Safety protection strategy intelligent adjustment system and method based on big data
Through the intelligent adjustment system of security protection strategy based on big data, the compatibility risks and security vulnerabilities of high-security systems during updates and access are solved, and efficient updates of security protection policies and long-term and stable operation of the system are achieved.
Patent Information
- Application Number
- CN202510534134.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-27
AI Technical Summary
When systems with high security requirements are frequently updated or external security equipment are connected, the compatibility risk increases, resulting in an increase in the probability of system downtime, and the system lagging updates accumulate security vulnerabilities, making them vulnerable when facing network attacks.
The intelligent adjustment system of security protection strategy based on big data is adopted. By obtaining the security protection task data of each node of the system, the allocation coefficient of the security protection module processing tasks is calculated, the update income and compatibility risks are evaluated, and the security protection strategy is adjusted to ensure the stable operation of the system.
Through phased optimization and cyclic updates, we ensure the efficiency and stability of security protection policy updates, reduce resource utilization inefficiency during system updates, and improve the stability and security of long-term system operation.
Smart Images

Figure CN120068094A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security protection strategy adjustment, and specifically to an intelligent adjustment system and method for security protection strategies based on big data. Background Art
[0002] In systems with high security requirements, frequent system updates or large-scale access of external security devices will increase the system compatibility risk, resulting in a significant increase in the system downtime probability. At the same time, it is also not conducive to the system data security management.
[0003] Regarding the above problems, on the one hand, there is a compatibility evaluation method based on the test environment, which conducts simulation environment tests on the system patches to be updated. When actually updating the system, the full-node update method is still used for patch updates. When compatibility failures not found in the test environment occur, version backtracking cannot be effectively and timely carried out to reduce the impact of the failures. On the other hand, to avoid system failures in the production environment caused by the one-sidedness of compatibility simulation during system update testing, many operating systems clearly require not to upgrade system patches or restrict users from upgrading patches by themselves during management. The lagging update of the system will accumulate a large number of security vulnerabilities after long-term operation. Coupled with the lack of scientific management and technical protection means during the daily operation and maintenance process, it appears extremely vulnerable when facing network attacks, bringing great potential hazards to safe production.
[0004] Therefore, an intelligent adjustment system and method for security protection strategies based on big data are needed to solve the above technical problems. Summary of the Invention
[0005] The purpose of the present invention is to provide an intelligent adjustment system and method for security protection strategies based on big data to solve the problems raised in the prior art.
[0006] To achieve the above purpose, the present invention provides the following technical solutions:
[0007] An intelligent adjustment method for security protection strategies based on big data includes the following analysis steps:
[0008] Step S100: Obtain all the security protection task data processed by each node of the system, classify and label the historical task data according to the task type, and calculate the processing quantity ratio of each type of security protection task in each node of the system.
[0009] Step S200: Process all the security protection tasks in parallel through each node of the system and the security protection module, compare the processing results of the security protection tasks processed by each node of the system and the security protection module, and analyze and calculate the first distribution coefficient and the second distribution coefficient of the security protection module for processing the security protection tasks of each node of the system.
[0010] Step S300: Calculate the updated benefits and compatibility risks of each node in the system for allocating security protection tasks to the security protection module based on the first allocation coefficient and the second allocation coefficient. By setting the system compatibility risk threshold, determine the processing and allocation ratio of security protection tasks during the current stage of the system node security protection policy update, and send feedback on the security protection policy update and system node compatibility optimization to the system administrator;
[0011] Step S400: Update the first allocation coefficient and the second allocation coefficient according to the actual processing results of the security protection tasks, and determine the processing and allocation ratio of security protection tasks during the next stage of the system node security protection policy update.
[0012] In the above technical solution, step S100 includes the following analysis steps:
[0013] Step S101: Obtain all the security protection task data processed by each node in the system, and classify and label the security protection task data according to the task type;
[0014] For any security protection task d, it is labeled as: d[Type_d, Res_d]; where, Type_d is the task type of the security protection task d, and Res_d is the set of system resource parameters for processing the security protection task d;
[0015] Step S102: Count the number of security protection tasks of each type processed by each node in the system, and calculate the processing quantity ratio of security protection tasks of each type in each node of the system;
[0016] Classify and label the security protection tasks processed by each node in the system, providing a refined data basis for subsequent allocation of security protection tasks for each node in the system, making the task allocation predictable and quantifiable.
[0017] In the above technical solution, the calculation method of the first allocation coefficient for the security protection module to process the security protection tasks in each node of the system in step S200 is as follows:
[0018] For any system node n, the first allocation coefficient α of the security protection module for processing the security protection tasks of the system node n n The calculation formula is as follows:
[0019] α n =∑ t {[R n (t) / n t ×∑ i {∑ j [k j ×(x sys (i,j)-x mod (i,j)) / x sys (i,j)]}};
[0020] Among them, t is the numbering of the security protection task type, and R n (t) is the proportion of the number of security protection tasks of type t in the system node n, and n t is the number of security protection tasks of type t in the system node n, i is the numbering of the security protection task of type t in the system node n, j is the numbering of the system resource parameters of the security protection task, and k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the security protection task, and x sys (i, j) is the data of the j-th system resource parameter when the system node processes the security protection task i, and x mod (i, j) is the data of the j-th system resource parameter when the security protection module processes the security protection task i;
[0021] Through the calculation of the first allocation coefficient, analyze the adaptability of the security protection task processed in the security protection module, and accurately quantify the improvement of the system resource utilization efficiency accompanied by the migration of the security protection tasks of each system node.
[0022] In the above technical solution, the calculation method of the second allocation coefficient for the security protection module to process the security protection tasks in each system node in step S200 is as follows:
[0023] For any system node n, the second allocation coefficient β of the security protection module to process the security protection tasks of the system node n n The calculation formula is as follows:
[0024] β n =∑ t {[R n (t) / n t ×∑ i {∑ j [k j ×x mod (i, j) / Res mod}};
[0025] Among them, n t is the number of security protection task types, t is the numbering of the security protection task type, and R n (t) is the proportion of the number of security protection tasks of type t in the system node n, and n t is the number of security protection tasks of type t in the system node n, i is the numbering of the security protection task of type t in the system node n, j is the numbering of the system resource parameters of the security protection task, and k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the security protection task, and x mod (i, j) is the data of the j-th system resource parameter when the security protection module processes the security protection task i, and Res mod(j) is the allocable amount of system resources corresponding to the j-th system resource parameter when the security protection module processes security protection tasks;
[0026] Through the calculation of the second allocation coefficient, analyze the resource allocation compatibility brought by the processing of security protection tasks in the security protection module, and accurately quantify the resource allocation compatibility risks accompanied by the migration of security protection tasks for each node in the system.
[0027] In the above technical solution, step S300 includes the following analysis steps:
[0028] According to the first allocation coefficient and the second allocation coefficient, calculate the updated benefits and compatibility risks of allocating security protection tasks from each node in the system to the security protection module. By setting the system compatibility risk threshold, determine the processing allocation ratio of security protection tasks in the current stage of the security protection strategy update for each node in the system, and send feedback on the security protection strategy update and system node compatibility optimization to the system administrator;
[0029] Step S301: Calculate the updated benefits and compatibility risks of allocating security protection tasks from each node in the system to the security protection module;
[0030] The updated benefit is the product of the processing allocation ratio of the security protection task of the system node and the first allocation coefficient for the security protection module to process this node, and the compatibility risk is the product of the processing allocation ratio of the security protection task of the system node and the second allocation coefficient for the security protection module to process this node;
[0031] Step S302: Set the system compatibility risk threshold Th risk , and construct the following compatibility risk constraints:
[0032] (1) The sum of the compatibility risks of allocating security protection tasks from all system nodes to the security protection module is less than or equal to Th risk ;
[0033] (2) The sum of the updated benefits of allocating security protection tasks from all system nodes to the security protection module is the largest;
[0034] Step S303: According to the above compatibility risk constraints, adjust the security protection strategies of each node in the system, update the processing allocation ratio of security protection tasks in the current stage, and send feedback on the security protection strategy update and system node compatibility optimization to the system administrator;
[0035] Comprehensively analyze the system resource allocation efficiency gain and compatibility risks when migrating security protection tasks for each node in the system. Through optimal decision-making, on the basis of ensuring controllable compatibility risks, maximize the update efficiency of the security protection strategies for each node in the system and accelerate the update progress of the security protection strategies for each node in the system.
[0036] In the above technical solution, step S400 includes the following content:
[0037] When the system administrator updates the security protection policies of each system node and optimizes the compatibility of system nodes, the processing allocation ratio of security protection tasks in the current stage is updated according to the security protection policies of each system node, and the security protection tasks in each system node are allocated; after the security protection policies of each system node are updated and the compatibility of system nodes is optimized, it is determined that the current stage of the security protection policy update of each system node ends, and the security protection policy update of the next stage starts;
[0038] Obtain the available system resources of the security protection module after the compatibility optimization of the system node, and synchronously update the security protection task ratio of each system node according to the allocation result; obtain all the security protection task data processed by each system node in the current stage of the security protection policy update of each system node, and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks in each system node based on this data;
[0039] Repeat the above security protection policy update process until the security protection tasks of all system nodes are allocated to the security protection module;
[0040] Quantitatively evaluate the adaptability of the security protection module in each stage of system update and the security protection task processing service of the original system through the method of task parallel processing and stage-by-stage update, reduce the risk of system downtime that may be brought by large-scale task adjustments at one time, reduce the probability of system sudden abnormal accidents, and improve the long-term operation stability of the system.
[0041] A security protection policy intelligent adjustment system based on big data in the above technical solution, the system includes: a security protection monitoring module, a task allocation analysis module, and a system update decision module;
[0042] The security protection monitoring module obtains the security protection task data of each system node for classification and annotation, and calculates the processing quantity ratio of each type of security protection task in each system node; the task allocation analysis module compares the processing results of the security protection tasks of each system node and the security protection module, calculates the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each system node, and updates the data in each stage of the security protection policy update of the system; the system update decision module calculates the update benefit and compatibility risk of allocating the security protection tasks of each system node to the security protection module, and determines the processing allocation ratio of the security protection tasks of each system node.
[0043] In the above technical solution, the security protection monitoring module includes: a task data processing unit, a task data statistics unit;
[0044] The task data processing unit obtains all the security protection task data processed by each node of the system, and classifies and labels the historical task data according to the task type; the task data statistics unit is used to calculate the proportion of the processing quantities of various types of security protection tasks in each node of the system.
[0045] In the above technical solution, the task allocation analysis module includes: a parallel processing analysis unit, an allocation coefficient analysis unit, and a data update unit;
[0046] The parallel processing analysis unit performs parallel processing on all security protection tasks through each node of the system and the security protection module, and compares the processing results of the security protection tasks by each node of the system and the security protection module; the allocation coefficient analysis unit is used to analyze and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system; the data update unit is used to update the allocable amount of system resources of the security protection module, the proportion of security protection tasks of each node of the system, the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks in each node of the system after the system node compatibility optimization.
[0047] In the above technical solution, the system update decision module includes: a system update evaluation unit and a task allocation ratio decision unit;
[0048] The system update evaluation unit evaluates and calculates the update benefits and compatibility risks of each node of the system for allocating security protection tasks to the security protection module according to the first allocation coefficient and the second allocation coefficient; the task allocation ratio decision unit determines the processing allocation ratio of security protection tasks in the current stage of the security protection strategy update of each node of the system by setting a system compatibility risk threshold.
[0049] Compared with the prior art, the beneficial effects of the present invention are:
[0050] In the present invention, the security protection strategies of each node of the system are optimized and iteratively updated in stages. In the system security protection task allocation decision-making, the optimal decision is made based on constraints, ensuring the high efficiency of the security protection strategy update on the premise of the stable operation of the system;
[0051] In the present invention, a phased parallel task allocation decision-making method is adopted to ensure the synchronization of the system update strategy and the compatibility optimization, further ensuring the stability of the multi-stage update process of the system, and significantly optimizing the utilization efficiency of resources in the system update process;
[0052] In the present invention, by performing staged updates on the allocation coefficient and system data, fully considering the utilization efficiency of system resources after the update, and timely and effectively adjusting and optimizing the update iteration of the system security protection strategy according to the actual resource utilization effect in different stages of the system update, effectively ensuring the timeliness and feasibility of the system decision-making. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 It is a flowchart of an intelligent adjustment method for a security protection strategy based on big data according to the present invention;
[0054] Figure 2 It is an organizational structure diagram of an intelligent adjustment system for a security protection strategy based on big data according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0056] Embodiment: Please refer to Figure 1 - Figure 2 , the present invention provides the following technical solutions:
[0057] As Figure 1 shown, the present application provides an intelligent adjustment method for a security protection strategy based on big data, including the following analysis steps:
[0058] Step S100: Obtain all security protection task data processed by each node of the system, classify and label the historical task data according to the task type, and calculate the processing quantity ratio of each type of security protection task in each node of the system;
[0059] Step S200: Parallel-process all security protection tasks through each node of the system and the security protection module, compare the processing results of the security protection tasks processed by each node of the system and the security protection module, and analyze and calculate the first distribution coefficient and the second distribution coefficient of the security protection module for processing the security protection tasks of each node of the system;
[0060] Step S300: According to the first distribution coefficient and the second distribution coefficient, calculate the update benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module, determine the processing allocation ratio of the security protection tasks in the current stage of the security protection strategy update of each node of the system by setting a system compatibility risk threshold, and send feedback on the security protection strategy update and system node compatibility optimization to the system administrator;
[0061] Step S400: Update the first distribution coefficient and the second distribution coefficient according to the actual processing results of the security protection tasks, and determine the processing allocation ratio of the security protection tasks in the next stage of the security protection strategy update of each node of the system;
[0062] In specific implementation, following the relevant regulations of the third level of GB / T 20272-2006 "Information Security Technology - Operating System Security Technical Requirements" for classified protection, in systems that require a higher security level, various types of security protection strategies such as identity authentication, trusted measurement of executed programs, program installation control, and malicious code protection are required. To ensure the long-term stability of the system and data security, some systems choose to ignore updates and iterations and use outdated security protection strategies for a long time, which places great pressure on the system's own operation and security protection.
[0063] Regarding the above problems, in order to balance the long-term security stability of the system and the requirement for updating security protection strategies, in this application, the system is subject to phased migration of security protection tasks based on the security protection task data processed by the system, converting the update of the system itself into the transfer of the system's security protection pressure, effectively avoiding the impact on the system operation caused by the resource allocation compatibility risk during the update of the system's security protection strategy.
[0064] Step S100 includes the following analysis steps:
[0065] Step S101: Obtain all the security protection task data processed by each node of the system, and classify and label the security protection task data according to the task type.
[0066] For any security protection task d, it is labeled as: d[Type_d, Res_d]; where Type_d is the task type of security protection task d, and Res_d is the set of system resource parameters for processing security protection task d.
[0067] Step S102: Count the number of security protection tasks of each type processed by each node of the system, and calculate the proportion of the number of security protection tasks processed of each type in each node of the system.
[0068] In specific implementation, since real-time parallel processing data of security protection tasks for comparison cannot be obtained in the system during the initial update, historical data of security protection tasks processed by the system is collected and simulated through an externally connected security protection module, serving as the data basis for security protection task allocation decisions in the initial update stage.
[0069] The calculation method of the first allocation coefficient for the security protection module to process security protection tasks in each node of the system in step S200 is as follows:
[0070] For any system node n, the first allocation coefficient α of the security protection module for processing security protection tasks of system node n n The calculation formula is as follows:
[0071] α n =∑ t {[R n (t) / nt ×∑ i {∑ j [k j ×(x sys (i,j)-x mod (i,j)) / x sys (i,j)]}};
[0072] Among them, t is the safety protection task type number, and R n (t) is the proportion of the number of safety protection tasks of type t in system node n, and n t is the number of safety protection tasks of type t in system node n, i is the safety protection task number of type t in system node n, j is the safety protection task system resource parameter number, and k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the safety protection task, and x sys (i,j) is the data of the j-th system resource parameter when system node processes safety protection task i, and x mod (i,j) is the data of the j-th system resource parameter when the safety protection module processes safety protection task i;
[0073] In specific implementation, the first allocation coefficient α of the safety protection module for processing the safety protection tasks of system node n n is used to quantify the optimization effect of the utilization efficiency of system resources when the safety protection tasks of system node n are migrated to the safety protection module for processing;
[0074] Furthermore, in the calculation of the first allocation coefficient, by parallel processing to compare the system resource parameters when the system and the safety protection module process each task, the optimization degree of the utilization efficiency of system resources when the safety protection tasks of each system node are migrated to the safety protection module is measured;
[0075] Furthermore, assume that system node n processes 2 types of safety protection tasks, namely identity authentication and malicious code protection; among them, the number of identity authentication tasks is 2, accounting for 2 / 3, and the number of malicious code protection tasks is 1, accounting for 1 / 3; the allocation evaluation weight coefficient of CPU occupancy is 0.6, and the allocation evaluation weight coefficient of memory occupancy is 0.4;
[0076] Task 1: When the system processes, the quantified value of CPU occupancy is 50%, and the memory occupancy is 200MB. When the safety protection module processes, the quantified value of CPU occupancy is 55%, and the memory occupancy is 180MB;
[0077] Task 2: When the system processes, the quantified value of CPU occupancy is 60%, and the memory occupancy is 250MB. When the safety protection module processes, the quantified value of CPU occupancy is 58%, and the memory occupancy is 230MB;
[0078] Task 3: When the system is processing, the quantified CPU occupancy is 40%, and the memory occupancy is 150MB. When the security protection module is processing, the quantified CPU occupancy is 42%, and the memory occupancy is 140MB;
[0079] Among them, the quantified CPU occupancy refers to the value obtained by unifying the data scale of the actual CPU occupancy rate according to the maximum CPU load capacity. For example, if the maximum CPU load capacity of the security protection module is twice that of the original system, for the same actual CPU occupancy rate, the quantified CPU occupancy in the security protection module is 1 / 2 of that in the original system;
[0080] Calculate the first allocation coefficient α of the security protection module processing node n n =0.00956.
[0081] The calculation method of the second allocation coefficient for the security protection tasks in each node of the security protection module processing system in step S200 is as follows:
[0082] For any system node n, the second allocation coefficient β of the security protection module processing the security protection task of system node n n The calculation formula is as follows:
[0083] β n =∑ t {[R n (t) / n t ×∑ i {∑ j [k j ×x mod (i,j) / Res mod (j)]}};
[0084] Among them, n t is the number of security protection task types, t is the security protection task type number, R n (t) is the proportion of the number of security protection tasks of type t in system node n, n t is the number of security protection tasks of type t in system node n, i is the security protection task number of type t in system node n, j is the security protection task system resource parameter number, k j is the allocation evaluation weight coefficient of the jth system resource parameter in the security protection task, x mod (i,j) is the data of the jth system resource parameter when the security protection module processes security protection task i, Res mod (j) is the allocable amount of the system resource corresponding to the jth system resource parameter when the security protection module processes the security protection task;
[0085] In specific implementation, the second allocation coefficient β of the security protection module processing the security protection task of system node n nIt is used to quantify the resource occupancy pressure of the security protection tasks in each node of the system migrated to the externally connected security protection module, and then reflect the compatibility risk of the system resource allocation for processing the security protection tasks of each node when using the externally connected security protection module to share the system security protection pressure;
[0086] Further, in the calculation of the second distribution coefficient, the proportion of the system resources of each security protection task to the allocable amount of resources of the security protection module is introduced to reflect the resource allocation pressure on the security protection module when each security protection task is migrated to the security protection module. The greater the resource consumption of a task, the higher the risk of competing for system resources. Furthermore, it can measure the compatibility risk of resource allocation when the security protection tasks of each node of the system are migrated;
[0087] Further, using the above parameter data, assume that the CPU occupancy in the allocable amount of system resources of the security protection module is 200% (the CPU allocable carrying capacity of the security protection module is twice that of the original system node), and the allocable amount of memory of the security protection module is 500MB;
[0088] It can be calculated that the second distribution coefficient β of the security protection module for processing node n n =0.1905.
[0089] The following analysis steps are included in step S300:
[0090] According to the first distribution coefficient and the second distribution coefficient, calculate the updated benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module. By setting the system compatibility risk threshold, determine the processing allocation ratio of security protection tasks in the current stage of the system security protection strategy update, and send feedback on the system security protection strategy update and system node compatibility optimization to the system administrator;
[0091] Step S301: Calculate the updated benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module;
[0092] The updated benefit is the product of the processing allocation ratio of the security protection task of the system node and the first distribution coefficient of the security protection module for processing this node, and the compatibility risk is the product of the processing allocation ratio of the security protection task of the system node and the second distribution coefficient of the security protection module for processing this node;
[0093] Step S302: Set the system compatibility risk threshold Th risk , and construct the following compatibility risk constraints:
[0094] (1) The sum of the compatibility risks of all system nodes for allocating security protection tasks to the security protection module is less than or equal to Th risk ;
[0095] (2) The sum of the updated benefits of all system nodes allocating security protection tasks to the security protection module is maximized;
[0096] Step S303: According to the above compatibility risk constraints, adjust the security protection policies of each system node, update the processing and allocation ratio of security protection tasks in the current stage, and send feedback on the update of the security protection policy and the compatibility optimization of system nodes to the system administrator;
[0097] In specific implementation, since the risk resistance capabilities and risk tolerance levels of different systems vary, it is necessary to set a compatibility risk threshold according to the specific system security requirements to ensure the controllability of the maximum risk of the system when updating the security protection policy, and prevent large-scale system failures and unnecessary losses;
[0098] At the same time, make an optimal decision on the migration of security protection tasks for all system nodes to ensure that the system update benefit is maximized in each update stage, that is, to maximize the system update progress, so as to avoid redundant system update time consumption, effectively improve the update efficiency of the system security protection policy, and simplify the system update process while ensuring the stable and reliable operation of the system.
[0099] Step S400 includes the following content:
[0100] When the system administrator updates the security protection policy of each system node and optimizes the compatibility of system nodes, allocate the security protection tasks in each system node according to the processing and allocation ratio of security protection tasks in the current stage of the security protection policy update of each system node; after the update of the security protection policy of each system node and the compatibility optimization of system nodes are completed, determine that the current stage of the security protection policy update of each system node ends, and start the security protection policy update of the next stage;
[0101] Obtain the available system resources of the security protection module after the compatibility optimization of the system node, and synchronously update the security protection task ratio of each system node according to the allocation result; obtain all the security protection task data processed by each system node in the current stage of the security protection policy update of each system node, and calculate the first allocation coefficient and the second allocation coefficient for the security protection module to process the security protection tasks in each system node based on this data;
[0102] Repeat the above security protection policy update process until the security protection tasks of all system nodes are allocated to the security protection module;
[0103] In specific implementation, when switching during the system update phase, calculate the allocation ratio of security protection tasks in the next phase. If the task allocation ratio of any node is small or there is no migration of security protection tasks in the next phase, it can be considered that the compatibility risk of the security protection task migration of this node is relatively high or the improvement effect of the utilization efficiency of system resources before and after is relatively average. When performing task migration, there is very likely a compatibility problem between the system node and the security protection module. For relevant compatibility problems, further optimization and processing are required to eliminate the compatibility risk after the complete update of the system security protection strategy;
[0104] Furthermore, except for using historical data for simulation testing in the initial update phase, in all subsequent update phases, a parallel synchronous processing method is adopted to monitor the system resource parameter data of the security protection module for processing the security protection tasks of each node of the system;
[0105] Furthermore, at the end of the subsequent update phase, compare and analyze the processing results of the system and the security protection module for processing security protection tasks in this phase, and update the numerical values of the first allocation coefficient and the second allocation coefficient to ensure that the final allocation ratio of security protection task migration can fully consider the effects of the system security protection strategy update in each phase, and ensure the balance and unity of the system security protection strategy update for the short-term efficiency and long-term stability of the system in each phase.
[0106] As Figure 2 shown, the present application also provides an intelligent adjustment system for security protection strategies based on big data. The system includes: a security protection monitoring module, a task allocation analysis module, and a system update decision module;
[0107] The security protection monitoring module obtains the security protection task data of each node of the system for classification and annotation, and calculates the processing quantity ratio of each type of security protection task in each node of the system; the task allocation analysis module compares the processing results of the security protection tasks of each node of the system and the security protection module, calculates the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system, and updates the data of each phase of the system security protection strategy update; the system update decision module calculates the update benefit and compatibility risk of allocating the security protection tasks of each node of the system to the security protection module, and determines the processing allocation ratio of the security protection tasks of each node of the system.
[0108] The security protection monitoring module includes: a task data processing unit and a task data statistics unit;
[0109] The task data processing unit obtains all the processed security protection task data of each node of the system, and classifies and annotates the historical task data according to the task type; the task data statistics unit is used to calculate the processing quantity ratio of each type of security protection task in each node of the system.
[0110] The task allocation analysis module includes: a parallel processing analysis unit, an allocation coefficient analysis unit, and a data update unit;
[0111] The parallel processing analysis unit performs parallel processing on all security protection tasks through each node and security protection module of the system, and compares the processing results of each node and security protection module of the system for processing security protection tasks; the allocation coefficient analysis unit is used to analyze and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system; the data update unit is used to update the allocable amount of system resources of the security protection module, the proportion of security protection tasks of each node of the system, the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system after the system node compatibility optimization.
[0112] The system update decision module includes: a system update evaluation unit and a task allocation ratio decision unit;
[0113] The system update evaluation unit evaluates and calculates the update benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module according to the first allocation coefficient and the second allocation coefficient; the task allocation ratio decision unit determines the processing allocation ratio of security protection tasks during the current stage of the security protection strategy update of each node of the system by setting a system compatibility risk threshold.
[0114] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present invention. Any reference signs in the claims should not be regarded as limiting the claimed rights.
Claims
1. A security protection strategy intelligent adjustment method based on big data, characterized in that , the method comprises the following analysis steps: Step S100: Acquire all security protection task data processed by each node of the system, classify and label the historical task data according to the task type, and calculate the proportion of each type of security protection task processed in each node of the system; Step S200: all security protection tasks are processed in parallel by the system nodes and security protection modules, the processing results of the security protection tasks processed by the system nodes and security protection modules are compared, and the first allocation coefficient and the second allocation coefficient of the security protection tasks processed by the security protection modules of the system nodes are analyzed and calculated; Step S300: Calculate the update benefits and compatibility risks of allocating security protection tasks to security protection modules at each node of the system according to the first allocation coefficient and the second allocation coefficient, set the system compatibility risk threshold, determine the security protection task processing allocation ratio in the current stage of security protection strategy update of each node of the system, and send security protection strategy update and system node compatibility optimization feedback to the system administrator; Step S400: According to the actual processing result of the security protection task, the first allocation coefficient and the second allocation coefficient are updated, and the allocation ratio of security protection task processing in the next stage of security protection strategy update of each node in the system is determined.
2. According to the method of intelligent adjustment of security protection strategy based on big data in claim 1, it is characterized in that: The step S100 includes the following analysis steps: Step S101: Acquire all security protection task data processed by each node of the system, and classify and label the security protection task data according to task type; For any security protection task d, it is marked as: d[Type_d,Res_d]; Type_d is the task type of security protection task d, and Res_d is the system resource parameter set for processing security protection task d; Step S102: Count the number of each type of security protection tasks processed by each node in the system, and calculate the proportion of each type of security protection task processed in each node in the system.
3. According to the method of intelligent adjustment of security protection strategy based on big data in claim 2, it is characterized in that: The method for calculating the first allocation coefficient of the security protection task in each node of the security protection module processing system in step S200 is as follows: For any system node n, the first allocation coefficient α of the security protection task of the security protection module processing system node n n The calculation formula is as follows: α n =∑ t {[R n (t) / n t ]×∑ i {∑ j [k j ×(x sys (i,j)-x mod (i,j)) / x sys (i,j)]}}; Among them, t is the security protection task type number, R n (t) is the proportion of type t security protection tasks in system node n, n t is the number of security protection tasks of type t for system node n, i is the number of security protection tasks of type t for system node n, j is the number of system resource parameters for security protection tasks, k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the security protection task, x sys (i,j) is the jth system resource parameter data when the system node processes security protection task i, x mod (i,j) is the j-th system resource parameter data when the security protection module processes security protection task i.
4. According to the method of intelligent adjustment of security protection strategy based on big data in claim 2, it is characterized in that: The method for calculating the second allocation coefficient of the security protection task in each node of the security protection module processing system in step S200 is as follows: For any system node n, the second allocation coefficient β of the security protection task of the security protection module for processing the system node n n The calculation formula is as follows: β n =∑ t {[R n (t) / n t ]×∑ i {∑ j [k j ×x mod (i,j) / Res mod (j)]}}; Among them, n t is the number of security protection task types, t is the security protection task type number, R n (t) is the proportion of security protection tasks of type t in system node n, n t is the number of type t security protection tasks in system node n, i is the number of type t security protection tasks in system node n, j is the number of system resource parameters of security protection tasks, k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the security protection task, x mod (i,j) is the jth system resource parameter data when the security protection module processes security protection task i, Res mod (j) is the allocatable amount of system resources corresponding to the jth system resource parameter when the security protection module processes the security protection task.
5. According to the method of intelligent adjustment of security protection strategy based on big data in claim 2, it is characterized in that: The step S300 includes the following analysis steps: According to the first allocation coefficient and the second allocation coefficient, the update benefits and compatibility risks of allocating security protection tasks to the security protection module of each node of the system are calculated, and the security protection task processing allocation ratio in the current stage of the security protection strategy update of each node of the system is determined by setting the system compatibility risk threshold, and the security protection strategy update and system node compatibility optimization feedback are sent to the system administrator; Step S301: calculating the update benefits and compatibility risks of allocating security protection tasks to security protection modules at each node of the system; The update benefit is the product of the system node security protection task processing allocation ratio and the first allocation coefficient of the security protection module processing the node, and the compatibility risk is the product of the system node security protection task processing allocation ratio and the second allocation coefficient of the security protection module processing the node; Step S302: Setting the system compatibility risk threshold Th risk , construct compatible risk constraints as follows: (1) The compatibility risk of all system nodes assigning security protection tasks to security protection modules is less than or equal to Th risk ; (2) Allocating security protection tasks to the security protection module of all system nodes maximizes the update benefits; Step S303: According to the above-mentioned compatibility risk constraints, adjust the security protection strategy of each node in the system, update the security protection task processing allocation ratio in the current stage, and send security protection strategy update and system node compatibility optimization feedback to the system administrator.
6. According to the method of intelligent adjustment of security protection strategy based on big data in claim 2, it is characterized in that: The step S400 includes the following contents: When the system administrator updates the security protection strategy of each node of the system and optimizes the compatibility of the system nodes, the security protection tasks in each node of the system are allocated according to the allocation ratio of the security protection task processing in the current stage of the security protection strategy update of each node of the system; after the security protection strategy update of each node of the system and the compatibility optimization of the system nodes are completed, it is determined that the current stage of the security protection strategy update of each node of the system is over, and the next stage of security protection strategy update begins; Obtain the allocatable amount of system resources of the security protection module after the system node is compatible with the optimization, and simultaneously update the security protection task ratio of each node in the system according to the allocation result; obtain the security protection strategy of each node in the system to update all security protection task data processed by each node in the system in the current stage, and use this as the data basis to calculate the first allocation coefficient and the second allocation coefficient of the security protection task in each node of the system processed by the security protection module; Repeat the above security protection strategy update process until the security protection tasks of all nodes in the system are assigned to the security protection module.
7. A security protection strategy intelligent adjustment system based on big data, used to execute a security protection strategy intelligent adjustment method based on big data according to any one of claims 1 to 6, characterized in that: The system includes: a security protection monitoring module, a task allocation analysis module, and a system update decision module; The security protection monitoring module obtains the security protection task data of each node in the system for classification and labeling, and calculates the proportion of each type of security protection task processing in each node of the system; the task allocation analysis module compares the security protection task processing results of each node in the system and the security protection module, calculates the first allocation coefficient and the second allocation coefficient of the security protection task processed by the security protection module for each node of the system, and updates the data of each stage of the system security protection strategy update; the system update decision module calculates the update benefits and compatibility risks of allocating security protection tasks of each node in the system to the security protection module, and determines the security protection task processing allocation ratio of each node in the system.
8. The intelligent adjustment system for security protection strategies based on big data according to claim 7 is characterized in that: The safety protection monitoring module includes: a task data processing unit and a task data statistics unit; The task data processing unit obtains all security protection task data processed by each node of the system, and classifies and labels the historical task data according to the task type; the task data statistics unit is used to calculate the proportion of the number of security protection tasks of each type processed in each node of the system.
9. The intelligent adjustment system for security protection strategy based on big data according to claim 7 is characterized in that: The task allocation analysis module includes: a parallel processing analysis unit, an allocation coefficient analysis unit, and a data update unit; The parallel processing analysis unit processes all security protection tasks in parallel through each node and security protection module of the system, and compares the processing results of the security protection tasks processed by each node and security protection module of the system; the allocation coefficient analysis unit is used to analyze and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system; the data update unit is used to update the allocatable amount of system resources of the security protection module, the ratio of security protection tasks of each node of the system, and the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system after the system node compatibility optimization.
10. The intelligent adjustment system for security protection strategy based on big data according to claim 7 is characterized in that: The system update decision module includes: a system update evaluation unit and a task allocation ratio decision unit; The system update evaluation unit evaluates the update benefits and compatibility risks of allocating security protection tasks to the security protection module at each node of the computing system based on the first allocation coefficient and the second allocation coefficient; the task allocation ratio decision unit determines the security protection task processing allocation ratio in the current stage of the security protection strategy update of each node in the system by setting the system compatibility risk threshold.
Citation Information
Patent Citations
Safety protection method and system for enterprise technology promotion information
CN111355727A
Artificial intelligence server with intelligent safety protection
CN115080968A
Wireless communication network information security protection system and method based on edge nodes
CN118695249A