An intelligent adjustment system and method for security protection strategies based on big data

Through big data analysis and phased optimization security protection strategies, the compatibility risks and security vulnerability problems in system updates are solved, and the system stability and security are improved.

CN120068094BActive Publication Date: 2025-07-08HUAGUANG (ZHUHAI) ELECTRIC POWER TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510534134.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-08
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

In the prior art, system updates or external security equipment access increase the risk of system compatibility, resulting in an increase in the probability of downtime, and the system lagging update accumulates security vulnerabilities, lacks scientific management, and is fragile when facing network attacks.

Method used

The intelligent adjustment method of security protection strategy based on big data is adopted. By obtaining the security protection task data of each node of the system, calculating the allocation coefficient, setting compatibility risk thresholds, optimizing security protection policies in stages, and performing parallel task processing and updates to ensure system stability and security.

Benefits of technology

It reduces the risk of downtime during system update, improves the stability and security of the system's long-term operation, optimizes resource utilization efficiency, and ensures the efficiency and feasibility of system updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068094B_ABST
    Figure CN120068094B_ABST
Patent Text Reader

Abstract

The present invention discloses an intelligent adjustment system and method for security protection strategies based on big data, which relates to the technical field of security protection strategy adjustment. The system includes: a security protection monitoring module, a task assignment analysis module, and a system update decision module. The security protection monitoring module obtains the security protection task data of each node of the system for classification and annotation, and calculates the proportion of the processing quantities of various types of security protection tasks in each node of the system. The task assignment analysis module compares the processing results of security protection tasks of each node of the system and the security protection module, calculates the first assignment coefficient and the second assignment coefficient for the security protection module to process the security protection tasks of each node of the system, and updates the data in each stage of the system security protection strategy update. The system update decision module calculates the update benefits and compatibility risks of assigning security protection tasks of each node of the system to the security protection module, and determines the processing assignment ratio of the security protection tasks of each node of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security protection strategy adjustment, and specifically to an intelligent adjustment system and method for security protection strategies based on big data. Background Art

[0002] In systems with high security requirements, frequent system updates or large-scale access of external security devices will increase the system compatibility risk, leading to a significant increase in the probability of system downtime. At the same time, it is also not conducive to the security management of system data.

[0003] Regarding the above problems, on the one hand, there is a compatibility evaluation method based on a test environment. The system patches to be updated are tested in a simulation environment. When actually updating the system, the full-node update method is still used for patch update. When compatibility failures not found in the test environment occur, version rollback cannot be effectively and timely carried out to reduce the impact of the failures. On the other hand, to avoid system failures in the production environment caused by the one-sidedness of compatibility simulation during system update testing, many operating systems clearly require not to upgrade system patches or restrict users from upgrading patches by themselves during management. However, the lagged update of the system will accumulate a large number of security vulnerabilities after long-term operation. Coupled with the lack of scientific management and technical protection means during daily operation and maintenance, it becomes extremely vulnerable when facing network attacks, bringing great hidden dangers to safe production.

[0004] Therefore, an intelligent adjustment system and method for security protection strategies based on big data are needed to solve the above technical problems. Summary of the Invention

[0005] The purpose of the present invention is to provide an intelligent adjustment system and method for security protection strategies based on big data to solve the problems raised in the prior art.

[0006] To achieve the above purpose, the present invention provides the following technical solutions:

[0007] An intelligent adjustment method for security protection strategies based on big data includes the following analysis steps:

[0008] Step S100: Obtain all the security protection task data processed by each node of the system, classify and label the historical task data according to the task type, and calculate the processing quantity ratio of each type of security protection task in each node of the system.

[0009] Step S200: Process all the security protection tasks in parallel through each node of the system and the security protection module, compare the processing results of the security protection tasks processed by each node of the system and the security protection module, and analyze and calculate the first distribution coefficient and the second distribution coefficient of the security protection module for processing the security protection tasks of each node of the system.

[0010] Step S300: Calculate the updated benefits and compatibility risks of each node in the system for allocating security protection tasks to the security protection module based on the first allocation coefficient and the second allocation coefficient. By setting the system compatibility risk threshold, determine the processing and allocation ratio of security protection tasks during the current stage of the system node security protection strategy update, and send feedback on the security protection strategy update and system node compatibility optimization to the system administrator.

[0011] Step S400: Update the first allocation coefficient and the second allocation coefficient according to the actual processing results of the security protection tasks, and determine the processing and allocation ratio of security protection tasks during the next stage of the system node security protection strategy update.

[0012] In the above technical solution, step S100 includes the following analysis steps:

[0013] Step S101: Obtain all the security protection task data processed by each node in the system, and classify and label the security protection task data according to the task type.

[0014] For any security protection task d, it is labeled as: d[Type_d, Res_d]; where, Type_d is the task type of security protection task d, and Res_d is the set of system resource parameters for processing security protection task d.

[0015] Step S102: Count the number of security protection tasks of each type processed by each node in the system, and calculate the processing quantity ratio of security protection tasks of each type in each node of the system.

[0016] Classify and label the security protection tasks processed by each node in the system, providing a refined data basis for subsequent allocation of security protection tasks for each node in the system, making the task allocation predictable and quantifiable.

[0017] In the above technical solution, the calculation method of the first allocation coefficient for the security protection module to process the security protection tasks in each node of the system in step S200 is as follows:

[0018] For any system node n, the first allocation coefficient α of the security protection module for processing the security protection tasks of system node n n The calculation formula is as follows:

[0019] α n =∑ t {[R n (t) / n t ×∑ i {∑ j [k j ×(x sys (i,j)-x mod (i,j)) / x sys (i,j)]}};

[0020] Among them, t is the safety protection task type number, and R n (t) is the proportion of the number of safety protection tasks of type t in system node n, and n t is the number of safety protection tasks of type t in system node n, i is the number of the safety protection task of type t in system node n, j is the number of the system resource parameter of the safety protection task, and k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the safety protection task, and x sys (i, j) is the data of the j-th system resource parameter when system node processes the safety protection task i, and x mod (i, j) is the data of the j-th system resource parameter when the safety protection module processes the safety protection task i;

[0021] Through the calculation of the first allocation coefficient, analyze the adaptability of the safety protection task processed in the safety protection module, and accurately quantify the improvement of the system resource utilization efficiency accompanied by the migration of the safety protection tasks of each system node.

[0022] In the above technical solution, the calculation method of the second allocation coefficient for the safety protection module to process the safety protection tasks in each system node in step S200 is as follows:

[0023] For any system node n, the second allocation coefficient β of the safety protection module to process the safety protection tasks of system node n n The calculation formula is as follows:

[0024] β n =∑ t {[R n (t) / n t ×∑ i {∑ j [k j ×x mod (i, j) / Res mod}};

[0025] Among them, n t is the number of safety protection task types, t is the safety protection task type number, and R n (t) is the proportion of the number of safety protection tasks of type t in system node n, and n t is the number of safety protection tasks of type t in system node n, i is the number of the safety protection task of type t in system node n, j is the number of the system resource parameter of the safety protection task, and k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the safety protection task, and x mod (i, j) is the data of the j-th system resource parameter when the safety protection module processes the safety protection task i, and Res mod(j) is the allocable amount of system resources corresponding to the j-th system resource parameter when the security protection module processes security protection tasks;

[0026] Through the calculation of the second allocation coefficient, analyze the resource allocation compatibility brought by the processing of security protection tasks in the security protection module, and accurately quantify the resource allocation compatibility risk accompanying the migration of security protection tasks at each node of the system.

[0027] In the above technical solution, the analysis steps included in step S300 are as follows:

[0028] According to the first allocation coefficient and the second allocation coefficient, calculate the updated benefit and compatibility risk of each node in the system for allocating security protection tasks to the security protection module. By setting the system compatibility risk threshold, determine the processing allocation ratio of security protection tasks in the current stage of the update of the security protection strategy for each node in the system, and send feedback on the update of the security protection strategy and the compatibility optimization of system nodes to the system administrator;

[0029] Step S301: Calculate the updated benefit and compatibility risk of each node in the system for allocating security protection tasks to the security protection module;

[0030] The updated benefit is the product of the processing allocation ratio of the security protection task of the system node and the first allocation coefficient for the security protection module to process this node, and the compatibility risk is the product of the processing allocation ratio of the security protection task of the system node and the second allocation coefficient for the security protection module to process this node;

[0031] Step S302: Set the system compatibility risk threshold Th risk , and construct the following compatibility risk constraints:

[0032] (1) The sum of the compatibility risks of all system nodes for allocating security protection tasks to the security protection module is less than or equal to Th risk ;

[0033] (2) The sum of the updated benefits of all system nodes for allocating security protection tasks to the security protection module is the largest;

[0034] Step S303: According to the above compatibility risk constraints, adjust the security protection strategies of each node in the system, update the processing allocation ratio of security protection tasks in the current stage, and send feedback on the update of the security protection strategy and the compatibility optimization of system nodes to the system administrator;

[0035] Comprehensively analyze the gain of system resource allocation efficiency and compatibility risk when the security protection tasks of each node in the system are migrated. Through optimal decision-making, on the basis of ensuring that the compatibility risk is controllable, maximize the update efficiency of the security protection strategies of each node in the system and accelerate the update progress of the security protection strategies of each node in the system.

[0036] In the above technical solution, step S400 includes the following content:

[0037] When the system administrator updates the security protection policies of each system node and optimizes the compatibility of system nodes, according to the updated proportion of security protection task processing distribution in the current stage of the security protection policies of each system node, the security protection tasks in each system node are allocated; after the security protection policies of each system node are updated and the compatibility of system nodes is optimized, it is determined that the current stage of the security protection policy update of each system node ends, and the security protection policy update of the next stage begins;

[0038] Obtain the available system resources of the security protection module after the compatibility optimization of the system node, and synchronously update the security protection task ratio of each system node according to the allocation result; obtain all the security protection task data processed by each system node in the current stage of the security protection policy update of each system node, and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks in each system node based on this data;

[0039] Repeat the above security protection policy update process until the security protection tasks of all system nodes are allocated to the security protection module;

[0040] Quantitatively evaluate the adaptability of the security protection module in each stage of system update and the security protection task processing service of the original system through the method of task parallel processing and stage-by-stage update, reduce the risk of system downtime that may be brought by large-scale task adjustments at one time, reduce the probability of system sudden abnormal accidents, and improve the long-term operation stability of the system.

[0041] A security protection policy intelligent adjustment system based on big data in the above technical solution, the system includes: a security protection monitoring module, a task allocation analysis module, and a system update decision module;

[0042] The security protection monitoring module obtains the security protection task data of each system node for classification and annotation, and calculates the processing quantity ratio of each type of security protection task in each system node; the task allocation analysis module compares the processing results of the security protection tasks of each system node and the security protection module, calculates the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each system node, and updates the data in each stage of the security protection policy update of the system; the system update decision module calculates the update benefit and compatibility risk of allocating the security protection tasks of each system node to the security protection module, and determines the security protection task processing distribution ratio of each system node.

[0043] In the above technical solution, the security protection monitoring module includes: a task data processing unit and a task data statistics unit;

[0044] The task data processing unit obtains all the security protection task data processed by each node of the system, and classifies and labels the historical task data according to the task type; the task data statistics unit is used to calculate the processing quantity ratio of each type of security protection task in each node of the system.

[0045] In the above technical solution, the task allocation analysis module includes: a parallel processing analysis unit, an allocation coefficient analysis unit, and a data update unit;

[0046] The parallel processing analysis unit performs parallel processing on all security protection tasks through each node of the system and the security protection module, and compares the processing results of the security protection tasks by each node of the system and the security protection module; the allocation coefficient analysis unit is used to analyze and calculate the first allocation coefficient and the second allocation coefficient for the security protection module to process the security protection tasks of each node of the system; the data update unit is used to update the allocable amount of system resources of the security protection module, the security protection task ratio of each node of the system, the first allocation coefficient and the second allocation coefficient for the security protection module to process the security protection tasks in each node of the system after the system node compatibility optimization.

[0047] In the above technical solution, the system update decision module includes: a system update evaluation unit and a task allocation ratio decision unit;

[0048] The system update evaluation unit evaluates and calculates the update benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module according to the first allocation coefficient and the second allocation coefficient; the task allocation ratio decision unit determines the processing allocation ratio of security protection tasks during the current stage of the security protection strategy update of each node of the system by setting a system compatibility risk threshold.

[0049] Compared with the prior art, the beneficial effects of the present invention are:

[0050] In the present invention, the security protection strategies of each node of the system are optimized and updated iteratively in stages. In the system security protection task allocation decision, the optimal decision is made based on constraints, ensuring the high efficiency of the security protection strategy update on the premise of the stable operation of the system;

[0051] In the present invention, a phased parallel task allocation decision method is adopted to ensure the synchronization of the system update strategy and the compatibility optimization, further ensuring the stability of the multi-stage update process of the system, and significantly optimizing the resource utilization efficiency in the system update process;

[0052] In the present invention, by performing staged updates on the allocation coefficient and system data, fully considering the system resource utilization efficiency after the update, and timely and effectively adjusting and optimizing the update iteration of the system security protection strategy according to the actual resource utilization effect in different stages of the system update, effectively ensuring the timeliness and feasibility of the system decision. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a flowchart of an intelligent adjustment method for a security protection strategy based on big data according to the present invention;

[0054] Figure 2 It is an organizational structure diagram of an intelligent adjustment system for a security protection strategy based on big data according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0056] Embodiment: Please refer to Figure 1 - Figure 2 , the present invention provides the following technical solutions:

[0057] As Figure 1 shown, the present application provides an intelligent adjustment method for a security protection strategy based on big data, including the following analysis steps:

[0058] Step S100: Obtain all security protection task data processed by each node of the system, classify and label the historical task data according to the task type, and calculate the processing quantity ratio of each type of security protection task in each node of the system;

[0059] Step S200: Process all security protection tasks in parallel through each node of the system and the security protection module, compare the processing results of the security protection tasks processed by each node of the system and the security protection module, and analyze and calculate the first distribution coefficient and the second distribution coefficient of the security protection module for processing the security protection tasks of each node of the system;

[0060] Step S300: According to the first distribution coefficient and the second distribution coefficient, calculate the update benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module. By setting the system compatibility risk threshold, determine the processing allocation ratio of the security protection tasks in the current stage of the security protection strategy update of each node of the system, and send feedback on the security protection strategy update and system node compatibility optimization to the system administrator;

[0061] Step S400: Update the first distribution coefficient and the second distribution coefficient according to the actual processing results of the security protection tasks, and determine the processing allocation ratio of the security protection tasks in the next stage of the security protection strategy update of each node of the system;

[0062] In specific implementation, following the relevant regulations of the third level of GB / T 20272-2006 "Information Security Technology - Operating System Security Technical Requirements" for classified protection, in systems that require a higher security level, various types of security protection strategies such as identity authentication, trusted measurement of executed programs, program installation control, and malicious code protection are required. To ensure the long-term stability of the system and data security, some systems choose to ignore updates and iterations and use outdated security protection strategies for a long time, which places great pressure on the system's own operation and security protection.

[0063] Regarding the above problems, to balance the long-term security stability of the system and the requirement for updating security protection strategies, in this application, the system's security protection tasks are migrated stage by stage based on the security protection task data processed by the system, converting the update of the system itself into a transfer of the system's security protection pressure, effectively avoiding the impact on the system operation caused by the resource allocation compatibility risk during the update of the system's security protection strategy.

[0064] Step S100 includes the following analysis steps:

[0065] Step S101: Obtain all the security protection task data processed by each node of the system, and classify and label the security protection task data according to the task type.

[0066] For any security protection task d, it is labeled as: d[Type_d, Res_d]; where, Type_d is the task type of security protection task d, and Res_d is the set of system resource parameters for processing security protection task d.

[0067] Step S102: Count the number of each type of security protection task processed by each node of the system, and calculate the processing quantity ratio of each type of security protection task in each node of the system.

[0068] In specific implementation, since real-time parallel processing data of security protection tasks for comparison cannot be obtained in the system during the initial update, historical data of security protection tasks processed by the system is collected and simulated through an externally connected security protection module, serving as the data basis for security protection task allocation decisions in the initial update stage.

[0069] The calculation method of the first allocation coefficient for the security protection module to process security protection tasks in each node of the system in step S200 is as follows:

[0070] For any system node n, the first allocation coefficient α of the security protection module for processing security protection tasks of system node n n The calculation formula is as follows:

[0071] α n =∑ t {[R n (t) / nt ×∑ i {∑ j [k j ×(x sys (i,j)-x mod (i,j)) / x sys (i,j)]}};

[0072] Among them, t is the security protection task type number, and R n (t) is the proportion of the number of security protection tasks of type t in the system node n. n t is the number of security protection tasks of type t in the system node n, i is the security protection task number of type t in the system node n, j is the security protection task system resource parameter number, and k j is the allocation evaluation weight coefficient of the jth system resource parameter in the security protection task. x sys (i,j) is the data of the jth system resource parameter when the system node processes the security protection task i. x mod (i,j) is the data of the jth system resource parameter when the security protection module processes the security protection task i;

[0073] In specific implementation, the first allocation coefficient α for the security protection module to process the security protection tasks of the system node n n is used to quantify the optimization effect on the system resource utilization efficiency when the security protection tasks of the system node n are migrated to the security protection module for processing;

[0074] Furthermore, in the calculation of the first allocation coefficient, by parallel processing to compare the system resource parameters when the system and the security protection module process each task, the optimization degree of the system resource utilization efficiency when the security protection tasks of each system node are migrated to the security protection module is measured;

[0075] Furthermore, assume that the system node n processes 2 types of security protection tasks, namely identity authentication and malicious code protection; among them, the number of identity authentication tasks is 2, accounting for 2 / 3, and the number of malicious code protection tasks is 1, accounting for 1 / 3; the allocation evaluation weight coefficient of CPU occupancy is 0.6, and the allocation evaluation weight coefficient of memory occupancy is 0.4;

[0076] Task 1: The quantified value of CPU occupancy when the system processes is 50%, and the memory occupancy is 200MB. The quantified value of CPU occupancy when the security protection module processes is 55%, and the memory occupancy is 180MB;

[0077] Task 2: The quantified value of CPU occupancy when the system processes is 60%, and the memory occupancy is 250MB. The quantified value of CPU occupancy when the security protection module processes is 58%, and the memory occupancy is 230MB;

[0078] Task 3: When the system is processing, the quantified CPU occupancy is 40%, and the memory occupancy is 150 MB. When the security protection module is processing, the quantified CPU occupancy is 42%, and the memory occupancy is 140 MB;

[0079] Among them, the quantified CPU occupancy refers to the value obtained by unifying the data scale of the actual CPU occupancy rate according to the maximum CPU load capacity. For example, if the maximum CPU load capacity of the security protection module is twice that of the original system, then for the same actual CPU occupancy rate, the quantified CPU occupancy in the security protection module is 1 / 2 of that in the original system;

[0080] Calculate the first distribution coefficient α of the security protection module processing node n n = 0.00956.

[0081] The calculation method of the second distribution coefficient for the security protection tasks of each node in the security protection module processing system in step S200 is as follows:

[0082] For any system node n, the second distribution coefficient β of the security protection module processing the security protection task of system node n n The calculation formula is as follows:

[0083] β n = ∑ t {[R n (t) / n t × ∑ i {∑ j [k j × x mod (i,j) / Res mod (j)]}};

[0084] Among them, n t is the number of security protection task types, t is the security protection task type number, R n (t) is the proportion of the number of security protection tasks of type t in system node n, n t is the number of security protection tasks of type t in system node n, i is the security protection task number of type t in system node n, j is the security protection task system resource parameter number, k j is the allocation evaluation weight coefficient of the jth system resource parameter in the security protection task, x mod (i,j) is the data of the jth system resource parameter when the security protection module processes security protection task i, Res mod (j) is the system resource allocable amount corresponding to the jth system resource parameter when the security protection module processes security protection tasks;

[0085] In specific implementation, the second distribution coefficient β of the security protection module processing the security protection task of system node n nUsed to quantify the resource occupancy pressure of the security protection tasks in each node of the system when migrated to the externally connected security protection module, and further reflect the compatibility risk of the system resource allocation for processing the security protection tasks of each node when using the externally connected security protection module to share the system security protection pressure;

[0086] Further, in the calculation of the second allocation coefficient, the proportion of the system resources of each security protection task to the allocable amount of resources of the security protection module is introduced to reflect the resource allocation pressure on the security protection module when each security protection task is migrated to the security protection module. The greater the resource consumption of a task, the higher the risk of competing for system resources, and thus the compatibility risk of resource allocation when the security protection tasks of each node of the system are migrated can be measured;

[0087] Further, using the above parameter data, assuming that the CPU occupancy in the allocable amount of system resources of the security protection module is 200% (the CPU allocable carrying capacity of the security protection module is twice that of the original system node), and the allocable amount of memory of the security protection module is 500MB;

[0088] It can be calculated that the second allocation coefficient β of the security protection module for processing node n n =0.1905.

[0089] Step S300 includes the following analysis steps:

[0090] According to the first allocation coefficient and the second allocation coefficient, calculate the updated benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module. By setting the system compatibility risk threshold, determine the processing allocation ratio of the security protection tasks in the current stage of the security protection strategy update for each node of the system, and send feedback on the security protection strategy update and system node compatibility optimization to the system administrator;

[0091] Step S301: Calculate the updated benefit and compatibility risk of each node of the system for allocating security protection tasks to the security protection module;

[0092] The updated benefit is the product of the processing allocation ratio of the security protection task of the system node and the first allocation coefficient of the security protection module for processing this node, and the compatibility risk is the product of the processing allocation ratio of the security protection task of the system node and the second allocation coefficient of the security protection module for processing this node;

[0093] Step S302: Set the system compatibility risk threshold Th risk , and construct the following compatibility risk constraint:

[0094] (1) The sum of the compatibility risks of all system nodes for allocating security protection tasks to the security protection module is less than or equal to Th risk ;

[0095] (2) The update benefits sum of all system nodes allocating security protection tasks to the security protection module is maximized;

[0096] Step S303: According to the above compatibility risk constraints, adjust the security protection strategies of each system node, update the processing allocation ratio of security protection tasks in the current stage, and send feedback on security protection strategy updates and system node compatibility optimization to the system administrator;

[0097] In specific implementation, due to the differences in the risk resistance capabilities and risk tolerances of different systems, it is necessary to set a compatibility risk threshold according to the specific system security requirements to ensure the controllability of the maximum risk of the system when updating the security protection strategy, prevent large-scale system failures from occurring, and cause unnecessary losses;

[0098] At the same time, make an optimal decision on the migration of security protection tasks for all system nodes to ensure that in each update stage, the system update benefits are maximized, that is, the system update progress is maximized, so as to avoid redundant system update time consumption, effectively improve the efficiency of security protection strategy updates for the system, and simplify the system update process while ensuring the stable and reliable operation of the system.

[0099] Step S400 includes the following content:

[0100] When the system administrator updates the security protection strategies of each system node and optimizes the compatibility of system nodes, allocate the security protection tasks in each system node according to the processing allocation ratio of security protection tasks in the current stage of the security protection strategy update of each system node; after the security protection strategy update of each system node and the compatibility optimization of system nodes are completed, determine that the current stage of the security protection strategy update of each system node ends, and start the security protection strategy update of the next stage;

[0101] Obtain the system resource allocable amount of the security protection module after system node compatibility optimization, and synchronously update the security protection task ratios of each system node according to the allocation results; obtain all the security protection task data processed by each system node in the current stage of the security protection strategy update of each system node, and calculate the first allocation coefficient and the second allocation coefficient for the security protection module to process the security protection tasks in each system node based on this data;

[0102] Repeat the above security protection strategy update process until the security protection tasks of all system nodes are allocated to the security protection module;

[0103] During specific implementation, when switching in the system update stage, calculate the allocation ratio of security protection tasks in the next stage. If the task allocation ratio of any node is small or there is no migration of security protection tasks in the next stage, it can be considered that the compatibility risk of the security protection task migration of this node is relatively high or the improvement effect of the utilization efficiency of system resources before and after is relatively average. There is very likely a compatibility problem between the system node and the security protection module during task migration. For relevant compatibility problems, further optimization and processing are required to eliminate the compatibility risk after the complete update of the system security protection strategy;

[0104] Furthermore, except for using historical data for simulation testing in the initial update stage, in all subsequent update stages, a parallel synchronous processing method is adopted to monitor the system resource parameter data of the security protection module for processing the security protection tasks of each node in the system;

[0105] Furthermore, at the end of the subsequent update stage, compare and analyze the processing results of the system and the security protection module for processing security protection tasks in this stage, and update the numerical values of the first allocation coefficient and the second allocation coefficient to ensure that the final allocation ratio of security protection task migration can fully consider the effects of the system security protection strategy update in each stage, and ensure the balance and unity of the system security protection strategy update for the short-term efficiency and long-term stability of the system in each stage.

[0106] As Figure 2 shown, the present application also provides an intelligent adjustment system for security protection strategies based on big data. The system includes: a security protection monitoring module, a task allocation analysis module, and a system update decision module;

[0107] The security protection monitoring module obtains the security protection task data of each node in the system for classification and annotation, and calculates the processing quantity ratio of each type of security protection task in each node of the system; the task allocation analysis module compares the processing results of the security protection tasks of each node in the system and the security protection module, calculates the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node in the system, and updates the data of each stage of the system security protection strategy update; the system update decision module calculates the update benefits and compatibility risks of each node in the system for allocating security protection tasks to the security protection module, and determines the processing allocation ratio of the security protection tasks of each node in the system.

[0108] The security protection monitoring module includes: a task data processing unit and a task data statistics unit;

[0109] The task data processing unit obtains all the processed security protection task data of each node in the system, and classifies and annotates the historical task data according to the task type; the task data statistics unit is used to calculate the processing quantity ratio of each type of security protection task in each node of the system.

[0110] The task assignment analysis module includes: a parallel processing analysis unit, an allocation coefficient analysis unit, and a data update unit;

[0111] The parallel processing analysis unit performs parallel processing on all security protection tasks through each node and security protection module of the system, and compares the processing results of each node and security protection module of the system for security protection tasks; the allocation coefficient analysis unit is used to analyze and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system; the data update unit is used to update the allocable amount of system resources of the security protection module, the proportion of security protection tasks of each node of the system, the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each node of the system after the system node is compatible and optimized.

[0112] The system update decision module includes: a system update evaluation unit and a task assignment ratio decision unit;

[0113] The system update evaluation unit evaluates and calculates the update benefits and compatibility risks of each node of the system for allocating security protection tasks to the security protection module according to the first allocation coefficient and the second allocation coefficient; the task assignment ratio decision unit determines the processing assignment ratio of security protection tasks during the current stage of the security protection strategy update of each node of the system by setting a system compatibility risk threshold.

[0114] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present invention. Any reference signs in the claims should not be regarded as limiting the claimed rights.

Claims

1. An intelligent adjustment method for security protection strategies based on big data, characterized in that , The method includes the following analysis steps: Step S100: Obtain all the security protection task data processed by each node of the system, classify and label the historical task data according to the task type, and calculate the processing quantity ratio of each type of security protection task in each node of the system; Step S200: Process all the security protection tasks in parallel through each node of the system and the security protection module, compare the processing results of the security protection tasks by each node of the system and the security protection module, and analyze and calculate the first distribution coefficient and the second distribution coefficient of the security protection module for processing the security protection tasks of each node of the system; Step S300: According to the first distribution coefficient and the second distribution coefficient, calculate the update benefit and the compatibility risk of each node of the system for allocating security protection tasks to the security protection module, set the system compatibility risk threshold, determine the processing allocation ratio of the security protection tasks in the current stage of the security protection strategy update of each node of the system, and send feedback on the security protection strategy update and the system node compatibility optimization to the system administrator; Step S300 includes: Step S301: Calculate the update benefit and the compatibility risk of each node of the system for allocating security protection tasks to the security protection module; The update benefit is the product of the processing allocation ratio of the security protection tasks of the system node and the first distribution coefficient of the security protection module for processing this node, and the compatibility risk is the product of the processing allocation ratio of the security protection tasks of the system node and the second distribution coefficient of the security protection module for processing this node; Step S302: Set the system compatibility risk threshold Th risk , and construct the following compatibility risk constraints: (1) The compatibility risk sum of all system nodes assigning security protection tasks to the security protection module is less than or equal to Th risk ; (2) The sum of the update benefits of all system nodes for allocating security protection tasks to the security protection module is the largest; Step S303: According to the above compatibility risk constraints, adjust the security protection strategy of each node of the system, update the processing allocation ratio of the security protection tasks in the current stage, and send feedback on the security protection strategy update and the system node compatibility optimization to the system administrator; Step S400: Update the first distribution coefficient and the second distribution coefficient according to the actual processing results of the security protection tasks, and determine the processing allocation ratio of the security protection tasks in the next stage of the security protection strategy update of each node of the system.

2. The intelligent adjustment method for a security protection strategy based on big data according to claim 1, characterized in that The said step S100 includes the following analysis steps: Step S101: Obtain all the security protection task data processed by each node of the system, and classify and label the security protection task data according to the task type; For any security protection task d, it is labeled as: d[Type_d,Res_d]; where, Type_d is the task type of the security protection task d, and Res_d is the set of system resource parameters for processing the security protection task d; Step S102: Count the quantity of each type of security protection task processed by each node of the system, and calculate the processing quantity ratio of each type of security protection task in each node of the system.

3. The intelligent adjustment method for a security protection strategy based on big data according to claim 2, wherein, The calculation method of the first distribution coefficient of the security protection module for processing the security protection tasks in each node of the system in the said step S200 is as follows: For any system node n, the first distribution coefficient α of the security protection module for processing the security protection tasks of system node n n The calculation formula is as follows: α n =∑ t {[R n (t) / n t ×∑ i {∑ j [k j ×(x sys (i,j)-x mod (i,j)) / x sys (i,j)]}}; Among them, t is the number of the security protection task type, and R n (t) is the proportion of the number of security protection tasks of type t in the system node n, and n t is the number of security protection tasks of type t in the system node n. i is the number of the security protection task of type t in the system node n, j is the number of the system resource parameter of the security protection task, and k j is the distribution evaluation weight coefficient of the j-th system resource parameter in the security protection task, and x sys (i, j) is the data of the j-th system resource parameter when the system node processes the security protection task i, and x mod (i, j) is the data of the j-th system resource parameter when the security protection module processes the security protection task i.

4. The intelligent adjustment method of a security protection strategy based on big data according to claim 2, characterized in that, The calculation method of the second distribution coefficient of the security protection module for processing the security protection tasks in each node of the system in the said step S200 is as follows: For any system node n, the second allocation coefficient β of the security protection module for processing the security protection task of system node n n The calculation formula is as follows: β n =∑ t {[R n (t) / n t ×∑ i {∑ j [k j ×x mod (i,j) / Res mod (j)]}}; Among them, n t is the number of security protection task types, t is the security protection task type number, and R n (t) is the proportion of the number of security protection tasks of type t in the system node n, and n t is the number of security protection tasks of type t in the system node n, i is the security protection task number of type t in the system node n, j is the security protection task system resource parameter number, and k j is the allocation evaluation weight coefficient of the j-th system resource parameter in the security protection task, and x mod (i, j) is the data of the j-th system resource parameter when the security protection module processes the security protection task i, and Res mod (j) is the allocable amount of the system resource corresponding to the j-th system resource parameter when the security protection module processes the security protection task.

5. The intelligent adjustment method of a security protection strategy based on big data according to claim 2, characterized in that The said step S400 includes the following content: When the system administrator updates the security protection policies of each system node and optimizes the system node compatibility, the processing allocation ratio of security protection tasks in the current stage is determined according to the update of the security protection policies of each system node, and the security protection tasks in each system node are allocated; after the security protection policies of each system node are updated and the system node compatibility is optimized, it is determined that the current stage of the security protection policy update of each system node ends, and the security protection policy update of the next stage begins; Obtain the system resource allocable amount of the security protection module after the system node compatibility optimization, and synchronously update the security protection task ratio of each system node according to the allocation result; obtain all the security protection task data processed by each system node in the current stage of the security protection policy update of each system node, and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks in each system node based on this data; Repeat the above security protection policy update process until all the security protection tasks of all system nodes are allocated to the security protection module.

6. A security protection policy intelligent adjustment system based on big data, which is used to execute a security protection policy intelligent adjustment method according to any one of claims 1-5, characterized in that, The system includes: a security protection monitoring module, a task allocation analysis module, and a system update decision module; The security protection monitoring module obtains the security protection task data of each system node for classification and annotation, and calculates the processing quantity ratio of each type of security protection task in each system node; the task allocation analysis module compares the processing results of the security protection tasks of each system node and the security protection module, calculates the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each system node, and updates the data of each stage of the system security protection policy update; the system update decision module calculates the update benefit and compatibility risk of allocating the security protection tasks of each system node to the security protection module, and determines the processing allocation ratio of the security protection tasks of each system node.

7. An intelligent adjustment system for a security protection strategy based on big data according to claim 6, characterized in that, The security protection monitoring module includes: a task data processing unit and a task data statistics unit; The task data processing unit obtains all the security protection task data processed by each system node, and classifies and annotates the historical task data according to the task type; the task data statistics unit is used to calculate the processing quantity ratio of each type of security protection task in each system node.

8. An intelligent adjustment system for security protection strategies based on big data according to claim 6, characterized in that, The task allocation analysis module includes: a parallel processing analysis unit, an allocation coefficient analysis unit, and a data update unit; The parallel processing analysis unit processes all the security protection tasks in parallel through each system node and the security protection module, and compares the processing results of the security protection tasks of each system node and the security protection module; the allocation coefficient analysis unit is used to analyze and calculate the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks of each system node; the data update unit is used to update the system resource allocable amount of the security protection module, the security protection task ratio of each system node, the first allocation coefficient and the second allocation coefficient of the security protection module for processing the security protection tasks in each system node after the system node compatibility optimization.

9. The intelligent adjustment system for security protection strategies based on big data according to claim 6, wherein, The system update decision module includes: a system update evaluation unit and a task allocation ratio decision unit; The system update evaluation unit evaluates and calculates the update benefits and compatibility risks of each node in the system for allocating security protection tasks to the security protection module according to the first allocation coefficient and the second allocation coefficient; the task allocation ratio decision unit determines the processing and allocation ratio of security protection tasks during the current stage of the security protection strategy update for each node in the system by setting a system compatibility risk threshold.

Citation Information

Patent Citations

  • Safety protection method and system for enterprise technology promotion information

    CN111355727A

  • Artificial intelligence server with intelligent safety protection

    CN115080968A