Network security equipment adaptive optimization method based on rule analysis

Through the analysis of historical feedback behavior patterns of network security equipment and adaptive optimization, the problem of inaccurate equipment management in the existing technology is solved, effective management and coordination of network security equipment is achieved, and protection efficiency and effect are improved.

CN120342673APending Publication Date: 2025-07-18HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510438583.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing network security equipment management methods are difficult to accurately evaluate and monitor the performance and protection effects of equipment, resulting in equipment with poor protection effects still exist, affecting the response efficiency and effectiveness of the network security protection system.

Method used

By obtaining the historical feedback behavior patterns of network security devices, it is divided into security and abnormal feedback behavior patterns, calculate the initial processing factor and event processing coefficient, perform adaptive optimization, remove equipment with poor protection effects, and achieve effective management and coordination.

Benefits of technology

It improves the efficiency and effect of network security protection, ensures the safe and stable operation of the network system, and gives full play to the protection functions of various network security equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342673A_ABST
    Figure CN120342673A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security equipment, and discloses a network security equipment adaptive optimization method based on rule analysis, which comprises the following steps: acquiring a historical feedback behavior mode of network security equipment, and dividing the historical feedback behavior mode into a historical security feedback behavior mode and a historical abnormal feedback behavior mode; determining a security feedback rule data set and an exception feedback rule data set, calculating an initial historical security processing factor and an initial historical exception processing factor, performing normalization processing, constructing an initial processing factor set, splitting the initial processing factor set into a first initial processing factor set and a second initial processing factor set, calculating a historical security event processing coefficient, and calculating a second historical security event processing coefficient; the historical security event processing coefficient of each network security device is extracted, the multiple network security devices are adaptively optimized, the network security devices with poor protection effects are removed, effective management and coordination are realized, the protection function of each network security device is fully played, the efficiency and effect of network security protection are improved, and the network security protection method is suitable for the network security devices. And safe and stable operation of a network system is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security devices, and more particularly to an adaptive optimization method for network security devices based on rule analysis. Background Art

[0002] Network security devices are used to protect computer networks from various security threats and attacks. The following are some common network security devices: firewalls, intrusion detection systems, intrusion prevention systems, vulnerability scanning systems, antivirus systems, switches, routers, etc. Network security devices all have their unique functions and roles, jointly constituting a network security protection system to ensure the security and stability of the network environment. With the increasing complexity of the network security situation, a single network security device is difficult to effectively cope with various security threats. Different types of network security devices need to work together to build a comprehensive network security protection system. These devices need to cooperate with each other and work together to give full play to their protection functions.

[0003] The existing network security device management methods are difficult to accurately evaluate and monitor the performance and protection effects of network security devices. This allows some network security devices with poor protection effects to remain in the network, not only wasting resources but also potentially becoming weak links in the entire network security protection system. This results in significant constraints on the response efficiency and effect of network security devices when dealing with complex security events. Summary of the Invention

[0004] Embodiments of the present invention provide an adaptive optimization method for network security devices based on rule analysis. The present invention can remove network security devices with poor protection effects, effectively manage and coordinate network security devices, give full play to the protection functions of each network security device, improve the efficiency and effect of network security protection, and ensure the safe and stable operation of the network system.

[0005] To achieve the above object, the present invention provides an adaptive optimization method for network security devices based on rule analysis, including: Determine a plurality of network security devices, obtain a plurality of historical feedback behavior patterns corresponding to each network security device, and divide the historical feedback behavior patterns into historical security feedback behavior patterns and historical abnormal feedback behavior patterns; Analyze the historical security feedback behavior patterns and historical abnormal feedback behavior patterns, determine a security feedback rule data set and an abnormal feedback rule data set, and calculate an initial historical security processing factor and an initial historical abnormal processing factor of the network security device according to the security feedback rule data set and the abnormal feedback rule data set; Normalize all initial historical security processing factors and initial historical anomaly processing factors to construct an initial processing factor set, and split the initial processing factor set into a first initial processing factor set and a second initial processing factor set; Process the first initial processing factor set and the second initial processing factor set, and calculate the historical security event processing coefficient of the network security device based on the processing results; Extract the historical security event processing coefficient corresponding to each network security device, and perform adaptive optimization on multiple network security devices according to all the historical security event processing coefficients.

[0006] Further, when obtaining multiple historical feedback behavior patterns corresponding to each network security device and dividing the historical feedback behavior patterns into historical security feedback behavior patterns and historical anomaly feedback behavior patterns, it includes: Extract the device feedback rule data corresponding to each historical feedback behavior pattern; Obtain the security device feedback rule data corresponding to each device feedback rule data, and determine whether all the device feedback rule data are less than the security device feedback rule data; If so, divide the corresponding historical feedback behavior pattern into the historical security feedback behavior pattern; If not, divide the corresponding historical feedback behavior pattern into the historical anomaly feedback behavior pattern.

[0007] Further, when calculating the initial historical anomaly processing factor of the network security device according to the anomaly feedback rule data set, it includes: Determine the anomaly feedback rule data set according to the device feedback rule data corresponding to the historical anomaly feedback behavior pattern; Calculate the device feedback rule data in the anomaly feedback rule data set to obtain a first subset processing factor; ; where q1 is the first subset processing factor, y is the number of device feedback rule data in the anomaly feedback rule data set, and y u is the u-th device feedback rule data in the anomaly feedback rule data set; Sort the device feedback rule data in the anomaly feedback rule data set from small to large, and determine the sorted anomaly feedback rule data set based on the sorting result. Calculate the sorted anomaly feedback rule data set to obtain a second subset processing factor; ; where q2 is the second subset processing factor, e is the number of device feedback rule data in the sorted anomaly feedback rule data set, and t w+1It is the feedback rule data of the (w + 1)-th device in the sorting anomaly feedback rule dataset, t w It is the feedback rule data of the w-th device in the sorting anomaly feedback rule dataset; Calculate the initial historical anomaly processing factor of the network security device based on the first subset processing factor and the second subset processing factor.

[0008] Further, when calculating the initial historical anomaly processing factor of the network security device based on the first subset processing factor and the second subset processing factor, it includes: Configure a first calculation coefficient for the first subset processing factor and a second calculation coefficient for the second subset processing factor; Calculate the initial historical security processing factor of the network security device according to the following formula: ; where p is the initial historical security processing factor of the network security device, a1 is the first calculation coefficient, and a2 is the second calculation coefficient.

[0009] Further, when calculating the initial historical security processing factor of the network security device according to the security feedback rule dataset, it includes: Determine the security feedback rule dataset according to the device feedback rule data corresponding to the historical security feedback behavior pattern; Calculate the initial historical security processing factor of the network security device according to the following formula: ; where s is the initial historical security processing factor of the network security device, n is the number of device feedback rule data in the security feedback rule dataset, d i is the i-th device feedback rule data in the security feedback rule dataset, f is the mean value of the device feedback rule data corresponding to the security feedback rule dataset, n1 is all satisfying ≥ 0.15, and g is the variance of all .

[0010] Further, when splitting the initial processing factor set into a first initial processing factor set and a second initial processing factor set, it includes: Calculate the standardized processing factor corresponding to the initial processing factor set; Taking the standardized processing factor as the clustering center, determine the clustering distance from each initial processing factor in the initial processing factor set to the standardized processing factor; Sort all the clustering distances from small to large, and select the initial processing factors corresponding to the first v clustering distances to generate a first extraction mark; Calculate the mean value of the initial processing factors corresponding to the initial processing factor set, extract all the initial processing factors greater than the mean value of the initial processing factors, and generate a second extraction tag; Analyze the initial processing factors corresponding to the first extraction tag and the second extraction tag, extract the intersection initial processing factors corresponding to the first extraction tag and the second extraction tag, and construct a first initial processing factor set according to the intersection initial processing factors; Construct a second initial processing factor set according to the remaining initial processing factors.

[0011] Further, when calculating the standardized processing factors corresponding to the initial processing factor set, it includes: Calculate the standardized processing factors corresponding to the initial processing factor set according to the following formula: ; where h is the standardized processing factor corresponding to the initial processing factor set, k is the number of initial processing factors in the initial processing factor set, c j is the j-th initial processing factor in the initial processing factor set, c min is the smallest initial processing factor in the initial processing factor set, c max is the largest initial processing factor in the initial processing factor set, is the maximum value of all ;

[0012] Further, when processing the first initial processing factor set and the second initial processing factor set, and calculating the historical security event processing coefficient of the network security device based on the processing results, it includes: Determine the first head initial processing factor and the first tail initial processing factor of the first initial processing factor set; Determine the second head initial processing factor and the second tail initial processing factor of the second initial processing factor set; Calculate the mean value of the first initial processing factors corresponding to the first initial processing factor set, and mark the mean value of the first initial processing factors in the first initial processing factor set as the first marking point; Calculate the mean value of the second initial processing factors corresponding to the second initial processing factor set, and mark the mean value of the second initial processing factors in the second initial processing factor set as the second marking point; Count the number b1 of the first initial processing factors from the first marking point to the first tail initial processing factor; Count the number b2 of the second initial processing factors from the second marking point to the second head initial processing factor; Calculate a first initial processing factor ratio m1 based on the first initial processing factor quantity b1 and the second initial processing factor quantity b2, where, , b is the total quantity of initial processing factors corresponding to the first initial processing factor set and the second initial processing factor set; Count the third initial processing factor quantity b3 of the first marked point to the first head initial processing factor; Count the fourth initial processing factor quantity b4 of the second marked point to the second tail initial processing factor; Calculate a second initial processing factor ratio m2 based on the third initial processing factor quantity b3 and the fourth initial processing factor quantity b4, where, ; Calculate the absolute value of the difference between the first initial processing factor ratio and the second initial processing factor ratio, and calculate the sum value of the first initial processing factor ratio and the second initial processing factor ratio; Take the ratio of the absolute value of the difference to the sum value as the historical security event processing coefficient of the network security device.

[0013] Further, when extracting the historical security event processing coefficients corresponding to each network security device and performing adaptive optimization on multiple network security devices according to all the historical security event processing coefficients, it includes: Calculate the variance of the historical security event processing coefficients corresponding to all historical security event processing coefficients; Delete all historical security event processing coefficients less than the variance of the historical security event processing coefficients, and extract the remaining historical security event processing coefficients; Perform linkage processing on the network security devices corresponding to the remaining historical security event processing coefficients.

[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention discloses a method for adaptive optimization of network security devices based on rule analysis, obtains the historical feedback behavior patterns of network security devices, divides them into historical security feedback behavior patterns and historical abnormal feedback behavior patterns, determines the security feedback rule data set and the abnormal feedback rule data set, calculates the initial historical security processing factors and the initial historical abnormal processing factors, and performs normalization processing, constructs an initial processing factor set, and splits it into a first initial processing factor set and a second initial processing factor set, calculates the historical security event processing coefficient, extracts the historical security event processing coefficients of each network security device, performs adaptive optimization on multiple network security devices, removes the network security devices with poor protection effects, realizes effective management and coordination, gives full play to the protection functions of each network security device, improves the efficiency and effect of network security protection, and ensures the safe and stable operation of the network system. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings: Figure 1 A schematic flowchart of the method for self - adaptive optimization of network security devices based on rule analysis in an embodiment of the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] The following further describes in detail the specific embodiments of the present invention in conjunction with the drawings and embodiments. The following embodiments are used to illustrate the present invention but are not intended to limit the scope of the present invention.

[0017] In the description of the present application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present application.

[0018] The terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present application, unless otherwise stated, the meaning of "a plurality" is two or more.

[0019] In the description of the present application, it should be noted that unless otherwise clearly defined and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.

[0020] The following is a description of the preferred embodiments of the present invention in conjunction with the drawings.

[0021] As Figure 1 shown, an embodiment of the present invention discloses a method for self - adaptive optimization of network security devices based on rule analysis, including: S110: Determine multiple network security devices, obtain multiple historical feedback behavior patterns corresponding to each network security device, and divide the historical feedback behavior patterns into historical security feedback behavior patterns and historical abnormal feedback behavior patterns; In this embodiment, the historical feedback behavior pattern refers to a series of reactions and response mechanisms demonstrated by a network security device during the entire process from encountering a security event until the event is resolved.

[0022] In some embodiments of the present application, when obtaining multiple historical feedback behavior patterns corresponding to each network security device and dividing the historical feedback behavior patterns into historical security feedback behavior patterns and historical abnormal feedback behavior patterns, it includes: Extract the device feedback rule data corresponding to each historical feedback behavior pattern; Obtain the security device feedback rule data corresponding to each device feedback rule data, and determine whether all the device feedback rule data are less than the security device feedback rule data; If so, divide the corresponding historical feedback behavior pattern into the historical security feedback behavior pattern; If not, divide the corresponding historical feedback behavior pattern into the historical abnormal feedback behavior pattern.

[0023] In this embodiment, each historical feedback behavior pattern corresponds to some device feedback rule data. The device feedback rule data includes data loss rate, network traffic change rate, security event response time, system load rate, etc., which are not shown one by one. For example, the data loss rate is 20% and the network traffic change rate is 15%.

[0024] In this embodiment, the security device feedback rule data corresponds one-to-one with the above device feedback rule data. For example, if the device feedback rule data is the data loss rate, the corresponding security device feedback rule data is 5%. Here, it is shown by way of example, and it can be adjusted according to the actual situation specifically.

[0025] The beneficial effects of the above technical solution are: The present invention realizes the accurate division of historical feedback behavior patterns according to the device feedback rule data and the corresponding security device feedback rule data, and obtains historical security feedback behavior patterns and historical abnormal feedback behavior patterns, which can provide a basis for subsequent calculations through the historical security feedback behavior patterns and historical abnormal feedback behavior patterns.

[0026] S120: Analyze the historical security feedback behavior patterns and historical abnormal feedback behavior patterns, determine a security feedback rule data set and an abnormal feedback rule data set, and calculate the initial historical security processing factor and the initial historical abnormal processing factor of the network security device according to the security feedback rule data set and the abnormal feedback rule data set; In some embodiments of the present application, when calculating the initial historical anomaly processing factor of the network security device according to the anomaly feedback rule dataset, it includes: Determine the anomaly feedback rule dataset according to the device feedback rule data corresponding to the historical anomaly feedback behavior pattern; Calculate the device feedback rule data in the anomaly feedback rule dataset to obtain the first subset processing factor; ; Among them, q1 is the first subset processing factor, y is the number of device feedback rule data in the anomaly feedback rule dataset, and y u is the u-th device feedback rule data in the anomaly feedback rule dataset; Sort the device feedback rule data in the anomaly feedback rule dataset from small to large, and determine the sorted anomaly feedback rule dataset based on the sorting result. Calculate the sorted anomaly feedback rule dataset to obtain the second subset processing factor; ; Among them, q2 is the second subset processing factor, e is the number of device feedback rule data in the sorted anomaly feedback rule dataset, and t w+1 is the (w + 1)-th device feedback rule data in the sorted anomaly feedback rule dataset, and t w is the w-th device feedback rule data in the sorted anomaly feedback rule dataset; Calculate the initial historical anomaly processing factor of the network security device based on the first subset processing factor and the second subset processing factor.

[0027] The beneficial effects of the above technical solutions are: The present invention first calculates the first subset processing factor and the second subset processing factor, provides two calculation methods, ensures the calculation accuracy, avoids calculation errors, and fully analyzes the anomaly feedback rule dataset.

[0028] In some embodiments of the present application, when calculating the initial historical anomaly processing factor of the network security device based on the first subset processing factor and the second subset processing factor, it includes: Configure a first calculation coefficient for the first subset processing factor and a second calculation coefficient for the second subset processing factor; Calculate the initial historical security processing factor of the network security device according to the following formula: ; Among them, p is the initial historical security processing factor of the network security device, a1 is the first calculation coefficient, and a2 is the second calculation coefficient.

[0029] In this embodiment, the first calculation coefficient is greater than the second calculation coefficient. Here, the first calculation coefficient is preferably 0.7, and the second calculation coefficient is preferably 0.3. Specifically, it can also be adjusted adaptively according to actual requirements.

[0030] The beneficial effects of the above technical solution are as follows: The present invention calculates the initial historical anomaly processing factor of the network security device based on the first subset processing factor and the second subset processing factor. On the one hand, it ensures the calculation accuracy of the initial historical anomaly processing factor. On the other hand, it provides a reliable basis for the analysis of the protection performance of the corresponding network security device and reflects the historical anomaly situation of the network security device.

[0031] In some embodiments of the present application, when calculating the initial historical security processing factor of the network security device according to the security feedback rule dataset, it includes: Determine the security feedback rule dataset according to the device feedback rule data corresponding to the historical security feedback behavior pattern; Calculate the initial historical security processing factor of the network security device according to the following formula: ; where s is the initial historical security processing factor of the network security device, n is the number of device feedback rule data in the security feedback rule dataset, d i is the i-th device feedback rule data in the security feedback rule dataset, f is the mean value of the device feedback rule data corresponding to the security feedback rule dataset, n1 is all that satisfy ≥0.15, and g is the variance of all .

[0032] The beneficial effects of the above technical solution are as follows: The present invention further provides a reliable basis for the analysis of the protection performance of the corresponding network security device by calculating the initial historical security processing factor and reflects the historical security situation of the network security device.

[0033] S130: Normalize all the initial historical security processing factors and initial historical anomaly processing factors to construct an initial processing factor set, and split the initial processing factor set into a first initial processing factor set and a second initial processing factor set; In this embodiment, the normalization method will not be introduced in detail here.

[0034] In this embodiment, the normalized initial historical security processing factors and initial historical anomaly processing factors in the initial processing factor set are uniformly named initial processing factors.

[0035] In some embodiments of the present application, when splitting the initial processing factor set into a first initial processing factor set and a second initial processing factor set, it includes: Calculate the standardized processing factor corresponding to the initial processing factor set; Taking the standardized processing factor as the clustering center, determine the clustering distance from each initial processing factor in the initial processing factor set to the standardized processing factor; Sort all the clustering distances from small to large, and select the initial processing factors corresponding to the first v clustering distances to generate a first extraction mark; Calculate the mean value of the initial processing factors corresponding to the initial processing factor set, extract all the initial processing factors greater than the mean value of the initial processing factors to generate a second extraction mark; Analyze the initial processing factors corresponding to the first extraction mark and the second extraction mark, extract the intersection initial processing factors corresponding to the first extraction mark and the second extraction mark, and construct a first initial processing factor set according to the intersection initial processing factors; Construct a second initial processing factor set according to the remaining initial processing factors.

[0036] In this embodiment, v is preferably 8, that is, extract the initial processing factors corresponding to the first 8 clustering distances to generate a first extraction mark.

[0037] In this embodiment, analyzing the initial processing factors corresponding to the first extraction mark and the second extraction mark means judging whether there is an intersection between the initial processing factors corresponding to the first extraction mark and the second extraction mark. If so, extract the intersection initial processing factors.

[0038] The beneficial effects of the above technical solution are: The present invention constructs a first initial processing factor set and a second initial processing factor set, realizing a refined analysis of the initial processing factor set, and further ensuring the calculation accuracy of the subsequent historical safety event processing coefficient.

[0039] In some embodiments of the present application, when calculating the standardized processing factor corresponding to the initial processing factor set, it includes: Calculate the standardized processing factor corresponding to the initial processing factor set according to the following formula: ; where h is the standardized processing factor corresponding to the initial processing factor set, k is the number of initial processing factors in the initial processing factor set, c j is the jth initial processing factor in the initial processing factor set, c min is the smallest initial processing factor in the initial processing factor set, c max is the largest initial processing factor in the initial processing factor set, for all The maximum value.

[0040] S140: Process the first initial processing factor set and the second initial processing factor set, and calculate the historical security event processing coefficient of the network security device based on the processing result; In some embodiments of the present application, when processing the first initial processing factor set and the second initial processing factor set and calculating the historical security event processing coefficient of the network security device based on the processing result, it includes: Determine the first head initial processing factor and the first tail initial processing factor of the first initial processing factor set; Determine the second head initial processing factor and the second tail initial processing factor of the second initial processing factor set; Calculate the first initial processing factor mean corresponding to the first initial processing factor set, and mark the first initial processing factor mean in the first initial processing factor set as the first marking point; Calculate the second initial processing factor mean corresponding to the second initial processing factor set, and mark the second initial processing factor mean in the second initial processing factor set as the second marking point; Count the number b1 of the first initial processing factors from the first marking point to the first tail initial processing factor; Count the number b2 of the second initial processing factors from the second marking point to the second head initial processing factor; Calculate the first initial processing factor quantity ratio m1 according to the first initial processing factor quantity b1 and the second initial processing factor quantity b2, where , b is the total number of initial processing factors corresponding to the first initial processing factor set and the second initial processing factor set; Count the number b3 of the third initial processing factors from the first marking point to the first head initial processing factor; Count the number b4 of the fourth initial processing factors from the second marking point to the second tail initial processing factor; Calculate the second initial processing factor quantity ratio m2 according to the third initial processing factor quantity b3 and the fourth initial processing factor quantity b4, where ; Calculate the absolute value of the difference between the first initial processing factor quantity ratio and the second initial processing factor quantity ratio, and calculate the sum value of the first initial processing factor quantity ratio and the second initial processing factor quantity ratio; Take the ratio of the absolute value of the difference to the sum value as the historical security event processing coefficient of the network security device.

[0041] In this embodiment, the head initial processing factor refers to the first data of a data set. For example, if the data set is {2, 5, 6}, the head initial processing factor is 2 and the tail initial processing factor is 6. This is illustrated by way of example for easy understanding.

[0042] In this embodiment, if the first initial processing factor set contains the first initial processing factor mean value, the first initial processing factor quantity also correspondingly includes the first initial processing factor mean value, and the second initial processing factor quantity also correspondingly includes the second initial processing factor mean value.

[0043] In this embodiment, if the second initial processing factor set contains the second initial processing factor mean value, the third initial processing factor quantity also correspondingly includes the second initial processing factor mean value, and the fourth initial processing factor quantity also correspondingly includes the second initial processing factor mean value.

[0044] The beneficial effects of the above technical solution are as follows: The present invention calculates the absolute value of the difference based on the ratio of the first initial processing factor quantity and the ratio of the second initial processing factor quantity, calculates the sum value based on the ratio of the first initial processing factor quantity and the ratio of the second initial processing factor quantity, and takes the ratio of the absolute value of the difference to the sum value as the historical security event processing coefficient of the network security device, ensuring the calculation accuracy of the historical security event processing coefficient, without manual participation in the calculation, eliminating the error in the calculation process. The historical security event processing coefficient can reflect the protection performance of a network security device when facing security events. When the historical security event processing coefficient is larger, the corresponding network security device has stronger protection performance. On the contrary, when the historical security event processing coefficient is smaller, the corresponding network security device has weaker protection performance. The historical security event processing coefficient can provide a judgment basis for removing network security devices with poor protection effects.

[0045] S150: Extract the historical security event processing coefficient corresponding to each network security device, and perform adaptive optimization on multiple network security devices according to all the historical security event processing coefficients.

[0046] In some embodiments of the present application, when extracting the historical security event processing coefficient corresponding to each network security device and performing adaptive optimization on multiple network security devices according to all the historical security event processing coefficients, it includes: Calculate the variance of the historical security event processing coefficients corresponding to all the historical security event processing coefficients; Delete all the historical security event processing coefficients that are less than the variance of the historical security event processing coefficients, and extract the remaining historical security event processing coefficients; Perform linkage processing on the network security devices corresponding to the remaining historical security event processing coefficients.

[0047] In this embodiment, the network security devices corresponding to the remaining historical security event processing coefficients are linked for collaborative response to security events.

[0048] The beneficial effects of the above technical solution are as follows: The present invention can remove network security devices with poor protection effects, effectively manage and coordinate network security devices, give full play to the protection functions of each network security device, improve the efficiency and effect of network security protection, and ensure the safe and stable operation of the network system.

[0049] In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in a suitable manner in any one or more embodiments or examples.

[0050] Although the present invention has been described above with reference to embodiments, various improvements can be made to it and components therein can be replaced with equivalents without departing from the scope of the present invention. In particular, as long as there is no structural conflict, the various features in the embodiments disclosed by the present invention can be combined with each other in any way, and the situations of these combinations are not all described in this specification only for the consideration of saving space and resources.

[0051] Those of ordinary skill in the art can understand that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. An adaptive optimization method for network security devices based on rule analysis, characterized in that, Including: Determine multiple network security devices, obtain multiple historical feedback behavior patterns corresponding to each network security device, and divide the historical feedback behavior patterns into historical security feedback behavior patterns and historical abnormal feedback behavior patterns; Analyze the historical security feedback behavior patterns and historical abnormal feedback behavior patterns, determine a security feedback rule data set and an abnormal feedback rule data set, and calculate an initial historical security processing factor and an initial historical abnormal processing factor of the network security device according to the security feedback rule data set and the abnormal feedback rule data set; Perform normalization processing on all the initial historical security processing factors and initial historical abnormal processing factors, construct an initial processing factor set, and split the initial processing factor set into a first initial processing factor set and a second initial processing factor set; Process the first initial processing factor set and the second initial processing factor set, and calculate a historical security event processing coefficient of the network security device based on the processing results; Extract the historical security event processing coefficients corresponding to each network security device, and perform adaptive optimization on the multiple network security devices according to all the historical security event processing coefficients.

2. The adaptive optimization method for network security devices based on rule analysis according to claim 1, characterized in that When obtaining multiple historical feedback behavior patterns corresponding to each network security device and dividing the historical feedback behavior patterns into historical security feedback behavior patterns and historical abnormal feedback behavior patterns, it includes: Extract device feedback rule data corresponding to each historical feedback behavior pattern; Obtain security device feedback rule data corresponding to each device feedback rule data, and determine whether all the device feedback rule data are less than the security device feedback rule data; If so, divide the corresponding historical feedback behavior pattern into the historical security feedback behavior pattern; If not, divide the corresponding historical feedback behavior pattern into the historical abnormal feedback behavior pattern.

3. The method for adaptively optimizing a network security device based on rule analysis according to claim 2, wherein When calculating the initial historical abnormal processing factor of the network security device according to the abnormal feedback rule data set, it includes: Determine an abnormal feedback rule data set according to the device feedback rule data corresponding to the historical abnormal feedback behavior pattern; Calculate the device feedback rule data in the abnormal feedback rule data set to obtain a first subset processing factor; ; Among them, q1 is the processing factor of the first subset, y is the number of device feedback rule data in the abnormal feedback rule dataset, and y u is the u-th device feedback rule data in the abnormal feedback rule dataset; Sort the device feedback rule data in the abnormal feedback rule data set from small to large, and determine a sorted abnormal feedback rule data set based on the sorting result. Calculate the sorted abnormal feedback rule data set to obtain a second subset processing factor; ; Among them, q2 is the second subset processing factor, e is the number of device feedback rule data in the sorting anomaly feedback rule dataset, and t w+1 is the (w + 1)-th device feedback rule data in the sorting anomaly feedback rule dataset, and t w is the w-th device feedback rule data in the sorting anomaly feedback rule dataset; Calculate the initial historical abnormal processing factor of the network security device based on the first subset processing factor and the second subset processing factor.

4. The method for adaptively optimizing a network security device based on rule analysis according to claim 3, characterized in that When calculating the initial historical abnormal processing factor of the network security device based on the first subset processing factor and the second subset processing factor, it includes: Configure a first calculation coefficient for the first subset processing factor and a second calculation coefficient for the second subset processing factor; Calculate the initial historical security processing factor of the network security device according to the following formula: ; where p is the initial historical security processing factor of the network security device, a1 is the first calculation coefficient, and a2 is the second calculation coefficient.

5. The method for adaptively optimizing a network security device based on rule analysis according to claim 2, characterized in that When calculating the initial historical security processing factor of the network security device according to the security feedback rule data set, it includes: Determine the security feedback rule data set according to the device feedback rule data corresponding to the historical security feedback behavior pattern; Calculate the initial historical security processing factor of the network security device according to the following formula: ; Among them, s is the initial historical security processing factor of the network security device, n is the number of device feedback rule data in the security feedback rule dataset, and d i is the i-th device feedback rule data in the security feedback rule dataset, f is the mean of the device feedback rule data corresponding to the security feedback rule dataset, and n1 is all satisfying ≥0.15, and g is the variance of all .

6. The method for adaptively optimizing a network security device based on rule analysis according to claim 1, wherein When splitting the initial processing factor set into a first initial processing factor set and a second initial processing factor set, it includes: Calculate the standardized processing factor corresponding to the initial processing factor set; Taking the standardized processing factor as the clustering center, determine the clustering distance from each initial processing factor in the initial processing factor set to the standardized processing factor; Sort all the clustering distances from small to large, and select the initial processing factors corresponding to the first v clustering distances to generate a first extraction mark; Calculate the mean value of the initial processing factors corresponding to the initial processing factor set, and extract all the initial processing factors greater than the mean value of the initial processing factors to generate a second extraction mark; Analyze the initial processing factors corresponding to the first extraction mark and the second extraction mark, extract the intersection initial processing factors corresponding to the first extraction mark and the second extraction mark, and construct a first initial processing factor set according to the intersection initial processing factors; Construct a second initial processing factor set according to the remaining initial processing factors.

7. The method for adaptively optimizing a network security device based on rule analysis according to claim 1, wherein When calculating the standardized processing factor corresponding to the initial processing factor set, it includes: Calculate the standardized processing factor corresponding to the initial processing factor set according to the following formula: ; Among them, h is the standardized processing factor corresponding to the initial processing factor set, k is the number of initial processing factors in the initial processing factor set, c j is the j-th initial processing factor in the initial processing factor set, c min is the smallest initial processing factor in the initial processing factor set, c max is the largest initial processing factor in the initial processing factor set, is the maximum value of all of them.

8. The method for adaptive optimization of a network security device based on rule analysis according to claim 1, wherein When processing the first initial processing factor set and the second initial processing factor set, and calculating the historical security event processing coefficient of the network security device based on the processing results, it includes: Determine the first head initial processing factor and the first tail initial processing factor of the first initial processing factor set; Determine the second head initial processing factor and the second tail initial processing factor of the second initial processing factor set; Calculate the mean value of the first initial processing factors corresponding to the first initial processing factor set, and mark the mean value of the first initial processing factors in the first initial processing factor set as the first marking point; Calculate the mean value of the second initial processing factors corresponding to the second initial processing factor set, and mark the mean value of the second initial processing factors in the second initial processing factor set as the second marking point; Count the number b1 of the first initial processing factors from the first marking point to the first tail initial processing factor; Count the number b2 of the second initial processing factors from the second marking point to the second head initial processing factor; Calculate a first initial processing factor ratio m1 based on the first initial processing factor quantity b1 and the second initial processing factor quantity b2, where, , b is the total quantity of initial processing factors corresponding to the first initial processing factor set and the second initial processing factor set; Count the number b3 of the third initial processing factors from the first marking point to the first head initial processing factor; Count the number b4 of the fourth initial processing factors from the second marking point to the second tail initial processing factor; Calculate a second initial processing factor ratio m2 according to the third initial processing factor quantity b3 and the fourth initial processing factor quantity b4, where, ; Calculate the absolute value of the difference between the ratio of the number of the first initial processing factors and the ratio of the number of the second initial processing factors, and calculate the sum value of the ratio of the number of the first initial processing factors and the ratio of the number of the second initial processing factors; Take the ratio of the absolute value of the difference to the sum value as the historical security event processing coefficient of the network security device.

9. The method for adaptively optimizing a network security device based on rule analysis according to claim 1, characterized in that When extracting the historical security event processing coefficients corresponding to each network security device and adaptively optimizing multiple network security devices based on all the historical security event processing coefficients, it includes: Calculating the variance of the historical security event processing coefficients corresponding to all the historical security event processing coefficients; Deleting all the historical security event processing coefficients that are less than the variance of the historical security event processing coefficients, and extracting the remaining historical security event processing coefficients; Performing linkage processing on the network security devices corresponding to the remaining historical security event processing coefficients.

Citation Information

Cited By

  • Eye fumigation therapeutic apparatus supervision method based on data fusion analysis

    CN121709187A

  • An eye fumigation therapeutic instrument supervision method based on data fusion analysis

    CN121709187B