Intelligent safety management and risk prediction system and method based on cloud computing
By building an intelligent security management and risk prediction system on the cloud computing platform, using multimodal threat analysis, space-time risk prediction and other technical means, the problem that traditional security management methods are difficult to deal with complex security threats is solved, and efficient and accurate security management and risk prediction are achieved.
Patent Information
- Application Number
- CN202510493817.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-19
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-19
AI Technical Summary
Traditional security management methods are difficult to quickly and accurately detect and analyze complex security threats, and cannot meet current security needs, especially in the processing of massive data.
It provides an intelligent security management and risk prediction system based on cloud computing, including multimodal threat analysis module, spatiotemporal risk prediction module, adaptive defense decision-making module, federal model evolution module and intelligent evidence traceability module. Through multimodal feature analysis, threat knowledge graph construction, spatiotemporal risk prediction, adaptive defense decision-making, federal model evolution and intelligent evidence traceability traceability and other technical means, intelligent security management and risk prediction are achieved.
It improves the accuracy and comprehensiveness of threat discovery, reduces the probability of security incidents, achieves efficient and accurate defense, adapts to the ever-changing security threat environment, and continuously improves the intelligent analysis and processing capabilities of the system.
Smart Images

Figure CN120012119A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to an intelligent security management and risk prediction system and method based on cloud computing. Background Art
[0002] As a mode of using public computing resources through the Internet, cloud computing covers various services such as servers, database management, and data storage, and has become a key technology to promote digital development. With the rapid development of information technology, emerging technologies such as cloud computing, artificial intelligence, and the Internet of Things are widely used in various industries, the amount of data is growing explosively, and the network environment is becoming more and more complex. For example, after enterprises go to the cloud, the data storage, computing, and business processing modes change, and they face new security risks such as data leakage and service interruption. Intelligent methods are needed to manage and predict risks. The development of technologies such as artificial intelligence, big data analysis, and machine learning provides technical support for intelligent security management and risk prediction. With the help of these technologies, massive security data can be mined and analyzed to discover potential risk patterns and trends, and realize automated and intelligent security management and risk prediction.
[0003] Today, there are still some shortcomings in this regard, which are specifically reflected in the fact that traditional security management relies on rules and experience. When dealing with new and complex security threats, there are problems such as delayed response, many false positives and missed positives, and difficulty in processing massive data. Traditional methods are difficult to detect and analyze quickly and accurately, and cannot meet current security needs. Summary of the invention
[0004] In view of the deficiencies in the prior art, the present invention provides a cloud computing-based intelligent security management and risk prediction system and method, which can effectively solve the problems involved in the above-mentioned background technology.
[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: In the first aspect, the present invention provides an intelligent security management and risk prediction system based on cloud computing, including a multimodal threat analysis module, a spatiotemporal risk prediction module, an adaptive defense decision module, a federated model evolution module and an intelligent forensics tracing module, wherein: the multimodal threat analysis module is used to collect multimodal features and external threat intelligence of the system to be monitored, output the encrypted feature vector of the system to be monitored and perform local anomaly marking, construct a threat knowledge graph, and obtain an entity association matrix; the spatiotemporal risk prediction module is used to obtain the network of the system to be monitored. The topological data is combined with the threat knowledge graph to perform spatiotemporal risk prediction to obtain the risk heat map of the system to be monitored; the adaptive defense decision-making module is used to obtain the resource constraints of the system to be monitored based on the risk heat map, and obtain the defense strategy set and resource allocation plan of the system to be monitored; the federated model evolution module is used to collect the edge model parameters of the system to be monitored, and obtain the global model of the system to be monitored in combination with the resource allocation plan and provide feedback; the intelligent forensics and tracing module is used to perform intelligent forensics and tracing based on the local anomaly tags and entity association matrix of the system to be monitored, and obtain the attack path map of the system to be monitored and the attacker fingerprint library.
[0006] As a further solution, the multimodal threat analysis module includes: a multimodal threat perception subsystem, which is used to collect multimodal features of the system to be monitored, perform multimodal threat perception, output the encrypted feature vector of the system to be monitored and perform local anomaly marking; a threat knowledge graph construction subsystem, which is used to construct a threat knowledge graph based on the decrypted feature vector and external threat intelligence, and obtain an entity association matrix.
[0007] As a further solution, we collect multimodal features of the system to be monitored, perform multimodal threat perception, output the encrypted feature vector of the system to be monitored, and perform local anomaly marking. The specific analysis process is as follows: collect multimodal features of the system to be monitored, including network traffic packets, API call sequences, and container behavior logs of the system to be monitored; perform multimodal threat perception on the multimodal features of the system to be monitored:
[0008] Perform time series feature extraction and use the LSTM-Attention model to process the multimodal features of the system to be monitored: LSTM hidden state: h t =LSTM(x t ,h t-1 );where h t is the LSTM hidden state at time step t, x t is the input data at time step t, specifically the network traffic packets, API call sequences and container behavior logs of the system to be monitored, h t-1 is the LSTM hidden state at time step t-1;
[0009] Attention weight: α t =softmax(W a [h t ;H t-k:t ]); where α t is the attention weight at time step t, W a is the weight matrix in the attention mechanism, H t-k:t is the hidden state sequence from time step tk to time step t;
[0010] Output the encrypted feature vector of the system to be monitored: f enc =Paillier(f t );
[0011] Where i is the time step index number, f t is the feature vector before encryption, a i is the attention weight of the index position at the i-th time step, h i is the LSTM hidden state at the index position of the i-th time step, f enc is the encrypted feature vector of the system to be monitored, Paillier is the Paillier encryption algorithm;
[0012] Calculate the exponentially weighted mean: μ t =0.9μ t-1 +0.1||f t ||2; where μ t is the exponentially weighted mean of the feature vector before encryption at time step t, μ t-1 is the exponentially weighted mean of the feature vector before encryption at time step t-1;
[0013] Calculate the exponentially weighted standard deviation: In the formula, σ t is the standard deviation of the feature vector before encryption at time step t, σ t-1 is the standard deviation of the feature vector before encryption at time step t-1;
[0014] Calculate the adaptive dynamic threshold: In the formula, Q thres is the adaptive dynamic threshold, e is a natural constant;
[0015] Based on the abnormal marking rule, the feature vector before encryption at each moment is locally marked as abnormal, where the abnormal marking rule is:
[0016] In the formula, A edge It is an abnormality marker variable, 1 represents abnormality and 0 represents normality.
[0017] As a further solution, a threat knowledge graph is constructed based on the decrypted feature vector and external threat intelligence. The specific analysis process is as follows: decrypt the encrypted feature vector of the system to be monitored to obtain the decrypted feature vector f t ′; obtain external threat intelligence, including common vulnerability disclosures CVE, vulnerability libraries, IP and attack tools; decrypt the feature vector f t ′The corresponding entity is mapped to the vector space of the knowledge graph;
[0018] Entity relationship modeling using the TransH algorithm:
[0019] Output threat knowledge graph.
[0020] As a further solution, the entity association matrix is obtained. The specific analysis process is as follows: Calculate the multi-dimensional association degree:
[0021] In the formula, e i′ is the initial embedding vector of entity i′, e j′ is the initial embedding vector of entity j′, cos(e i′ ,e j′ ) is e i′ and e j′ The cosine similarity of i′ is the set of relations related to entity i′, R j′ is the set of relations related to entity j′, Jaccard(R i′ ,R j′ ) is R i′ and R j′ Jaccard similarity, d geo (i′,j′) is the geographical distance between entity i′ and entity j′, m i′j′ is the multi-dimensional correlation between entity i′ and entity j′, and e is a natural constant;
[0022] The multi-dimensional correlation between entity i′ and entity j′ is sparsely processed:
[0023] Where M entity [i′,j′] is the association matrix between entity i′ and entity j′;
[0024] Output entity association matrix M entity .
[0025] As a further solution, the network topology data of the system to be monitored is obtained, and the spatiotemporal risk prediction is carried out in combination with the threat knowledge graph to obtain the risk heat map of the system to be monitored. The specific analysis process is as follows: the network topology data of the system to be monitored is obtained, including the logical connection relationship and node attributes of the network nodes; each entity is recorded as each node of the threat knowledge graph;
[0026] Construct a dynamic adjacency matrix:
[0027] Where W b is the weight matrix, represents the transpose of a vector, d hop (i′, j′) is the number of node hops between entity i′ and entity j′, h i′ is the feature vector related to entity i′ extracted from the threat knowledge graph, h j′ is the feature vector related to entity j′ extracted from the threat knowledge graph, sigmoid is the activation function, is the dynamic adjacency matrix element between entity i′ and entity j′ at time step t;
[0028] Layered convolution calculation: In the formula, H (l) is the node feature matrix at layer l, is the weight matrix in the convolution operation of the first layer, ReLU is the linear rectification function, TCN (H (l) ) is the feature matrix H of the l-th layer node of the temporal convolutional network (l) The convolution operation performed in the time dimension, A t is the adjacency matrix at time step t, H (l+1) is the feature matrix of the next layer of nodes obtained after the l-th layer convolution calculation;
[0029] Risk heat map generation:
[0030] Kernel density estimation: In the formula, R map (x,y) is the value of the risk heat map at the coordinate (x,y), N is the total number of entities, that is, the total number of threat knowledge graph nodes, h′ is the bandwidth parameter, (x i′ ,y i′ ) is the coordinate position of entity i′, is the risk value of entity i′ based on the node feature matrix at time step t, K(·) is the Epanechnikov kernel function;
[0031] Output the risk heat map R of the system to be monitored map .
[0032] As a further solution, based on the risk heat map and obtaining the resource constraints of the system to be monitored, the defense strategy set and resource allocation plan of the system to be monitored are obtained. The specific analysis process is as follows: obtaining the resource constraints of the system to be monitored;
[0033] Status definition: s t =[max(R map ),entropy(R map ),CPU usage ]; where s t is the state vector, max(R map ) is the risk heat map R map The maximum value in entropy(R map ) is the risk heat map R map Entropy, CPU usage is the CPU usage;
[0034] Building the reward function: r t =10ΔR global -∑action_cost-5Π false_positive ; In the formula, r t is the reward value, ΔR global is the change in global risk, action_cost is the total cost of executing the action, Π false_positive is the false positive indicator variable;
[0035] Get the action candidate set stored in the database; select actions from the action candidate set through the ε-greedy strategy, and update the Q table of the Q-Learning strategy after the action is executed; get the defense strategy set of the system to be monitored from the actions corresponding to the Q values in the final converged Q table, including several defense action combinations; under resource constraints, select the defense action combination with the lowest cost, screen the defense action combinations in the defense strategy set of the system to be monitored based on the mixed integer programming model, and generate a resource allocation plan:
[0036] Minimize the objective function:
[0037]
[0038] Resource constraints:
[0039] In the formula, min is the minimization target, c f is the fixed cost of executing the f-th defensive action, x f is the execution status of the f-th defensive action, 1 if executed, 0 if not executed, d g is the unit cost of the g-th resource, y fgis the number of g-th resources allocated to the f-th defense action, λ is the weight coefficient, s g is the slack variable of the g-th resource, F is the number of defensive actions, G is the number of resources, a fg is the unit usage coefficient of the f-th defense action on the g-th resource, b g is the total amount of the g-th resource;
[0040] Use the solver to output the resource allocation plan.
[0041] As a further solution, the edge model parameters of the system to be monitored are collected, and the global model of the system to be monitored is obtained and fed back in combination with the resource allocation plan. The specific analysis process is as follows: the edge model parameters θ of the edge devices of the system to be monitored are collected k , combined with the resource allocation plan, model aggregation is performed to obtain the global model of the system to be monitored:
[0042] In the formula, θ global is the global model parameter after aggregation, N k is the number of samples of the kth edge device, acc k N is the accuracy of the risk prediction of the corresponding edge model after the resource allocation scheme is implemented for the edge model of the kth edge device, v is the number of samples of the vth edge device, acc v The accuracy of the edge model prediction risk after the resource allocation scheme is implemented for the vth edge device, where K is the total number of edge devices;
[0043] Based on the aggregated global model parameters, the global model of the system to be monitored is obtained; the global model of the system to be monitored is fed back to each edge device as the initial model for the next round of federated learning.
[0044] As a further solution, based on the local anomaly marks and entity association matrix of the system to be monitored, intelligent forensic tracing is performed to obtain the attack path diagram of the system to be monitored and the attacker fingerprint library. The specific analysis process is as follows: the local anomaly marks and entity association matrix of the system to be monitored are taken as input;
[0045] Perform causal reasoning and backdoor adjustment formula:
[0046] Where P(Y|do(X)) is the probability distribution of the outcome variable Y when the intervened variable X is intervened, P(Y|X,Z=z) is the probability distribution of the outcome variable Y when the intervened variable X and the confounding variable set Z that satisfies the backdoor criterion are known to take the value z, and P(Z=z) is the probability that the confounding variable set Z that satisfies the backdoor criterion takes the value z;
[0047] Obtain an attack path diagram of the system to be monitored;
[0048] Generate attacker fingerprint:
[0049] H mash =SHA3(MD5(IP)||SimHash(UA)||WLSH(behavior sequence));
[0050] In the formula, H mash is the attacker's fingerprint, IP is the IP address, UA is the user agent string, behavior sequence is the attacker's operation steps and behavior sequence in the system, SHA3, MD5, SimHash, WLSH are hash algorithms;
[0051] Output the attacker fingerprint library.
[0052] The second aspect of the present invention provides an intelligent security management and risk prediction method based on cloud computing, comprising the following steps: collecting multimodal features and external threat intelligence of the system to be monitored, outputting the encrypted feature vector of the system to be monitored and performing local anomaly marking, constructing a threat knowledge graph, and obtaining an entity association matrix; obtaining network topology data of the system to be monitored, combining the threat knowledge graph to perform spatiotemporal risk prediction, and obtaining a risk heat map of the system to be monitored; based on the risk heat map and obtaining resource constraints of the system to be monitored, obtaining a defense strategy set and a resource allocation plan for the system to be monitored; collecting edge model parameters of the system to be monitored, combining the resource allocation plan to obtain a global model of the system to be monitored and providing feedback; based on the local anomaly markings and entity association matrix of the system to be monitored, intelligent forensics and tracing are performed to obtain an attack path map of the system to be monitored and an attacker fingerprint library.
[0053] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects:
[0054] (1) The present invention provides a cloud computing-based intelligent security management and risk prediction system and method. The multimodal threat analysis module collects multimodal features and external threat intelligence, and can mine potential threats from multiple dimensions. It outputs encrypted feature vectors and marks anomalies, and also constructs threat knowledge graphs and entity association matrices to achieve a deep understanding and precise characterization of threats, thereby improving the accuracy and comprehensiveness of threat discovery. The spatiotemporal risk prediction module combines threat knowledge graphs and network topology data, considers time and space factors to predict risks, and generates a risk heat map. It can intuitively present the system risk distribution and reduce the probability of security incidents.
[0055] (2) The present invention formulates a defense strategy set and resource allocation plan based on risk heat maps and resource constraints. It can flexibly allocate resources according to the actual risk status and resource conditions of the system to achieve efficient and accurate defense, avoid waste of resources, and improve the defense effect and the overall security of the system. The federated model evolution module collects edge model parameters and generates a global model in combination with the resource allocation plan, and continuously optimizes through feedback. It can adapt to the ever-changing security threat environment, continuously improve the system's intelligent analysis and processing capabilities, and maintain the ability to detect and prevent new threats. The intelligent forensics and tracing module operates based on local anomaly markers and entity association matrices to quickly and accurately determine attack paths and attacker fingerprints. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] The present invention is further described using the accompanying drawings, but the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other drawings based on the following drawings without creative work.
[0057] Figure 1 It is a schematic diagram of system module connection of the present invention.
[0058] Figure 2 The figure is a schematic flow chart of the method steps of the present invention. DETAILED DESCRIPTION
[0059] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0060] Reference Figure 1 As shown, the first aspect of the present invention provides an intelligent security management and risk prediction system based on cloud computing, including a multimodal threat analysis module, a spatiotemporal risk prediction module, an adaptive defense decision module, a federated model evolution module and an intelligent forensics tracing module.
[0061] The multimodal threat analysis module is used to collect multimodal features and external threat intelligence of the system to be monitored, output the encrypted feature vector of the system to be monitored and mark local anomalies, build a threat knowledge graph, and obtain an entity association matrix.
[0062] The multimodal threat analysis module includes: a multimodal threat perception subsystem, which is used to collect multimodal features of the system to be monitored, perform multimodal threat perception, output the encrypted feature vector of the system to be monitored and perform local anomaly marking; a threat knowledge graph construction subsystem, which is used to construct a threat knowledge graph based on the decrypted feature vector and external threat intelligence, and obtain an entity association matrix.
[0063] Collect multimodal features of the system to be monitored, perform multimodal threat perception, output the encrypted feature vector of the system to be monitored and mark local anomalies. The specific analysis process is as follows: collect multimodal features of the system to be monitored, including network traffic packets, API call sequences and container behavior logs of the system to be monitored; perform multimodal threat perception on the multimodal features of the system to be monitored:
[0064] Perform time series feature extraction and use the LSTM-Attention model to process the multimodal features of the system to be monitored: LSTM hidden state: h t =LSTM(x t ,h t-1 );where h t is the LSTM hidden state at time step t, x t is the input data at time step t, specifically the network traffic packets, API call sequences and container behavior logs of the system to be monitored, h t-1 is the LSTM hidden state at time step t-1;
[0065] Attention weight: α t =softmax(W a [h t ;H t-k:t ]); where α t is the attention weight at time step t, W a is the weight matrix in the attention mechanism, H t-k:t is the hidden state sequence from time step tk to time step t;
[0066] Output the encrypted feature vector of the system to be monitored: f enc =Paillier(f t );
[0067] Where i is the time step index number, f t is the feature vector before encryption (including network traffic packet feature vector, API call sequence feature vector and container behavior log feature vector), a i is the attention weight of the index position at the i-th time step, h i is the LSTM hidden state at the index position of the i-th time step, f encis the encrypted feature vector of the system to be monitored, Paillier is the Paillier encryption algorithm;
[0068] Calculate the exponentially weighted mean: μ t =0.9μ t-1 +0.1||f t ||2; where μ t is the exponentially weighted mean of the feature vector before encryption at time step t, μ t-1 is the exponentially weighted mean of the feature vector before encryption at time step t-1;
[0069] Calculate the exponentially weighted standard deviation: In the formula, σ t is the standard deviation of the feature vector before encryption at time step t, σ t-1 is the standard deviation of the feature vector before encryption at time step t-1;
[0070] Calculate the adaptive dynamic threshold: In the formula, Q thres is the adaptive dynamic threshold, e is a natural constant;
[0071] Based on the abnormal marking rule, the feature vector before encryption at each moment is locally marked as abnormal, where the abnormal marking rule is:
[0072] In the formula, A edge To mark an abnormal variable, if the feature vector norm is greater than the adaptive dynamic threshold and the feature vector f before encryption t The feature vector f before encryption at the previous moment t-1 If the cosine similarity is less than 0.5, it is marked as 1, indicating abnormality, otherwise it is marked as 0, indicating normality;
[0073] Based on the anomaly classification results of the anomaly marking rules, local anomaly marking is performed.
[0074] Collecting multi-modal features such as network traffic packets, API call sequences, and container behavior logs can reflect the system operation status from different levels and comprehensively capture all kinds of potential threats. Compared with single-modal detection, it greatly improves the ability to perceive complex and changing threats and reduces the omission of threats.
[0075] The Paillier encryption algorithm is used to encrypt the feature vector to ensure the security and privacy of data during transmission and processing without leaking the data content, meeting the requirements for sensitive data protection in security management.
[0076] By calculating the exponentially weighted mean and standard deviation, we can get an adaptive dynamic threshold, which can be adjusted adaptively with the change of data distribution to adapt to the dynamic operation characteristics of the system. Combining the abnormal marking rules of feature vector norm and cosine similarity, and comprehensively considering the amplitude change and similarity of features, we can more accurately identify abnormal behaviors and reduce false positives and false negatives.
[0077] Local anomaly marking based on anomaly marking rules can clearly point out the specific location or link where the anomaly occurs in the system, making it easier for security personnel to quickly locate the problem, take targeted measures in a timely manner, and improve the efficiency of security incident response.
[0078] The LSTM-Attention model is used to process multimodal features. LSTM is suitable for processing time series data and can mine long-term dependencies in data; the Attention mechanism can focus on key information and enhance the model's sensitivity to important features. The combination of the two can more accurately extract time series features and provide a high-quality data foundation for subsequent analysis.
[0079] The threat knowledge graph is constructed based on the decrypted feature vector and external threat intelligence. The specific analysis process is as follows: decrypt the encrypted feature vector of the system to be monitored to obtain the decrypted feature vector f t ′; Map the entity corresponding to the decrypted feature vector to the vector space of the knowledge graph;
[0080] Entity relationship modeling using the TransH algorithm:
[0081] Perform hyperplane projection: In the formula, e r Represents the embedding vector of relation r in the vector space, w r is the normal vector of the hyperplane, is the hyperplane projection vector of relation r, Represents the transpose of a vector;
[0082] Calculate the relationship score: In the formula, score(h,r,t′) is the relationship score, is the projection vector of the head entity h on the hyperplane, is the projection vector of the tail entity t′ on the hyperplane;
[0083] Add time and space tags: In the formula, is the embedding vector of entity i′ after adding spatiotemporal information, e i′ is the initial embedding vector of entity i′, TimeEnc(t i′ ) is the time encoding function, which converts the time information t i′ Encoded into vector form and integrated into the entity representation, GeoEnc(loci′ ) is a geocoding function that converts the geographic location information loc i′ Encoded into vector form and integrated into the entity representation, It is a vector concatenation operation;
[0084] Output threat knowledge graph.
[0085] By decrypting feature vectors and combining them with external threat intelligence such as CVE and vulnerability libraries, the internal features of the system to be monitored are combined with external known threat information, and threat-related data is comprehensively summarized to form a more complete threat awareness system, which helps to discover potential security risks.
[0086] The TransH algorithm is used to model entity relationships and distinguish the semantics of entities under different relationships through hyperplane projection. This can more accurately represent the complex associations between entities, uncover hidden causal relationships and potential threat paths between entities, and enhance the understanding of threat propagation and evolution.
[0087] Calculating relationship scores can quantify the rationality and closeness of relationships between entities. This score can be used to quickly screen out key entity relationships, give priority to high-scoring relationship pairs, and improve the efficiency and pertinence of threat analysis.
[0088] Adding spatiotemporal tags integrates time and geographic location information into entity representation, making the entity description richer and more three-dimensional. This helps analyze the propagation patterns of threats in the spatiotemporal dimension, such as determining the source of the attack, the time of occurrence, and the potential spread trend, providing a more timely and spatially targeted basis for security decision-making.
[0089] The final output is a threat knowledge graph that graphically presents various entities and their relationships, making it easier for security personnel to conduct visual analysis and understanding, and quickly locate key nodes and potential threat paths.
[0090] And get the entity association matrix. The specific analysis process is: Calculate the multi-dimensional association degree:
[0091] In the formula, e i′ is the initial embedding vector of entity i′, e j′ is the initial embedding vector of entity j′, cos(e i′ ,e j′ ) is e i′ and e j′ The cosine similarity of i′ is the set of relations related to entity i′, R j′ is the set of relations related to entity j′, Jaccard(R i′ ,R j′ ) is R i′ and Rj′ Jaccard similarity, d geo (i′,j′) is the geographical distance between entity i′ and entity j′, m i′j′ is the multi-dimensional correlation between entity i′ and entity j′, and e is a natural constant;
[0092] The multi-dimensional correlation between entity i′ and entity j′ is sparsely processed:
[0093] Where M entity [i′,j′] is the association matrix between entity i′ and entity j′;
[0094] Output entity association matrix M entity .
[0095] By combining the cosine similarity of the embedding vector, Jaccard similarity, and geographic distance to calculate multidimensional associations, we can consider the relationship between entities from different angles. Not only does it take into account the similarity of entity features, but it also takes into account the overlap of entity-related relationship sets and spatial location relationships, making the evaluation of entity associations more comprehensive and accurate, and helping to discover potential complex associations.
[0096] The entity association matrix obtained after processing clearly presents the key associations between entities, providing a structured and concise data foundation for subsequent causal reasoning, attack path analysis, etc. In scenarios such as intelligent forensics and tracing, it can help quickly locate entities and associations related to anomalies, and assist in the analysis and handling of security incidents.
[0097] The spatiotemporal risk prediction module is used to obtain the network topology data of the system to be monitored, combine it with the threat knowledge graph to perform spatiotemporal risk prediction, and obtain the risk heat map of the system to be monitored.
[0098] The specific analysis process is as follows: obtain the network topology data of the system to be monitored, including the logical connection relationship and node attributes of the network nodes; record each entity as a node of the threat knowledge graph;
[0099] Construct a dynamic adjacency matrix:
[0100] Where W b is the weight matrix, represents the transpose of a vector, d hop (i′, j′) is the number of node hops between entity i′ and entity j′, h i′ is the feature vector related to entity i′ extracted from the threat knowledge graph, h j′ is the feature vector related to entity j′ extracted from the threat knowledge graph, sigmoid is the activation function, is the dynamic adjacency matrix element between entity i′ and entity j′ at time step t;
[0101] Layered convolution calculation: In the formula, H (l) is the node feature matrix at layer l, is the weight matrix in the convolution operation of the first layer, ReLU is the linear rectification function, TCN (H (l) ) is the feature matrix H of the l-th layer node of the temporal convolutional network (l) The convolution operation performed in the time dimension, A t is the adjacency matrix at time step t, H (l+1) is the feature matrix of the next layer of nodes obtained after the l-th layer convolution calculation;
[0102] Risk heat map generation:
[0103] Kernel density estimation: In the formula, R map (x,y) is the value of the risk heat map at the coordinate (x,y), N is the total number of entities, that is, the total number of threat knowledge graph nodes, h′ is the bandwidth parameter, (x i′ ,y i′ ) is the coordinate position of entity i′, is the risk value of entity i′ obtained based on the node feature matrix at time step t (the feature vector related to entity i′ is extracted from the node feature matrix of the last layer output by the hierarchical convolution calculation, and the extracted feature vector is compared with the vector-risk value mapping table stored in the database, that is, the feature vector related to entity i′ obtained in advance is compared with the vector in the vector-risk value mapping table to determine the closest vector, and the corresponding risk value is determined through the mapping relationship), K(·) is the Epanechnikov kernel function;
[0104] Output the risk heat map R of the system to be monitored map .
[0105] By combining network topology data and threat knowledge graphs, the system's network structure information is integrated with threat-related entity and relationship information, and the system's spatial layout and potential threat factors are fully considered, making risk predictions more in line with actual conditions and improving prediction accuracy.
[0106] When constructing a dynamic adjacency matrix, factors such as the number of hops between nodes and eigenvectors are considered to reflect the connection relationship between entities that changes over time. At the same time, the activation function is used to make the values of matrix elements more reasonable, which can dynamically capture the changes in entity relationships in the network, adapt to the dynamic nature of the network environment, and effectively respond to changing security risks.
[0107] Hierarchical convolutional computing combines graph convolution and temporal convolutional network (TCN). Graph convolution aggregates node features in the spatial dimension and mines the association information between entities; TCN extracts features in the temporal dimension and analyzes the temporal evolution of risks. The combination of the two can deeply extract features from the spatial and temporal dimensions and better understand the spread and development patterns of risks.
[0108] The use of ReLU (linear rectification function) introduces nonlinearity to enhance the model's expressiveness, enabling the model to learn more complex risk features and patterns. At the same time, the use of various matrices and parameters in the calculation process helps to optimize feature extraction and calculation processes, and improve model efficiency and performance.
[0109] The risk heat map is generated through kernel density estimation, presenting the risk distribution of the system in an intuitive and visual way. Security personnel can quickly locate high-risk areas, understand the spatial aggregation and change trend of risks, provide a clear reference for formulating targeted defense strategies, and improve the efficiency and effectiveness of security management.
[0110] The adaptive defense decision module is used to obtain the defense strategy set and resource allocation plan of the system to be monitored based on the risk heat map and the resource constraints of the system to be monitored.
[0111] The specific analysis process is as follows: obtaining resource constraints of the system to be monitored, including but not limited to CPU resource constraints, memory resource constraints and bandwidth resource constraints of the system to be monitored;
[0112] Status definition: s t =[max(R map ),entropy(R map ),CPU usage ]; where s t is the state vector, max(R map ) is the risk heat map R map The maximum value in entropy(R map ) is the risk heat map R map Entropy, CPU usage is the CPU usage;
[0113] Building the reward function: r t =10ΔR global -∑action_cost-5Π false_positive ; In the formula, r t is the reward value, ΔR global is the change in global risk, action_cost is the total cost of executing the action, Π false_positive is a false alarm indicator variable, which is 1 if a false alarm occurs and 0 otherwise;
[0114] Obtain the action candidate set stored in the database (including access control actions, security monitoring and defense actions, system resource management actions, and data management actions, etc.); select actions from the action candidate set through the ε-greedy strategy, and update the Q table of the Q-Learning strategy after the action is executed; obtain the defense strategy set of the system to be monitored from the actions corresponding to the Q values in the final converged Q table, including several defense action combinations; under resource constraints, select the defense action combination with the lowest cost, and screen the defense action combinations in the defense strategy set of the system to be monitored based on the mixed integer programming model to generate a resource allocation plan:
[0115] Minimize the objective function:
[0116]
[0117] Resource constraints:
[0118] In the formula, min is the minimization target, c f is the fixed cost of executing the f-th defensive action, x f is the execution status of the f-th defensive action, 1 if executed, 0 if not executed, d g is the unit cost of the g-th resource, y fg is the number of g-th resources allocated to the f-th defense action, λ is the weight coefficient, s g is the slack variable of the g-th resource, F is the number of defensive actions, G is the number of resources, a fg is the unit usage coefficient of the f-th defense action on the g-th resource, b g is the total amount of the g-th resource;
[0119] Use the solver to output the resource allocation plan.
[0120] Defense decisions are made based on risk heat maps and resource constraints, taking into account both the risk situation faced by the system and the actual available resources (such as CPU, memory, and bandwidth), ensuring that the formulated defense strategies and resource allocation plans are in line with reality, effectively responding to risks while avoiding waste or shortage of resources.
[0121] Using Q-Learning strategy optimization, the system status is fully reflected by carefully defining the state vector (including the maximum value of the risk heat map, entropy, and CPU usage). Combined with the reward function (comprehensive global risk change, action cost, and false alarm), the intelligent agent is encouraged to learn the optimal defense strategy, and the defense action can be dynamically adjusted according to the real-time status of the system to improve the pertinence and effectiveness of the defense.
[0122] The ε-greedy strategy is used to select actions, which balances the relationship between exploring new defense strategies and using existing experience strategies. In the early stage of system operation, it is encouraged to explore new strategies to find better solutions; as experience accumulates, more proven effective strategies are used, so that defense decisions can maintain a certain stability while constantly adapting to changes.
[0123] Under resource constraints, a mixed integer programming model is used to generate a resource allocation plan with the goal of minimizing costs, taking into account the cost coefficients and constraints related to various resources. Through the solver output plan, the lowest-cost combination of defense actions and resource allocation methods can be found to achieve the optimal configuration of resources and minimize resource consumption while meeting defense requirements.
[0124] The federated model evolution module is used to collect the edge model parameters of the system to be monitored, combine the resource allocation plan to obtain the global model of the system to be monitored and provide feedback.
[0125] The specific analysis process is as follows: Collect the edge model parameters θ of the edge devices of the system to be monitored k , combined with the resource allocation plan, model aggregation is performed to obtain the global model of the system to be monitored:
[0126] In the formula, θ global is the global model parameter after aggregation, N k is the number of samples of the kth edge device, acc k N is the accuracy of the risk prediction of the corresponding edge model after the resource allocation scheme is implemented for the edge model of the kth edge device, v is the number of samples of the vth edge device, acc v The accuracy of the edge model prediction risk after the resource allocation scheme is implemented for the vth edge device, where K is the total number of edge devices;
[0127] Based on the aggregated global model parameters, the global model of the system to be monitored is obtained; the global model of the system to be monitored is fed back to each edge device as the initial model for the next round of federated learning.
[0128] Without transmitting the original data, only the edge model parameters are collected for model aggregation, which avoids the risk of privacy leakage during data transmission and processing, meets the requirements for sensitive data protection, and is especially suitable for monitoring system scenarios that are sensitive to data privacy.
[0129] By combining the computing and storage resources of edge devices, the model training tasks are distributed to each edge device. This fully utilizes the local resources of edge devices, reduces the burden of data transmission to the central server, reduces network bandwidth pressure, and improves the overall processing efficiency of the system.
[0130] Through model aggregation, the global model parameters are weighted and calculated by comprehensively considering the number of samples and model accuracy of each edge device. Edge devices with a large number of samples and high accuracy have a greater impact on the global model, allowing the global model to integrate the advantages of multiple edge models, effectively improving the model's generalization ability and prediction accuracy, and better responding to diverse monitoring data and complex security threats.
[0131] The global model is fed back to each edge device as the initial model for the next round of federated learning, forming a closed-loop optimization iteration mechanism. As time goes by and more data is involved, the model can continuously adapt to new security threats and system changes, and continuously improve monitoring and defense capabilities.
[0132] Distributed model training and evolution reduce the reliance on a single central server. Even if some edge devices fail or are attacked, other devices can continue to participate in model training and updates, ensuring the normal operation of the system and the continuous evolution of the model, enhancing the robustness and reliability of the entire system.
[0133] The intelligent forensics and tracing module is used for intelligent forensics and tracing based on the local anomaly marks and entity association matrix of the system to be monitored, so as to obtain the attack path diagram of the system to be monitored and the attacker's fingerprint library.
[0134] The specific analysis process is as follows: taking the local anomaly mark and entity association matrix of the system to be monitored as input;
[0135] Perform causal reasoning and backdoor adjustment formula:
[0136] Where, P(Y|do(X)) is the probability distribution of the outcome variable Y when intervening the intervened variable X (e.g., the risk of data leakage is reduced from 30% to 5% after blocking the IP), P(Y|X,Z=z) is the probability distribution of the outcome variable Y when the intervened variable X and the confounding variable set Z that meets the backdoor criterion are known to take the value z, and P(Z=z) is the probability that the confounding variable set Z that meets the backdoor criterion takes the value z;
[0137] Obtain an attack path diagram of the system to be monitored;
[0138] For the intervened variable X (such as blocking a certain IP, closing the vulnerability exploitation port), A edge The abnormal flag variable triggers, A edge When it is 1, intervention is performed, such as blocking the attacker's IP, that is, do(X) is 1. The confounding variable set Z that meets the backdoor criterion needs to satisfy the requirement that the intervened variable X is related to the outcome variable Y, and at the same time is not on the causal path from X to Y (that is, it does not mediate the impact of X on Y). It is screened from the entity association matrix.
[0139] Generate attacker fingerprint:
[0140] H mash =SHA3(MD5(IP)||SimHash(UA)||WLSH(behavior sequence));
[0141] In the formula, H mash is the attacker's fingerprint, IP is the IP address, UA is the user agent string, behavior sequence is the attacker's operation steps and behavior sequence in the system, SHA3, MD5, SimHash, WLSH are hash algorithms;
[0142] Output the attacker fingerprint library.
[0143] With the help of local anomaly markers and entity association matrix, and using the backdoor adjustment formula in causal reasoning, we can deeply analyze the causal relationship between various factors and accurately sort out the propagation path in the system when the attack occurs. This helps security personnel to clearly understand the full picture of the attack, including the starting point, the nodes passed through, and the diffusion method, providing key clues for subsequent vulnerability repair and defense strategy formulation.
[0144] By applying multiple hash algorithms to information such as the attack source IP address, user agent string, and behavior sequence, the attacker's fingerprint is generated, and the attacker's characteristics are characterized from multiple dimensions. These unique fingerprint information can be used to distinguish different attackers and accumulate data for tracking the attacker's identity and behavior pattern.
[0145] The output attack path diagram and attacker fingerprint library build a comprehensive attack information resource library for the system. The attack path diagram records historical attack situations, which is convenient for analyzing attack trends and common methods; the attacker fingerprint library can be used to compare and identify whether new attacks come from known attackers, improving the ability to prevent repeated attacks or similar attackers.
[0146] Reference Figure 2 As shown, the second aspect of the present invention provides an intelligent security management and risk prediction method based on cloud computing, including the following steps: collecting multimodal features and external threat intelligence of the system to be monitored, outputting the encrypted feature vector of the system to be monitored and performing local anomaly marking, constructing a threat knowledge graph, and obtaining an entity association matrix.
[0147] The network topology data of the system to be monitored is obtained, and the spatiotemporal risk prediction is performed in combination with the threat knowledge graph to obtain the risk heat map of the system to be monitored.
[0148] Based on the risk heat map and the resource constraints of the system to be monitored, the defense strategy set and resource allocation plan of the system to be monitored are obtained.
[0149] The edge model parameters of the system to be monitored are collected, and the global model of the system to be monitored is obtained and fed back in combination with the resource allocation plan.
[0150] Based on the local anomaly marks and entity association matrix of the system to be monitored, intelligent forensics and traceability are performed to obtain the attack path diagram of the system to be monitored and the attacker's fingerprint library.
[0151] The above contents are merely examples and explanations of the structure of the present invention. The technicians in this technical field may make various modifications or additions to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the structure of the invention or exceed the scope defined by the claims, they should all fall within the protection scope of the present invention.
Claims
1. An intelligent security management and risk prediction system based on cloud computing, characterized in that: It includes multimodal threat analysis module, spatiotemporal risk prediction module, adaptive defense decision module, federated model evolution module and intelligent forensics tracing module, among which: The multimodal threat analysis module is used to collect multimodal features and external threat intelligence of the system to be monitored, output the encrypted feature vector of the system to be monitored and perform local anomaly marking, construct a threat knowledge graph, and obtain an entity association matrix; The spatiotemporal risk prediction module is used to obtain network topology data of the system to be monitored, perform spatiotemporal risk prediction in combination with the threat knowledge graph, and obtain a risk heat map of the system to be monitored; The adaptive defense decision module is used to obtain the defense strategy set and resource allocation plan of the system to be monitored based on the risk heat map and the resource constraints of the system to be monitored; The federated model evolution module is used to collect edge model parameters of the system to be monitored, obtain the global model of the system to be monitored in combination with the resource allocation plan, and provide feedback; The intelligent evidence collection and tracing module is used for intelligent evidence collection and tracing based on the local abnormality marks and entity association matrix of the system to be monitored, so as to obtain the attack path diagram of the system to be monitored and the attacker fingerprint library.
2. The cloud computing-based intelligent security management and risk prediction system according to claim 1, characterized in that: The multimodal threat analysis module comprises: The multimodal threat perception subsystem is used to collect multimodal features of the system to be monitored, perform multimodal threat perception, output the encrypted feature vector of the system to be monitored and perform local anomaly marking; The threat knowledge graph construction subsystem is used to construct a threat knowledge graph based on the decrypted feature vector and external threat intelligence, and obtain the entity association matrix.
3. The cloud computing-based intelligent security management and risk prediction system according to claim 2, characterized in that: Collect multimodal features of the system to be monitored, perform multimodal threat perception, output the encrypted feature vector of the system to be monitored and mark local anomalies. The specific analysis process is as follows: Collect multimodal features of the system to be monitored, including network traffic packets, API call sequences, and container behavior logs of the system to be monitored; To deal with the multimodal characteristics of the monitoring system, multimodal threat perception is performed: Perform time series feature extraction and use the LSTM-Attention model to process the multimodal features of the system to be monitored: LSTM hidden state: h t =LSTM(x t ,h t-1 ); In the formula, h t is the LSTM hidden state at time step t, x t is the input data at time step t, specifically the network traffic packets, API call sequences and container behavior logs of the system to be monitored, h t-1 is the LSTM hidden state at time step t-1; Attention weight: α t =softmax(W a [h t ;H t-k:t ]); In the formula, α t is the attention weight at time step t, W a is the weight matrix in the attention mechanism, H t-k:t is the hidden state sequence from time step tk to time step t; Output the encrypted feature vector of the system to be monitored: f enc =Paillier(f t ); Where i is the time step index number, f t is the feature vector before encryption, a i is the attention weight of the index position at the i-th time step, h i is the LSTM hidden state at the index position of the i-th time step, f enc is the encrypted feature vector of the system to be monitored, Paillier is the Paillier encryption algorithm; Calculate the exponentially weighted mean: μ t =0.9μ t-1 +0.1||f t ||2; In the formula, μ t is the exponentially weighted mean of the feature vector before encryption at time step t, μ t-1 is the exponentially weighted mean of the feature vector before encryption at time step t-1; Calculate the exponentially weighted standard deviation: In the formula, σ t is the standard deviation of the feature vector before encryption at time step t, σ t-1 is the standard deviation of the feature vector before encryption at time step t-1; Calculate the adaptive dynamic threshold: In the formula, Q thres is the adaptive dynamic threshold, e is a natural constant; Based on the abnormal marking rule, the feature vector before encryption at each moment is locally marked as abnormal, where the abnormal marking rule is: In the formula, A edge It is an abnormality marker variable, 1 represents abnormality and 0 represents normality.
4. The cloud computing-based intelligent security management and risk prediction system according to claim 2, characterized in that: The threat knowledge graph is constructed based on the decrypted feature vector and external threat intelligence. The specific analysis process is as follows: Decrypt the encrypted feature vector of the system to be monitored and obtain the decrypted feature vector f t ′; The decrypted feature vector f t ′The corresponding entity is mapped to the vector space of the knowledge graph; Use TransH algorithm for entity relationship modeling; Output threat knowledge graph.
5. The cloud computing-based intelligent security management and risk prediction system according to claim 4, characterized in that: Get the entity association matrix, the specific analysis process is: Calculate multidimensional association: In the formula, e i′ is the initial embedding vector of entity i′, e j′ is the initial embedding vector of entity j′, cos(e i′ ,e j′ ) is e i′ and e j′ The cosine similarity, R i′ is the set of relations related to entity i′, R j′ is the set of relations related to entity j′, Jaccard(R i′ ,R j′ ) is R i′ and R j′ Jaccard similarity, d geo (i′,j′) is the geographical distance between entity i′ and entity j′, m i′j′ is the multi-dimensional correlation between entity i′ and entity j′, and e is a natural constant; The multi-dimensional correlation between entity i′ and entity j′ is sparsely processed: Where M entity [i′,j′] is the association matrix between entity i′ and entity j′; Output entity association matrix M entity .
6. The cloud computing-based intelligent security management and risk prediction system according to claim 1, characterized in that: Obtain the network topology data of the system to be monitored, combine it with the threat knowledge graph to perform spatiotemporal risk prediction, and obtain the risk heat map of the system to be monitored. The specific analysis process is as follows: Obtain network topology data of the system to be monitored, including the logical connection relationship and node attributes of network nodes; Each entity is recorded as a threat knowledge graph node; Construct a dynamic adjacency matrix: Where W b is the weight matrix, represents the transpose of a vector, d hop (i′, j′) is the number of node hops between entity i′ and entity j′, h i′ is the feature vector related to entity i′ extracted from the threat knowledge graph, h j′ is the feature vector related to entity j′ extracted from the threat knowledge graph, sigmoid is the activation function, is the dynamic adjacency matrix element between entity i′ and entity j′ at time step t; Layered convolution calculation: In the formula, H (l) is the node feature matrix at layer l, is the weight matrix in the convolution operation of the first layer, ReLU is the linear rectification function, TCN (H (l) ) is the feature matrix H of the l-th layer node of the temporal convolutional network (l) The convolution operation performed in the time dimension, A t is the adjacency matrix at time step t, H (l+1) is the feature matrix of the next layer of nodes obtained after the l-th layer convolution calculation; Risk heat map generation: Kernel density estimation: In the formula, R map (x,y) is the value of the risk heat map at the coordinate (x,y), N is the total number of entities, that is, the total number of threat knowledge graph nodes, h′ is the bandwidth parameter, (x i′ ,y i′ ) is the coordinate position of entity i′, is the risk value of entity i′ based on the node feature matrix at time step t, K(·) is the Epanechnikov kernel function; Output the risk heat map R of the system to be monitored map .
7. The cloud computing-based intelligent security management and risk prediction system according to claim 6, characterized in that: Based on the risk heat map and the resource constraints of the system to be monitored, the defense strategy set and resource allocation plan of the system to be monitored are obtained. The specific analysis process is as follows: Obtain resource constraints of the system to be monitored; Status definition: s t =[max(R map ),entropy(R map ),CPU usage ]; In the formula, s t is the state vector, max(R map ) is the risk heat map R map The maximum value in entropy(R map ) is the risk heat map R map Entropy, CPU usage is the CPU usage; Building the reward function: r t =10ΔR global -∑action_cost-5Π false_positive ; In the formula, r t is the reward value, ΔR global is the change in global risk, action_cost is the total cost of executing the action, Π false_positive is the false positive indicator variable; Obtaining the action candidate set stored in the database; Select actions from the action candidate set through the ε-greedy strategy, and update the Q table of the Q-Learning strategy after the action is executed; The defense strategy set of the system to be monitored is obtained from the actions corresponding to the Q values in the Q table after the final convergence, including several defense action combinations; Under resource constraints, the lowest-cost defense action combination is selected, and the defense action combination in the defense strategy set of the monitored system is screened based on the mixed integer programming model to generate a resource allocation plan: Minimize the objective function: Resource constraints: In the formula, min is the minimization target, c f is the fixed cost of executing the f-th defensive action, x f is the execution status of the f-th defensive action, 1 if executed, 0 if not executed, d g is the unit cost of the g-th resource, y fg is the number of g-th resources allocated to the f-th defense action, λ is the weight coefficient, s g is the slack variable of the g-th resource, F is the number of defensive actions, G is the number of resources, a fg is the unit usage coefficient of the f-th defense action on the g-th resource, b g is the total amount of the g-th resource; Use the solver to output the resource allocation plan.
8. The cloud computing-based intelligent security management and risk prediction system according to claim 1, characterized in that: Collect the edge model parameters of the system to be monitored, combine the resource allocation plan to obtain the global model of the system to be monitored and provide feedback. The specific analysis process is as follows: Collect edge model parameters θ of the edge devices of the system to be monitored k , and execute resource allocation schemes on edge devices, perform model aggregation, and obtain the global model of the system to be monitored: In the formula, θ global is the global model parameter after aggregation, N k is the number of samples of the kth edge device, acc k N is the accuracy of the risk prediction of the corresponding edge model after the resource allocation scheme is implemented for the edge model of the kth edge device, v is the number of samples of the vth edge device, acc v The accuracy of the edge model prediction risk after the resource allocation scheme is implemented for the vth edge device, where K is the total number of edge devices; Based on the aggregated global model parameters, a global model of the system to be monitored is obtained; The global model of the system to be monitored is fed back to each edge device as the initial model for the next round of federated learning.
9. The cloud computing-based intelligent security management and risk prediction system according to claim 1, characterized in that: Based on the local abnormal mark and entity association matrix of the system to be monitored, intelligent forensics and tracing are performed to obtain the attack path diagram of the system to be monitored and the attacker fingerprint library. The specific analysis process is as follows: Take the local anomaly labels and entity association matrix of the system to be monitored as input; Perform causal reasoning and backdoor adjustment formula: Where P(Y|do(X)) is the probability distribution of the outcome variable Y when the intervened variable X is intervened, P(Y|X,Z=z) is the probability distribution of the outcome variable Y when the intervened variable X and the confounding variable set Z that satisfies the backdoor criterion are known to take the value z, and P(Z=z) is the probability that the confounding variable set Z that satisfies the backdoor criterion takes the value z; Obtain an attack path diagram of the system to be monitored; Generate attacker fingerprint: H mash =SHA3(MD5(IP)||SimHash(UA)||WLSH(behavior sequence)); In the formula, H mash is the attacker's fingerprint, IP is the IP address, UA is the user agent string, behavior sequence is the attacker's operation steps and behavior sequence in the system, SHA3, MD5, SimHash, WLSH are hash algorithms; Output the attacker fingerprint library.
10. A cloud computing-based intelligent security management and risk prediction method, applied to a cloud computing-based intelligent security management and risk prediction system according to any one of claims 1 to 9, characterized in that: The following steps are involved: Collect multimodal features and external threat intelligence of the system to be monitored, output the encrypted feature vector of the system to be monitored and mark local anomalies, build a threat knowledge graph, and obtain an entity association matrix; Obtain the network topology data of the system to be monitored, combine it with the threat knowledge graph to perform spatiotemporal risk prediction, and obtain the risk heat map of the system to be monitored; Based on the risk heat map and the resource constraints of the system to be monitored, the defense strategy set and resource allocation plan of the system to be monitored are obtained; Collect edge model parameters of the system to be monitored, combine with resource allocation plan to obtain the global model of the system to be monitored and provide feedback; Based on the local anomaly marks and entity association matrix of the system to be monitored, intelligent forensics and traceability are performed to obtain the attack path diagram of the system to be monitored and the attacker's fingerprint library.
Citation Information
Patent Citations
Network anomaly monitoring method and system of switch
CN119071052A
Chemical industrial park illegal behavior intervention and tracing system based on edge calculation
CN119339334A
Network attack link tracking and threat situation reasoning method based on knowledge graph
CN119544327A
Self-evolution network security defense strategy generation and dynamic deployment method
CN119561793A
Multi-source software supply chain intelligent analysis method and system
CN119720225A
Cited By
Digital power grid information security identification method, device, equipment and medium
CN120474828A
Network threat detection method and device, equipment and storage medium
CN120675764A
Intelligent terminal network intrusion behavior identification method and device based on deep learning
CN121940231A