Multi-level adaptive network security protection method and system

By dynamically adjusting security protection strategies in a multi-level adaptive network, the shortcomings of traditional network security protection systems in dealing with complex attacks and internal threats are solved, and more efficient network security protection is achieved.

CN120110792AActive Publication Date: 2025-06-06BEIJING AEROSPACE STAR BRIDGE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510572040.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-06-06
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

Traditional network security protection systems have significant flaws in responding to complex attack scenarios and internal threats, especially in enterprise information leakage and advanced persistent threat (APT) protection. Static strategies are difficult to dynamically respond to new attacks or abnormal behaviors of internal users.

Method used

By acquiring user access requests at the terminal device layer of a multi-level adaptive network, issuing a key to obtain user access data in combination with the hardware security module, calculate the risk value of network sensitive information, determine threat intelligence data, and dynamically adjust security protection policies based on these data.

Benefits of technology

It comprehensively improves the real-time, accuracy and adaptability of network security protection, can promptly detect and respond to potential security threats, effectively protect corporate networks and data assets, and improves the efficiency and effectiveness of network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110792A_ABST
    Figure CN120110792A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-level adaptive network security protection method and system, and relates to the technical field of network security. According to the invention, the user access request is obtained at the terminal equipment layer, the key is issued in combination with the hardware security module to obtain the user access data, the network sensitive information risk value is calculated, the threat intelligence data is determined, and the security protection strategy is dynamically adjusted based on the data, so that the real-time performance, the accuracy and the adaptability of network security protection are comprehensively improved; potential security threats can be found and dealt with in time, and enterprise networks and data assets are effectively protected; through comprehensive analysis and utilization of multi-dimensional data, accurate risk assessment and automatic security decision are realized, the efficiency and effect of network security management are improved, and the possibility of occurrence of security events and the negative influence of the security events on enterprise businesses are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a multi-level adaptive network security protection method and system. Background Art

[0002] With the acceleration of digital transformation of enterprises, network security protection technology has gradually become the key to protecting the core data assets and business continuity of enterprises. The current mainstream network security protection system is mainly based on a layered defense architecture, combining traditional security technologies (such as firewalls, intrusion detection systems, encrypted communications) and emerging technologies to form a multi-level and multi-dimensional protection framework. At present, most of the network security protection of enterprises is achieved by deploying independent security modules (such as firewalls, IDS / IPS, hardware encryption modules) at different network levels (such as terminal device layer, network boundary layer, core communication layer) to form a deep defense system and effectively intercept external attacks. Although the security of enterprise networks has been improved to a certain extent, there are still significant defects in dealing with complex attack scenarios and internal threats, especially in the protection of enterprise information leakage and advanced persistent threats (APT). Traditional security policies rely on predefined rules and cannot dynamically respond to new attacks or abnormal behaviors of internal users. For example, when legitimate users frequently access sensitive data during non-working hours, static policies are difficult to adjust permissions or trigger alarms in real time. Security tools at each level (such as terminal device logs, network traffic data, and application layer access records) operate independently and lack the ability to integrate and correlate data, resulting in fragmented threat intelligence and difficulty in identifying covert cross-level attacks. Summary of the invention

[0003] The purpose of the present invention is to provide a multi-level adaptive network security protection method and system to improve the above technical problems.

[0004] In order to achieve the above-mentioned object of the invention, the embodiment of the present invention provides the following technical solutions:

[0005] A multi-level adaptive network security protection method is provided, which includes:

[0006] Obtaining user access requests at the terminal device layer of the multi-level adaptive network;

[0007] Based on the user access request, the key is issued through the hardware security module to obtain the user access data; the user access data includes application access data, network boundary data, core communication link data, terminal device data and key time interval;

[0008] Calculate the risk value of network sensitive information based on application access data, terminal device data and key time interval;

[0009] Determine threat intelligence data based on network sensitive information risk value and network boundary data;

[0010] Dynamically adjust security protection strategies and implement them based on threat intelligence data and core communication link data.

[0011] Furthermore, the terminal device data includes access information of the user corresponding to the user access request, including the user's department, user level, device number / IP address, application time, application frequency, application data department, application data size and application data level;

[0012] The application access data is the user's historical access information; the historical access information includes historical device number / IP address, historical application time, department to which the historical application data belongs, historical application data size, historical application data level, historical application data content, historical application frequency, historical key input time interval and historical collaboration information between the user's department and other departments.

[0013] Furthermore, the calculating of the network sensitive information risk value based on the application access data, the terminal device data and the key time interval includes:

[0014] Set sensitivity factors based on application time, device number / IP address, and historical device number / IP address;

[0015] Build a department association matrix based on the historical collaboration information between the user's department and other departments;

[0016] Calculate the level risk index based on the department association matrix, sensitivity factors, user level and application data level;

[0017] Calculate the time risk index based on the application time, application frequency, key input time interval, historical application time, historical application frequency and historical key input time interval;

[0018] Calling the application data content corresponding to the user access request, and calculating the access information risk index based on the application data size, application data level, historical application data size, historical application data level and historical application data content;

[0019] The network sensitive information risk value is calculated based on the level risk index, time risk index and access information risk index.

[0020] Furthermore, the process of calculating the time risk index includes:

[0021] Normalize the historical application time, historical application frequency and historical key input time interval;

[0022] Based on each normalized historical application time and its corresponding normalized historical application frequency and normalized historical key input time interval, a corresponding three-dimensional time distribution graph is drawn by a kernel density estimation method;

[0023] Normalize the application time, application frequency, and key input time interval and integrate them into application coordinate data;

[0024] Calculate the distance between the application coordinate data and all coordinate points of the three-dimensional time distribution map; based on all distances, calculate the corresponding average distance;

[0025] Determine whether the average distance is less than the distance threshold; if so, the application coordinate data falls on the three-dimensional time distribution graph, and the value of the time similarity index is set to 0; otherwise, calculate the vertical distance between the application coordinate data and the three-dimensional time distribution graph and use it as the time similarity index.

[0026] Furthermore, the process of calculating the access information risk index includes:

[0027] Match the application data content with the historical application data content and calculate the corresponding data matching degree;

[0028] Calculate the data overlap based on the application data size and the historical application data size;

[0029] Determine data level similarity based on the application data level and the historical application data level;

[0030] The access information risk index is calculated based on data matching, data volume overlap and data level similarity.

[0031] Furthermore, the determining of threat intelligence data based on the network sensitive information risk value and network boundary data includes:

[0032] Set the risk threshold according to actual needs; determine whether the risk value of network sensitive information is less than the risk threshold; if so, approve the user's access request, call the corresponding data content and feedback it to the applicant, and complete the protection of the user's access request;

[0033] Otherwise, the user access request is regarded as a dangerous behavior, and the network boundary data is analyzed to obtain the corresponding network security analysis results;

[0034] Based on the network security analysis results, potential threats are identified through defense detection systems and firewalls;

[0035] Conduct correlation analysis on dangerous behaviors and potential threats to obtain corresponding correlation analysis results;

[0036] Based on the correlation analysis results, determine the threat intelligence data.

[0037] Furthermore, the dynamically adjusting and implementing security protection strategies based on threat intelligence data and core communication link data includes:

[0038] Identify the core communication link data and obtain abnormal communication patterns;

[0039] Analyze threat intelligence data and extract key information from it;

[0040] Assess threat severity based on key information and abnormal communication patterns;

[0041] Based on the severity of the threat, the security protection strategy is dynamically adjusted to obtain the adjusted security protection strategy and implement it.

[0042] A multi-level adaptive network security protection system is provided, comprising:

[0043] A user access request acquisition module, used to obtain user access requests at the terminal device layer of the multi-level adaptive network;

[0044] A user access data acquisition module, which is used to obtain user access data by issuing a key through a hardware security module based on a user access request; the user access data includes application access data, network boundary data, core communication link data, terminal device data and key time interval;

[0045] A network sensitive information risk calculation module, used to calculate the network sensitive information risk value based on application access data, terminal device data and key time interval;

[0046] A threat intelligence data analysis module is used to determine threat intelligence data based on the risk value of network sensitive information and network boundary data;

[0047] The security protection strategy adjustment module is used to dynamically adjust and implement security protection strategies based on threat intelligence data and core communication link data.

[0048] Furthermore, the network sensitive information risk calculation module includes:

[0049] Related parameter setting unit, used to set sensitive factors and construct departmental correlation matrix;

[0050] A level risk index calculation unit is used to calculate the level risk index based on the department association matrix, sensitive factors, and terminal equipment data;

[0051] A time risk index calculation unit, used to calculate a time risk index based on terminal device data and application access data;

[0052] An access information risk index calculation unit, used to call the application data content corresponding to the user access request, and calculate the access information risk index based on the terminal device data and the application access data;

[0053] The network sensitive information risk calculation unit is used to calculate the network sensitive information risk value based on the level risk index, time risk index and access information risk index.

[0054] The beneficial effects of the present invention are:

[0055] The present invention obtains user access requests at the terminal device layer, obtains user access data by issuing keys in combination with the hardware security module, calculates the risk value of network sensitive information, determines threat intelligence data, and dynamically adjusts security protection strategies based on these data, thereby comprehensively improving the real-time, accuracy and adaptability of network security protection, being able to promptly discover and respond to potential security threats, and effectively protecting enterprise networks and data assets; through the comprehensive analysis and utilization of multi-dimensional data, accurate risk assessment and automated security decision-making are achieved, the efficiency and effectiveness of network security management are improved, and the possibility of security incidents and their negative impact on enterprise business are reduced. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments are briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.

[0057] Figure 1 A flow chart of a method in an embodiment of the present invention;

[0058] Figure 2 This is a flow chart of a method for calculating a network sensitive information risk value in an embodiment of the present invention;

[0059] Figure 3 A system structure diagram in an embodiment of the present invention;

[0060] Figure 4 This is a structural diagram of a network sensitive information risk calculation module in an embodiment of the present invention. DETAILED DESCRIPTION

[0061] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The components of the embodiments of the present invention generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents the selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present invention.

[0062] See also Figure 1 This embodiment provides a multi-level adaptive network security protection method, which includes

[0063] S1. Obtain a user access request at the terminal device layer of the multi-level adaptive network. The user access request refers to the data content required by the user, for example, an employee in the R&D department needs to call the company's product parameters and R&D data.

[0064] Among them, the multi-level adaptive network includes hardware security module, terminal device layer, network boundary layer, core communication link and application layer.

[0065] S2. Based on the user access request, the hardware security module issues a key and obtains user access data. The user access data includes application access data, network boundary data, core communication link data, terminal device data, and key time interval. The key time interval refers to the time interval from the issuance of the key to the key input.

[0066] Thus, the S2 includes:

[0067] S2-1, authenticate the user; if the authentication fails, the threat level is determined to be medium and enter S5-4; otherwise, enter S2-2. The user refers to the person who issues the user access request.

[0068] S2-2. Send the key to the user end through the hardware security module of the multi-level adaptive network to obtain the key time interval.

[0069] S2-3. Obtain application access data, network boundary data, core communication link data, and terminal device data at each level in the multi-level adaptive network.

[0070] Terminal device data refers to the data in the terminal device layer, which includes the user's access information, including the user's department, user level, device number / IP address, application time, application frequency, application data department, application data size and application data level. User level refers to the authority level set according to the user's position. For example, the authority level of the general manager is 3, and the authority level of the manager is 2. The authority level decreases with the lower the position level.

[0071] Application access data is the user's historical access information; historical access information includes historical device number / IP address, historical application time, historical application data department, historical application data size, historical application data level, historical application data content, historical application frequency, historical key input time interval, and historical collaboration information between the user's department and other departments. Historical collaboration information includes historical collaboration times and historical data sharing times.

[0072] The core communication link data is the data in the core communication link, which includes the link flow size and the link flow rate.

[0073] Network boundary data refers to data in the network boundary layer, including traffic data, connection status network, and external attack information. Traffic data includes information such as the size, direction, protocol type, port number, etc. of traffic flowing into and out of the network; through the firewall, intrusion detection system (IDS) / intrusion prevention system (IPS) and other devices deployed at the network boundary, network traffic can be monitored and recorded in real time to understand the overall network traffic situation and external access requests. The connection status network includes the source IP address, destination IP address, connection establishment time, connection duration, etc. of the connection, which can be used to track the connection behavior and session status in the network.

[0074] The present invention accurately collects multi-source data of enterprises / companies, facilitates unified management and analysis, and improves access management efficiency. It avoids the management difficulties and analysis complexities caused by decentralized data storage, and facilitates subsequent security policy adjustments.

[0075] S3. Calculate the network sensitive information risk value based on application access data, terminal device data and key time interval. Convert multi-dimensional data into specific network sensitive information risk values ​​to provide enterprises with intuitive risk assessment indicators. Provide key basis for subsequent dynamic adjustment of security protection strategies to ensure that security measures match the risk level.

[0076] like Figure 2 As shown, the S3 includes:

[0077] S3-1. Set sensitivity factors based on application time, device number / IP address, and historical device number / IP address If the application time is during working hours, the sensitivity factor is -0.2; if the device number is a historical device number, the sensitivity factor is -0.1; if the IP address is not a historical IP address, the sensitivity factor is -0.3.

[0078] S3-2. Based on the historical collaboration information between the user's department and other departments, a department association matrix is ​​constructed. The department association matrix is ​​a two-dimensional matrix used to quantify the collaboration between departments within an organization, and its value range is [0, 1]. Therefore, the formula corresponding to the department association matrix is:

[0079] ;

[0080] ;

[0081] ;

[0082] in, Indicates the department to which the user belongs and the department to which the application data belongs The departmental correlation matrix between , Respectively represent the department to which the user belongs The department to which the application data belongs ,department The collaboration matrix between Indicates the total number of departments of the enterprise / company, represents the summation function, , They represent the collaboration times matrix and the sharing times matrix respectively, Indicates the department to which the user belongs and the department to which the application data belongs The number of collaborations between , Respectively represent the department to which the user belongs The maximum and minimum number of collaborations, represents the logarithmic function with the natural constant e as the base, , Respectively represent the department to which the user belongs and the department to which the application data belongs The number of times the user is shared, the department to which the user belongs The maximum number of shares for Department This refers to the department to which the user belongs. Other departments outside.

[0083] S3-3. Calculate the level risk index based on the department association matrix, sensitivity factors, user level and application data level.

[0084] Level risk indicator The corresponding formula is:

[0085] ;

[0086] ;

[0087] in, , , Represents the sensitive weight coefficient, and the corresponding values ​​are all greater than 0. Indicates the historical frequency of users applying for data from the same department. represents the user-data level indicator, Indicates the preset maximum allowed level difference, , Respectively represent the user level and application data level, Indicates absolute value. and , .

[0088] S3-4. Calculate the time risk index based on the application time, application frequency, key input time interval, historical application time, historical application frequency and historical key input time interval.

[0089] The S3-4 includes:

[0090] S3-4-1. Normalize the historical application time, historical application frequency and historical key input time interval; each time an application is made, the application frequency is increased by 1; thus, each application time has a corresponding historical key input time interval and historical application frequency.

[0091] S3-4-2. Based on each normalized historical application time and its corresponding normalized historical application frequency and normalized historical key input time interval, a corresponding three-dimensional time distribution graph is drawn by a kernel density estimation method. The XYZ axes of the three-dimensional time distribution graph are the values ​​corresponding to the application time, application frequency, and key input time interval, respectively.

[0092] S3-4-3. Normalize the application time, application frequency, and key input time interval and integrate them into application coordinate data.

[0093] S3-4-4. Calculate the distance between the applied coordinate data and all coordinate points of the three-dimensional time distribution graph; based on all distances, calculate the corresponding average distance.

[0094] S3-4-5, determine whether the average distance is less than the distance threshold; if so, the application coordinate data falls on the three-dimensional time distribution diagram, and the value of the time similarity index is set to 0; otherwise, enter S3-4-6. The distance threshold is set according to the experience of network security personnel in different situations.

[0095] S3-4-6. Calculate the vertical distance between the application coordinate data and the three-dimensional time distribution diagram, and use it as a time similarity indicator.

[0096] S3-5. Call the application data content corresponding to the user access request, and calculate the access information risk index based on the application data size, application data level, historical application data size, historical application data level and historical application data content.

[0097] The S3-5 includes:

[0098] S3-5-1. Match the application data content with the historical application data content and calculate the corresponding data matching degree ,include:

[0099] The application data content is cleaned to remove special characters, stop words and punctuation marks in the application data content, and the text is uniformly converted to lowercase to obtain application cleansing data.

[0100] The application cleaning data is segmented, stemmed and restored to obtain the application segmentation data.

[0101] Perform feature extraction on the application word segmentation data to obtain the corresponding application feature vector data.

[0102] Calculate the similarity between the application feature vector data and the historical application data content, and take the average of each similarity as the data matching degree. The similarity can be measured by cosine similarity, Jaccard similarity coefficient, and edit distance. Among them, word segmentation, stem extraction, word form restoration, and feature extraction are existing technologies, so they are not described in detail.

[0103] S3-5-2. Calculate the data overlap based on the size of the application data and the size of the historical application data , the corresponding formula is:

[0104] ;

[0105] in, Indicates the size of the application data. Indicates the average size of historical application data.

[0106] S3-5-3. Determine the data level similarity based on the application data level and the historical application data level , the corresponding formula is:

[0107] ;

[0108] in, Indicates the application data level, Indicates the average of historical application data levels.

[0109] S3-5-4. Calculate access information risk indicators based on data matching, data volume overlap and data level similarity , the corresponding formula is:

[0110] ;

[0111] in, , , Represents the access information weight coefficient, and the corresponding values ​​are all greater than 0. Among them, and , .

[0112] S3-6, based on level risk indicators , Time Risk Indicator and access information risk indicators , calculate the risk value of network sensitive information , the corresponding formula is:

[0113] ;

[0114] in, , , Represents the network sensitivity weight coefficient, and the corresponding values ​​are all greater than 0. Among them, .

[0115] The present invention comprehensively considers multi-dimensional factors such as time, user level, data level, historical behavior, etc., comprehensively and accurately evaluates the risk level of network access behavior, and reduces missed reports and false positives. Breaking down risk assessment into specific indicators to achieve quantification and hierarchical management of risks will help to take targeted protective measures, facilitate real-time monitoring of key risk factors, dynamically update risk values, and capture potential threats in a timely manner. Providing accurate risk assessment data will assist in the dynamic adjustment and intelligent decision-making of security strategies, and improve the automation and intelligence level of network security protection. The weight coefficient and risk threshold can be adjusted according to enterprise needs, and it can flexibly adapt to the network security needs of different enterprises and industries, provide a quantitative basis for the dynamic adjustment of security protection strategies, and take strict protective measures in a timely manner for high-risk behaviors.

[0116] S4. Determine threat intelligence data based on the risk value of network sensitive information and network boundary data.

[0117] The S4 includes:

[0118] S4-1. Set the risk threshold according to actual needs; determine whether the risk value of network sensitive information exceeds the risk threshold; if so, treat the user's access request as a dangerous behavior and enter S4-2; otherwise, agree to the user's access request, call the corresponding data content and feedback to the user, complete the protection of the user's access request, and implement the security protection strategy of the previous protection. Using the risk value of network sensitive information for judgment, high-risk access requests can be quickly distinguished, and early warnings can be issued in time, so that enterprises can quickly respond to potential threats, provide automated decision-making basis for the enterprise's security system, reduce manual intervention, and improve efficiency.

[0119] S4-2. Analyze the network boundary data to obtain corresponding network security analysis results.

[0120] The network security analysis results include flow data analysis results, connection status analysis results and external attack analysis results, so S4-2 includes:

[0121] Traffic data is monitored, traffic size and change trends are analyzed, and traffic data analysis results are obtained, which can be used to identify abnormal traffic peaks or sudden increases in traffic. If abnormal traffic peaks or sudden increases in traffic occur, it indicates that the enterprise / company may be subject to network attacks or data leaks.

[0122] Check the connection status network to identify connections from suspicious IP addresses, a large number of connection attempts in a short period of time, or abnormal connection duration, and obtain connection status analysis results.

[0123] Analyze the external attack information, determine the type, frequency and intensity of the attack, and obtain the external attack analysis results. The analysis process in S4-2 adopts the existing network analysis method.

[0124] S4-3. Based on the results of network security analysis, identify potential threats through defense detection systems (IDS intrusion detection system, IPS intrusion prevention system) and firewalls. The network complete analysis results are identified through defense detection systems (IDS intrusion detection system, IPS intrusion prevention system) and firewalls, and corresponding identification results are obtained respectively; all identification results are integrated to obtain potential threats.

[0125] S4-4. Perform correlation analysis on dangerous behaviors and potential threats to obtain corresponding correlation analysis results.

[0126] Dangerous behaviors and potential dangers are integrated to obtain a dangerous data set; the potential relationship between different data in the dangerous data set is extracted using an association rule mining algorithm, and the relationship between dangerous behaviors and potential threats and specific business activities is determined and displayed through a graphical interface in combination with the enterprise's business processes and network architecture. The graphical interface can be a network topology diagram or a time series diagram.

[0127] S4-5. Determine threat intelligence data based on the correlation analysis results. Use machine learning to process the correlation analysis results and the risk data set to extract threat features; integrate all extracted threat features to obtain threat intelligence data. Machine learning can use clustering algorithms, decision tree algorithms, and random forests.

[0128] The present invention analyzes network boundary data, can provide comprehensive network security situation awareness, help enterprises understand network status in real time, timely discover abnormal traffic peaks or traffic surges, quickly detect DDoS attacks or data leakage events, reduce their impact on enterprise networks, and can also identify abnormal behaviors such as connections from suspicious IP addresses and a large number of connection attempts in a short period of time, and early discover brute force attacks or malicious scanning behaviors. Based on the results of network security analysis, potential threats are identified through defense detection systems and firewalls, and the detection results of IDS, IPS and firewalls are integrated to improve the accuracy of threat detection, reduce the false negative rate, and timely identify and respond to potential threats. Correlation analysis is performed on dangerous behaviors and potential threats to reveal the hidden relationship between dangerous behaviors and potential threats, provide deeper threat insights, help enterprises formulate more effective security strategies, clarify the relationship between dangerous behaviors and potential threats and business activities, formulate accurate security protection strategies, and protect key business assets; machine learning is used to extract threat features and integrate threat intelligence data. The machine learning algorithm automatically extracts threat features, improves the efficiency and accuracy of feature extraction, helps enterprises quickly identify new threats, integrates threat features to form threat intelligence data, facilitates internal sharing within the enterprise and sharing with other organizations, and improves the overall network security protection level.

[0129] S5. Dynamically adjust and implement security protection strategies based on threat intelligence data and core communication link data.

[0130] The S5 includes:

[0131] S5-1. Identify the core communication link data to obtain an abnormal communication pattern.

[0132] Use historical core communication link data to establish a baseline of normal behavior for core communication links, determine normal traffic ranges, typical latency values, and packet loss rates.

[0133] Compare the core communication link data with the normal behavior baseline to obtain the comparison results.

[0134] Based on the comparison results, use statistical analysis or machine learning algorithms to identify abnormal patterns, such as sudden increase in traffic, excessive delay, or abnormal packet loss rate; record relevant information of the abnormal pattern, such as occurrence time, duration, links involved, etc., integrate the abnormal pattern and related information, and obtain the abnormal communication pattern.

[0135] S5-2. Analyze the threat intelligence data and extract key information from the threat intelligence data, such as the attack source IP address, attack type, attack time, affected system or data type, etc.

[0136] Extract the original key information such as attack source IP, attack type, attack time, affected system, etc.; classify the initial key information and agree on the information format to obtain the initial key information; filter the initial key information based on the preset filtering conditions to obtain the key information. The filtering conditions can be preset rules or importance levels, which are set according to actual needs / conditions.

[0137] S5-3. Assess the severity of the threat based on key information and abnormal communication patterns.

[0138] The S5-3 includes:

[0139] S5-3-1. Correlate and analyze key information with abnormal communication patterns. For example, check whether the attack source IP matches the source IP of the abnormal link traffic, or whether the attack time coincides with the abnormal communication time period, to obtain corresponding threat correlation information.

[0140] S5-3-2. Input threat-related information, key information and abnormal communication patterns into the risk assessment model: Use the risk assessment model to comprehensively consider the possibility and impact of the threat and obtain the corresponding risk assessment results, that is, the severity of the threat. The severity of the threat is divided into three levels: high, medium and low. The risk assessment model can use LSTM neural network, DBN neural network and Transformer neural network.

[0141] S5-4. Based on the severity of the threat, dynamically adjust the security protection strategy, obtain the adjusted security protection strategy and implement it.

[0142] When the threat severity is high, adopt and implement high-risk threat strategies, immediately reject user access requests, block attack source IPs, close non-essential ports of the affected system, turn on protection mode and send warning signals to the network security protection department or the department responsible for network security.

[0143] When the threat severity is medium, adopt and implement a medium-threat strategy, repeatedly authenticate users, including but not limited to face recognition, fingerprint recognition and other verification methods, send early warning signals to the network security protection department or the department responsible for network security, strengthen monitoring of affected systems or links, and restrict access rights of some suspicious IPs.

[0144] When the threat severity is low, maintain normal monitoring and consider taking minor protective measures without affecting business.

[0145] The present invention can accurately identify abnormal communication patterns through the identification and analysis of core communication link data; the analysis of threat intelligence data and the extraction of key information can help to quickly focus on key threat features and improve the efficiency and accuracy of threat identification; based on the correlation analysis of key information and abnormal communication patterns and the application of risk assessment models, the severity of threats can be scientifically assessed to achieve hierarchical management of threats, ensuring that enterprises can prioritize the allocation of limited security resources to high-risk threats. Dynamically adjust security protection strategies according to the severity of threats, making the enterprise's network security protection measures more targeted and timely, effectively blocking the source of attack, and reducing the impact of security incidents on business operations. At the same time, through different levels of threat response strategies, refined management of security protection is achieved to ensure the safe and stable operation of the enterprise network.

[0146] like Figure 3 As shown, a multi-level adaptive network security protection system includes:

[0147] A user access request acquisition module, used to obtain user access requests at the terminal device layer of the multi-level adaptive network;

[0148] A user access data acquisition module, which is used to obtain user access data by issuing a key through a hardware security module based on a user access request; the user access data includes application access data, network boundary data, core communication link data, terminal device data and key time interval;

[0149] A network sensitive information risk calculation module, used to calculate the network sensitive information risk value based on application access data, terminal device data and key time interval;

[0150] A threat intelligence data analysis module is used to determine threat intelligence data based on the risk value of network sensitive information and network boundary data;

[0151] The security protection strategy adjustment module is used to dynamically adjust and implement security protection strategies based on threat intelligence data and core communication link data.

[0152] like Figure 4 As shown, the network sensitive information risk calculation module includes:

[0153] Related parameter setting unit, used to set sensitive factors and construct departmental correlation matrix;

[0154] A level risk index calculation unit is used to calculate the level risk index based on the department association matrix, sensitive factors, and terminal equipment data;

[0155] A time risk index calculation unit, used to calculate a time risk index based on terminal device data and application access data;

[0156] An access information risk index calculation unit, used to call the application data content corresponding to the user access request, and calculate the access information risk index based on the terminal device data and the application access data;

[0157] The network sensitive information risk calculation unit is used to calculate the network sensitive information risk value based on the level risk index, time risk index and access information risk index.

[0158] To summarize, the present invention obtains user access requests at the terminal device layer, obtains user access data in combination with the hardware security module to issue keys, calculates the risk value of network sensitive information, determines threat intelligence data, and dynamically adjusts security protection strategies based on these data, thereby comprehensively improving the real-time, accuracy and adaptability of network security protection, being able to timely discover and respond to potential security threats, and effectively protecting enterprise networks and data assets; through the integration and analysis of multi-dimensional data, accurate risk assessment and automated security decision-making are achieved, the efficiency and effectiveness of network security management are improved, and the possibility of security incidents and their negative impact on enterprise business are reduced.

[0159] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

Claims

1. A multi-level adaptive network security protection method, characterized in that: include: Obtaining user access requests at the terminal device layer of the multi-level adaptive network; Based on the user access request, the key is issued through the hardware security module to obtain the user access data; the user access data includes application access data, network boundary data, core communication link data, terminal device data and key time interval; Calculate the risk value of network sensitive information based on application access data, terminal device data and key time interval; Determine threat intelligence data based on network sensitive information risk value and network boundary data; Dynamically adjust security protection strategies and implement them based on threat intelligence data and core communication link data.

2. The multi-level adaptive network security protection method according to claim 1, characterized in that: The terminal device data includes the access information of the user corresponding to the user access request, including the user's department, user level, device number / IP address, application time, application frequency, application data department, application data size and application data level; The application access data is the user's historical access information; the historical access information includes historical device number / IP address, historical application time, department to which the historical application data belongs, historical application data size, historical application data level, historical application data content, historical application frequency, historical key input time interval and historical collaboration information between the user's department and other departments.

3. The multi-level adaptive network security protection method according to claim 2, characterized in that: The calculating of the network sensitive information risk value based on the application access data, the terminal device data and the key time interval includes: Set sensitivity factors based on application time, device number / IP address, and historical device number / IP address; Build a department association matrix based on the historical collaboration information between the user's department and other departments; Calculate the level risk index based on the department association matrix, sensitivity factors, user level and application data level; Calculate the time risk index based on the application time, application frequency, key input time interval, historical application time, historical application frequency and historical key input time interval; Calling the application data content corresponding to the user access request, and calculating the access information risk index based on the application data size, application data level, historical application data size, historical application data level and historical application data content; The network sensitive information risk value is calculated based on the level risk index, time risk index and access information risk index.

4. The multi-level adaptive network security protection method according to claim 3 is characterized in that: The process of calculating the time risk indicator includes: Normalize the historical application time, historical application frequency and historical key input time interval; Based on each normalized historical application time and its corresponding normalized historical application frequency and normalized historical key input time interval, a corresponding three-dimensional time distribution graph is drawn by a kernel density estimation method; Normalize the application time, application frequency, and key input time interval and integrate them into application coordinate data; Calculate the distance between the application coordinate data and all coordinate points of the three-dimensional time distribution map; based on all distances, calculate the corresponding average distance; Determine whether the average distance is less than the distance threshold; if so, the application coordinate data falls on the three-dimensional time distribution graph, and the value of the time similarity index is set to 0; otherwise, calculate the vertical distance between the application coordinate data and the three-dimensional time distribution graph and use it as the time similarity index.

5. The multi-level adaptive network security protection method according to claim 3 is characterized in that: The process of calculating the access information risk index includes: Match the application data content with the historical application data content and calculate the corresponding data matching degree; Calculate the data overlap based on the application data size and the historical application data size; Determine data level similarity based on the application data level and the historical application data level; The access information risk index is calculated based on data matching, data volume overlap and data level similarity.

6. The multi-level adaptive network security protection method according to claim 2, characterized in that: Determining threat intelligence data based on the network sensitive information risk value and network boundary data includes: Set the risk threshold according to actual needs; determine whether the risk value of network sensitive information is less than the risk threshold; if so, approve the user's access request, call the corresponding data content and feedback to the user, and complete the protection of the user's access request; Otherwise, the user access request is regarded as a dangerous behavior, and the network boundary data is analyzed to obtain the corresponding network security analysis results; Based on the network security analysis results, potential threats are identified through defense detection systems and firewalls; Conduct correlation analysis on dangerous behaviors and potential threats to obtain corresponding correlation analysis results; Based on the correlation analysis results, determine the threat intelligence data.

7. The multi-level adaptive network security protection method according to claim 2, characterized in that: The dynamically adjusting and implementing security protection strategies based on threat intelligence data and core communication link data includes: Identify the core communication link data and obtain abnormal communication patterns; Analyze threat intelligence data and extract key information from it; Assess threat severity based on key information and abnormal communication patterns; Based on the severity of the threat, the security protection strategy is dynamically adjusted to obtain the adjusted security protection strategy and implement it.

8. A multi-level adaptive network security protection system, used to implement a multi-level adaptive network security protection method according to any one of claims 1 to 7, characterized in that: include: A user access request acquisition module, used to obtain user access requests at the terminal device layer of the multi-level adaptive network; A user access data acquisition module, which is used to obtain user access data by issuing a key through a hardware security module based on a user access request; the user access data includes application access data, network boundary data, core communication link data, terminal device data and key time interval; A network sensitive information risk calculation module, used to calculate the network sensitive information risk value based on application access data, terminal device data and key time interval; A threat intelligence data analysis module is used to determine threat intelligence data based on the risk value of network sensitive information and network boundary data; The security protection strategy adjustment module is used to dynamically adjust and implement security protection strategies based on threat intelligence data and core communication link data.

9. The multi-level adaptive network security protection system according to claim 8, characterized in that: The network sensitive information risk calculation module includes: Related parameter setting unit, used to set sensitive factors and construct departmental correlation matrix; A level risk index calculation unit is used to calculate the level risk index based on the department association matrix, sensitive factors, and terminal equipment data; A time risk index calculation unit, used to calculate a time risk index based on terminal device data and application access data; An access information risk index calculation unit, used to call the application data content corresponding to the user access request, and calculate the access information risk index based on the terminal device data and the application access data; The network sensitive information risk calculation unit is used to calculate the network sensitive information risk value based on the level risk index, time risk index and access information risk index.

Citation Information

Patent Citations

  • Security access control method and device, electronic equipment and medium

    CN118690391A

  • Self-adaptive zero-trust network evaluation method and system based on edge calculation

    CN118869267A

  • Computer storage file protection system

    CN119249499A

  • Information security risk assessment method and system based on API

    CN119788309A

  • Threat detection of application traffic flows

    US20210075799A1