AI-based dynamic security risk assessment and intelligent response system and method
Through the AI-based dynamic security risk assessment and intelligent response system, multi-dimensional data is collected and analyzed in real time, real-time threat intelligence is generated and adaptive responses are made, which solves the delay and error problems of traditional security protection in the face of complex attacks and realizes efficient and accurate network security protection.
Patent Information
- Application Number
- CN202510779614.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-06-12
AI Technical Summary
When facing complex network attacks, the response mechanism of existing technologies may be delayed or incomplete, and it is easy to cause data inconsistency or error accumulation in real-time data processing. Traditional security protection methods have blind spots when facing unknown attacks.
An AI-based dynamic security risk assessment and intelligent response system is adopted. Data is collected in real time through multi-dimensional intelligent modules, and AI models are used for data preprocessing and risk assessment to generate real-time threat intelligence. Tiered response measures are adaptively generated, combined with dynamic adjustment of transmission modes and rates to achieve adaptive response.
It achieves real-time identification and efficient response to complex network threats, improves the accuracy and response speed of security protection, and can dynamically adjust risk assessment and response to adapt to different types of security threats.
Smart Images

Figure CN120321033B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of dynamic security risk assessment and intelligent response, and specifically to an AI-based dynamic security risk assessment and intelligent response system and method. Background Art
[0002] In the current network security environment, with the continuous development of information technology, the methods and means of network attacks are becoming increasingly diverse, the frequency of attacks is increasing, and the scale of attacks is gradually expanding. Network security has become a major challenge facing countries, enterprises and individuals. Traditional security protection technologies mainly rely on static firewalls, intrusion detection systems and other methods. Although these technologies can prevent common attacks to a certain extent, with the continuous evolution of attack technologies, the response capabilities of these methods are becoming increasingly insufficient.
[0003] With the development of AI technology, intelligent security protection has gradually become an effective way to solve security problems. Traditional security protection methods usually rely on manually set rules, resulting in large blind spots when facing new and unknown attacks. In contrast, existing technologies can automatically identify and respond to various complex security threats by collecting and analyzing multi-dimensional data in real time, greatly improving the accuracy and response speed of security protection.
[0004] However, the response mechanisms proposed by existing technologies are unable to quickly respond to complex attack patterns in some cases. In situations where the attack scale is large or there are multiple attack combinations, the response mechanism may show delays or incompleteness, and when faced with real-time data, it is still easy to cause data inconsistency or error accumulation. Summary of the Invention
[0005] In order to solve the technical problems mentioned in the current background technology, the present invention proposes an AI-based dynamic security risk assessment and intelligent response system and method.
[0006] To this end, the technical solution adopted in the present invention is as follows:
[0007] The AI-based dynamic security risk assessment and intelligent response system is characterized in that the system includes:
[0008] The multi-dimensional intelligent module collects multi-dimensional security data in real time through a group of sensors deployed in network nodes, terminal devices, and the physical environment. Based on AI-based intelligent perception technology, it pre-processes the multi-dimensional security data and outputs a structured security data stream.
[0009] a risk assessment module that analyzes the structured security data stream using an AI model, adjusts the weights of the components of the structured security data stream, identifies cross-dimensional attack feature correlation patterns based on a deep neural network, generates real-time threat intelligence, updates risk determination thresholds based on the real-time threat intelligence, and generates a security assessment report that includes risk levels and threat types;
[0010] An adaptive intelligent response module generates and executes graded response measures based on the security assessment report. The graded response measures include early warning prompts, access restrictions, and system isolation. The response execution results are fed back to the risk assessment module for dynamic adjustment and generation of a new security assessment report.
[0011] The communication module automatically selects a data transmission mode and a transmission rate based on the structured security data stream and the new security assessment report, synchronizes the data transmission mode and the transmission rate to the multi-dimensional intelligent module, and dynamically adjusts the collection frequency.
[0012] Furthermore, the multi-dimensional security data includes network traffic data, user behavior data and device status data.
[0013] The network traffic data is collected by a network node sensor group deployed on each node in the network.
[0014] The user behavior data is collected by a terminal device sensor group deployed on the terminal device.
[0015] The device status data is collected by a physical environment sensor group deployed in a network physical environment.
[0016] Furthermore, the preprocessing includes data cleaning and feature extraction and fusion, and the data cleaning includes standardization, missing value filling and anomaly detection.
[0017] The standardization scales the multi-dimensional safety data to the same scale, the missing value filling fills the missing data in the collection process by interpolation, and the anomaly detection detects and removes outliers in the multi-dimensional safety data by using the isolation forest algorithm; and the data cleaning outputs the cleaned multi-dimensional safety data;
[0018] The cleaned multi-dimensional security data is subjected to feature extraction through an AI algorithm, and the extracted features are fused through a weighted average method to output a structured security data stream.
[0019] Furthermore, the weight adjustment formula is:
[0020]
[0021] in, is the updated weight; is the original weight; α is the learning rate, and its value is ; is the weight calculated according to the AI model; the original weight, that is, the output of the AI model, is obtained by calculating the gradient of the loss function with respect to the weight, and the formula is:
[0022]
[0023] Where L is the value of the loss function; is the i-th feature; is the model’s predicted value for the i-th feature; is a hyperparameter of the regularization term, which controls the impact of regularization on the loss function; is the weight of the jth parameter in the model; N is the number of features; and M is the number of model parameters.
[0024] Furthermore, the real-time threat intelligence includes attack type, attack severity, attack mode and attack source.
[0025] The risk determination threshold adjustment formula is:
[0026]
[0027] in, is the updated risk assessment threshold; is the original risk determination threshold; Score real-time threat intelligence; is the historical threat intelligence score; α is the learning rate, and its value is ;
[0028] The risk level is divided into low, medium and high levels according to the score of the real-time threat intelligence and the updated risk determination threshold.
[0029] when When the risk level is low,
[0030] when and When the risk level is medium,
[0031] when When , the risk level is high;
[0032] The threat types are categorized into DDoS attacks, malware, and SQL injection, and the characteristics of the threat types are described.
[0033] The security assessment report is output through the API interface.
[0034] Furthermore, the early warning prompt is triggered when the risk level is low, and a warning notification is issued.
[0035] The access restriction is triggered when the risk level is medium, specifically, blocking specific ports and protocols.
[0036] The system isolation is used when the risk level is high, automatically isolating the attacked device and network segment;
[0037] The execution of the hierarchical response measures is automated, and predetermined response measures are automatically triggered through the integration of hardware and software.
[0038] Furthermore, the dynamic adjustment adjusts the risk determination threshold and the weights of each component of the structured security data flow according to the response effect of the feedback, and generates a new security assessment report.
[0039] The new security assessment report includes optimized risk levels and threat types.
[0040] Furthermore, the transmission mode includes a normal transmission mode and an encrypted transmission mode.
[0041] The conventional transmission mode is adopted when the risk level is low or medium, and the encrypted transmission mode is adopted when the risk level is high;
[0042] According to the adjustment of the transmission mode, the transmission rate is dynamically adjusted, and the transmission rate includes high frequency and low frequency; in the normal transmission mode, the high frequency transmission rate is selected; in the encrypted transmission mode, the low frequency transmission rate is selected;
[0043] According to the transmission mode and transmission rate, a transmission strategy instruction set is generated, including the transmission mode type, transmission rate and recommended acquisition frequency range. Based on the transmission strategy instruction set, the acquisition frequency of each sensor group is adjusted through the internal acquisition scheduling controller.
[0044] The AI-based dynamic security risk assessment and intelligent response method is characterized in that the method includes:
[0045] The sensor group collects multi-dimensional security data in real time, pre-processes the multi-dimensional security data based on AI-based intelligent perception technology, and outputs a structured security data stream;
[0046] Analyze the structured security data stream through an AI model, adjust the weights of the various components of the structured security data stream, and identify cross-dimensional attack feature correlation patterns based on a deep neural network to generate real-time threat intelligence. Update risk assessment thresholds based on the real-time threat intelligence and generate a security assessment report.
[0047] Based on the security assessment report, hierarchical response measures are generated and executed, and the response execution results are fed back to the risk assessment module for dynamic adjustment to generate a new security assessment report;
[0048] Based on the structured security data stream and the new security assessment report, the data transmission mode and transmission rate are automatically selected, the data transmission mode and transmission rate are synchronized to the multi-dimensional intelligent module, and the collection frequency is dynamically adjusted.
[0049] Compared with the prior art, the advantages of the present invention are:
[0050] 1. Real-time and intelligent adaptive response mechanism: This paper designs an adaptive intelligent response module that can automatically generate and execute hierarchical response measures based on risk assessment reports. In addition, the response effect feedback mechanism can dynamically adjust the weights of each component of the risk assessment model and structured data flow based on the execution effect, achieving more accurate risk assessment and response.
[0051] 2. Efficient cross-dimensional threat identification and assessment: Through deep neural networks, structured security data streams are deeply analyzed to identify and process cross-dimensional attack feature correlation patterns, generate real-time threat intelligence, and improve the system's ability to identify complex attacks. By dynamically adjusting risk assessment thresholds, the system can adaptively respond to different types of security threats.
[0052] 3. Real-time dynamic adjustment and optimization: This invention uses a dynamic adjustment mechanism to optimize multi-dimensional security data streams in real time, combining different transmission modes and transmission rates to ensure the security and efficiency of data transmission. This dynamic optimization not only improves the stability of data transmission, but also ensures efficient processing capabilities in the face of high-frequency attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0054] Figure 1 This is a flow chart of the dynamic security risk assessment and intelligent response system of the present invention;
[0055] Figure 2 This is a flow chart of the multi-dimensional intelligent module of the present invention;
[0056] Figure 3 This is a flow chart of the risk assessment module of the present invention. DETAILED DESCRIPTION
[0057] To achieve the above objectives, the present invention is implemented through the following technical solutions. The present invention provides an AI-based dynamic security risk assessment and intelligent response system. Figures 1 to 3 , the system comprises:
[0058] M1, a multi-dimensional intelligent module, collects multi-dimensional security data in real time through sensor groups deployed in network nodes, terminal devices and physical environments, pre-processes multi-dimensional security data based on AI intelligent perception technology, and outputs structured security data streams.
[0059] The multi-dimensional intelligent module collects multi-dimensional security data in real time through a group of sensors deployed in network nodes, terminal devices and physical environments. Based on AI-based intelligent perception technology, the module pre-processes the collected multi-dimensional security data and ultimately outputs a structured security data stream, providing accurate and comprehensive data support for subsequent risk assessment modules and response modules.
[0060] Multi-dimensional security data includes network traffic data, user behavior data, and device status data;
[0061] Network node sensors are deployed on various nodes in the network to collect network traffic data in real time. In this embodiment, the technologies used include NetFlow, sFlow, and a custom traffic analysis module;
[0062] Terminal device sensors are deployed on terminal devices to collect user behavior data. In this embodiment, WMI and SNMP protocols are used;
[0063] Physical environment sensors are deployed in the network's physical environment to collect device status data. This information helps determine whether the device's abnormal behavior is caused by hardware failure;
[0064] Each sensor is responsible for collecting a specific type of data and transmitting the data to the multi-dimensional intelligent module for centralized processing.
[0065] Preprocessing includes data cleaning and feature extraction and fusion. Data cleaning includes standardization, missing value filling and anomaly detection. To ensure the consistency of data display from different sensors, a standardization method is used to scale the data to the same scale. For missing data that may appear during the collection process, interpolation is used to fill the missing values. The isolation forest algorithm is used to detect and eliminate outliers in the data. Standardization, missing value filling and anomaly detection are used to output cleaned multi-dimensional security data.
[0066] The AI algorithm is used to extract features from the cleaned multi-dimensional security data to identify potential security features in the data. In this embodiment, IP address distribution, packet size distribution, and traffic burst features are extracted from network traffic data; CPU load changes and process behavior pattern features are extracted from device status data. Multi-dimensional security feature data is generated through feature extraction.
[0067] Multi-dimensional security feature data is fused through the weighted average method to form a unified multi-dimensional data structure, different types of features are fused into a comprehensive feature vector, and a structured security data stream is output.
[0068] M2, the risk assessment module, analyzes structured security data streams through AI models, adjusts the weights of each component of the structured security data stream, and identifies cross-dimensional attack feature correlation patterns based on deep neural networks to generate real-time threat intelligence. It updates risk judgment thresholds based on real-time threat intelligence and generates a security assessment report that includes risk levels and threat types.
[0069] The main function of the risk assessment module is to analyze structured security data streams, use deep neural networks to identify cross-dimensional attack feature correlation patterns, generate real-time threat intelligence, and update risk judgment thresholds to generate security assessment reports that include risk levels and threat types. This process involves dynamic weighted analysis of structured security data streams and efficient feature extraction to ensure timely and accurate identification of potential threats in the network.
[0070] The AI model analyzes structured security data streams and generates a weight adjustment factor. This factor dynamically updates the weight based on the contribution of each data dimension in the risk assessment. The formula is:
[0071]
[0072] in, is the updated weight; is the original weight; α is the learning rate, and its value is ; The weight is calculated according to the AI model; the weight output of the AI model is calculated by calculating the gradient of the loss function with respect to the weight, and the formula is:
[0073]
[0074] Where L is the value of the loss function; is the i-th feature; is the model’s predicted value for the i-th feature; is a hyperparameter of the regularization term, which controls the impact of regularization on the loss function; is the weight of the jth parameter in the model; N is the number of features; M is the number of model parameters;
[0075] The learning rate α is dynamically adjusted and adaptively optimized based on historical data and performance feedback of the AI model. In this embodiment, in the initial stage, a larger learning rate is set to quickly adjust the weights, and after convergence, the learning rate is gradually reduced to stabilize the AI model.
[0076] Through deep neural network learning, it identifies the correlation between attack behaviors and various data dimensions and generates real-time threat intelligence, including attack type, attack severity, attack mode and attack source;
[0077] Attack type is the attack type in the prediction results output by the model, including DDoS attack, malware, and SQL injection;
[0078] Attack severity: Based on the analysis results, threat intelligence will be accompanied by the severity level of the attack (high, medium, or low);
[0079] Attack mode: Based on the feature identification results, threat intelligence will describe the pattern of attack behavior;
[0080] The attack source is, in some cases, threat intelligence may also include detailed information such as the attack source's IP address, attack methods, and attack targets.
[0081] Based on the generated real-time threat intelligence, the risk assessment threshold is dynamically updated. In this embodiment, when a high-risk DDoS attack is detected, the model will increase the risk assessment threshold for that type of attack, thereby enhancing the system's response capability to DDoS attacks. The risk assessment threshold adjustment formula is:
[0082]
[0083] in, is the updated risk assessment threshold; is the original risk determination threshold; Score real-time threat intelligence; is the historical threat intelligence score; α is the learning rate, and its value is ;
[0084] Generate security assessment reports based on real-time threat intelligence and updated risk assessment thresholds, including risk levels and threat types;
[0085] Risk level: Based on the current threat intelligence score and updated thresholds, the current risk level is assessed. The risk level is divided into low, medium, and high levels to help decision makers judge the severity of the threat.
[0086] when When the risk level is low,
[0087] when and When the risk level is medium,
[0088] when When , the risk level is high;
[0089] Threat types include DDoS attacks, malware, and SQL injection, and describe the threat characteristics and possible impacts;
[0090] The generated security assessment report is in JSON or XML format and output through the API interface to facilitate interaction with administrators.
[0091] M3, the adaptive intelligent response module, generates and executes graded response measures based on the security assessment report. The graded response measures include early warning prompts, access restrictions, and system isolation. The response execution effect is fed back to the risk assessment module for dynamic adjustment and generates a new security assessment report.
[0092] The Adaptive Intelligent Response Module receives a security assessment report from the Risk Assessment Module that includes the risk level and threat type. The report indicates the type of threat and the risk level (low, medium, or high). Based on the security assessment report, the module determines the intensity of the response measures, including early warning prompts, access restrictions, and system isolation.
[0093] For low-risk threats, early warning notifications are generated. This includes sending warning notifications to administrators and security teams, notifying them of potential threats and recommending further monitoring and manual inspections. These warnings do not affect normal network operations. Warning notifications are sent via SMS, email, and the internal security dashboard. The warning information includes key information such as the threat type, occurrence time, and impact scope.
[0094] For medium-risk threats, access restrictions are implemented. This response measures access control to specific IP addresses, ports, and protocols, preventing suspicious traffic from entering the network and reducing the potential attack surface. Access restrictions specifically use firewall policies or blacklist-based IP blocking technology to restrict network access for suspicious IP addresses, or block specific ports and protocols.
[0095] For high-risk threats, system isolation measures are taken. This response measure automatically isolates the attacked device or network segment to prevent the attack from spreading and protect the security of critical systems. System isolation specifically involves disconnecting the affected device from the network or isolating it through a virtual local area network (VLAN) to ensure that the system is not further attacked.
[0096] The execution of graded response measures is fully automated. By integrating with hardware and software such as network devices, firewalls, and traffic monitoring systems, it automatically triggers predetermined protection behaviors. This feature ensures that response measures can be executed quickly and efficiently after a threat is discovered.
[0097] After the response measures are executed, feedback data is collected in real time, including network traffic, device status changes, whether access restrictions are effective, and other information. This data is fed back to the risk assessment module as a basis for adjusting the security assessment report;
[0098] The risk assessment module adjusts the risk determination threshold and the weights of each component of the structured security data flow based on the response effect of the feedback. In this embodiment, if certain attack patterns are often misjudged as low risk, the system will adjust its sensitivity to this type of threat through the feedback mechanism to make it more accurate.
[0099] Based on the risk determination threshold and the adjustment of the weights of each component of the structured security data flow, the risk assessment module will generate a new security assessment report, which reflects the risk level and threat type optimized based on the feedback.
[0100] M4, communication module, automatically selects data transmission mode and transmission rate based on structured security data flow and new security assessment report, synchronizes data transmission mode and transmission rate to multi-dimensional intelligent module, and dynamically adjusts the collection frequency.
[0101] The transmission modes include conventional transmission mode and encrypted transmission mode. In low-risk situations, the communication module selects the conventional data transmission protocol. This mode has lower transmission delay and higher data transmission rate, and is suitable for the transmission of non-sensitive data. In high-risk situations, the communication module automatically switches to the encrypted transmission channel. This mode can ensure data security and prevent data from being attacked and leaked by man-in-the-middle during transmission.
[0102] Based on the selected transmission mode, the communication module dynamically adjusts the data transmission rate. In conventional transmission mode, a high transmission rate is selected to improve data transmission efficiency; in encrypted transmission mode, a low transmission rate is selected to avoid network congestion and performance degradation. Transmission rate adjustment is based on real-time monitoring of network traffic to ensure transmission stability and timeliness, and avoid data loss during network congestion.
[0103] After determining the transmission mode and transmission rate, the communication module immediately generates a transmission strategy instruction set, which includes the transmission mode type, transmission rate and recommended acquisition frequency range. After receiving the transmission strategy instruction set, the multi-dimensional intelligent module dynamically adjusts the acquisition frequency of each sensor group through the internal acquisition scheduling controller.
[0104] The AI-based dynamic security risk assessment and intelligent response method is characterized in that the method includes:
[0105] The sensor group collects multi-dimensional security data in real time, pre-processes the multi-dimensional security data based on AI-based intelligent perception technology, and outputs a structured security data stream;
[0106] Analyze the structured security data stream through an AI model, adjust the weights of the various components of the structured security data stream, and identify cross-dimensional attack feature correlation patterns based on a deep neural network to generate real-time threat intelligence. Update risk assessment thresholds based on the real-time threat intelligence and generate a security assessment report.
[0107] Based on the security assessment report, hierarchical response measures are generated and executed, and the response execution results are fed back to the risk assessment module for dynamic adjustment to generate a new security assessment report;
[0108] Based on the structured security data stream and the new security assessment report, the data transmission mode and transmission rate are automatically selected, the data transmission mode and transmission rate are synchronized to the multi-dimensional intelligent module, and the collection frequency is dynamically adjusted.
[0109] The AI-based dynamic security risk assessment and intelligent response system and method proposed in the present invention can achieve real-time identification and response to complex security threats through multi-dimensional data collection, deep neural network analysis and adaptive response mechanism. The present invention improves the processing capability and response speed in complex attack environments through efficient data cleaning, feature extraction and fusion, as well as real-time dynamic adjustment and optimization. In particular, it has significant advantages over existing technologies in terms of data quality, threat assessment accuracy and response timeliness.
[0110] In summary, the present invention, by combining advanced artificial intelligence technology with security risk assessment methods, not only solves the problems of data cleaning and response delay in the existing technology, but also realizes in-depth mining and real-time response of multi-dimensional security data, significantly improving the accuracy and reliability of security protection. The present invention can effectively deal with various complex network security threats and has broad application prospects.
[0111] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. AI-based dynamic security risk assessment and intelligent response system, characterized by: The system includes: The multi-dimensional intelligent module collects multi-dimensional security data in real time through a group of sensors deployed in network nodes, terminal devices, and the physical environment. Based on AI-based intelligent perception technology, it pre-processes the multi-dimensional security data and outputs a structured security data stream. The risk assessment module analyzes the structured security data stream through an AI model, adjusts the weights of the various components of the structured security data stream, and identifies cross-dimensional attack feature correlation patterns based on deep neural networks to generate real-time threat intelligence. It updates the risk judgment threshold based on the real-time threat intelligence and generates a security assessment report containing risk levels and threat types. The weight adjustment formula is: in, is the updated weight; is the original weight; is the learning rate, and its value is ; It is the weight calculated by the AI model, that is, the output of the AI model, which is obtained by calculating the gradient of the loss function with respect to the weight. The formula is: Where L is the value of the loss function; is the i-th feature; is the model’s predicted value for the i-th feature; is a hyperparameter of the regularization term, which controls the impact of regularization on the loss function; is the weight of the jth parameter in the model; N is the number of features; M is the number of model parameters; The adaptive intelligent response module generates and executes graded response measures based on the security assessment report. The graded response measures include early warning prompts, access restrictions, and system isolation. The response execution results are fed back to the risk assessment module for dynamic adjustment and the generation of a new security assessment report. The dynamic adjustment adjusts the risk determination threshold and the weights of each component of the structured security data flow according to the response effect of the feedback, and generates a new security assessment report; The communication module automatically selects a data transmission mode and a transmission rate based on the structured security data stream and the new security assessment report, synchronizes the data transmission mode and the transmission rate to the multi-dimensional intelligent module, and dynamically adjusts the collection frequency.
2. The AI-based dynamic security risk assessment and intelligent response system according to claim 1 is characterized in that: The multi-dimensional security data includes network traffic data, user behavior data and device status data. The network traffic data is collected by a network node sensor group deployed on each node in the network. The user behavior data is collected by a terminal device sensor group deployed on the terminal device. The device status data is collected by a physical environment sensor group deployed in a network physical environment.
3. The AI-based dynamic security risk assessment and intelligent response system according to claim 2 is characterized in that: The preprocessing includes data cleaning and feature extraction and fusion, and the data cleaning includes standardization, missing value filling and anomaly detection. The standardization scales the multi-dimensional safety data to the same scale, the missing value filling fills the missing data in the collection process by interpolation, and the anomaly detection detects and removes outliers in the multi-dimensional safety data by using the isolation forest algorithm; and the data cleaning outputs the cleaned multi-dimensional safety data; The cleaned multi-dimensional security data is subjected to feature extraction through an AI algorithm, and the extracted features are fused through a weighted average method to output a structured security data stream.
4. The AI-based dynamic security risk assessment and intelligent response system according to claim 3 is characterized in that: The real-time threat intelligence includes attack type, attack severity, attack pattern and attack source, The risk determination threshold adjustment formula is: in, is the updated risk assessment threshold; is the original risk determination threshold; Score real-time threat intelligence; Score historical threat intelligence; ; The risk level is divided into low, medium and high levels according to the score of the real-time threat intelligence and the updated risk determination threshold. when When the risk level is low, when and When the risk level is medium, when When , the risk level is high; The threat types are categorized into DDoS attacks, malware, and SQL injection, and the characteristics of the threat types are described. The security assessment report is output through the API interface.
5. The AI-based dynamic security risk assessment and intelligent response system according to claim 4 is characterized in that: The warning prompt is triggered when the risk level is low, and a warning notification is issued. The access restriction is triggered when the risk level is medium, specifically, the port and protocol are blocked. The system isolation is used when the risk level is high, automatically isolating the attacked device and network segment; The execution of the hierarchical response measures is automated, and predetermined response measures are automatically triggered through the integration of hardware and software.
6. The AI-based dynamic security risk assessment and intelligent response system according to claim 5 is characterized in that: The new security assessment report includes optimized risk levels and threat types.
7. The AI-based dynamic security risk assessment and intelligent response system according to claim 6 is characterized in that: The transmission mode includes a normal transmission mode and an encrypted transmission mode. The conventional transmission mode is adopted when the risk level is low or medium, and the encrypted transmission mode is adopted when the risk level is high; According to the adjustment of the transmission mode, the transmission rate is dynamically adjusted, and the transmission rate includes high frequency and low frequency; in the normal transmission mode, the high frequency transmission rate is selected; in the encrypted transmission mode, the low frequency transmission rate is selected; According to the transmission mode and transmission rate, a transmission strategy instruction set is generated, including the transmission mode type, transmission rate and recommended acquisition frequency range. Based on the transmission strategy instruction set, the acquisition frequency of each sensor group is adjusted through the internal acquisition scheduling controller.
8. AI-based dynamic security risk assessment and intelligent response method, characterized by: The method includes: The sensor group collects multi-dimensional security data in real time, pre-processes the multi-dimensional security data based on AI-based intelligent perception technology, and outputs a structured security data stream; The structured security data stream is analyzed through the AI model, the weights of the various components of the structured security data stream are adjusted, and cross-dimensional attack feature correlation patterns are identified based on deep neural networks to generate real-time threat intelligence. The risk judgment threshold is updated based on the real-time threat intelligence, and a security assessment report is generated. The weight adjustment formula is: in, is the updated weight; is the original weight; is the learning rate, and its value is ; It is the weight calculated by the AI model, that is, the output of the AI model, which is obtained by calculating the gradient of the loss function with respect to the weight. The formula is: Where L is the value of the loss function; is the i-th feature; is the model’s predicted value for the i-th feature; is a hyperparameter of the regularization term, which controls the impact of regularization on the loss function; is the weight of the jth parameter in the model; N is the number of features; M is the number of model parameters; Based on the security assessment report, hierarchical response measures are generated and executed, and the response execution effect is fed back to the AI model for dynamic adjustment to generate a new security assessment report. The dynamic adjustment adjusts the risk determination threshold and the weights of each component of the structured security data flow according to the response effect of the feedback, and generates a new security assessment report; Based on the structured security data stream and the new security assessment report, the data transmission mode and transmission rate are automatically selected, the data transmission mode and transmission rate are synchronized to the multi-dimensional intelligent module, and the collection frequency is dynamically adjusted.
Citation Information
Patent Citations
Network data risk assessment system for computer
CN119449432A