maintenance management.
[0005] In achieving a three-dimensional security linkage across the cloud, network, and end, issues such as inconsistent interface protocols, incompatible data formats, and imperfect linkage mechanisms between different security components can lead to security omissions and blind spots. Achieving seamless integration and coordinated linkage between various security components to build a comprehensive, real-time, and efficient three-dimensional security protection system is a complex system integration issue, requiring in-depth technical research and optimization in security architecture design, interface protocol definition, data exchange methods, and linkage strategy configuration. Summary of the Invention
[0006] The present invention provides a method for integrating domain users with cloud desktop users, which mainly includes:
[0007] For user identity information in different systems, a unified user information model is pre-established and the user attributes of each system are mapped to the model to achieve standardized representation of user data between different systems, thereby ensuring the accuracy of data conversion and mapping. At the same time, a distributed data synchronization mechanism is adopted, and message queue technology is used to achieve real-time data synchronization between systems to ensure the consistency of user identity information;
[0008] When synchronizing user identity information, the interface protocols of each system are adapted and converted to achieve compatibility between different protocols. To address issues such as data loss and duplication that may occur during the synchronization process, a data verification and fault-tolerance mechanism is introduced to verify the integrity of the synchronized data. The final consistency of the data is ensured through retransmission, thereby improving the success rate of identity authentication.
[0009] To achieve a balance between group policy configuration and system performance, a dynamic policy configuration method is adopted. The granularity and strictness of group policy are dynamically adjusted based on the system's real-time performance indicators, such as CPU occupancy and memory usage. When the system load is high, policy restrictions are appropriately relaxed, and when the system load is low, policy management is strengthened. At the same time, fine-grained permission control is implemented for key data access operations to reduce unnecessary data access, thereby ensuring data security while minimizing the impact on system performance.
[0010] In the three-dimensional security protection linkage of cloud, network, and terminal, by defining a unified security event format and data exchange interface, data format compatibility and seamless connection between various security components are achieved. A linkage architecture based on a message bus is adopted, and each security component is connected to a unified message bus. Real-time information sharing and linkage between components are achieved through a publish-subscribe mechanism.
[0011] For the linkage policy configuration of security components, a rule-based engine is used to abstract the linkage policy into a series of rules. The rule engine dynamically matches and handles security incidents. Based on the severity and impact of security incidents, the corresponding linkage rules are triggered, and relevant security components are called for coordinated protection, achieving accurate and efficient security incident response.
[0012] In the process of three-dimensional security protection linkage, machine learning algorithms are used to analyze and mine massive amounts of security event data to identify potential security threats and attack patterns. Anomaly detection algorithms, such as isolation forest and one-class support vector machines, are used to model user behavior, network traffic, and other data. The degree of deviation from the normal model is used to determine whether abnormal behavior exists, enabling real-time detection and early warning of unknown threats.
[0013] Combining machine learning algorithms with expert experience, it uses artificial intelligence technology to automatically analyze and make decisions on security incidents. It adopts algorithms based on reinforcement learning to adaptively adjust strategies based on the handling effects of security incidents, continuously optimize linkage strategies, and improve the intelligent level of security protection. At the same time, it uses visualization technology to present complex security incidents and linkage processes in an intuitive manner, assisting security administrators in analysis and decision-making, and improving the efficiency and accuracy of human-machine collaboration.
[0014] The technical solution provided by the embodiment of the present invention may have the following beneficial effects:
[0015] The present invention discloses a cross-system identity authentication and security protection method based on a unified user model. By establishing a unified user information model, standardized representation and real-time synchronization of user data between different systems are achieved. Dynamic policy configuration is adopted to adjust the group policy granularity according to the system load to balance security and performance. In cloud network security protection, a unified interface is defined and a message bus architecture is adopted to achieve seamless linkage of various components. Machine learning algorithms are introduced to analyze massive security events and identify potential threats. Combined with rule engines and reinforcement learning, linkage strategies are intelligently optimized to improve the adaptive capabilities of security protection. Complex security events are presented visually to assist administrators in decision-making. The present invention effectively solves problems such as cross-system user authentication, performance and security balance, and intelligent linkage protection, and significantly improves the level of identity authentication and security protection in a distributed environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 This is a flow chart of a method for integrating domain users and cloud desktop users according to the present invention.
[0017] Figure 2 A schematic diagram of a method for integrating domain users and cloud desktop users according to the present invention.
[0018] Figure 3 This is another schematic diagram of a method for integrating domain users and cloud desktop users according to the present invention. DETAILED DESCRIPTION
[0019] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments derived by those skilled in the art based on the embodiments in this specification without creative effort shall fall within the scope of protection of this specification.
[0020] like Figure 1-3 In this embodiment, a method for integrating domain users with cloud desktop users may specifically include:
[0021] S101. For user identity information across different systems, a unified user information model is pre-established and user attributes from each system are mapped to this model, achieving standardized representation of user data across different systems and ensuring the accuracy of data conversion and mapping. Furthermore, a distributed data synchronization mechanism is implemented, utilizing message queue technology to achieve real-time data synchronization between systems, ensuring consistency of user identity information.
[0022] Based on a pre-established unified user information model, user attribute data from each system is obtained and mapped to corresponding fields in the unified model using an attribute mapping algorithm, resulting in a standardized user information representation. To address the need for user data synchronization across distributed systems, message queue technology is used to establish data synchronization channels between systems. When user information in a system changes, a change message is published to the message queue. Other systems subscribe to the message queue to receive the user information change message and update their local user data based on the message content, achieving real-time data synchronization in a distributed environment. During the data synchronization process, user attributes are compared and verified to determine whether there are data conflicts or inconsistencies. If data inconsistencies are found, the data in the system that is used is determined based on pre-set data priority rules, and data is overwritten or merged to ensure final user information consistency. To identify and associate users across systems, a matching algorithm based on user attribute similarity is used. By comparing the similarity of user attributes across different systems, it is determined whether they are the same user and a cross-system user identity mapping is established. During the user identity matching process, machine learning algorithms such as decision trees and support vector machines are introduced. By training historical user data, a model is established to associate user attributes with identities, improving the accuracy of identity recognition and matching. To ensure the security and privacy of user information, data desensitization and encryption technologies are used during data synchronization and user identity association to desensitize sensitive user attributes. Encryption algorithms are also used to encrypt data transmission and storage to prevent the leakage of user information and unauthorized access.
[0023] Specifically, a unified user information model is the foundation for cross-system user data integration. For example, a standard model can be defined that includes common fields such as user ID, name, gender, age, and contact information. During the attribute mapping process, user attributes from different systems need to be converted to the format of the unified model. For example, the "user_name" field in System A is mapped to the "name" field in the unified model, and the "gender" field in System B is mapped to the "gender" field. This standardization helps eliminate data format inconsistencies. Message queue technology plays an important role in achieving real-time synchronization of user data in a distributed environment. A data synchronization channel can be established using messaging middleware such as RabbitMQ or Kafka. When a user in System A changes their phone number, a message containing the user ID and the new phone number is published to a queue. System B, upon subscribing to the queue and receiving the message, updates the corresponding phone number in its local database, thus maintaining data consistency across systems. Data conflicts may occur during data synchronization. For example, if a user's email address is changed simultaneously in System A and System B, the conflict needs to be resolved according to predefined priority rules. System A can be given a higher priority than System B, so that the data in System A prevails. Alternatively, a timestamp strategy can be adopted to retain the most recent modification. This mechanism ensures that all systems ultimately reach consensus on user information. Cross-system user identity verification is key to integrating user data across different systems. Matching can be based on user attribute similarity, such as comparing key attributes like name, mobile phone number, and ID number. For example, if two systems have user records with the exact same name and the last four digits of their mobile phone number, they can be considered the same user. Introducing machine learning algorithms can improve matching accuracy. Decision tree models trained on historical data can learn the importance of different attribute combinations in determining user identity, allowing for more accurate identification of the same user across systems. Throughout this process, user data security and privacy protection are paramount. Sensitive information, such as ID numbers, can be desensitized, retaining only the last four digits. SSL / TLS encryption is used during data transmission to ensure data security during network transmission. Symmetric encryption algorithms, such as AES, can be used to encrypt sensitive fields during storage, with strict control over access to the key. These measures effectively prevent the risk of user information leakage and unauthorized access. By establishing a unified user information model, achieving real-time data synchronization, resolving data conflicts, performing cross-system identity recognition, and taking security protection measures, we can achieve effective integration and consistent management of user information in a distributed environment while ensuring data security, providing enterprises with a comprehensive and accurate user view, and supporting better business decisions and user services.
[0024] By establishing a unified user information model, mapping the user attributes of each system to the model, adopting a distributed data synchronization mechanism, and using message queue technology to achieve real-time data synchronization between systems, the accuracy of data conversion and mapping is judged based on the consistency of identity information, and a standardized user data representation between systems is obtained.
[0025] Based on business needs, design a unified user information data model, determine the attribute fields and their data types, constraints, etc. Analyze the user data structure of each system, identify the corresponding relationship with the unified model, and construct attribute mapping rules. Use distributed database technology to build a cross-system user information storage architecture that supports horizontal expansion and high availability. Design a suitable message queue model for the data update scenario of each system, such as a publish-subscribe model or a point-to-point model. Deploy a data synchronization module in each system to capture user information change events and write the changes to the message queue. The data synchronization module reads the change messages from the message queue, performs data conversion according to the attribute mapping rules, and updates the user information of the target system. By comparing key identity information such as user ID, mobile phone number, email address, etc., the accuracy of data synchronization is judged to ensure the consistency of user data across systems.
[0026] Specifically, a unified user information data model is the foundation for achieving cross-system user data consistency. The design should consider user attributes across various systems, such as basic information, account status, and permissions. For example, a model can be defined containing fields such as user ID, name, mobile number, email address, registration date, and account status. Unique attributes across different systems can be accommodated through extended fields. Developing attribute mapping rules requires in-depth analysis of the data structures of each system. For example, "user_name" in System A corresponds to "name" in the unified model, while "mobile_phone" in System B corresponds to "mobile number." This mapping can be maintained in configuration files or database tables, facilitating subsequent adjustments and expansion. Distributed database technologies such as Apache Cassandra or MongoDB can be used to build a cross-system user information storage architecture. These databases support data sharding and replication, enabling horizontal scalability and high availability. For example, sharding can be performed by user ID range, distributing user data for different ranges across multiple nodes to improve query efficiency and system capacity. The choice of message queue model depends on the specific business scenario. For scenarios requiring the broadcast of user information changes, a publish-subscribe model, such as Apache Kafka, can be adopted. Each system, acting as a producer, publishes change messages, and other systems, acting as consumers, subscribe to and process these messages. For point-to-point data synchronization, a message queue supporting a point-to-point model, such as RabbitMQ, can be used. The design of the data synchronization module should consider exception handling and retry mechanisms. For example, when a user information change is detected, the change is first written to the local transaction log and then asynchronously sent to the message queue. If the send fails, a scheduled task can be used to retry, ensuring eventual data consistency. During data conversion, issues such as data type inconsistencies and field length limits need to be addressed. For example, a date formatted as "YYYY-MM-DD" in system A may be converted to the "YYYYMMDD" format required by system B. Data exceeding the field length limit can be truncated or compressed, and logged for subsequent manual processing. Data synchronization accuracy can be verified through multiple validation steps. First, a unique identifier, such as the user ID, is used for matching. Second, key information, such as mobile phone numbers and email addresses, is compared for consistency. Finally, a hash value can be calculated to quickly determine complete data consistency. If an inconsistency is detected, an alert can be triggered and the data repair process initiated. This cross-system user data synchronization solution effectively resolves the issue of inconsistent user information across multiple systems, improving data quality and business processing efficiency. Furthermore, through distributed architecture and message queue technology, it enhances system scalability and reliability, providing strong support for enterprises' digital transformation.
[0027] S102. When synchronizing user identity information, the interface protocols of each system are adapted and converted to achieve compatibility between different protocols. To address issues such as data loss and duplication that may arise during synchronization, a data verification and fault-tolerance mechanism is introduced to verify the integrity of synchronized data. Ultimate data consistency is ensured through retransmission, thereby improving the success rate of identity authentication.
[0028] According to the user identity information, the interface protocol type of the source system and the target system that need to be synchronized is obtained; for different interface protocol types, the corresponding protocol adaptation rules are obtained from the pre-established protocol adaptation rule library; the protocol adaptation rules are used to perform protocol conversion on the user identity information of the source system to obtain user identity information that complies with the interface protocol of the target system; the converted user identity information is synchronized through the interface of the target system, and the synchronization result is obtained; according to the preset data verification rules, the integrity of the synchronized user identity information is verified. If the verification fails, the user identity information that failed to synchronize is added to the retransmission queue; the user identity information that failed to synchronize is obtained from the retransmission queue in turn, and steps 3 and 4 are re-executed until the number of retransmissions reaches the preset threshold or the synchronization is successful; according to the synchronization result and the verification result, it is determined whether the user identity information is synchronized and consistent. If it is consistent, the identity authentication is determined to be successful, otherwise the authentication fails.
[0029] Specifically, during the user identity information synchronization process, the interface protocol types of the source and target systems must be determined. These protocols may include REST API, SOAP, GraphQL, and more. For example, the source system may use REST API, while the target system uses SOAP. To implement conversion between different protocols, a protocol adaptation rule library must be established. This rule library contains mappings and conversion methods between various protocols. Taking the conversion from REST API to SOAP as an example, adaptation rules may include mapping HTTP methods to SOAP operations and converting URL parameters to SOAP message bodies. Suppose the source system has a REST API for retrieving user information: GET / users / {id}. The corresponding SOAP request might be an operation named "GetUserInfo," which requires the user ID to be included in the SOAP message body. During the protocol conversion process, the system converts the REST request into a SOAP request based on the adaptation rules. This involves constructing the SOAP envelope, setting the correct namespace, and converting REST parameters into the SOAP message body. The converted user identity information is then synchronized through the target system's SOAP interface. After synchronization is complete, the system verifies the synchronization results. Verification rules may include checking required fields, data format validation, and business logic validation. For example, they may check whether the username is blank, the email address is in the correct format, and the age is within a reasonable range. If a user's information fails verification, the record is added to the retransmission queue. The retransmission mechanism is key to ensuring data synchronization reliability. The system retrieves failed records from the retransmission queue and retrys the protocol conversion and synchronization process. To avoid infinite retries, a retransmission threshold is typically set, such as a maximum of three retries. If the threshold is reached and the synchronization still fails, the system may mark the record as requiring manual intervention. Finally, the system determines whether the user's identity information is synchronized based on the synchronization and verification results. This determination process may involve comparing multiple dimensions, such as basic user information, permissions, and associated accounts. Identity authentication is considered successful only when all key information is consistent. The advantage of this protocol adaptation and synchronization mechanism is that it enables seamless data exchange between heterogeneous systems, improving the flexibility and scalability of system integration. Furthermore, the introduction of verification and retransmission mechanisms significantly improves the reliability and consistency of data synchronization. This is of great significance for scenarios that require identity authentication across multiple systems, such as single sign-on between multiple business systems within an enterprise.
[0030] S103. To balance group policy configuration with system performance, a dynamic policy configuration method is employed. The granularity and strictness of group policy are dynamically adjusted based on real-time system performance indicators, such as CPU utilization and memory usage. When the system load is high, policy restrictions are appropriately relaxed; when the system load is low, policy control is strengthened. At the same time, fine-grained permission control is implemented for key data access operations to reduce unnecessary data access, thereby ensuring data security while minimizing the impact on system performance.
[0031] System performance indicator data is obtained as a policy management dataset, including four data types: system CPU usage, memory utilization, hard disk read / write rates, and network throughput. Performance data is collected at fixed time intervals over a period of time. Time series data processing algorithms are applied to remove data values that deviate by more than two standard deviations from the mean based on temporal characteristics. Feature data mining is performed on the performance dataset. Based on the performance data output in the previous step, principal component analysis is used to generate several main components reflecting different load types, resulting in a set of system load states over a period of time. States above the set threshold in this dataset are matched to the group policies at the corresponding time. The group policy dataset is separated into permissions and access. Based on the policy list corresponding to the system load state obtained in the previous step, rules related to access operations and permission control are extracted from the group policies. Regular expressions are used to perform data hiding on other types of rules unrelated to access operations and permission control, and the cleansed rules are output. Training datasets with different loads and policies are constructed. Based on the data in the rule base, a stratified sampling strategy is used to establish three levels of system load: high, medium, and low, as well as two corresponding fine-grained and coarse-grained group policies for each state. According to the corresponding configuration of the group policy, the K-means algorithm, DBSCAN algorithm and Gaussian mixture algorithm are integrated to determine the distribution structure of the data set and obtain the different distribution structure parameters of each data set. The group policy generates a model and configures the parameters. The model parameters are configured using the corresponding parameters of the group policy output in the fourth step. According to the load data characteristics and rules obtained in the fourth step, the decision tree algorithm is applied to determine which type of model corresponds to the load. The access control data is split into different entity nouns using a word segmentation tool, and the entity list is obtained by comparing the entity similarity. After obtaining the entity list data, the access data is classified by comparing the access paths, merging the operation types, and obtaining a simplified set of access rules. For the simplified access rules, the corresponding permission information of each user is compared using text similarity technology. After obtaining the mapping table of rules and permissions. If the permissions corresponding to the rules are the same, the group policy settings are modified.
[0032] Specifically, to obtain system performance indicator data as a policy management dataset, the data type must first be determined, such as system CPU usage, memory utilization, disk read / write rates, and network throughput. Suppose a server collects data every 5 minutes for an hour, resulting in 12 sets of data. Applying a time series data processing algorithm, the mean and standard deviation of these data sets are calculated, and outliers exceeding two standard deviations from the mean are removed. For example, if the mean of CPU utilization is 60% and the standard deviation is 5%, data exceeding two standard deviations from the mean (i.e., exceeding 70% or falling below 50%) is removed. Eigenvalue data mining is performed on the performance dataset. Principal component analysis (PCA) is used to reduce the multidimensional data to generate principal components that reflect different dimensional load types. Assume that PCA analysis yields three principal components, representing compute load, memory load, and network load. The set of these principal components describes the system load status over a period of time. The data sets that exceed the set threshold are then matched with the group policy at that time. Assuming a threshold of 80%, load states above this threshold are marked as high and matched against the current group policy to analyze whether the policy applied under high load is appropriate. The group policy dataset is separated into permissions and access, extracting rules related to access operations and permission control. For example, a group policy contains two rules: "Allow user A to access file B" and "Prohibit user C from executing program D." These rules are extracted using regular expressions, and irrelevant rules are hidden, outputting the cleaned rules. A training dataset with different loads and policies is constructed. Using a stratified sampling strategy, three levels of system load are established: high, medium, and low, along with fine-grained and coarse-grained group policies corresponding to each level. For example, in a high-load scenario, the fine-grained policy might include "Limiting CPU usage to no more than 85%," while the coarse-grained policy might include "Prioritizing core business operations." The K-means algorithm, DBSCAN, and Gaussian mixture algorithms are integrated to determine the distribution structure of the dataset. For example, the K-means algorithm discovered that the dataset exhibited three cluster centers, corresponding to high, medium, and low load states, respectively. The DBSCAN algorithm identified dense areas under high load conditions, and the Gaussian mixture algorithm further refined the distribution parameters for each state. The group policy generation model configured parameters and applied a decision tree algorithm based on load data characteristics and rules to determine which model type corresponds to the load. For example, the decision tree algorithm determined the appropriate fine-grained policy under high load conditions based on characteristics such as CPU utilization and memory usage. Access control data was segmented using a word segmentation tool to break it down into distinct entity nouns. Entity similarities were then compared to generate an entity list. For example, "User A accesses file B" was split into "User A" and "File B," and similar entities were merged through similarity calculations. The simplified access rules were then compared with the corresponding permission information for each user using text similarity techniques.For example, the rule "Allow user A to access file B" is compared with the permission information "User A has read permission for file B" for similarity to confirm the mapping relationship between the rule and the permission. After obtaining the mapping table of rules and permissions, if the permissions corresponding to the rules are the same, the group policy settings are modified. For example, if it is found that multiple rules allow user A to access file B, this permission is set as the default permission to simplify the group policy configuration. Through the above steps, not only the accurate collection and processing of system performance data is achieved, but also the generation and application of group policies are optimized through multi-dimensional analysis and intelligent matching, thereby improving the stability and security of the system. Each step is linked together to form a complete policy management system to ensure that the system can run efficiently under high load and user permissions are reasonably controlled.
[0033] Dynamically adjust the granularity and strictness of group policies based on real-time system performance indicators such as CPU occupancy and memory usage. By relaxing policy restrictions when the system load is high and strengthening control when the load is low, fine-grained access rights are used to control key data operations and reduce unnecessary access. This ensures data security while reducing the impact on system performance and achieving a balance between policy configuration and performance.
[0034] The monitoring module continuously collects CPU usage and memory usage of the current device to determine the system load status. It then constructs a group policy based on the system load status, creating a mapping table between loads and group policies within a preset time range. Each load in the mapping table is associated with at least one group policy, and different load ranges have group policies with varying degrees of strictness. A fine-grained access rights association list is constructed from group policies and key data operation types, with a one-to-many mapping relationship between group policies and access rights to determine the control strategy. After obtaining the device's current group policy and operation request information in real time, it extracts permitted operations from the fine-grained access rights association list, and configures blocking permissions for other operations not listed. A decision tree algorithm is used to construct an access rights control model. The decision tree inputs real-time load data and fine-grained access request data to determine whether access is permitted. Based on this information, it determines whether the operation should be executed. Historical load data passing through the model is statistically analyzed at preset time intervals. The group policy identifies the load range with the highest frequency during that time period and its corresponding access rights table to determine the frequency of access rights control model rule updates. The Gaussian process regression algorithm is used to input load, access permission data, and historical data on the impact of adjusted group policies on performance. This method obtains the direction of improving the prediction model, determines the direction of group policy adjustment, and the optimal access permission control, and obtains a dynamically optimized control model.
[0035] Specifically, the monitoring module continuously collects CPU and memory usage data on the current device to determine the system load status. For example, suppose a server's CPU utilization reaches 85% and its memory utilization reaches 80% during peak hours, while during off-peak hours, the CPU utilization is only 30% and the memory utilization is 40%. Using this data, the system can determine whether it is currently in a high or low load state. Group policies are constructed based on the system load status, mapping loads to group policies within preset time ranges. For example, a high load range might be defined as CPU utilization exceeding 75% and memory utilization exceeding 70%, a medium load range as CPU utilization between 50% and 75% and memory utilization between 50% and 70%, and a low load range as CPU utilization below 50% and memory utilization below 50%. In high load states, a more permissive group policy is employed to reduce system burden; in low load states, a stricter group policy is employed to strengthen security control. A fine-grained access permission association list is constructed from group policies and key data operation types. Assume there are three key data operation types: read, write, and delete. Under high load conditions, only read operations may be allowed; under medium load conditions, read and write operations may be allowed; and under low load conditions, all operations may be allowed. A one-to-many mapping relationship exists between group policies and access rights, ensuring the system can flexibly adjust access rights under varying loads. After obtaining the device's current group policy and operation request information in real time, the system extracts permitted operations from the fine-grained access rights association list. For example, if the system is under high load and a user requests a data write operation, the system will determine based on the association list that the operation is not permitted and configure a blocking permission to ensure unimpeded system performance. A decision tree algorithm is used to construct an access rights control model. Real-time load data and fine-grained access request data are input to determine whether access is permitted. Assume that the decision tree model divides decision nodes based on CPU utilization and memory usage, ultimately outputting a decision of whether to allow or block. Based on this information, the system determines whether to execute the operation, ensuring that critical services are prioritized during high load conditions. Historical load data is collected at preset intervals, and the group policy identifies the load range with the highest frequency during that period and the corresponding access rights table to determine the frequency of access rights control model rule updates. For example, if statistics show that the system was most frequently under high load over the past week, the access rights rules for these high-load states will be updated first to ensure the model adapts to actual operating conditions. Using a Gaussian process regression algorithm, we input load and access rights data, as well as historical data on the performance impact of adjusted group policies, to identify areas for improving the predictive model. If Gaussian process regression analysis reveals that relaxing certain access rights within a specific load range significantly improves system performance, the system will adjust the group policy accordingly to optimize access rights control. By determining the direction of group policy adjustments and the optimal access rights control, we develop a dynamically optimized control model.For example, after multiple iterations of optimization, the system discovered that moderately relaxing write permissions under moderate load conditions did not significantly impact performance, but improved the user experience. Therefore, the system adjusted group policies to allow more write operations under moderate load conditions. Through these steps, the system dynamically adjusts group policies and access permissions based on real-time load conditions, ensuring both system performance and data security. This dynamically optimized control model not only effectively addresses performance requirements under varying load conditions but also continuously optimizes itself based on historical data, improving the system's overall operational efficiency and security. The monitoring module's continuous data collection and real-time adjustments ensure stable system operation under varying load conditions. The construction of a fine-grained access permission association list enables the system to flexibly respond to various operation requests while ensuring security. The application of the decision tree algorithm provides a scientific basis for decision-making, while the introduction of the Gaussian process regression algorithm provides strong support for continuous model optimization. This multi-level, multi-dimensional dynamic optimization strategy significantly improves the system's overall performance and management efficiency.
[0036] S104. In the three-dimensional security protection linkage of cloud, network, and terminal, by defining a unified security event format and data exchange interface, data format compatibility and seamless connection between various security components are achieved. A linkage architecture based on a message bus is adopted, connecting each security component to a unified message bus, and achieving real-time information sharing and linkage between components through a publish-subscribe mechanism.
[0037] Each security component obtains a template definition file in a standardized security event format through a preset method. This definition file is used to generate a structured security event data file, resulting in a standardized representation of all security event data. Security event identifiers are associated with features to determine the threat level and classification label of the security event. If the threat level of a security event is high and the classification label is malicious, the event is sent to a pre-established security event priority queue, which outputs statistics on the time and number of security events sent. An index table is constructed based on the time and type information of the security events, creating a security event index library that enables efficient retrieval. A list of all index nodes in the security event index library is obtained and distributed to multiple processing server clusters for security event rule matching. The security analysis engine then aggregates anomalous access events from the same source. The total security event count is calculated for each source IP address. The security analysis engine integrates an anomaly detection algorithm based on statistical learning. Based on the aggregated results of all security event type labels and occurrence frequencies, the labels are sorted in descending order of frequency to generate a table of hot security event labels. By setting a threshold for event frequency, labels with frequencies within this threshold are merged into similar items to determine the topic label of the security incident. Security event merging technology is implemented using a machine learning algorithm. The interface connection protocols and communication addresses of each security component are obtained. Multiple security components with the same topic label are aggregated and processed as objects, outputting a group of collaborative components. The frequency of security events generated by any component in each collaborative component group is used to determine the time offset between that component and other components in the group. Intelligent component linkage is achieved by training a collaborative action decision model based on a convolutional neural network. Reinforcement learning algorithms are used to learn and optimize the coordination mechanism between components. Monitoring and collection components deployed on the network, cloud, and terminals collect real-time information streams, obtain data interaction statistics on real-time data communication within the collaborative component group, and determine whether collaborative actions occur within a time window. A graph database is used to store the connection relationships between components. Based on predefined collaborative action semantics and logical relationships, the information flow determines whether to trigger corresponding collaborative policy adjustments. If a coordinated action that meets the preset trigger conditions is identified within a certain time window, a dynamic adjustment mechanism is triggered to modify and update the event notification matrix. By comparing the changes in multiple cycles before and after the event, the final fitness score of the component group is obtained. If the fitness score exceeds the set threshold, the coordinated action is considered profitable, and the score is used as reward feedback to iteratively adjust the policy model parameters.
[0038] Specifically, each security component obtains a template definition file in a standardized security event format through a preset method, and uses this definition file to generate a security event structured data file to obtain a standardized expression of all security event data. For example, a company's security system uses a template definition file in JSON format, which defines fields such as event ID, event type, source IP, target IP, and timestamp. Through this template, the system converts raw log data into structured data, such as `{"eventID":"12345",
[0039] "eventType":"SQL injection", "sourceIP":"192.168.1.1",
[0040] "dest inat ionIP":"10.0.0.1", "timestamp":"2023-10-01T12:00:00Z"}` ensures data consistency and processability. Security event identifiers are associated with features to determine the threat level and classification label of security events. Assume that the system categorizes events into three threat levels: low, medium, and high, based on the event type and the reputation score of the source IP. For example, if a SQL injection attack from a known malicious IP is detected, the system will mark it as high-risk, classify it as "Malicious Attack Event," and immediately send it to a pre-established security event priority queue. The queue output shows that 50 high-risk events were received in the past 24 hours, primarily concentrated in the early morning hours. After statistics are compiled, an index table is constructed using the time and type information of these security events, resulting in an efficient searchable security event index. For example, the index table records the ID, time, and type of each event. Using inverted indexing, it can quickly locate events of a specific type or time range. The system returns results in milliseconds when querying "SQL injection attacks in the past week." By obtaining a list of all index nodes in the security event index database and distributing these nodes to multiple processing server clusters for security event rule matching, the security analysis engine then aggregates anomalous access events from the same source. For example, an enterprise's security analysis engine, integrated with a statistical learning-based anomaly detection algorithm, discovers that the source IP address "192.168.1.1" frequently accesses multiple sensitive ports within a short period of time. The system classifies this as "potential scanning behavior" and counts the total number of events for this IP address as 100. Based on the aggregated results of all security event type tags and their frequency of occurrence, the tags are sorted in descending order by frequency to produce a table of hot security event tags. For example, the system displays "SQL injection," "DDoS attack," and "phishing email" as the top three hot tags, with frequencies of 500, 300, and 200, respectively. By setting a frequency threshold range, such as 100-300, "DDoS attack" and "phishing email" are merged into the "network attack" topic tag. This security event aggregation technology is implemented using a machine learning algorithm. For example, clustering algorithms can be used to group similar events together, further refining topic labels. The interface connection protocols and communication addresses of each security component are obtained. Multiple security components with the same topic labels are aggregated and processed as objects, outputting a set of collaborative component clusters. For example, if an enterprise's firewall, IDS, and antivirus software all report "cyber attack" events, the system will aggregate them into a collaborative component cluster. The frequency of events generated by any component can be used to analyze the time offset between components. Intelligent processing of component linkage is achieved by training a collaborative action decision model based on a convolutional neural network.For example, based on historical data, the model learns that when a firewall detects a large amount of malicious traffic, the IDS should immediately increase monitoring and the antivirus software should initiate a deep scan. A reinforcement learning algorithm is used to learn and optimize the coordination mechanism between components. Through trial and error, the model finds the optimal linkage strategy. Monitoring and collection components deployed on the network, cloud, and terminals collect real-time information flows, capturing data interaction statistics for real-time data communication within the current collaborative component group. Within a time window, it determines whether inter-component communication behaviors are coordinated. For example, if the system detects a significant increase in communication frequency between the firewall, IDS, and antivirus software within 5 minutes, it determines that coordinated action has occurred. A graph database is used to store the connections between components. In a graph database, nodes represent components and edges represent communication relationships. By analyzing the graph's topology, key nodes and paths are identified. Based on predefined coordinated action semantics and logical relationships, the information flow determines whether to trigger corresponding coordinated policy adjustments. For example, if the system's default rule is "When a firewall issues an alarm and the IDS confirms an attack, initiate an antivirus scan," a policy adjustment is triggered when the conditions are met. If a coordinated action that meets the preset trigger conditions is identified within a certain time window, a dynamic adjustment mechanism is triggered to modify and update the event notification matrix. By comparing the changes over multiple cycles before and after the event, the final fitness score of the component group is obtained. For example, after the system strategy adjustment, the number of attacks decreased by 30%, and the fitness score increased to 85 points, exceeding the set threshold of 80 points. The coordinated action is considered beneficial, and the score is used as reward feedback to iteratively adjust the strategy model parameters, further improving the system's defense capabilities.
[0041] S105: For security component linkage policy configuration, a rule-based engine is used to abstract the linkage policy into a series of rules. This engine dynamically matches and handles security incidents. Based on the severity and impact of a security incident, the corresponding linkage rules are triggered, invoking relevant security components for coordinated protection, achieving accurate and efficient security incident response.
[0042] Security log data streams are acquired and data preprocessing methods are used to clean noise and extract structured feature data, such as event occurrence time, involved IP addresses, and request behavior data from the original log text. A streaming computing framework is used to parse security logs in real time, generating events to be classified based on the event time window. A time series graph is constructed using log information, with vertices representing log objects and edges representing relationships between objects. Associated data includes the type, number of resource accesses, and time differences. A risk status detection method is constructed based on a set of pre-set event rules. A random forest algorithm is used to train a rule tree, inputting feature vectors and status labels. A risk scoring function is generated to assess the degree of anomalies in security logs and predict behavioral evolution trends. The resulting security status classification results are compared against a baseline for detection. When a pre-set deviation threshold is exceeded, an alarm is triggered, the current event is recorded, and stored in an event information database. The event level is determined by the severity of the event. Based on the information stored in the event information database, different security devices are triggered to perform behavioral actions. Different security devices receive different types of security information for diversion and processing, and data from the processing devices is collected. The system captures the IP address access relationships involved in the event and performs real-time tracing, creating access path diagrams, statistically analyzing changes in request data traffic, and predicting risk trends based on multivariate time series prediction methods. After generating prediction results based on risk trends, the system dynamically adjusts rule engine parameters, automatically adjusting the corresponding rule base weights based on risk, optimizing the configuration ratio of rule entries, and outputting optimization strategies to guide the decision-making process.
[0043] Specifically, capturing security log data streams is fundamental to network security analysis. Security devices deployed at network perimeters and key servers can collect raw data such as network traffic and system logs in real time. For example, firewalls can log network connection requests, intrusion detection systems can detect suspicious network behavior, and web application firewalls can record HTTP request information. These raw logs often contain a large amount of redundant and irrelevant information, requiring data preprocessing and cleaning. During data preprocessing, techniques such as regular expression matching and field extraction can be used to extract key information from the raw logs. For example, fields such as request time, source IP address, target URL, and request method can be extracted from HTTP request logs. Data standardization is also necessary, such as converting time in different formats to a standard timestamp format. These processes transform unstructured raw logs into structured feature data, facilitating subsequent analysis. Using streaming computing frameworks such as Apache Flink to parse real-time logs, events can be grouped by time windows (e.g., 5-minute windows). A time series graph is constructed based on the grouped events. Vertices in the graph can represent IP addresses or servers, while edges represent the access relationships between them. Edge attributes can include statistical information such as the number of accesses and average response time. This graph structure can intuitively represent the interaction patterns between entities in a network. The random forest algorithm is an ensemble learning method that constructs multiple decision trees and performs classification by majority voting. For security incident detection, the random forest model can be trained using historically labeled data. Input features can include IP reputation scores, access frequency, and request payload characteristics, while the output is a label of normal or abnormal. The trained model can be used to evaluate new log events in real time and assign a risk score. When an abnormal event is detected, the system triggers an alert and records detailed information. For example, if a certain IP address makes multiple failed login attempts within a short period of time, it may be a brute force attack. The system records information such as the attack source IP address, attack time, and number of attempts, and determines the event severity based on pre-set rules, such as classifying such an event as high risk. Based on this recorded event information, the system can automatically trigger appropriate security devices to take action. For example, if a brute force attack is detected, the firewall can be instructed to temporarily block access to the IP address and the web application server can be instructed to strengthen protection for the account. Different types of security events are distributed to corresponding response devices, such as DDoS attacks handled by traffic scrubbing devices and malware infections handled by endpoint security software. By analyzing the IP address access relationships involved in an incident, we can map the attack path. For example, in an APT attack, we might observe attackers first compromising edge servers and then moving laterally to critical internal network servers. Combining historical data with time series analysis methods like ARIMA models can predict future attack trends and provide decision support for security operations.Based on predictions, the system can dynamically adjust the parameters of the rule engine. For example, if a certain type of attack is predicted to increase, the weight of the relevant detection rules can be increased, and the sampling frequency can be increased to improve the detection rate. At the same time, based on the number of false positives, the weight of overly sensitive rules can be appropriately reduced to balance detection effectiveness and system load. This adaptive mechanism enables the security protection system to continuously optimize and enhance its ability to respond to new threats.
[0044] S106. During the multi-dimensional security protection linkage process, machine learning algorithms are used to analyze and mine massive amounts of security event data to identify potential security threats and attack patterns. Anomaly detection algorithms, such as isolation forests and one-class support vector machines, are used to model user behavior, network traffic, and other data. The degree of deviation from the normal model is used to determine whether abnormal behavior exists, enabling real-time detection and early warning of unknown threats.
[0045] Security logs from multiple heterogeneous devices are acquired and decoded using message parsing technology. Information in non-standard data formats is converted into standard structured information for storage, resulting in a pre-processed data set that complies with the algorithm. A time window is selected based on the attack model, and characteristic information about attack behaviors in the log data is collected. A minimum support value for each security event type is set for each security domain. Each security log entry is then combined with historical security event behavior rules from each security domain to generate a security log set within each time window. Clustering is then applied to the data over the specified time period to obtain abnormal attack data for each security domain. Access source and boundary point information is extracted from the abnormal behavior data and attacker information occurring per unit time. A correlation graph model is constructed between access sources and boundary point accesses to determine the correlation between two attack behaviors and a set threshold. A behavior chain model is then constructed between nodes to obtain the relevant path information for the behavior chain. The behavior chain path information from multiple datasets is collected as raw network access traffic. The path data is vectorized and fed into a trained single-class support vector machine model to obtain the value of the trained classification hyperplane. The system determines whether an anomaly exists by comparing it to a set threshold. If so, it performs a similarity analysis on the abnormal behavior chain, determines the threat level, and then records the alarm information in the association rule database. Based on the definition of security status, the threat alarm is classified according to the security status information of the threat event according to the rules. The frequency and distribution of alarms in different security states are statistically analyzed to obtain information on the switching model between each security state. The vectorized data of the state transition behavior determined in real time is processed by the isolation forest model. If the deviation from the security state exceeds the safety value, the abnormal risk is output. Based on the output, the corresponding disposal strategy is implemented to prevent the attack behavior from causing harm to other security domains.
[0046] Specifically, the acquisition and preprocessing of security logs from multiple, heterogeneous devices is fundamental to security analysis. For example, the log formats generated by devices such as firewalls, intrusion detection systems, and application servers vary, requiring packet parsing technology to convert them into standardized structured information. This process may involve operations such as field extraction, timestamp unification, and IP address normalization, ultimately resulting in a dataset that is easy to analyze. To extract attack behavior features, a suitable time window, such as five minutes, can be selected to count metrics such as the number of abnormal connections and failed login attempts within that timeframe. For web application security, the characteristics of typical attack patterns such as SQL injection and cross-site scripting can be focused on. By setting a minimum support threshold, such as requiring a certain type of event to occur more than ten times within five minutes, low-frequency noise can be effectively filtered out, focusing on potentially high-risk behaviors. Cluster analysis can help uncover hidden attack patterns. For example, using the K-means algorithm to cluster features such as IP addresses, ports, and protocols may reveal the hallmarks of distributed denial of service attacks—a large number of source IP addresses initiating similar requests to the same target. This approach can identify complex attack behaviors that are difficult to detect using a single metric. Building an access correlation graph model is key to understanding attack paths. Suppose internal server A frequently accesses external IP address B, and B establishes connections with multiple internal hosts. This may indicate that A is being used as a springboard to attack other internal resources. By setting a correlation threshold, such as a connection frequency between two nodes exceeding 100 times per minute, highly correlated behavior chains can be identified. Vectorization of behavior chain path information is a prerequisite for applying machine learning models. Path information can be converted into feature vectors, such as source IP address, destination IP address, protocol type, and duration. Using a trained support vector machine model, it is possible to quickly determine whether a newly emerging behavior chain is anomalous. For example, if the distance between a path's feature vector and the decision boundary of known normal behavior exceeds a preset threshold, it may be classified as an anomaly. Threat level classification is crucial for resource optimization. Threats can be categorized as low, medium, or high based on factors such as attack duration, impact scope, and potential damage. High-level threats may require immediate human intervention, while low-level threats can be temporarily handled by automated systems. Security state transition models help understand the evolution of attacks. For example, states such as "normal," "alert," "attack," and "recovery" can be defined, and the frequency of transitions between these states can be measured. If you notice frequent jumps from "normal" to "attack," it may indicate that existing early warning mechanisms are insensitive and require adjustment. The application of the Isolation Forest algorithm in anomaly detection demonstrates its ability to process high-dimensional data. By calculating the isolation degree of each data point, it can effectively identify anomalous behaviors that are difficult to detect using traditional statistical methods. For example, if a server suddenly experiences a large number of connection requests to an uncommon port, while the individual requests may appear normal, the overall pattern deviates significantly from historical data. In this case, the Isolation Forest algorithm can assign a higher anomaly score.Finally, executing appropriate action strategies based on detection results is a key step in closed-loop security management. For example, for high-risk IP addresses detected, their access rights can be temporarily blocked at the perimeter firewall. For suspicious internal hosts, their network bandwidth can be restricted or additional authentication can be required. These measures can effectively prevent the further spread of attacks and protect the security of critical assets.
[0047] S107. Combine machine learning algorithms with expert experience to automate security incident analysis and decision-making through artificial intelligence. Employing a reinforcement learning-based algorithm, policies are adaptively adjusted based on the effectiveness of security incident handling, continuously optimizing linkage strategies and enhancing the intelligent level of security protection. Furthermore, visualization technology is used to present complex security incidents and linkage processes in an intuitive manner, assisting security administrators in analysis and decision-making, and improving the efficiency and accuracy of human-machine collaboration.
[0048] Data related to security incidents, including incident type, severity, and time of occurrence, is collected and fed into a machine learning model for analysis. Using a reinforcement learning-based algorithm, the current incident handling strategy is adaptively adjusted and optimized based on the effectiveness of handling historical security incidents. The machine learning model's analysis results are supplemented and revised using a knowledge base of expert experience, improving the accuracy and reliability of the strategy. If the severity of a security incident exceeds a preset threshold, an automated linkage mechanism is triggered to rapidly resolve the incident according to the optimized strategy. During the linkage process, incident handling data is collected in real time and fed back to the reinforcement learning algorithm to continuously optimize the strategy. Visualization technology presents the security incident analysis results and linkage process in charts, flow charts, and other formats, facilitating intuitive understanding and decision-making by security administrators. The AI system interacts and collaborates with security administrators, who can adjust the system's analysis and decision-making based on their professional experience, improving the efficiency and accuracy of human-machine collaboration.
[0049] Specifically, acquiring data related to security incidents is a critical first step in a three-dimensional security protection linkage. This data includes event type (such as DDoS attacks, malware infections), severity (high, medium, low), and time of occurrence. For example, if an enterprise network detects 100 suspicious login attempts in a single day, the system will record information such as the time, source IP address, and account used for each attempt. This data is then fed into a machine learning model for analysis. Using reinforcement learning algorithms, such as Q-learning or Deep Q Networks (DQNs), decisions can be continuously optimized based on the effectiveness of historical security incident handling. For example, the system may learn that blocking a certain type of IP address is more effective, while blocking another type of IP address may cause unintended consequences for normal business operations, thus favoring the former strategy in future decisions. Introducing an expert knowledge base can compensate for the shortcomings of machine learning models. For example, machine learning models may not be able to accurately identify emerging attack methods in a timely manner. In this case, expert knowledge can provide supplementary guidance. For example, if an attack exploits a newly discovered vulnerability, experts can quickly add relevant rules to guide the system's identification and handling. When the severity of a security incident exceeds a preset threshold, the system triggers an automated linkage mechanism. For example, if a large-scale data breach is detected, the system might automatically execute a series of actions: disconnecting the affected server from the external network, initiating backup and recovery procedures, and notifying relevant personnel. This rapid response can significantly reduce the scope and duration of the security incident. During the linkage response process, the system collects real-time response data and feeds it into the reinforcement learning algorithm. For example, it records the effectiveness of each IP ban and changes in security status after each system patch update. This data is used to further optimize the response strategy, enabling the system to make more accurate decisions in similar situations. The application of visualization technology makes complex security incident analysis results intuitive and easy to understand. For example, heat maps can be used to display attack intensity over different time periods, network topology diagrams can be used to illustrate attack paths, and pie charts can be used to display the proportion of different attack types. These visualization tools help security administrators quickly grasp the overall security situation and make accurate decisions. The collaborative working model between the AI system and security administrators can fully leverage the strengths of both parties. The system can quickly process massive amounts of data and propose preliminary solutions, while security administrators can fine-tune the system's decisions based on experience. For example, the system might recommend blocking a specific IP address range, but the security administrator, knowing that this IP address range includes important customers, can choose a more refined blocking strategy. This human-machine collaboration not only improves decision-making accuracy but also speeds up response times, making the entire security protection system more efficient and reliable.
[0050] The above only lists some preferred embodiments of the present invention, but the present invention is not limited thereto, and many improvements and modifications can be made. As long as the improvements and modifications are made on the basis of the basic principles of the present invention, they should be considered to fall within the scope of protection of the present invention.
Claims
1. A method for integrating domain users and cloud desktop users, characterized in that: The method comprises: For the user identity information of different systems, a unified user information model is established in advance, and the user attributes of each system are mapped to the model to achieve standardized representation of user data between different systems, thereby ensuring the accuracy of data conversion and mapping. At the same time, a distributed data synchronization mechanism is adopted, and message queue technology is used to achieve real-time data synchronization between systems to ensure the consistency of user identity information; When synchronizing user identity information, the interface protocols of each system are adapted and converted to achieve compatibility between different protocols. In order to solve the problems of data loss and duplication that may occur during the synchronization process, a data verification and fault tolerance mechanism is introduced to verify the integrity of the synchronized data, and the final consistency of the data is ensured through retransmission, thereby improving the success rate of identity authentication. In order to strike a balance between group policy configuration and system performance, a dynamic policy configuration method is adopted. According to the real-time performance indicators of the system, such as CPU occupancy rate and memory usage rate, the granularity and strictness of group policies are dynamically adjusted. When the system load is high, the policy restrictions are appropriately relaxed. When the system load is low, the policy management is strengthened. At the same time, fine-grained permission control is performed on key data access operations to reduce unnecessary data access, thereby ensuring data security while reducing the impact on system performance. In the three-dimensional security protection linkage of cloud, network and terminal, by defining a unified security event format and data exchange interface, data format compatibility and seamless connection between various security components are achieved. A linkage architecture based on message bus is adopted to connect various security components to a unified message bus, and real-time information sharing and linkage between components are achieved through a publish-subscribe mechanism. For the linkage strategy configuration of security components, a rule engine-based approach is adopted to abstract the linkage strategy into a series of rules. The rule engine dynamically matches and handles security events. According to the severity, impact range and other attributes of the security event, the corresponding linkage rules are triggered, and the relevant security components are called for collaborative protection, thus achieving accurate and efficient security event response. In the process of three-dimensional security protection linkage, massive security event data is analyzed and mined through machine learning algorithms to identify potential security threats and attack patterns. Anomaly detection-based algorithms, such as isolation forest and one-class SVM, are used to model user behavior, network traffic and other data. The degree of deviation from the normal model is used to determine whether there is abnormal behavior, thereby achieving real-time detection and early warning of unknown threats. Combining machine learning algorithms with expert experience, using artificial intelligence technology to automate analysis and decision-making of security incidents, using algorithms based on reinforcement learning, adaptively adjusting strategies based on the handling effects of security incidents, continuously optimizing linkage strategies, and improving the level of intelligent security protection. At the same time, through visualization technology, complex security incidents and linkage processes are presented in an intuitive way, assisting security administrators in analysis and decision-making, and improving the efficiency and accuracy of human-machine collaboration.
2. The method according to claim 1, characterized in that The user identity information of different systems is mapped to the user attributes of each system into a unified user information model in advance to achieve standardized representation of user data between different systems, thereby ensuring the accuracy of data conversion and mapping; at the same time, a distributed data synchronization mechanism is adopted to achieve real-time data synchronization between systems using message queue technology to ensure the consistency of user identity information, including: According to the pre-established unified user information model, the user attribute data of each system is obtained, and these attribute data are mapped to the corresponding fields in the unified model through the attribute mapping algorithm to obtain a standardized user information representation; In response to the user data synchronization needs in distributed systems, message queue technology is used to establish data synchronization channels between systems; When the user information of a system changes, the change message is published to the message queue; Other systems obtain user information change messages by subscribing to message queues, and update local user data according to the message content to achieve real-time data synchronization in a distributed environment; During the data synchronization process, the user attributes are compared and verified to determine whether there are data conflicts or inconsistencies; If data inconsistency is found, the preset data priority rules will be used to determine which system's data shall prevail, and data overwriting or merging operations will be performed to ensure the final consistency of user information; For cross-system user identity recognition and association, a matching algorithm based on user attribute similarity is used to compare the similarity of user attributes in different systems to determine whether they are the same user and establish a cross-system user identity mapping relationship; In the process of user identity matching, machine learning algorithms such as decision trees and support vector machines are introduced to build a correlation model between user attributes and identities by training historical user data, thereby improving the accuracy of identity recognition and matching; In order to ensure the security and privacy of user information, data desensitization and encryption technologies are used during data synchronization and user identity association to desensitize sensitive user attributes, and encryption algorithms are used to encrypt data transmission and storage to prevent leakage and illegal access to user information. It also includes: establishing a unified user information model, mapping the user attributes of each system to the model, adopting a distributed data synchronization mechanism, using message queue technology to achieve real-time data synchronization between systems, judging the accuracy of data conversion and mapping based on the consistency of identity information, and obtaining standardized user data representation between systems.
3. The method according to claim 2, characterized in that The method establishes a unified user information model, maps the user attributes of each system to the model, adopts a distributed data synchronization mechanism, uses message queue technology to achieve real-time data synchronization between systems, and determines the accuracy of data conversion and mapping based on the consistency of identity information to obtain a standardized user data representation between systems, including: Design a unified user information data model based on business needs, determine each attribute field and its data type, constraints, etc.; Analyze the user data structure of each system, identify the corresponding relationship with the unified model, and build attribute mapping rules; Adopt distributed database technology to build a cross-system user information storage architecture to support horizontal expansion and high availability; Design appropriate message queue models for data update scenarios of each system, such as publish-subscribe mode or point-to-point mode; Deploy data synchronization modules in each system to capture user information change events and write the changes into the message queue; The data synchronization module reads the change message from the message queue, converts the data according to the attribute mapping rules, and updates the user information of the target system; By comparing key identity information such as user ID, mobile phone number, email address, etc., the accuracy of data synchronization can be determined to ensure the consistency of user data across systems.
4. The method according to claim 1, characterized in that: When synchronizing user identity information, the interface protocols of each system are adapted and converted to achieve compatibility between different protocols; in view of the problems of data loss and duplication that may occur during the synchronization process, a data verification and fault tolerance mechanism is introduced to verify the integrity of the synchronized data, and the final consistency of the data is ensured by retransmission, etc., so as to improve the success rate of identity authentication, including: According to the user identity information, the interface protocol types of the source system and the target system to be synchronized are obtained; For different interface protocol types, corresponding protocol adaptation rules are obtained from a pre-established protocol adaptation rule library; The protocol adaptation rule is used to perform protocol conversion on the user identity information of the source system to obtain user identity information that complies with the interface protocol of the target system; The converted user identity information is synchronized through the interface of the target system and the synchronization result is obtained; According to the preset data verification rules, the integrity of the synchronized user identity information is verified. If the verification fails, the user identity information that failed synchronization is added to the retransmission queue; Obtain the user identity information of the users whose synchronization failed from the retransmission queue in sequence, and re-execute steps 3 and 4 until the number of retransmissions reaches a preset threshold or the synchronization succeeds; Based on the synchronization results and verification results, determine whether the user identity information is synchronized and consistent. If it is consistent, the identity authentication is successful, otherwise the authentication fails.
5. The method according to claim 1, characterized in that The balance between group policy configuration and system performance is achieved by adopting a dynamic policy configuration method, dynamically adjusting the granularity and strictness of group policy according to the real-time performance indicators of the system, such as CPU occupancy rate, memory usage rate, etc.; appropriately relaxing policy restrictions when the system load is high; strengthening policy management when the system load is low; at the same time, fine-grained permission control is performed on key data access operations to reduce unnecessary data access, thereby ensuring data security while reducing the impact on system performance, including: Obtain system performance indicator data as a policy management data set, including four data types: system CPU usage, memory occupancy, hard disk read and write rate, and network throughput; Collect performance data at fixed time intervals over a period of time, apply time series data processing algorithms, and remove data values that deviate from the mean by more than two standard deviations based on time characteristics; Perform eigenvalue data mining on performance data sets; Based on the performance data output in the previous step; Through principal component analysis, several main components reflecting different dimensional load types are generated, and the set of system load states over a period of time is obtained; Matching the states in the data set that are higher than the set threshold with the group policy at the corresponding moment; Separate permissions and access to group policy data sets; According to the policy list corresponding to the system load status obtained in the previous step, extract the rules related to access operations and permission control in the group policy, use regular expressions to perform data hiding processing on other types of rules that are not related to access operations and permission control, and output the cleaned rules; Build training datasets for different loads and strategies; Based on the data in the rule base, a stratified sampling strategy is used to establish three levels of system load states: high, medium, and low, as well as two group strategies: fine-grained and coarse-grained. According to the corresponding configuration of the group strategy, the K-means algorithm, DBSCAN algorithm and Gaussian mixture algorithm are integrated to determine the distribution structure of the data set and obtain different distribution structure parameters of each data set; The group policy generates a model and configures parameters; Configure the model parameters through the group policy corresponding parameters output in step 4; Apply the decision tree algorithm based on the load data characteristics and rules obtained in step 4 to determine which type of model corresponds to the load; Access control data, apply word segmentation tools, split it into different entity nouns, and obtain the entity list by comparing entity similarities; After obtaining the entity list data, the access data is classified by comparing the access paths, merging the operation types, and obtaining a simplified access rule set; For the simplified output access rules, the corresponding permission information of each user is compared by using text similarity technology; After obtaining the mapping table of rules and permissions; If the permissions corresponding to the rules are the same, modify the group policy settings; It also includes: dynamically adjusting the granularity and strictness of group policies based on real-time system performance indicators such as CPU occupancy and memory usage, relaxing policy restrictions when the system load is high and strengthening management when the load is low, and using fine-grained access rights to control key data operations and reduce unnecessary access, thereby ensuring data security while reducing the impact on system performance and achieving a balance between policy configuration and performance.
6. The method according to claim 5, characterized in that The system dynamically adjusts the granularity and strictness of group policies based on real-time system performance indicators such as CPU occupancy and memory usage, relaxes policy restrictions when the system load is high and strengthens control when the load is low, and uses fine-grained access rights to control key data operations and reduce unnecessary access, thereby ensuring data security while reducing the impact on system performance and achieving a balance between policy configuration and performance, including: The monitoring module continuously collects the CPU usage and memory usage of the current device to obtain the system load status; Build a group policy based on the system's load status, and build a mapping table between loads and group policies within a preset time range. Each load in the mapping table has at least one group policy corresponding to it, and different load ranges have group policies with different degrees of strictness. Build a fine-grained access rights association list from group policies and key data operation types. There is a one-to-many mapping relationship between group policies and access rights to determine the control strategy. After obtaining the current group policy and operation request information of the device in real time, the allowed operations are extracted from the fine-grained access permission association list, and the access permission is configured to block the other operations outside the list; The access control model is constructed through the decision tree algorithm. The decision tree inputs real-time load data and fine-grained access request data to obtain information on whether access is allowed, and determines whether the operation is executed based on the information obtained; According to the preset time interval, the historical load data is counted, and the load range with the highest frequency in the time period and the corresponding access permission table are found from the group policy to determine the update frequency of the access permission control model rules; The Gaussian process regression algorithm is used to input the historical data of load, access permission data and the impact of adjusted group policies on performance, obtain the direction of improvement of the prediction model, determine the direction of group policy adjustment, and the optimal access permission control, and obtain a dynamically optimized control model.
7. The method according to claim 1, characterized in that In the three-dimensional security protection linkage of cloud, network and terminal, by defining a unified security event format and data exchange interface, data format compatibility and seamless connection between various security components are achieved; a linkage architecture based on a message bus is adopted to connect various security components to a unified message bus, and real-time information sharing and linkage between components are achieved through a publish-subscribe mechanism, including: Each security component obtains a template definition file in a standardized security event format by a preset method, and generates a security event structured data file using the definition file to obtain a standardized expression of all security event data; By associating security event identifiers with features, the threat level and classification label of security events can be determined; If the threat level of a security event is high-risk and the classification label is a malicious attack event, it will be sent to a pre-established security event priority queue, which will output the sending time and number of security events. After statistics, an index table is constructed based on the time and type information of the security event to obtain a security event index library that can be efficiently searched; By obtaining a list of all index nodes in the security event index library, these nodes are distributed to multiple processing server clusters for security event rule matching, and the security analysis engine is used to obtain the merged results of abnormal access events from the same source; Count the total number of security events for each source IP address; The security analysis engine needs to integrate anomaly detection algorithms based on statistical learning; According to the merged results of all security event type labels and occurrence frequencies, the labels are sorted in descending order by frequency to obtain an output hot security event label table; By setting a threshold range for event frequency, the tag sets with frequencies within this threshold range are merged into similar items to determine the topic tag of the security event; Security event merging technology is implemented through machine learning algorithms; Obtain the interface connection protocol and communication address of each security component, aggregate multiple security components with the same subject label as objects, and output them into a group of collaborative component groups. Use the frequency of security events generated by any component in each collaborative component group to obtain the time offset between the component and other components in the same group. Intelligent processing of component linkage is achieved by training a collaborative action decision model based on convolutional neural networks; Use reinforcement learning algorithms to learn and optimize the coordination mechanism between components; By collecting real-time information flows through monitoring and collection components deployed in the network, cloud, and terminals, data interaction statistics of real-time data communication within the current collaborative component group are obtained, and whether collaborative actions occur in the communication behaviors between components within the time window range; Use graph database to store the connection relationship between components; According to the predefined collaborative action semantics and logical relationships, determine whether to trigger the corresponding collaborative strategy adjustment operation through information flow; If a collaborative action that meets the preset trigger conditions is identified within a certain time window, an event notification matrix with a dynamic adjustment mechanism is triggered, modified and updated. By comparing the changes in multiple cycles before and after the event, the final fitness score of the component group is obtained; If the fitness score exceeds the set threshold, the collaborative action is deemed profitable, and the score is used as reward feedback to iteratively correct the policy model parameters.
8. The method according to claim 1, characterized in that The linkage strategy configuration for security components adopts a rule engine-based approach to abstract the linkage strategy into a series of rules, and dynamically matches and handles security events through the rule engine; according to the severity, impact range and other attributes of the security event, the corresponding linkage rules are triggered, and the relevant security components are called for collaborative protection to achieve accurate and efficient security event response, including: Obtain security log data stream, use data preprocessing methods to clean up noise, and extract structured feature data.
9. The method according to claim 1, characterized in that: In the process of three-dimensional security protection linkage, the massive amount of security event data is analyzed and mined through machine learning algorithms to identify potential security threats and attack patterns; anomaly detection-based algorithms, such as isolation forest and one-class SVM, are used to model user behavior, network traffic and other data, and the degree of deviation from the normal model is used to determine whether there is abnormal behavior, so as to achieve real-time detection and early warning of unknown threats, including: Obtain security logs of multi-source heterogeneous devices, decode them using message parsing technology, convert non-standard data format information into standard structured information and store it, and obtain a data set that complies with the algorithm after preprocessing; Select a time window according to the attack model, count the characteristic information of attack behaviors in the log data, set the minimum support of the security event type in each security domain, and fuse each security log with the historical security event behavior rule information of each security domain to obtain the security log set in each time window. By performing clustering algorithm analysis on the data of the set time period, the abnormal attack data in each security domain can be obtained. Extract access source and boundary point information from abnormal behavior data and attacker information that occur per unit time, build a correlation graph model of access source and boundary point access, determine the value of the correlation between two attack behaviors and set a threshold, build a behavior chain model between nodes, and obtain relevant path information of the behavior chain; Collect the behavior chain path information from multiple data sets as the original network access traffic, convert the path data into vectors, and then put the vector into the trained single-classification support vector machine model for processing to obtain the value of the trained classification hyperplane; It is determined whether there is an abnormal situation by comparing it with the threshold of the set plane. If there is an abnormal situation, the similarity analysis step is performed on the abnormal behavior chain. After determining the threat level classification, the alarm information is recorded in the association rule database; According to the definition of security status, the threat alarm is defined according to the rules to define the security status information of the threat event, the occurrence frequency and distribution of different security status alarms are counted, and the switching model information between each security status is obtained; After the vectorized data of the state transition behavior determined in real time is put into the isolation forest model for processing, it is judged that the value of the behavior deviating from the safe state is greater than the safety value and then the abnormal risk is output. The corresponding disposal strategy is executed through the output to prevent the attack behavior from causing harm to other security domains.
10. The method according to claim 1, characterized in that The above-mentioned method combines machine learning algorithms with expert experience to automatically analyze and make decisions on security incidents through artificial intelligence technology; adopts algorithms based on reinforcement learning to adaptively adjust strategies according to the handling effects of security incidents, continuously optimizes linkage strategies, and improves the intelligent level of security protection; at the same time, complex security incidents and linkage processes are presented in an intuitive way through visualization technology, assisting security administrators in analysis and decision-making, and improving the efficiency and accuracy of human-machine collaboration, including: Obtain data related to security incidents, including incident type, severity, and time of occurrence, and input the data into machine learning models for analysis; Adopting a reinforcement learning-based algorithm, the current security incident handling strategy is adaptively adjusted and optimized according to the handling effects of historical security incidents; Through the expert experience knowledge base, the analysis results of the machine learning model are supplemented and corrected to improve the accuracy and reliability of the strategy; If the severity of a security incident exceeds the preset threshold, the automated linkage mechanism is triggered to quickly handle the security incident based on the optimized strategy. During the linkage process, event handling data is collected in real time and fed back to the reinforcement learning algorithm to continuously optimize the strategy; Through visualization technology, the analysis results and linkage process of security events are presented in the form of charts and flow charts, which facilitates security administrators to intuitively understand and make decisions; The artificial intelligence system interacts and collaborates with security administrators, who can adjust the system's analysis and decision-making based on professional experience to improve the efficiency and accuracy of human-machine collaboration.