Network security management method and system

By performing digital antibody analysis and environmental isolation simulation on network behavior data and host behavior data, a network security attack behavior map is built, and combined with historical data to generate immune strategies, the problems of slow response and defense blind spots in the face of rapidly evolving network attacks in the existing technology are solved, and efficient and flexible network security defense is achieved.

CN120200838AActive Publication Date: 2025-06-24NETWORK SECURITY SERVICE MANAGEMENT CONSULTING SERVICE (YUNNAN) CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510566983.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-06-24
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

Existing cybersecurity management methods have limitations of slow response and defense blind spots in the face of rapidly evolving cyber attacks and advanced persistent threats.

Method used

By performing digital antibody analysis on the network behavior data and host behavior data of the target network, suspicious behavior data packets are obtained; then the data packets are environmentally isolated and simulated to extract dynamic behavior tags; based on these data and tags, a network security attack behavior map is constructed; finally, the historical network antibody performance data is deeply fusion and analysis is carried out to generate current network security immunity strategy information.

Benefits of technology

It realizes early identification and precise defense of potential threats, eliminates the limitations of slow response and defense blind spots, and improves the network system's perception ability, defense flexibility and overall security protection level for unknown attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200838A_ABST
    Figure CN120200838A_ABST
Patent Text Reader

Abstract

The invention relates to a network security management method and system. The method comprises the following steps: performing digital antibody analysis on network behavior data and host behavior data of a target network to obtain a suspicious behavior data packet; performing environment isolation simulation on the suspicious behavior data packet to obtain a dynamic behavior tag set; analyzing an infection defense mechanism of the network attack according to the suspicious behavior data packet and the dynamic behavior label set to obtain a network security attack behavior map; and inputting the historical network antibody expression data into the network security attack behavior map to obtain current network security immune strategy information. By adopting the method, the limitations of slow response and defense blind areas can be effectively eliminated in the face of quickly evolved network attacks and advanced persistent threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a network security management method and system. Background Art

[0002] In traditional technologies, network security management methods mainly rely on means such as firewalls, intrusion detection systems (IDS), antivirus software, and access control to achieve basic protection by protecting the network boundary, monitoring data flows, and identifying known threats. These methods focus on preventing known attacks and post-event responses, usually using static rules and signature libraries for threat identification, which are applicable to relatively closed and controllable IT environments. However, when facing rapidly evolving network attacks and advanced persistent threats (APT), they have limitations of slow response and defense blind spots. Summary of the Invention

[0003] Based on this, it is necessary to provide a network security management method and system that can effectively eliminate the limitations of slow response and defense blind spots when facing rapidly evolving network attacks and advanced persistent threats for the above technical problems.

[0004] In a first aspect, this application provides a network security management method, including:

[0005] Performing digital antibody analysis on the network behavior data and host behavior data of a target network to obtain suspicious behavior data packets;

[0006] Performing environment isolation simulation on the suspicious behavior data packets to obtain a dynamic behavior label set;

[0007] Analyzing the infection defense mechanism of network attacks based on the suspicious behavior data packets and the dynamic behavior label set to obtain a network security attack behavior map;

[0008] Inputting historical network antibody performance data into the network security attack behavior map to obtain current network security immunity policy information.

[0009] In a second aspect, this application also provides a network security management device, and the system includes a terminal and a computer;

[0010] The computer is used to perform digital antibody analysis on the network behavior data and host behavior data of a target network to obtain suspicious behavior data packets; the network behavior data and the host behavior data are obtained through the terminal;

[0011] The computer is used to perform environment isolation simulation on the suspicious behavior data packets to obtain a dynamic behavior label set;

[0012] The computer is configured to analyze the infection prevention mechanism of network attacks based on the suspicious behavior data packet and the dynamic behavior tag set, and obtain a network security attack behavior map;

[0013] The computer is configured to input historical network antibody performance data into the network security attack behavior map to obtain current network security immunity policy information, where the historical network antibody performance data is obtained through the terminal.

[0014] The above network security management method and system, by integrating network behavior data and host behavior data, and adopting digital antibody analysis technology, can comprehensively identify potential suspicious behavior data packets and improve the accuracy of initial detection; further, by performing environmental isolation simulation on the suspicious data packets and extracting their dynamic behavior tags in a controlled environment, it can effectively capture deep - level attack features that are difficult to discover by traditional static analysis; based on the suspicious data and their dynamic behavior tags, a network security attack behavior map is constructed, which can clearly present the attack path, infection method, and potential threat chain, facilitating a comprehensive understanding of the attack logic and behavior intention; then, through in - depth fusion analysis of historical network antibody performance data and the behavior map, it realizes the accurate generation and dynamic optimization of the immunity policy in the current network environment, can effectively eliminate the limitations of slow response and defense blind spots when facing rapidly evolving network attacks and advanced persistent threats, and improve the network system's perception ability, defense flexibility, and overall security protection level for unknown attacks, thus realizing an adaptive and self - evolving network security defense system. Brief Description of the Drawings

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0016] Figure 1 It is an application environment diagram of the network security management method in an embodiment;

[0017] Figure 2 It is a flowchart of the network security management method in an embodiment;

[0018] Figure 3 It is a flowchart of the method for obtaining suspicious behavior data packets in an embodiment;

[0019] Figure 4 It is a flowchart of the method for obtaining behavior difference analysis data in an embodiment;

[0020] Figure 5Schematic flowchart of a method for obtaining behavioral difference analysis data in another embodiment;

[0021] Figure 6 Schematic flowchart of a method for obtaining path matching analysis data in one embodiment;

[0022] Figure 7 Schematic flowchart of a method for obtaining a network security attack behavior map in one embodiment;

[0023] Figure 8 Schematic flowchart of a method for constructing a phased propagation chain of defense behaviors in one embodiment;

[0024] Figure 9 Schematic flowchart of a method for obtaining current network security immunity policy information in one embodiment;

[0025] Figure 10 Internal structure diagram of a computer device in one embodiment. Detailed implementation manners

[0026] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.

[0027] A network security management method provided by an embodiment of the present application can be applied to an application environment as shown in Figure 1 . Among them, the terminal 102 communicates with the server 104 through a network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed in the cloud or other network servers. Among them, the server 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0028] In an exemplary embodiment, as shown in Figure 2 , a network security management method is provided. Taking the method applied to the server in Figure 1 as an example, the method includes the following steps 202 to step 206.

[0029] Among them:

[0030] Step 202: Perform digital antibody analysis on the network behavior data and host behavior data of the target network to obtain suspicious behavior data packets.

[0031] Among them, the target network can be a computer network system that needs to be monitored, analyzed and protected, and usually includes an enterprise internal network, a cloud computing platform, a data center or critical infrastructure, etc.

[0032] Among them, network behavior data can be the data flow information generated by various devices in the network during the communication process, covering contents such as IP address, port number, protocol type, connection duration, data packet size, access frequency, etc.

[0033] Among them, host behavior data can be the operating status information of a single computing node or device at the operating system level, including process startup and termination, system calls, file reading and writing, registry access, memory changes, user login behavior, etc.

[0034] Among them, digital antibody analysis can be a network security technology that simulates the antibody recognition mechanism in the biological immune system, and compares and identifies data behaviors that deviate from the normal state in the network by building a "normal behavior model" (antibody). This method combines pattern recognition and anomaly detection algorithms to achieve rapid classification and risk assessment of network and host behaviors, and identify potential threat targets.

[0035] Suspicious behavior data packets can be data packets that are identified as possibly carrying malicious behavior characteristics during the digital antibody analysis process. Although such data packets have not been fully confirmed to contain attack behaviors, their behavior patterns are significantly different from normal communications and require further analysis and verification.

[0036] Specifically, by deploying monitoring probes at the network boundary and inside the host, multi-source heterogeneous data including network traffic, port access, protocol type, connection frequency, process behavior, system calls, file operations, memory reading and writing, etc. are continuously collected; using a digital antibody model built based on the principle of artificial immunity, the collected network behavior data and host behavior data are feature extracted and encoded, and pattern matched and similarity calculated with the normal behavior model; then, through anomaly detection algorithms (such as density-based outlier detection, cluster analysis or machine learning classifiers), abnormal behaviors that deviate significantly from the normal model are identified; these abnormal behaviors are further screened as suspicious behavior data packets, and each suspicious behavior data packet is preliminarily labeled as input for subsequent simulation analysis and behavior modeling.

[0037] Step 204: Perform environmental isolation simulation on suspicious behavior data packets to obtain a dynamic behavior label set.

[0038] Among them, environmental isolation simulation can be a security technology that performs execution tests on suspicious data packets in a virtual or controlled environment, often with the help of a sandbox, virtual machine or simulation system.

[0039] Among them, the dynamic behavior tag set can be a set of tags formed by classifying and identifying the key behaviors generated when the system runs on suspicious data packets in an environment isolation simulation. These tags may include "download remote file", "modify registry", "attempt privilege escalation", "establish reverse connection", etc., and are used to describe and identify the intent and path of attack behaviors.

[0040] Specifically, input the suspicious behavior data packets identified in the first stage into a highly isolated and controllable simulation environment for environment isolation simulation, such as a sandbox system or a virtual machine cluster, to avoid any impact on the real production network; execute the instructions or behavior trigger logic contained in the suspicious behavior data packets in the environment isolation simulation, and comprehensively monitor and record various behavior characteristics generated during its operation, including dynamic behaviors such as network connection attempts, system file modifications, registry changes, malicious process creation, memory injection, command and control interactions, etc.; parse these operation trajectories through a behavior analysis module, extract the key behavior patterns with attack characteristics, and after modeling by combining time series, behavior context, and behavior chain, organize the identified behavior characteristics into a set of dynamically behavior tag sets with clear semantics and quantifiable metrics.

[0041] Step 206, analyze the infection prevention and defense mechanism of the network attack based on the suspicious behavior data packets and the dynamic behavior tag set, and obtain a network security attack behavior map.

[0042] Among them, the infection prevention and defense mechanism can be a set of protection strategies established by the network system to cope with the penetration and spread of attackers, including measures such as intrusion detection, access control, behavior blocking, system hardening, isolation response, etc. By analyzing the attack path, the protection effect of the existing mechanism can be evaluated, defense blind spots can be found, and the defense strategy can be optimized.

[0043] Among them, the network security attack behavior map can be a graph structure model used to comprehensively present the action trajectory and attack strategy of the attacker in the network. It abstracts the attack behavior into nodes in the graph, and the dependency relationship between nodes constitutes the edge. By visualizing, it reveals the attack path, stage evolution, and behavior linkage, which is convenient for analysis and protection strategy formulation.

[0044] Specifically, the suspicious behavior data packets and the dynamic behavior tag sets are fused to form composite attack behavior units with temporality and context relevance. The attack chain modeling technology is used to identify the logical relationships and causal paths among the various behavior units in the composite attack behavior units, and analyze their roles in the network intrusion process, such as initial penetration, privilege escalation, lateral movement, information theft, etc. Then, the graph construction algorithm is used to abstract each behavior unit in the composite attack behavior units into nodes, and the dependency relationships between behaviors are abstracted into edges in the graph to form a complete attack behavior path graph. Further, the key infection nodes and propagation paths are marked in the graph to identify potential defense weak links and attack propagation bottlenecks, and a network security attack behavior map is generated. This network security attack behavior map depicts the penetration process, attack strategies, and behavior patterns of the attacker in the target system.

[0045] Step 208: Input the historical network antibody performance data into the network security attack behavior map to obtain the current network security immunization strategy information.

[0046] Among them, the historical network antibody performance data can be the recorded data of the identification, protection, and response to various security threats in the past, including the identified attack types, triggered security policies, execution effects, and disposal results.

[0047] Among them, the current network security immunization strategy information can be a protection plan for the current threat environment automatically generated based on the latest attack map and historical antibody data. It includes emergency response measures, defense configuration suggestions, access control policies, monitoring priorities, etc., to guide the network system to achieve dynamic and intelligent security defense and continuous immunization.

[0048] Specifically, extract the historical network antibody performance data that is similar to the nodes or paths in the existing attack behavior map from the historical security event library, including past attack detection records, defense policies, response measures, and their effectiveness evaluations. Through the behavior feature matching and correlation analysis algorithm, align the historical network antibody performance data with the key attack behavior nodes in the network security attack behavior map to identify which historical policies were effective or ineffective for similar attack behaviors. Use knowledge transfer and strategy optimization technology, combined with the configuration, resource status, and risk preferences of the current network environment, to adapt and optimize the recommended historical immunization mechanisms that may be applicable, and generate the current network security immunization strategy information, including real-time response measures, preventive control suggestions, key asset reinforcement plans, etc.

[0049] In the above network security management method, by integrating network behavior data and host behavior data and adopting digital antibody analysis technology, potential suspicious behavior data packets can be comprehensively identified, improving the accuracy of initial detection; further, by performing environmental isolation simulation on the suspicious data packets and extracting their dynamic behavior tags in a controlled environment, deep attack characteristics that are difficult to discover by traditional static analysis can be effectively captured; based on the suspicious data and their dynamic behavior tags, a network security attack behavior map is constructed, which can clearly present the attack path, infection method, and potential threat chain, facilitating a comprehensive understanding of the attack logic and behavior intention; then, by deeply integrating and analyzing historical network antibody performance data and the behavior map, accurate generation and dynamic optimization of immune strategies in the current network environment can be achieved, effectively eliminating the limitations of slow response and defense blind spots when facing rapidly evolving network attacks and advanced persistent threats, improving the network system's perception ability, defense flexibility, and overall security protection level for unknown attacks, thereby realizing an adaptive and self-evolving network security defense system.

[0050] In an exemplary embodiment, as Figure 3 shown, digital antibody analysis is performed on the network behavior data and host behavior data of the target network to obtain suspicious behavior data packets, including steps 302 to 306. Among them:

[0051] Step 302, perform behavior feature extraction on the network behavior data and host behavior data to obtain a set of behavior feature information.

[0052] Among them, behavior feature extraction can be a process of identifying and refining key feature information from network behavior data and host behavior data for subsequent analysis.

[0053] Among them, the set of behavior feature information can be a structured data set output by the behavior feature extraction module, covering behavior features in multiple dimensions from the network side and the host side, such as the number of connections, resource access paths, process call chains, etc.

[0054] Specifically, use feature extraction algorithms to perform abstract modeling on network behavior data and host behavior data in different dimensions, such as extracting feature indicators such as connection frequency, call path, behavior sequence pattern, and behavior duration, and perform structured processing using coding (such as One-hot, TF-IDF) or numerical normalization methods; integrate all abstracted behavior features to form a unified set of behavior feature information as the set of behavior feature information.

[0055] Step 304, perform behavior deviation analysis on each behavior feature information in the set of behavior feature information to obtain behavior difference analysis data.

[0056] Among them, the behavior deviation analysis can be to jointly analyze the current behavior characteristics with a preset normal behavior baseline model to analyze whether the behavior deviates or is abnormal. This analysis uses methods such as similarity calculation, clustering analysis, and statistical modeling to quantitatively evaluate the fluctuation range of features, the differences in behavior sequences, and the temporal correlation, so as to determine which behaviors have obvious deviations and may indicate the occurrence of abnormal or malicious operations.

[0057] Among them, the behavior difference analysis data can be the output result of the behavior deviation analysis, recording the behavior items with significant differences compared with the normal behavior model and their specific deviation characteristics, including information such as behavior type, deviation amplitude, associated entities (such as IP, process name), and timestamp.

[0058] Specifically, each behavior characteristic information in the behavior characteristic information set is jointly analyzed with the system's preset normal behavior baseline model. This baseline model is trained based on a large amount of historical normal data and represents the behavior patterns of the target network and host under normal operation; during the analysis process, a behavior analysis algorithm is used to analyze the deviation degree of each behavior characteristic. Common methods include Euclidean distance calculation, Mahalanobis distance analysis, cosine similarity measurement, and time series alignment, etc., to quantify the difference between the current behavior and the baseline. For features with significant deviation degrees, in-depth analysis is performed, combined with behavior context, historical patterns, and multi-dimensional behavior cross-validation, to analyze the possible abnormal behavior trends, and the analysis results are organized into behavior difference analysis data, recording the characteristic category, deviation degree, behavior path, and occurrence time of each deviated behavior.

[0059] Step 306, according to each preset malicious feature rule, perform suspicious behavior analysis on the behavior difference analysis data to obtain a suspicious behavior data packet.

[0060] Among them, the preset malicious feature rules can be a rule library constructed based on existing network attack knowledge, used to identify common malicious behavior patterns. These rules describe the characteristic combinations, behavior sequences, or triggering conditions of specific attack behaviors, such as frequent port scanning, abnormal packet structures, permission abnormal operations, etc., and usually exist in the form of feature patterns, logical expressions, or decision trees, used to identify potential threats in the behavior difference data.

[0061] Among them, the suspicious behavior analysis can be a process of in-depth analysis and determination of behaviors that may have attack tendencies based on the combination of behavior difference analysis data and preset malicious feature rules.

[0062] Specifically, the behavior difference analysis data is input into the malicious feature rule matching engine, which has multiple preset malicious feature rules, covering typical attack features such as port scanning, abnormal traffic surge, malicious instruction execution, C2 communication behavior, privilege escalation, lateral movement, etc.; then the behavior difference data is compared with each preset malicious feature rule one by one to determine whether it meets the combination conditions or trigger thresholds of the attack features. For example, multiple failed login attempts and suspicious source addresses may trigger the "brute force cracking" rule. Further risk analysis and confidence assessment are performed on the comparison results, combined with contextual semantics and historical behaviors, to further eliminate false positives and strengthen the threat judgment of associated behaviors; data fragments identified as having obvious attack intentions or high-risk potential are extracted and encapsulated into suspicious behavior data packets, including source address, target end, trigger rule number, timestamp and related behavior path.

[0063] In this embodiment, multi-dimensional behavioral features are extracted from network behavior data and host behavior data to construct a comprehensive and detailed behavioral feature information set. On this basis, a behavioral deviation analysis mechanism is introduced to accurately identify abnormal behaviors that differ from normal behavior patterns. Further, combined with a preset malicious feature rule library, semantic analysis and pattern matching are performed on the behavioral difference data to quickly screen out suspicious behavior data packets with potential attack characteristics, thereby greatly improving the accuracy and real-time performance of network threat detection, reducing false alarms and missed alarms, and enhancing the system's perception and pre-warning capabilities of unknown attacks, thereby realizing an efficient and intelligent security protection front-end identification mechanism.

[0064] In an exemplary embodiment, Figure 4 As shown, a behavior deviation analysis is performed on each behavior feature information in the behavior feature information set to obtain behavior difference analysis data, including steps 402 to 406.

[0065] in:

[0066] Step 402, constructing a graph according to the behavior evolution state and behavior evolution path in each behavior feature information to obtain a behavior conformation chain graph.

[0067] The behavior evolution state can be the specific behavior state of an entity (such as a host, user, or process) at a specific time point or stage, which reflects the stage position and context characteristics of the behavior in the entire behavior chain. For example, the startup of a process, the execution of a system call, or the establishment of a network connection can all be considered an evolution state.

[0068] Among them, the behavior evolution path can be a continuous behavior chain formed by multiple behavior evolution states according to the chronological order and causal logic, which describes the behavior trajectory and state transition process of a certain actor within a specific time period. The path not only shows the sequential relationship between behaviors, but also reveals the dependency relationship or potential attack chain in the behavior development process.

[0069] Among them, the behavior conformation chain diagram can be a graph structure model constructed based on the behavior evolution state and path. Usually in the form of a directed graph or state transition graph, the behavior states are used as nodes in the graph, and the evolution paths between states are connected as directed edges, forming a chain structure diagram describing the dynamic evolution process of behaviors.

[0070] Specifically, extract the key timestamp, behavior type, object of action, and behavior context of each behavior from the various behavior feature information, and determine its position and logical relationship in the overall behavior process; abstract each specific behavior instance into a "behavior evolution state" based on the above-extracted information, and identify the sequential, dependent, or triggering relationship between it and other behaviors to form a "behavior evolution path". Adopt graph modeling methods, such as constructing a directed graph or a time-sequence state graph, connect all behavior states as nodes in the graph and behavior paths as directed edges to form a chain graph structure that can reflect the sequential order and causal relationship of behavior flow; during the graph construction process, additional context information (such as host ID, port number, call path, etc.) is also attached to the nodes to enhance the expression ability of the graph, generating the behavior conformation chain diagram.

[0071] Step 404, perform conformation path similarity analysis between the behavior conformation chain diagram and the historical conformation evolution diagram of the target network to obtain path matching analysis data.

[0072] Among them, the conformation path similarity analysis can be a process of analyzing the similarity degree of the path structure between the current behavior conformation chain diagram and the historical conformation evolution diagram to analyze whether the behavior deviates from the normal mode or approaches the known attack path.

[0073] Among them, the path matching analysis data can be the output result of the conformation path similarity analysis, which is used to record the matching degree, similar path segments, unmatched nodes, path offset points, and matching confidence between the current behavior path and the historical conformation diagram, etc.

[0074] Specifically, call the conformational evolution graph database of the target network during historical operation from the behavior analysis system. This database contains the historical conformational evolution graphs of behavior paths in normal states and known attack scenarios. Use the currently constructed behavior conformational chain graph as the object to be analyzed, and analyze it one by one in combination with the historical conformational evolution graphs. During the analysis process, adopt graph path similarity algorithms, such as graph edit distance calculation, path sequence alignment (such as the longest common sub-path), dynamic time warping (DTW), etc., to conduct comprehensive similarity analysis on the node order, edge connection relationship, path length, and behavior characteristics in the graph. Analyze the similarity properties of the parts with highly overlapping paths, abnormal path offsets, path breaks, or newly generated paths in the analysis results, and assign a path similarity score and a matching confidence level to each comparison result. Finally, output the path matching analysis data, recording information such as the similarity degree, difference position, and key offset nodes between the current behavior and each historical behavior path.

[0075] Step 406: Conduct antibody matching analysis on the path matching analysis data to obtain behavior difference analysis data.

[0076] Among them, the antibody matching analysis can be to analyze by combining the path matching analysis data with the digital antibody model, and analyze the process covered by the current behavior path and the existing antibody templates.

[0077] Specifically, use the path matching analysis data as the input and input it into the constructed digital antibody matching model. This model pre-stores a "antibody library" of normal behaviors constructed based on the artificial immune mechanism, where each antibody represents a recognized safe behavior pattern or historical immune path by the system. The digital antibody matching model analyzes the key path nodes, path offset positions, and unmatched segments in the current path matching data one by one with various antibody templates in the antibody library. During the analysis process, methods such as similarity calculation, feature vector alignment, and behavior weight evaluation are usually used to analyze the differences between this behavior path and normal immune behaviors. For path segments that fail to effectively match antibody templates or have structural differences with multiple antibodies, further deviation quantification analysis is carried out to mark their risk levels and deviation attributes (such as newly generated behaviors, mutant behaviors, attack tendency behaviors, etc.), generating behavior difference analysis data, and detailedly recording abnormal path segments, antibody unmatched parts, evolution deviation trends, and their context characteristics.

[0078] In this embodiment, by constructing a graph of the behavior evolution state and evolution path in the behavior feature information to generate a structured behavior conformation chain diagram, the evolution process of individual behaviors in terms of time sequence and logic can be clearly restored; subsequently, through path similarity analysis with the historical conformation evolution diagram of the target network, the matching degree between the current behavior and existing normal or abnormal behavior patterns is identified, realizing the deep structure recognition of behavior deviation; further introducing an antibody matching mechanism, and combining with the historical immune model to conduct a comparative analysis of the path matching results, accurately judging whether the behavior has potential threats, and finally outputting behavior difference analysis data, thereby improving the accuracy and intelligent level of abnormal behavior recognition, and effectively enhancing the adaptability and immune response ability of the network security system to variant attacks and unknown threats.

[0079] In an exemplary embodiment, as Figure 5 shown, antibody matching analysis is performed on the path matching analysis data to obtain behavior difference analysis data, including steps 502 to 506. Among them:

[0080] Step 502, construct a set of mimic antibody response paths according to the historical conformation evolution diagram.

[0081] Among them, the set of mimic antibody response paths can be a set of behavior immune model paths constructed based on the historical conformation evolution diagram, simulating the response mechanism of the digital immune system when facing external behavior stimuli. Each path represents the effective response process of the system when facing a certain type of induced behavior in the past, including triggering conditions, state transition nodes, coping strategies, and other contents.

[0082] Specifically, a large number of behavior paths representing the normal operation and successful defense records of the system are extracted from the historical conformation evolution diagram database. These paths cover the whole process from the initial state of the behavior to the completion of the immune response, including key nodes, triggering events, and the system feedback mechanism. The extracted behavior paths are normalized, and the paths with similar defense effects under different attack scenarios are classified in terms of structure, feature abstracted, and labeled to form a response path template with pattern representativeness. Combining the "mimic" idea in the artificial immune system, these response paths are constructed into a set, called the response path set, and each path in the set is defined as an "immune unit" that can be activated by a specific behavior inducement; during the construction process, context information such as applicable environmental conditions, inducement feature range, and path trigger threshold is also attached to each path to enhance its generalization ability and dynamic adaptability, obtaining the set of mimic antibody response paths.

[0083] Step 504, input the path matching analysis data as an inducing factor into the set of mimic antibody response paths to obtain behavior conformation activation data.

[0084] Among them, the inducing factor can be an abnormal behavior segment or deviation feature that can trigger an immune system response extracted from the path matching analysis data, usually including behavior path deviation points, abnormal nodes, unmatched behavior segments, and their context information.

[0085] Among them, the behavior conformation activation data can be the structured information generated after receiving the inducing factor by comparing the trigger conditions and structural features of each path in the mimic antibody response path set and identifying the activated or partially activated antibody paths. It records content such as which antibody paths are successfully activated, the activation degree, the distribution of matching nodes, and the response intensity, and is the core intermediate data for measuring the adaptability and coverage ability of the immune system to the current behavior.

[0086] Specifically, extract the behavior deviation nodes, path breakpoints, similar path segments, and their corresponding behavior feature information identified in the path matching analysis data as the inducing factors that may "stimulate" the immune system for the current system behavior; then perform a matching analysis of these inducing factors with each antibody path in the mimic antibody response path set, compare their coincidence degrees in terms of behavior trigger conditions, state transition structures, context environment parameters, etc., and judge whether the activation conditions are met. For the antibody paths that meet the activation conditions, record their activated states, activation degrees (such as fully activated, partially activated, or critically activated), activation intensity scores, and the positions of matching nodes; organize all the activated or partially activated antibody paths and their response states into structured behavior conformation activation data to reflect the effect of the current behavior on the immune system.

[0087] Step 506, perform a response activation analysis on the behavior conformation activation data to obtain behavior difference analysis data.

[0088] Among them, the response activation analysis can be a process of systematically evaluating the behavior conformation activation data, used to analyze whether the antibody response activated by the current behavior is complete, effective, and reasonable.

[0089] Specifically, comprehensively evaluate the activation status of each antibody response path in the behavior conformation activation data, with a focus on analyzing the activation integrity of each path, the consistency of trigger nodes, the rationality of response timing, and the activation intensity score; then identify and label the cases with abnormal patterns, such as only local activation, significant structural deviation of the activation path from the original path, ineffective triggering of key nodes, or response lag, etc. These phenomena may indicate that the current behavior is not fully covered by the digital antibody system. Conduct a behavior deviation analysis on these abnormal response paths, and further analyze the possibility of unknown mutations, potential attacks, or immune escape of the behavior by combining the characteristics of the inducing factors and the risk level of the unactivated area; structure the above analysis results into behavior difference analysis data, which includes different behavior nodes, deviation types, unmatched path segments, response missing situations, and comprehensive risk scores.

[0090] In this embodiment, by constructing a mimetic antibody response path set based on the historical conformation evolution graph, the defense response knowledge and immune path model of the system in different security scenarios are effectively precipitated; input the path matching analysis data as an inducing factor into this response set, which can simulate the stimulation process of abnormal behaviors on the immune system in a real network environment, accurately activate the defense path matching the current behavior characteristics, and generate behavior conformation activation data; further through response activation analysis, judge the recognition degree and response coverage ability of the immune system to the current abnormal behavior, and finally form behavior difference analysis data, so as to realize the dynamic linkage of behavior recognition and immune mechanism, and significantly improve the system's adaptive recognition ability and defense response efficiency for complex threat behaviors.

[0091] In an exemplary embodiment, as Figure 6 shown, conduct a conformation path similarity analysis between the behavior conformation chain graph and the historical conformation evolution graph of the target network to obtain path matching analysis data, including steps 602 to 606. Among them:

[0092] Step 602, conduct a row state space migration analysis on the behavior conformation chain graph to obtain a behavior path migration graph.

[0093] Among them, the row state space migration analysis can be based on the sequential behavior states extracted from the behavior conformation chain graph. By identifying the evolution relationship between adjacent states, the behavior flow process is modeled as continuous migration activities occurring in the state space. This analysis not only focuses on the order between states, but also considers the trigger conditions, context environment, and behavior feature changes of state transitions, so as to reveal the dynamic change path of the behavior subject within a specific time range.

[0094] Among them, the behavior path migration graph can be a graph structure generated by modeling the behavior state migration process, where each node represents a specific behavior state, each edge represents the migration relationship between two states, and attributes such as transfer direction, transfer conditions, time interval, and behavior labels are attached.

[0095] Specifically, extract all behavior state nodes and their evolutionary connection relationships from the behavior conformation chain graph, identify the system state characteristics represented by each node (such as access behavior, process call, permission change, etc.) and their temporal order and logical dependencies in the behavior sequence; based on these states and their evolutionary paths, construct a state space model, abstract each pair of adjacent behavior states as a "state migration", and record its occurrence conditions, context environment, and changes in behavior characteristics. By integrating all state migration actions in the recorded state space model, a path migration graph is formed, where nodes represent the behavior states of the system at a certain moment, edges represent the conversion relationships between states, and information such as transfer direction, transfer probability, time interval, and behavior labels are attached; during the integration process, different path segments can also be clustered or classified to identify common migration patterns and rare transfer paths, and finally the generated behavior path migration graph.

[0096] Step 604, map the behavior path migration graph in the historical conformation evolution graph to obtain the migration energy overhead value.

[0097] Among them, the migration energy overhead value can be an index that quantifies the structural deviation and matching cost generated when the current behavior path is mapped in the historical conformation evolution graph, reflecting the "energy consumption" of the current behavior during the process of replicating the historical path.

[0098] Specifically, retrieve the historical behavior paths related to the current behavior path from the historical conformation evolution graph, and these historical behavior paths represent the standard state evolution process of the system under normal or known attack scenarios. Match each state migration path in the currently generated behavior path migration graph with the historical behavior paths one by one, and use graph mapping algorithms (such as subgraph matching, path alignment, edit distance calculation) to compare the structural similarity, consistency of node behavior characteristics, and rationality of time order of the migration paths; during the matching process, a "migration energy value" will be calculated for each structural deviation, state inconsistency, or path jump, and this value is used to measure the adjustment or offset intensity required for the current path to be mapped into the historical path. Accumulate or weight all the migration energy values on the entire path to obtain the overall migration energy overhead of the current path relative to the historical graph, and finally output this migration energy overhead value.

[0099] Step 606, analyze the migration energy distribution according to the migration energy overhead value to obtain path matching analysis data.

[0100] Among them, the migration energy distribution can be an energy strength distribution map formed by segmenting and counting multiple migration energy cost values ​​on a complete behavior path, reflecting the degree of fit between the behavior path and the historical template at each stage. This distribution can help identify high-risk sections, high-drift nodes or abnormal jump areas in the behavior path, and then be used to determine whether the entire behavior process is within the normal range or has potential attack characteristics.

[0101] Specifically, the migration energy cost value is normalized and segmented, the entire behavior path is divided into multiple migration segments, and the energy intensity corresponding to each segment is calculated to form a migration energy distribution map. Then, the energy distribution of the migration energy distribution map is statistically analyzed to identify the high-energy area (representing significant deviation or high matching cost), low-energy area (representing high path fit) and energy mutation point (possible abnormal behavior node); the spatial pattern of changes between these energy areas is further analyzed, and the similarity, matching integrity and potential abnormal behavior location between the current behavior path and the normal behavior path are analyzed by combining the path structure with the historical mapping path comparison; at the same time, the energy density can be graded and labeled according to the set threshold, and the behavior paths corresponding to different energy segments can be classified into "normal matching", "partial deviation" or "serious deviation" and other states. The above analysis results are integrated into path matching analysis data, including energy distribution map, similarity score, offset node identification, matching level and confidence score.

[0102] In one embodiment, the calculation formula of the migration energy cost value is:

[0103]

[0104] E struct (v i ,μ i )=1-sim sem (v i ,μ i )

[0105]

[0106] E curve (v i-1 ,v i ,v i+1 )=θ(v i-1 ,v i ,v i+1 ) 2

[0107] Among them, E totav (P c ,P h ) is the migration energy cost value, P c is the current behavior conformation path, Ph is the conformational path for historical reference; E struct (v i , μ i ) is the structural offset energy term, (v i , μ i ) is the i-th node of the current path and the historical path; E jump (v i , v i-1 ) is the jump energy term, (v i , v i-1 ) is the behavioral level transition from v i-1 to v i , E curve (v i-1 , v i , v i+1 ) is the path curvature energy term, (v i-1 , v i , v i+1 ) is the behavioral level transition from v i-1 to v i and from v i to v i+1 , sim sem (v i , μ i ) is the semantic similarity function; ΔT is the behavioral time interval between nodes, δ(v i-1 , v i ) is the behavioral transition amplitude function of the behavioral level transition from v i-1 to v i , θ is the included angle of the node triple, α is the structural offset energy weight factor, β is the jump energy weight factor, and γ is the path curvature energy weight factor.

[0108] In this embodiment, by performing behavioral state space migration analysis on the behavioral conformation chain diagram to construct a behavioral path migration diagram, the dynamic evolution process of behavior in the system state space can be accurately characterized; further, path mapping is performed between this migration diagram and the historical conformation evolution diagram to quantify the difference from the existing normal mode during the behavior evolution process, and the deviation degree is intuitively reflected in the form of a migration energy overhead value; then, by analyzing the distribution of the migration energy, abnormal mutation points and high-offset regions in the behavior path are identified to generate path matching analysis data, thereby realizing the identification of structural differences in complex behavior sequences, improving the sensitivity and accuracy of anomaly detection, and effectively enhancing the system's ability to perceive potential threats in advance and respond dynamically.

[0109] In an exemplary embodiment, as Figure 7As shown in the figure, according to the suspicious behavior data packets and the dynamic behavior tag set, the infection defense mechanism of network attacks is analyzed to obtain a network security attack behavior map, including steps 702 to 708. Among them:

[0110] Step 702, perform an attack infection path analysis on the suspicious behavior data packets to obtain attack infection propagation status data.

[0111] Among them, the attack infection path analysis can be an analysis of the suspicious behavior data packets and their propagation behaviors, combined with the network topology structure, host communication relationships, and timing characteristics, to deduce the possible diffusion paths of attack activities in the network.

[0112] Among them, the attack infection propagation status data can be the result of the attack infection path analysis, used to record the status information during the propagation process of attack behaviors in the network, including the timestamp, propagation direction, attack type, behavior characteristics, and the corresponding target system status of each propagation node.

[0113] Specifically, parse the key information such as the source address, target address, port, protocol type, transmission content, and trigger time contained in the suspicious behavior data packets, and combine the behavior intentions reflected in the dynamic behavior tags (such as remote control, malicious delivery, permission change, etc.) to initially judge whether it has attack propagation characteristics. Load the topology structure of the target network, the host association relationships, and the historical communication patterns, identify the possible propagation paths of the data packets in the network, and track the host nodes, service interfaces, and adjacent communication entities involved. Further, by establishing a propagation model based on time series and host behavior sequences, model and mark the status of each propagation node to form a multi-stage attack diffusion chain that starts from the source point and expands along a specific logical path. Finally, output the attack infection propagation status data, recording the infection time, infection method, propagation direction, and status change information of each node.

[0114] Step 704, according to the dynamic behavior tag set, mark each attack behavior in the attack infection propagation status data to obtain an attack behavior stage propagation chain.

[0115] Among them, an attack behavior can be an operation behavior initiated by an attacker in the network or on a host, with malicious intentions and likely to cause harm to the system. Typical examples include remote login attempts, privilege escalation command executions, malicious script injections, data leaks, etc.

[0116] Among them, the attack behavior stage propagation chain can be a structured chain formed by marking and sorting each propagation node in the attack infection propagation status data according to its behavior characteristics and attack stages.

[0117] Specifically, each propagation node in the attack infection propagation status data is analyzed one by one to extract its corresponding data packet behavior and host response log; then these behaviors are feature-matched with the standardized tags in the dynamic behavior tag set. For example, the tag "remote connection attempt" can match SSH brute-force behavior, and "sensitive file tampering" can match operations such as configuration poisoning. During the matching process, the context information, temporal logic, and position in the behavior chain where the behavior occurs are considered, so as to classify each node into a specific attack stage, such as "initial penetration", "privilege escalation", "lateral movement", or "data exfiltration". According to the occurrence order and propagation logic of the attack behaviors, these marked nodes are sorted and structurally reorganized in stages to construct a clear phased propagation chain of attack behaviors.

[0118] Step 706: Simulate the antibody response behaviors triggered in each attack stage of the phased propagation chain of attack behaviors to construct a phased propagation chain of defense behaviors.

[0119] Among them, the attack stage can be a specific stage in the attack behavior life cycle, usually divided according to the attacker's operation intention and the network attack chain model (such as MITRE ATT&CK), including initial access, privilege escalation, lateral movement, persistence, command and control, and data exfiltration, etc.

[0120] Among them, the antibody response behavior can be a security defense action automatically triggered in the digital immune system when a specific attack behavior is recognized, such as blocking communication, isolating the host, locking the account, or triggering an alarm, etc.

[0121] Among them, the phased propagation chain of defense behaviors can be a chain structure formed after response modeling for each attack stage in the phased propagation chain of attack behaviors, indicating the antibody response behaviors triggered or should be triggered in each attack stage, their acting nodes, triggering times, and effects.

[0122] Specifically, according to the specific attack type, behavior characteristics, and influence scope of each stage in the phased propagation chain of attack behaviors, the corresponding immune response rules and historical defense strategy templates in the digital antibody library are called; then the defense mechanisms that may be triggered when facing this type of attack in the real network environment are simulated, such as abnormal login triggering account locking, malicious file writing triggering file isolation, lateral movement attempt activating network segmentation and other protection measures. Further organize these response behaviors according to the timeline and logical order of the attack stages to construct a defense chain structure that corresponds one by one to the attack chain structure, where each node represents a specific immune response or the triggering of a security policy, and the edge represents the stage connection and influence relationship between the responses; at the same time, this chain also defines the triggering conditions, execution nodes, response latency, and policy effectiveness evaluation of each response behavior to obtain the phased propagation chain of defense behaviors.

[0123] Step 708: Map the nodes of the attack behavior phased propagation chain and the defense behavior phased propagation chain to obtain a network security attack behavior graph.

[0124] Specifically, each node in the attack behavior phased propagation chain and the defense behavior phased propagation chain is matched one by one according to the time sequence and behavior semantics to identify whether there is a corresponding defense response for each attack behavior; during the matching process, consider the behavior trigger conditions, affected objects, upstream and downstream relationships, and whether it is the same asset or session context to ensure the accuracy and integrity of the mapping. For the successfully matched node pairs, mark them as "effective response", and the attack nodes that are not matched or have a response delay exceeding the threshold are marked as "not responded" or "response failed", and record the window period or response missing segment in their propagation paths, and integrate these mapping relationships in the form of a graph structure to construct a network security attack behavior graph, where the attack nodes and defense nodes are the key entities in the graph, and the connecting edges represent the causal relationship, response path and time dependence between the two.

[0125] In this embodiment, by analyzing the attack infection path of suspicious behavior data packets, the propagation trajectory of attack behaviors in the network can be comprehensively restored, and structured attack infection propagation state data can be generated; combined with the dynamic behavior label set, each propagation node is accurately marked to construct a clear attack behavior phased propagation chain, which helps to reveal the temporal and phased characteristics of the attacker's behavior; further, by simulating the antibody response behaviors that may be triggered in each attack stage, a corresponding defense behavior phased propagation chain is constructed to fully reflect the immune response process of the system; finally, the attack chain and the defense chain are mapped at the node level to form a network security attack behavior graph, which depicts the threat evolution and defense effect from both the attack and defense perspectives, and significantly improves the network security system's visualization perception ability of the attack chain, dynamic modeling ability of the confrontation relationship, and support ability for accurate response and strategy optimization.

[0126] In an exemplary embodiment, as Figure 8 shown, simulate the antibody response behaviors triggered in each attack stage of the attack behavior phased propagation chain, and construct a defense behavior phased propagation chain, including steps 802 to 808. Among them:

[0127] Step 802: Extract the behavior conformation features and stage labels of each attack behavior node in the attack behavior phased propagation chain as immune trigger data.

[0128] Among them, the attack behavior node can be the core component element in the attack behavior phased propagation chain, and each node represents a specific malicious behavior implemented by the attacker against the target system at a certain moment, such as remote connection, command execution, file tampering, etc.

[0129] Among them, the behavioral conformation feature can be a structured description of the behavioral pattern reflected by the attack behavior node, including the behavior type, execution location, behavior path, triggering mechanism, resource object operated on, and its context environment.

[0130] Among them, the phase label can be a classification identifier for the stage where the attack behavior node is located in the entire attack life cycle, usually divided according to the attack chain model, such as "initial penetration", "privilege escalation", "lateral movement", "command and control", etc.

[0131] Among them, the immune trigger data can be structured input data composed of the behavioral conformation feature and phase label of the attack behavior node, representing the stimulation signal of the attack behavior to the system's immune mechanism.

[0132] Specifically, traverse each attack behavior node in the attack behavior stage propagation chain, and sequentially extract its behavioral conformation feature information, including behavior type (such as network scanning, remote login, file tampering, etc.), behavior object (target IP, port, file path, etc.), execution environment (such as user privilege, operating system status), behavior timestamp, and context information; combine the upstream and downstream behaviors of the attack chain with the existing attack model, and label the attack stage label of each attack behavior node, such as "initial penetration", "privilege escalation", or "lateral movement", to accurately reflect the role and position of the node in the entire attack evolution process. Subsequently, standardize the format and fuse the semantics of the extracted behavioral conformation features and phase labels to form structured immune trigger data.

[0133] Step 804, in the set of predetermined mimic immune response pathways, analyze the response pathways of the trigger reaction processes that match the immune trigger data to obtain a set of candidate antibody response behaviors.

[0134] Among them, the set of predetermined mimic immune response pathways can be a defense behavior path library constructed according to historical security policies, defense rules, and mimic immune mechanisms, where each pathway mimics the response process that the system may take when facing a specific attack type or stage.

[0135] Among them, the trigger reaction process can be the defense mechanism execution path recognized by the system once the trigger condition of a certain defense path in the set of mimic immune response pathways matches the input immune trigger data.

[0136] Among them, the set of candidate antibody response behaviors can be a set of response paths with actual defense significance screened through the matching of the trigger reaction process. This set includes multiple immune behavior paths that may be activated in the current attack scenario, and is a candidate library for evaluating the response effectiveness and selecting the optimal defense action.

[0137] Specifically, input the immune trigger data into a set of predefined mimic immune response pathways. This set of predefined mimic immune response pathways is an aggregate composed of multiple response paths constructed based on historical attack response experiences, rule bases, and simulated immune mechanisms. Each path describes a sequence of defense behaviors that the system may adopt under specific attack conditions. Then, compare and analyze the conformational features and attack phase labels in the immune trigger data with the trigger conditions of each response path in the set of predefined mimic immune response pathways to identify which paths have trigger features highly matching the current input. During the matching process, dimensions such as the context environment, attack intensity, and resource sensitivity are also analyzed to filter out inapplicable or redundant paths. Extract all the response paths that meet the matching conditions and organize them into a set of candidate antibody response behaviors. Each candidate path represents a defense strategy that may be activated under the current attack behavior.

[0138] Step 806: Select a set of defense behavior nodes according to the activation confidence and propagation coverage of each response path in the set of candidate antibody response behaviors.

[0139] Among them, the activation confidence can be a probability value evaluating the actual triggering and successful execution of a candidate antibody response path in the current network environment and behavioral context, usually calculated based on factors such as behavior matching degree, policy enabling status, and resource availability.

[0140] Among them, the propagation coverage can be a measure of the range that a certain response path can defend or affect in the entire attack propagation chain, mainly including the number of protected nodes, defense depth, and the ability to block key attack nodes in the propagation chain.

[0141] Among them, the set of defense behavior nodes can be a set of key defense action nodes comprehensively selected from the set of candidate antibody response behaviors based on activation confidence and propagation coverage.

[0142] Specifically, evaluate each response path in the set of candidate antibody response behaviors, calculate its activation confidence, that is, the possibility of being successfully triggered and executed under the current immune trigger data and network environment. This evaluation considers factors such as behavior matching degree, system resource status, and policy enabling conditions. Subsequently, further calculate the propagation coverage of each response path to measure the defense range of this defense behavior in the entire attack behavior stage propagation chain, including the depth of the attack path it can interrupt, the number of protected nodes, and the ability to affect the spread of the propagation chain. After comprehensively scoring these two indicators of each response path, use a multi-factor optimization strategy or weight sorting algorithm to screen out the key behavior nodes in those response paths with sufficient activation conditions, strong response timeliness, and wide defense range. Extract these selected behavior nodes to form a set of defense behavior nodes.

[0143] Step 808: Sort each defense behavior node in the set of defense behavior nodes according to the chronological order of each attack behavior node to obtain a phased propagation chain of defense behaviors.

[0144] Specifically, based on the timestamps and phase labels of each attack behavior node in the phased propagation chain of attack behaviors, a chronological model of attack behaviors is established to clarify the occurrence order and propagation rhythm of attack behaviors in each phase. Subsequently, the previously selected set of defense behavior nodes is associated and matched with their corresponding attack nodes to ensure that each defense node is mapped to the correct attack phase and the time logic relationship of the original attack behaviors is retained. Then, the successfully matched defense nodes are sorted according to the chronological order of the attack behavior nodes, so that the defense response chain is logically aligned with the attack chain in phases; at the same time, the situation where multiple defense nodes correspond to one attack node will be merged and optimized, or recommended supplementary response strategies will be inserted in some defense gaps to enhance the integrity and practical adaptability of the chain, and a phased propagation chain of defense behaviors is obtained.

[0145] In this embodiment, by extracting the behavior conformation characteristics and phase labels of each node in the phased propagation chain of attack behaviors, immune trigger data is formed to realize the structured modeling and semantic recognition of attack behaviors; on this basis, a set of mimetic immune response pathways is introduced to match the defense paths corresponding to the trigger data, effectively reusing historical defense knowledge, and generating a set of candidate antibody response behavior sets; further, by evaluating the activation confidence and propagation coverage of each response path, a set of defense behavior nodes with the best response effect and defense value is selected to ensure the accuracy and efficiency of defense actions; finally, the defense nodes are organized in an orderly manner according to the chronological order of attack behaviors to construct a phased propagation chain of defense behaviors, thereby realizing a dynamic and phased immune response mechanism for the attack chain, and greatly improving the system's anti-strike ability, response adaptability and strategy intelligence level.

[0146] In an exemplary embodiment, as Figure 9 shown, input the historical network antibody performance data into the network security attack behavior map to obtain the current network security immune strategy information, including steps 902 to 906. Among them:

[0147] Step 902: Map the historical network antibody performance data to each defense response node in the network security attack behavior map to obtain a response behavior performance annotation map.

[0148] Among them, the defense response node can be one of the basic units in the network security attack behavior map, which is used to represent the specific defense actions taken by the system when dealing with specific attack behaviors, such as blocking network connections, isolating hosts, locking accounts or enabling alarms, etc.

[0149] Among them, the response behavior performance annotation graph can be an enhanced graph formed after mapping historical network antibody performance data to each defense response node in the attack behavior map, where each defense response node is attached with quantitative indicators of historical execution performance, such as response success rate, average delay, false alarm rate, and resource consumption.

[0150] Specifically, extract historical network antibody performance data from sources such as security event logs, historical defense strategy execution records, and emergency response reports. The content of historical network antibody performance data includes key indicators such as the trigger times, response times, success rates, resource consumption, and handling effects of various defense behaviors. Match the behavior semantics of these historical antibody data with the defense response nodes in the network security attack behavior map, and align them according to dimensions such as behavior type (such as access blocking, account locking, process isolation), attack stage, and context environment. Map the successfully matched data to the graph nodes, establish the corresponding relationship between the nodes and the historical antibody performance, and attach structured performance annotations to each response node, including execution effect scores, response stability, historical coverage, and average handling delay, to generate a response behavior performance annotation graph with historical experience evaluation attributes.

[0151] Step 904, analyze the propagation role and behavior performance of each defense response node in the response behavior performance annotation graph to obtain the analysis data of each immune response path strategy.

[0152] Among them, the propagation role can be the function of containment, interception, or mitigation of diffusion played by the defense response node in the attack propagation path. Usually, evaluate whether it can effectively interrupt the attack chain, prevent the advancement of key behaviors, reduce lateral movement, or delay the attack process.

[0153] Among them, the behavior performance can be a comprehensive indicator for measuring the execution effect of the defense response node in the actual or simulated attack environment, including its response speed, success rate, stability, misjudgment rate, and resource usage efficiency.

[0154] Among them, the analysis data of the immune response path strategy can be the structured information generated after comprehensively analyzing the propagation role and behavior performance of the defense response node and its combined path, and is used to represent the defense value and execution effect of each immune path in actual applications.

[0155] Specifically, based on the network security attack behavior graph, perform propagation analysis on the positions of each defense response node to determine whether it is a key node in the attack chain, such as whether it can block the attack path, prevent the spread of phased behaviors, or cut off the attacker's control channel; combine the historical antibody performance data recorded in the response behavior performance annotation graph to evaluate the response capabilities of each defense response node, including dimensions such as the successful interception rate, response timeliness, execution reliability, false alarm rate, and resource cost. Then, combine multiple defense nodes with logical continuity on the propagation path into a complete immune response path, and conduct an overall performance evaluation of these paths based on the above propagation analysis results and response capabilities, analyzing their defense effects, coverage, and deployment value at different attack stages; at the same time, compare the policy efficiencies between different paths to identify which paths have the advantages of high performance, low latency, and high stability, and which paths show consistency or failure characteristics in multiple attacks, and finally generate immune response path policy analysis data.

[0156] Step 906, perform data form conversion on the policy analysis data of each immune response path to generate the current network security immune policy information.

[0157] Among them, data form conversion can be the process of converting technical analysis data (such as response indicators, propagation weights, etc.) into policy decision information during the policy generation stage. Through a rule engine or a policy mapping model, convert the original numerical and graph-structured data into decision labels, policy instructions, or deployment parameters, such as "recommended to enable", "high-priority response", "automation execution level", etc., to make it capable of being directly applied in an actual network defense system.

[0158] Specifically, perform structural conversion on the technical indicators included in the policy analysis data of the immune response path, map data such as the response success rate, average protection delay, path coverage rate, and resource overhead to actionable policy labels, such as "high-priority enable", "recommended manual review", "low-intervention automatic response", etc., and combine the current network environment status, security policy preferences, business continuity requirements, and asset importance weights to conduct an adaptability evaluation and hierarchical ranking of each response path, and screen out the policy combination with the best responsiveness and risk control capabilities in the current situation. Perform policy aggregation and redundancy elimination operations on the selected policy paths to form an immune policy set with optimized structure, and define the activation conditions, response mechanisms, and dynamic adjustment parameters of each policy, and finally output the current network security immune policy information, including the policy application scope, protection target, enable level, and execution priority, as the basis for automated defense deployment, situation warning linkage, and security operation scheduling.

[0159] In this embodiment, by mapping the historical network antibody performance data to each defense response node in the network security attack behavior map, a response behavior performance annotation map is constructed, which can fully integrate the historical defense effect data and the current attack behavior structure, and realize the performance visualization of the defense node in the real scenario; further analyze the propagation effect and behavior performance of each defense response node, extract the interception effect, execution efficiency and coverage ability of each immune response path in the attack chain, and form path analysis data with strategic reference value; finally, through data form conversion, convert technical indicators into strategic parameters, generate immune strategy information for the current network environment, and realize the intelligent generation and dynamic adaptation of defense strategies, thereby significantly improving the immune decision-making ability, defense response accuracy and overall security protection efficiency of the network system.

[0160] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.

[0161] In an exemplary embodiment, a network security management system is provided. The system includes a terminal and a computer.

[0162] The computer is configured to perform digital antibody analysis on the network behavior data and host behavior data of the target network to obtain suspicious behavior data packets; the network behavior data and host behavior data are obtained through the terminal.

[0163] The computer is configured to perform environment isolation simulation on the suspicious behavior data packets to obtain a dynamic behavior label set.

[0164] The computer is configured to analyze the infection defense mechanism of network attacks based on the suspicious behavior data packets and the dynamic behavior label set to obtain a network security attack behavior map.

[0165] The computer is configured to input the historical network antibody performance data into the network security attack behavior map to obtain the current network security immune strategy information. The historical network antibody performance data is obtained through the terminal.

[0166] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structural diagram may be as shown in Figure 10 . The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Those skilled in the art can understand that the structure shown in Figure 10 is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0167] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0168] In one embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0169] In one embodiment, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the steps in the above method embodiments.

[0170] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0171] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium, and when the computer program is executed, it may include the processes of the above method embodiments.

[0172] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

[0173] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A network security management method, characterized in that: The method comprises: Perform digital antibody analysis on the network behavior data and host behavior data of the target network to obtain suspicious behavior data packets; Performing environmental isolation simulation on the suspicious behavior data packet to obtain a dynamic behavior label set; Analyze the infection defense mechanism of network attacks according to the suspicious behavior data packet and the dynamic behavior tag set to obtain a network security attack behavior map; The historical network antibody performance data is input into the network security attack behavior map to obtain the current network security immunity strategy information.

2. The method according to claim 1, characterized in that: The digital antibody analysis of the network behavior data and host behavior data of the target network to obtain suspicious behavior data packets includes: Extracting behavior features from the network behavior data and the host behavior data to obtain a behavior feature information set; Performing behavior deviation analysis on each behavior feature information in the behavior feature information set to obtain behavior difference analysis data; According to each preset malicious feature rule, suspicious behavior analysis is performed on the behavior difference analysis data to obtain the suspicious behavior data packet.

3. The method according to claim 2, characterized in that The performing behavior deviation analysis on each behavior feature information in the behavior feature information set to obtain behavior difference analysis data includes: According to the behavior evolution state and behavior evolution path in each of the behavior characteristic information, a behavior conformation chain diagram is obtained; Performing conformational path similarity analysis between the behavior conformation chain graph and the historical conformation evolution graph of the target network to obtain path matching analysis data; Antibody matching analysis is performed on the pathway matching analysis data to obtain the behavior difference analysis data.

4. The method according to claim 3, characterized in that The performing antibody matching analysis on the pathway matching analysis data to obtain the behavior difference analysis data includes: According to the historical conformational evolution graph, construct a set of mimetic antibody response pathways; Inputting the pathway matching analysis data as an inducing factor into the mimetic antibody response pathway set to obtain behavioral conformation activation data; The behavioral conformation activation data are subjected to response activation analysis to obtain the behavioral difference analysis data.

5. The method according to claim 3, characterized in that: The conformation path similarity analysis is performed between the behavior conformation chain diagram and the historical conformation evolution diagram of the target network to obtain path matching analysis data, including: Performing state space migration analysis on the behavior conformation chain diagram to obtain a behavior path migration diagram; Perform path mapping on the behavior path migration graph in the historical conformation evolution graph to obtain a migration energy cost value; The migration energy distribution is analyzed according to the migration energy cost value to obtain the path matching analysis data.

6. The method according to claim 5, characterized in that The calculation formula of the migration energy cost value is: AND struct (v i ,μ i )=1-yes sem (v i ,μ i ) E curve (in i-1 ,v i ,v i+1 )=θ(v i-1 ,v i ,v i+1 ) 2 Among them, E total (P c ,P h ) is the migration energy cost value, P c is the current behavior conformation path, P h is the historical reference conformation path; E struct (v i ,μ i ) is the structural offset energy term, (v i ,μ i ) is the i-th node of the current path and the historical path; E jump (v i ,v i-1 ) is the jump energy term, (v i ,v i-1 ) is from v i-1 to v i The behavioral level transition, E curve (v i-1 ,v i ,v i+1 ) is the path curvature energy term, (v i-1 ,v i ,v i+1 ) is from v i-1 to v i And from v i to v i+1 Behavior level jump, sim sem (v i ,μ i ) is the semantic similarity function; ΔT is the behavior time interval between nodes, δ(v i-1 ,v i ) is from v i-1 to v i The behavior transition amplitude function of the behavior level transition is θ, α is the structural offset energy weight factor, β is the jump energy weight factor, and γ is the path curvature energy weight factor.

7. The method according to claim 1, characterized in that The analysis of the infection defense mechanism of the network attack based on the suspicious behavior data packet and the dynamic behavior tag set to obtain a network security attack behavior map includes: Performing attack infection path analysis on the suspicious behavior data packet to obtain attack infection propagation status data; According to the dynamic behavior tag set, each attack behavior of the attack infection propagation state data is marked to obtain a staged propagation chain of the attack behavior; Simulating the antibody response behavior triggered in each attack stage of the attack behavior staged transmission chain, and constructing a defense behavior staged transmission chain; The attack behavior phased propagation chain and the defense behavior phased propagation chain are node mapped to obtain the network security attack behavior graph.

8. The method according to claim 7, characterized in that The simulating of the antibody response behavior triggered in each attack stage of the attack behavior staged transmission chain to construct the defense behavior staged transmission chain includes: Extracting the behavior conformation characteristics and stage labels of each attack behavior node in the staged propagation chain of the attack behavior as immune triggering data; In a predetermined set of mimetic immune response pathways, analyzing the response pathways of the triggering reaction process that matches the immune triggering data to obtain a set of candidate antibody response behaviors; Selecting a defense behavior node set according to the activation confidence and propagation coverage of each response path in the candidate antibody response behavior set; According to the time sequence of each of the attack behavior nodes, each defense behavior node in the defense behavior node set is sorted to obtain the defense behavior staged propagation chain.

9. The method according to claim 1, characterized in that: The inputting of historical network antibody performance data into the network security attack behavior map to obtain current network security immunity strategy information includes: Mapping the historical network antibody performance data to each defense response node in the network security attack behavior graph to obtain a response behavior performance annotation graph; Analyze the propagation effect and behavior performance of each of the defense response nodes in the response behavior performance annotation graph to obtain strategy analysis data of each immune response path; The immune response path strategy analysis data are converted into data form to generate the current network security immune strategy information.

10. A network security management system, characterized in that: The system includes a terminal and a computer; The computer is used to perform digital antibody analysis on the network behavior data and host behavior data of the target network to obtain suspicious behavior data packets; The network behavior data and the host behavior data are obtained through the terminal; The computer is used to perform environmental isolation simulation on the suspicious behavior data packet to obtain a dynamic behavior label set; The computer is used to analyze the infection defense mechanism of network attacks according to the suspicious behavior data packet and the dynamic behavior tag set to obtain a network security attack behavior map; The computer is used to input historical network antibody performance data into the network security attack behavior map to obtain current network security immunization strategy information, and the historical network antibody performance data is obtained through the terminal.

Citation Information

Patent Citations

  • User behavior authentication method based on Petri network in private cloud environment

    CN111917801A

  • Design method of deception defense system based on heterogeneous fusion

    CN119299172A

  • Network attack countering method and device, computer equipment and storage medium

    CN119484140A

  • Method for analyzing suspicious activity on an aircraft network

    US20170054752A1

  • Techniques for defensing cloud platforms against cyber-attacks

    US20200213338A1