Artificial Intelligence-Based Enterprise Information Security Management Method and System

By building an enterprise information security management system based on artificial intelligence, using graph learning models to identify attack paths and generate protection strategies, the problem that traditional systems cannot cope with unknown threats and internal threats is solved, real-time dynamic protection and rapid response are achieved.

CN120200851BActive Publication Date: 2025-07-18SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510669800.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-07-18
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

The existing enterprise information security management system cannot effectively respond to unknown threats and internal threats, lacks adaptability, and data analysis delays lead to inability to respond to cyber attacks in real time.

Method used

Build an enterprise information security management system based on artificial intelligence, conduct threat perception and behavioral risk assessment through graph learning models, identify attack paths, and generate dynamic protection strategies, combining lightweight monitoring components to achieve real-time protection.

Benefits of technology

Real-time identification and dynamic protection of unknown threats are achieved, system response speed is improved, real-time intervention to ensure information security and prevent threats from spreading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200851B_ABST
    Figure CN120200851B_ABST
Patent Text Reader

Abstract

The present invention discloses an enterprise information security management method and system based on artificial intelligence, belonging to the technical field of information management. It includes inputting original data, integrating the original data into a first behavior graph structure, and constructing an attribute vector for user nodes; performing threat perception and behavior risk assessment through a graph learning model, and outputting the threat probability of each edge; identifying and quantifying the attack paths in the graph, generating an attack path set and a path risk score set; generating a candidate set of protection strategies for each path, evaluating to obtain the scoring results of the protection strategies, and sorting the protection strategies according to the scoring results; deploying the protection strategies, and monitoring the deployment status and protection feedback. After the strategy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information. The present invention combines intelligent prediction and simulation to identify potential security threats in real time and dynamically adjust security strategies according to the changes of threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information management, and particularly relates to an enterprise information security management method and system based on artificial intelligence. Background Art

[0002] With the rapid development of information technology and the advancement of globalization, enterprises are constantly facing various information security challenges in their daily operations. Enterprise information security management not only involves data protection, network security, but also includes complex issues such as preventing data leakage, system intrusion, and malware attacks. In this context, most traditional information security protection systems rely on means such as rule-based firewalls, intrusion detection systems (IDS), access control, and encryption technologies. These traditional technologies detect and prevent attacks by setting rules, pattern recognition, and signature matching. However, with the continuous evolution of network attack technologies, especially the emergence of new attack means such as advanced persistent threats (APT) and zero-day vulnerability attacks, these traditional security protection measures gradually show many limitations.

[0003] Firstly, existing firewalls and intrusion detection systems usually rely on static rules and signature matching, which are usually manually configured by security experts and can only deal with known threats. For new attacks that have not been identified, existing systems often cannot detect and respond in a timely manner. Secondly, traditional security protection systems lack adaptability. Once encountering complex or unknown attacks, existing systems often cannot make effective real-time adjustments and protections, resulting in the expansion of attack incidents. More critically, most current enterprise information security protection methods can only deal with external attacks and lack effective prevention and monitoring of internal threats (such as employee abuse of authority, internal data leakage, etc.).

[0004] In addition, existing systems generally have problems with data analysis delay. Due to the huge amount of data generated in enterprise networks, traditional data processing methods often have a certain delay in security analysis and cannot achieve real-time threat detection and response. The information systems of modern enterprises need to respond quickly and be able to warn and prevent potential threats before attacks occur. However, traditional rule-based methods show obvious deficiencies in dealing with rapidly changing network environments and attack patterns and cannot provide dynamic protection.

[0005] Therefore, we propose an enterprise information security management method and system based on artificial intelligence to solve the above problems. Summary of the Invention

[0006] The purpose of the present invention is to propose an enterprise information security management method and system based on artificial intelligence to solve the problems in the prior art that unknown threats and internal threats cannot be dealt with.

[0007] To achieve the above object, the present invention adopts the following technical solutions:

[0008] An enterprise information security management method based on artificial intelligence, comprising:

[0009] S1: Input original data, where the original data includes a user permission information set, a network connection record set, and a resource access log set;

[0010] Integrate the original data into a first-order graph structure, and construct an attribute vector for the user nodes;

[0011] S2: Based on the first-order graph, perform threat perception and behavioral risk assessment through a graph learning model, and output the threat probability of each edge;

[0012] The learning steps of the graph learning model include node embedding generation, edge representation construction, and edge-level risk prediction;

[0013] The node embedding generation aggregates information through graph convolution with structural normalization;

[0014] The edge representation construction is completed by concatenating the two-end node embeddings and edge attributes;

[0015] The edge-level risk prediction obtains a risk score by inputting the edge representation vector into a single-layer perceptron;

[0016] Output an edge risk score set and a node embedding set;

[0017] S3: Based on the edge risk score set and the node embedding set, combined with the first-order graph, identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generate an attack path set and a path risk score set; the generation steps are as follows:

[0018] Starting from each non-core node, use breadth-first search with a limited depth to construct a set of potential attack paths on the premise that the edge risk score is higher than a set threshold;

[0019] Design a path scoring function for measuring the feasibility and concealment of the attacker's lateral penetration along the path;

[0020] For each node, retain the top K paths with the highest scores starting from it and reaching the core node set;

[0021] Design a structure perturbation test mechanism to perform path credibility confidence analysis on the high-score paths;

[0022] S4: Based on the attack path set and the path risk score, generate a set of candidate protection strategies for each path, evaluate the effectiveness of the protection strategies to obtain a scoring result of the protection strategies, and sort the protection strategies according to the scoring result;

[0023] The generation of the protection strategy generates corresponding protection strategies according to risk scores, path behaviors, and access frequencies according to a preset

[0024] The evaluation is completed by calculating the difference in risk scores of the path before and after applying the corresponding protection strategy;

[0025] The sorting is performed according to preset rules; the preset rules include maximizing the strategy effect and balancing costs and benefits;

[0026] S5: Based on the protection strategy candidate set and the scoring results of the corresponding protection strategies, deploy the protection strategies and monitor the deployment status and protection feedback; the deployment includes the following steps:

[0027] Call the policy deployment mapping function to translate the logical policy into system control commands;

[0028] Perform a deployment priority sorting on all policies, deploy them in order from largest to smallest according to the priority, skip conflicting policies or place them in the manual confirmation queue;

[0029] After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0030] Preferably, the node set of the first row of the graph includes three types of nodes: users, hosts, and resources;

[0031] The edge set of the first row of the graph represents the operation behavior of the user on other nodes;

[0032] The edge attributes of the first row of the graph represent behavior details, and the node attributes of the first row of the graph represent behavior identities and frequencies.

[0033] Preferably, a role difference factor is introduced in the edge representation to measure the cross-level access intensity between the user and the target, and the role difference factor takes the L1 norm, representing the absolute value of the role level difference.

[0034] Preferably, the path scoring function is obtained by inputting the edge risk score into a single-layer perceptron, performing a linear transformation, and then compressing the linear transformation result through a Sigmoid function.

[0035] Preferably, a role crossing weight is introduced in the path scoring function, and the role crossing weight is calculated through the role encoding of the nodes at both ends of the edge.

[0036] Preferably, a path structure jump penalty term is introduced in the path scoring function, and the path structure jump penalty term represents the mean square change rate of the continuous node embedding vectors in the path, highlighting the hidden coherence of the attack.

[0037] Preferably, the structural perturbation test mechanism randomly removes the edges not on the path in the graph and re-evaluates the change in the path score. If the path score fluctuation is less than the threshold, the path is marked as a structurally stable path.

[0038] Preferably, the generation of the protection strategy includes the following rules:

[0039] Node-level strategy: If the behavior risk score of a certain node in the path is relatively high, a strategy for this node can be generated, including freezing the account and restricting access rights;

[0040] Edge-level strategy: If a certain edge in the path involves communication with a high-risk protocol or an unconventional port, a strategy for restricting protocol access or blocking the port is generated;

[0041] Path interruption strategy: If the path is composed of multiple nodes through low-risk behaviors and there is a relatively high security risk in the "connection" of the intermediate path, a strategy for disconnecting a certain critical edge or enabling strong authentication is generated.

[0042] An enterprise information security management system based on artificial intelligence includes:

[0043] A data modeling module that inputs the original data, and the original data includes a user privilege information set, a network connection record set, and a resource access log set;

[0044] Integrate the original data into a first-order graph structure and construct an attribute vector for the user nodes;

[0045] A risk assessment module that, based on the first-order graph, performs threat perception and behavior risk assessment through a graph learning model and outputs the threat probability of each edge;

[0046] Output an edge risk score set and a node embedding set;

[0047] A path simulation module that, based on the edge risk score set and the node embedding set, combines with the first-order graph to identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generates an attack path set and a path risk score set;

[0048] A strategy generation module that, based on the attack path set and the path risk score, generates a candidate set of protection strategies for each path, evaluates the effect of the protection strategies to obtain a scoring result of the protection strategies, and sorts the protection strategies according to the scoring result;

[0049] A policy deployment module that deploys a protection policy based on a candidate set of protection policies and the scoring results of the corresponding protection policies, monitors the deployment status and protection feedback, records the deployment target status after the policy deployment is completed, and installs a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0050] In summary, the technical effects and advantages of the present invention are as follows: By constructing a behavior analysis model and attack simulation, the present invention can not only detect known attacks, but also identify new threats in real time through adaptive learning, ensuring that the system has the ability to cope with future attacks. In addition, the present invention also greatly improves the system response speed by introducing an efficient data processing and automated protection adjustment mechanism, ensuring that the enterprise information security protection can carry out effective intervention in real time to prevent the spread of threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a flowchart of the method steps in the present invention;

[0052] Figure 2 It is a schematic diagram of the system structure in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0054] As Figure 1 shown, an enterprise information security management method based on artificial intelligence includes:

[0055] S1: Input the original data, where the original data includes a user privilege information set, a network connection record set, and a resource access log set;

[0056] Integrate the original data into a first-row graph structure and construct an attribute vector for the user nodes;

[0057] S2: Based on the first-row graph, perform threat perception and behavior risk assessment through a graph learning model, and output the threat probability of each edge;

[0058] The learning steps of the graph learning model include node embedding generation, edge representation construction, and edge-level risk prediction;

[0059] The node embedding generation aggregates information through a structure-normalized graph convolution;

[0060] The edge representation construction is completed by concatenating the two-end node embeddings and the edge attributes;

[0061] The edge-level risk prediction obtains a risk score by inputting the edge representation vector into a single-layer perceptron;

[0062] Output the set of edge risk scores and the set of node embeddings;

[0063] S3: Based on the set of edge risk scores and the set of node embeddings, combined with the first behavior graph, identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generate an attack path set and a path risk score set; the generation steps are as follows:

[0064] Starting from each non-core node, use breadth-first search with a limited depth to construct a set of potential attack paths on the premise that the edge risk score is higher than the set threshold;

[0065] Design a path scoring function for measuring the feasibility and concealment of the attacker's lateral penetration along this path;

[0066] For each node, retain the top K paths with the highest scores starting from it and reaching the set of core nodes;

[0067] Design a structure perturbation test mechanism to perform path credibility confidence analysis on high-scoring paths;

[0068] S4: Based on the attack path set and the path risk score, generate a candidate set of protection strategies for each path, evaluate the effect of the protection strategies to obtain the scoring results of the protection strategies, and sort the protection strategies according to the scoring results;

[0069] The generation of the protection strategy generates corresponding protection strategies according to the risk score, path behavior, and access frequency according to the preset;

[0070] The evaluation is completed by calculating the difference in the risk score of this path before and after applying the corresponding protection strategy;

[0071] The sorting is carried out according to the preset rules; the preset rules include maximizing the strategy effect and balancing cost and benefit;

[0072] S5: Based on the candidate set of protection strategies and the scoring results of the corresponding protection strategies, deploy the protection strategies and monitor the deployment status and protection feedback; the deployment includes the following steps:

[0073] Call the policy deployment mapping function to translate the logical policy into system control commands;

[0074] Perform a deployment priority sorting on all strategies, deploy them in order from largest to smallest according to the priority, skip conflicting strategies or place them in the manual confirmation queue;

[0075] After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0076] The specific steps are as follows:

[0077] Step 1: Modeling of Multi-source Heterogeneous Security Behavior Data

[0078] In this step, data from multiple key security domains within the enterprise are structurally integrated to construct a behavior graph with the ability to express entity interaction relationships and behavior semantics , which is used for subsequent identification and analysis of security threats by the graph neural network model. To ensure the integrity of the modeling structure and its high coupling with the enterprise security scenario, only three core data sources are selected for integration in this step, namely: ① User identity and permission data, ② Host network connection data, and ③ File and database access logs. These three types of data together reflect the complete security behavior chain of "who, where, what, and what was done", which is the smallest closed loop for modeling high-risk behaviors within the enterprise

[0079] Input

[0080] User permission information set : Among them is the user identifier is its role code in RBAC (such as ordinary employee, administrator);

[0081] Network connection record set : is the user is the accessed host address is the access timestamp is the protocol type (such as RDP, SSH);

[0082] Resource access log set : is the user is the accessed resource (such as file, database) is the access time is the operation type (such as read, write, update)

[0083] Step details:

[0084] We integrate the three types of behavior data into a unified behavior graph structure , where:

[0085] : Node set, including three types of nodes: users, hosts, and resources;

[0086] : Edge set, representing the operation behavior of users on other nodes;

[0087] : Node attribute vector, such as user role, resource type, etc.;

[0088] : Edge attribute vector, used to express behavioral detail features.

[0089] The construction of the edge set is based on the following formula:

[0090]

[0091] : Respectively represent the user and their behavioral target nodes (host or resource);

[0092] : Behavioral frequency (such as the number of connections / accesses in the past 24 hours, normalized to 0–1);

[0093] : Protocol or operation type encoding, for example, RDP is 1, SSH is 2, file read is 3, write is 4, DB update is 5.

[0094] At the same time, for the user node construct an attribute vector:

[0095]

[0096] : The role encoding of this user (such as 1 for administrator and 0 for employee);

[0097] : The average daily access quantity of this user to the host or resource (used for modeling activity).

[0098] In the final graph structure, each user node is connected to the host and resource nodes it has operated on through edges. The edge attributes represent behavioral details, and the node attributes represent behavioral identity and frequency.

[0099] Output

[0100] Output 1: Structured behavior graph , where all nodes and edges carry semantic attributes;

[0101] Output 2: Behavioral edge label vector , where indicates that this behavior is marked as a historical high-risk behavior by the security system (can be marked by the administrator or automatically matched and generated).

[0102] In this step, three types of representative enterprise security data are accurately selected and integrated: user identity and permissions, network access records, and resource access logs. A unified behavior graph is constructed through structure mapping , significantly improves the expressive ability of behavioral semantics and the structured modeling ability. Compared with the traditional method of using tables or event lists, this behavioral graph not only expresses "whether the behavior occurs", but also clarifies "the context, frequency, and protocol type of the behavior". More importantly, this graph provides a natural graph structure input for graph neural network modeling, effectively capturing potential associated abnormal patterns within the enterprise, which is a key support for subsequent threat recognition and attack path analysis.

[0103] Step 2: Threat Perception and Risk Assessment Based on Graph Learning

[0104] In this step, on the basis of the structured behavior graph constructed in Step 1 , through a graph learning model, threat perception and behavioral risk assessment are carried out, and the threat probability of each edge is output , which is used to support subsequent attack path deduction and security policy decision-making. In the scenario of this patent, the core of enterprise information security issues lies in the potential linkage relationships between complex behaviors. These behaviors may seem normal individually, but the paths formed in the structure have serious security risks. Therefore, the goal of this step is not only to identify individual behaviors that "seem like attacks", but more importantly, to model potential threats such as privilege escalation and abnormal propagation paths hidden in the "behavior combination" through graph learning, providing intelligent support for proactive defense of the patent.

[0105] Different from general graph classification or node classification, this step focuses on edge-level threat prediction, that is, judging whether each type of operation relationship between users and hosts, files, and databases constitutes a security risk. In the design, the graph topology structure, node role attributes, behavioral context features, and security annotation labels output in Step 1 are fully integrated to construct a multi-perspective graph learning scheme for detecting highly concealed behaviors.

[0106] To identify high-risk operations brought about by structurally complex behaviors, the graph learning scheme designed in this step includes three core stages: (1) node embedding generation; (2) edge representation construction; (3) edge-level risk prediction.

[0107] The key innovation lies in: introducing a structure-sensitive regularization term, a context relationship encoding function, and a graph topology stability constraint term, which strengthens the ability to identify "abnormal behavior combinations" while maintaining computational efficiency.

[0108] First, node embeddings are constructed by aggregating information through structure-normalized graph convolution as follows:

[0109]

[0110] : the embedding vector of node ;

[0111] : The initial features of neighbor nodes come from ;

[0112] : Node degree, used for normalization;

[0113] : Graph convolution weight matrix;

[0114] : Bias term;

[0115] : Node 's neighbor set.

[0116] Subsequently, we construct the edge representation , which not only concatenates the embeddings of the two end nodes and the edge attributes , but also introduces the "context role difference factor" to measure the cross-level access intensity between the user and the target:

[0117]

[0118] : The representation vector of edge ;

[0119] : Respectively represent the role encodings of nodes and , coming from ;

[0120] : Take the L1 norm to represent the absolute value of the role level difference (e.g., from an employee to a database administrator, with a high value);

[0121] : The attribute vector of the edge, coming from ;

[0122] : Concatenation operation.

[0123] This design is for a key phenomenon in the patent scenario: unauthorized access often occurs when the role span is large but the frequency of the behavior itself is not high, which is difficult to identify by traditional frequency / protocol analysis. Through the structural difference significance modeling, this factor can enhance the model's recognition of asymmetric structure threats.

[0124] Then, the risk score Obtained by inputting a single-layer perceptron through edge representation vectors:

[0125]

[0126] : Edge The risk prediction value of;

[0127] : Perceptron weight matrix;

[0128] : Bias;

[0129] : Sigmoid function.

[0130] To improve the ability to judge highly concealed edge behaviors, we designed a regularization term , which is used to punish the sensitivity of the model to local structure perturbations and improve its stability under slightly changed graph topologies:

[0131]

[0132] Where is the risk score recalculated under slight perturbations (such as deleting 5% of random edges) in the edge set , which is used to constrain the robustness of the model to structural micro-changes and enhance its generality in actual attack path construction scenarios.

[0133] The comprehensive loss function is:

[0134]

[0135] : Binary cross-entropy loss;

[0136] : Regularization term weight, which controls the importance of structural robustness;

[0137] All parameters are trained using the standard Adam optimizer.

[0138] Output:

[0139] Output 1: Edge risk score set , which is used for subsequent path construction;

[0140] Output 2: Node embedding set , which represents the semantic context vector of each node and is used for credibility propagation calculation in subsequent paths.

[0141] Starting from the behavior graph, this step designs a structured graph learning method for edge-level risk scoring, which combines graph structure, behavior attributes, role differences, and structural robustness modeling to form a complete end-to-end threat perception process. Compared with existing rule-based or clustering-based detection methods, this method can identify low-frequency but highly impactful abnormal interaction paths at the structural level, especially suitable for the problem characteristics of "sparse attack behavior distribution but strong structural impact" in the scenario of this patent. By introducing the role difference term and the structural stability regularization term , this solution shows stronger pertinence and interpretability in actual attack modeling, and also significantly improves the practicality and creativity of the model in the enterprise multi-role environment.

[0142] Step 3: Attack path simulation based on the risk graph

[0143] Based on the set of edge risk scores generated in Step 2 and the set of node embeddings , combined with the complete behavior graph constructed in Step 1 , a deduction mechanism for predicting potential attack propagation paths is constructed. In enterprise information security management, attacks often do not occur at a single point but have the characteristics of stages and lateral movement. Especially in an enterprise environment with complex permission levels and deep system structure distribution, attackers usually penetrate into the core system through "low-risk behavior chains". Therefore, the key objective of this step is to identify and quantify the attack paths composed of multiple medium- and low-risk behaviors in the graph, and to achieve forward-looking modeling of unknown attack chains in the enterprise without relying on known attack templates.

[0144] This step is the bridge connecting "risk identification" and "security policy generation", and its design logic directly affects the system response ability of the patent. Different from traditional path traversal methods, this step introduces multiple real complexities in the patent scenario, such as "multi-role access control hierarchy", "priority focus on core assets", "context modeling of node behavior jumpiness", etc., with clear technical originality and practical guidance.

[0145] The essence of an attack path is one or more high-risk propagation chains that spread from non-critical nodes (attack entrances) to critical nodes (attack targets). Due to the complexity of the enterprise network, attack chains often do not show obvious characteristics and are even composed of "seemingly normal" low-intensity operations. Therefore, this step adopts the following four-stage modeling strategy:

[0146] The first stage: Construct a potential path graph

[0147] Starting from each non-core node , using breadth-first search (BFS) with limited depth, at the edge risk score above the set threshold , construct all paths from to any path set , each path is represented as a sequence of nodes , and its corresponding edge set is .

[0148] Phase 2: Path scoring function design

[0149] Path scoring function is used to measure the feasibility and concealment of the attacker's lateral penetration along this path. In order to combine the enterprise-specific access control structure, role hierarchy span, and path structure complexity, we propose the following risk function:

[0150]

[0151] where:

[0152] : Edge risk score, from step 2;

[0153] : Role crossing weight, are the role codes of the nodes at both ends of the edge respectively (e.g., 0 for ordinary employees, 2 for security administrators), and this item amplifies the importance of the path of "privilege abuse";

[0154] : Protocol sensitivity coefficient, extract the communication protocol or operation type from (e.g., set a high weight for the remote login protocol and a low weight for ordinary HTTP);

[0155] : Path structure jump penalty term, representing the mean square change rate of the embedding vectors of consecutive nodes in the path, defined as follows:

[0156]

[0157] This item reflects the degree of semantic jump of the nodes in the path. If an attack path has frequent changes in system roles, operation semantics, etc., it is more likely to be an attack path.

[0158] is the adjustment coefficient of the structure jump penalty term, which can be set to a value between 0.3 - 0.5.

[0159] The design of this scoring function reflects three innovative points:

[0160] Introduce It solves the problem that unauthorized jumps cannot be identified solely by connection frequency;

[0161] Introduce It enhances the ability to identify attack channel preferences (such as SSH / RDP);

[0162] Introduce Model the context mutation of the behavior path to prevent the model from overlearning the "stacking of high-risk edges" while ignoring the hidden coherence of the attack.

[0163] The third stage: Path screening and sorting

[0164] For each , retain the top highest-scoring paths that start from it and reach the core node set . If there are structural redundancy behaviors such as node duplication and nesting in the path, the simplest-first principle of structure can be used to remove duplicates (such as giving priority to shorter path lengths and lower hop counts).

[0165] The fourth stage: Path credibility confidence analysis

[0166] For all high-scoring paths, we introduce a structural adversarial perturbation test mechanism, that is, randomly remove the edges that are not on the path in the graph, and re-evaluate the changes. If the path score fluctuation is less than the threshold , then mark this path as a structurally stable path for subsequent policy direct intervention.

[0167] Output

[0168] Output 1: Attack path set , each path is a node sequence;

[0169] Output 2: Path risk score set , sorted in descending order of score.

[0170] This step integrates the structure diagram information in step 1, the edge risk score and node context embedding representation in step 2, and proposes an attack path modeling method that takes into account both structural interpretability and risk forward-looking in the real scenario of enterprise information security management. By comprehensively considering three core risk patterns in enterprise security management: "role span", "communication protocol preference", and "behavior continuity jump", and designing a risk scoring function and a structural perturbation test mechanism, it realizes a highly credible prediction of the lateral attack chain. This solution breaks through the limitation of the existing single-point high-risk strike model, enabling this patent to have the ability to actively identify unknown attack paths under complex organizational system structures.

[0171] Step 4: Generation and Effect Evaluation of Attack Path-Driven Policy Candidate Sets

[0172] This step is based on the attack path set output in Step 3 and the path risk scores , and automatically generates a set of policy candidates for each path. These policy candidate sets provide a series of policy decisions for high-risk behavior nodes or key jump behaviors in the path to prevent the further expansion of the attack path. The core goal of this step is to generate multiple candidate policies based on information such as the path structure, risk scores, and node role characteristics, and quantitatively evaluate the effectiveness of these candidate policies.

[0173] The focus of this step is to generate dynamic and targeted policy candidate sets through the analysis of the path structure, rather than directly reacting to or deploying against attacks. Its ultimate goal is to lay a foundation for subsequent policy deployment and actual execution.

[0174] For each path , this step needs to generate multiple policy candidates and evaluate the effects of these candidate policies. The generation of policies is based on information such as key nodes, cross-node behaviors, and the total risk score of the path. The specific process is as follows:

[0175] 1. Policy Candidate Generation

[0176] Each path corresponds to a set of policy candidates , and each policy represents a protection measure for one or more behavior nodes in the path . We generate policy candidates according to the following criteria:

[0177] Node-level policy: If the behavior risk score of a certain node in the path is relatively high, policies for this node can be generated, such as freezing the account, restricting access rights, etc.;

[0178] Edge-level policy: If a certain edge in the path involves communication with high-risk protocols (such as RDP, SSH) or non-conventional ports, policies for restricting protocol access or port blocking can be generated;

[0179] Path interruption policy: If the path is composed of multiple nodes combined through low-risk behaviors, and there is a relatively high security risk in the "connection" of the middle path (for example, access logs show that a "low-frequency high-privilege user" accesses an "important file"), a policy for disconnecting a certain key edge or enabling strong authentication can be generated.

[0180] Specifically, assume the path , we generate candidate policies for each node , such as:

[0181]

[0182] For an edge , the generated policies may be:

[0183]

[0184] These policy candidates are mainly based on the following considerations:

[0185] High-risk nodes on the path: For example, when the risk score is higher than the threshold, measures are preferentially taken against it;

[0186] Role differences: For example, when multiple permission levels are crossed in the path (such as from an ordinary employee to an administrator), "permission elevation blocking" type policies are preferentially generated;

[0187] Access frequency: For example, if the behavior nodes in a certain path involve frequent access to high-privilege resources, "multi-factor authentication" type policies are generated.

[0188] 2. Policy effect evaluation

[0189] After each policy candidate is generated, its effect needs to be evaluated next. The policy effect evaluation function is defined as the degree of risk reduction of the policy for the path, and is calculated as follows:

[0190]

[0191] Where:

[0192] is the risk score of the path before the policy is applied;

[0193] is the path after the policy is applied.

[0194] When calculating , we use all the nodes and edges on the path to update, considering the node importance, the protocol characteristics of the edges, and the behavior patterns, and evaluate the inhibitory effect of the policy on the attack propagation in the path. When evaluating the policy, the cost of the policy is also considered. For example, some policies (such as full-network traffic encryption) may cause business interruption, and the score will be affected when the cost is too high.

[0195] 3. Policy priority ranking and screening

[0196] After generating all policy candidates and evaluating their effects, this step will screen out the optimal policies according to the following rules:

[0197] Maximizing policy effectiveness: Prioritize those policies that can significantly reduce path risks, i.e., maximize ;

[0198] Balancing cost and benefit: Evaluate the cost of efficient policies and screen out those with low cost and high efficiency.

[0199] Ultimately, each path will correspond to an optimal policy , which is used for subsequent deployment and execution.

[0200] Output

[0201] Output 1: Policy candidate set , the optimal protection policy for each path;

[0202] Output 2: Scoring results of policy candidates , which is used for subsequent decision-making support.

[0203] This step proposes a dynamic policy generation and evaluation method based on attack paths by combining multi-dimensions such as nodes, edge risks, and role information in the path. Different from traditional static protection policies, this method generates specialized protection policies according to the specific structure of the attack path, making the policy design more intelligent and personalized. In enterprise security management, this method can cope with complex and dynamic security threat environments. Especially in scenarios with complex organizations and variable permission levels, it can provide flexible and scalable protection solutions to ensure precise risk control for each path.

[0204] Step 5: Deployment and response of protection policies

[0205] This step is based on the policy set output in Step 4 and the corresponding policy effect scores . It deploys the policies to the actual enterprise security system and monitors the deployment status and protection feedback in real time to achieve the closed-loop implementation of "from identification to response". This step no longer introduces early processing structures such as graph models and embedded features, but completely focuses on the deployment mapping, execution feedback analysis, and priority scheduling around the policy structure itself. Different from the traditional approach of "policy push is deployment", this step introduces policy conflict detection, deployment feedback functions, false blocking rate evaluation mechanisms, etc. to improve the intelligence and controllability of deployment.

[0206] First, for each policy , call the policy deployment mapping function to translate the logical policy into system control commands:

[0207]

[0208] Among them:

[0209] : Policy deployment instruction;

[0210] : API template corresponding to the policy type, such as blocking connection, firewall rule;

[0211] : Parameters such as target user, target service, communication protocol carried in the policy.

[0212] For example:

[0213] If is the access privilege policy for then:

[0214] { "type": "LimitAccess", "target": "user_123", "params": { "new_role": "quarantined"}}

[0215] Is mapped to:

[0216] POST / api / iam / roles / update{ "user_id": "user_123", "role": "quarantined"}

[0217] Then, perform deployment priority sorting on all policies, and the priority function is defined as:

[0218]

[0219] Among them:

[0220] : Policy deployment priority;

[0221] : Risk reduction effect of the policy on the path ;

[0222] : Conflict factor. If conflicts with any policy target in then , otherwise it is .

[0223] According to values, deploy policies in descending order, skip conflicting policies or place them in the manual confirmation queue.

[0224] After each policy is deployed, the system records the status at the deployment interface and installs lightweight monitoring components on the deployment target to collect deployment feedback information. The policy execution feedback function is defined as follows:

[0225]

[0226] Where:

[0227] : Policy deployment feedback score;

[0228] : Whether the policy deployment is successful (success is and failure is );

[0229] : Policy misinterception rate, which is equal to the number of legitimate behavior anomaly alarms generated within 30 minutes after deployment / the number of normal accesses.

[0230] If , the policy will be marked as "rollback candidate" and added to the rollback buffer pool for further processing by the administrator or the system policy manager.

[0231] This step constructs a standardized deployment interface mapping , deployment priority function and execution feedback function starting from the policy structure, realizing dynamic scheduling and quality closed-loop of policy implementation. The innovation lies in that in the deployment stage, not only "whether it is issued" is tracked, but also "whether it is effective and whether there are false positives" is tracked. Combining with the effect prediction during policy generation, it realizes intelligent, controllable and quantitative feedback of deployment execution, and completely supports the last link of the enterprise information security closed-loop protection system proposed in the patent.

[0232] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages: By combining intelligent prediction and simulation, potential security threats are identified in real time, and security policies are dynamically adjusted according to the changes of threats, making up for the static and lagging problems of traditional methods. By constructing a behavior analysis model and attack simulation, not only known attacks can be detected, but also new threats can be identified in real time through adaptive learning. By introducing an efficient data processing and automatic protection adjustment mechanism, the system response speed is greatly improved, ensuring that the enterprise information security protection can intervene effectively in real time and prevent the spread of threats.

[0233] The embodiments of the present application also provide an enterprise information security management system based on artificial intelligence, as shown in Figure 2 and includes:

[0234] A data modeling module that inputs raw data, where the raw data includes a user permission information set, a network connection record set, and a resource access log set;

[0235] Integrate the raw data into a graph structure with the first row, and construct an attribute vector for the user nodes;

[0236] A risk assessment module that, based on the graph with the first row, performs threat perception and behavioral risk assessment through a graph learning model, and outputs the threat probability of each edge;

[0237] Output an edge risk score set and a node embedding set;

[0238] A path simulation module that, based on the edge risk score set and the node embedding set, combines with the graph with the first row, identifies and quantifies the attack paths composed of multiple medium and low-risk behaviors in the graph, and generates an attack path set and a path risk score set;

[0239] A policy generation module that, based on the attack path set and the path risk score, generates a candidate set of protection policies for each path, evaluates the effectiveness of the protection policies to obtain a scoring result of the protection policies, and sorts the protection policies according to the scoring result;

[0240] A policy deployment module that, based on the candidate set of protection policies and the scoring result of the corresponding protection policies, deploys the protection policies, monitors the deployment status and protection feedback. After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

[0241] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages: By using cutting-edge technologies such as deep learning, adaptive model optimization, and large-scale data analysis, the present invention provides an intelligent security system with dynamic and adaptive protection, which can continuously monitor, predict, and respond to various threats in a complex and dynamically changing enterprise network environment.

[0242] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. An enterprise information security management method based on artificial intelligence, characterized in that, Including: S1: Input the original data, where the original data includes a user permission information set, a network connection record set, and a resource access log set; Integrate the original data into a graph structure with the first row, and construct an attribute vector for the user node; S2: Based on the graph with the first row, perform threat perception and behavior risk assessment through a graph learning model, and output the threat probability of each edge; The learning steps of the graph learning model include node embedding generation, edge representation construction, and edge-level risk prediction; The node embedding generation aggregates information through graph convolution with structural normalization; The edge representation construction is completed by concatenating the node embeddings at both ends and the edge attributes; The edge-level risk prediction obtains a risk score by inputting the edge representation vector into a single-layer perceptron; Output the edge risk score set and the node embedding set; S3: Based on the edge risk score set and the node embedding set, combined with the graph with the first row, identify and quantify the attack paths composed of multiple medium and low-risk behaviors in the graph, and generate an attack path set and a path risk score set; The generation steps are as follows: Starting from each non-core node, use breadth-first search with a limited depth to construct a set of potential attack paths on the premise that the edge risk score is higher than the set threshold; Design a path scoring function for measuring the feasibility and concealment of the attacker's lateral penetration along this path; For each node, retain the top K paths with the highest scores starting from it and reaching the core node set; Design a structure perturbation test mechanism to perform path credibility confidence analysis on the high-scoring paths; S4: Based on the attack path set and the path risk score, generate a candidate set of protection strategies for each path, evaluate the effect of the protection strategies to obtain the scoring results of the protection strategies, and sort the protection strategies according to the scoring results; The generation of the protection strategy generates corresponding protection strategies according to the risk score, path behavior, and access frequency according to the preset; The evaluation is completed by calculating the difference in the risk score of the path before and after applying the corresponding protection strategy; The sorting is carried out according to the preset rules; the preset rules include maximizing the strategy effect and balancing cost and benefit; S5: Based on the candidate set of protection strategies and the scoring results of the corresponding protection strategies, deploy the protection strategies, and monitor the deployment status and protection feedback; The deployment includes the following steps: Call the policy deployment mapping function to translate the logical policy into a system control command; Sort all policies according to the deployment priority, deploy them in descending order according to the priority, skip conflicting policies or place them in the manual confirmation queue; After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

2. The enterprise information security management method based on artificial intelligence according to claim 1, wherein The node set of the graph with the first row contains three types of nodes: users, hosts, and resources; The edge set of the graph with the first row represents the operation behavior of the user on other nodes; The edge attributes of the graph with the first row represent the behavior details, and the node attributes of the graph with the first row represent the behavior identity and frequency.

3. The enterprise information security management method based on artificial intelligence according to claim 1, wherein In the edge representation construction, a role difference factor is introduced to measure the cross-level access intensity between the user and the target, and the role difference factor takes the L1 norm, representing the absolute value of the role level difference.

4. The enterprise information security management method based on artificial intelligence according to claim 1, wherein The path scoring function is obtained by inputting the edge risk score into a single-layer perceptron, performing a linear transformation, and then compressing the result of the linear transformation through a Sigmoid function.

5. The enterprise information security management method based on artificial intelligence according to claim 4, wherein A role crossing weight is introduced in the path scoring function, and the role crossing weight is calculated through the role encodings of the nodes at both ends of the edge.

6. The enterprise information security management method based on artificial intelligence according to claim 4, wherein A path structure jump penalty term is introduced in the path scoring function, and the path structure jump penalty term represents the mean square change rate of the continuous node embedding vectors in the path, highlighting the covert coherence of the attack.

7. The enterprise information security management method based on artificial intelligence according to claim 1, characterized in that The structure perturbation test mechanism randomly removes the edges not on the path in the graph and re-evaluates the change in the path score. If the path score fluctuation is less than the threshold, the path is marked as a structurally stable path.

8. The method for enterprise information security management based on artificial intelligence according to claim 1, wherein, The generation of the protection strategy includes the following rules: Node-level strategy: If the behavior risk score of a certain node in the path is high, a strategy for this node can be generated, including freezing the account and restricting access rights. Edge-level strategy: If a certain edge in the path involves communication with a high-risk protocol or an unconventional port, a strategy for restricting protocol access or blocking the port is generated. Path interruption strategy: If the path is composed of multiple nodes combined through low-risk behaviors and there is a high security risk in the "connection" of the middle path, a strategy for disconnecting a certain critical edge or enabling strong authentication is generated.

9. An enterprise information security management system based on artificial intelligence, characterized in that, Including: A data modeling module, which is configured to input the original data, and the original data includes a user permission information set, a network connection record set, and a resource access log set; Integrate the original data into a first-order graph structure and construct an attribute vector for the user nodes; A risk assessment module, which is configured to perform threat perception and behavior risk assessment based on the first-order graph through a graph learning model, and output the threat probability of each edge; the learning steps of the graph learning model include node embedding generation, edge representation construction, and edge-level risk prediction; the node embedding generation performs information aggregation through graph convolution with structural normalization; the edge representation construction is completed by concatenating the embeddings of the two end nodes and the edge attributes; the edge-level risk prediction obtains a risk score by inputting the edge representation vector into a single-layer perceptron; output an edge risk score set and a node embedding set; A path simulation module, which is configured to identify and quantify the attack paths composed of multiple medium- and low-risk behaviors in the graph based on the edge risk score set and the node embedding set, in combination with the first-order graph, and generate an attack path set and a path risk score set; the generation steps are as follows: starting from each non-core node, using breadth-first search with a limited depth, construct a set of potential attack paths on the premise that the edge risk score is higher than the set threshold; design a path scoring function for measuring the feasibility and covertness of the attacker's lateral penetration along the path; for each node, retain the top K paths with the highest scores starting from it and reaching the core node set; design a structure perturbation test mechanism to perform path credibility confidence analysis on the high-scoring paths. A policy generation module, which is configured to generate a candidate set of protection policies for each path based on an attack path set and a path risk score, evaluate the effectiveness of the protection policies to obtain a scoring result of the protection policies, and sort the protection policies according to the scoring result; the generation of the protection policies generates corresponding protection policies according to risk scores, path behaviors, and access frequencies according to a preset; the evaluation is completed by calculating the difference in risk scores of the path before and after applying the corresponding protection policy; the sorting is performed according to a preset rule; the preset rule includes maximizing policy effectiveness and balancing costs and benefits; A policy deployment module, which is configured to deploy protection policies based on a candidate set of protection policies and the scoring results of the corresponding protection policies, and monitor the deployment status and protection feedback; the deployment includes the following steps: Call a policy deployment mapping function to translate the logical policy into a system control command; Sort all policies according to the deployment priority, deploy them in descending order of priority, skip conflicting policies or place them in the manual confirmation queue; After the policy deployment is completed, record the deployment target status, and install a lightweight monitoring component on the deployment target to collect deployment feedback information.

Citation Information

Patent Citations

  • Cross-domain network security policy automatic generation and protection policy collaboration method and system

    CN119449428A

  • Software supply chain risk detection protection method and system

    CN119808082A