Security protection method, system and device for target network and medium
The method improves network security by authenticating and authorizing user requests in real-time using a defined security space and behavior risk assessment, addressing the limitations of static security strategies in dynamically changing environments.
Patent Information
- Application Number
- CN202510465400.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-15
AI Technical Summary
Traditional security protection methods mainly rely on static security policies and rule matching, resulting in low identification accuracy and response efficiency for potential threats, and are unable to adapt to dynamically changing network environments and new threats.
By obtaining the real-time call request of the target access user in the target network, authenticating and verifying based on its secure behavior space, combining the pre-built behavior risk assessment model for risk identification and service authorization, and dynamically adjusting security policies to improve threat identification and response efficiency.
It significantly improves the accuracy and response efficiency of potential threats, effectively prevents illegal access and resource abuse, improves the stability and security of the network, and achieves real-time security protection response.
Smart Images

Figure CN120321646A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network technologies, and in particular, to a security protection method, system, device and medium for a target network. Background Art
[0002] With the continuous evolution of mobile communication technologies, a new generation of networks based on an open capabilities architecture is becoming an important development direction. Taking the currently rapidly developing 5G network as an example, its open capabilities architecture allows network service providers to open some capabilities or functions of the network to third-party applications or services, effectively promoting industry innovation and service diversity. At the same time, more access points and more complex service interactions also bring new security challenges.
[0003] Traditional security protection methods mainly rely on static security policies and rule matching, such as encryption, access control, and security protocols. When facing a dynamically changing network environment and evolving threat patterns, these methods are unable to perform real-time and accurate user authentication, resulting in low accuracy in identifying potential threats and low response efficiency. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a security protection method, system, device and medium for a target network to solve the problem that traditional security protection methods mainly rely on static security policies and rule matching, resulting in low accuracy in identifying potential threats and low response efficiency.
[0005] In a first aspect, the present invention provides a security protection method for a target network, the
[0006] method comprising:
[0007] Obtaining a real-time call request of a target access user in the target network;
[0008] Performing authentication verification on the real-time call request based on the security behavior space of the target access user; wherein, the security behavior space of the target access user defines a set of security behavior criteria or standards for the target access user, and the security behavior criteria or standards are set based on a list of network services and resources that the target access user can access or call;
[0009] In response to the result of the authentication verification being authentication passed, performing service authorization on the real-time call request;
[0010] Using a pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization, and obtaining a risk discrimination result;
[0011] Performing a security protection response based on the risk discrimination result.
[0012] Further, before obtaining the real-time call request of the target access user in the target network, the method further includes:
[0013] Interact with the management layer of the target network to obtain the access user information of multiple access users connected to the target network; wherein, the target access user is any one of the multiple access users;
[0014] Construct a capability call list for each access user according to the access user information, wherein the capability call list includes a list of network services and resources that the access user can access or call;
[0015] Construct a security behavior space for each access user based on the capability call list.
[0016] Further, the access user information includes user standard information and user log information, and the constructing a capability call list for each access user according to the access user information specifically includes:
[0017] According to the user standard information of each access user, obtain the predefined standard operation permissions and standard operation capabilities, and generate a user capability list according to the standard operation permissions and standard operation capabilities;
[0018] Filter the access logs based on the user log information of each access user, extract the supplementary operation permissions and supplementary operation capabilities of the access user according to the access logs, and generate a user call list according to the supplementary operation permissions and supplementary operation capabilities;
[0019] Fuse the user capability list and the user call list of each access user to generate a capability call list corresponding to each access user.
[0020] Further, before obtaining the real-time call request of the target access user in the target network, the method further includes:
[0021] By executing the topology hiding policy of the target access user, hide or display some functions in the target network capability open architecture to ensure that the target access user can only access the network services within its permissions.
[0022] Further, before hiding or displaying some functions in the target network capability open architecture by executing the topology hiding policy of the target access user, the method further includes:
[0023] Define hidden classification information for each access user according to the security behavior space of each access user; wherein, the hidden classification information is used to reflect the permissions of the access user to access specific parts of the target network capability open architecture.
[0024] Obtain a topology hiding policy library, where the topology hiding policy library includes a variety of topology hiding policies, and each topology hiding policy corresponds to a different hiding rating, and the hiding rating is used to describe the degree of hiding of information after applying the topology hiding policy.
[0025] Select a topology hiding policy suitable for each access user from the topology hiding policy library according to the hidden classification information of each access user.
[0026] Further, the authentication and verification of the real-time call request based on the security behavior space of the target access user specifically includes:
[0027] Use a privacy computing method to perform a baseline verification on the identity information and device information of the target access user in the real-time call request to obtain a baseline verification result.
[0028] In response to the baseline verification result being verified successfully, extract the real-time call capability set corresponding to the real-time call request.
[0029] Combine the real-time call capability set and the security behavior space of the target access user to perform authentication and verification on the real-time call request, and generate an operation permission verification result and an operation capability verification result.
[0030] If both the operation permission verification result and the operation capability verification result are passed, the result of the authentication and verification is authentication passed.
[0031] Further, the service authorization for the real-time call request specifically includes:
[0032] Check whether the target access user or its device is in the exclusion list library.
[0033] If the target access user or its device is not in the exclusion list library, perform service authorization on the real-time call request.
[0034] Further, before checking whether the target access user or its device is in the exclusion list library, the method further includes:
[0035] By analyzing the security protection logs, identify potential security threats and add the corresponding threat entities to the exclusion list library.
[0036] Classify and label the threat entities in the exclusion list library by using the rules and conditions in the security behavior spaces of multiple said access users, and construct an associated synchronization relationship matrix to define the threat propagation paths among security objects;
[0037] Establish an associated mapping table between the exclusion list library and the access users according to the associated synchronization relationship matrix and a preset associated depth constraint;
[0038] Dynamically update the exclusion list library according to the associated mapping table and a preset synchronization period constraint, and synchronize the relevant different parts to the corresponding access users.
[0039] Further, before using a pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization and obtaining a risk discrimination result, the method further includes:
[0040] Share the security protection results of each network node in the target network through a pre-constructed threat intelligence sharing channel;
[0041] Construct the behavior risk assessment model through federated learning based on the shared security protection results.
[0042] Further, the method further includes:
[0043] Taking the security behavior spaces of multiple said access users as indexes, locate and extract the policies related to specific security requirements to form a node security protection policy set, where the node security protection policy set includes multiple security protection policy subsets for different edge nodes in the target network, and each security protection policy subset defines the security protection measures for the corresponding edge node;
[0044] Determine the security functions and rules applicable to each edge node by analyzing each security protection policy subset and the node capability list of the edge node, and configure the corresponding security protection components based on the security functions and rules to form an edge protection component set;
[0045] Send the edge protection component set to the corresponding edge node for local protection.
[0046] In a second aspect, the present invention provides a security protection system for a target network, including:
[0047] A request acquisition module, configured to acquire a real-time call request of a target access user in a target network;
[0048] A request authentication module, connected to the request acquisition module, is configured to perform authentication verification on the real-time call request based on the security behavior space of the target access user; wherein, the security behavior space of the target access user defines a set of security behavior guidelines or standards for the target access user, and the security behavior guidelines or standards are set based on a list of network services and resources that the target access user can access or call;
[0049] A service authorization module, connected to the request authentication module, is configured to perform service authorization on the real-time call request in response to the result of the authentication verification being authentication passed;
[0050] A risk discrimination module, connected to the service authorization module, is configured to use a pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization and obtain a risk discrimination result;
[0051] A security protection module, connected to the risk discrimination module, is configured to perform a security protection response based on the risk discrimination result.
[0052] In a third aspect, the present invention provides a security protection device for a target network, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to implement the security protection method for the target network described in the first aspect above.
[0053] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the security protection method for the target network described in the first aspect above.
[0054] The security protection method, system, device and medium for the target network provided by the present invention. First, obtain the real-time call request of the target access user in the target network; and perform authentication verification on the real-time call request based on the security behavior space of the target access user; wherein, the security behavior space of the target access user defines a set of security behavior criteria or standards for the target access user, and the security behavior criteria or standards are set based on the list of network services and resources that the target access user can access or call; then, in response to the result of the authentication verification being passed, perform service authorization on the real-time call request; then use the pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization, and obtain the risk discrimination result; finally, perform a security protection response based on the risk discrimination result. By obtaining the real-time call request of the target access user and performing authentication verification based on the security behavior space set according to the list of network services and resources that can be accessed or called, the present invention breaks through the limitations of traditional static security policies. At the same time, combining service authorization with a dynamic security analysis mechanism based on the behavior risk assessment model significantly improves the accuracy of identifying potential threats and the response efficiency, effectively preventing illegal access and resource abuse, thereby enhancing the stability and security of the network. Finally, through real-time risk discrimination and automated security protection response, it is ensured that the network can respond to threats in the first time, significantly enhancing the real-time performance and effect of security protection. It solves the problem that traditional security protection methods mainly rely on static security policies and rule matching, resulting in low accuracy of identifying potential threats and low response efficiency. Description of the Drawings
[0055] Figure 1 It is a flowchart of a security protection method for a target network according to Embodiment 1 of the present invention;
[0056] Figure 2 It is a schematic structural diagram of a security protection system for a target network according to Embodiment 2 of the present invention;
[0057] Figure 3 It is a schematic structural diagram of a security protection device for a target network according to Embodiment 3 of the present invention. Detailed Embodiments
[0058] To enable those skilled in the art to better understand the technical solutions of the present invention, the embodiments of the present invention will be further described in detail below in conjunction with the drawings.
[0059] It can be understood that the specific embodiments and drawings described herein are only for explaining the present invention, rather than limiting the present invention.
[0060] It can be understood that, without conflict, the various embodiments in the present invention and the features in the embodiments can be combined with each other.
[0061] It is understood that for ease of description, only the parts related to the present invention are shown in the drawings of the present invention, while the parts unrelated to the present invention are not shown in the drawings.
[0062] It is understood that the terms "first", "second", etc. in the embodiments of the present invention are used to distinguish different objects or different processes for the same object, rather than to describe a specific order of the objects.
[0063] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of the present invention may occur in an order different from that marked in the drawings.
[0064] It is understood that in the flowcharts and block diagrams of the present invention, the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the embodiments of the present invention are shown. Among them, each block in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified function. Moreover, each block or combination of blocks in the block diagram and flowchart may be implemented by a hardware-based system for implementing the specified function, or by a combination of hardware and computer instructions.
[0065] It is understood that the units and modules involved in the embodiments of the present invention may be implemented in software or in hardware. For example, the units and modules may be located in the processor.
[0066] Embodiment 1:
[0067] This embodiment provides a security protection method for a target network, as Figure 1 shown, the method includes:
[0068] Step S101: Obtain the real-time call request of the target access user in the target network.
[0069] In this embodiment, the target network may be any network with an open architecture, including but not limited to a 5G network. The real-time call request refers to a service request initiated by the target access user in the target network, such as a request to access a certain website, send data, or start an application, etc.
[0070] Step S102: Perform authentication and verification on the real-time call request based on the security behavior space of the target access user; wherein, the security behavior space of the target access user defines a set of security behavior criteria or standards for the target access user, and the security behavior criteria or standards are set based on a list of network services and resources that the target access user can access or call.
[0071] In this embodiment, authentication verification is a process of verifying the identity and permissions of a user, ensuring that the requester (i.e., the target access user) is a legitimate user and has the right to perform the requested operation.
[0072] Optionally, before obtaining the real-time call request of the target access user in the target network, the method further includes:
[0073] Interact with the management layer of the target network to obtain the access user information of multiple access users connected to the target network; wherein, the target access user is any one of the multiple access users;
[0074] Construct a capability call list for each access user according to the access user information, where the capability call list includes a list of network services and resources that the access user can access or call;
[0075] Construct a security behavior space for each access user based on the capability call list.
[0076] In this embodiment, the management layer of the target network is responsible for the configuration, monitoring, and control of the network. By interacting with the management layer of the target network, the access user information of multiple access users connected to the target network is obtained. The access user information includes user standard information and user log information. The user standard information is the basic information about the user, including but not limited to user identity: such as username, user ID, account, etc., device type: such as smartphone, Internet of Things device, etc., location information: such as IP (Internet Protocol) address, geographical location, etc., role, and permission; the user log information is the log recording the behavior of the access user on the target network, including the time, location, type, etc. of the user operation.
[0077] In this embodiment, a capability call list can be constructed for each access user according to the user type (such as enterprise user, personal user) and device type, where the user type is obtained through the role or permission information in the user standard information. For example, the user standard information contains information such as user ID, role (such as personal user, enterprise user), and permission. The capability call list is a list of network services and resources that the access user can access or call. These network services and resources belong to the capability open architecture of the target network. Through the capability call list, the system can ensure that the access user can only access the authorized services.
[0078] Specifically, the capability call list includes the user identity and the corresponding network services and resources that can be accessed or called.
[0079] For example: Enterprise User A (Industrial Internet of Things device)
[0080] Identity information: Device ID: A12345, Type: Industrial IoT (Internet of Things) device
[0081] Callable capabilities: QoS (Quality of Service) management (ensuring industrial data priority), network slicing (dedicated low-latency channels), device remote control permissions, security log access permissions.
[0082] Individual User B (smartphone)
[0083] Identity information: User ID: B56789, Type: Individual user
[0084] Callable capabilities: Location service, 5G high-speed data access, video streaming service, SMS (Short Message Service), MMS (Multimedia Messaging Service), access to DRM (Digital Rights Management)-protected content.
[0085] In this embodiment, based on the capability invocation list, the code of conduct and restrictions for the access users when accessing or invoking these network services and resources are further defined, and the secure behavior space of each access user is constructed. Among them, the secure behavior space is a set of defined secure behavior guidelines or standards used to determine whether the user's behavior is secure. The secure behavior space includes the range of legal behaviors and the restrictions on abnormal behaviors, such as the normal ranges of parameters such as data transfer rate, connection time, and access frequency.
[0086] Optionally, constructing the capability invocation list for each access user according to the access user information specifically includes:
[0087] According to the user standard information of each access user, obtain the predefined standard operation permissions and standard operation capabilities, and generate a user capability list according to the standard operation permissions and standard operation capabilities;
[0088] Filter the access logs based on the user log information of each access user, extract the supplementary operation permissions and supplementary operation capabilities of the access user according to the access logs, and generate a user invocation list according to the supplementary operation permissions and supplementary operation capabilities;
[0089] Fuse the user capability list and the user invocation list of each access user to generate the capability invocation list corresponding to each access user.
[0090] In this embodiment, the standard operation permissions and standard operation capabilities refer to the network service functions that an access user or device can access or execute based on its role and basic permissions, which are directly related to the identity and responsibilities of the access user or device in the network. The standard operation permissions and standard operation capabilities are output as a user capability list. This user capability list reflects the standard operation permissions that the access user should have in the system.
[0091] In this embodiment, the access log records information about the access user's access to specific resources or services. Based on these access logs, the supplementary operation permissions and supplementary operation capabilities of the access user are extracted to generate a user invocation list. Among them, the supplementary operation permissions and supplementary operation capabilities refer to the operation permissions and capabilities that are dynamically adjusted based on the historical behavior and preferences of the access user. These permissions and capabilities are not predefined but are updated in real time according to the behavior patterns and requirements of the access user. Among them, the standard operation permissions and capabilities (statically defined) and the supplementary operation permissions and capabilities (dynamically adjusted) both belong to the capabilities that can be provided by the capability open architecture.
[0092] In this embodiment, the user capability list and the user invocation list are merged to generate a capability invocation list. This list details the network services and resources that each access user can access or invoke.
[0093] Optionally, before obtaining the real-time invocation request of the target access user in the target network, the method further includes:
[0094] By executing the topology hiding strategy of the target access user, some functions in the target network capability open architecture are hidden or displayed to ensure that the target access user can only access the network services within its permissions.
[0095] In this embodiment, by executing the topology hiding strategy, some functions in the target capability open architecture (i.e., the target network capability open architecture) are adaptively hidden or displayed, so that the access user can only access the network services within its permissions, thereby improving the security and compliance of the service and providing flexible access control at the same time.
[0096] Optionally, before hiding or displaying some functions in the target network capability open architecture by executing the topology hiding strategy of the target access user, the method further includes:
[0097] According to the security behavior space of each access user, hiding classification information is defined for each access user; wherein, the hiding classification information is used to reflect the permissions of the access user to access specific parts of the target network capability open architecture.
[0098] Obtain a topology hiding policy library, where the topology hiding policy library includes multiple topology hiding policies, and each topology hiding policy corresponds to a different hiding rating, and the hiding rating is used to describe the hiding degree of information after applying the topology hiding policy;
[0099] According to the hiding classification information of each access user, select a topology hiding policy suitable for each access user from the topology hiding policy library.
[0100] In this embodiment, the hiding classification information reflects the access rights of the access user to specific parts of the system, and the specific parts will vary according to the different hiding classification information defined for the access user, that is, the specific parts refer to various service sets divided according to permissions in the system. For example, user A is defined as hiding classification level 1, indicating that it can access most of the public services of the architecture; user B is defined as hiding classification level 3, indicating that it can only access restricted services.
[0101] In this embodiment, the topology hiding policies in the topology hiding policy library include virtualization and distributed layout, dynamic routing and obfuscation techniques, camouflage and deception, etc., which are used to control the visibility of specific parts in the open architecture of the target network capabilities.
[0102] In this embodiment, using the hiding classification information as a constraint condition, traverse the topology hiding policy library, and select the most suitable topology hiding policy for the user according to the hiding classification information of the access user.
[0103] It should be noted that if the hiding classification information of the access user allows access to certain functions or services in the open architecture of the access capabilities, then these functions or services will be displayed and allowed to be called when they are requested. If certain functions or services are not within the hiding classification permissions of the access user, the system will use topology hiding policies (such as dynamic routing, obfuscation techniques, etc.) to make the access user unable to perceive the existence of these functions or services, that is, the topology hiding policy is used to control whether the access user can see certain architecture parts.
[0104] Optionally, the authentication verification of the real-time call request based on the security behavior space of the target access user specifically includes:
[0105] Use a privacy computing method to perform a benchmark verification on the identity information and device information of the target access user in the real-time call request to obtain a benchmark verification result;
[0106] In response to the benchmark verification result being verified, extract the real-time call capability set corresponding to the real-time call request;
[0107] Authenticate the real-time call request by combining the real-time call capability set and the security behavior space of the target access user, and generate an operation permission verification result and an operation capability verification result.
[0108] If both the operation permission verification result and the operation capability verification result pass, the result of the authentication verification is authentication passed.
[0109] In this embodiment, the privacy computing method allows the system to analyze data without exposing the actual data. For example, the system uses homomorphic encryption or differential privacy technology to process this information to ensure data security. By performing benchmark verification on the identity information and device information of the target access user, it can be ensured that the real-time call request is initiated by a legitimate user from a legitimate device, including but not limited to checking whether the username and password match, and whether the device ID is in the known list of legitimate devices, etc.
[0110] In this embodiment, if the benchmark verification result is verification passed, extract the real-time call capability set based on the real-time call request. Among them, the real-time call capability set includes the operations that the access user can perform and the resources that can be accessed in the current request (i.e., the real-time call request). For example, if the user requests to access a social media account, the real-time call capability set includes operations such as viewing posts and uploading pictures.
[0111] In this embodiment, authenticate the real-time call request by combining the real-time call capability set and the security behavior space, check whether the corresponding operation is within the preset permissions and capabilities, and obtain the operation permission verification result and the operation capability verification result. If both the operation permission verification result and the operation capability verification result pass, output the authentication verification result as authentication passed.
[0112] Step S103: In response to the result of the authentication verification being authentication passed, perform service authorization on the real-time call request.
[0113] In this embodiment, if the authentication is passed, perform service authorization on the real-time call request to allow the target access user to perform the requested operation. At the same time, the system will record this authorization operation, including the request time, request content, authorization result, etc., for monitoring and security analysis.
[0114] Optionally, the performing service authorization on the real-time call request specifically includes:
[0115] Check whether the target access user or its device is in the exclusion list library;
[0116] If the target access user or its device is not in the exclusion list library, perform service authorization on the real-time call request.
[0117] In this embodiment, the exclusion list library contains threat entities identified as security threats or threats to be excluded, such as IP addresses, device IDs, malware identifiers, etc. If the target access user or their device is not in the exclusion list library, service authorization is performed on the real-time call request; otherwise, access is denied.
[0118] Optionally, before checking whether the target access user or their device is in the exclusion list library, the method further includes:
[0119] By analyzing security protection logs, potential security threats are identified, and the corresponding threat entities are added to the exclusion list library;
[0120] Using the rules and conditions in the security behavior spaces of multiple access users, the threat entities in the exclusion list library are classified and marked, and an association synchronization relationship matrix is constructed to define the threat propagation paths between security objects;
[0121] According to the association synchronization relationship matrix and a preset association depth constraint, an association mapping table between the exclusion list library and access users is established;
[0122] According to the association mapping table and a preset synchronization period constraint, the exclusion list library is dynamically updated, and the relevant differential parts are synchronized to the corresponding access users.
[0123] In this embodiment, if a device of a certain access user has malicious behavior, such as launching a DDoS (Distributed Denial of Service) attack, then the IP or device ID of this device may be included in the exclusion list library. Therefore, threat entities generally refer to objects that may pose a threat to network security, including but not limited to the following categories: malicious IP addresses (from known attackers), infected user devices (such as terminals infected by Trojans), malware or malicious code (such as malicious executable files), attacker accounts (such as accounts taken over by hackers), abnormal traffic sources (such as the origin of DDoS attacks).
[0124] In this embodiment, the rules and conditions are the refinement and specification of security behavior guidelines or standards. The rules and conditions are specific clauses further formulated based on security behavior guidelines or standards. Using the rules and conditions in the security behavior space, the threat entities in the exclusion list library are classified and marked to obtain an association synchronization relationship matrix. The association synchronization relationship matrix is used to define the threat propagation paths between security objects, that is, to represent the association relationships and synchronization states between different security objects. Among them, security objects refer to various entities in the target network, including users, devices, services, etc., and they can all be objects of security protection.
[0125] In this embodiment, the association depth constraint is a parameter that restricts the degree of synchronization association. It can be a specific number of layers or the magnitude of the association degree, and is used to control the depth of the association between the exclusion list and the user, avoiding excessive restriction of user operations. The association mapping table is a mapping relationship established between the exclusion list library and the access users based on the association synchronization relationship matrix and the association depth constraint, guiding the adaptive synchronization of the exclusion list. This mapping table records which users need to be excluded and which objects in the exclusion list library are associated with these users.
[0126] In this embodiment, the synchronization period constraint is a rule that defines the synchronization frequency of the exclusion list, ensuring timely update without causing unnecessary resource consumption. Based on the association mapping table and the synchronization period constraint, the system dynamically updates the exclusion list library according to the behaviors and requirements of the access users, and synchronizes the different parts in the exclusion list library related to specific access users to the corresponding access users.
[0127] Step S104: Use the pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization, and obtain the risk discrimination result.
[0128] In this embodiment, the behavior risk assessment model is pre-trained using the security protection results shared by each network node in the target network. The security protection results shared by each network node may include information such as detected security threats, abnormal behavior patterns, and successful intrusion attempts. The abnormality of the real-time call request is analyzed in real time through the behavior risk assessment model to evaluate the attack risk. It should be noted that the security behavior space is the first static rule filtering, and the behavior risk assessment model is the second dynamic security analysis. Through the combination of the two, not only the defense against known threats is strengthened, but also the recognition and response capabilities for unknown and new threats are improved.
[0129] Optionally, before using the pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization and obtaining the risk discrimination result, the method further includes:
[0130] Share the security protection results of each network node in the target network through the pre-constructed threat intelligence sharing channel;
[0131] Based on the shared security protection results, construct the behavior risk assessment model through federated learning.
[0132] In this embodiment, the threat intelligence sharing channel is a communication mechanism that allows each network node in the target network to share information about security threats, such as security protection results. By sharing this information, each network node in the target network can jointly learn and improve the ability to identify security threats, realizing the real-time update and synchronization of threat intelligence.
[0133] It should be noted that the problem of information silos usually makes it difficult to share data between network nodes. In traditional networks, security data and threat intelligence are scattered in various independent systems, with insufficient information sharing, making it difficult to form a unified security protection system, resulting in low threat detection and response efficiency. The present invention conducts federated learning by sharing security protection results, constructs a behavioral risk assessment model for risk discrimination of real-time call requests, which can not only promote data interconnection between different systems, break information silos, achieve comprehensive information sharing and collaborative protection, but also protect the privacy of user data. In this way, each participating party can integrate information and resources from multiple parties, enhance the overall security protection ability, and thus improve the speed and accuracy of threat detection and response.
[0134] Step S105: Perform a security protection response based on the risk discrimination result.
[0135] In this embodiment, the risk discrimination result is a risk level, such as low risk, medium risk, high risk, etc. Based on the risk discrimination result, the system matches corresponding security policies or response measures, and then executes corresponding security protection responses according to the matched security policies or response measures. Among them, the security policies or response measures include allowing the request to proceed normally, requiring additional authentication, restricting user permissions, or completely blocking the request, etc. The security protection responses include automatically blocking, isolating the attacked network slice, device or node, and triggering manual review, etc., aiming to protect the security of the network and users according to the risk level of the request.
[0136] Optionally, the method further includes:
[0137] Using the security behavior spaces of multiple said access users as indexes, locating and extracting policies related to specific security requirements to form a node security protection policy set, where the node security protection policy set includes multiple security protection policy subsets for different edge nodes in the target network, and each security protection policy subset defines the security protection measures for the corresponding edge node;
[0138] By analyzing each security protection policy subset of the edge node and the node capability list, determining the security functions and rules applicable to each edge node, and configuring corresponding security protection components based on the security functions and rules to form an edge protection component set;
[0139] Sending the edge protection component set to the corresponding edge node for local protection.
[0140] In this embodiment, the edge node (i.e., the edge terminal) is located at the network edge and is directly connected to the access users or the network. When an access user accesses or invokes a service or resource, their operations will first pass through the edge node. The edge node is protected based on the security protection components in the edge protection component set, such as firewalls, intrusion detection systems, etc. Only after being verified and filtered by the security protection components can the access user access or invoke the requested service or resource. This architecture ensures that the access user requests have been security-checked before reaching the core network, thereby improving the overall network security.
[0141] In a specific embodiment, taking the target network as a 5G network as an example, the security protection method for this target network may include the following steps:
[0142] Step 1, interact with the target management layer to obtain the access user information of multiple access users, establish a capability invocation list based on the access user information, and define a security behavior space.
[0143] Among them, the target management layer refers to the management layer of the 5G network, which is responsible for network configuration, monitoring, and control; by interacting with the 5G network management layer, the system obtains the access user information of multiple users connected to the network. The access user information includes, but is not limited to, user identity (such as username, account number, etc.), device type (such as smart phone, Internet of Things device, etc.), location information (such as IP address, geographical location, etc.), and historical behavior data (such as past access records, behavior patterns, etc.). These information are important bases for evaluating user permissions and security risks, providing data support for the subsequent construction of the capability invocation list and the definition of the security behavior space.
[0144] Among them, the capability invocation list is a list containing the network services and resources that a user can access or invoke. The construction method is: based on the obtained access user information, the system constructs a personalized capability invocation list for each access user. The detail level of the list is closely related to the user type (such as enterprise user, individual user) and device type. Through the capability invocation list, the system can ensure that access users can only access authorized services. For example, individual users may be authorized to access high-speed data services and video streaming media, but have no right to access sensitive enterprise internal network resources.
[0145] Among them, the security behavior space is a set of defined security behavior guidelines or standards used to judge whether the behavior of access users is safe. The security behavior space includes the range of legal behaviors and the restrictions on abnormal behaviors, such as the normal ranges of parameters such as data transmission rate, connection time, and access frequency. The setting of the security behavior space is based on user information and the security requirements of the network. Any behavior beyond the normal range may be regarded as a potential security threat.
[0146] It should be noted that there is a close association between the secure behavior space and the capability invocation list. The capability invocation list defines the network services and resources that the accessing user can access, while the secure behavior space, based on these capability invocation lists, further defines the behavior guidelines and restrictions for the accessing user when accessing these resources. For example, the secure behavior space may stipulate the normal ranges of parameters such as the data transfer rate, connection time, and access frequency when the accessing user accesses a certain service. The secure behavior space is defined for a single accessing user, but if some accessing users have similar permissions and behavior patterns, the same secure behavior space can apply to these groups of accessing users.
[0147] Optionally, step 1 specifically includes:
[0148] Step 1.1: Interact with the target management layer to obtain the list of accessing users.
[0149] The target management layer specifically refers to the management layer of the 5G network, which is responsible for network configuration, monitoring, and control. Communicate with the target management layer, query all current online user information from the database, and obtain the list of all currently logged-in or authorized accessing users.
[0150] Step 1.2: Extract the user standard information and user log information according to the list of accessing users, and output them as accessing user information.
[0151] According to the list of accessing users, the system extracts the user standard information and user log information of each accessing user. The user standard information is the basic information about the accessing user, such as user ID, role, permissions, etc. The user log information is the log recording the behavior of the accessing user on the network, including the time, location, type of user operations, etc. Output the user standard information and user log information as accessing user information.
[0152] Step 1.3: Analyze the user standard information, extract the standard operation permissions and standard operation capabilities of the accessing user, and output them as the user capability list.
[0153] Analyze the user standard information, extract the predefined standard operation permissions and standard operation capabilities, and generate the user capability list. Among them, the standard operation permissions and standard operation capabilities refer to the network service functions that the accessing user or device can access or execute based on its role and basic permissions, which are directly related to the identity and responsibilities of the accessing user or device in the network. Output the standard operation permissions and standard operation capabilities as the user capability list. This user capability list reflects the standard operation permissions that the accessing user should have in the system. For example, an ordinary user has the right to access email services but has no right to access the company's internal network resources.
[0154] Step 1.4: Screen the Finder logs based on the user log information, and extract the supplementary operation permissions and supplementary operation capabilities of the accessing users from the Finder logs, and output them as a user call list.
[0155] The system uses data analysis tools to screen the Finder logs based on the user log information. These logs record the information of accessing users' access to specific resources or services. Based on these Finder logs, the supplementary operation permissions and supplementary operation capabilities of the accessing users are extracted to generate a user call list. Among them, the supplementary operation permissions and supplementary operation capabilities refer to the operation permissions and capabilities dynamically adjusted based on the historical behaviors and preferences of the accessing users. These permissions and capabilities are not predefined, but are updated in real time according to the behavior patterns and requirements of the accessing users. The standard operation permissions and capabilities, and the supplementary operation permissions and capabilities both belong to the capabilities that can be provided by the capability open architecture, such as location, push, QoS management, DRM, SMS, content provision, MMS, RSS (Really Simple Syndication / Rich Site Summary, simple information aggregation), network storage, network monitoring, registration, charging, network slicing, etc.
[0156] Step 1.5: Integrate the user capability list and the user call list to obtain a capability call list, and define a security behavior space based on the capability call list.
[0157] The system integrates the user capability list and the user call list to generate a capability call list. This list details the network services and resources that each accessing user can access or call. Based on this capability call list, the security behavior space of the accessing users in the system is finally defined, that is, a series of standards or guidelines for security behaviors are set. The system can monitor the behaviors of the accessing users in real time through this security behavior space, identify abnormal behaviors and give real-time warnings and responses to ensure that the operations of the accessing users both conform to their roles and do not exceed their authorities.
[0158] Step 2: Perform adaptive hiding of architecture capabilities
[0159] Step 2.1: Define the hidden classification information of accessing users
[0160] According to the security behavior space, define the hidden classification information for each accessing user. Among them, the hidden classification information reflects the permissions of the accessing users to access specific parts of the system. For example, User A is defined as hidden classification 1, indicating that he can access most of the public services of the architecture; User B is defined as hidden classification 3, indicating that he can only access restricted services. The hidden classification information is used as the basis for subsequent selection of topology hiding strategies to ensure that accessing users can only access the services within their permissions.
[0161] Step 2.2: Obtain the topology hiding policy library
[0162] The system interacts with the target management layer to obtain a policy library containing various topology hiding policies from the management layer of the target capability open architecture. The topology hiding policy library contains multiple topology hiding policies, and each policy corresponds to a different hiding rating. The policies include virtualization and distributed layout, dynamic routing and obfuscation techniques, camouflage and deception, etc., which are used to control the visibility of specific parts in the target capability open architecture.
[0163] Among them, the hiding rating is used to describe the degree of information hiding after applying this policy, and is used to evaluate the security and applicability of the policy.
[0164] Step 2.3, traverse the topology hiding policy library and select a policy
[0165] Using the hidden classification information as a constraint condition, traverse the topology hiding policy library, and select the most suitable topology hiding policy for the user according to the hidden classification information of the accessing user.
[0166] Execute the called topology hiding policy to adaptively hide or display some functions in the target capability open architecture.
[0167] Among them, the purpose of realizing the adaptive hiding of the architecture capabilities is to ensure that the accessing users can only access the network services within their permissions. By dynamically adjusting the service visibility for external accessing users, the security and compliance of the services are improved, and at the same time, flexible access control is provided.
[0168] It should be noted that although both the hiding rating and the hidden classification involve access control and visibility, their functions and usage scenarios are different. The hidden classification is set from the perspective of the user and determines which network capabilities this user can see. The hiding rating is set from the perspective of the policy and determines the hiding intensity of this policy. The system selects a suitable topology hiding policy according to the user's hidden classification and applies the corresponding hiding rating.
[0169] It should be noted that performing the adaptive hiding of the architecture capabilities is equivalent to a protection mechanism to determine which architecture capabilities need to be hidden or protected and which capabilities can be made public. For example, the modules and communication control functions involved in sensitive data processing should be hidden first.
[0170] Step 3, obtain a real-time call request, perform authentication verification of the real-time call request based on the security behavior space, and perform service authorization according to the authentication verification result.
[0171] Among them, a real-time call request refers to a service request initiated by a user in a 5G network, such as a request to access a certain website, send data, or start an application. Authentication verification is the process of verifying the identity and permissions of a user to ensure that the requester is a legitimate user and has the right to perform the requested operation. Service authorization is the process of deciding whether to grant the service or resources requested by the user based on the result of the authentication verification.
[0172] Specifically, the system receives a real-time call request from an accessing user. When the request arrives, the system first performs authentication verification on the request based on the previously defined security behavior space, checking whether the request conforms to the predefined security criteria, such as whether the time, location, frequency, and type of the request are within the normal range. The execution steps may include:
[0173] Step 3.1: Extract the request verification information from the real-time call request, where the request verification information includes identity information and device information.
[0174] Extract the request verification information containing the user's identity information and device information from the real-time call request. The identity information includes the username and password, and the device information includes the device ID and type.
[0175] Step 3.2: Based on the privacy computing method, perform benchmark verification of the real-time call request through the target management layer to obtain the benchmark verification result, where the benchmark verification result includes identity verification and device verification.
[0176] Process this information using the privacy computing method. The privacy computing method allows the system to analyze data without exposing the actual data. For example, the system uses homomorphic encryption or differential privacy technology to process this information to ensure data security. The system performs benchmark verification on the legitimacy of the user identity information and device information through the target management layer to ensure that the request is initiated by a legitimate user from a legitimate device, including checking whether the username and password match, and whether the device ID is in the known list of legitimate devices.
[0177] Step 3.3: If the benchmark verification result is verification passed, extract the real-time call capability set based on the real-time call request.
[0178] If the foregoing benchmark verification result is verification passed, the system will next extract the real-time call capability set based on the real-time call request. This real-time call capability set contains the operations that the accessing user can perform and the resources that can be accessed in the current request (i.e., the real-time call request). For example, if the accessing user requests to access a social media account, the real-time call capability set includes operations such as viewing posts and uploading pictures.
[0179] Step 3.4: Perform authentication verification of the real-time call request based on the security behavior space to obtain the operation permission verification result and the operation capability verification result.
[0180] The system authenticates real-time call requests in the security behavior space, checks whether the operations of the accessing users are within the preset permissions and capabilities, and obtains the operation permission verification result and the operation capability verification result. For example, the system will check whether the accessing user has the right to upload pictures and whether there is enough storage space to save the uploaded pictures, and obtain the corresponding verification results.
[0181] Step 3.5: If both the operation permission verification result and the operation capability verification result are passed, output the authentication verification result as authentication passed, perform service authorization on the real-time call request, and record the authorization operation.
[0182] If both the operation permission verification result and the operation capability verification result are passed, the system will output the authentication verification result as authentication passed, perform service authorization on the real-time call request, and allow the accessing user to execute the requested operation. At the same time, the system will record this authorization operation, including the request time, request content, authorization result, etc., for monitoring and security analysis.
[0183] Step 4: Form a threat intelligence sharing channel, share the security protection results for federated learning, and build a behavior risk assessment model.
[0184] Step 4.1: Build a threat intelligence sharing channel
[0185] A threat intelligence sharing channel is a communication mechanism that allows different network components or systems to share information about security threats. The shared information includes but is not limited to attack patterns, malware characteristics, threat actor information, etc. By sharing this information, each network node in the network can jointly learn and improve the ability to identify security threats, and achieve real-time update and synchronization of threat intelligence.
[0186] Step 4.2: Collect security protection results
[0187] The security protection results shared by each network node may include information such as detected security threats, abnormal behavior patterns, successful intrusion attempts, etc. By collecting this information, a basic training set is provided for subsequent federated learning.
[0188] Step 4.3: Use federated learning to build a behavior risk assessment model
[0189] Adopt federated learning algorithms, such as FedAvg or Secure Aggregation, etc., to distributively train the behavior risk assessment model among the participating parties. The process includes:
[0190] a. Each network node uses its own data to locally train the model;
[0191] b. Aggregate the updates of the model to the central server;
[0192] c. The central server integrates these updates to improve the global model and obtains the final behavioral risk assessment model.
[0193] Advantages: This method protects the privacy of user data, while allowing collaborative improvement of the model's effectiveness among network nodes, achieving dual guarantees for data sharing and model training.
[0194] Step 4.4, Model evaluation
[0195] The behavioral risk assessment model analyzes security elements such as resource performance, operating status information, behavioral logs, security logs, and traffic logs based on historical data and real-time data. It predicts and identifies potential security threats, and evaluates whether the behavior of accessing users or devices poses security risks. Through continuous iteration and optimization of the model by federated learning, the accuracy and efficiency of threat detection can be improved.
[0196] Step 5: Based on the service authorization result, call the behavioral risk assessment model to perform risk discrimination on the real-time call request, obtain the risk discrimination result, and perform security protection response based on the risk discrimination result.
[0197] Step 5.1, Service authorization result check
[0198] Before starting, the system first checks the service authorization result to ensure that the accessing user has the right to access the requested service or resource.
[0199] Step 5.2, Call of the behavioral risk assessment model
[0200] If the accessing user is authorized, the system immediately calls the behavioral risk assessment model to perform risk discrimination on the real-time call request. This model compares the characteristics of the request (such as time, location, frequency, and type) with known threat patterns and outputs a risk score or level as the risk discrimination result.
[0201] It should be noted that although both the security behavior space and the behavioral risk assessment model analyze the characteristics of the request (time, location, frequency, type, etc.), their functions and objectives are different.
[0202] (1) Function of the security behavior space: Set static security rules
[0203] Security behavior space = predefined set of behavioral rules, used to statically define which requests are legal. For example:
[0204] Access frequency: no more than 100 requests per minute;
[0205] Access time: access is allowed from 9:00 to 18:00 on weekdays;
[0206] Access location: Can only be accessed from the company network;
[0207] Access type: Ordinary users can only access basic services;
[0208] If a request exceeds these rules, it will directly deny access and not enter the behavioral risk assessment model. For example, if a user attempts to access a certain API (Application Programming Interface) 1000 times continuously at 3 am, the security behavior space will directly deny it without entering the risk assessment stage.
[0209] (2) Behavioral risk assessment model = machine learning or rule engine, which analyzes the abnormality of real-time call requests in real time and assesses the attack risk. Even if a request conforms to the basic rules of the security behavior space, it may still be malicious. For example, the accessed IP conforms to the rules and the IP does not belong to the list of known attackers, that is, the device is legal, but the behavior is abnormal (performing a large number of complex operations in a short time), and the access pattern is similar to an automated script rather than a normal user. Therefore, even if a request passes the verification of the security behavior space, it still needs to be further evaluated for risk. That is to say, the security behavior space is the first static rule filter, and the behavioral risk assessment model is the second dynamic security analysis.
[0210] Step 5.3, Risk discrimination and security policy matching
[0211] Based on the risk discrimination result, the system matches the corresponding security policy or response measure. Possible response measures include allowing the request to proceed normally, requiring additional authentication, restricting user permissions, or completely blocking the request.
[0212] It should be noted that the risk discrimination result is a risk level. For example, low risk: allow the request to proceed normally; medium risk: require additional authentication, such as entering a verification code; high risk: restrict user permissions or completely block the request. Among them, restricting user permissions ≠ directly denying the request, restricting user permissions ≠ completely blocking the request, but reducing the user's access level. Possible restriction methods include:
[0213] a) Can only perform low-risk operations, such as only being able to read data but not modify data.
[0214] b) Reduce the request rate, such as only being able to send 10 requests within 1 minute instead of 100.
[0215] c) Restrict sensitive operations, such as users can view account information but cannot change passwords or withdraw cash.
[0216] Step 5.4, Security response execution
[0217] Based on the matching security policies or response measures, the system performs corresponding security protection responses. Exemplary security protection responses include automatic blocking, isolating the attacked network slices, devices or nodes, and triggering manual reviews, etc. These responses are designed to protect the security of the network and users according to the requested risk level.
[0218] Optionally, the method may further include:
[0219] Step 6. Dynamic security protection method
[0220] Step 6.1. Extract the node security protection policy set
[0221] Using the security behavior space as an index, quickly locate and extract the policies related to specific security requirements to form a node security protection policy set. This policy set contains multiple security protection policy subsets for different nodes in the network, and each subset defines the security protection measures for the node.
[0222] Among them, a node refers to a computing device or service point in the network that provides one or more services or resources for users. These devices include servers, edge terminals (i.e., edge nodes), routers, etc. Nodes are key components in the network architecture and are responsible for processing and forwarding user requests. And the security protection policy is a set of rules and measures used to protect network nodes and services from security threats. These policies include access control, intrusion detection, malware protection, data encryption, etc. The specific content of the policy depends on the type and security requirements of the node. For example, an edge terminal may require a lightweight firewall and intrusion detection system, while a server may require more comprehensive security protection measures.
[0223] Specifically, taking each rule or condition in the security behavior space as an index, quickly locate and extract the policies related to specific security requirements to obtain a node security protection policy set. This policy set contains multiple security protection policy subsets for different nodes in the network. Each policy subset defines the security protection measures for the node, such as access control, intrusion detection, etc. Exemplarily, if there is a rule in the security behavior space that "users can only access network resources within a specific area during working hours", the system can use this rule as an index to extract the security policies related to time limit and area limit. This extraction process is dynamic, and as the rules in the security behavior space change, the system will update and adjust the node security protection policy set accordingly.
[0224] It should be noted that specific security requirements refer to security rules formulated for the network environment and user access behaviors, and they are indeed closely related to requests, services, or resource access. Specific security requirements usually come from:
[0225] 1) Secure behavior space: For example, "a certain user can only access the company's internal server during working hours".
[0226] 2) Service access policy: For example, "double authentication is required for accessing sensitive data".
[0227] 3) Node security policy: For example, "certain edge nodes can only process low-sensitivity data".
[0228] 4) Risk assessment result: If a certain request is identified as high-risk, additional authentication may be required.
[0229] Step 6.2, Configure lightweight security protection components
[0230] Analyze the security protection policy subset and capability list of each node to determine the security functions and rules applicable to that node. Use the behavioral risk assessment model to predict and identify potential security threats faced by the node, and combine enhanced training and knowledge distillation techniques to configure appropriate security protection components to form an edge protection component set.
[0231] Step 6.3, Distribute the edge protection component set
[0232] Distribute the edge protection component set to multiple edge terminals (or edge terminals and other nodes) for local protection. These edge terminals correspond to multiple access users in the network.
[0233] The edge terminal receives the corresponding protection component set according to its own capabilities and risks, and performs local security protection tasks.
[0234] It should be noted that the edge terminal is a computing device at the network edge, directly connected to access users or the network, and belongs to a type of node. The edge terminal is responsible for performing local security protection tasks and is a node close to the user side in the network architecture. When an access user accesses or invokes a service or resource, its operation will first pass through the edge terminal. The edge terminal performs protection based on the security protection components in the edge protection component set, such as firewalls, intrusion detection systems, etc. Only after being verified and filtered by the security protection components can the access user access or invoke the requested service or resource. This architecture ensures that access user requests have passed through security checks before reaching the core network, thereby improving the overall network security.
[0235] Optionally, the method may further include:
[0236] Step 7, Exclusion list library adaptive synchronization method
[0237] Step 7.1, Establish an exclusion list library
[0238] Collect and analyze security protection logs, identify potential security threats, and add these threat entities to the exclusion list library.
[0239] Among them, threat entities include certain devices accessing the user, or IPs, accounts, etc. used by the accessing user. If there is malicious behavior in a device of an accessing user (such as launching a DDoS attack), then the IP or device ID of this device may be included in the exclusion list library. Therefore, threat entities generally refer to objects that may pose a threat to network security, including but not limited to the following categories: malicious IP addresses (from known attackers), infected user devices (such as terminals infected by Trojans), malicious software or malicious code (such as malicious executable files), attacker accounts (such as accounts taken over by hackers), and abnormal traffic sources (such as the origin of DDoS attacks).
[0240] Specifically, first collect and parse security protection logs, which record security events and operations in the network, such as intrusion attempts, triggering of security rules, etc. By analyzing these logs, the system can identify potential security threats and add these threat entities to the exclusion list library. This exclusion list library contains threat entities identified as security threats or to be excluded, such as IP addresses, device IDs, malware identifiers, etc., for automatically denying access to these entities in the future.
[0241] Step 7.2, Object Marking and Associated Synchronization Relationship Matrix
[0242] Use the rules and conditions in the security behavior space to classify and mark the objects in the exclusion list library. Obtain the associated synchronization relationship matrix, which represents the association relationships and synchronization statuses between different security objects. Among them, security objects refer to various entities in the network, including users, devices, services, etc., and they can all be objects of security protection.
[0243] Specifically, use the rules and conditions in the security behavior space to classify and mark the objects in the exclusion list library (that is, associate the threat entities with the rules and conditions in the security behavior space to achieve classification and marking). For example, if a certain IP address is marked as malicious, the system will determine which accessing users may be affected by this threat object according to the service area associated with this IP address. At the same time, the system obtains the associated synchronization relationship matrix, which is used to represent the association relationships and synchronization statuses between different security objects. For example, if user A is an AR (Augmented Reality) service provider and user B is a VR (Virtual Reality) service provider, then even if the network of user A is not directly associated with the service of user B, if the threat object detected in the security log of user A may pose a threat to the VR service of user B, the system will also mark this threat object as having a potential threat to user B. Because AR and VR services may share certain resources or have business associations.
[0244] Step 7.3: Establish an association mapping table
[0245] Based on the association synchronization relationship matrix and the preset association depth constraint, establish an association mapping table between the exclusion list library and multiple access users.
[0246] Specifically, based on the association synchronization relationship matrix and the preset association depth constraint, the system establishes an association mapping table between the exclusion list library and multiple access users to guide the personalized synchronization strategy of the exclusion list. Among them, the association depth constraint is a parameter that restricts the degree of synchronization association. It can be a specific number of layers or the magnitude of the association degree, used to control the depth of the association between the exclusion list and the access users to avoid excessive restriction of user operations. For example, the system sets a rule that if a threat object is directly associated with a certain access user or indirectly associated through one layer, the synchronization is activated. Or, the system can determine whether to activate the synchronization according to the association degree between the threat object and the access user, such as traffic volume, access frequency, etc. The association mapping table is a mapping relationship established between the exclusion list library and the access users based on the association synchronization relationship matrix, guiding the adaptive synchronization of the exclusion list. This mapping table records which users need to be excluded and which objects in the exclusion list library are associated with these users.
[0247] Step 7.4: Adaptive synchronization of the exclusion list library
[0248] Based on the association mapping table and the synchronization period constraint, dynamically update the exclusion list library and synchronize the different parts related to specific access users to the corresponding access users.
[0249] Specifically, based on the association mapping table and the synchronization period constraint, the system dynamically updates the exclusion list library according to the behaviors and needs of the access users, and synchronizes the different parts related to specific access users in the exclusion list library to the corresponding access users. Among them, the synchronization period constraint is a rule that defines the synchronization frequency of the exclusion list to ensure timely update without causing unnecessary resource consumption. Exemplarily, VR service provider B recently detected multiple unauthorized access attempts from unknown sources. After analyzing its protection logs, the system identified that the behavior originated from IP address Y, added it to the exclusion list library, and marked its direct association with B. At the same time, the analysis found that Y also attempted to access the resources of AR service provider A, so Y was marked as having an indirect association with A. According to the association depth constraint set by the system (for example, depth 2), the information of Y will be synchronized to A and B. The system only synchronizes the latest information of Y to A and B according to the association mapping table, instead of synchronizing the entire exclusion list, achieving effective utilization of resources and precise defense against threats.
[0250] It should be noted that the exclusion list library can be used in the above multiple steps:
[0251] Service authorization steps: During service authorization, the system can refer to the exclusion list library to decide whether to authorize access to the services or resources requested by the accessing user.
[0252] Risk discrimination for real-time call requests: In subsequent real-time call requests, the system can use the exclusion list library for risk discrimination to further enhance security.
[0253] Among them, the exclusion list library is not directly added to the security behavior space, but is used as a supplement to the security behavior space to enhance the security protection ability.
[0254] Example process:
[0255] The accessing user requests to access resources;
[0256] The system checks the identity and authorization of the accessing user;
[0257] The system calls the behavior risk assessment model to analyze risks;
[0258] During the risk discrimination stage, query the exclusion list library;
[0259] If the accessing user or device is in the exclusion list library, access is denied (high risk);
[0260] If the IP address of the accessing user is marked as malicious, additional verification is triggered (medium risk);
[0261] Take protection measures according to the risk results.
[0262] It should be noted that the security protection method for the target network provided by the present invention realizes precise control and reasonable allocation of network resources through a dynamic authentication and service authorization mechanism, effectively preventing illegal access and resource abuse, and improving the stability and security of the network. Secondly, the construction of threat intelligence sharing and behavior risk assessment models not only strengthens the defense against known threats, but also improves the ability to identify and respond to unknown and new threats, realizing intelligent optimization of security policies. Finally, real-time risk discrimination and automated security response ensure that the network can respond to threats in the first time, significantly improving the real-time performance and effect of security protection.
[0263] The security protection method for the target network provided by the embodiment of the present invention first obtains the real-time call request of the target access user in the target network; and performs authentication verification on the real-time call request based on the security behavior space of the target access user; wherein, the security behavior space of the target access user defines a set of security behavior criteria or standards for the target access user, and the security behavior criteria or standards are set based on the list of network services and resources that the target access user can access or call; then, in response to the result of the authentication verification being authentication passed, service authorization is performed on the real-time call request; then, the pre-constructed behavior risk assessment model is used to perform risk discrimination on the real-time call request after service authorization to obtain a risk discrimination result; finally, a security protection response is made based on the risk discrimination result. The present invention breaks through the limitations of traditional static security policies by obtaining the real-time call request of the target access user and performing authentication verification based on the security behavior space set according to the list of network services and resources that can be accessed or called by the target access user. At the same time, by combining service authorization with a dynamic security analysis mechanism based on a behavior risk assessment model, the accuracy of potential threat identification and response efficiency are significantly improved, effectively preventing illegal access and resource abuse, thereby enhancing the stability and security of the network. Finally, through real-time risk discrimination and automated security protection response, it is ensured that the network can respond to threats in the first time, significantly improving the real-time performance and effect of security protection. It solves the problem that traditional security protection methods mainly rely on static security policies and rule matching, resulting in low accuracy of potential threat identification and response efficiency.
[0264] Embodiment 2:
[0265] As Figure 2 shown, this embodiment provides a security protection system for a target network, which is used to execute the above-mentioned security protection method for the target network, and includes:
[0266] A request acquisition module 11, which is used to obtain the real-time call request of the target access user in the target network;
[0267] A request authentication module 12, which is connected to the request acquisition module 11 and is used to perform authentication verification on the real-time call request based on the security behavior space of the target access user; wherein, the security behavior space of the target access user defines a set of security behavior criteria or standards for the target access user, and the security behavior criteria or standards are set based on the list of network services and resources that the target access user can access or call;
[0268] A service authorization module 13, which is connected to the request authentication module 12 and is used to perform service authorization on the real-time call request in response to the result of the authentication verification being authentication passed;
[0269] A risk discrimination module 14, connected to the service authorization module 13, is configured to use a pre-constructed behavioral risk assessment model to discriminate risks for the real-time call request after service authorization, and obtain a risk discrimination result;
[0270] A security protection module 15, connected to the risk discrimination module 14, is configured to perform a security protection response based on the risk discrimination result.
[0271] Optionally, the system further includes:
[0272] An access user information acquisition module, configured to interact with the management layer of the target network to obtain access user information of multiple access users connected to the target network; wherein, the target access user is any one of the multiple access users;
[0273] A capability call list construction module, configured to construct a capability call list for each access user according to the access user information, wherein the capability call list includes a list of network services and resources that the access user can access or call;
[0274] A security behavior space construction module, configured to construct a security behavior space for each access user based on the capability call list.
[0275] Optionally, the access user information includes user standard information and user log information, and the capability call list construction module specifically includes:
[0276] A user capability list generation unit, configured to obtain predefined standard operation permissions and standard operation capabilities according to the user standard information of each access user, and generate a user capability list according to the standard operation permissions and standard operation capabilities;
[0277] A user call list generation unit, configured to screen access logs based on the user log information of each access user, extract supplementary operation permissions and supplementary operation capabilities of the access user according to the access logs, and generate a user call list according to the supplementary operation permissions and supplementary operation capabilities;
[0278] A list fusion unit, configured to fuse the user capability list and the user call list of each access user to generate a capability call list corresponding to each access user.
[0279] Optionally, the system further includes:
[0280] A topology hiding policy execution module, configured to hide or display some functions in the target network capability open architecture by executing the topology hiding policy of the target access user, so as to ensure that the target access user can only access network services within its authority range.
[0281] Optionally, the system further includes:
[0282] A hidden classification definition module, configured to define hidden classification information for each access user according to the security behavior space of each access user; wherein, the hidden classification information is used to reflect the access rights of the access user to a specific part of the target network access capability architecture;
[0283] A topology hiding policy library acquisition module, configured to acquire a topology hiding policy library, wherein the topology hiding policy library includes multiple topology hiding policies, and each topology hiding policy corresponds to a different hiding rating, and the hiding rating is used to describe the hiding degree of information after applying the topology hiding policy;
[0284] A topology hiding policy selection module, configured to select a topology hiding policy suitable for each access user from the topology hiding policy library according to the hidden classification information of each access user.
[0285] Optionally, the request authentication module 12 specifically includes:
[0286] A benchmark verification unit, configured to use a privacy computing method to perform benchmark verification on the identity information and device information of the target access user in the real-time call request, and obtain a benchmark verification result;
[0287] A real-time call capability set extraction unit, configured to extract a real-time call capability set corresponding to the real-time call request in response to the benchmark verification result being verified passed;
[0288] An authentication verification unit, configured to perform authentication verification on the real-time call request by combining the real-time call capability set and the security behavior space of the target access user, and generate an operation permission verification result and an operation capability verification result;
[0289] An authentication passed determination unit, configured to determine that the result of the authentication verification is authentication passed if both the operation permission verification result and the operation capability verification result are passed.
[0290] Optionally, the service authorization module 13 includes:
[0291] An inspection unit, configured to inspect whether the target access user or its device is in the exclusion list library;
[0292] A service authorization unit, configured to perform service authorization on the real-time call request if the target access user or its device is not in the exclusion list library.
[0293] Optionally, the system further includes:
[0294] The exclusion list library building module is used to identify potential security threats by analyzing security protection logs and add the corresponding threat entities to the exclusion list library;
[0295] The classification and marking module is used to classify and mark the threat entities in the exclusion list library by using the rules and conditions in the security behavior spaces of multiple access users, and construct an associated synchronization relationship matrix to define the threat propagation paths between security objects;
[0296] The associated mapping table building module is used to establish an associated mapping table between the exclusion list library and access users according to the associated synchronization relationship matrix and a preset associated depth constraint;
[0297] The exclusion list library update module is used to dynamically update the exclusion list library according to the associated mapping table and a preset synchronization period constraint, and synchronize the relevant different parts to the corresponding access users.
[0298] Optionally, the system further includes:
[0299] The security protection result sharing module is used to share the security protection results of each network node in the target network through a pre-constructed threat intelligence sharing channel;
[0300] The behavior risk assessment model construction module is used to construct the behavior risk assessment model through federated learning based on the shared security protection results.
[0301] Optionally, the system further includes:
[0302] The node security protection policy set forming module is used to locate and extract the policies related to specific security requirements by using the security behavior spaces of multiple access users as indexes to form a node security protection policy set, where the node security protection policy set includes multiple security protection policy subsets for different edge nodes in the target network, and each security protection policy subset defines the security protection measures for the corresponding edge node;
[0303] The edge protection component set forming module is used to determine the security functions and rules applicable to each edge node by analyzing the security protection policy subsets and node capability lists of each edge node, and configure the corresponding security protection components based on the security functions and rules to form an edge protection component set;
[0304] The edge protection component set distribution module is used to distribute the edge protection component set to the corresponding edge nodes for local protection.
[0305] Embodiment 3:
[0306] Reference Figure 3, this embodiment provides a security protection device for a target network, including a memory 21 and a processor 22. A computer program is stored in the memory 21, and the processor 22 is configured to run the computer program to execute the security protection method for the target network in Embodiment 1.
[0307] Among them, the memory 21 is connected to the processor 22. The memory 21 can adopt flash memory, read-only memory or other memories, and the processor 22 can adopt a central processing unit or a single-chip microcomputer.
[0308] Embodiment 4:
[0309] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the security protection method for the target network in Embodiment 1 above.
[0310] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). The computer-readable storage medium includes, but is not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), digital versatile disc (DVD) or other optical disc storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.
[0311] In summary, the security protection method, system, device, and medium for the target network provided by the embodiments of the present invention first obtain the real-time call requests of the target access users in the target network; and perform authentication verification on the real-time call requests based on the security behavior space of the target access users; wherein, the security behavior space of the target access users defines a set of security behavior criteria or standards for the target access users, and the security behavior criteria or standards are set based on the list of network services and resources that the target access users can access or call; then, in response to the result of the authentication verification being passed, service authorization is performed on the real-time call requests; then, the pre-constructed behavior risk assessment model is used to perform risk discrimination on the real-time call requests after service authorization to obtain the risk discrimination result; finally, a security protection response is made based on the risk discrimination result. By obtaining the real-time call requests of the target access users and performing authentication verification based on the security behavior space set according to the list of network services and resources that they can access or call, the present invention breaks through the limitations of traditional static security policies. At the same time, by combining service authorization with a dynamic security analysis mechanism based on the behavior risk assessment model, the accuracy of identifying potential threats and the response efficiency are significantly improved, effectively preventing illegal access and resource abuse, thereby enhancing the stability and security of the network. Finally, through real-time risk discrimination and automated security protection response, it is ensured that the network can respond to threats in the first time, significantly enhancing the real-time performance and effect of security protection. This solves the problem that traditional security protection methods mainly rely on static security policies and rule matching, resulting in low accuracy of identifying potential threats and low response efficiency.
[0312] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principle of the present invention, and the present invention is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also regarded as the protection scope of the present invention.
Claims
1. A security protection method for a target network, characterized in that, The method includes: Obtaining a real-time call request of a target access user in a target network; Performing authentication verification on the real-time call request based on the security behavior space of the target access user; wherein, the security behavior space of the target access user defines a set of security behavior criteria or standards for the target access user, and the security behavior criteria or standards are set based on a list of network services and resources that the target access user can access or call; In response to the result of the authentication verification being authentication passed, performing service authorization on the real-time call request; Using a pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization, and obtaining a risk discrimination result; Performing a security protection response based on the risk discrimination result.
2. The method according to claim 1, wherein Before obtaining the real-time call request of the target access user in the target network, the method further includes: Interacting with the management layer of the target network to obtain access user information of multiple access users connected to the target network; wherein, the target access user is any one of the multiple access users; Constructing a capability call list for each access user according to the access user information, wherein the capability call list includes a list of network services and resources that the access user can access or call; Constructing the security behavior space of each access user based on the capability call list.
3. The method according to claim 2, wherein The access user information includes user standard information and user log information. The constructing a capability call list for each access user according to the access user information specifically includes: According to the user standard information of each access user, obtaining predefined standard operation permissions and standard operation capabilities, and generating a user capability list according to the standard operation permissions and standard operation capabilities; Filtering access logs based on the user log information of each access user, extracting supplementary operation permissions and supplementary operation capabilities of the access user according to the access logs, and generating a user call list according to the supplementary operation permissions and supplementary operation capabilities; Fusing the user capability list and the user call list of each access user to generate a capability call list corresponding to each access user.
4. The method according to claim 2, wherein Before obtaining the real-time call request of the target access user in the target network, the method further includes: By executing the topology hiding policy of the target access user, hiding or displaying some functions in the target network capability open architecture to ensure that the target access user can only access network services within its authority scope.
5. The method according to claim 4, wherein Before hiding or displaying some functions in the target network capability open architecture by executing the topology hiding policy of the target access user, the method further includes: Defining hidden classification information for each access user according to the security behavior space of each access user; wherein, the hidden classification information is used to reflect the authority of the access user to access a specific part of the target network capability open architecture. Obtain a topology hiding policy library, where the topology hiding policy library includes multiple topology hiding policies, and each topology hiding policy corresponds to a different hiding rating, and the hiding rating is used to describe the hiding degree of information after applying the topology hiding policy; According to the hiding classification information of each access user, select a suitable topology hiding policy for each access user from the topology hiding policy library.
6. The method according to claim 1, characterized in that The authentication verification of the real-time call request based on the security behavior space of the target access user specifically includes: Using a privacy computing method, perform a benchmark verification on the identity information and device information of the target access user in the real-time call request to obtain a benchmark verification result; In response to the benchmark verification result being verified successfully, extract the real-time call capability set corresponding to the real-time call request; Combining the real-time call capability set and the security behavior space of the target access user, perform authentication verification on the real-time call request to generate an operation permission verification result and an operation capability verification result; If both the operation permission verification result and the operation capability verification result are passed, the result of the authentication verification is authentication passed.
7. The method according to claim 2, characterized in that, The service authorization for the real-time call request specifically includes: Check whether the target access user or its device is in the exclusion list library; If the target access user or its device is not in the exclusion list library, perform service authorization on the real-time call request.
8. The method according to claim 7, characterized in that Before checking whether the target access user or its device is in the exclusion list library, the method further includes: By analyzing the security protection logs, identify potential security threats and add the corresponding threat entities to the exclusion list library; Using the rules and conditions in the security behavior spaces of multiple access users, classify and label the threat entities in the exclusion list library, and construct an association synchronization relationship matrix to define the threat propagation path between security objects; According to the association synchronization relationship matrix and the preset association depth constraint, establish an association mapping table between the exclusion list library and the access users; According to the association mapping table and the preset synchronization period constraint, dynamically update the exclusion list library and synchronize the relevant different parts to the corresponding access users.
9. The method according to claim 1, wherein Before using the pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call request after service authorization and obtain a risk discrimination result, the method further includes: Through a pre-constructed threat intelligence sharing channel, share the security protection results of each network node in the target network; Based on the shared security protection results, construct the behavior risk assessment model through federated learning.
10. The method according to claim 2, wherein The method further includes: Using the security behavior spaces of multiple access users as an index, locate and extract the policies related to specific security requirements to form a node security protection policy set, where the node security protection policy set includes multiple security protection policy subsets for different edge nodes in the target network, and each security protection policy subset defines the security protection measures for the corresponding edge node; By analyzing the security protection policy subsets and node capability lists of each of the edge nodes, determine the security functions and rules applicable to each of the edge nodes, and configure corresponding security protection components based on the security functions and rules to form an edge protection component set; Send the edge protection component set to the corresponding edge nodes for local protection.
11. A security protection system for a target network, characterized in that, Comprising: A request acquisition module, configured to acquire real-time call requests of target access users in a target network; A request authentication module, connected to the request acquisition module, configured to perform authentication verification on the real-time call requests based on the security behavior space of the target access users; wherein, the security behavior space of the target access users defines a set of security behavior criteria or standards for the target access users, and the security behavior criteria or standards are set based on a list of network services and resources that the target access users can access or call; A service authorization module, connected to the request authentication module, configured to perform service authorization on the real-time call requests in response to the authentication verification result being authentication passed; A risk discrimination module, connected to the service authorization module, configured to use a pre-constructed behavior risk assessment model to perform risk discrimination on the real-time call requests after service authorization to obtain a risk discrimination result; A security protection module, connected to the risk discrimination module, configured to perform security protection responses based on the risk discrimination result.
12. A security protection device for a target network, characterized in that, Comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to implement the security protection method for the target network according to any one of claims 1-10.
13. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, it implements the security protection method for the target network according to any one of claims 1-10.
Citation Information
Cited By
AI semantic model and robot interconnection method and system based on MCP protocol, and medium
CN120791784A
Mcp protocol-based ai semantic model and robot interconnection method, system and medium
CN120791784B