Information security assessment method and system based on cloud computing
By constructing a cloud-based information security assessment method, using multimodal data encryption and quantum heuristic algorithms to generate dynamic defense strategies, the problems of insufficient correlation and defense lag in multimodal data in the cloud computing environment are solved, and efficient information security assessment is achieved.
Patent Information
- Application Number
- CN202510492919.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-18
AI Technical Summary
When facing a dynamic environment, the information security assessment method in the existing cloud computing environment is difficult to adapt to the real-time changing attack surface, resulting in a zero-day attack detection delay and missed detection rate rising. Traditional encryption mechanisms increase computing overhead and are difficult to resist side channel attacks. The lack of correlation of multimodal data leads to frequent false alarms and missed detection phenomena.
By collecting multimodal data and performing local desensitization, encrypting with node unique identifiers, building spatiotemporal data packets, combining edge node federated learning and quantum heuristic algorithms, generating dynamic defense strategies, using Do-Calculus algorithm to locate root cause threats, combining threat intelligence database to build spatiotemporal causal graphs, and generating evaluation audit logs.
It has achieved a breakthrough in the aspects of privacy protection and dynamic defense, reduced multimodal data correlation error, improved the ground state energy convergence speed of the APT attack detection model, reduced false alarm rate, shortened the delay in the generation of defense strategy, and reduced resource consumption.
Smart Images

Figure CN120342693A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an information security assessment method and system based on cloud computing. Background Art
[0002] Currently, the information security assessment of the cloud computing environment generally adopts a detection mechanism combining rule matching and static models. For example, pattern recognition is performed on log events based on a predefined threat feature library, or alarms are triggered through fixed thresholds. Sensitive data desensitization relies on regular expressions to uniformly mask fields such as IP addresses and user identities, and encryption transmission uses a single algorithm, combined with a periodic key rotation strategy. Vulnerability scanning tools need to rely on an offline updated feature library to match known attack signatures. Such methods can partially meet the requirements in the static resource allocation scenario, but in the face of the cloud-native dynamic environment, static rules are difficult to adapt to the real-time changing attack surface, resulting in an increase in the detection delay and false negative rate of zero-day attacks. In addition, due to the inability of traditional classification models to capture the non-linear correlation characteristics of API access timing and resource consumption in the microservice call chain, false alarms and false negatives occur frequently.
[0003] Existing technologies mostly construct threat association networks based on linear statistical methods or use traditional clustering algorithms to divide risk patterns. The threat level is divided by statistically correlating the protocol type and the number of login failures, or a Bayesian network is used to infer the attack path. However, the linear model has insufficient representation ability for cross-layer service dependencies, resulting in misjudgment of threat propagation paths; the static causal inference framework cannot quantify the evolution law of root cause threats with the elastic scaling of resources because it does not integrate spatio-temporal dynamic characteristics. At the same time, due to the rigid key rotation strategy and the defect of multi-tenant data isolation in traditional encryption mechanisms, it not only increases the computational overhead but also is difficult to resist side-channel attacks, further restricting the security efficiency of the cloud platform. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides an information security assessment method based on cloud computing to solve the problems of insufficient spatio-temporal feature correlation and lagging generation of dynamic defense strategies in multi-modal threat assessment.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides an information security assessment method based on cloud computing, which includes,
[0008] Collect multi-modal data, perform local desensitization processing on the multi-modal data through a trusted execution environment, attach spatio-temporal tags, and use the unique node identifier for symmetric encryption and asymmetric negotiation for encryption to generate spatio-temporal data packets;
[0009] Through the edge node federated learning architecture, secure multi-party computation is used to aggregate threat features, and the desensitized multi-modal data in the spatio-temporal data packet is mapped into a standardized feature vector to construct a multi-modal threat matrix;
[0010] Based on the quantum-inspired algorithm, a risk assessment model is constructed. The encrypted gradients of edge nodes are aggregated through the federated reinforcement learning architecture, and the threat feature vector is output to the cloud causal inference engine. A spatio-temporal causal graph is constructed in combination with the threat intelligence library, and the Do-Calculus algorithm is applied to locate the root cause threat and generate a dynamic defense strategy;
[0011] Based on the edge node, the dynamic defense strategy is parsed, and the access control rules are adjusted by using the spatial coordinates mapped in real time by the digital twin. The policy execution log is encrypted and stored locally, and an evaluation audit log is generated.
[0012] As a preferred solution of the information security assessment method based on cloud computing according to the present invention, wherein: the multi-modal data includes network traffic metadata, security audit logs, and spatial coordinate information;
[0013] The collection of multi-modal data and local desensitization processing through trusted execution includes,
[0014] By mounting the eBPF program through the edge node kernel protocol stack, the metadata of L3-L7 layers is captured in real time, and the sampling frequency is dynamically adjusted based on the bandwidth utilization rate;
[0015] The security audit log collects user operation events through the Linux Auditd framework, and uses regular expressions to dynamically mask sensitive fields in the trusted execution environment. The masking rules are dynamically adjusted according to the data classification level;
[0016] When the spatial coordinate information calculates the three-dimensional coordinates through the trilateration algorithm, the Kalman filter is used to eliminate the multipath effect noise, and the non-collinear deployment of Wi-Fi access points is combined to optimize the positioning accuracy.
[0017] As a preferred solution of the information security assessment method based on cloud computing according to the present invention, wherein: the mapping of the desensitized multi-modal data in the spatio-temporal data packet into a standardized feature vector means,
[0018] The protocol type in the network traffic metadata is binary encoded to generate a byte identifier, and the time interval frequency distribution of the same protocol data packets within the time window is statistically analyzed. The port number is compressed by range normalization;
[0019] The user ID in the security audit log is converted into a hash integer, the operation result is mapped into a boolean value, and the event frequency is statistically analyzed in the time window;
[0020] Perform radix conversion on the GeoHash string in the spatial coordinate information, and calculate the moving speed through the quotient of the coordinate difference between adjacent time windows and the time increment;
[0021] Based on the global mean and standard deviation pre-computed in the cloud, perform Z-score standardization on the network traffic metadata, security audit logs, and spatial coordinate information respectively, and splice them into a standardized feature vector.
[0022] As a preferred solution of the information security assessment method based on cloud computing according to the present invention, wherein: the construction of the risk assessment model by the quantum heuristic algorithm includes,
[0023] Adopt the path integral Monte Carlo method to simulate the quantum annealing process, map the threat features to the quantum Hamiltonian, and characterize the energy interaction relationship between the features;
[0024] Through dynamic parameter adjustment, the annealing magnetic field strength decays exponentially with time to optimize the quantum state transition, the threat correlation strength activation threshold is dynamically calculated based on the global mean and standard deviation, filter out low-correlation noise, and use federated reinforcement learning to aggregate encrypted gradients to construct a risk assessment model.
[0025] As a preferred solution of the information security assessment method based on cloud computing according to the present invention, wherein: the construction of the spatio-temporal causal graph in combination with the threat intelligence library and the application of the Do-Calculus algorithm to locate the root cause threat include,
[0026] Based on the quantum projection vector and the threat intelligence library, fuse spatio-temporal tags to construct a spatio-temporal tensor, and use the spatial autocorrelation index to quantify the geographical aggregation of the attack source.
[0027] Through the Do-Calculus algorithm combined with the time series Granger causality test, calculate the average causal effect of the candidate nodes, and use the CVSS vulnerability score and information entropy to screen the root cause threats, and output the root cause threat location result.
[0028] As a preferred solution of the information security assessment method based on cloud computing according to the present invention, wherein: the generation of the evaluation audit log includes,
[0029] Feed back the real-time changes of the network traffic metadata, security audit logs, and spatial coordinate information to the federated learning framework, jointly update the weights of the risk assessment model, encrypt and store the optimized policy execution logs, and generate the evaluation audit log.
[0030] In a second aspect, the present invention provides an information security assessment system based on cloud computing, including,
[0031] The data acquisition module is used to acquire multimodal data, perform local desensitization processing on the multimodal data through a trusted execution environment, attach spatio-temporal tags, and use the unique node identifier for symmetric encryption and asymmetric negotiation for encryption to generate spatio-temporal data packets;
[0032] The federated analysis module is used to aggregate threat features through a secure multi-party computation by means of an edge node federated learning architecture, map the desensitized multimodal data in the spatio-temporal data packet into a standardized feature vector, and construct a multimodal threat matrix;
[0033] The quantum factoring module is used to construct a risk assessment model based on a quantum heuristic algorithm, aggregate the encrypted gradients of edge nodes through a federated reinforcement learning architecture, output a threat feature vector to a cloud causal inference engine, and construct a spatio-temporal causal graph in combination with a threat intelligence library, apply the Do-Calculus algorithm to locate the root cause threat, and generate a dynamic defense strategy;
[0034] The dynamic defense intelligent auditing module is used to analyze the dynamic defense strategy based on edge nodes, adjust access control rules by using the spatial coordinates of real-time mapping of digital twins, and locally encrypt and store policy execution logs to generate evaluation audit logs.
[0035] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the information security assessment method based on cloud computing as described in the first aspect of the present invention is implemented.
[0036] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the information security assessment method based on cloud computing as described in the first aspect of the present invention is implemented.
[0037] The beneficial effects of the present invention are as follows: By constructing a spatio-temporal coupled multimodal threat assessment system, breakthroughs are achieved at the levels of privacy protection and dynamic defense. Based on the collaboration of dynamic spatio-temporal tags and a hybrid encryption mechanism, the cross-modal correlation error of network traffic, security logs, and spatial coordinates is reduced, effectively eliminating semantic fragmentation in feature aggregation; By simulating the quantum annealing process through path integral Monte Carlo and dynamically optimizing the Hamiltonian parameters in combination with federated reinforcement learning, the convergence speed of the ground state energy of the APT attack detection model is increased and the false alarm rate is reduced; Further integrating the spatio-temporal causal graph with the root cause localization engine of CVSS vulnerability scoring, and combining digital twin real-time mapping and KL divergence constraint, the generation delay of the defense strategy is shortened and the resource consumption is reduced. The problems of insufficient multimodal data correlation, defense lag, and verification fault in the cloud computing environment are solved, and the collaborative leap of evaluation accuracy and response efficiency is realized. Description of the Drawings
[0038] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0039] Figure 1 It is a flowchart of data collection and encryption in the embodiment.
[0040] Figure 2 It is a flowchart of quantum risk assessment in the embodiment.
[0041] Figure 3 It is a flowchart of dynamic defense and auditing in the embodiment.
[0042] Figure 4 It is a module diagram of the information security assessment system based on cloud computing in the embodiment. Specific Embodiments
[0043] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification.
[0044] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0045] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that mutually excludes other embodiments.
[0046] Embodiment, referring to Figures 1 to 4 , which is an embodiment of the present invention. This embodiment provides an information security assessment method based on cloud computing, including the following steps:
[0047] S1. Collect multi-modal data, perform local desensitization processing on the multi-modal data through a trusted execution environment, attach spatio-temporal tags, and use the unique node identifier for symmetric encryption and asymmetric negotiation for encryption to generate spatio-temporal data packets;
[0048] Specifically, it includes the following steps:
[0049] S1.1. Network traffic metadata collection is achieved by deploying network flow EBPF for traffic collection at the cloud computing edge nodes, capturing metadata of L3-L7 layers (source IP address, destination IP address, protocol type, port number, packet payload signature), calculating the bandwidth utilization rate once per second (1-second sliding window) based on bandwidth monitoring, and calculating the bandwidth utilization rate through the exponentially weighted moving average (EMA) smoothing algorithm.
[0050] Among them, the sampling frequency is dynamically adjusted based on bandwidth monitoring to the default of 100 ms, and switches to 10 ms when traffic surges.
[0051] Security audit log collection is to obtain operation security event logs (user login, file access, process startup records) through the Linux Auditd framework, and the log fields include timestamp, user ID, and operation result (success / failure).
[0052] Spatial coordinate information collection is to obtain the longitude and latitude coordinates outdoors through GPS, use multi-frequency GNSS to receive signals, integrate RTK differential correction. In the indoor environment, 3 Wi-Fi access points that support the IEEE802.11mc protocol are deployed in a non-collinear triangle distribution. The Kalman filter is used to suppress multipath effect noise, calculate the filtered distance value, and solve the three-dimensional coordinates based on the trilateration algorithm.
[0053] S1.2. Based on the trusted execution environment, sensitive information (such as credit card numbers) in the security audit logs is matched through regular expressions, the matching fields are dynamically masked, and for the source IP address and destination IP address in the network traffic metadata, partial masking is performed according to preset rules (example: RFC1918 private address range) (example: 192.168.1.1 → 192.168).
[0054] The AES-128-GCM algorithm is used to encrypt the desensitized security audit logs and traffic metadata. The key is dynamically generated by the hardware random number generator in the trusted execution environment and is bound to the CPU physical fingerprint through the SGX sealed storage technology.
[0055] It should be noted that the session key is used for a single node communication session and is destroyed after the session ends. The long-term key is used for cross-session identity authentication and is rotated every 24 hours.
[0056] S1.3. The Unix timestamp is sliced into time windows at fixed intervals (example: 10-minute granularity). The GeoHash algorithm is used to encode the longitude and latitude coordinates into strings, and the encoding accuracy is dynamically adjusted according to the privacy level of the area where the device is located. The time window identifier and the geographical grid encoding are spliced into data with spatio-temporal tags.
[0057] S1.4. Encrypt and desensitize the data with time - space tags using AES - 256 - GCM, and encapsulate it into a time - space data packet in combination with the key negotiated by ECDH over Curve25519.
[0058] S2. Aggregate threat features through secure multi - party computation using the edge - node federated learning architecture, map the desensitized multi - modal data in the time - space data packet to a standardized feature vector, and construct a multi - modal threat matrix.
[0059] S2.1. Each edge node acts as a client to establish a horizontal federated learning architecture with the cloud coordinator, and ensures that only authorized devices participate through X.509 certificate verification.
[0060] Adopt the additive secret sharing protocol. Each node splits the local model gradient into shards equal to the number of participating nodes (for example, split into 3 parts for 3 nodes), and through large - prime - number modular arithmetic, ensures that the shard values are within a finite field. After encrypting the shards, they are distributed to other nodes.
[0061] It should be noted that the shards are encrypted by AES - 128 - GCM. The key is dynamically generated by the trusted execution environment (TEE), bound to the node hardware fingerprint, and requires 3 - node threshold BLS signature verification to resist collusion attacks.
[0062] S2.2. Decrypt the time - space data packet within the trusted execution environment and map the multi - modal data according to the rules.
[0063] Among them, mapping the multi - modal data according to the rules is as follows:
[0064] Network traffic metadata is encoded as a 1 - byte binary identifier through the protocol type, and the time - interval frequency distribution of packets with the same protocol type within 10 minutes is counted. The port number is normalized to a value in the range of [0, 1], and the first 16 bytes are intercepted from the load hash (a 64 - byte hash value generated by the BLAKE3 algorithm).
[0065] The security audit log has the user ID hash as a 32 - bit integer, the operation result is encoded as a boolean value (success = 1 / failure = 0), and the time interval is statistically counted according to a 10 - minute window.
[0066] The spatial coordinate information is converted from a GeoHash string to a 5 - bit integer, and the moving speed is calculated through the coordinate difference within the time window.
[0067] Perform Z - score standardization based on the global mean and standard deviation pre - calculated by the cloud every hour to eliminate the dimension difference, and generate a standardized 58 - dimensional feature vector.
[0068] It should be noted that the network traffic metadata has 18 dimensions, the security audit log has 34 dimensions, and the spatial coordinate information has 6 dimensions, constituting a standardized 58 - dimensional feature vector.
[0069] S2.3. Use Paillier homomorphic encryption to encrypt the standardized 58-dimensional feature vector and upload it to the cloud. The cloud performs ciphertext multiplication operations. After aggregating the encrypted features of all nodes, it uses the private key to decrypt and construct a 58×58 multimodal threat matrix.
[0070] Among them, the threat matrix represents the cross-modal association strength of two types of features. The network traffic metadata is associated with the security audit log, analyzing the correlation between the surge in TCP protocol traffic and the number of login failures, the association between spatial coordinates and network traffic, and the detection of geographical aggregation of abnormal port access behaviors.
[0071] S3. Build a risk assessment model based on a quantum-inspired algorithm. Aggregate the encrypted gradients of edge nodes through a federated reinforcement learning architecture, output threat feature vectors to the cloud causal inference engine, and construct a spatio-temporal causal graph in combination with the threat intelligence library. Apply the Do-Calculus algorithm to locate the root cause threats and generate dynamic defense strategies;
[0072] S3.1. Map the multimodal threat matrix input to a quantum-inspired Hamiltonian of the quantum, which is used to characterize the interaction energy between features. Adopt path integral Monte Carlo to simulate the quantum annealing process and solve the ground state energy through Markov chain sampling.
[0073] Among them, the mapping to the Hamiltonian of the quantum is expressed as:
[0074]
[0075] In the formula, M jk is the cross-modal association strength of the features in the j-th dimension and the k-th dimension, is the activation state encoding the j-th dimension, is the activation state encoding the k-th dimension, is the driving quantum state transition in the j-th dimension, Γ(t) is the magnetic field strength annealing with time t, j is the single-dimensional feature index, k is the associated dimension index, t is the time, x is the driving quantum state transition, and H is the multimodal threat quantum Hamiltonian.
[0076] Among them, the quantum annealing simulation is expressed as:
[0077]
[0078] In the formula, Z is the normalization factor, β is the inverse temperature parameter, θ is the threat association strength activation threshold, ReLU is to filter low-correlation noise, V proj (j) is the quantum projection vector, dt is the time differential, and T is the total annealing duration.
[0079] S3.2 Input the quantum projection vector into the federated reinforcement learning architecture, generate the weight adjustment amount through the policy network, use the cloud to aggregate and encrypt the gradients, and update the global weights.
[0080] Among them, inputting the quantum projection vector into the federated reinforcement learning and generating the weight adjustment amount through the policy network is expressed as:
[0081]
[0082] In the formula, V proj (j) is the excitation probability of the j-th dimensional feature in the quantum annealing, λ is the ability to control the escape of the risk assessment model from the local optimal solution, tanh is the hyperbolic tangent function, ΔW i is the federated quantum dynamic weight adjustment amount, Ent(V proj ) is to suppress the over-concentration of the feature distribution, and η is to control the weight adjustment amount.
[0083] It should be noted that is the feature gating function, Mjj is the diagonal element of the threat matrix, μ is the global mean, and σ is the global standard deviation.
[0084] Among them, using the cloud to aggregate and encrypt the gradients and updating the global weights is expressed as:
[0085]
[0086] In the formula, R i is the random mask generated by the node, PRG is the pseudo-random generator to restore the true gradient, is the XOR operation to obfuscate the gradient, m is the number of training rounds, N is the total number of edge nodes in the federated learning, is the weight vector of the federated learning global risk assessment model after training, is the weight vector of the federated learning global risk assessment model after the (m + 1)-th round of training.
[0087] S3.3 Multiply the projection vector generated by the quantum annealing and the weight vector of the federated learning global risk assessment model after training element by element through the Hadamard Product, and based on the L2 normalization, combine the minimum constant to dynamically constrain the amplitude of the threat feature vector to [-1, 1] to generate the threat feature vector.
[0088] Among them, the L2 normalization is expressed as:
[0089]
[0090] In the formula, V threat is the normalized threat feature vector, ⊙ is the element-wise product, and ∈ is the minimum constant.
[0091] S3.4 Use multi-source heterogeneous data fusion to fuse the threat feature vector with the timestamps and geographical grid codes in the threat intelligence database to construct a spatio-temporal tensor.
[0092] Among them, the construction of the spatio-temporal tensor is expressed as:
[0093]
[0094] In the formula, T uml is the spatio-temporal tensor, u is the spatial grid index, m is the time window index, l is the threat feature dimension index, s u is the central coordinate of the spatial grid u, t m is the start time of the m-th time window, t0 is the first detection time of the attack, s src is the attack source coordinate, γ is the spatial decay radius, and α is the time decay coefficient.
[0095] Using the spatio-temporal decay function to suppress high-frequency noise is expressed as:
[0096] w(τ) = e -ατ ·sinc(ζτ)(ζ = 0.5);
[0097] In the formula, w(τ) is the time-domain window function that suppresses high-frequency noise and retains the low-frequency features of threat propagation, τ is the time interval that quantifies the evolution of the threat over time, e -ατ is the exponential decay of the threat signal intensity as the time interval τ increases, ζ is the frequency band width that adjusts the sinc function and affects the noise suppression intensity, and sinc(ζτ) is to limit the signal frequency band width and suppress high-frequency noise.
[0098] S3.5. Based on the causal discovery algorithm and the time-series Granger causality test, construct a spatio-temporal causal graph and apply Do-Calculus to calculate the intervention analysis for the candidate root cause nodes in the causal graph.
[0099] Among them, based on the causal discovery algorithm and the time-series Granger causality test is expressed as:
[0100]
[0101] In the formula, C mn is the causal effect intensity, is the value of the threat feature l at the spatial grid u at time t, s u is the coordinate of the spatial grid u, s v is the associated grid coordinate, Δτ is the dynamic optimization time delay parameter, Moran's I(s u , s v ) is the spatial autocorrelation index, and ξ is to balance local and global associations.
[0102] Among them, the analysis after applying Do-Calculus for intervention is expressed as:
[0103]
[0104] In the formula, ACE(v p ) is the average causal effect, v p is the node identifier in the causal graph, Pa(v p ) is the set of all precursor nodes directly affecting v p in the causal graph, z is the combination of parent node values, P(z) is the probability of the parent node combination, E[Eff|v p = 1, z] is the expected value of the defense effect Eff when forcibly blocking v p and the parent node combination is z, E[Eff|v p = 0, z] is the expected value of the defense effect Eff when not blocking v p and the parent node combination is z, p is the unique index of the node in the causal graph, Eff is the defense effect index, v p is the specific threat node in the causal graph.
[0105] S3.6. Based on the causal effect strength and the average causal effect, fuse the CVSS vulnerability score and the information entropy suppression to calculate the threat score, and generate a dynamic defense strategy.
[0106] Among them, the calculation of the threat score by fusing the CVSS vulnerability score and the information entropy suppression is expressed as:
[0107]
[0108] In the formula, R p is the threat score of node p, CVSS(v p ) is the CVSS score of the vulnerability corresponding to node p, Entropy(v p ) is the information entropy of node p, quantifying the uncertainty of its behavior.
[0109] Dynamically generate defense actions (block / quarantine / trap) based on the threat score and the vulnerability severity, and adaptively adjust the validity period of the strategy through the Sigmoid function in combination with the attack geographical diffusion rate, and finally generate a standardized dynamic defense strategy.
[0110] S4. Parse and execute the dynamic defense strategy based on the edge nodes, adjust the access control rules by using the spatial coordinates mapped in real time by the digital twin, and encrypt and store the strategy execution log locally;
[0111] S4.1. Construct a syntax tree for the dynamic defense strategy through an extended Backus-Naur form, and parse it into an atomic instruction set including the action type, the target object, and the effective conditions (spatiotemporal constraints).
[0112] Use the formal verification tool Z3 to solve the constraints of the atomized instruction set, ensure that each policy only maps to a unique action (such as blocking and trapping the same target are mutually exclusive), and generate standardized instructions after eliminating execution conflicts.
[0113] S4.2. Map the physical node coordinates to the digital twin space through the Kriging spatial interpolation algorithm based on the spatio-temporal tags and threat scores in the standardized instructions.
[0114] Generate virtual coordinates in combination with the threat diffusion path; when the attack source is on the diffusion path and the time is within the threat window, calculate the blocking priority through the logistic function to generate dynamic access control rules.
[0115] S4.3. Optimize the defense queue according to the ACL priority using reinforcement learning (PPO). The objective function balances the threat suppression weight and resource consumption, and uses the KL divergence to constrain the magnitude of policy updates to generate two types of policy execution instructions (real-time blocking generates dynamic packet loss rules based on traffic hashing, and precise trapping selects the honeypot configuration with the highest cosine similarity to the attack characteristics and the lowest cost), and records them through local logs.
[0116] S4.4. Aggregate the policy execution logs by time window using structured compression, remove redundant fields (such as duplicate spatio-temporal tags), and generate a compact binary format.
[0117] Encrypt the logs using the AES-256-GCM algorithm, and the key is generated and stored by the hardware security module of the edge node.
[0118] Among them, generate evaluation audit logs.
[0119] It should be noted that the security audit logs and spatial coordinate information are fed back to the federated learning framework. Each edge node first encrypts the local risk assessment model through Paillier homomorphic encryption, and the cloud aggregates the encrypted gradients and decrypts to update the weights of the global risk assessment model.
[0120] The execution process record contains logs of action type, target IP, timestamp, and spatial grid encoding. After the logs are aggregated by a 10-minute window, the SHA3-256 hash chain is used to ensure continuity.
[0121] Encrypt and store it in the local trusted execution environment using the hardware fingerprint binding key (AES-256-GCM), and verify the integrity of the hash chain by constructing a zk-SNARK arithmetic circuit to generate evaluation audit logs.
[0122] This embodiment also provides an information security assessment system based on cloud computing, including: a data collection module, a federated analysis module, a quantum factorization module, and a dynamic defense intelligent auditing module; the data collection module is used to collect multimodal data, perform local desensitization processing on the multimodal data through a trusted execution environment, attach spatio-temporal tags, and use the node unique identifier for symmetric encryption and asymmetric negotiation for encryption to generate spatio-temporal data packets; the federated analysis module is used to aggregate threat features through a secure multi-party computing based on an edge node federated learning architecture, map the desensitized multimodal data in the spatio-temporal data packets into standardized feature vectors, and construct a multimodal threat matrix; the quantum factorization module is used to construct a risk assessment model based on a quantum heuristic algorithm, aggregate the encrypted gradients of edge nodes through a federated reinforcement learning architecture, output threat feature vectors to a cloud causal inference engine, and construct a spatio-temporal causal graph in combination with a threat intelligence library, and apply the Do-Calculus algorithm to locate the root cause threat and generate a dynamic defense strategy; the dynamic defense intelligent auditing module is used to parse the dynamic defense strategy based on edge nodes, adjust access control rules by using the spatial coordinates of real-time mapping of digital twins, and locally encrypt and store policy execution logs to generate evaluation audit logs.
[0123] This embodiment also provides a computer device, which is applicable to the situation of the information security assessment method based on cloud computing, including: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to implement the information security assessment method based on cloud computing as proposed in the above embodiment.
[0124] This computer device can be a terminal. This computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of this computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be achieved through WIFI, a carrier network, NFC (near field communication), or other technologies. The display screen of this computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of this computer device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad set on the computer device housing, or an external keyboard, a touchpad, or a mouse, etc.
[0125] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the information security assessment method based on cloud computing proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, magnetic disk or optical disc.
[0126] In summary, the present invention: constructs a spatio-temporal coupled multi-modal threat assessment system, achieves breakthroughs in the aspects of privacy protection and dynamic defense, and based on the collaboration of dynamic spatio-temporal tags and hybrid encryption mechanisms, reduces the cross-modal association error of network traffic, security logs and spatial coordinates, and effectively eliminates the semantic fragmentation in feature aggregation; through path integral Monte Carlo simulation of the quantum annealing process, combines federated reinforcement learning to dynamically optimize the Hamiltonian parameters, improves the convergence speed of the ground state energy of the APT attack detection model, and reduces the false alarm rate; further integrates the root cause location engine of spatio-temporal causal graph and CVSS vulnerability scoring, and combines digital twin real-time mapping and KL divergence constraint to achieve a reduction in the generation delay of defense strategies and a reduction in resource consumption. It solves the problems of insufficient multi-modal data correlation, defense lag and verification fault in the cloud computing environment, and realizes the collaborative leap of evaluation accuracy and response efficiency.
[0127] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. An information security assessment method based on cloud computing, characterized in that: including collecting multimodal data, performing local desensitization processing on the multimodal data through a trusted execution environment, attaching spatio-temporal tags, and performing symmetric encryption and asymmetric negotiation encryption using a node unique identifier to generate spatio-temporal data packets; through an edge node federated learning architecture, using secure multi-party computation to aggregate threat features, mapping the desensitized multimodal data in the spatio-temporal data packets into a standardized feature vector, and constructing a multimodal threat matrix; constructing a risk assessment model based on a quantum-inspired algorithm, aggregating encrypted gradients of edge nodes through a federated reinforcement learning architecture, outputting a threat feature vector to a cloud causal inference engine, and combining with a threat intelligence library to construct a spatio-temporal causal graph, applying the Do-Calculus algorithm to locate the root cause threat, and generating a dynamic defense strategy; parsing the dynamic defense strategy based on edge nodes, adjusting access control rules using the spatial coordinates of real-time mapping of digital twins, and locally encrypting and storing policy execution logs to generate evaluation audit logs.
2. The information security assessment method based on cloud computing according to claim 1, characterized in that: The multimodal data includes network traffic metadata, security audit logs, and spatial coordinate information; The collecting multimodal data and performing local desensitization processing through trusted execution includes mounting an eBPF program through the edge node kernel protocol stack to capture L3-L7 layer metadata in real time, and dynamically adjusting the sampling frequency based on bandwidth utilization; security audit logs collect user operation events through the Linux Auditd framework, and use regular expressions to dynamically mask sensitive fields within a trusted execution environment, and the masking rules are dynamically adjusted according to the data classification level; when resolving three-dimensional coordinates through a trilateration algorithm for spatial coordinate information, a Kalman filter is used to eliminate multipath effect noise, and the positioning accuracy is optimized by combining non-collinear deployment of Wi-Fi access points.
3. The information security assessment method based on cloud computing according to claim 1, characterized in that: The mapping the desensitized multimodal data in the spatio-temporal data packets into a standardized feature vector means performing binary encoding on the protocol type in the network traffic metadata to generate a byte identifier, statistically analyzing the time interval frequency distribution of packets with the same protocol within a time window, and compressing the port number through range normalization; performing hash integer conversion on the user ID in the security audit logs, mapping the operation result to a boolean value, and statistically analyzing the event frequency in a time window; performing radix conversion on the GeoHash string in the spatial coordinate information, and calculating the moving speed through the quotient of the coordinate difference between adjacent time windows and the time increment; based on the global mean and standard deviation pre-computed in the cloud, performing Z-score normalization on the network traffic metadata, security audit logs, and spatial coordinate information respectively, and splicing them into a standardized feature vector.
4. The information security assessment method based on cloud computing according to claim 1, wherein: The constructing a risk assessment model based on a quantum-inspired algorithm includes using the path integral Monte Carlo method to simulate the quantum annealing process, mapping threat features to a quantum Hamiltonian to characterize the energy interaction relationship between features; through dynamic parameter adjustment, the annealing magnetic field strength decays exponentially with time to optimize quantum state transition, the threat correlation strength activation threshold is dynamically calculated based on the global mean and standard deviation, filtering low-correlation noise, and using federated reinforcement learning to aggregate encrypted gradients to construct a risk assessment model.
5. The information security assessment method based on cloud computing according to claim 1, characterized in that: Constructing a spatio-temporal causal graph in combination with the threat intelligence library, and applying the Do-Calculus algorithm to locate the root cause threats includes Based on the quantum projection vector and the threat intelligence library, fusing spatio-temporal tags to construct a spatio-temporal tensor, and using the spatial autocorrelation index to quantify the geographical aggregation of attack sources; Combining the Do-Calculus algorithm with the time-series Granger causality test, calculating the average causal effect of candidate nodes, and using the CVSS vulnerability score and information entropy to screen the root cause threats, and outputting the root cause threat location result.
6. The information security assessment method based on cloud computing according to claim 1, characterized in that: Parsing the dynamic defense strategy based on the edge node, and adjusting the access control rules by using the spatial coordinates of the digital twin real-time mapping includes Adopting the digital twin to real-time map the virtual coordinates, calculating the blocking priority through the logistic function, and generating the spatio-temporal sensitive access control rules; Using reinforcement learning to optimize the defense queue scheduling, balancing the threat suppression weight and resource consumption, and adjusting the access control rules through the KL divergence constraint strategy.
7. The information security assessment method based on cloud computing according to claim 1, wherein: Generating the evaluation audit log includes Feeding the real-time changes of network traffic metadata, security audit logs and spatial coordinate information back to the federated learning framework, jointly updating the weights of the risk assessment model, encrypting and storing the optimized policy execution logs, and generating the evaluation audit log.
8. An information security evaluation system based on cloud computing, based on the information security evaluation method based on cloud computing according to any one of claims 1 to 7, characterized in that: Including a data collection module, a federated analysis module, a quantum factorization module and a dynamic defense intelligent audit module; The data collection module is used to collect multimodal data, perform local desensitization processing on the multimodal data through a trusted execution environment, attach spatio-temporal tags, and use the unique node identifier for symmetric encryption and asymmetric negotiation for encryption to generate spatio-temporal data packets; The federated analysis module is used to aggregate threat features through the edge node federated learning architecture, map the desensitized multimodal data in the spatio-temporal data packet into a standardized feature vector, and construct a multimodal threat matrix; The quantum factorization module is used to construct a risk assessment model based on the quantum heuristic algorithm, aggregate the encrypted gradients of edge nodes through the federated reinforcement learning architecture, output the threat feature vector to the cloud causal inference engine, construct a spatio-temporal causal graph in combination with the threat intelligence library, apply the Do-Calculus algorithm to locate the root cause threats, and generate a dynamic defense strategy; The dynamic defense intelligent audit module is used to parse the dynamic defense strategy based on the edge node, adjust the access control rules by using the spatial coordinates of the digital twin real-time mapping, and locally encrypt and store the policy execution log to generate the evaluation audit log.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, the steps of the information security assessment method based on cloud computing according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the information security assessment method based on cloud computing according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Network information security comprehensive analysis and monitoring system and method
CN118413359A
Network attack and defense decision support method and system based on artificial intelligence
CN119155099A
Information network security self-defense method and system based on trusted computing
CN119254489A
Artificial Intelligence-based Quantified Cyber Defense Control Model
US20240314158A1
Cited By
File co-processing method and system based on cloud computing
CN120561626A
Data security defense method and device for financial management system
CN120768684A
Data security defense method and device for financial management system
CN120768684B
Distributed network security early warning method based on cloud computing
CN120979834A
A cloud-computing-based distributed network security early warning method
CN120979834B