Preplan generation and execution method and system for network security emergency response

By building a threat model based on knowledge graphs and optimizing the graph neural network, an intelligent emergency response plan is generated, and real-time monitoring and dynamic adjustments are carried out, the problems of insufficient threat perception capabilities, low plan generation efficiency and unreasonable resource allocation in the existing technology are solved, and efficient and intelligent network security emergency response is achieved.

CN120200786APending Publication Date: 2025-06-24GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510285391.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing network security emergency response technology has problems such as insufficient threat perception capabilities, low plan generation efficiency, unreasonable resource allocation and lack of closed-loop feedback mechanisms.

Method used

By building a threat model based on knowledge graphs, using graph neural networks to optimize deep learning, generate intelligent emergency response plans, and monitor network status in real time during the implementation of the plan, and dynamically adjust plan parameters.

Benefits of technology

It significantly improves threat perception and plan generation efficiency, improves resource utilization and system adaptability, forms a closed-loop feedback system, and enhances the intelligence level of network security emergency response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200786A_ABST
    Figure CN120200786A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a plan generation and execution method and system for network security emergency response, and the method comprises the following steps: obtaining and preprocessing network security threat data, extracting key features, and constructing a threat model; based on the threat model, generating at least one emergency response plan through a preset algorithm; sorting the generated plans according to priorities, and selecting an optimal plan for execution; the network state is monitored in real time in the plan execution process, plan parameters are dynamically adjusted according to the feedback result, and the plan parameters are used for conducting result adjustment in the plan process. The system corresponds to the method. By the adoption of the method and device, the defects of a traditional method in threat identification and resource scheduling are effectively overcome, and a reliable solution is provided for modern network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and specifically to a method and system for generating and executing emergency response plans for network security. Background Art

[0002] With the increasing complexity and diversification of network attack means, traditional network security protection measures (such as firewalls, intrusion detection systems, etc.) are difficult to meet the needs of modern enterprises for rapid response and efficient disposal. The current network security emergency response methods mainly have the following problems:

[0003] Insufficient threat perception ability: Existing systems usually rely on predefined rules or a single data source for threat detection, and cannot comprehensively capture complex network threat characteristics. Lack of the ability to deeply mine threat intelligence, resulting in a low recognition rate of new attacks.

[0004] Low efficiency in generating emergency response plans: Traditional methods of generating emergency response plans mostly rely on manual experience, which takes a long time and is prone to missing key links. The emergency response plans lack an intelligent adjustment mechanism and have poor adaptability in the face of a dynamically changing threat environment.

[0005] Unreasonable resource allocation: In a large-scale distributed network environment, task scheduling and resource allocation often rely on static policies and do not fully consider real-time load and priority requirements. The phenomenon of resource contention is serious, and it may lead to high-priority tasks being delayed due to insufficient resources.

[0006] Lack of a closed-loop feedback mechanism: Existing systems lack real-time monitoring and dynamic adjustment functions during the execution of emergency response plans, and it is difficult to optimize subsequent response strategies according to the actual effects. The data records are scattered and opaque, which is not conducive to historical data analysis and experience accumulation.

[0007] In recent years, emerging technologies such as artificial intelligence, edge computing, and blockchain have provided new ideas for solving the above problems:

[0008] Knowledge graph and graph neural network: By constructing a threat knowledge base and combining deep learning models, the threat perception ability and prediction accuracy can be significantly improved. Edge computing and distributed architecture: Support low-latency and high-efficiency task coordination and resource allocation, and are suitable for large-scale distributed network environments.

[0009] Although these technologies show great potential, they still face many challenges in practical applications. Summary of the Invention

[0010] The purpose of this application is to provide a method and system for generating and executing emergency response plans for network security, aiming to overcome the defects in the prior art, solve the problems existing in the current network security emergency response technology, and improve the technical intelligence level, resource utilization rate, and security.

[0011] To achieve the above object, the present application discloses the following technical solutions:

[0012] In a first aspect, the present application discloses a method for generating and executing a contingency plan for network security emergency response, the method comprising the following steps:

[0013] Obtain network security threat data and perform preprocessing, extract key features and construct a threat model;

[0014] Based on the threat model, generate at least one emergency response plan through a preset algorithm;

[0015] Sort the generated plans according to priority and select the optimal plan for execution;

[0016] During the execution of the plan, monitor the network status in real time and dynamically adjust the plan parameters according to the feedback results, where the plan parameters are used to adjust the results during the plan process.

[0017] Preferably, the construction of the threat model adopts semantic analysis technology based on a knowledge graph, and forms a multi-level and multi-dimensional threat knowledge base by integrating ontology knowledge in the field of network security and real-time threat intelligence data.

[0018] Preferably, the construction of the threat model specifically includes the following steps:

[0019] Construct an ontology knowledge framework in the field of network security, define key entities and their relationships, where the key entities include threat types, attack paths, and affected assets;

[0020] Collect and parse real-time threat intelligence data, and extract structured and unstructured information related to threats;

[0021] Use natural language processing technology to perform semantic analysis on unstructured threat intelligence and convert it into a quantifiable feature vector;

[0022] Map the extracted feature vectors into the knowledge graph, establish the association relationship between entities, and generate a dynamically updated threat model.

[0023] Preferably, the construction of the threat model further includes: performing deep learning optimization on the knowledge graph; the specific steps of performing deep learning optimization on the knowledge graph include:

[0024] Define the knowledge graph as a graph structure G=(V, E), where the node V is a set of nodes and the edge E is a set of edges;

[0025] Use a graph neural network to perform embedding learning on the graph structure, map each node v∈V to a low-dimensional vector space, and perform node embedding by aggregating neighbor node information and transforming its own features;

[0026] Use a graph convolutional network or a graph attention network to perform end-to-end training on the graph structure and optimize the objective function of the threat prediction task.

[0027] Preferably, the node embedding by aggregating neighbor node information and transforming its own features specifically includes:

[0028] Calculate the set of neighbor nodes N(v) of node v;

[0029] Use an aggregation function and a transformation function to generate node embeddings. The formula for node embeddings is:

[0030] Zv = Aggregate({Zu|u∈N(v)}) + Ttansform(xv)

[0031] where Zv is the embedding vector of node v, xv is the initial feature vector of node v, Aggregate() is the aggregation function, and Ttansform() is the transformation function.

[0032] Preferably, the objective function is achieved by maximizing the conditional probability between the class label and the node embedding. The specific formula for the objective function is:

[0033] L = -∑ ( v,c ∈D) logP(c|Zv)

[0034] where D is the training data set, c is the class label of the node, and P(c|Zv) is the conditional probability of class c given the node embedding Zv.

[0035] Preferably, the generated plans are sorted according to priority, specifically including: calculating the risk assessment value through non-linear normalization and dynamic adjustment mechanism according to the threat level, resource requirements, and execution cost. The higher the risk assessment value, the higher the priority of the corresponding plan.

[0036] Preferably, the network status is monitored in real time during the execution of the plan, specifically including:

[0037] Continuously collect network status data, including traffic information, log records, and performance metrics;

[0038] Perform anomaly detection on the collected data to identify potential security risks;

[0039] Compare the detection results with predefined thresholds and trigger corresponding warning mechanisms.

[0040] Preferably, the dynamic adjustment of the pre - plan parameters is achieved through the Bayesian update principle.

[0041] In a second aspect, the present application discloses a pre - plan generation and execution system for network security emergency response, which applies the pre - plan generation and execution method for network security emergency response described above, including:

[0042] A data collection module, configured to: obtain network security threat data and perform pre - processing;

[0043] A model construction module, configured to: extract key features from the pre - processed data and construct a threat model;

[0044] A pre - plan generation module, configured to: generate at least one emergency response pre - plan based on the threat model through a preset algorithm;

[0045] A pre - plan selection module, configured to: sort the generated pre - plans according to priority and select the optimal pre - plan for execution;

[0046] An execution supervision module, configured to: monitor the network status in real - time during the execution of the pre - plan, and dynamically adjust the pre - plan parameters according to the feedback results, where the pre - plan parameters are used to adjust the results during the pre - plan process.

[0047] The pre - plan generation and execution method and system for network security emergency response of the present application have the following beneficial effects compared with the prior art:

[0048] By integrating the ontology knowledge and real - time threat intelligence data in the field of network security, a multi - level and multi - dimensional threat knowledge base is constructed. Using graph neural networks to optimize the knowledge graph through deep learning, the prediction ability and generalization performance of the threat model are greatly improved, and it can capture the complexity and dynamic change characteristics of network threats more comprehensively. Multiple candidate pre - plans are generated based on the threat model, and the pre - plans are sorted according to priority through a comprehensive evaluation function to ensure that the optimal pre - plan is executed first. During the execution of the pre - plan, the network status data is collected through the real - time monitoring module, improving the adaptive ability of the system. At the same time, continuously collect network status data, identify potential risks through anomaly detection algorithms, trigger corresponding warning mechanisms, and combine feedback to dynamically adjust the task scheduling strategy to form a closed - loop feedback system, improving the intelligent level of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.

[0050] Figure 1 It is a flowchart of the method for generating and executing a plan for network security emergency response provided in this embodiment. Specific implementation manners

[0051] Next, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0052] In this article, the term "including" is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article or device. Without more limitations, the elements defined by the statement "including..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0053] This embodiment provides a method for generating and executing a plan for network security emergency response as shown in Figure 1 The method includes the following steps:

[0054] S1 - Obtain network security threat data and perform preprocessing, extract key features and construct a threat model. Specifically, through sensors or log collection tools deployed in the network, threat information such as traffic data and abnormal behaviors are captured in real time. For example, DDoS attack traffic characteristics (such as packet rate, source IP distribution) are captured, and cleaning and feature extraction are performed. Machine learning algorithms are used to model the preprocessed data to generate a knowledge representation reflecting the current threat situation.

[0055] S2 - Based on the threat model, generate at least one emergency response plan through a preset algorithm. For example, for a DDoS attack, the corresponding emergency response plan may include operations such as "enable firewall rules" and "increase bandwidth limit".

[0056] S3 - Sort the generated plans according to the priority and select the optimal plan for execution.

[0057] S4 - Monitor the network status in real time during the execution of the plan, and dynamically adjust the plan parameters according to the feedback results. The plan parameters are used to adjust the results during the plan process.

[0058] In this embodiment, the construction of the threat model adopts semantic analysis technology based on a knowledge graph. By integrating ontology knowledge in the field of network security and real-time threat intelligence data, a multi-level and multi-dimensional threat knowledge base is formed. The construction of the threat model specifically includes the following steps:

[0059] Construct an ontology knowledge framework in the field of network security, define key entities (such as attackers, vulnerabilities, assets) and their relationships (such as "attackers use vulnerabilities to attack assets"). The key entities include threat types, attack paths, and affected assets. For the ontology knowledge framework, for example, the set of edges between the "attack path" entity and the "affected asset" can be defined as "influence".

[0060] Collect and analyze real-time threat intelligence data, and extract structured and unstructured information related to threats.

[0061] Use natural language processing technology to perform semantic analysis on unstructured threat intelligence, and convert unstructured threat intelligence (such as news reports, forum discussions) into quantifiable feature vectors, that is, structured feature vectors. For example, for an article about a new ransomware, NLP technology can extract keywords such as "ransomware" and "encryption algorithm", and map them to nodes in the knowledge graph.

[0062] Map the extracted feature vectors into the knowledge graph, establish the association relationship between entities, and generate a dynamically updated threat model.

[0063] In order to further improve the prediction ability of the threat model, especially in dealing with large-scale and complex network environments, in this embodiment, the construction of the threat model also includes: performing deep learning optimization on the knowledge graph. The specific steps for performing deep learning optimization on the knowledge graph are as follows:

[0064] Define the knowledge graph as a graph structure G=(V, E), where the node V is a set of nodes, and each node v∈V represents a threat-related entity (such as attackers, vulnerabilities, assets, etc.), and the edge E is a set of edges, and each edge e∈E represents the relationship between entities (such as "attackers use vulnerabilities to attack assets").

[0065] Use a graph neural network to perform embedding learning on the graph structure, map each node v∈V to a low-dimensional vector space, and perform node embedding by aggregating neighbor node information and transforming its own features.

[0066] Use a graph convolutional network or a graph attention network to perform end-to-end training on the graph structure, and optimize the objective function of the threat prediction task.

[0067] Specifically, the node embedding by aggregating neighbor node information and transforming its own features specifically includes:

[0068] Calculate the set of neighbor nodes N(v) of node v, that is, the set of all nodes directly connected to node v;

[0069] Generate node embeddings using an aggregation function and a transformation function. The formula for node embeddings is:

[0070] Zv = Aggregate({Zu|u ∈ N(v)}) + Ttansform(xv)

[0071] where Zv is the embedding vector of node v, which is its low-dimensional feature representation. For example, for an attacker node, its embedding vector may contain features such as attack frequency and attack type; Zu is the embedding vector of neighbor node u; xv is the initial feature vector of node v, usually extracted from raw data (such as threat intelligence or logs); Aggregate() is an aggregation function used to summarize the information of neighbor nodes. Common aggregation functions include mean aggregation, max aggregation, or attention mechanism; Ttansform() is a transformation function used to process the features of the node itself. Usually a linear transformation or a non-linear activation function (such as ReLU). Feasibly, an available mean aggregation function is An available linear transformation function is Ttansform(xv) = T·xv + b, where T is the weight matrix and b is the bias term.

[0072] Furthermore, in order to accurately predict newly emerging threat data, the objective function is achieved by maximizing the conditional probability between the class label and the node embedding. The specific formula of the objective function is:

[0073] L = -∑ ( v,c ∈D) logP(c|Zv)

[0074] where D is the training dataset, which contains nodes and their corresponding class labels; c is the class label of the node, such as "malicious attack" or "normal traffic"; P(c|Zv) is the conditional probability of class c given the node embedding Zv. It represents the likelihood that node v belongs to class c.

[0075] Based on the above, the knowledge graph represents threat-related entities and their relationships in the form of nodes and edges, and can effectively capture the correlations between complex threats. For example, the relationship that an attacker uses a certain vulnerability to attack a specific asset can be represented by an edge ("attacker", "vulnerability", "asset") ("attacker", "vulnerability", "asset"). The core idea of the graph neural network is to capture the topological information and feature information in the graph structure through node embedding learning. By aggregating the information of neighboring nodes, the model can understand the dependencies between nodes, thereby generating more accurate node representations. Using a graph convolutional network (GCN) or a graph attention network (GAT) for end-to-end training can directly optimize the objective function of the threat prediction task. Compared with traditional methods, this method does not require manual feature design and has stronger generalization ability and prediction accuracy. The trained graph neural network model can complete the classification and risk assessment of new threat data within milliseconds, significantly improving the real-time response ability.

[0076] As a preferred implementation manner of this embodiment, the prioritization of the generated plans specifically includes: calculating a risk assessment value through a non-linear normalization and dynamic adjustment mechanism according to the threat level, resource requirements, and execution cost. The higher the risk assessment value, the higher the priority of the corresponding plan. For the risk assessment value, it is the core indicator used to calculate the priority of the plan. The risk assessment value comprehensively considers multiple factors such as the threat level, resource requirements, execution cost, and dynamic risk factors, and is calculated through a non-linear normalization and dynamic adjustment mechanism. The size of the risk assessment value directly determines the priority ranking of the plans, and the specific relationship is as follows:

[0077]

[0078] Among them, F is the threat level, which is processed by non-linear normalization to highlight the impact of high-threat events. After non-linear normalization, the impact of high-threat events is significantly amplified. For example, when a certain plan involves a serious APT attack, its threat level is relatively high, resulting in a significant increase in the risk assessment value, thereby enhancing the priority of the plan. R is the resource requirement, indicating the total amount of resources required to complete the plan; C is the execution cost, including time cost and economic cost. The resource requirement and execution cost are adjusted through the function f(C). If a certain plan requires a large amount of resources and high costs, its weight value WW will be relatively reduced, and the priority will also decrease. D is the dynamic risk factor, reflecting the risk change trend of the current network environment. If the real-time monitoring module detects potential security risks (such as the exploitation of new vulnerabilities), the value of the dynamic risk factor will increase, thereby enhancing the risk assessment value and priority of the relevant plan. α, β, and γ are weight coefficients used to balance the importance of different factors, corresponding to the importance of the threat level, resource requirement, and dynamic risk factor respectively, and satisfying α + β + γ = 1. For example, in some scenarios, the threat level may be more important than the resource requirement, so a larger α value can be set to highlight the impact of the threat level.

[0079] The magnitude of the risk assessment value reflects the importance and urgency of the plan, directly affecting the priority ranking of the plan. Specifically:

[0080] The higher the risk assessment value, the more serious the threat, more reasonable the resource requirement, or higher the dynamic risk corresponding to the plan, and thus the higher the priority.

[0081] The lower the risk assessment value, the less serious the threat, higher the resource requirement, or lower the dynamic risk corresponding to the plan, and thus the lower the priority.

[0082] For example, among multiple candidate plans, the system will sort the plans according to the risk assessment value and select the plan with the highest risk assessment value as the optimal plan for priority execution, so as to ensure that high-threat events are responded to in a timely manner, while taking into account the resource allocation efficiency and execution cost control.

[0083] In order to quickly identify potential security risks and reduce the possibility of threat diffusion, in this embodiment, the real-time monitoring of the network status during the execution of the plan specifically includes:

[0084] Continuously collect network status data, including traffic information, log records, and performance metrics. For example, it is detected that the inbound traffic of a certain server suddenly surges to 10 times the usual level; or the CPU utilization rate exceeds 80%, triggering a high-priority alarm;

[0085] Perform anomaly detection on the collected data to identify potential security risks;

[0086] Compare the detection results with predefined thresholds to trigger corresponding warning mechanisms.

[0087] In order to continuously optimize the response strategy during operation, in this embodiment, the dynamic adjustment of the pre - plan parameters is achieved through the Bayesian update principle. By combining real - time monitoring results and historical data, new parameter values are calculated. The specific principle is as follows: First, calculate the deviation between the actual observed value and the predicted value, and then adjust the parameter value using the learning rate. In network security emergency response, the dynamic adjustment of pre - plan parameters is a key link to ensure that the system can adapt to the constantly changing threat environment. Traditional static parameter configuration methods are difficult to cope with real - time changing network states and threat characteristics. Therefore, this method introduces the Bayesian update principle. By combining real - time monitoring results and historical data, the pre - plan parameters are dynamically adjusted to improve the system's adaptability and response accuracy. It is known that Bayesian update is a classic probability - statistical method used to update existing knowledge based on new observed data. Any Bayesian update principle in the prior art can be selected to implement this embodiment.

[0088] In summary, the pre - plan generation and execution method for network security emergency response in this embodiment, by constructing a threat model based on a knowledge graph and a graph neural network, combines a multi - objective optimization algorithm to generate an intelligent pre - plan, significantly improving the speed, accuracy, and reliability of network security emergency response. Specifically, it enhances the threat perception ability, achieving comprehensive capture and accurate prediction of complex threats; optimizes the pre - plan generation and dynamic adjustment mechanism to ensure the scientificity and adaptability of the response strategy; at the same time, the closed - loop feedback mechanism supports continuous optimization, further strengthening the system's intelligence level and long - term operation effect. The overall solution effectively solves the deficiencies of traditional methods in threat recognition, resource scheduling, and security, providing an innovative solution for modern network security protection.

[0089] In the second aspect, this embodiment provides a pre - plan generation and execution system for network security emergency response, applying the pre - plan generation and execution method for network security emergency response as described above, including:

[0090] A data collection module, configured to: obtain network security threat data and perform pre - processing;

[0091] A model construction module, configured to: extract key features from the pre - processed data and construct a threat model;

[0092] A pre - plan generation module, configured to: generate at least one emergency response pre - plan based on the threat model through a preset algorithm;

[0093] A pre - plan selection module, configured to: sort the generated pre - plans according to priority and select the optimal pre - plan for execution;

[0094] An execution supervision module, configured to: monitor the network status in real time during the execution of the plan, and dynamically adjust the plan parameters according to the feedback results, where the plan parameters are used to adjust the results during the plan process.

[0095] It should be noted that in this embodiment, this system corresponds to the foregoing method for generating and executing a plan for network security emergency response. Therefore, for parts not described in detail in this system (not limited to specific technical means and technical effects), reference can be made to the specific descriptions in the foregoing method for generating and executing a plan for network security emergency response, and details are not repeated herein.

[0096] Finally, it should be noted that the above are only preferred embodiments of the present application and are not used to limit the present application. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for generating and executing a plan for network security emergency response, characterized in that: The method comprises the following steps: Obtain and pre-process network security threat data, extract key features and build threat models; Based on the threat model, generating at least one emergency response plan through a preset algorithm; Sort the generated plans by priority and select the best plan for execution; During the execution of the plan, the network status is monitored in real time, and the plan parameters are dynamically adjusted according to the feedback results. The plan parameters are used to adjust the results during the plan process.

2. The method for generating and executing a plan for network security emergency response according to claim 1, characterized in that: The threat model is constructed by using semantic analysis technology based on knowledge graph, and a multi-level and multi-dimensional threat knowledge base is formed by integrating ontological knowledge and real-time threat intelligence data in the field of network security.

3. The method for generating and executing a plan for network security emergency response according to claim 2, characterized in that: The construction of the threat model specifically includes the following steps: Construct an ontology knowledge framework in the field of network security and define key entities and their relationships, wherein the key entities include threat types, attack paths, and affected assets; Collect and parse real-time threat intelligence data to extract structured and unstructured information related to threats; Use natural language processing technology to perform semantic analysis on unstructured threat intelligence and convert it into quantifiable feature vectors; The extracted feature vectors are mapped to the knowledge graph, the association relationship between entities is established, and a dynamically updated threat model is generated.

4. The method for generating and executing a plan for network security emergency response according to claim 3, characterized in that: The construction of the threat model further includes: performing deep learning optimization on the knowledge graph; the deep learning optimization on the knowledge graph specifically includes: The knowledge graph is defined as a graph structure G = (V, E), where node V is a node set and edge E is an edge set; Use graph neural networks to embed graph structures, map each node v∈V to a low-dimensional vector space, and embed nodes by aggregating neighbor node information and transforming their own features; The graph structure is trained end-to-end using graph convolutional networks or graph attention networks to optimize the objective function of the threat prediction task.

5. The method for generating and executing a plan for network security emergency response according to claim 4, characterized in that: The node embedding by aggregating neighbor node information and transforming own features specifically includes: Calculate the neighbor node set N(v) of node v; Node embedding is generated using aggregation functions and transformation functions. The formula for node embedding is: Zv=Aggregate({Zu|u∈N(v)})+Ttansform(xv) Among them, Zv is the embedding vector of node v, xv is the initial feature vector of node v, Aggregate() is the aggregation function, and Ttansform() is the transformation function.

6. The method for generating and executing a plan for network security emergency response according to claim 5, characterized in that: The objective function is achieved by maximizing the conditional probability between the category label and the node embedding. The formula of the objective function is as follows: L=-∑ ( in,c ∈D) logP(c|Zv) Where D is the training dataset, c is the category label of the node, and P(c|Zv) is the conditional probability of category c given the node embedding Zv.

7. The method for generating and executing a plan for network security emergency response according to claim 1, characterized in that: The generated plans are sorted by priority, specifically including: calculating the risk assessment value through nonlinear normalization and dynamic adjustment mechanism according to the threat level, resource requirements and execution cost, when the risk assessment value is higher, the priority of the plan is higher.

8. The method for generating and executing a plan for network security emergency response according to claim 1, characterized in that: The real-time monitoring of the network status during the execution of the plan specifically includes: Continuously collect network status data, including traffic information, log records, and performance indicators; Perform anomaly detection on collected data to identify potential security risks; Compare the detection results with the predefined thresholds and trigger the corresponding early warning mechanism.

9. The method for generating and executing a plan for network security emergency response according to claim 1, characterized in that: The dynamic adjustment of the plan parameters is achieved through the Bayesian updating principle.

10. A system for generating and executing a plan for network security emergency response, using the method for generating and executing a plan for network security emergency response as described in any one of claims 1 to 9, characterized in that: include: The data acquisition module is configured to: obtain network security threat data and perform pre-processing; The model building module is configured to: extract key features from the preprocessed data and build a threat model; A plan generation module is configured to: generate at least one emergency response plan based on the threat model through a preset algorithm; The plan selection module is configured to: sort the generated plans according to priority and select the best plan for execution; The execution supervision module is configured to: monitor the network status in real time during the execution of the plan, and dynamically adjust the plan parameters according to the feedback results, and the plan parameters are used to adjust the results during the plan process.

Citation Information

Cited By

  • Emergency response intelligent decision and data security guarantee system based on AI

    CN120579790A

  • Systems and methods for automatic security rule generation

    US20260122108A1