An intelligent security management and risk prediction system and method based on cloud computing
The cloud-based intelligent security management system addresses traditional security management's limitations by employing advanced analytical modules to enhance threat detection, resource allocation, and adaptive defense strategies, ensuring precise and efficient security responses to complex threats.
Patent Information
- Application Number
- CN202510493817.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-19
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-19
AI Technical Summary
Traditional security management methods have lagged responses and many false alarms and missed reports when dealing with new and complex security threats, making it difficult to process massive data and cannot meet current security needs.
The intelligent security management and risk prediction system based on cloud computing is adopted, including multimodal threat analysis module, spatiotemporal risk prediction module, adaptive defense decision-making module, federal model evolution module and intelligent evidence traceability module. Through technical means such as multimodal threat perception, threat knowledge graph construction, spatiotemporal risk prediction, resource allocation and intelligent evidence traceability, we can achieve in-depth understanding and accurate characterization of threats.
It improves the accuracy and comprehensiveness of threat discovery, achieves efficient and accurate defense, adapts to the ever-changing security threat environment, and improves the overall security and analysis and processing capabilities of the system.
Smart Images

Figure CN120012119B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and specifically provides an intelligent security management and risk prediction system and method based on cloud computing. Background Art
[0002] Cloud computing, as a model of using public computing resources through the Internet, covers various services such as servers, database management, and data storage, and has become a key technology to promote digital development. With the rapid development of information technology, emerging technologies such as cloud computing, artificial intelligence, and the Internet of Things have been widely applied in various industries, the amount of data has increased explosively, and the network environment has become increasingly complex. For example, after an enterprise migrates to the cloud, the data storage, computing, and business processing modes change, and it faces new security risks such as data leakage and service interruption, which requires intelligent methods to manage and predict risks. The development of technologies such as artificial intelligence, big data analysis, and machine learning provides technical support for intelligent security management and risk prediction. With the help of these technologies, massive security data can be mined and analyzed to discover potential risk patterns and trends, and automated and intelligent security management and risk prediction can be achieved.
[0003] At present, there are still some deficiencies in this regard, specifically manifested in that traditional security management relies on rules and experience, and when dealing with new and complex security threats, there are problems such as lagging response, many false positives and false negatives, and difficulty in processing massive data. Traditional methods are difficult to detect and analyze quickly and accurately, and cannot meet the current security requirements. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention provides an intelligent security management and risk prediction system and method based on cloud computing, which can effectively solve the problems involved in the above background art.
[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: In the first aspect of the present invention, an intelligent security management and risk prediction system based on cloud computing is provided, including a multi-modal threat analysis module, a spatio-temporal risk prediction module, an adaptive defense decision-making module, a federated model evolution module, and an intelligent forensic tracing module, where: The multi-modal threat analysis module is used to collect multi-modal features of the system to be monitored and external threat intelligence, output encrypted feature vectors of the system to be monitored and perform local anomaly marking, construct a threat knowledge graph, and obtain an entity association matrix; The spatio-temporal risk prediction module is used to obtain the network topology data of the system to be monitored, combine the threat knowledge graph to perform spatio-temporal risk prediction, and obtain a risk heat map of the system to be monitored; The adaptive defense decision-making module is used to obtain the resource constraints of the system to be monitored based on the risk heat map, and obtain a defense strategy set and a resource allocation plan for the system to be monitored; The federated model evolution module is used to collect the edge model parameters of the system to be monitored, combine the resource allocation plan to obtain the global model of the system to be monitored and perform feedback; The intelligent forensic tracing module is used to perform intelligent forensic tracing based on the local anomaly marking and entity association matrix of the system to be monitored, and obtain an attack path map and an attacker fingerprint database of the system to be monitored.
[0006] As a further solution, the multi-modal threat analysis module includes: a multi-modal threat perception subsystem, which is used to collect multi-modal features of the system to be monitored, perform multi-modal threat perception, output encrypted feature vectors of the system to be monitored and perform local anomaly marking; a threat knowledge graph construction subsystem, which is used to construct a threat knowledge graph based on the decrypted feature vectors and external threat intelligence, and obtain an entity association matrix.
[0007] As a further solution, collecting multi-modal features of the system to be monitored, performing multi-modal threat perception, outputting encrypted feature vectors of the system to be monitored and performing local anomaly marking, the specific analysis process is as follows: Collecting multi-modal features of the system to be monitored, specifically including the network traffic packets, API call sequences, and container behavior logs of the system to be monitored; Performing multi-modal threat perception on the multi-modal features of the system to be monitored:
[0008] Performing time series feature extraction, using the LSTM-Attention model to process the multi-modal features of the system to be monitored: LSTM hidden state: h t = LSTM(x t , h t-1 ); In the formula, h t is the LSTM hidden state at time step t, x t is the input data at time step t, specifically the network traffic packets, API call sequences, and container behavior logs of the system to be monitored, h t-1 is the LSTM hidden state at time step t-1;
[0009] Attention weight: α t = softmax(W a [h t ; H t-k:t ); where α t is the attention weight at time step t, W a is the weight matrix in the attention mechanism, and H t-k:t is the sequence of hidden states from time step t - k to time step t;
[0010] Output the encrypted feature vector of the system to be monitored: f enc = Paillier(f t );
[0011] where i is the time step index number, f t is the feature vector before encryption, a i is the attention weight at the i-th time step index position, h i is the LSTM hidden state at the i-th time step index position, f enc is the encrypted feature vector of the system to be monitored, and Paillier is the Paillier encryption algorithm;
[0012] Calculate the exponentially weighted mean: μ t = 0.9μ t-1 + 0.1||f t ||²; where μ t is the exponentially weighted mean of the feature vector before encryption at time step t, and μ t-1 is the exponentially weighted mean of the feature vector before encryption at time step t - 1;
[0013] Calculate the exponentially weighted standard deviation: where σ t is the standard deviation of the feature vector before encryption at time step t, and σ t-1 is the standard deviation of the feature vector before encryption at time step t - 1;
[0014] Calculate the adaptive dynamic threshold: where Q thres is the adaptive dynamic threshold, and e is the natural constant;
[0015] Perform local anomaly marking on the feature vectors before encryption at each moment based on the anomaly marking rule, where the anomaly marking rule is:
[0016] where A edge is the anomaly marking variable, 1 represents anomaly, and 0 represents normal.
[0017] As a further solution, a threat knowledge graph is constructed based on the decrypted feature vector and external threat intelligence. The specific analysis process is as follows: decrypt the encrypted feature vector of the system to be monitored to obtain the decrypted feature vector f t '; obtain external threat intelligence, specifically including Common Vulnerabilities and Exposures (CVE), vulnerability databases, IPs, and attack tools; map the entities corresponding to the decrypted feature vector f t ' to the vector space of the knowledge graph;
[0018] Use the TransH algorithm for entity relationship modeling:
[0019] Output the threat knowledge graph.
[0020] As a further solution, an entity association matrix is obtained. The specific analysis process is as follows: calculate the multi-dimensional association degree:
[0021] In the formula, e i′ is the initial embedding vector of entity i', e j′ is the initial embedding vector of entity j', cos(e i′ , e j′ ) is the cosine similarity between e i′ and e j′ , R i′ is the set of relationships related to entity i', R j′ is the set of relationships related to entity j', Jaccard(R i′ , R j′ ) is the Jaccard similarity between R i′ and R j′ , d geo (i', j') is the geographical distance between entity i' and entity j', m i′j′ is the multi-dimensional association degree between entity i' and entity j', and e is the natural constant;
[0022] Perform sparsification processing on the multi-dimensional association degree between entity i' and entity j':
[0023] In the formula, M entity [i', j'] is the association matrix between entity i' and entity j';
[0024] Output the entity association matrix M entity .
[0025] As a further solution, obtain the network topology data of the system to be monitored, combine it with the threat knowledge graph for spatio-temporal risk prediction, and obtain the risk heat map of the system to be monitored. The specific analysis process is as follows: Obtain the network topology data of the system to be monitored, including the logical connection relationship and node attributes of network nodes; Denote each entity as a node in the threat knowledge graph;
[0026] Construct a dynamic adjacency matrix:
[0027] where W b is the weight matrix, represents the transpose of the vector, d hop (i′, j′) is the number of hops between nodes of entities i′ and j′, h i′ is the feature vector related to entity i′ extracted from the threat knowledge graph, h j′ is the feature vector related to entity j′ extracted from the threat knowledge graph, sigmoid is the activation function, is the element of the dynamic adjacency matrix between entities i′ and j′ at time step t;
[0028] Hierarchical convolution calculation: where H (l) is the node feature matrix at the l-th layer, is the weight matrix in the l-th layer convolution operation, ReLU is the rectified linear unit function, TCN(H (l) ) is the convolution operation performed by the temporal convolutional network on the node feature matrix H (l) in the time dimension, A t is the adjacency matrix at time step t, H (l+1) is the next layer node feature matrix obtained after the l-th layer convolution calculation;
[0029] Risk heat map generation:
[0030] Kernel density estimation: where R map (x, y) is the value of the risk heat map at coordinates (x, y), N is the total number of entities, that is, the total number of nodes in the threat knowledge graph, h′ is the bandwidth parameter, (x i′ , y i′ ) is the coordinate position of entity i′, is the risk value of entity i′ obtained based on the node feature matrix at time step t, K(·) is the Epanechnikov kernel function;
[0031] Output the risk heat map R map .
[0032] As a further solution, based on the risk heat map and obtaining the resource constraints of the system to be monitored, a defense strategy set and a resource allocation plan for the system to be monitored are obtained. The specific analysis process is as follows: Obtain the resource constraints of the system to be monitored;
[0033] State definition: s t =[max(R map ),entropy(R map ),CPU usage ; In the formula, s t is the state vector, max(R map ) is the maximum value in the risk heat map R map , entropy(R map ) is the entropy of the risk heat map R map , CPU usage is the CPU usage rate;
[0034] Establish a reward function: r t =10ΔR global -∑action_cost-5Π false_positive ; In the formula, r t is the reward value, ΔR global is the change in global risk, action_cost is the total cost of executing the action, Π false_positive is the false alarm indicator variable;
[0035] Obtain the set of action candidates stored in the database; Select an action from the set of action candidates through the ε-greedy strategy, and update the Q-table of the Q-Learning strategy after the action is executed; Obtain the defense strategy set of the system to be monitored from the actions corresponding to the Q values in the finally converged Q-table, including several defense action combinations; Under resource constraints, select the defense action combination with the lowest cost, and screen the defense action combinations in the defense strategy set of the system to be monitored based on the mixed integer programming model to generate a resource allocation plan:
[0036] Minimize the objective function:
[0037]
[0038] Resource constraint conditions:
[0039] In the formula, min is the minimization objective, c f is the fixed cost of executing the f-th defense action, x f is the execution situation of the f-th defense action, 1 for execution and 0 for non-execution, d g is the unit usage cost of the g-th resource, y fgThe quantity of the g-th resource allocated to the f-th defense action, λ is the weight coefficient, s g is the slack variable of the g-th resource, F is the number of defense actions, G is the number of resources, a fg is the coefficient of the unit usage of the g-th resource by the f-th defense action, b g is the total amount of the g-th resource;
[0040] Use the solver to output the resource allocation plan.
[0041] As a further solution, collect the edge model parameters of the system to be monitored, combine them with the resource allocation plan to obtain the global model of the system to be monitored and conduct feedback. The specific analysis process is as follows: Collect the edge model parameters θ of the edge devices of the system to be monitored k , combine with the resource allocation plan, and conduct model aggregation to obtain the global model of the system to be monitored:
[0042] In the formula, θ global is the aggregated global model parameter, N k is the number of samples of the k-th edge device, acc k is the accuracy rate of the corresponding edge model prediction risk after the k-th edge device implements the resource allocation plan, N v is the number of samples of the v-th edge device, acc v is the accuracy rate of the corresponding edge model prediction risk after the v-th edge device implements the resource allocation plan, and K is the total number of edge devices;
[0043] Based on the aggregated global model parameters, obtain the global model of the system to be monitored; feedback the global model of the system to be monitored to each edge device as the initial model for the next round of federated learning.
[0044] As a further solution, based on the local anomaly markings and entity association matrix of the system to be monitored, conduct intelligent forensic tracing to obtain the attack path graph and attacker fingerprint library of the system to be monitored. The specific analysis process is as follows: Use the local anomaly markings and entity association matrix of the system to be monitored as the input;
[0045] Conduct causal reasoning, and the backdoor adjustment formula:
[0046] In the formula, P(Y∣do(X)) is the probability distribution of the result variable Y under the condition of intervening in the intervened variable X, P(Y∣X,Z = z) is the probability distribution of the result variable Y under the condition of knowing the intervened variable X and the value of the confounding variable set Z that satisfies the backdoor criterion being z, and P(Z = z) is the probability that the confounding variable set Z that satisfies the backdoor criterion takes the value z;
[0047] Obtain an attack path diagram of the system to be monitored;
[0048] Generate attacker fingerprint:
[0049] H mash =SHA3(MD5(IP)||SimHash(UA)||WLSH(behavior sequence));
[0050] In the formula, H mash is the attacker's fingerprint, IP is the IP address, UA is the user agent string, behavior sequence is the attacker's operation steps and behavior sequence in the system, SHA3, MD5, SimHash, WLSH are hash algorithms;
[0051] Output the attacker fingerprint library.
[0052] The second aspect of the present invention provides an intelligent security management and risk prediction method based on cloud computing, comprising the following steps: collecting multimodal features and external threat intelligence of the system to be monitored, outputting the encrypted feature vector of the system to be monitored and performing local anomaly marking, constructing a threat knowledge graph, and obtaining an entity association matrix; obtaining network topology data of the system to be monitored, combining the threat knowledge graph to perform spatiotemporal risk prediction, and obtaining a risk heat map of the system to be monitored; based on the risk heat map and obtaining resource constraints of the system to be monitored, obtaining a defense strategy set and a resource allocation plan for the system to be monitored; collecting edge model parameters of the system to be monitored, combining the resource allocation plan to obtain a global model of the system to be monitored and providing feedback; based on the local anomaly markings and entity association matrix of the system to be monitored, intelligent forensics and tracing are performed to obtain an attack path map of the system to be monitored and an attacker fingerprint library.
[0053] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects:
[0054] (1) The present invention provides a cloud computing-based intelligent security management and risk prediction system and method. The multimodal threat analysis module collects multimodal features and external threat intelligence, and can mine potential threats from multiple dimensions. It outputs encrypted feature vectors and marks anomalies, and also constructs threat knowledge graphs and entity association matrices to achieve a deep understanding and precise characterization of threats, thereby improving the accuracy and comprehensiveness of threat discovery. The spatiotemporal risk prediction module combines threat knowledge graphs and network topology data, considers time and space factors to predict risks, and generates a risk heat map. It can intuitively present the system risk distribution and reduce the probability of security incidents.
[0055] (2) The present invention formulates a defense strategy set and a resource allocation plan based on a risk heat map and resource constraints. It can flexibly allocate resources according to the actual risk situation and resource conditions of the system, achieve efficient and accurate defense, avoid resource waste, and improve the defense effect and the overall security of the system. The federated model evolution module collects edge model parameters and generates a global model in combination with the resource allocation plan, and continuously optimizes it through feedback. It can adapt to the changing security threat environment, continuously improve the intelligent analysis and processing ability of the system, and maintain the detection and prevention ability against new threats. The intelligent forensics and traceability module operates based on local anomaly markers and entity association matrices to quickly and accurately determine the attack path and attacker fingerprints. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] The present invention will be further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on the following drawings without creative efforts.
[0057] Figure 1 It is a schematic diagram of the connection of the system modules of the present invention.
[0058] Figure 2 It is a schematic diagram of the method step flow of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0060] Referring to Figure 1 As shown, the first aspect of the present invention provides an intelligent security management and risk prediction system based on cloud computing, including a multi-modal threat analysis module, a spatio-temporal risk prediction module, an adaptive defense decision module, a federated model evolution module, and an intelligent forensics and traceability module.
[0061] The multi-modal threat analysis module is used to collect multi-modal features of the system to be monitored and external threat intelligence, output an encrypted feature vector of the system to be monitored and perform local anomaly marking, construct a threat knowledge graph, and obtain an entity association matrix.
[0062] The multi-modal threat analysis module includes: a multi-modal threat perception subsystem, which is used to collect multi-modal features of the system to be monitored, perform multi-modal threat perception, output the encrypted feature vector of the system to be monitored, and perform local anomaly marking; a threat knowledge graph construction subsystem, which is used to construct a threat knowledge graph based on the decrypted feature vector and external threat intelligence, and obtain an entity association matrix.
[0063] Collect the multi-modal features of the system to be monitored, perform multi-modal threat perception, output the encrypted feature vector of the system to be monitored, and perform local anomaly marking. The specific analysis process is as follows: Collect the multi-modal features of the system to be monitored, specifically including the network traffic packets, API call sequences, and container behavior logs of the system to be monitored; perform multi-modal threat perception on the multi-modal features of the system to be monitored:
[0064] Perform time-series feature extraction and use the LSTM-Attention model to process the multi-modal features of the system to be monitored: The LSTM hidden state: h t = LSTM(x t , h t-1 ); In the formula, h t is the LSTM hidden state at time step t, x t is the input data at time step t, specifically the network traffic packets, API call sequences, and container behavior logs of the system to be monitored, and h t-1 is the LSTM hidden state at time step t-1;
[0065] Attention weight: α t = softmax(W a [h t ; H t-k:t ); In the formula, α t is the attention weight at time step t, W a is the weight matrix in the attention mechanism, and H t-k:t is the hidden state sequence from time step t-k to time step t;
[0066] Output the encrypted feature vector of the system to be monitored: f enc = Paillier(f t );
[0067] In the formula, i is the time step index number, f t is the feature vector before encryption (including the network traffic packet feature vector, API call sequence feature vector, and container behavior log feature vector), a i is the attention weight at the i-th time step index position, h i is the LSTM hidden state at the i-th time step index position, and f encis the encrypted feature vector of the system to be monitored, and Paillier is the Paillier encryption algorithm;
[0068] Calculate the exponentially weighted mean: μ t = 0.9μ t-1 + 0.1||f t ||²; where μ t is the exponentially weighted mean of the feature vector before encryption at time step t, and μ t-1 is the exponentially weighted mean of the feature vector before encryption at time step t-1;
[0069] Calculate the exponentially weighted standard deviation: where σ t is the standard deviation of the feature vector before encryption at time step t, and σ t-1 is the standard deviation of the feature vector before encryption at time step t-1;
[0070] Calculate the adaptive dynamic threshold: where Q thres is the adaptive dynamic threshold, and e is the natural constant;
[0071] Based on the anomaly marking rule, perform local anomaly marking on the feature vector before encryption at each moment, where the anomaly marking rule is:
[0072] where A edge is the anomaly marking variable. If the feature vector norm is greater than the adaptive dynamic threshold and the cosine similarity between the current feature vector f t before encryption and the feature vector f t-1 before encryption at the previous moment is less than 0.5, then mark it as 1, representing an anomaly, otherwise mark it as 0, representing normal;
[0073] Based on the anomaly division result of the anomaly marking rule, perform local anomaly marking.
[0074] Collect multi-modal features such as network traffic packets, API call sequences, and container behavior logs, which can reflect the system operation status from different levels and comprehensively capture various potential threats. Compared with single-modal detection, it greatly improves the perception ability of complex and changing threats and reduces threat omission.
[0075] Use the Paillier encryption algorithm to encrypt the feature vector. Without revealing the data content, it ensures the security and privacy of the data during transmission and processing, meeting the requirements for the protection of sensitive data in security management.
[0076] An adaptive dynamic threshold is obtained by calculating the exponentially weighted mean and standard deviation. This threshold can be adaptively adjusted according to the data distribution, adapting to the dynamic operation characteristics of the system. Combining the anomaly marking rules of the feature vector norm and cosine similarity, and comprehensively considering the amplitude change and similarity of features, abnormal behaviors can be identified more accurately, reducing false positives and false negatives.
[0077] Based on the anomaly marking rules, local anomaly marking is performed, which can clearly indicate the specific location or link where anomalies occur in the system, facilitating security personnel to quickly locate problems and take targeted handling measures in a timely manner, improving the efficiency of security incident response.
[0078] The LSTM-Attention model is used to process multi-modal features. LSTM is suitable for processing time-series data and can mine long-term dependencies in the data; the Attention mechanism can focus on key information and enhance the model's sensitivity to important features. The combination of the two can extract time-series features more accurately, providing a high-quality data basis for subsequent analysis.
[0079] A threat knowledge graph is constructed based on the decrypted feature vector and external threat intelligence. The specific analysis process is as follows: decrypt the encrypted feature vector of the system to be monitored to obtain the decrypted feature vector f t ′; map the entity corresponding to the decrypted feature vector to the vector space of the knowledge graph;
[0080] Use the TransH algorithm for entity relationship modeling:
[0081] Perform hyperplane projection: In the formula, e r represents the embedding vector of the relationship r in the vector space, w r is the normal vector of the hyperplane, is the hyperplane projection vector of the relationship r, represents the transpose of the vector;
[0082] Calculate the relationship score: In the formula, score(h,r,t′) is the relationship score, is the projection vector of the head entity h on the hyperplane, is the projection vector of the tail entity t′ on the hyperplane;
[0083] Add spatio-temporal tags: In the formula, is the embedding vector of the entity i′ after adding spatio-temporal information, e i′ is the initial embedding vector of the entity i′, TimeEnc(t i′ ) is the time encoding function, which encodes the time information t i′ into a vector form and integrates it into the entity representation, GeoEnc(loci′ ) is a geocoding function that encodes the geographical location information loc i′ into a vector form and integrates it into the entity representation. is the vector concatenation operation;
[0084] Output the threat knowledge graph.
[0085] By decrypting the feature vector and combining external threat intelligence such as CVE and vulnerability databases, the internal features of the system to be monitored are combined with external known threat information to comprehensively summarize threat-related data and form a more complete threat awareness system, which helps to discover potential security risks.
[0086] Use the TransH algorithm to model entity relationships. By distinguishing the semantics of entities under different relationships through hyperplane projection, it can more accurately represent the complex associations between entities, mine the hidden causal relationships and potential threat paths between entities, and improve the understanding of threat propagation and evolution.
[0087] Calculating the relationship score can quantify the rationality and closeness of the relationship between entities. Through this score, key entity relationships can be quickly screened out, and high-score relationship pairs can be given priority attention, improving the efficiency and pertinence of threat analysis.
[0088] Adding spatio-temporal tags integrates time and geographical location information into the entity representation, making the description of entities more rich and three-dimensional. This helps to analyze the propagation law of threats in the spatio-temporal dimension, such as judging the source location, occurrence time and potential diffusion trend of attacks, and providing a more timely and spatially targeted basis for security decision-making.
[0089] Finally, output the threat knowledge graph, which visually presents various entities and their relationships in a graphical way, facilitating security personnel for visual analysis and understanding, and quickly locating key nodes and potential threat paths.
[0090] And obtain the entity association matrix. The specific analysis process is as follows: Calculate the multi-dimensional correlation degree:
[0091] In the formula, e i′ is the initial embedding vector of entity i′, e j′ is the initial embedding vector of entity j′, cos(e i′ , e j′ ) is the cosine similarity between e i′ and e j′ , R i′ is the set of relationships related to entity i′, R j′ is the set of relationships related to entity j′, Jaccard(R i′ , R j′ ) is R i′ and Rj′ The Jaccard similarity, d geo (i′, j′) is the geographical distance between entity i′ and entity j′, m i′j′ is the multi-dimensional correlation degree between entity i′ and entity j′, and e is the natural constant;
[0092] Sparsify the multi-dimensional correlation degree of entity i′ and entity j′:
[0093] In the formula, M entity [i′, j′] is the association matrix of entity i′ and entity j′;
[0094] Output the entity association matrix M entity 。
[0095] By calculating the multi-dimensional correlation degree by combining the cosine similarity of embedding vectors, Jaccard similarity, and geographical distance, etc., the relationship between entities can be considered from different perspectives. It not only considers the similarity of entity features, but also incorporates the overlap of the set of entity-related relationships and the spatial position relationship, making the evaluation of entity association more comprehensive and accurate, and helping to discover potential complex associations.
[0096] The entity association matrix obtained after processing clearly presents the key associations between entities, providing a structured and concise data basis for subsequent causal reasoning, attack path analysis, etc. In scenarios such as intelligent forensics and traceability, it can help quickly locate entities and associations related to anomalies, and assist in the analysis and handling of security incidents.
[0097] The spatio-temporal risk prediction module is used to obtain the network topology data of the system to be monitored, combine the threat knowledge graph for spatio-temporal risk prediction, and obtain the risk heat map of the system to be monitored.
[0098] The specific analysis process is as follows: Obtain the network topology data of the system to be monitored, including the logical connection relationship and node attributes of network nodes; Denote each entity as each node of the threat knowledge graph;
[0099] Construct a dynamic adjacency matrix:
[0100] In the formula, W b is the weight matrix, represents the transpose of the vector, d hop (i′, j′) is the number of hops between nodes of entity i′ and entity j′, h i′ is the feature vector related to entity i′ extracted from the threat knowledge graph, h j′ is the feature vector related to entity j′ extracted from the threat knowledge graph, sigmoid is the activation function, is the element of the dynamic adjacency matrix between entity i' and entity j' at time step t;
[0101] Hierarchical convolution calculation: In the formula, H (l) is the node feature matrix at the l-th layer, is the weight matrix in the l-th layer convolution operation, ReLU is the rectified linear unit function, TCN(H (l) ) is the convolution operation performed by the temporal convolutional network on the node feature matrix H (l) in the time dimension, A t is the adjacency matrix at time step t, H (l+1) is the next layer node feature matrix obtained after the l-th layer convolution calculation;
[0102] Risk heatmap generation:
[0103] Kernel density estimation: In the formula, R map (x, y) is the value of the risk heatmap at the coordinate (x, y), N is the total number of entities, that is, the total number of nodes in the threat knowledge graph, h' is the bandwidth parameter, (x i′ , y i′ ) is the coordinate position of entity i', is the risk value of entity i' obtained based on the node feature matrix at time step t (extract the feature vector related to entity i' from the node feature matrix of the last layer output by the hierarchical convolution calculation, compare the extracted feature vector with the vector-risk value mapping table stored in the database, that is, compare the feature vector related to entity i' obtained in advance with the vectors in the vector-risk value mapping table to determine the closest vector, and determine the corresponding risk value through the mapping relationship), K(·) is the Epanechnikov kernel function;
[0104] Output the risk heatmap R map of the system to be monitored.
[0105] Combining network topology data and threat knowledge graphs, integrating the network structure information of the system with threat-related entity and relationship information, comprehensively considering the spatial layout of the system and potential threat factors, making the risk prediction more in line with the actual situation and improving the prediction accuracy.
[0106] When constructing the dynamic adjacency matrix, considering factors such as the number of hops between nodes and feature vectors can reflect the time-varying connection relationships between entities. At the same time, using activation functions can make the matrix element values more reasonable, dynamically capture changes in entity relationships in the network, adapt to the dynamic nature of the network environment, and effectively respond to changing security risks.
[0107] The hierarchical convolution calculation combines graph convolution and the Temporal Convolution Network (TCN). Graph convolution aggregates node features in the spatial dimension to mine the correlation information between entities; TCN extracts features in the temporal dimension to analyze the temporal evolution law of risks. The combination of the two can deeply extract features from the spatio-temporal dimension to better understand the propagation and development patterns of risks.
[0108] The rectified linear unit (ReLU) is used to introduce non-linearity to enhance the expressive power of the model, enabling the model to learn more complex risk features and patterns. At the same time, the use of various matrices and parameters in the calculation process helps to optimize the feature extraction and calculation process, improving the efficiency and performance of the model.
[0109] The risk heat map is generated through kernel density estimation to visually present the risk distribution of the system. Security personnel can quickly locate high-risk areas, understand the spatial aggregation and change trends of risks, provide a clear reference basis for formulating targeted defense strategies, and improve the efficiency and effectiveness of security management.
[0110] The adaptive defense decision-making module is used to obtain the resource constraints of the system to be monitored based on the risk heat map and obtain the defense strategy set and resource allocation plan for the system to be monitored.
[0111] The specific analysis process is as follows: Obtain the resource constraints of the system to be monitored, including but not limited to the CPU resource constraints, memory resource constraints, and bandwidth resource constraints of the system to be monitored;
[0112] State definition: s t =[max(R map ), entropy(R map ), CPU usage ; In the formula, s t is the state vector, max(R map ) is the maximum value in the risk heat map R map , entropy(R map ) is the entropy of the risk heat map R map , and CPU usage is the CPU usage rate;
[0113] Establish the reward function: r t =10ΔR global -∑action_cost - 5Π false_positive ; In the formula, r t is the reward value, ΔR global is the change in global risk, action_cost is the total cost of executing the action, and Π false_positive is the false alarm indicator variable, which is 1 if a false alarm occurs and 0 otherwise;
[0114] Obtain the set of action candidates stored in the database (including access control actions, security monitoring and defense actions, system resource management actions, data management actions, etc.); select an action from the set of action candidates through the ε-greedy strategy, and update the Q-table of the Q-Learning strategy after the action is executed; obtain the defense strategy set of the system to be monitored from the actions corresponding to the Q-values in the finally converged Q-table, including several combinations of defense actions; under resource constraints, select the defense action combination with the lowest cost, and screen the defense action combinations in the defense strategy set of the system to be monitored based on the mixed integer programming model to generate a resource allocation plan:
[0115] Minimize the objective function:
[0116]
[0117] Resource constraint conditions:
[0118] In the formula, min is the minimization objective, c f is the fixed cost of executing the f-th defense action, x f is the execution situation of the f-th defense action, 1 for execution and 0 for non-execution, d g is the unit usage cost of the g-th resource, y fg is the quantity of the g-th resource allocated to the f-th defense action, λ is the weight coefficient, s g is the slack variable of the g-th resource, F is the number of defense actions, G is the number of resources, a fg is the unit usage coefficient of the f-th defense action for the g-th resource, b g is the total amount of the g-th resource;
[0119] Use the solver to output the resource allocation plan.
[0120] Make defense decisions based on the risk heat map and resource constraints, which not only consider the risk situation faced by the system but also take into account the actual available resources (such as CPU, memory, bandwidth), ensuring that the formulated defense strategies and resource allocation plans are practical, and avoiding resource waste or insufficiency while effectively coping with risks.
[0121] Optimize using the Q-Learning strategy. By carefully defining the state vector (including the maximum value of the risk heat map, entropy, and CPU usage rate), comprehensively reflect the system state. Combine the reward function (comprehensive global risk change, action cost, and false alarm situation) to motivate the intelligent agent to learn the optimal defense strategy, and be able to dynamically adjust the defense actions according to the real-time state of the system, improving the pertinence and effectiveness of the defense.
[0122] The ε-greedy strategy is adopted to select actions, which balances the relationship between exploring new defense strategies and exploiting existing experience strategies. In the initial stage of system operation, exploration of new strategies is encouraged to discover better solutions; as experience accumulates, more verified and effective strategies are exploited, enabling defense decisions to maintain a certain stability while continuously adapting to changes.
[0123] Under resource constraints, a mixed-integer programming model is used to generate a resource allocation plan, aiming to minimize costs, comprehensively considering various resource-related cost coefficients and constraints. By outputting the plan through a solver, the defense action combination and resource allocation method with the lowest cost can be found, achieving the optimal allocation of resources and minimizing resource consumption to the greatest extent while meeting defense requirements.
[0124] The federated model evolution module is used to collect the edge model parameters of the system to be monitored, obtain the global model of the system to be monitored in combination with the resource allocation plan, and provide feedback.
[0125] The specific analysis process is as follows: collect the edge model parameters θ of the edge devices of the system to be monitored k , combine with the resource allocation plan, perform model aggregation, and obtain the global model of the system to be monitored:
[0126] In the formula, θ global is the aggregated global model parameter, N k is the number of samples of the k-th edge device, acc k is the accuracy rate of the predicted risk of the edge model corresponding to the k-th edge device after implementing the resource allocation plan, N v is the number of samples of the v-th edge device, acc v is the accuracy rate of the predicted risk of the edge model corresponding to the v-th edge device after implementing the resource allocation plan, and K is the total number of edge devices;
[0127] Based on the aggregated global model parameters, the global model of the system to be monitored is obtained; the global model of the system to be monitored is fed back to each edge device as the initial model for the next round of federated learning.
[0128] Without transmitting the original data, only collecting edge model parameters for model aggregation avoids the risk of privacy leakage during data transmission and processing, meets the requirements for protecting sensitive data, and is especially suitable for scenarios of systems to be monitored that are sensitive to data privacy.
[0129] Combined with the computing and storage resources of edge devices, the model training tasks are distributed to each edge device. The local resources of edge devices are fully utilized, reducing the burden of data transmission to the central server, reducing network bandwidth pressure, and improving the overall processing efficiency of the system.
[0130] Through model aggregation, the global model parameters are weighted and calculated by comprehensively considering the sample quantity and model accuracy of each edge device. Edge devices with a large number of samples and high accuracy have a greater impact on the global model, enabling the global model to integrate the advantages of multiple edge models, effectively improving the generalization ability and prediction accuracy of the model, and better coping with diverse monitoring data and complex security threats.
[0131] The global model is fed back to each edge device as the initial model for the next round of federated learning, forming a closed-loop optimization and iteration mechanism. Over time and with the participation of more data, the model can continuously adapt to new security threats and system changes, and continuously improve the monitoring and defense capabilities.
[0132] The distributed model training and evolution method reduces the dependence on a single central server. Even if some edge devices fail or are attacked, other devices can still continue to participate in model training and updating, ensuring the normal operation of the system and the continuous evolution of the model, and enhancing the robustness and reliability of the entire system.
[0133] The intelligent forensics and traceability module is used to perform intelligent forensics and traceability based on the local anomaly markers and entity association matrix of the system to be monitored, and obtain the attack path map and attacker fingerprint database of the system to be monitored.
[0134] The specific analysis process is as follows: The local anomaly markers and entity association matrix of the system to be monitored are used as inputs;
[0135] Causal reasoning is carried out, and the backdoor adjustment formula:
[0136] In the formula, P(Y∣do(X)) is the probability distribution of the result variable Y under the condition of intervening on the intervened variable X (for example, after blocking the IP, the data leakage risk drops from 30% to 5%), P(Y∣X,Z = z) is the probability distribution of the result variable Y under the condition that the intervened variable X is known and the set of confounding variables Z that satisfies the backdoor criterion takes the value z, and P(Z = z) is the probability that the set of confounding variables Z that satisfies the backdoor criterion takes the value z;
[0137] The attack path map of the system to be monitored is obtained;
[0138] For the intervened variable X (such as blocking a certain IP, closing the vulnerability exploitation port), it is triggered by the A edge anomaly marker variable. When A edge is 1, the intervention is executed, such as blocking the attacker's IP, that is, do(X) is 1. The set of confounding variables Z that satisfies the backdoor criterion needs to satisfy that the intervened variable X and the result variable Y are related, and at the same time, it is not on the causal path from X to Y (that is, it does not mediate the influence of X on Y), and is screened from the entity association matrix.
[0139] Generate attacker fingerprint:
[0140] H mash =SHA3(MD5(IP)||SimHash(UA)||WLSH(behavior sequence));
[0141] In the formula, H mash is the attacker's fingerprint, IP is the IP address, UA is the user agent string, behavior sequence is the attacker's operation steps and behavior sequence in the system, SHA3, MD5, SimHash, WLSH are hash algorithms;
[0142] Output the attacker fingerprint library.
[0143] With the help of local anomaly markers and entity association matrix, and using the backdoor adjustment formula in causal reasoning, we can deeply analyze the causal relationship between various factors and accurately sort out the propagation path in the system when the attack occurs. This helps security personnel to clearly understand the full picture of the attack, including the starting point, the nodes passed through, and the diffusion method, providing key clues for subsequent vulnerability repair and defense strategy formulation.
[0144] By applying multiple hash algorithms to information such as the attack source IP address, user agent string, and behavior sequence, the attacker's fingerprint is generated, and the attacker's characteristics are characterized from multiple dimensions. These unique fingerprint information can be used to distinguish different attackers and accumulate data for tracking the attacker's identity and behavior pattern.
[0145] The output attack path diagram and attacker fingerprint library build a comprehensive attack information resource library for the system. The attack path diagram records historical attack situations, which is convenient for analyzing attack trends and common methods; the attacker fingerprint library can be used to compare and identify whether new attacks come from known attackers, improving the ability to prevent repeated attacks or similar attackers.
[0146] Reference Figure 2 As shown, the second aspect of the present invention provides an intelligent security management and risk prediction method based on cloud computing, including the following steps: collecting multimodal features and external threat intelligence of the system to be monitored, outputting the encrypted feature vector of the system to be monitored and performing local anomaly marking, constructing a threat knowledge graph, and obtaining an entity association matrix.
[0147] The network topology data of the system to be monitored is obtained, and the spatiotemporal risk prediction is performed in combination with the threat knowledge graph to obtain the risk heat map of the system to be monitored.
[0148] Based on the risk heat map and the resource constraints of the system to be monitored, the defense strategy set and resource allocation plan of the system to be monitored are obtained.
[0149] Collect the edge model parameters of the system to be monitored, combine with the resource allocation scheme to obtain the global model of the system to be monitored and give feedback.
[0150] Based on the local anomaly markers and entity association matrix of the system to be monitored, conduct intelligent forensic tracing to obtain the attack path diagram and attacker fingerprint database of the system to be monitored.
[0151] The above content is only an example and illustration of the structure of the present invention. Those skilled in the art of the present technology can make various modifications or supplements to the described specific embodiments or use similar methods for substitution. As long as they do not deviate from the structure of the invention or exceed the scope defined by this claim, they should fall within the protection scope of the present invention.
Claims
1. An intelligent security management and risk prediction system based on cloud computing, characterized in that, It includes a multi-modal threat analysis module, a spatio-temporal risk prediction module, an adaptive defense decision-making module, a federated model evolution module, and an intelligent forensics and traceability module, where: The multi-modal threat analysis module is used to collect the multi-modal features of the system to be monitored and external threat intelligence, output the encrypted feature vector of the system to be monitored and perform local anomaly marking, construct a threat knowledge graph, and obtain an entity association matrix; The spatio-temporal risk prediction module is used to obtain the network topology data of the system to be monitored, combine it with the threat knowledge graph to perform spatio-temporal risk prediction, and obtain the risk heat map of the system to be monitored; The adaptive defense decision-making module is used to obtain the resource constraints of the system to be monitored based on the risk heat map, and obtain the defense strategy set and resource allocation plan of the system to be monitored; The federated model evolution module is used to collect the edge model parameters of the system to be monitored, combine the resource allocation plan to obtain the global model of the system to be monitored and give feedback; The intelligent forensics and traceability module is used to perform intelligent forensics and traceability based on the local anomaly marking and entity association matrix of the system to be monitored, and obtain the attack path map and attacker fingerprint library of the system to be monitored; The multi-modal threat analysis module includes: The multi-modal threat perception subsystem is used to collect the multi-modal features of the system to be monitored, perform multi-modal threat perception, output the encrypted feature vector of the system to be monitored and perform local anomaly marking; The threat knowledge graph construction subsystem is used to construct a threat knowledge graph based on the decrypted feature vector and external threat intelligence, and obtain an entity association matrix; Collect the multi-modal features of the system to be monitored, perform multi-modal threat perception, output the encrypted feature vector of the system to be monitored and perform local anomaly marking. The specific analysis process is as follows: Collect the multi-modal features of the system to be monitored, specifically including the network traffic packets, API call sequences, and container behavior logs of the system to be monitored; Perform multi-modal threat perception on the multi-modal features of the system to be monitored: Perform time-series feature extraction, and use the LSTM-Attention model to process the multi-modal features of the system to be monitored: LSTM hidden state: h t = LSTM(x t , h t-1 ); where h t is the LSTM hidden state at time step t, x t is the input data at time step t, specifically the network traffic packets, API call sequences, and container behavior logs of the system to be monitored, and h t-1 is the LSTM hidden state at time step t-1; Attention weight: α t = softmax(W a [h t ; H t-k:t ); where α t is the attention weight at time step t, W a is the weight matrix in the attention mechanism, and H t-k:t is the sequence of hidden states from time step t - k to time step t; Output the encrypted feature vector of the system to be monitored: f enc = Paillier(f t ); where \(i\) is the time step index number, \(f\) t is the feature vector before encryption, \(a\) i is the attention weight at the \(i\)-th time step index position, \(h\) i is the LSTM hidden state at the \(i\)-th time step index position, \(f\) enc is the encrypted feature vector of the system to be monitored, and Paillier is the Paillier encryption algorithm; Calculate the exponentially weighted mean: μ t = 0.9μ t-1 + 0.1||f t ||2; where μ t is the exponentially weighted mean of the feature vector before encryption at time step t, and μ t-1 is the exponentially weighted mean of the feature vector before encryption at time step t - 1; Calculate the exponentially weighted standard deviation: where, σ t is the standard deviation of the feature vector before encryption at time step t, and σ t-1 is the standard deviation of the feature vector before encryption at time step t - 1; Calculate the adaptive dynamic threshold: where Q thres is the adaptive dynamic threshold, and e is the natural constant; Perform local anomaly marking on the feature vector before encryption at each moment based on the anomaly marking rule, where the anomaly marking rule is: Where A edge is an anomaly flag variable, where 1 represents an anomaly and 0 represents normal.
2. An intelligent security management and risk prediction system based on cloud computing according to claim 1, characterized in that: Construct a threat knowledge graph based on the decrypted feature vector and external threat intelligence. The specific analysis process is as follows: Decrypt the encrypted feature vector of the system to be monitored to obtain the decrypted feature vector f t ′; Map the entity corresponding to the decrypted feature vector f t ' to the vector space of the knowledge graph; Use the TransH algorithm to perform entity relationship modeling; Output the threat knowledge graph.
3. An intelligent security management and risk prediction system based on cloud computing according to claim 2, characterized in that: Obtain the entity association matrix. The specific analysis process is as follows: Calculate the multi-dimensional correlation degree: where e i′ is the initial embedding vector of entity i′, e j′ is the initial embedding vector of entity j′, cos(e i′ , e j′ ) is the cosine similarity between e i′ and e j′ , R i′ is the set of relationships related to entity i′, R j′ is the set of relationships related to entity j′, Jaccard(R i′ , R j′ ) is the Jaccard similarity between R i′ and R j′ , d geo (i′, j′) is the geographical distance between entity i′ and entity j′, m i′j′ is the multi-dimensional correlation degree between entity i′ and entity j′, and e is the natural constant; Sparsify the multi-dimensional correlation degree between entity i' and entity j': where M entity [i′, j′] is the association matrix of entity i′ and entity j′; Output entity association matrix M entity .
4. An intelligent security management and risk prediction system based on cloud computing according to claim 1, characterized in that: Obtain the network topology data of the system to be monitored, combine it with the threat knowledge graph to perform spatio-temporal risk prediction, and obtain the risk heat map of the system to be monitored. The specific analysis process is as follows: Obtain the network topology data of the system to be monitored, specifically including the logical connection relationship and node attributes of network nodes; Record each entity as a node in the threat knowledge graph; Construct a dynamic adjacency matrix: Where, W b is the weight matrix, represents the transpose of a vector, d hop (i′, j′) is the number of hops between nodes between entity i′ and entity j′, h i′ is the feature vector related to entity i′ extracted from the threat knowledge graph, h j′ is the feature vector related to entity j′ extracted from the threat knowledge graph, sigmoid is the activation function, is the element of the dynamic adjacency matrix between entity i′ and entity j′ at time step t; Hierarchical Convolution Computation: where, H (l) is the node feature matrix at the l-th layer, is the weight matrix in the convolutional operation of the l-th layer, ReLU is the rectified linear unit, TCN(H (l) ) is the convolutional operation performed by the temporal convolutional network on the node feature matrix H (l) in the time dimension, A t is the adjacency matrix at time step t, H (l+1) is the next-layer node feature matrix obtained after the convolutional calculation of the l-th layer; Risk heat map generation: Kernel density estimation: where R map (x, y) is the value of the risk heat map at the coordinates (x, y), N is the total number of entities, that is, the total number of nodes in the threat knowledge graph, h′ is the bandwidth parameter, (x i′ , y i′ ) is the coordinate position of entity i′, is the risk value of entity i′ obtained based on the node feature matrix at time step t, and K(·) is the Epanechnikov kernel function; Output the risk heat map R of the system to be monitored map .
5. An intelligent security management and risk prediction system based on cloud computing according to claim 4, characterized in that: Obtain the defense strategy set and resource allocation plan of the system to be monitored based on the risk heat map and obtain the resource constraints of the system to be monitored. The specific analysis process is as follows: Obtain the resource constraints of the system to be monitored; Status definition: s t = [max(R map ), entropy(R map ), CPU usage ; where s t is the state vector, max(R map ) is the maximum value in the risk heat map R map , entropy(R map ) is the entropy of the risk heat map R map , and CPU usage is the usage rate of the CPU; Establish the reward function: r t = 10ΔR global - Σaction_cost - 5Π false_positive ; where r t is the reward value, ΔR global is the change in global risk, action_cost is the total cost of performing an action, and Π false_positive is the false alarm indicator variable; Obtain the set of candidate actions stored in the database; Select an action from the set of candidate actions through the ε-greedy strategy, and update the Q-table of the Q-Learning strategy after the action is executed; Obtain the defense strategy set of the system to be monitored from the actions corresponding to the Q-values in the finally converged Q-table, including several defense action combinations; Under the resource constraints, select the defense action combination with the lowest cost, and screen the defense action combinations in the defense strategy set of the system to be monitored based on the mixed-integer programming model to generate a resource allocation plan: Minimize the objective function: Resource constraints: where min is the minimization objective, c f is the fixed cost of performing the f-th defense action, x f is the execution status of the f-th defense action, with execution being 1 and no execution being 0, d g is the unit usage cost of the g-th resource, y fg is the quantity of the g-th resource allocated to the f-th defense action, λ is the weight coefficient, s g is the slack variable of the g-th resource, F is the number of defense actions, G is the number of resources, a fg is the unit usage coefficient of the f-th defense action for the g-th resource, b g is the total amount of the g-th resource; Use the solver to output the resource allocation plan.
6. An intelligent security management and risk prediction system based on cloud computing according to claim 1, characterized in that: Collect the edge model parameters of the system to be monitored, and obtain the global model of the system to be monitored in combination with the resource allocation plan and give feedback. The specific analysis process is as follows: Collect the edge model parameter θ of the edge device of the system to be monitored k , and execute the resource allocation scheme for the edge device to perform model aggregation to obtain the global model of the system to be monitored: where θ global is the global model parameter after aggregation, N k is the number of samples of the k-th edge device, acc k is the accuracy rate of the predicted risk of the edge model corresponding to the k-th edge device after implementing the resource allocation scheme for the edge model, N v is the number of samples of the v-th edge device, acc v is the accuracy rate of the predicted risk of the edge model corresponding to the v-th edge device after implementing the resource allocation scheme, and K is the total number of edge devices; Based on the aggregated global model parameters, obtain the global model of the system to be monitored; Feed back the global model of the system to be monitored to each edge device as the initial model for the next round of federated learning.
7. An intelligent security management and risk prediction system based on cloud computing according to claim 1, characterized in that: Based on the local anomaly marks and entity association matrix of the system to be monitored, conduct intelligent forensic tracing to obtain the attack path graph and attacker fingerprint library of the system to be monitored. The specific analysis process is as follows: Take the local anomaly marks and entity association matrix of the system to be monitored as inputs; Conduct causal reasoning, backdoor adjustment formula: In the formula, P(Y∣do(X)) is the probability distribution of the result variable Y under the condition of intervening in the intervened variable X, P(Y∣X,Z=z) is the probability distribution of the result variable Y under the condition that the intervened variable X and the set of confounding variables Z that satisfy the backdoor criterion take the value z, and P(Z=z) is the probability that the set of confounding variables Z that satisfy the backdoor criterion takes the value z; Obtain the attack path graph of the system to be monitored; Generate attacker fingerprints: H mash = SHA3(MD5(IP) || SimHash(UA) || WLSH(behavior sequence)); Where H mash is the generated attacker fingerprint, IP is the IP address, UA is the user agent string, the behavior sequence is the operation steps and behavior order of the attacker in the system, and SHA3, MD5, SimHash, and WLSH are hashing algorithms; Output the attacker fingerprint library.
8. A cloud computing-based intelligent security management and risk prediction method, applied to the cloud computing-based intelligent security management and risk prediction system according to any one of claims 1-7, characterized in that, Include the following steps: Collect the multi-modal features and external threat intelligence of the system to be monitored, output the encrypted feature vector of the system to be monitored and conduct local anomaly marking, construct a threat knowledge graph, and obtain an entity association matrix; Obtain the network topology data of the system to be monitored, and conduct spatio-temporal risk prediction in combination with the threat knowledge graph to obtain the risk heat map of the system to be monitored; Based on the risk heat map and obtain the resource constraints of the system to be monitored, obtain the defense strategy set and resource allocation plan of the system to be monitored; Collect the edge model parameters of the system to be monitored, and obtain the global model of the system to be monitored in combination with the resource allocation plan and give feedback; Based on the local anomaly marks and entity association matrix of the system to be monitored, conduct intelligent forensic tracing to obtain the attack path graph and attacker fingerprint library of the system to be monitored.
Citation Information
Patent Citations
Network anomaly monitoring method and system of switch
CN119071052A
Multi-level information security policy generation method based on knowledge graph
CN119728302A
Cited By
Intelligent safety management and risk prediction method and system based on cloud computing
CN121056234A
Intelligent safety management and risk prediction method and system based on cloud computing
CN121056234B