A multi-level adaptive network security protection method and system
By acquiring user access requests and data in a multi-level adaptive network, calculating the risk value of network sensitive information, and dynamically adjusting security protection strategies, the shortcomings of traditional network security protection systems in dealing with complex attacks and internal threats are solved, achieving more efficient network security management and threat response.
Patent Information
- Application Number
- CN202510572040.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2045-05-06
AI Technical Summary
Existing cybersecurity protection systems have significant shortcomings in dealing with complex attack scenarios and internal threats, especially in the protection against corporate information leaks and advanced persistent threats (APTs). Traditional security strategies rely on predefined rules and cannot dynamically respond to new attacks or abnormal behavior of internal users. Security tools at all levels lack the ability to integrate and correlate data, resulting in fragmented threat intelligence and difficulty in identifying covert attacks across levels.
By acquiring user access requests at the terminal device layer of a multi-level adaptive network, and combining this with user access data obtained through hardware security modules, the risk value of network sensitive information is calculated, and security protection strategies are dynamically adjusted. This includes threat intelligence data analysis based on user behavior and network boundary data, enabling cross-level data integration and correlation analysis.
It enhances the real-time nature, accuracy, and adaptability of network security protection, enabling timely detection and response to potential threats, achieving accurate risk assessment and automated security decision-making, reducing the negative impact of security incidents on business operations, and improving the efficiency and effectiveness of network security management.
Smart Images

Figure CN120110792B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a multi-level adaptive network security protection method and system. BACKGROUND
[0002] With the acceleration of enterprise digital transformation, network security protection technology has gradually become the key to protecting enterprise core data assets and business continuity. The current mainstream network security protection system is mainly based on a layered defense architecture, combined with traditional security technologies (such as firewalls, intrusion detection systems, encrypted communications) and emerging technologies, forming a multi-level, multi-dimensional protection framework. At present, the network security protection of enterprises is mostly through the deployment of independent security modules (such as firewalls, IDS / IPS, hardware encryption modules) at different network levels (such as terminal device layer, network boundary layer, core communication layer), forming a defense-in-depth system, effectively intercepting external attacks. Although it has improved the security of enterprise networks to some extent, it still has significant defects in dealing with complex attack scenarios and internal threats, especially in the protection of enterprise information leakage and advanced persistent threats (APTs). Traditional security policies rely on predefined rules and cannot dynamically respond to new attacks or abnormal behavior of internal users. For example, when a legitimate user frequently accesses sensitive data outside working hours, static policies have difficulty in adjusting permissions or triggering alarms in real time. The security tools at each level (such as terminal device logs, network traffic data, and application layer access records) operate independently, lacking data integration and correlation analysis capabilities, resulting in fragmented threat intelligence and difficulty in identifying hidden attacks across levels. SUMMARY
[0003] The purpose of the present application is to provide a multi-level adaptive network security protection method and system to improve the above technical problems.
[0004] To achieve the above application purpose, the embodiments of the present application provide the following technical solutions:
[0005] A multi-level adaptive network security protection method is provided, which includes:
[0006] Obtaining a user access request at the terminal device layer of a multi-level adaptive network;
[0007] Based on the user access request, a key is issued through a hardware security module to obtain user access data; the user access data includes application access data, network boundary data, core communication link data, terminal device data, and key time interval;
[0008] Based on the application access data, terminal device data, and key time interval, a network sensitive information risk value is calculated;
[0009] Based on the network sensitive information risk value and network boundary data, threat intelligence data is determined;
[0010] Based on the threat intelligence data and the core communication link data, dynamically adjust and implement security protection strategies.
[0011] Further, the terminal device data includes access information of a user corresponding to the user access request, including a department to which the user belongs, a user level, a device number / IP address, an application time, an application frequency, an application data department, an application data size, and an application data level.
[0012] The application access data is historical access information of the user, and the historical access information includes a historical device number / IP address, a historical application time, a historical application data department, a historical application data size, a historical application data level, a historical application data content, a historical application frequency, a historical key input time interval, and historical collaboration information of the user and other departments.
[0013] Further, the network sensitive information risk value is calculated based on the application access data, the terminal device data, and the key time interval, including:
[0014] Based on the application time, the device number / IP address, and the historical device number / IP address, a sensitive factor is set.
[0015] Based on the historical collaboration information of the user and other departments, a department correlation matrix is constructed.
[0016] Based on the department correlation matrix, the sensitive factor, the user level, and the application data level, a level risk index is calculated.
[0017] Based on the application time, the application frequency, the key input time interval, the historical application time, the historical application frequency, and the historical key input time interval, a time risk index is calculated.
[0018] The application data content corresponding to the user access request is called, and based on the application data size, the application data level, the historical application data size, the historical application data level, and the historical application data content, an access information risk index is calculated.
[0019] Based on the level risk index, the time risk index, and the access information risk index, a network sensitive information risk value is calculated.
[0020] Further, the process of calculating the time risk index includes:
[0021] The historical application time, the historical application frequency, and the historical key input time interval are normalized.
[0022] Based on each normalized historical application time and its corresponding normalized historical application frequency and normalized historical key input time interval, a corresponding three-dimensional time distribution graph is drawn through kernel density estimation method;
[0023] The application time, application frequency and key input time interval are normalized and integrated into application coordinate data;
[0024] The distance between the application coordinate data and all coordinate points of the three-dimensional time distribution graph is calculated; based on all distances, the corresponding average distance is calculated;
[0025] It is judged whether the average distance is less than the distance threshold; if so, the application coordinate data falls on the three-dimensional time distribution graph, and the value of the time similarity index is set to 0; otherwise, the perpendicular distance between the application coordinate data and the three-dimensional time distribution graph is calculated and used as the time similarity index.
[0026] Further, the process of calculating the access information risk index includes:
[0027] The application data content and the historical application data content are matched to calculate the corresponding data matching degree;
[0028] Based on the application data size and the historical application data size, the data amount coincidence degree is calculated;
[0029] Based on the application data level and the historical application data level, the data level similarity is determined;
[0030] Based on the data matching degree, the data amount coincidence degree and the data level similarity, the access information risk index is calculated.
[0031] Further, the determination of threat intelligence data based on network sensitive information risk value and network boundary data includes:
[0032] According to the actual demand, the risk threshold is set; it is judged whether the network sensitive information risk value is less than the risk threshold; if so, the user access request is agreed, and the corresponding data content is called to feedback to the application user, completing the protection of the user access request;
[0033] Otherwise, the user access request is regarded as dangerous behavior, and the network boundary data is analyzed to obtain the corresponding network security analysis result;
[0034] Based on the network security analysis result, the potential threat is identified through the defense detection system and the firewall;
[0035] The dangerous behavior and the potential threat are associated and analyzed to obtain the corresponding association analysis result;
[0036] Based on the association analysis result, the threat intelligence data is determined.
[0037] Further, the dynamic adjustment of the security protection strategy based on the threat intelligence data and the core communication link data, and the implementation, include:
[0038] The core communication link data is identified to obtain an abnormal communication mode;
[0039] The threat intelligence data is parsed to extract key information in the threat intelligence data;
[0040] Based on the key information and the abnormal communication mode, the threat severity is evaluated;
[0041] Based on the threat severity, the security protection strategy is dynamically adjusted to obtain an adjusted security protection strategy and implement it.
[0042] A multi-level adaptive network security protection system is provided, which includes:
[0043] A user access request collection module is configured to acquire a user access request at a terminal device layer of the multi-level adaptive network;
[0044] A user access data acquisition module is configured to acquire user access data based on the user access request by issuing a key through a hardware security module; the user access data includes application access data, network boundary data, core communication link data, terminal device data, and a key time interval;
[0045] A network sensitive information risk calculation module is configured to calculate a network sensitive information risk value based on the application access data, the terminal device data, and the key time interval;
[0046] A threat intelligence data analysis module is configured to determine threat intelligence data based on the network sensitive information risk value and the network boundary data;
[0047] A security protection strategy adjustment module is configured to dynamically adjust a security protection strategy based on the threat intelligence data and the core communication link data, and implement it.
[0048] Further, the network sensitive information risk calculation module includes:
[0049] A related parameter setting unit is configured to set a sensitive factor and construct a department correlation matrix;
[0050] A level risk index calculation unit is configured to calculate a level risk index based on the department correlation matrix, the sensitive factor, and the terminal device data;
[0051] A time risk index calculation unit is configured to calculate a time risk index based on the terminal device data and the application access data;
[0052] The access information risk index calculation unit is configured to call application data content corresponding to the user access request, and calculate an access information risk index based on terminal device data and application access data.
[0053] The network sensitive information risk calculation unit is configured to calculate a network sensitive information risk value based on the level risk index, the time risk index and the access information risk index.
[0054] The present application has the following beneficial effects:
[0055] The present application obtains a user access request at a terminal device layer, obtains user access data by combining a hardware security module to issue a key, calculates a network sensitive information risk value, determines threat intelligence data, and dynamically adjusts a security protection strategy based on the data, thereby comprehensively improving real-time performance, accuracy and adaptability of network security protection, discovering and responding to potential security threats in a timely manner, effectively protecting enterprise networks and data assets, and achieving precise risk assessment and automatic security decision-making through comprehensive analysis and utilization of multi-dimensional data, improving efficiency and effectiveness of network security management, and reducing the possibility of security incidents and negative impact on enterprise business. BRIEF DESCRIPTION OF DRAWINGS
[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments, and it should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0057] Figure 1 The present application has the following beneficial effects:
[0058] Figure 2 The present application has the following beneficial effects:
[0059] Figure 3 The present application has the following beneficial effects:
[0060] Figure 4 The present application has the following beneficial effects: DETAILED DESCRIPTION
[0061] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. The components of the embodiments of the present application described and shown in the drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.
[0062] Referring to Figure 1 The embodiment provides a multi-level adaptive network security protection method, which comprises the following steps.
[0063] S1, obtaining a user access request at a terminal device layer of a multi-level adaptive network. The user access request refers to data content required by a user, for example, a staff of a research and development department needs to call product parameters and research and development data of the company.
[0064] The multi-level adaptive network comprises a hardware security module, a terminal device layer, a network boundary layer, a core communication link and an application layer.
[0065] S2, issuing a key based on the user access request through the hardware security module to obtain user access data. The user access data comprises application access data, network boundary data, core communication link data, terminal device data and a key time interval. The key time interval refers to a time interval from issuing the key to inputting the key.
[0066] Therefore, the S2 comprises the following steps.
[0067] S2-1, authenticating the user; if the authentication fails, determining that the threat level is medium and entering S5-4; otherwise, entering S2-2. The user refers to a person who issues the user access request.
[0068] S2-2, issuing the key to the user end through the hardware security module of the multi-level adaptive network to obtain the key time interval.
[0069] S2-3, obtaining the application access data, the network boundary data, the core communication link data and the terminal device data of each level in the multi-level adaptive network.
[0070] The terminal device data is data in the terminal device layer, and the access information of the user includes a department to which the user belongs, a user level, a device number / IP address, an application time, an application frequency, a department to which application data belongs, an application data size, and an application data level. The user level refers to a permission level set according to a post of the user, for example, the permission level of a general manager is 3, the permission level of a manager is 2, and the permission level decreases as the post level decreases.
[0071] The application access data is historical access information of the user, and the historical access information includes a historical device number / IP address, a historical application time, a department to which historical application data belongs, a historical application data size, a historical application data level, historical application data content, a historical application frequency, a historical key input time interval, and historical collaboration information of the department to which the user belongs and other departments. The historical collaboration information includes a historical collaboration frequency and a historical data sharing frequency.
[0072] The core communication link data is data in the core communication link, and includes a link traffic size and a link traffic rate.
[0073] The network boundary data is data in the network boundary layer, and includes traffic data, a connection state network, and external attack information. The traffic data includes a traffic size, a direction, a protocol type, a port number, and the like of traffic flowing into and out of the network; by deploying a firewall, an intrusion detection system (IDS) / intrusion prevention system (IPS), and the like in the network boundary, network traffic can be monitored and recorded in real time, and overall traffic conditions and external access requests of the network can be understood. The connection state network includes a source IP address, a destination IP address, a connection establishment time, a connection duration, and the like of a connection, and can be used to track connection behavior and session states in the network.
[0074] The application precisely collects multi-source data of an enterprise / company, facilitates unified management and analysis, and improves access management efficiency. Management difficulties and analysis complexity caused by scattered data storage are avoided, and convenience is provided for subsequent security policy adjustment.
[0075] S3, based on the application access data, the terminal device data, and the key time interval, calculates a network sensitive information risk value. Multi-dimensional data is converted into a specific network sensitive information risk value, and an intuitive risk evaluation index is provided for an enterprise. A key basis is provided for subsequent dynamic adjustment of a security protection strategy, and security measures are ensured to match the risk level.
[0076] As shown in Figure 2 S3 includes:
[0077] S3-1, based on the application time, the device number / IP address, and the historical device number / IP address, sets a sensitive factor If the application time is in working hours, the sensitive factor is -0.2; if the device number belongs to historical device numbers, the sensitive factor is -0.1; if the IP address does not belong to historical IP addresses, the sensitive factor is -0.3.
[0078] S3-2, based on the historical collaboration information of the department to which the user belongs and other departments, a department correlation matrix is constructed. The department correlation matrix is a two-dimensional matrix that quantifies the collaboration tightness between departments in an organization, with a value range of [0, 1]. Thus, the formula corresponding to the department correlation matrix is:
[0079] ;
[0080] ;
[0081] ;
[0082] wherein, denotes the department correlation matrix between the department to which the user belongs and the department to which the application data belongs , , respectively denote the collaboration matrix between the department to which the user belongs and the department to which the application data belongs , respectively, denotes the total number of departments of the enterprise / company, denotes the summation function, , respectively denote the collaboration frequency matrix and the sharing frequency matrix, denotes the collaboration frequency between the department to which the user belongs and the department to which the application data belongs , , respectively denote the maximum and minimum collaboration frequencies of the department to which the user belongs , denotes the natural constant e-based logarithmic function, , respectively denote the sharing frequency between the department to which the user belongs and the department to which the application data belongs , and the maximum sharing frequency of the department to which the user belongs . Department refers to other departments except the department to which the user belongs .
[0083] S3-3, based on the department correlation matrix, the sensitive factor, the user level and the application data level, the level risk index is calculated.
[0084] Grade risk indicator The corresponding formula is:
[0085] ;
[0086] ;
[0087] wherein, , , sensitive weight coefficient, and the corresponding values are greater than 0, indicates the historical frequency of the user applying for the same department data, indicates the user-data grade indicator, indicates the preset maximum allowed grade difference, , respectively indicate the user grade and the application data grade, indicates the absolute value. and , .
[0088] S3-4, based on the application time, the application frequency, the key input time interval, the historical application time, the historical application frequency and the historical key input time interval, calculate the time risk indicator.
[0089] The S3-4 includes:
[0090] S3-4-1, normalize the historical application time, the historical application frequency and the historical key input time interval; each time an application is made, the application frequency is increased by 1; thus, each application time has a corresponding historical key input time interval and historical application frequency.
[0091] S3-4-2, based on each normalized historical application time and its corresponding normalized historical application frequency and normalized historical key input time interval, draw the corresponding three-dimensional time distribution graph through the kernel density estimation method. The XYZ axes of the three-dimensional time distribution graph are the values corresponding to the application time, the application frequency and the key input time interval.
[0092] S3-4-3, normalize and integrate the application time, the application frequency and the key input time interval into application coordinate data.
[0093] S3-4-4, calculate the distance between the application coordinate data and all coordinate points of the three-dimensional time distribution graph; based on all the distances, calculate the corresponding average distance.
[0094] S3-4-5, judging whether the average distance is less than a distance threshold value; if yes, the application coordinate data is dropped on the three-dimensional time distribution map, and the value of the time similarity index is set to 0; otherwise, S3-4-6 is entered. The distance threshold value is set according to the experience of network security personnel in different situations.
[0095] S3-4-6, calculating the vertical distance between the application coordinate data and the three-dimensional time distribution map as the time similarity index.
[0096] S3-5, calling the application data content corresponding to the user access request, and calculating the access information risk index based on the application data size, the application data level, the historical application data size, the historical application data level and the historical application data content.
[0097] The S3-5 includes:
[0098] S3-5-1, matching the application data content and the historical application data content to calculate the corresponding data matching degree , including:
[0099] The application data content is subjected to data cleaning to eliminate special characters, stop words and punctuation marks in the application data content, and the text is uniformly converted to lowercase to obtain application cleaning data.
[0100] The application cleaning data is subjected to word segmentation, stem extraction and lemmatization to obtain application segmented data.
[0101] The application segmented data is subjected to feature extraction to obtain corresponding application feature vector data.
[0102] The similarity between the application feature vector data and the historical application data content is calculated, and the average value of each similarity is taken as the data matching degree. The similarity can adopt cosine similarity, Jaccard similarity coefficient and edit distance. Among them, word segmentation, stem extraction, lemmatization and feature extraction are prior art, and therefore are not described in detail.
[0103] S3-5-2, calculating the data quantity coincidence degree based on the application data size and the historical application data size , the corresponding formula is:
[0104] ;
[0105] Among them, represents the application data size, represents the average value of the historical application data size.
[0106] S3-5-3, determining the data level similarity based on the application data level and the historical application data level , the corresponding formula is:
[0107] ;
[0108] wherein, represents the application data level, represents the mean value of the historical application data level.
[0109] S3-5-4, based on the data matching degree, the data amount coincidence degree and the data level similarity, the access information risk index is calculated , the corresponding formula is:
[0110] ;
[0111] wherein, , , represents the access information weight coefficient, and the corresponding value is greater than 0, wherein, and , .
[0112] S3-6, based on the level risk index , the time risk index and the access information risk index , the network sensitive information risk value , the corresponding formula is:
[0113] ;
[0114] wherein, , , represents the network sensitive weight coefficient, and the corresponding value is greater than 0, wherein, .
[0115] The application comprehensively considers time, user level, data level, historical behavior and other multi-dimensional factors, comprehensively and accurately evaluates the risk degree of network access behavior, reduces false negatives and false positives. Refine the risk assessment to specific indicators, realize the quantization and hierarchical management of risk, help to take targeted protection measures, help to monitor key risk factors in real time, dynamically update risk values, and capture potential threats in time. Provide accurate risk assessment data, help dynamic adjustment of security policy and intelligent decision-making, and improve the automation and intelligent level of network security protection. The weight coefficient and risk threshold can be adjusted according to the enterprise demand, and the network security demand of different enterprises and industries can be flexibly adapted, which provides quantitative basis for dynamic adjustment of security protection strategy, and strict protection measures are taken in time for high-risk behavior.
[0116] S4, based on the network sensitive information risk value and the network boundary data, the threat intelligence data is determined.
[0117] The S4 comprises:
[0118] S4-1, setting a risk threshold according to actual needs; judging whether the network sensitive information risk value exceeds the risk threshold; if yes, regarding the user access request as dangerous behavior, and entering S4-2; otherwise, agreeing to the user access request, calling corresponding data content feedback to the user, completing the protection of the user access request, and implementing the security protection strategy of the previous protection. Using the network sensitive information risk value for judgment can quickly distinguish high-risk access requests, timely issue early warnings, enable enterprises to quickly respond to potential threats, provide automated decision-making basis for the security system of the enterprise, reduce manual intervention, and improve efficiency.
[0119] S4-2, analyzing the network boundary data to obtain corresponding network security analysis results.
[0120] The network security analysis results include traffic data analysis results, connection state analysis results, and external attack analysis results, so that the S4-2 comprises:
[0121] The traffic data is monitored to analyze the traffic size and change trend to obtain traffic data analysis results, which can be used to identify abnormal traffic peaks or traffic surges. If abnormal traffic peaks or traffic surges occur, it indicates that the enterprise / company may be subjected to network attacks or data breaches.
[0122] The connection state network is checked to identify connections from suspicious IP addresses, a large number of connection attempts in a short time, or abnormal connection duration to obtain connection state analysis results.
[0123] The external attack information is analyzed to determine the type, frequency, and intensity of attacks to obtain external attack analysis results. The analysis process in S4-2 uses existing network analysis methods.
[0124] S4-3, based on the network security analysis results, identifying potential threats through a defense detection system (IDS intrusion detection system, IPS intrusion prevention system) and a firewall. The network complete analysis results are identified through the defense detection system (IDS intrusion detection system, IPS intrusion prevention system) and the firewall respectively to obtain corresponding identification results; all identification results are integrated to obtain potential threats.
[0125] S4-4, correlating dangerous behavior and potential threats to obtain corresponding correlation analysis results.
[0126] The dangerous behavior and the potential danger are integrated to obtain a dangerous data set; a potential relationship between different data in the dangerous data set is extracted by using a correlation rule mining algorithm, and the relationship between the dangerous behavior and the potential threat and a specific business activity is determined and displayed through a graphical interface by combining the business process and the network architecture of the enterprise. The graphical interface can adopt a network topology diagram or a time sequence diagram.
[0127] S4-5, determining threat intelligence data based on the correlation analysis result. The correlation analysis result and the dangerous data set are processed by using machine learning to extract threat features; all the extracted threat features are integrated to obtain threat intelligence data. Machine learning can adopt a clustering algorithm, a decision tree algorithm and a random forest.
[0128] The network boundary data is analyzed, comprehensive network security situation awareness can be provided, the enterprise can realize real-time network condition, abnormal traffic peak or traffic burst can be found in time, DDoS attack or data leakage event can be quickly detected, the influence of the DDoS attack or the data leakage event on the enterprise network can be reduced, abnormal behaviors such as connection from a suspicious IP address and a large number of connection attempts in a short time can be identified, and a brute force attack or a malicious scanning behavior can be found early. Based on the network security analysis result, potential threats can be identified through a defense detection system and a firewall, the detection results of an IDS, an IPS and the firewall are fused, the threat detection accuracy is improved, the false negative rate is reduced, potential threats can be identified and responded in time. The hidden relationship between the dangerous behavior and the potential threat is revealed by performing correlation analysis on the dangerous behavior and the potential threat, deeper threat insight is provided, the enterprise can formulate more effective security strategies, the relationship between the dangerous behavior and the potential threat and business activities is clear, accurate security protection strategies are formulated, and key business assets are protected; threat features are extracted by using machine learning, threat intelligence data is obtained by integration, the machine learning algorithm automatically extracts the threat features, the feature extraction efficiency and accuracy are improved, new threats can be quickly identified by the enterprise, the threat intelligence data is formed by integrating the threat features, the enterprise internal sharing and sharing with other organizations are facilitated, and the overall network security protection level is improved.
[0129] S5, dynamically adjusting and implementing the security protection strategy based on the threat intelligence data and the core communication link data.
[0130] The S5 includes:
[0131] S5-1, identifying the core communication link data to obtain an abnormal communication mode.
[0132] The normal behavior baseline of the core communication link is established by using the historical core communication link data, the normal traffic range, the typical delay value and the packet loss rate are determined.
[0133] The comparison result is obtained by comparing the core communication link data with the normal behavior baseline.
[0134] Based on the comparison results, use statistical analysis or machine learning algorithms to identify abnormal patterns such as traffic surges, excessive delays, or abnormal packet loss rates; record relevant information such as the time of occurrence, duration, and involved links, integrate the abnormal patterns and relevant information, and obtain abnormal communication patterns.
[0135] S5-2, analyze threat intelligence data and extract key information such as attack source IP address, attack type, attack time, affected system or data type, etc.
[0136] Extract attack source IP, attack type, attack time, affected system, etc. Raw key information; classify and agree on the information format of the initial key information to obtain the initial key information; based on the preset filtering conditions, filter the initial key information to obtain the key information. The filtering conditions can be preset rules or importance levels, which are set according to actual needs / conditions.
[0137] S5-3, based on the key information and abnormal communication patterns, assess the threat severity.
[0138] S5-3 includes:
[0139] S5-3-1, associate and analyze the key information and abnormal communication patterns, for example, check if the attack source IP matches the source IP of the abnormal link traffic, or if the attack time coincides with the abnormal communication time period, to obtain corresponding threat association information.
[0140] S5-3-2, input the threat association information, key information, and abnormal communication patterns into the risk assessment model: use the risk assessment model to consider the possibility and impact of threats comprehensively to obtain the corresponding risk assessment result, i.e. threat severity. Threat severity is divided into three levels: high, medium, and low. The risk assessment model can use LSTM neural network, DBN neural network, and Transformer neural network.
[0141] S5-4, based on the threat severity, dynamically adjust the security protection strategy to obtain the adjusted security protection strategy and implement it.
[0142] When the threat severity is high, high-risk threat strategy is adopted and implemented, user access request is immediately rejected, attack source IP is blocked, unnecessary ports of affected systems are closed, protection mode is turned on, and warning signal is sent to network security protection department or department responsible for network security.
[0143] When the threat severity is medium, a medium-risk threat strategy is adopted and implemented, the user is repeatedly authenticated, including but not limited to face recognition, fingerprint recognition and other verification methods, a warning signal is sent to a network security protection department or a department responsible for network security, monitoring of an affected system or link is strengthened, and access rights of some suspicious IP are limited.
[0144] When the threat severity is low, normal monitoring is maintained, and slight protection measures are considered to be taken without affecting business.
[0145] The application can accurately identify abnormal communication patterns through identification and analysis of core communication link data; the analysis of threat intelligence data and the extraction of key information help to quickly focus on key threat features, improve the efficiency and accuracy of threat identification; based on the correlation analysis of key information and abnormal communication patterns and the application of a risk assessment model, the threat severity is scientifically evaluated, the threat is managed in a hierarchical manner, and the enterprise can allocate limited security resources to high-risk threats. According to the threat severity, the security protection strategy is dynamically adjusted, so that the network security protection measures of the enterprise are more targeted and timely, which can effectively block the attack source and reduce the impact of security incidents on business operation. At the same time, through different levels of threat response strategies, fine management of security protection is realized, and the safe and stable operation of the enterprise network is ensured.
[0146] As shown in Figure 3 , a multi-level adaptive network security protection system comprises:
[0147] A user access request collection module is configured to acquire a user access request at a terminal device layer of a multi-level adaptive network.
[0148] A user access data acquisition module is configured to acquire user access data based on the user access request by issuing a key through a hardware security module; the user access data comprises application access data, network boundary data, core communication link data, terminal device data and a key time interval.
[0149] A network sensitive information risk calculation module is configured to calculate a network sensitive information risk value based on the application access data, the terminal device data and the key time interval.
[0150] A threat intelligence data analysis module is configured to determine threat intelligence data based on the network sensitive information risk value and the network boundary data.
[0151] A security protection strategy adjustment module is configured to dynamically adjust and implement a security protection strategy based on the threat intelligence data and the core communication link data.
[0152] As shown in Figure 4 , the network sensitive information risk calculation module comprises:
[0153] A correlation parameter setting unit is configured to set a sensitive factor and construct a department correlation matrix.
[0154] A grade risk index calculation unit is configured to calculate a grade risk index based on the department correlation matrix, the sensitive factor and terminal device data.
[0155] A time risk index calculation unit is configured to calculate a time risk index based on terminal device data and application access data.
[0156] An access information risk index calculation unit is configured to call application data content corresponding to a user access request, and calculate an access information risk index based on terminal device data and application access data.
[0157] A network sensitive information risk calculation unit is configured to calculate a network sensitive information risk value based on the grade risk index, the time risk index and the access information risk index.
[0158] To sum up, the application obtains a user access request at a terminal device layer, obtains user access data by combining a hardware security module to issue a key, calculates a network sensitive information risk value, determines threat intelligence data, and dynamically adjusts a security protection strategy based on the data, thereby comprehensively improving the real-time performance, accuracy and adaptability of network security protection, discovering and responding to potential security threats in a timely manner, effectively protecting enterprise networks and data assets, integrating and analyzing multi-dimensional data to achieve accurate risk assessment and automatic security decision-making, improving the efficiency and effectiveness of network security management, and reducing the possibility of security incidents and their negative impact on enterprise business.
[0159] The above merely describes specific embodiments of the application, but the protection scope of the application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the application, which should be covered within the protection scope of the application. Therefore, the protection scope of the application should be subject to the protection scope of the claims.
Claims
1. A multi-level adaptive network security protection method, characterized in that, include: Obtain user access requests at the terminal device layer of a multi-level adaptive network; Based on user access requests, a key is issued through a hardware security module to obtain user access data; the user access data includes application access data, network boundary data, core communication link data, terminal device data, and key time intervals; Based on application access data, terminal device data, and key time intervals, a network sensitive information risk value is calculated. The terminal device data includes the user's department, user level, device number / IP address, application time, application frequency, department to which the applied data belongs, application data size, and application data level. The application access data includes historical device number / IP address, historical application time, department to which historical application data belongs, historical application data size, historical application data level, historical application data content, historical application frequency, historical key input time intervals, and historical collaboration information between the user's department and other departments. Threat intelligence data is determined based on network sensitive information risk values and network boundary data; Based on threat intelligence data and core communication link data, dynamically adjust and implement security protection strategies. The calculation of network sensitive information risk value includes: Sensitive factors are set based on application time, device ID / IP address, and historical device ID / IP address; A department association matrix is constructed based on the user's department and historical collaboration information with other departments; the historical collaboration information includes the number of historical collaborations and the number of historical data sharings. Based on the departmental association matrix, sensitive factors, user level, and application data level, calculate the level risk index; Calculate time risk indicators based on application time, application frequency, key input time interval, historical application time, historical application frequency, and historical key input time interval; The system retrieves the application data content corresponding to the user's access request, and generates data matching degree, data volume overlap degree, and data level similarity based on the application data size, application data level, historical application data size, historical application data level, and historical application data content, and calculates access information risk indicators. Based on the risk level indicator, time risk indicator, and access information risk indicator, calculate the risk value of network sensitive information; The formula corresponding to the risk value of the network sensitive information is: ; ; ; ; in, Indicates the risk value of sensitive network information. , , Represents the network sensitivity weight coefficient. , , These represent the risk level indicator, the time risk indicator, and the access information risk indicator, respectively. , , Indicates the sensitive weight coefficient. This indicates the historical frequency of data requests from the same user to the same department. This indicates the user application - data level indicator. This indicates the preset maximum allowable level difference. , These represent user level and requested data level, respectively. Represents absolute value. , , This represents the access information weighting coefficient. , , These represent data matching degree, data volume overlap degree, and data level similarity, respectively. Indicates sensitive factors; The formula corresponding to the departmental association matrix is: ; ; ; in, Represents the departmental association matrix. , These represent the user's department. Each with the department to which the requested data belongs ,department The collaboration matrix between them This indicates the total number of departments in the enterprise / company. This represents the summation function. , These represent the collaboration frequency matrix and the sharing frequency matrix, respectively. Indicates the user's department and the department to which the application data belongs The number of historical collaborations between them , These represent the user's department. The minimum and maximum values of the historical number of collaborations. Let represent a logarithmic function with base e. , These represent the user's department. and the department to which the application data belongs Historical data sharing frequency between them, user's department The maximum number of times historical data can be shared.
2. The multi-level adaptive network security protection method according to claim 1, characterized in that, The process of calculating the time risk index includes: The historical application time, historical application frequency, and historical key input time interval are normalized. Based on the normalized historical application time, its corresponding normalized historical application frequency, and the normalized historical key input time interval, a corresponding three-dimensional time distribution map is drawn using the kernel density estimation method. The application time, application frequency, and key input time interval are normalized and integrated into application coordinate data; Calculate the distance between the applied coordinate data and all coordinate points on the 3D time distribution map; based on all distances, calculate the corresponding average distance; Determine if the average distance is less than the distance threshold; if so, the application coordinate data falls on the three-dimensional time distribution map, and the value of the time risk indicator is set to 0; otherwise, calculate the vertical distance between the application coordinate data and the three-dimensional time distribution map, and use it as the time risk indicator.
3. The multi-level adaptive network security protection method according to claim 1, characterized in that, The process of calculating the access information risk index includes: The application data content is matched with the historical application data content, and the corresponding data matching degree is calculated; Calculate the data overlap based on the size of the application data and the size of historical application data; Determine the data level similarity based on the application data level and the historical application data level; Based on data matching degree, data volume overlap degree, and data level similarity, access information risk indicators are calculated.
4. The multi-level adaptive network security protection method according to claim 1, characterized in that, The determination of threat intelligence data based on network sensitive information risk values and network boundary data includes: Set risk thresholds according to actual needs; determine whether the risk value of sensitive network information is less than the risk threshold; if so, grant the user's access request, retrieve the corresponding data content and send it back to the user, thus completing the protection of the user's access request; Conversely, user access requests are considered dangerous behaviors, and network boundary data is analyzed to obtain corresponding network security analysis results. Based on network security analysis results, potential threats are identified through defense detection systems and firewalls; A correlation analysis was conducted between dangerous behaviors and potential threats to obtain the corresponding correlation analysis results. Threat intelligence data was identified based on the correlation analysis results.
5. The multi-level adaptive network security protection method according to claim 1, characterized in that, The dynamic adjustment and implementation of security protection strategies based on threat intelligence data and core communication link data includes: By identifying core communication link data, abnormal communication patterns can be obtained; Analyze threat intelligence data and extract key information from it; Assess the severity of the threat based on key information and unusual communication patterns; Based on the severity of the threat, the security protection strategy is dynamically adjusted to obtain the adjusted security protection strategy and then implemented.
6. A multi-level adaptive network security protection system, used to implement the multi-level adaptive network security protection method according to any one of claims 1 to 5, characterized in that, include: The user access request acquisition module is used to acquire user access requests at the terminal device layer of a multi-level adaptive network. The user access data acquisition module is used to acquire user access data based on user access requests by issuing keys through the hardware security module; the user access data includes application access data, network boundary data, core communication link data, terminal device data, and key time interval. The network sensitive information risk calculation module is used to calculate the network sensitive information risk value based on application access data, terminal device data, and key time intervals. The threat intelligence data analysis module is used to determine threat intelligence data based on network sensitive information risk values and network boundary data. The security protection strategy adjustment module is used to dynamically adjust and implement security protection strategies based on threat intelligence data and core communication link data.
7. The multi-level adaptive network security protection system according to claim 6, characterized in that, The network sensitive information risk calculation module includes: The relevant parameter setting unit is used to set sensitivity factors and construct departmental association matrices; The risk level indicator calculation unit is used to calculate risk level indicators based on departmental correlation matrix, sensitive factors, and terminal device data. The time risk indicator calculation unit is used to calculate time risk indicators based on terminal device data and application access data. The access information risk indicator calculation unit is used to call the application data content corresponding to the user access request, and calculate the access information risk indicator based on terminal device data and application access data. The network sensitive information risk calculation unit is used to calculate the network sensitive information risk value based on the level risk indicator, time risk indicator, and access information risk indicator.
Citation Information
Patent Citations
Computer storage file protection system
CN119249499A
Information security risk assessment method and system based on API
CN119788309A