Dynamic security risk assessment and intelligent response system and method based on AI

The AI-driven dynamic security risk assessment system addresses the limitations of traditional security systems by enabling real-time, adaptive responses to complex network attacks, improving threat recognition and response efficiency.

CN120321033AActive Publication Date: 2025-07-15CCCC SOUTH CHINA SURVEY & MAPPING TECH CO LTD +1

Patent Information

Application Number
CN202510779614.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-15
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

When the prior art faces complex cyber attacks, the response mechanism is delayed or incomplete, making it difficult to deal with multiple attack combinations, and it is easy to cause data inconsistency or error accumulation in real-time data processing.

Method used

Using AI-based dynamic security risk assessment and intelligent response system, data is collected through multi-dimensional sensors, preprocessing and deep neural network analysis, real-time threat intelligence is generated, risk determination thresholds are dynamically adjusted, and hierarchical response measures are generated, combining adaptive response modules and communication modules for real-time optimization.

Benefits of technology

Real-time identification and efficient response to complex threats is achieved, and the accuracy and response speed of security protection are improved, ensuring efficient processing capabilities during high-frequency attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321033A_ABST
    Figure CN120321033A_ABST
Patent Text Reader

Abstract

The invention provides a dynamic security risk assessment and intelligent response system and method based on AI, relates to the field of dynamic security risk assessment and intelligent response, and improves the accuracy and response speed of security protection. The method comprises the following steps: firstly, collecting multi-dimensional security data, carrying out data preprocessing by utilizing an AI technology, and outputting a structured security data stream; then analyzing the data flow based on an AI model, identifying cross-dimension attack features, generating real-time threat intelligence, updating a risk judgment threshold value, generating a security assessment report, automatically generating and executing hierarchical response measures according to the assessment report, feeding back a response execution effect, performing dynamic adjustment, and generating a new security assessment report; and finally, automatically selecting a data transmission mode and rate according to the new security assessment report, and adjusting the acquisition frequency of the sensor. According to the method, through dynamic optimization and an intelligent response mechanism, the recognition and defense capability on complex attacks is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of dynamic security risk assessment and intelligent response, and specifically to an AI-based dynamic security risk assessment and intelligent response system and method. Background Art

[0002] In the current network security environment, with the continuous development of information technology, the ways and means of network attacks have become increasingly diversified, the attack frequency has been increasing, and the attack scale has gradually expanded. Network security has become a major challenge faced by countries, enterprises, and individuals. Traditional security protection technologies mainly rely on methods such as static firewalls and intrusion detection systems. Although these technologies can prevent common attacks to a certain extent, with the continuous evolution of attack technologies, the response capabilities of these methods have become increasingly insufficient.

[0003] With the development of AI technology, intelligent security protection has gradually become an effective way to solve security problems. Traditional security protection methods usually rely on manually setting rules, resulting in large blind spots when facing new and unknown attacks. In contrast, existing technologies can automatically identify and respond to various complex security threats by collecting and analyzing multi-dimensional data in real time, greatly improving the accuracy and response speed of security protection.

[0004] However, the response mechanisms proposed by existing technologies cannot quickly respond to complex attack patterns in some cases. In the face of large-scale attacks or combinations of multiple attacks, the response mechanisms may show delays or incompleteness, and when facing real-time data, data inconsistency or error accumulation is still likely to occur. Summary of the Invention

[0005] In order to solve the technical problems mentioned in the current background art, the present invention proposes an AI-based dynamic security risk assessment and intelligent response system and method.

[0006] For this reason, the technical solution adopted by the present invention is as follows: An AI-based dynamic security risk assessment and intelligent response system, characterized in that the system includes: A multi-dimensional intelligent module, which collects multi-dimensional security data in real time through sensor groups deployed in network nodes, terminal devices, and physical environments, preprocesses the multi-dimensional security data based on AI-based intelligent perception technology, and outputs a structured security data stream; A risk assessment module, which analyzes the structured security data stream through an AI model, adjusts the weights of the components of the structured security data stream, and identifies cross-dimensional attack feature association patterns based on a deep neural network, generates real-time threat intelligence, updates the risk determination threshold according to the real-time threat intelligence, and generates a security assessment report including a risk level and a threat type; An adaptive intelligent response module generates and executes hierarchical response measures according to the security assessment report. The hierarchical response measures include early warning prompts, access restrictions, and system isolation, and the response execution effect is fed back to the risk assessment module for dynamic adjustment to generate a new security assessment report. A communication module automatically selects a data transmission mode and transmission rate based on the structured security data stream and the new security assessment report, synchronizes the data transmission mode and transmission rate to the multi-dimensional intelligent module, and dynamically adjusts the acquisition frequency.

[0007] Furthermore, the multi-dimensional security data includes network traffic data, user behavior data, and device status data. The network traffic data is collected by a network node sensor group deployed on each node in the network. The user behavior data is collected by a terminal device sensor group deployed on the terminal device. The device status data is collected by a physical environment sensor group deployed in the network physical environment.

[0008] Furthermore, the preprocessing includes data cleaning and feature extraction and fusion. The data cleaning includes standardization, missing value filling, and anomaly detection. The standardization scales the multi-dimensional security data to the same scale. The missing value filling fills the missing data in the acquisition process by interpolation method. The anomaly detection detects and removes the outliers in the multi-dimensional security data through the isolation forest algorithm. The cleaned multi-dimensional security data is output through the data cleaning. Feature extraction is performed on the cleaned multi-dimensional security data through an AI algorithm, and at the same time, the extracted features are fused through the weighted average method to output a structured security data stream.

[0009] Furthermore, the adjustment formula for the weight is:

[0010] where is the updated weight; is the original weight; α is the learning rate, and the value is ; is the weight calculated according to the AI model; the original weight, that is, the output of the AI model, is obtained by calculating the gradient of the weight of the loss function, and the formula is:

[0011] where L is the value of the loss function; is the i-th feature; is the predicted value of the model for the i-th feature; is the hyperparameter of the regularization term, which controls the impact of regularization on the loss function; is the weight of the j-th parameter in the model; N is the number of features; M is the number of model parameters.

[0012] Furthermore, the real-time threat intelligence includes attack type, attack severity, attack pattern, and attack source. The formula for adjusting the risk determination threshold is:

[0013] where, is the updated risk determination threshold; is the original risk determination threshold; is the real-time threat intelligence score; is the historical threat intelligence score; α is the learning rate, and the value is ; The risk levels are divided into low, medium, and high levels, which are divided according to the score of the real-time threat intelligence and the updated risk determination threshold. When the risk level is low. When and the risk level is medium. When the risk level is high. The threat types are divided into DDoS attacks, malware, and SQL injection, and the characteristics of the threat types are described. The security assessment report is output through the API interface.

[0014] Furthermore, the warning prompt is triggered when the risk level is low and a warning notice is issued. The restricted access is triggered when the risk level is medium. Specifically, specific ports and protocols are blocked. The system isolation is adopted when the risk level is high, and the attacked device and network segment are automatically isolated. The execution of the hierarchical response measures is automated, and through the integration of hardware and software, the predetermined response measures are automatically triggered.

[0015] Furthermore, the dynamic adjustment adjusts the risk determination threshold and the weights of the components of the structured security data stream according to the feedback response effect, and generates a new security assessment report. The new security assessment report includes the optimized risk level and threat type.

[0016] Furthermore, the transmission mode includes a regular transmission mode and an encrypted transmission mode. The conventional transmission mode is adopted when the risk level is low or medium, and the encrypted transmission mode is adopted when the risk level is high; According to the adjustment of the transmission mode, the transmission rate is dynamically adjusted. The transmission rate includes high frequency and low frequency. In the conventional transmission mode, the high-frequency transmission rate is selected. In the encrypted transmission mode, the low-frequency transmission rate is selected; According to the transmission mode and transmission rate, a transmission strategy instruction set is generated, including the transmission mode type, transmission rate, and recommended acquisition frequency range. Based on the transmission strategy instruction set, the acquisition frequency of each sensor group is adjusted by the internal acquisition scheduling controller.

[0017] An AI-based dynamic security risk assessment and intelligent response method, characterized in that the method includes: Real-time collection of multi-dimensional security data through a sensor group, and based on AI-based intelligent perception technology, preprocessing the multi-dimensional security data to output a structured security data stream; Analyze the structured security data stream through an AI model, adjust the weights of the components of the structured security data stream, and identify cross-dimensional attack feature association patterns based on a deep neural network to generate real-time threat intelligence. Update the risk determination threshold according to the real-time threat intelligence and generate a security assessment report; According to the security assessment report, generate hierarchical response measures and execute them, and feedback the response execution effect to the risk assessment module for dynamic adjustment to generate a new security assessment report; Based on the structured security data stream and the new security assessment report, automatically select the data transmission mode and transmission rate, synchronize the data transmission mode and transmission rate to the multi-dimensional intelligent module, and dynamically adjust the acquisition frequency.

[0018] Compared with the prior art, the advantages of the present invention are: 1. Real-time and intelligence of the adaptive response mechanism: The present invention designs an adaptive intelligent response module that can automatically generate and execute hierarchical response measures according to the risk assessment report. In addition, the response effect feedback mechanism can dynamically adjust the risk assessment model and the weights of the components of the structured data stream according to the execution effect to achieve more accurate risk assessment and response.

[0019] 2. Efficient cross-dimensional threat identification and assessment: Through in-depth analysis of the structured security data stream by a deep neural network, it is possible to identify and process cross-dimensional attack feature association patterns, generate real-time threat intelligence, improve the system's ability to identify complex attacks, and also adaptively respond to different types of security threats by dynamically adjusting the risk determination threshold.

[0020] 3. Real-time Dynamic Adjustment and Optimization: The present invention performs real-time optimization on multi-dimensional security data streams through a dynamic adjustment mechanism, combines different transmission modes and transmission rates to ensure the security and efficiency of data transmission. This dynamic optimization not only improves the stability of data transmission but also ensures efficient processing capabilities in the face of high-frequency attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0022] Figure 1 It is a flowchart of the dynamic security risk assessment and intelligent response system of the present invention; Figure 2 It is a flowchart of the multi-dimensional intelligent module of the present invention; Figure 3 It is a flowchart of the risk assessment module of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] To achieve the above objectives, the present invention is implemented through the following technical solutions. The present invention provides an AI-based dynamic security risk assessment and intelligent response system. Please refer to Figures 1 to 3 , the system includes: M1, a multi-dimensional intelligent module, which collects multi-dimensional security data in real time through a sensor group deployed in network nodes, terminal devices, and the physical environment. Based on AI-based intelligent perception technology, it preprocesses the multi-dimensional security data and outputs a structured security data stream. The multi-dimensional intelligent module collects multi-dimensional security data in real time through a sensor group deployed in network nodes, terminal devices, and the physical environment. Based on AI-based intelligent perception technology, it preprocesses the collected multi-dimensional security data and finally outputs a structured security data stream, providing accurate and comprehensive data support for the subsequent risk assessment module and response module.

[0024] The multi-dimensional security data includes network traffic data, user behavior data, and device status data; Network node sensors are deployed on each node in the network to collect network traffic data in real time. In this embodiment, the technologies used include NetFlow, sFlow, and a custom traffic analysis module; Terminal device sensors are deployed on terminal devices to collect user behavior data. In this embodiment, the WMI and SNMP protocols are used; Physical environment sensors are deployed in the cyber-physical environment to collect device status data, and this information helps to determine whether the abnormal behavior of the device is caused by hardware failures; Each sensor is responsible for collecting specific types of data and transmitting the data to the multi-dimensional intelligent module for centralized processing.

[0025] Preprocessing includes data cleaning and feature extraction and fusion. Data cleaning includes standardization, missing value imputation, and anomaly detection; to ensure the consistency of data from different sensors, a standardization method is used to scale the data to the same scale. For missing data that may occur during the acquisition process, an interpolation method is used to fill in the missing values, and the isolation forest algorithm is used to detect and remove outliers in the data; the multi-dimensional security data after cleaning is output through standardization, missing value imputation, and anomaly detection.

[0026] Feature extraction is performed on the multi-dimensional security data after cleaning through AI algorithms to identify potential security features in the data. In this embodiment, the IP address distribution, packet size distribution, and traffic burst characteristics are extracted from the network traffic data; the CPU load change and process behavior pattern characteristics are extracted from the device status data; multi-dimensional security feature data is generated through feature extraction; The multi-dimensional security feature data is fused through the weighted average method to form a unified multi-dimensional data structure, and different types of features are fused into a comprehensive feature vector to output a structured security data stream.

[0027] M2, the risk assessment module, analyzes the structured security data stream through an AI model, adjusts the weights of the components of the structured security data stream, and identifies the cross-dimensional attack feature association pattern based on the deep neural network to generate real-time threat intelligence, updates the risk determination threshold according to the real-time threat intelligence, and generates a security assessment report including the risk level and threat type. The main function of the risk assessment module is to analyze the structured security data stream, use the deep neural network to identify the cross-dimensional attack feature association pattern, generate real-time threat intelligence, and update the risk determination threshold, so as to generate a security assessment report including the risk level and threat type. This process involves dynamic weighted analysis and efficient feature extraction of the structured security data stream to ensure timely and accurate identification of potential threats in the network.

[0028] An AI model analyzes the structured security data stream to generate a weight adjustment factor, which dynamically updates the weights according to the contribution degree of each data dimension in the risk assessment. The formula is:

[0029] where, is the updated weight; is the original weight; α is the learning rate, with a value of ; is the weight calculated according to the AI model; the weight output of the AI model is carried out by calculating the gradient of the loss function with respect to the weight, and the formula is:

[0030] where L is the value of the loss function; is the i-th feature; is the predicted value of the model for the i-th feature; is the hyperparameter of the regularization term, controlling the impact of regularization on the loss function; is the weight of the j-th parameter in the model; N is the number of features; M is the number of model parameters; The learning rate α is dynamically adjusted, and is adaptively optimized based on historical data and the performance feedback of the AI model. In this embodiment, in the initial stage, a relatively large learning rate is set to quickly adjust the weight, and after convergence, the learning rate is gradually reduced to make the AI model tend to be stable.

[0031] Through the learning of the deep neural network, the association between attack behaviors and each data dimension is identified, and real-time threat intelligence is generated. The real-time threat intelligence includes attack type, attack severity, attack pattern, and attack source; The attack type is the attack type in the predicted result output by the model, including DDoS attack, malware, and SQL injection; The attack severity is that, according to the analysis result, the threat intelligence will attach the severity level (high, medium, low) of the attack; The attack pattern is that, according to the feature recognition result, the threat intelligence will describe the pattern of the attack behavior; The attack source is that, in some cases, the threat intelligence may also contain detailed information such as the IP address of the attack source, attack means, and attack target.

[0032] According to the generated real-time threat intelligence, the risk determination threshold is dynamically updated. In this embodiment, when a high-risk DDoS attack is detected, the model will increase the risk determination threshold for this type of attack, thereby enhancing the system's response ability to DDoS attacks; the risk determination threshold adjustment formula is:

[0033] where is the updated risk determination threshold; is the original risk determination threshold; is the real-time threat intelligence score; is the historical threat intelligence score; α is the learning rate, with a value of ; Generate a security assessment report based on real-time threat intelligence and updated risk determination thresholds, including risk levels and threat types; The risk level is evaluated based on the current threat intelligence score and the updated threshold. The risk levels are divided into low, medium, and high levels to help decision-makers judge the severity of the threat; When the risk level is low; When and the risk level is medium; When the risk level is high; The threat types include DDoS attacks, malware, SQL injection, and describe the threat characteristics and possible impacts; The generated security assessment report is in JSON or XML format and is output through an API interface for easy interaction with administrators.

[0034] M3, the Adaptive Intelligent Response Module, generates and executes hierarchical response measures based on the security assessment report. The hierarchical response measures include warning prompts, access restrictions, and system isolation, and feedback the response execution effect to the risk assessment module for dynamic adjustment to generate a new security assessment report. The Adaptive Intelligent Response Module receives a security assessment report containing risk levels and threat types from the risk assessment module. The report will indicate the type of the current threat and the risk level (low, medium, high); based on the content of the security assessment report, determine the intensity of the response measures, including warning prompts, access restrictions, and system isolation; For low-risk threats, generate a warning prompt, which includes sending warning notifications to administrators and the security team, indicating the existence of potential threats, and suggesting further monitoring and manual checks. The warning measures do not affect the normal operation of the network. The warning prompts are SMS, emails, and warning notifications on the internal security dashboard. The warning information includes key information such as threat types, occurrence times, and affected scopes; For medium-risk threats, adjust to restrict access. This response measure will implement access control on specific IP addresses, ports, and protocols to prevent suspicious traffic from entering the network and reduce the potential attack surface. The access restriction is specifically to use firewall policies or IP blocking technologies based on blacklists to restrict network access to suspicious IPs, or block specific ports and protocols; For high-risk threats, take system isolation measures. This response measure will automatically isolate the attacked device or network segment to prevent the spread of the attack and protect the security of critical systems. The system isolation is specifically to disconnect the affected device from the network or isolate it through a virtual local area network (VLAN) to ensure that the system will not be further attacked.

[0035] The execution of hierarchical response measures is fully automated. Through the integration with hardware and software such as network devices, firewalls, and traffic monitoring systems, it automatically triggers predefined protection behaviors. This function ensures that after a threat is detected, the response measures can be executed quickly and efficiently. After the response measures are executed, feedback data is collected in real time, including information such as network traffic, changes in device status, and whether access restrictions are effective. This data is fed back into the risk assessment module as the basis for adjusting the security assessment report. The risk assessment module adjusts the risk determination threshold and the weights of the components of the structured security data stream according to the feedback response effect. In this embodiment, if certain attack patterns are often misjudged as low risk, the system will adjust the sensitivity to this type of threat through the feedback mechanism to make it more accurate. Based on the adjustment of the risk determination threshold and the weights of the components of the structured security data stream, the risk assessment module generates a new security assessment report, which reflects the optimized risk level and threat type according to the feedback.

[0036] M4, the communication module, based on the structured security data stream and the new security assessment report, automatically selects the data transmission mode and transmission rate, synchronizes the data transmission mode and transmission rate to the multi-dimensional intelligent module, and dynamically adjusts the acquisition frequency. The transmission modes include the normal transmission mode and the encrypted transmission mode. In the case of low risk, the communication module selects the normal data transmission protocol. This mode has a lower transmission delay and a higher data transmission rate, and is suitable for the transmission of non-sensitive data. In the case of high risk, the communication module will automatically switch to the encrypted transmission channel. This mode can ensure the security of data and prevent man-in-the-middle attacks and data leakage during data transmission.

[0037] According to the selection of the transmission mode, the communication module dynamically adjusts the data transmission rate. In the normal transmission mode, a high-frequency transmission rate is selected to improve data transmission efficiency. In the encrypted transmission mode, a low-frequency transmission rate is selected to avoid network congestion and performance degradation. The adjustment of the transmission rate is based on the real-time monitoring of network traffic to ensure transmission stability and timeliness, and to avoid data loss during network congestion.

[0038] After determining the transmission mode and transmission rate, the communication module immediately generates a transmission policy instruction set, which includes the transmission mode type, transmission rate, and recommended acquisition frequency range. After receiving the transmission policy instruction set, the multi-dimensional intelligent module dynamically adjusts the acquisition frequency of each sensor group through the internal acquisition scheduling controller.

[0039] The dynamic security risk assessment and intelligent response method based on AI is characterized in that the method includes: Real-time collect multi-dimensional security data through a sensor group, and based on AI-based intelligent perception technology, preprocess the multi-dimensional security data to output a structured security data stream; Analyze the structured security data stream through an AI model, adjust the weights of the components of the structured security data stream, and identify cross-dimensional attack feature association patterns based on a deep neural network to generate real-time threat intelligence. Update the risk determination threshold according to the real-time threat intelligence and generate a security assessment report; Generate and execute hierarchical response measures according to the security assessment report, and feedback the response execution effect to the risk assessment module for dynamic adjustment to generate a new security assessment report; Based on the structured security data stream and the new security assessment report, automatically select the data transmission mode and transmission rate, synchronize the data transmission mode and transmission rate to the multi-dimensional intelligent module, and dynamically adjust the acquisition frequency.

[0040] The AI-based dynamic security risk assessment and intelligent response system and method proposed by the present invention can realize real-time identification and response to complex security threats through multi-dimensional data collection, deep neural network analysis and adaptive response mechanism. The present invention improves the processing ability and response speed in a complex attack environment through efficient data cleaning, feature extraction and fusion, and real-time dynamic adjustment and optimization, especially in terms of data quality, threat assessment accuracy and response timeliness, and has significant advantages compared with the prior art.

[0041] In summary, by combining advanced artificial intelligence technology with security risk assessment methods, the present invention not only solves the problems of data cleaning and response delay in the prior art, but also realizes in-depth mining and real-time response to multi-dimensional security data, significantly improving the accuracy and reliability of security protection. The present invention can effectively cope with various complex network security threats and has a wide range of application prospects.

[0042] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An AI-based dynamic security risk assessment and intelligent response system, characterized in that, The system includes: A multi-dimensional intelligent module that, through a sensor group deployed in network nodes, terminal devices, and the physical environment, collects multi-dimensional security data in real time, and based on AI-based intelligent perception technology, preprocesses the multi-dimensional security data and outputs a structured security data stream; A risk assessment module that analyzes the structured security data stream through an AI model, adjusts the weights of the components of the structured security data stream, and based on a deep neural network, identifies cross-dimensional attack feature association patterns, generates real-time threat intelligence, updates the risk determination threshold according to the real-time threat intelligence, and generates a security assessment report including a risk level and a threat type; An adaptive intelligent response module that, according to the security assessment report, generates and executes hierarchical response measures, which include early warning prompts, access restrictions, and system isolation, and feeds back the response execution effect to the risk assessment module for dynamic adjustment to generate a new security assessment report; A communication module that, based on the structured security data stream and the new security assessment report, automatically selects a data transmission mode and a transmission rate, synchronizes the data transmission mode and the transmission rate to the multi-dimensional intelligent module, and dynamically adjusts the acquisition frequency.

2. The AI-based dynamic security risk assessment and intelligent response system according to claim 1, wherein The multi-dimensional security data includes network traffic data, user behavior data, and device status data. The network traffic data is collected through a network node sensor group deployed on each node in the network. The user behavior data is collected through a terminal device sensor group deployed on the terminal device. The device status data is collected through a physical environment sensor group deployed in the network physical environment.

3. The AI-based dynamic security risk assessment and intelligent response system according to claim 2, characterized in that, The preprocessing includes data cleaning and feature extraction and fusion. The data cleaning includes standardization, missing value filling, and anomaly detection. The standardization scales the multi-dimensional security data to the same scale. The missing value filling fills the missing data in the acquisition process through interpolation. The anomaly detection detects and eliminates outliers in the multi-dimensional security data through the isolation forest algorithm. The cleaned multi-dimensional security data is output through the data cleaning. Feature extraction is performed on the cleaned multi-dimensional security data through an AI algorithm, and at the same time, the extracted features are fused through the weighted average method to output a structured security data stream.

4. The AI-based dynamic security risk assessment and intelligent response system according to claim 3, characterized in that, The adjustment formula for the weight is: Among them, is the updated weight; is the original weight; α is the learning rate, and its value is ; is the weight calculated according to the AI model; the original weight, that is, the output of the AI model, is obtained by calculating the gradient of the loss function with respect to the weight, and the formula is: Among them, L is the value of the loss function; is the i-th feature; is the predicted value of the model for the i-th feature; is the hyperparameter of the regularization term, controlling the influence of regularization on the loss function; is the weight of the j-th parameter in the model; N is the number of features; M is the number of model parameters.

5. The AI-based dynamic security risk assessment and intelligent response system according to claim 4, wherein The real-time threat intelligence includes attack type, attack severity, attack mode, and attack source. The adjustment formula for the risk determination threshold is: Among them, is the updated risk determination threshold; is the original risk determination threshold; is the real-time threat intelligence score; is the historical threat intelligence score; α is the learning rate, and the value is ; The risk level is divided into low, medium, and high levels, which are divided according to the score of the real-time threat intelligence and the updated risk determination threshold. When the risk level is low When and the risk level is medium, When the risk level is high; The threat type is divided into DDoS attacks, malware, and SQL injection, and the characteristics of the threat type are described. The security assessment report is output through an API interface.

6. The AI-based dynamic security risk assessment and intelligent response system according to claim 5, wherein The early warning prompt is triggered when the risk level is low and a warning notice is issued. The access restriction is triggered when the risk level is medium. Specifically, specific ports and protocols are blocked. The system isolation is adopted when the risk level is high, and the attacked device and network segment are automatically isolated. The implementation of the hierarchical response measures is automated. Through the integration of hardware and software, predefined response measures are automatically triggered.

7. The AI-based dynamic security risk assessment and intelligent response system according to claim 6, characterized in that, The dynamic adjustment adjusts the risk determination threshold and the weights of the components of the structured security data stream according to the feedback of the response effect, and generates a new security assessment report. The new security assessment report includes the optimized risk level and threat type.

8. The AI-based dynamic security risk assessment and intelligent response system according to claim 7, characterized in that, The transmission modes include the regular transmission mode and the encrypted transmission mode. The regular transmission mode is adopted when the risk level is low or medium, and the encrypted transmission mode is adopted when the risk level is high. According to the adjustment of the transmission mode, the transmission rate is dynamically adjusted. The transmission rate includes high frequency and low frequency. In the regular transmission mode, the high-frequency transmission rate is selected. In the encrypted transmission mode, the low-frequency transmission rate is selected. According to the transmission mode and transmission rate, a transmission policy instruction set is generated, including the transmission mode type, transmission rate, and recommended acquisition frequency range. Based on the transmission policy instruction set, the acquisition frequency of each sensor group is adjusted by the internal acquisition scheduling controller.

9. AI-based dynamic security risk assessment and intelligent response method, characterized in that, The method includes: Real-time collecting multi-dimensional security data through a sensor group, preprocessing the multi-dimensional security data based on AI-based intelligent perception technology, and outputting a structured security data stream. Analyzing the structured security data stream through an AI model, adjusting the weights of the components of the structured security data stream, identifying the cross-dimensional attack feature association pattern based on a deep neural network, generating real-time threat intelligence, updating the risk determination threshold according to the real-time threat intelligence, and generating a security assessment report. According to the security assessment report, generating and executing hierarchical response measures, and feeding back the response execution effect to the risk assessment module for dynamic adjustment to generate a new security assessment report. Based on the structured security data stream and the new security assessment report, automatically selecting the data transmission mode and transmission rate, synchronizing the data transmission mode and transmission rate to the multi-dimensional intelligent module, and dynamically adjusting the acquisition frequency.

Citation Information

Patent Citations

  • Industrial control network intelligent safety monitoring and early warning method and system

    CN119402244A

  • Network data risk assessment system for computer

    CN119449432A

  • Distributed photovoltaic system adaptive information physical security risk assessment method and system

    CN119918934A

  • Information security risk assessment whole-process management system

    CN119939591A

  • An AI and ML-based system for accurate and efficient cybersecurity risk assessment solutions.

    DE202024104310U1

Cited By

  • AI dynamic secure transmission system based on SASE framework

    CN120811744A

  • An AI dynamic security transmission system based on a SASE framework

    CN120811744B

  • Intelligent management system and method for full life cycle of ship equipment based on Internet of Things

    CN120822944A

  • Internet of things based ship equipment whole life cycle intelligent management system and method

    CN120822944B

  • Threat detection response agent security protection method and system based on terminal deployment

    CN120880798A