A network security management method and system
By analyzing network behavior and host behavior data digitally and simulating environmental isolation, a network security attack behavior map is constructed. Combined with historical data, the immune strategy is optimized, which solves the problems of slow response and blind spots in traditional network security management methods when facing rapid attacks, and realizes adaptive and self-evolving network security defense.
Patent Information
- Application Number
- CN202510566983.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-04-30
AI Technical Summary
Traditional network security management methods are slow to respond to rapidly evolving cyberattacks and advanced persistent threats, and have blind spots in defense, making it difficult to effectively identify and respond to unknown attacks.
By performing digital antibody analysis on network behavior data and host behavior data, suspicious behavior data packets are identified, and dynamic behavior tags are extracted in environmental isolation simulation to construct a network security attack behavior map. Combined with historical network antibody performance data for in-depth fusion analysis, a current network security immunity strategy is generated.
It enables adaptive defense against rapidly evolving cyberattacks and advanced persistent threats, enhancing the network system's ability to detect unknown attacks and its defensive flexibility, and eliminating the limitations of slow response and defense blind spots.
Smart Images

Figure CN120200838B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a network security management method and system. BACKGROUND
[0002] In the prior art, network security management methods mainly rely on firewalls, intrusion detection systems (IDS), antivirus software and access control, etc., and achieve basic protection through protection of network boundaries, monitoring of data flow and identification of known threats. These methods focus on prevention and post-response of known attacks, and usually use static rules and signature libraries for threat identification, which are suitable for relatively closed and controllable IT environments, but have limitations of slow response and defense blind area when facing rapidly evolving network attacks and advanced persistent threats (APT). SUMMARY
[0003] Therefore, it is necessary to provide a network security management method and system which can effectively eliminate the limitations of slow response and defense blind area when facing rapidly evolving network attacks and advanced persistent threats.
[0004] In a first aspect, the present application provides a network security management method, comprising:
[0005] performing digital antibody analysis on network behavior data and host behavior data of a target network to obtain suspicious behavior data packets;
[0006] performing environment isolation simulation on the suspicious behavior data packets to obtain a dynamic behavior tag set;
[0007] analyzing an infection defense mechanism of a network attack according to the suspicious behavior data packets and the dynamic behavior tag set to obtain a network security attack behavior graph;
[0008] inputting historical network antibody performance data into the network security attack behavior graph to obtain current network security immune strategy information.
[0009] In a second aspect, the present application further provides a network security management device, comprising a terminal and a computer.
[0010] The computer is configured to perform digital antibody analysis on network behavior data and host behavior data of a target network to obtain suspicious behavior data packets, wherein the network behavior data and the host behavior data are obtained through the terminal.
[0011] The computer is configured to perform environment isolation simulation on the suspicious behavior data packets to obtain a dynamic behavior tag set.
[0012] The computer is configured to analyze an infection defense mechanism of a network attack according to the suspicious behavior data packet and the dynamic behavior tag set, and obtain a network security attack behavior graph.
[0013] The computer is configured to input historical network antibody performance data into the network security attack behavior graph, and obtain current network security immune strategy information, wherein the historical network antibody performance data is obtained by the terminal.
[0014] The network security management method and system can comprehensively identify potential suspicious behavior data packets by fusing network behavior data and host behavior data, improve the accuracy of initial detection by using digital antibody analysis technology, effectively capture deep attack features that cannot be found by traditional static analysis by simulating environment isolation of suspicious data packets and extracting dynamic behavior tags of the suspicious data packets in a controlled environment, clearly present attack paths, infection modes and potential threat chains by constructing a network security attack behavior graph based on suspicious data and dynamic behavior tags, facilitate comprehensive understanding of attack logic and behavior intention, and realize precise generation and dynamic optimization of immune strategies in a current network environment by combining historical network antibody performance data and behavior graphs for deep fusion analysis. Therefore, the network security management method and system can effectively eliminate the limitations of reaction delay and defense blind area when facing rapidly evolving network attacks and advanced persistent threats, improve the perception ability, defense flexibility and overall security protection level of a network system to unknown attacks, and realize an adaptive and self-evolving network security defense system. BRIEF DESCRIPTION OF DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the embodiments or the related art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0016] Figure 1 An application environment diagram of the network security management method in an embodiment;
[0017] Figure 2 A flowchart of the network security management method in an embodiment;
[0018] Figure 3 A flowchart of the suspicious behavior data packet obtaining method in an embodiment;
[0019] Figure 4 A flowchart of the behavior difference analysis data obtaining method in an embodiment;
[0020] Figure 5A flowchart of a method for obtaining behavior difference analysis data in another embodiment is shown in FIG. 8.
[0021] Figure 6 A flowchart of a method for obtaining path matching analysis data in an embodiment is shown in FIG. 9.
[0022] Figure 7 A flowchart of a method for obtaining a network security attack behavior graph in an embodiment is shown in FIG. 10.
[0023] Figure 8 A flowchart of a method for constructing a defensive behavior stage transmission chain in an embodiment is shown in FIG. 11.
[0024] Figure 9 A flowchart of a method for obtaining current network security immune strategy information in an embodiment is shown in FIG. 12.
[0025] Figure 10 An internal structure diagram of a computer device in an embodiment is shown in FIG. 13. DETAILED DESCRIPTION
[0026] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.
[0027] The network security management method provided by the embodiments of the present application can be applied in an application environment as shown in FIG. 1. Figure 1 In the application environment, a terminal 102 communicates with a server 104 through a network. A data storage system can store data required to be processed by the server 104. The data storage system can be integrated on the server 104, or placed on a cloud or other network server. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0028] In an exemplary embodiment, as shown in FIG. 2, a network security management method is provided. The method is applied to the server in FIG. 1 as an example and includes the following steps 202 to 206. Figure 2 Figure 1 In the application environment, a terminal 102 communicates with a server 104 through a network. A data storage system can store data required to be processed by the server 104. The data storage system can be integrated on the server 104, or placed on a cloud or other network server. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0029] In the application environment, a terminal 102 communicates with a server 104 through a network. A data storage system can store data required to be processed by the server 104. The data storage system can be integrated on the server 104, or placed on a cloud or other network server. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0030] In the application environment, a terminal 102 communicates with a server 104 through a network. A data storage system can store data required to be processed by the server 104. The data storage system can be integrated on the server 104, or placed on a cloud or other network server. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0031] In the application environment, a terminal 102 communicates with a server 104 through a network. A data storage system can store data required to be processed by the server 104. The data storage system can be integrated on the server 104, or placed on a cloud or other network server. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers. In the application environment, a terminal 102 communicates with a server 104 through a network. A data storage system can store data required to be processed by the server 104. The data storage system can be integrated on the server 104, or placed on a cloud or other network server. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0032] The network behavior data can be data stream information generated by various devices in the network during communication, covering IP address, port number, protocol type, connection duration, data packet size, access frequency, and the like.
[0033] The host behavior data can be running state information of a single computing node or device at the operating system level, including process startup and termination, system call, file read / write, registry access, memory change, user login behavior, and the like.
[0034] The digital antibody analysis can be a network security technology simulating the antibody recognition mechanism in the biological immune system, and the "normal behavior model" (antibody) is constructed to compare and identify data behaviors deviating from the normal state in the network. This method combines pattern recognition and anomaly detection algorithms to realize fast classification and risk assessment of network and host behaviors, and identify potential threat targets.
[0035] The suspicious behavior data packet can be a data packet identified as possibly carrying malicious behavior characteristics in the digital antibody analysis process. Although such a data packet is not completely confirmed to have attack behavior, its behavior pattern is significantly different from normal communication, and needs to be further analyzed and verified.
[0036] Specifically, by deploying monitoring probes at the network boundary and inside the host, multi-source heterogeneous data including network traffic, port access, protocol type, connection frequency, process behavior, system call, file operation, memory read / write, and the like are continuously collected; the digital antibody model constructed based on the artificial immune principle is used to extract and encode the collected network behavior data and host behavior data, and perform pattern matching and similarity calculation with the normal behavior model; then, an anomaly detection algorithm (such as density-based outlier detection, clustering analysis, or machine learning classifier) is used to identify abnormal behaviors significantly deviating from the normal model; these abnormal behaviors are further filtered into suspicious behavior data packets, and each suspicious behavior data packet is preliminarily labeled as an input for subsequent simulation analysis and behavior modeling.
[0037] In step 204, the suspicious behavior data packets are subjected to environment isolation simulation to obtain a dynamic behavior tag set.
[0038] The environment isolation simulation can be a security technology for performing test on suspicious data packets in a virtual or controlled environment, often with the aid of a sandbox, virtual machine, or simulation system.
[0039] The dynamic behavior tag set can be a tag set formed by classifying and identifying key behaviors generated by the system in runtime of the suspicious data packet in the environment isolation simulation. The tags can include "download remote file", "modify registry", "attempt privilege escalation", "establish reverse connection", and the like, and are used to describe and identify the intention and path of the attack behavior.
[0040] Specifically, the suspicious behavior data packet identified in the first stage is input into a highly isolated and controllable simulation environment, such as a sandbox system or a virtual machine cluster, to avoid any impact on the real production network; the instructions or behavior triggering logic contained in the suspicious behavior data packet are executed in the environment isolation simulation, and various behavior characteristics generated in the running process are comprehensively monitored and recorded, including network connection attempts, system file modifications, registry changes, malicious process creation, memory injection, command control interaction, and the like; the behavior analysis module analyzes these running tracks, extracts key behavior patterns with attack characteristics, and models the time sequence, behavior context, and behavior chain, and organizes the identified behavior characteristics into a set of dynamic behavior tags with clear semantics and quantifiable.
[0041] In step 206, the infection defense mechanism of the network attack is analyzed according to the suspicious behavior data packet and the dynamic behavior tag set, and a network security attack behavior graph is obtained.
[0042] The infection defense mechanism can be a set of protection strategies established by the network system to cope with the penetration and spread of attackers, including intrusion detection, access control, behavior blocking, system hardening, isolation response, and the like. Through the analysis of the attack path, the protection effect of the existing mechanism can be evaluated, the defense blind spot can be found, and the defense strategy can be optimized.
[0043] The network security attack behavior graph can be a graph structure model, which is used to comprehensively present the action track and attack strategy of the attacker in the network. It abstracts the attack behavior as a node in the graph, and the dependency relationship between the nodes forms an edge, which reveals the attack path, stage evolution and behavior linkage through visualization, facilitating the analysis and defense strategy formulation.
[0044] Specifically, suspicious behavior data packets and dynamic behavior tag sets are fused to form a composite attack behavior unit with time sequence and context correlation; attack chain modeling technology is used to identify the logical relationship and causal path between each behavior unit in the composite attack behavior unit, analyze its role in the network intrusion process, such as initial penetration, privilege escalation, lateral movement, information theft, etc.; then a graph construction algorithm is used to abstract each behavior unit in the composite attack behavior unit as a node, and the dependency relationship between behaviors as an edge in the graph, forming a complete attack behavior path graph; further, key infection nodes and propagation paths are marked in the graph, potential defense weak links and attack propagation bottlenecks are identified, and a network security attack behavior graph is generated, which depicts the penetration process, attack strategy and behavior pattern of the attacker in the target system.
[0045] Step 208, input the historical network antibody performance data into the network security attack behavior graph to obtain current network security immune strategy information.
[0046] Among them, the historical network antibody performance data can be the record data of the identification, protection and response to various security threats in the past, including the identified attack type, triggered security policy, execution effect and disposal result.
[0047] Among them, the current network security immune strategy information can be a protection scheme for the current threat environment automatically generated based on the latest attack graph and historical antibody data. It includes emergency response measures, defense configuration suggestions, access control policies, monitoring priorities, etc., to guide the network system to realize dynamic and intelligent security defense and continuous immunity.
[0048] Specifically, historical network antibody performance data with similarity to nodes or paths in the existing attack behavior graph is extracted from the historical security event library, including past attack detection records, defense strategies, response measures and their effect evaluation; through behavior feature matching and correlation analysis algorithm, the historical network antibody performance data is aligned with the key attack behavior nodes in the network security attack behavior graph, and it is identified which historical strategies have been effective or ineffective against similar attack behaviors; using knowledge transfer and strategy optimization technology, combined with the configuration, resource state and risk preference of the current network environment, the historical immune mechanism that may be applicable is adapted and adjusted and optimized recommended to generate current network security immune strategy information, including real-time response measures, prevention and control suggestions, key asset reinforcement schemes, etc.
[0049] In the network security management method, by fusing the network behavior data and the host behavior data, using the digital antibody analysis technology, potential suspicious behavior data packets can be comprehensively identified, and the accuracy of initial detection is improved. Further, by simulating the environment isolation of the suspicious data packets, the dynamic behavior tags of the suspicious data packets in the controlled environment are extracted, and deep attack features that cannot be found by traditional static analysis are effectively captured. Based on the suspicious data and the dynamic behavior tags, a network security attack behavior graph is constructed, which can clearly present the attack path, the infection mode and the potential threat chain, and facilitate the comprehensive understanding of the attack logic and the behavior intention. In combination with the historical network antibody performance data and the behavior graph, deep fusion analysis is performed, the immune strategy is accurately generated and dynamically optimized under the current network environment, the limitations of reaction lag and defense blind area can be effectively eliminated when facing rapidly evolving network attacks and advanced persistent threats, the perception ability, the defense flexibility and the overall security protection level of the network system to unknown attacks are improved, and thus an adaptive and self-evolving network security defense system is realized.
[0050] In one exemplary embodiment, as shown in Figure 3 The network behavior data and the host behavior data of the target network are subjected to digital antibody analysis to obtain suspicious behavior data packets, including steps 302 to 306. Among them:
[0051] Step 302, behavior feature extraction is performed on the network behavior data and the host behavior data to obtain a behavior feature information set.
[0052] The behavior feature extraction can be a process of identifying and extracting key feature information from the network behavior data and the host behavior data for subsequent analysis.
[0053] The behavior feature information set can be a structured data set output by a behavior feature extraction module, covering multiple dimensions of behavior features from the network side and the host side, such as connection frequency, resource access path, process call chain, etc.
[0054] Specifically, the feature extraction algorithm is used to perform abstract modeling on the network behavior data and the host behavior data in different dimensions, such as extracting connection frequency, call path, behavior sequence pattern, behavior duration, etc. Feature indicators are extracted, and encoding (such as One-hot, TF-IDF) or numerical normalization is used for structured processing; all abstracted behavior features are integrated to form a unified behavior feature information set as the behavior feature information set.
[0055] Step 304, behavior deviation analysis is performed on each behavior feature information in the behavior feature information set to obtain behavior difference analysis data.
[0056] The behavior deviation analysis can be a joint analysis of the current behavior characteristics and a preset normal behavior baseline model to analyze whether the behavior deviates or is abnormal. The analysis quantitatively evaluates the fluctuation amplitude of the characteristics, the behavior sequence difference, and the time correlation by similarity calculation, cluster analysis, statistical modeling, and the like, to determine which behaviors deviate significantly, which can indicate the occurrence of abnormal or malicious operations.
[0057] The behavior difference analysis data can be an output result of the behavior deviation analysis, and records the behavior items that have significant differences compared with the normal behavior model and specific deviation characteristics thereof, including the behavior type, the deviation amplitude, the associated entity (such as IP, process name), the timestamp, and the like.
[0058] Specifically, each behavior characteristic information in the behavior characteristic information set is jointly analyzed with a preset normal behavior baseline model of the system. The baseline model is trained based on a large amount of historical normal data, and represents the behavior mode of the target network and host under normal operation. In the analysis process, the deviation degree of each behavior characteristic is analyzed by using a behavior analysis algorithm. Common methods include Euclidean distance calculation, Mahalanobis distance analysis, cosine similarity measurement, and time sequence alignment, to quantify the difference between the current behavior and the baseline. In-depth analysis is performed on the characteristics with significant deviation degree, combined with the behavior context, historical mode, and multi-dimensional behavior cross verification, to analyze the possible abnormal behavior trend. The analysis result is organized as behavior difference analysis data, to record the characteristic category, deviation degree, behavior path, and occurrence time of each deviated behavior.
[0059] In step 306, suspicious behavior analysis is performed on the behavior difference analysis data according to each preset malicious feature rule, to obtain a suspicious behavior data package.
[0060] The preset malicious feature rule can be a rule library constructed based on existing network attack knowledge, to identify common malicious behavior modes. These rules describe the feature combination, behavior sequence, or trigger condition of specific attack behaviors, such as frequent port scanning, abnormal data packet structure, abnormal permission operation, and the like, and are usually in the form of feature mode, logical expression, or decision tree, to identify potential threats in the behavior difference data.
[0061] The suspicious behavior analysis can be a process of in-depth analysis and determination of behaviors that may have attack tendency, based on the combination of the behavior difference analysis data and the preset malicious feature rule.
[0062] Specifically, the behavior difference analysis data is input into a malicious feature rule matching engine, which has multiple preset malicious feature rules built in, covering typical attack features such as port scanning, abnormal traffic surge, malicious instruction execution, C2 communication behavior, privilege escalation, and lateral movement; then the behavior difference data is compared with each preset malicious feature rule, to determine whether it meets the combination conditions or trigger threshold of the attack features, for example, multiple failed login attempts and suspicious source address may trigger the "brute force cracking" rule. Further, risk analysis and confidence assessment are performed on the comparison results, combined with context semantics and historical behavior, to further exclude false positives and strengthen the threat judgment of associated behaviors; data segments identified as having obvious attack intent or high-risk potential are extracted and packaged as suspicious behavior data packets, including source address, target, trigger rule number, timestamp, and related behavior path.
[0063] In this embodiment, by performing multi-dimensional behavior feature extraction on network behavior data and host behavior data, a comprehensive and detailed behavior feature information set is constructed, and on this basis, a behavior deviation analysis mechanism is introduced, which can accurately identify abnormal behaviors that deviate from normal behavior patterns; further, by combining a preset malicious feature rule library, semantic analysis and pattern matching are performed on the behavior difference data, to quickly filter out suspicious behavior data packets with potential attack features, thereby greatly improving the accuracy and real-time performance of network threat detection, reducing false positives and false negatives, enhancing the system's perception and early warning capabilities for unknown attacks, and achieving an efficient and intelligent security protection front-end identification mechanism.
[0064] In one exemplary embodiment, as shown in Figure 4 behavior deviation analysis is performed on each behavior feature information in the behavior feature information set, to obtain behavior difference analysis data, including steps 402 to 406.
[0065] Among them:
[0066] Step 402: According to the behavior evolution state and behavior evolution path in each behavior feature information, a behavior conformation chain diagram is constructed.
[0067] Among them, the behavior evolution state can be the specific behavior state of an entity (such as a host, user, or process) at a specific time point or stage, which reflects the stage position and context features of the behavior in the entire behavior chain. For example, the startup of a process, the execution of a system call, or the establishment of a network connection can be regarded as an evolution state.
[0068] The behavior evolution path can be a continuous behavior chain formed by a plurality of behavior evolution states in time sequence and causal logic, describes the behavior trajectory and state transition process of a behavior body in a specific time period, and the path not only shows the before-and-after relationship between behaviors, but also reveals the dependent relationship or potential attack chain in the behavior development process.
[0069] The behavior conformation chain graph can be a graph structure model constructed based on the behavior evolution states and paths, usually in the form of a directed graph or a state transition graph, taking the behavior states as nodes in the graph and the evolution paths between the states as directed edges, and the whole constitutes a chain structure graph describing the dynamic evolution process of the behavior.
[0070] Specifically, the key timestamps, behavior types, action objects and behavior contexts of each behavior are extracted from the various behavior feature information to determine their positions and logical relationships in the overall behavior process. Each specific behavior instance is abstracted as a "behavior evolution state" according to the information extracted above, and the order, dependency or trigger relationship with other behaviors is identified to form a "behavior evolution path". Graph modeling methods are used, such as constructing a directed graph or a time sequence state graph, taking all behavior states as nodes in the graph and behavior paths as directed edges for connection, to form a chain graph structure that can reflect the behavior flow sequence and causal relationship. In the graph building process, context information (such as host ID, port number, call path, etc.) is also added to the nodes to enhance the expression ability of the graph, and the behavior conformation chain graph is generated.
[0071] Step 404, conformation path similarity analysis between the behavior conformation chain graph and the historical conformation evolution graph of the target network is performed to obtain path matching analysis data.
[0072] The conformation path similarity analysis can be an analysis of the similarity degree of the path structure between the current behavior conformation chain graph and the historical conformation evolution graph, to analyze whether the behavior deviates from the normal mode or approaches the known attack path.
[0073] The path matching analysis data can be the output result of the conformation path similarity analysis, used to record the matching degree, similar path segment, unmatched node, path offset point and path matching confidence between the current behavior path and the historical conformation graph.
[0074] Specifically, the target network calls the conformation evolution graph database of the historical running process from the behavior analysis system, which contains the historical conformation evolution graph of the behavior path in the normal state and the known attack scene; the behavior conformation chain graph currently constructed is taken as the object to be analyzed, and the historical conformation evolution graph is analyzed one by one; in the analysis process, graph path similarity algorithms such as graph edit distance calculation, path sequence comparison (such as the longest common sub-path), dynamic time warping (DTW) and the like are used to comprehensively analyze the node order, edge connection relationship, path length and behavior characteristics and the like in the graph. The similarity of the highly coincident path, the abnormal path offset, the path break or the part of the newly generated path in the analysis result is analyzed, and the path similarity score and the path matching confidence are given to each comparison result; finally, the path matching analysis data is output, and the similarity, difference position, key offset node and the like between the current behavior and each historical behavior path are recorded.
[0075] Step 406, antibody matching analysis is performed on the path matching analysis data to obtain behavior difference analysis data.
[0076] Among them, the antibody matching analysis can be combined with the path matching analysis data and the digital antibody model to analyze the coverage process of the current behavior path and the existing antibody template.
[0077] Specifically, the path matching analysis data is taken as input and transmitted into the digital antibody matching model constructed, which pre-stores a normal behavior “antibody library” constructed based on an artificial immune mechanism, wherein each antibody represents a safe behavior mode or a historical immune path recognized by the system. The digital antibody matching model analyzes the key path nodes, path offset positions and unmatched fragments in the current path matching data, and each antibody template in the antibody library one by one, and usually uses similarity calculation, feature vector alignment, behavior weight evaluation and the like in the analysis process to analyze the difference between the behavior path and the normal immune behavior; for the path segment that fails to effectively match the antibody template or has structural differences with multiple antibodies, further deviation quantization analysis is performed, and its risk level and deviation attribute (such as newly generated behavior, mutant behavior, attack tendency behavior and the like) are marked, to generate behavior difference analysis data, and record the abnormal path segment, the antibody unmatched part, the evolution deviation trend and the context characteristics in detail.
[0078] In this embodiment, by mapping the behavior evolution state in the behavior feature information and the evolution path, a structured behavior conformation chain graph is generated, which can clearly restore the evolution process of individual behavior in time sequence and logic; then, through path similarity analysis with the historical conformation evolution graph of the target network, the matching degree between the current behavior and the existing normal or abnormal behavior pattern is identified, the deep structure recognition of behavior deviation is realized; further, the antibody matching mechanism is introduced, the path matching result is compared and analyzed combined with the historical immune model, whether the behavior has potential threat is accurately judged, and finally the behavior difference analysis data is output, so that the precision and intelligent level of abnormal behavior recognition are improved, and the adaptability and immune response ability of the network security system to variant attacks and unknown threats are effectively enhanced.
[0079] In one exemplary embodiment, as shown in Figure 5 The antibody matching analysis of the path matching analysis data is performed to obtain behavior difference analysis data, including steps 502 to 506. Among them:
[0080] Step 502, according to the historical conformation evolution graph, a set of quasi-antibody response paths is constructed.
[0081] Among them, the set of quasi-antibody response paths can be a set of behavior immune model paths constructed based on the historical conformation evolution graph, simulating the response mechanism of the digital immune system when facing external behavior stimulation. Each path represents the effective response process of the system when facing a certain inducing behavior in the past, including trigger conditions, state transition nodes, coping strategies and other contents.
[0082] Specifically, a large number of behavior paths representing normal operation and successful defense records of the system are extracted from the historical conformation evolution graph database, which cover the whole process from the initial state of the behavior to the completion of the immune response, including key nodes, trigger events and system feedback mechanisms. The extracted behavior paths are standardized, and the paths with similar defense effects under different attack scenarios are structurally classified, feature abstracted and labeled to form response path templates with pattern representation. Combined with the "quasi-state" idea in artificial immune system, these response paths are constructed into a set, called response path set, each path in the set is defined as an "immune unit" that can be activated by a specific behavior inducer; in the construction process, context information such as applicable environmental conditions, inducer feature range, path trigger threshold, etc. is also attached to each path to enhance its generalization ability and dynamic adaptability, and a set of quasi-antibody response paths is obtained.
[0083] Step 504, input the path matching analysis data as an inducing factor into the set of quasi-antibody response paths to obtain behavior conformation activation data.
[0084] The inducing factor can be an abnormal behavior segment or deviation feature extracted from the path matching analysis data that can trigger an immune system response, usually including behavior path deviation points, abnormal nodes, unmatched behavior segments, and context information thereof.
[0085] The behavior conformation activation data can be structured information generated by comparing the trigger conditions and structural features of each path in the set of antibody response paths after receiving the inducing factor and identifying the activated or partially activated antibody paths. It records which antibody paths are successfully activated, the degree of activation, the distribution of matching nodes, and the response intensity, etc. It is the core intermediate data for measuring the adaptability and coverage ability of the immune system to the current behavior.
[0086] Specifically, the behavior deviation nodes, path breakpoints, similar path segments, and their corresponding behavior feature information identified in the path matching analysis data are extracted as the inducing factors that may stimulate the immune system in response to the current system behavior. Subsequently, these inducing factors are matched with each antibody path in the set of antibody response paths to compare their degree of agreement in terms of behavior trigger conditions, state transition structures, context environment parameters, etc. to determine whether the activation condition is met. For antibody paths that meet the activation condition, the activated state, the degree of activation (such as complete activation, partial activation, or critical activation), the activation intensity score, and the matching node position are recorded. All activated or partially activated antibody paths and their response states are organized into structured behavior conformation activation data to reflect the effect of the current behavior on the immune system.
[0087] Step 506, performing response activation analysis on the behavior conformation activation data to obtain behavior difference analysis data.
[0088] The response activation analysis can be a systematic evaluation process of the behavior conformation activation data, used to analyze whether the activated antibody response of the current behavior is complete, effective, and reasonable.
[0089] Specifically, the activation state of each antibody response path in the behavior conformation activation data is comprehensively evaluated, focusing on the activation integrity, trigger node consistency, response timing rationality, and activation intensity score of each path. Subsequently, cases with abnormal patterns are identified and labeled, such as partial activation only, significant structural deviation between the activated path and the original path, ineffective triggering of key nodes, or response lag, which may indicate that the current behavior is not fully covered by the digital antibody system. Behavior deviation analysis is performed on these abnormal response paths, combined with the characteristics of the inducing factors and the risk level of the unactivated area, to further analyze whether the behavior has the possibility of unknown variation, potential attack, or immune escape. The analysis results are structured as behavior difference analysis data, which includes difference behavior nodes, deviation types, unmatched path segments, response missing conditions, and comprehensive risk scores.
[0090] In this embodiment, by constructing a quasi-antibody response path set based on the historical conformation evolution graph, the defense response knowledge and immune path model of the system under different security scenarios are effectively precipitated. The path matching analysis data is input into the response set as an inducing factor, which can simulate the stimulation process of abnormal behavior on the immune system in a real network environment, accurately activate the defense path matching the current behavior characteristics, and generate behavior conformation activation data. Further response activation analysis is performed to judge the recognition degree and response coverage ability of the immune system to the current abnormal behavior, and finally the behavior difference analysis data is formed, thereby realizing the dynamic linkage of behavior recognition and immune mechanism, and significantly improving the adaptive recognition ability and defense response efficiency of the system to complex threat behaviors.
[0091] In one exemplary embodiment, as shown in Figure 6 conformation path similarity analysis between the behavior conformation chain graph and the historical conformation evolution graph of the target network is performed to obtain path matching analysis data, including steps 602 to 606. Among them:
[0092] Step 602, the behavior conformation chain graph is analyzed to obtain a behavior path migration graph.
[0093] The row state space migration analysis can be based on the time sequence behavior state extracted from the behavior conformation chain graph, and the behavior flow process is modeled as continuous migration activities occurring in the state space by identifying the evolution relationship between adjacent states. This analysis not only focuses on the order of states, but also considers the trigger conditions, context environment, and behavior feature changes of state transitions, thereby revealing the dynamic change path of the behavior subject within a specific time range.
[0094] The behavior path migration graph can be a graph structure generated by modeling the behavior state migration process, wherein each node represents a specific behavior state, each edge represents the migration relationship between two states, and is accompanied by attributes such as transition direction, transition condition, time interval, and behavior label.
[0095] Specifically, all behavior state nodes and evolution connection relationships therebetween are extracted from the behavior conformation chain graph, system state features represented by each node (such as access behavior, process call, permission change, etc.) and their time sequence order and logical dependence in the behavior sequence are identified, a state space model is constructed based on these states and their evolution paths, each pair of adjacent behavior states is abstracted as a “state migration”, and the occurrence condition, context environment and behavior feature change are recorded. By integrating all state migration actions recorded in the state space model, a path migration graph is formed, wherein the nodes represent the behavior state of the system at a certain time, the edges represent the conversion relationship between the states, and the attributes such as transition direction, transition probability, time interval and behavior label are added. In the integration process, different path segments can also be clustered or classified to identify common migration patterns and rare transition paths, and finally the behavior path migration graph is generated.
[0096] Step 604, mapping the behavior path migration graph to the historical conformation evolution graph to obtain a migration energy consumption value.
[0097] The migration energy consumption value can be an index quantifying the structural deviation and matching cost generated when the current behavior path is mapped to the historical conformation evolution graph, reflecting the “energy consumption” of the current behavior in reproducing the historical path.
[0098] Specifically, the historical behavior paths related to the current behavior path are retrieved from the historical conformation evolution graph, and these historical behavior paths represent the standard state evolution process of the system under normal or known attack scenarios. Each state migration path in the current generated behavior path migration graph is compared with the historical behavior path for structure matching, and a graph mapping algorithm (such as subgraph matching, path alignment, edit distance calculation) is used to compare the structural similarity, node behavior feature consistency and time sequence rationality of the migration paths. In the matching process, a “migration energy value” is calculated for each structural deviation, state inconsistency or path jump, which is used to measure the adjustment or deviation strength required when the current path is mapped to the historical path. All migration energy values on the entire path are accumulated or weighted to obtain the overall migration energy consumption of the current path relative to the historical graph, and finally the migration energy consumption value is output.
[0099] Step 606, analyzing the migration energy distribution according to the migration energy consumption value to obtain path matching analysis data.
[0100] The migration energy distribution can be a distribution map of energy strength formed by segmenting and counting a plurality of migration energy cost values on a complete behavior path, and reflects the degree of fit of the behavior path at each stage with the historical template. The distribution can help identify high-risk paragraphs, high-deviation nodes or abnormal jump areas in the behavior path, and then be used to determine whether the entire behavior process is within the normal range or has potential attack characteristics.
[0101] Specifically, the migration energy cost value is normalized and segmented, the entire behavior path is divided into a plurality of migration segments, and the energy intensity of each segment is calculated to form a migration energy distribution map. Then, the energy distribution of the migration energy distribution map is statistically analyzed to identify high-energy areas (representing significant deviation or high matching cost), low-energy areas (representing high path consistency) and energy mutation points (possible abnormal behavior nodes); further analyze the spatial patterns of changes between these energy areas, compare the path structure with the historical mapping path, analyze the similarity, matching integrity and potential behavior abnormal position between the current behavior path and the normal behavior path; at the same time, the energy density can also be classified and labeled according to the set threshold, and the behavior path corresponding to different energy segments is classified into states such as "matching normal", "partial deviation" or "serious deviation". The above analysis results are integrated into path matching analysis data, including energy distribution map, similarity score, deviation node identification, matching level and confidence score.
[0102] In one embodiment, the calculation formula of the migration energy cost value is
[0103]
[0104] E struct (v i ,μ i )=1-sim sem (v i ,μ i )
[0105]
[0106] E curve (v i-1 ,v i ,v i+1 )=θ(v i-1 ,v i ,v i+1 ) 2
[0107] Wherein, E totav (P c ,P h ) is the migration energy cost value, P c is the current behavior conformation path, Ph is the historical reference conformation path; E struct (v i , μ i ) is the structural deviation energy term, (v i , μ i ) is the i-th node of the current path and the historical path; E jump (v i , v i-1 ) is the jump energy term, (v i , v i-1 ) is the behavior level transition from v i-1 to v i , E curve (v i-1 , v i , v i+1 ) is the path curvature energy term, (v i-1 , v i , v i+1 ) is the behavior level transition from v i-1 to v i and from v i to v i+1 , sim sem (v i , μ i ) is the semantic similarity function; ΔT is the behavior time interval between nodes, δ(v i-1 , v i ) is the behavior transition amplitude function of the behavior level transition from v i-1 to v i , θ is the included angle of the node triplet, α is the structural deviation energy weight factor, β is the jump energy weight factor, and γ is the path curvature energy weight factor.
[0108] In the embodiment, by performing behavior state space migration analysis on the behavior conformation chain graph, a behavior path migration graph is constructed, which can accurately depict the dynamic evolution process of the behavior in the system state space. Further, the migration graph is mapped with the historical conformation evolution graph, the differences between the behavior evolution process and the existing normal mode are quantified, and the deviation degree is intuitively reflected in the form of migration energy consumption value. Then, by analyzing the distribution of the migration energy, the abnormal mutation points and the high deviation region in the behavior path are identified, the path matching analysis data is generated, and thus the structural difference recognition of the complex behavior sequence is realized, the sensitivity and accuracy of the abnormal detection are improved, and the early perception and dynamic response ability of the system to potential threats is effectively enhanced.
[0109] In an exemplary embodiment, as Figure 7As shown, according to the suspicious behavior data packet and the dynamic behavior tag set, the infection defense mechanism of the network attack is analyzed to obtain a network security attack behavior graph, including steps 702 to 708. Among them:
[0110] Step 702, the attack infection path analysis of the suspicious behavior data packet is performed to obtain attack infection propagation state data.
[0111] Among them, the attack infection path analysis can be an analysis of the suspicious behavior data packet and its propagation behavior, combined with the network topology structure, host communication relationship and time sequence characteristics, to deduce the possible diffusion path of the attack activity in the network.
[0112] Among them, the attack infection propagation state data can be the result of the attack infection path analysis, used to record the state information of the attack behavior in the propagation process in the network, including the time stamp, propagation direction, attack type, behavior characteristics and corresponding target system state of each propagation node.
[0113] Specifically, the key information contained in the suspicious behavior data packet, such as source address, target address, port, protocol type, transmission content and trigger time, is parsed, combined with the behavior intention reflected in the dynamic behavior tag (such as remote control, malicious delivery, permission change, etc.), to preliminarily judge whether it has attack propagation characteristics. Load the topology structure of the target network, host association relationship and historical communication mode, identify the possible propagation path of the data packet in the network, and track the host nodes, service interfaces and adjacent communication entities involved. Further, by establishing a propagation model based on time sequence and host behavior sequence, the state of each propagation node is modeled and labeled to form a multi-stage attack diffusion chain starting from the source point and extending along a specific logical path. Finally, the attack infection propagation state data is output to record the infection time, infection mode, propagation direction and state change information of each node.
[0114] Step 704, according to the dynamic behavior tag set, each attack behavior of the attack infection propagation state data is labeled to obtain an attack behavior stage propagation chain.
[0115] Among them, the attack behavior can be an operation behavior initiated by an attacker in the network or host, with malicious intent and possibly causing harm to the system, such as remote login attempt, privilege escalation command execution, malicious script injection, data leakage, etc.
[0116] Among them, the attack behavior stage propagation chain can be a structured chain formed by labeling and sorting each propagation node in the attack infection propagation state data according to its behavior characteristics and attack stage.
[0117] Specifically, each propagation node in the attack infection propagation state data is analyzed one by one, and the corresponding packet behavior and host response log are extracted; then the behaviors are matched with the standardized labels in the dynamic behavior label set, such as the label "remote connection attempt" can match the SSH burst behavior, and the label "sensitive file tampering" can match the configuration poisoning operation, wherein the context information, timing logic and behavior chain position of the behavior occurrence are considered in the matching process, so as to classify each node into a specific attack stage, such as "initial penetration", "privilege escalation", "lateral movement" or "data exfiltration". According to the occurrence order of the attack behavior and the propagation logic, the marked nodes are sequentially sorted and structurally reorganized, and a clear attack behavior stage propagation chain is constructed.
[0118] In step 706, the antibody response behavior triggered in each attack stage of the simulated attack behavior stage propagation chain is simulated, and a defense behavior stage propagation chain is constructed.
[0119] Wherein, the attack stage can be a specific stage in the life cycle of the attack behavior, which is usually divided according to the operation intention of the attacker and the network attack chain model (such as MITRE ATT&CK), including initial access, privilege escalation, lateral movement, persistence, command control and data exfiltration.
[0120] Wherein, the antibody response behavior can be a security defense action automatically triggered in the digital immune system when a specific attack behavior is identified, such as blocking communication, isolating host, locking account or triggering alarm, etc.
[0121] Wherein, the defense behavior stage propagation chain can be a chain structure formed after modeling the response of each attack stage in the attack behavior stage propagation chain, representing the antibody response behavior triggered or to be triggered in each attack stage and its action node, trigger time and effect.
[0122] Specifically, according to the specific attack type, behavior characteristics and influence range of each stage in the attack behavior stage propagation chain, the corresponding immune response rules and historical defense strategy templates in the digital antibody library are called; then the defense mechanisms that may be triggered in the real network environment when facing this type of attack are simulated, such as account locking triggered by abnormal login, file isolation caused by malicious file writing, network segmentation activated by lateral movement attempt, etc. Further, these response behaviors are organized according to the time line and logical order of the attack stage, and a defense chain structure corresponding to the attack chain structure is constructed, wherein each node represents a specific immune response or the triggering of a security policy, and the edge represents the stage connection and influence relationship between the responses; at the same time, the chain also defines the trigger condition, execution node, response delay and policy effectiveness evaluation of each response behavior, and obtains the defense behavior stage propagation chain.
[0123] Step 708, node mapping is performed between the attack behavior phase propagation chain and the defense behavior phase propagation chain, and a network security attack behavior graph is obtained.
[0124] Specifically, each node in the attack behavior phase propagation chain and the defense behavior phase propagation chain is one-to-one matched in time sequence and behavior semantics, and it is identified whether each attack behavior has a corresponding defense response. In the matching process, the behavior trigger condition, the influence object, the upstream and downstream relationship, and whether it is the same asset or the session context are considered to ensure the accuracy and integrity of the mapping. For the successfully matched node pair, it is marked as "effective response", and the attack node that is not matched or whose response delay exceeds the threshold is marked as "unresponsive" or "response failure", and the empty window period or response missing segment in the propagation path is recorded, and these mapping relationships are integrated in the form of a graph structure to construct a network security attack behavior graph, wherein the attack node and the defense node are key entities in the graph, and the connection edge represents the causal relationship, the response path, and the time dependence between them.
[0125] In this embodiment, by analyzing the attack infection path of the suspicious behavior data packet, the propagation trajectory of the attack behavior in the network can be fully restored, and the structured attack infection propagation state data is generated. Combined with the dynamic behavior label set, each propagation node is accurately marked, and a clear attack behavior phase propagation chain is constructed, which helps to reveal the timing and stage characteristics of the attacker's behavior. Further, by simulating the antibody response behavior triggered in each attack stage, a corresponding defense behavior phase propagation chain is constructed, and the immune response process of the system is fully reflected. Finally, the attack chain and the defense chain are node-mapped to form a network security attack behavior graph, which depicts the threat evolution and defense effect from the perspectives of attack and defense, significantly improving the visual perception ability of the network security system to the attack chain, the dynamic modeling ability of the confrontation relationship, and the support ability of accurate response and strategy optimization.
[0126] In one exemplary embodiment, as shown in Figure 8 the antibody response behavior triggered in each attack stage of the attack behavior phase propagation chain is simulated to construct a defense behavior phase propagation chain, including steps 802 to 808. Among them:
[0127] Step 802, the behavior conformation features and stage labels of each attack behavior node in the attack behavior phase propagation chain are extracted as immune trigger data.
[0128] The attack behavior node can be a core component element in the attack behavior phase propagation chain, and each node represents a specific malicious behavior implemented by the attacker at a certain time against the target system, such as remote connection, command execution, file tampering, etc.
[0129] The behavior conformation feature can be a structured description of the behavior pattern reflected by the attack behavior node, including behavior type, execution location, behavior path, trigger mechanism, resource object operated, and context environment.
[0130] The stage label can be a classification identification of the stage of the attack behavior node in the entire attack life cycle, which is usually divided according to the attack chain model, such as “initial penetration”, “privilege escalation”, “lateral movement”, “command control”, and the like.
[0131] The immune trigger data can be structured input data combined by the behavior conformation feature and the stage label of the attack behavior node, representing a stimulation signal of the attack behavior to the system immune mechanism.
[0132] Specifically, each attack behavior node in the attack behavior stage propagation chain is traversed, and the behavior conformation feature information is extracted in sequence, including behavior type (such as network scanning, remote login, file tampering, etc.), behavior object (target IP, port, file path, etc.), execution environment (such as user permission, operating system state), behavior timestamp and context information; in combination with the upstream and downstream behaviors on the attack chain and the existing attack model, the attack stage label of each attack behavior node is labeled, for example, “initial penetration”, “privilege escalation” or “lateral movement”, to accurately reflect the role and position of the node in the entire attack evolution process. Then the extracted behavior conformation feature and stage label are standardized in format and fused in semantics to form structured immune trigger data.
[0133] In step 804, among the predetermined mimic immune response path set, the response path of the trigger reaction process matched with the immune trigger data is analyzed to obtain a candidate antibody response behavior set.
[0134] The predetermined mimic immune response path set can be a defense behavior path library constructed according to historical security policies, defense rules, and simulated immune mechanisms, wherein each path simulates the response process that the system can take when facing a specific attack type or stage.
[0135] The trigger reaction process can be a defense mechanism execution path identified by the system in the mimic immune response path set, once the trigger condition of a certain defense path matches the input immune trigger data.
[0136] The candidate antibody response behavior set can be a response path set with actual defense significance filtered out after matching the trigger reaction process. The set includes multiple immune behavior paths that can be activated in the current attack scenario, and is a candidate library for evaluating response effectiveness and selecting optimal defense actions.
[0137] Specifically, the immune trigger data is input into a predetermined set of immune response pathways, which is a collection of multiple response paths constructed based on historical attack response experience, rule base and simulated immune mechanisms, each path describing a sequence of defensive behaviors that the system can take under specific attack conditions. Then, the conformational features, attack stage labels in the immune trigger data and the trigger conditions of each response path in the predetermined set of immune response pathways are compared and analyzed to identify which paths have trigger features that highly match the current input; during the matching process, context environment, attack strength and resource sensitivity are also analyzed to filter out inappropriate or redundant paths. All response paths that meet the matching conditions are extracted and organized into a candidate antibody response behavior set, with each candidate path representing a defensive strategy that can be activated under the current attack behavior.
[0138] At step 806, a defensive behavior node set is selected according to the activation confidence and propagation coverage of each response path in the candidate antibody response behavior set.
[0139] The activation confidence can be a probability value that evaluates the actual triggering and successful execution of the candidate antibody response path in the current network environment and behavior context, which is usually calculated based on factors such as behavior matching degree, strategy enabling state, resource availability, etc.
[0140] The propagation coverage can be a measure of the range of a response path that can be defended or affected in the entire attack propagation chain, including the number of protected nodes, the depth of defense, and the blocking ability of key attack nodes in the propagation chain.
[0141] The defensive behavior node set can be a set of key defensive action nodes selected from the candidate antibody response behavior set based on the activation confidence and propagation coverage.
[0142] Specifically, each response path in the candidate antibody response behavior set is evaluated to calculate its activation confidence, i.e. the likelihood of being successfully triggered and executed under the current immune trigger data and network environment, taking into account factors such as behavior matching degree, system resource state, strategy enabling condition, etc. Then the propagation coverage of each response path is further calculated to measure the defensive range of the defensive behavior in the entire attack behavior stage propagation chain, including the depth of attack path interruption, the number of protected nodes, and the ability to affect the spread of the propagation chain. After comprehensive scoring of these two indicators of each response path, a multi-factor optimization strategy or weight ranking algorithm is used to select key behavior nodes in response paths that have sufficient activation conditions, strong response timeliness and wide defensive range. These selected behavior nodes are extracted to form the defensive behavior node set.
[0143] Step 808, according to the time sequence order of each attack behavior node, the defense behavior nodes in the defense behavior node set are sorted to obtain the defense behavior stage propagation chain.
[0144] Specifically, according to the time stamp and stage label of each attack behavior node in the attack behavior stage propagation chain, a time sequence model of the attack behavior is established to determine the occurrence order and propagation rhythm of the attack behavior in each stage. Then the previously selected defense behavior node set is associated and matched with the corresponding attack node to ensure that each defense node is mapped to the correct attack stage and the time logic relationship of the original attack behavior is preserved. Then, according to the time sequence order of the attack behavior nodes, the defense nodes that have been successfully matched are sorted to make the defense response chain logically aligned with the attack chain in stages; at the same time, the situation where multiple defense nodes correspond to one attack node is merged and optimized, or a suggested supplementary response strategy is inserted in some defense window segments to enhance the integrity and practical adaptability of the chain, and the defense behavior stage propagation chain is obtained.
[0145] In this embodiment, by extracting the behavior conformation features and stage labels of each node in the attack behavior stage propagation chain, immune trigger data is formed to realize the structured modeling and semantic recognition of the attack behavior; on this basis, a set of mimic immune response pathways is introduced to match and trigger the defense path corresponding to the trigger data, effectively reuse historical defense knowledge, and generate a set of candidate antibody response behaviors; further, by evaluating the activation confidence and propagation coverage of each response path, a set of defense behavior nodes with the most response effect and defense value is selected to ensure the accuracy and efficiency of the defense action; finally, the defense nodes are ordered according to the time sequence order of the attack behavior to construct the defense behavior stage propagation chain, thereby realizing a dynamic and staged immune response mechanism for the attack chain, and greatly improving the anti-attack ability, response adaptability and strategy intelligence level of the system.
[0146] In one exemplary embodiment, as shown in Figure 9 the historical network antibody performance data is input into the network security attack behavior graph to obtain current network security immune strategy information, including steps 902 to 906. Among them:
[0147] Step 902, map the historical network antibody performance data to each defense response node in the network security attack behavior graph to obtain a response behavior performance labeling graph.
[0148] Among them, the defense response node can be one of the basic units in the network security attack behavior graph, which is used to represent the specific defense action taken by the system when responding to a specific attack behavior, such as blocking network connection, isolating host, locking account or enabling alarm, etc.
[0149] The response behavior performance annotation graph can be an enhanced graph formed by mapping historical network antibody performance data to each defense response node in the attack behavior graph, wherein each defense response node is attached with quantitative indicators of historical execution performance, such as response success rate, average delay, false positive rate, and resource consumption, etc.
[0150] Specifically, historical network antibody performance data is extracted from sources such as security event logs, historical defense policy execution records, emergency response reports, etc. The historical network antibody performance data content includes key indicators such as the number of triggers of various defense behaviors, response time, success rate, resource consumption, and disposal effect. These historical antibody data are matched with defense response nodes in the network security attack behavior graph in terms of behavior semantics, and are aligned according to dimensions such as behavior type (such as access blocking, account locking, process isolation), attack stage, and context environment. The matched data are mapped to the graph nodes to establish the correspondence between the nodes and the historical antibody performance, and structured performance annotations are added to each response node, including execution effect score, response stability, historical coverage, and average disposal delay, etc. to generate a response behavior performance annotation graph with historical experience evaluation attributes.
[0151] Step 904, analyze the propagation effect and behavior performance of each defense response node in the response behavior performance annotation graph to obtain each immune response path strategy analysis data.
[0152] The propagation effect can be the function of the defense response node in the attack propagation path, such as containment, interception, or diffusion mitigation. It is usually evaluated whether it can effectively interrupt the attack chain, prevent the advancement of key behaviors, reduce horizontal movement, or delay the attack process.
[0153] The behavior performance can be a comprehensive indicator to measure the execution effect of the defense response node in the actual or simulated attack environment, including its response speed, success rate, stability, false positive rate, and resource use efficiency, etc.
[0154] The immune response path strategy analysis data can be structured information generated by comprehensive analysis of the propagation effect and behavior performance of the defense response node and its combined path, used to represent the defense value and execution effect of each immune path in actual application.
[0155] Specifically, based on the network security attack behavior graph, the position of each defense response node is analyzed for propagation, and it is judged whether it is a key node in the attack chain, such as whether it can block the attack path, stop the stage behavior diffusion, or cut off the attacker's control channel; in combination with the historical antibody performance data recorded in the response behavior performance label graph, the response ability of each defense response node is evaluated, including success interception rate, response timeliness, execution reliability, false positive rate, and resource cost dimensions. Then, multiple defense nodes with logical continuity on the propagation path are combined into complete immune response paths, and the overall performance of these paths is evaluated according to the propagation analysis results and the response ability, and their defense effect, coverage range and deployment value at different attack stages are analyzed; at the same time, the strategy efficiency between different paths is compared, and it is identified which paths have the advantages of high performance, low delay, and high stability, and which paths show consistency or failure characteristics in multiple attacks, and finally the immune response path strategy analysis data is generated.
[0156] Step 906, data form conversion is performed on each immune response path strategy analysis data to generate current network security immune strategy information.
[0157] Among them, the data form conversion can be the process of converting technical analysis data (such as response indicators, propagation weights, etc.) into strategy decision information in the strategy generation stage. Through a rule engine or a strategy mapping model, the original numerical type and graph structure type data are converted into decision labels, strategy instructions or deployment parameters, such as "recommended to enable", "high priority response", "automation execution level", etc., so that they have the ability to be directly applied in actual network defense systems.
[0158] Specifically, the technical indicators contained in the immune response path strategy analysis data are structurally transformed, and data such as response success rate, average protection delay, path coverage, and resource overhead are mapped to operational strategy labels such as "high priority enable", "recommended manual review", "low intervention automatic response", etc. through a rule engine and a strategy model. In combination with the current network environment state, security policy preferences, business continuity requirements and asset importance weights, each response path is adaptively evaluated and hierarchically sorted, and the strategy combination with the best responsiveness and risk control ability in the current situation is selected. The selected strategy path is executed for strategy aggregation and redundancy elimination operation to form a structurally optimized immune strategy set, and the activation condition, response mechanism and dynamic adjustment parameters of each strategy are defined, and finally the current network security immune strategy information is output, including the strategy applicable range, protection target, enable level and execution priority, as the basis for automated defense deployment, situation early warning linkage and security operation scheduling.
[0159] In this embodiment, by mapping the historical network antibody performance data to each defense response node in the network security attack behavior graph, a response behavior performance annotation graph is constructed, which can fully integrate historical defense effect data and current attack behavior structure, realize the performance visualization of defense nodes in real scenarios, further analyze the propagation effect and behavior performance of each defense response node, extract the interception effect, execution efficiency and coverage ability of each immune response path in the attack chain, form path analysis data with strategic reference value, and finally convert technical indicators into strategic parameters through data form conversion, generate immune strategy information for the current network environment, realize intelligent generation and dynamic adaptation of defense strategies, and significantly improve the immune decision-making ability, defense response accuracy and overall security protection efficiency of the network system.
[0160] It should be understood that, although each step in the flowchart involved in each embodiment as described above is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other orders. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.
[0161] In an exemplary embodiment, a network security management system is provided, the system comprising a terminal and a computer;
[0162] The computer is configured to perform digital antibody analysis on network behavior data and host behavior data of a target network to obtain suspicious behavior data packets, and the network behavior data and the host behavior data are obtained through the terminal.
[0163] The computer is configured to perform environment isolation simulation on the suspicious behavior data packets to obtain a dynamic behavior tag set.
[0164] The computer is configured to analyze the infection defense mechanism of a network attack based on the suspicious behavior data packets and the dynamic behavior tag set to obtain a network security attack behavior graph.
[0165] The computer is configured to input historical network antibody performance data into the network security attack behavior graph to obtain current network security immune strategy information, and the historical network antibody performance data is obtained through the terminal.
[0166] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 10 As shown. This computer device includes a processor, memory, input / output interfaces (I / O), and communication interfaces. Those skilled in the art will understand that... Figure 10 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0167] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0168] In one embodiment, a computer-readable storage medium is provided storing a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0169] In one embodiment, a computer program product or computer program is provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and executes the computer instructions, causing the computer device to perform the steps in the above method embodiments.
[0170] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0171] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods.
[0172] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0173] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A network security management method characterized by comprising: The method comprises: performing digital antibody analysis on network behavior data and host behavior data of a target network to obtain suspicious behavior data packets; performing environment isolation simulation on the suspicious behavior data packets to obtain a dynamic behavior tag set; performing attack infection path analysis on the suspicious behavior data packets to obtain attack infection propagation state data; labeling each attack behavior of the attack infection propagation state data according to the dynamic behavior tag set to obtain an attack behavior stage propagation chain; extracting behavior conformation features and stage labels of each attack behavior node in the attack behavior stage propagation chain as immune trigger data; analyzing response paths of trigger reactions matched with the immune trigger data in a predetermined mimic immune response path set to obtain a candidate antibody response behavior set; selecting a defense behavior node set according to activation confidence and propagation coverage of each response path in the candidate antibody response behavior set; sorting each defense behavior node in the defense behavior node set according to a time sequence of each attack behavior node to obtain a defense behavior stage propagation chain; performing node mapping on the attack behavior stage propagation chain and the defense behavior stage propagation chain to obtain a network security attack behavior graph; and inputting historical network antibody performance data into the network security attack behavior graph to obtain current network security immune strategy information.
2. The method of claim 1, wherein, The method comprises: performing behavior feature extraction on the network behavior data and the host behavior data to obtain a behavior feature information set; performing behavior deviation analysis on each behavior feature information in the behavior feature information set to obtain behavior difference analysis data; performing suspicious behavior analysis on the behavior difference analysis data according to each preset malicious feature rule to obtain the suspicious behavior data packets.
3. The method of claim 2, wherein, The method comprises: mapping behavior evolution states and behavior evolution paths in each behavior feature information to obtain a behavior conformation chain graph; performing conformation path similarity analysis between the behavior conformation chain graph and a historical conformation evolution graph of the target network to obtain path matching analysis data; performing antibody matching analysis on the path matching analysis data to obtain the behavior difference analysis data.
4. The method of claim 3, wherein, The method comprises: constructing a mimic antibody response path set according to the historical conformation evolution graph; inputting the path matching analysis data as an inducing factor into the mimic antibody response path set to obtain behavior conformation activation data; performing response activation analysis on the behavior conformation activation data to obtain the behavior difference analysis data.
5. The method of claim 3, wherein, The method comprises: performing row state space migration analysis on the behavior conformation chain graph to obtain a behavior path migration graph; The behavior path migration graph is path-mapped on the historical conformation evolution graph to obtain a migration energy consumption value; According to the migration energy consumption value, migration energy distribution is analyzed to obtain the path matching analysis data.
6. The method of claim 5, wherein, The calculation formula of the migration energy consumption value is , , , , wherein, is a migration energy expenditure value, is a current behavior conformation path, is a historical reference conformation path; is a structural offset energy term, is a first node of the current path and the historical path; is a jump energy term, is a behavior level transition from to , is a path curvature energy term, is a behavior level transition from to and from to , is a semantic similarity function; is a behavior time interval between nodes, is a behavior transition magnitude function for a behavior level transition from to , is an angle of a node triad, is a structural offset energy weight factor, is a jump energy weight factor, is a path curvature energy weight factor.
7. The method of claim 1, wherein, The historical network antibody performance data is input into the network security attack behavior graph to obtain current network security immune strategy information, including: The historical network antibody performance data is mapped to each defense response node in the network security attack behavior graph to obtain a response behavior performance labeling graph; The propagation role and behavior performance of each defense response node in the response behavior performance labeling graph are analyzed to obtain immune response path strategy analysis data; The immune response path strategy analysis data is subjected to data form conversion to generate the current network security immune strategy information.
8. A network security management system characterized by comprising: The system comprises a terminal and a computer; The computer is configured to analyze digital antibodies of network behavior data and host behavior data of a target network to obtain suspicious behavior data packets; The network behavior data and the host behavior data are obtained through the terminal; The computer is configured to simulate environment isolation of the suspicious behavior data packets to obtain a dynamic behavior label set; The computer is configured to analyze attack infection path of the suspicious behavior data packets to obtain attack infection propagation state data; According to the dynamic behavior label set, each attack behavior of the attack infection propagation state data is marked to obtain an attack behavior stage propagation chain; Behavior conformation features and stage labels of each attack behavior node in the attack behavior stage propagation chain are extracted as immune trigger data; In a predetermined paratope immune response pathway set, a response pathway of a trigger reaction process matched with the immune trigger data is analyzed to obtain a candidate antibody response behavior set; According to the activation confidence and propagation coverage of each response path in the candidate antibody response behavior set, a defense behavior node set is selected; According to the time sequence order of each attack behavior node, each defense behavior node in the defense behavior node set is sorted to obtain a defense behavior stage propagation chain; The attack behavior stage propagation chain and the defense behavior stage propagation chain are subjected to node mapping to obtain a network security attack behavior graph; The computer is configured to input historical network antibody performance data into the network security attack behavior graph to obtain current network security immune strategy information, and the historical network antibody performance data is obtained through the terminal.
Citation Information
Patent Citations
User behavior authentication method based on Petri network in private cloud environment
CN111917801A
Design method of deception defense system based on heterogeneous fusion
CN119299172A
Network attack countering method and device, computer equipment and storage medium
CN119484140A