A security protection policy automatic generation method, system, electronic device and product
By acquiring security log data and using the GRU-Attention-DQN model to generate an initial policy, and then updating it based on policy feedback data, the problem of complex security policy generation and lagging adjustment in existing technologies is solved. This enables automatic generation and dynamic adjustment of security protection policies, thereby improving security response capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CENTURY LONGMAI TECH
- Filing Date
- 2025-05-14
- Publication Date
- 2026-05-01
AI Technical Summary
Existing security policy generation technologies suffer from high configuration complexity, reliance on human experience in policy writing, and slow adjustments, making it difficult to adapt to the ever-changing security threat environment. They also lack a deep understanding of the context and the ability to provide policy feedback.
By acquiring security log data, performing preprocessing and feature extraction, generating an initial security protection strategy using the GRU-Attention-DQN model, and updating the model using policy feedback data, a closed-loop optimization is formed.
It enables the automatic generation and dynamic adjustment of security protection strategies, improving security response capabilities and automated protection levels, and the generated strategies are closer to actual needs.
Smart Images

Figure CN120434001B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, specifically relating to a method, system, electronic device, and product for automatically generating security protection strategies. Background Technology
[0002] As cybersecurity threats become increasingly complex and attack methods continue to evolve, more and more enterprises and organizations rely on security strategies for risk control and network protection. However, current mainstream security software generally suffers from high configuration complexity, reliance on human experience for policy writing, and delayed adjustments. In particular, its intelligence level in generating and evolving security policies is low, making it difficult to adapt to the ever-changing security threat environment.
[0003] In the prior art, some technical solutions have attempted to automate the process of generating security policies. For example, Chinese patent CN105844176A discloses a security policy generation method and device, which automatically generates an initial security policy by learning and analyzing the operations during the operation of a business system, and can continue to dynamically update the policy during system operation. Although this method can improve the automation level of policy generation to a certain extent, it relies on traditional statistical modeling methods and lacks a deep understanding of the context state and the ability to provide policy feedback.
[0004] Chinese patent CN104753857A discloses a network traffic control device and its security policy configuration method and apparatus. It proposes a security policy generation method based on the hierarchical logic of enterprise organizational structure. This method simplifies the policy configuration process by automatically generating policies by identifying the source, destination, and application type of data flows and combining this with organizational structure hierarchy. However, the policy modeling process of this method is still relatively static and lacks a feedback mechanism for policy execution effects, making it impossible for the security policy to automatically optimize according to environmental changes. Summary of the Invention
[0005] The present invention aims to solve the above-mentioned technical problems to at least a certain extent. The present invention provides a method, system, electronic device and product for automatically generating security protection strategies.
[0006] To achieve the above objectives, the present invention adopts the following technical solution:
[0007] In a first aspect, the present invention provides a method for automatically generating security protection strategies, comprising:
[0008] Acquire security log data, and obtain security event time sequence feature data based on the security log data;
[0009] The security event time-series feature data is input into the security policy generation model to obtain the initial security protection policy corresponding to the security log data, and the initial security protection policy is executed.
[0010] Receive policy feedback data and update the initial security protection policy based on the policy feedback data to obtain the final security protection policy.
[0011] In one possible design, security event timing characteristic data is obtained based on the security log data, including:
[0012] The security log data is preprocessed to obtain security event time-series data;
[0013] The security event time-series data is processed by feature extraction to obtain security event time-series feature data.
[0014] In one possible design, the security log data is preprocessed to obtain security event time-series data, including:
[0015] The security log data is cleaned, standardized, and security event element extracted to obtain security event time-series data.
[0016] In one possible design, the security policy generation model includes a temporal modeling layer, an attention layer, and a policy generation layer;
[0017] The time-series modeling layer is used to perform time-series modeling processing on the security event time-series feature data to obtain the hidden state vector of the security event time-series feature data.
[0018] The attention layer is used to perform attention calculations on the hidden state vector to obtain the context vector of the security event time-series feature data;
[0019] The policy generation layer is used to obtain the initial security protection policy corresponding to the security log data based on the context vector.
[0020] In one possible design, the timing modeling layer comprises multiple layers of GRUs.
[0021] In one possible design, the policy generation layer employs a DQN network.
[0022] In one possible design, after receiving policy feedback data, the method further includes:
[0023] The policy feedback data is used as correction sample training data to update the security policy generation model, so as to obtain the updated security policy generation model.
[0024] Secondly, the present invention provides an automatic security protection strategy generation system, comprising:
[0025] The data acquisition module is used to acquire security log data and obtain security event time sequence feature data based on the security log data.
[0026] An initial policy generation module, which is communicatively connected to the data acquisition module, is used to input the security event time-series feature data into the security policy generation model to obtain the initial security protection policy corresponding to the security log data, and execute the initial security protection policy.
[0027] The policy update module is communicatively connected to the initial policy generation module. It is used to receive policy feedback data and update the initial security protection policy according to the policy feedback data to obtain the final security protection policy.
[0028] Thirdly, the present invention provides an electronic device, comprising:
[0029] Memory, used to store computer program instructions; and,
[0030] A processor is configured to execute the computer program instructions to perform the operation of the automatic generation method for security protection strategies as described in any of the preceding claims.
[0031] Fourthly, the present invention provides a computer program product, including a computer program or instructions, wherein the computer program or instructions, when executed by a computer, implement an automatic security protection strategy generation method as described in any of the above.
[0032] The beneficial effects of this invention are as follows:
[0033] This invention discloses a method, system, electronic device, and product for automatically generating security protection strategies. It can automatically generate initial security protection strategies based on security log data and dynamically adjust the strategies through a feedback mechanism, exhibiting strong environmental adaptability. Specifically, in implementation, the invention first acquires security log data and obtains security event time-series characteristic data based on the security log data. Then, it inputs the security event time-series characteristic data into a security strategy generation model to obtain the initial security protection strategy corresponding to the security log data and executes the initial security protection strategy. Subsequently, it receives strategy feedback data and updates the initial security protection strategy based on the strategy feedback data to obtain the final security protection strategy. Based on this, the invention can automatically generate initial security protection strategies using a security strategy generation model and update the initial security protection strategy based on the strategy feedback data received during the execution of the initial security protection strategy, achieving dynamic adjustment of the security protection strategy. This increases the accuracy of the generated final security protection strategy, thereby improving security response capabilities and the level of automated protection.
[0034] Other beneficial effects of the present invention will be further explained in the specific embodiments. Attached Figure Description
[0035] Figure 1 This is a flowchart of a method for automatically generating a security protection strategy in one embodiment;
[0036] Figure 2 This is a block diagram of a security protection strategy automatic generation system in one embodiment;
[0037] Figure 3 This is a block diagram of an electronic device in one embodiment. Detailed Implementation
[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in conjunction with the accompanying drawings and descriptions of the embodiments or the prior art. Obviously, the following description of the structure of the accompanying drawings is only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. It should be noted that the description of these embodiments is for the purpose of helping to understand the present invention, but does not constitute a limitation of the present invention.
[0039] Example 1:
[0040] This embodiment discloses an automatic security protection strategy generation method, which can be executed by, but is not limited to, a computer device or virtual machine with certain computing resources, such as a personal computer, smartphone, personal digital assistant or wearable device, or by a virtual machine.
[0041] like Figure 1 As shown, an automatic security protection strategy generation method may include, but is not limited to, the following steps:
[0042] S1. Obtain security log data and derive security event time-series characteristic data based on the security log data. It should be noted that in this embodiment, the security log data originates from network traffic, system logs, and threat intelligence, etc. Specifically, network traffic is captured through traffic mirroring, such as using tcpdump (a command-line tool for capturing network packets and analyzing them in a command-line interface) or Zeek (an open-source, passive network traffic analysis software); system logs are collected from firewalls and IDS / IPS (Intrusion Detection System / Intrusion Prevention System) logs using tools such as Suricata (an open-source network threat detection engine) or ELK Stack (a data processing toolchain primarily composed of three open-source software programs: Elasticsearch (collection), Logstash (processing), and Kibana (display)); threat intelligence is such as publicly available threat databases integrated based on the MITRE ATT&CK framework (a security technology tactical knowledge base framework).
[0043] In step S1, security event time-series characteristic data is obtained based on the security log data, including:
[0044] S101. The security log data is preprocessed to obtain security event time-series data.
[0045] In this embodiment, the security log data is preprocessed to obtain security event time-series data, including:
[0046] The security log data is cleaned, standardized, and security event element extracted to obtain security event time-series data.
[0047] Specifically, in this embodiment, the data cleaning step removes duplicate values from the security log data, fills in missing values (e.g., using sliding window mean filling), and handles outliers. The cleaned security log data can then be further standardized to obtain standardized security log time-series data. During standardization, continuous features in the cleaned security log data can be standardized using Z-Score Normalization, while discrete features can be standardized using one-hot encoding. This results in security log time-series data in CSV (comma-separated values, a common text file format) or Parquet (a highly structured format). The security event element extraction process involves extracting corresponding data from the standardized security log time-series data based on preset specified security event elements (also known as essential elements for security event description), thereby obtaining security event time-series data for subsequent generation of usable security policies.
[0048] In this embodiment, the essential elements for describing a security event include the security event type, the security event action, the event initiator (which may be an IP address, a user, etc.), the event operation object (which may be a target network, a database, etc.), the event severity, and the time factor (which can be used to describe the sequence or interval of events). Of course, in order to describe the security events in the security log data more completely, the essential elements for describing a security event may also include additional options such as element description fields and the location of the event initiator, which are not limited here.
[0049] S102. Perform feature extraction processing on the security event time-series data to obtain security event time-series feature data. It should be noted that in this embodiment, feature extraction processing on the security event time-series data involves extracting time-series features related to attack detection from the security event time-series data. Specifically, for data from the network layer, the extracted time-series features include traffic entropy, SYN packet ratio, and IP address dispersion; for data from the host layer, the extracted time-series features include file modification frequency, abnormal process tree depth, and number of permission changes. Furthermore, this embodiment uses a sliding window method for feature extraction, and sets the length of the time window to 10 steps (i.e., data from the past 10 seconds).
[0050] In this embodiment, standardizing the security log data facilitates the abstraction of various attack application scenarios.
[0051] As an example, in this embodiment, the format of security event data at a certain moment in the security event time series data obtained from the original security log data is as follows:
[0052] {
[0053] "timestamp":"2023-10-01T12:00:00Z",
[0054] "event_type(event type)":"Unauthorized Access"
[0055] "action(action type)":"Authorized(authorized)",
[0056] "source_ip(event initiator)":"192.168.1.1",
[0057] "target_ip(event operation object)":"192.168.1.2",
[0058] "severity (severity level)": "High"
[0059] }
[0060] Feature extraction from security event time-series data, such as converting event type and action type into one-hot encoding, mapping event severity to numerical values, and converting timestamps into time intervals, yields security event time-series feature data. The feature vector for time step t can be represented as x. t = [EventType,Action,Severity,TimeInterval(time interval)].
[0061] S2. Input the security event time-series characteristic data into the security policy generation model to obtain the initial security protection policy corresponding to the security log data, and execute the initial security protection policy. Specifically, in this embodiment, the essential elements of the security protection policy include the policy execution action and the policy execution action object (which may be an IP address, instruction, etc.), and may also include optional elements such as the operation object of the policy execution action object (optional), the policy execution action subject (such as "network layer", "application layer"), execution time, execution frequency description, and other optional elements.
[0062] In step S2, the security policy generation model includes a temporal modeling layer, an attention layer, and a policy generation layer;
[0063] The time-series modeling layer is used to perform time-series modeling processing on the security event time-series feature data to obtain the hidden state vector of the security event time-series feature data.
[0064] Specifically, in this embodiment, the temporal modeling layer includes multiple layers of GRUs (Gate Recurrent Units), which can capture the temporal dependencies of the temporal feature data of security events by modeling the evolution of security events over time (such as sudden attacks and continuous anomalies). The resulting hidden state vector can represent the current state of the network environment. It should be noted that the advantages of GRUs lie in their ability to handle variable-length sequence data, capture long-term dependencies in input data, and achieve real-time learning with low computational complexity, making them suitable for real-time processing of temporal data related to time-sensitive events such as network intrusions.
[0065] In this embodiment, the hidden state vector of time step t output by the time series modeling layer is:
[0066]
[0067] In the formula, z t To update the gate, z t =σ(W z ·[h t-1 ,x t ]), W z h is the preset first weight matrix. t-1 Let x be the hidden state vector of the previous time step t-1. t The feature data for time step t in the time series feature data of the security event is σ(), which is the Sigmoid activation function used to compress the value to [0,1]. Let be the candidate hidden state vector. W is a preset second weight matrix, r t To reset the door, r t =σ(W r ·[h t-1 ,x t ]), W r is the preset third weight matrix, ⊙ is the element-wise multiplication operator, and tanh() is the hyperbolic tangent function.
[0068] It should be noted that the update gate z t and reset door r t The information flow is jointly controlled to determine how much historical information from the security event time-series feature data should be retained (e.g., long-term memory is needed when continuous attacks are detected), and to hide the state vector h. t The dimensions need to be large enough to capture complex temporal patterns, such as 64-256 dimensions, to balance computational efficiency and feature extraction capability. In this embodiment, it is set to 128 dimensions.
[0069] The attention layer is used to perform attention calculations on the hidden state vector to obtain the context vector of the security event time-series feature data. It should be noted that, in this embodiment, the attention mechanism is introduced into the output of the time-series modeling layer through the attention layer to focus on certain high-impact events (such as abnormally high-frequency requests). Based on this, the security policy generation model in this embodiment can be enhanced to identify key features and reduce information noise interference.
[0070] In this embodiment, the attention layer employs a multi-head attention mechanism to enhance the ability to perform cross-analysis of multi-dimensional features.
[0071] The context vector of time step t output by the attention layer is:
[0072]
[0073] In the formula, α ti The preset attention weights represent the importance of time step i to time step t, satisfying the condition ∑ i α ti =1, T is the total number of time steps i; α ti =softmax(v T tanh(W a [h i h t ])), softmax() is a normalization function used to convert the scores into a probability distribution, v is a preset parameter vector for generating attention scores, and W a h is the preset fourth weight matrix; i Let be the hidden state vector at time step i.
[0074] It should be noted that the attention weight α ti Visualization can pinpoint key log events (such as a specific IP frequently triggering alarms within a short period of time), context vector c t The dimension is twice that of the temporal modeling layer.
[0075] The policy generation layer is used to obtain the initial security protection policy (such as blocking IPs or limiting rates for abnormally high-frequency requests) corresponding to the security log data based on the context vector.
[0076] Specifically, in this embodiment, the policy generation layer employs a DQN (Deep Q-Network). During implementation, a reward function is used to measure policy effectiveness, and reinforcement learning techniques such as experience replay and target networks are introduced to enhance stability. Imitation learning pre-training (using expert policies to initialize the model) is combined to address the cold start problem.
[0077] In this embodiment, the strategy generation layer updates the Q value through the Bellman equation and adopts a dual network structure including a target network and a value network to prevent oscillations.
[0078] As an example, in this embodiment, the generated initial security protection strategy is as follows:
[0079] {
[0080] "p_action":"Block IP",
[0081] "action_obj":"192.168.1.1",
[0082] "target_ip":"192.168.1.2",
[0083] }
[0084] It should be noted that, in this embodiment, the security policy generation model can also be called the GRU-Attention-DQN model, which is a deep reinforcement learning model that integrates attention mechanisms.
[0085] It should also be noted that in this embodiment, the security policy generation model is pre-trained based on sample data, and the training process will not be described in detail here.
[0086] S3. Receive policy feedback data and update the initial security protection policy based on the policy feedback data to obtain the final security protection policy. It should be noted that in this embodiment, the policy feedback data is data obtained through manual interaction and feedback based on the initial security protection policy. Based on this, this embodiment can continuously learn and evolve with the help of manual feedback to obtain the final security protection policy, forming a closed-loop optimization, thereby making the security protection policy closer to actual needs.
[0087] It should be understood that in order to receive policy feedback data, a corresponding human interaction interface should be set up so that humans can confirm the policy when the system executes the initial security protection policy. By introducing this human confirmation mechanism, the initial security protection policy can be updated.
[0088] In this embodiment, after receiving policy feedback data, the method further includes:
[0089] S4. The policy feedback data is used as correction sample training data to update the security policy generation model, so as to obtain the updated security policy generation model. It should be noted that in this embodiment, the security policy generation model is updated by manually input policy feedback data. For example, the model is updated once every 100 manually input policy feedback data are received, thereby reducing the need for future manual intervention and realizing model self-evolution.
[0090] It should be noted that the security protection strategy generated in this embodiment can be used to deal with potential threats in the network to ensure network security. It is applicable to scenarios such as network security, data security, and physical security, and has a wide range of applications.
[0091] This embodiment can automatically generate an initial security protection strategy based on security log data and dynamically adjust the strategy through a feedback mechanism, exhibiting strong environmental adaptability. Specifically, in the implementation process, this embodiment first acquires security log data and obtains security event time-series characteristic data based on the security log data; then, it inputs the security event time-series characteristic data into a security strategy generation model to obtain the initial security protection strategy corresponding to the security log data, and executes the initial security protection strategy; subsequently, it receives strategy feedback data and updates the initial security protection strategy based on the strategy feedback data to obtain the final security protection strategy. Based on this, this embodiment can automatically generate an initial security protection strategy using a security strategy generation model and update the initial security protection strategy based on the strategy feedback data received during the execution of the initial security protection strategy, realizing dynamic adjustment of the security protection strategy. This increases the accuracy of the generated final security protection strategy, thereby improving security response capabilities and the level of automated protection.
[0092] Example 2:
[0093] This embodiment discloses an automatic security protection strategy generation system for implementing the automatic security protection strategy generation method in Embodiment 1; such as... Figure 2 As shown, the automatic security protection strategy generation system includes:
[0094] The data acquisition module is used to acquire security log data and obtain security event time sequence feature data based on the security log data.
[0095] An initial policy generation module, which is communicatively connected to the data acquisition module, is used to input the security event time-series feature data into the security policy generation model to obtain the initial security protection policy corresponding to the security log data, and execute the initial security protection policy.
[0096] The policy update module is communicatively connected to the initial policy generation module. It is used to receive policy feedback data and update the initial security protection policy according to the policy feedback data to obtain the final security protection policy.
[0097] It should be noted that the working process, working details and technical effects of the security protection strategy automatic generation system provided in this embodiment 2 can be found in embodiment 1, and will not be repeated here.
[0098] Example 3:
[0099] Based on Embodiment 1 or 2, this embodiment discloses an electronic device, which may be a smartphone, tablet computer, laptop computer, or desktop computer, etc. The electronic device may be referred to as a user terminal, portable terminal, desktop terminal, etc. Figure 3 As shown, the electronic device includes:
[0100] Memory, used to store computer program instructions; and,
[0101] A processor is used to execute the computer program instructions to perform the operation of an automatic security protection strategy generation method as described in any of Embodiment 1.
[0102] Specifically, processor 301 may include one or more processing cores, such as a quad-core processor or an octa-core processor. Processor 301 may be implemented using at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). Processor 301 may also include a main processor and a coprocessor. The main processor, also known as a CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, processor 301 may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content required to be displayed on the screen.
[0103] The memory 302 may include one or more computer-readable storage media, which may be non-transitory. The memory 302 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In some embodiments, the non-transitory computer-readable storage media in the memory 302 are used to store at least one instruction, which is executed by the processor 301 to implement the automatic generation method of security protection strategy provided in Embodiment 1 of this application.
[0104] In some embodiments, the terminal may also optionally include a communication interface 303 and at least one peripheral device. The processor 301, memory 302, and communication interface 303 can be connected via a bus or signal line. Each peripheral device can be connected to the communication interface 303 via a bus, signal line, or circuit board. Specifically, the peripheral device includes at least one of a radio frequency circuit 304, a display screen 305, and a power supply 306.
[0105] The communication interface 303 can be used to connect at least one I / O (Input / Output) related peripheral device to the processor 301 and the memory 302. In some embodiments, the processor 301, the memory 302, and the communication interface 303 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 301, the memory 302, and the communication interface 303 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.
[0106] The radio frequency (RF) circuit 304 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The RF circuit 304 communicates with communication networks and other communication devices via electromagnetic signals.
[0107] Display screen 305 is used to display the UI (User Interface). The UI may include any combination of graphics, text, icons, and video.
[0108] Power supply 306 is used to supply power to various components in electronic devices.
[0109] Example 4:
[0110] Based on any one of Embodiments 1 to 3, this embodiment discloses a computer program product, including a computer program or instructions, which, when executed by a computer, implements an automatic security protection strategy generation method as described in any one of Embodiments 1. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.
[0111] Obviously, those skilled in the art will understand that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device, or fabricating them separately as individual integrated circuit modules, or fabricating multiple modules or steps as a single integrated circuit module. Thus, the present invention is not limited to any particular hardware and software combination.
[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. These modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for automatically generating security protection strategies, characterized in that, include: Acquire security log data, and obtain security event time sequence feature data based on the security log data; The security event time-series feature data is input into the security policy generation model to obtain the initial security protection policy corresponding to the security log data, and the initial security protection policy is executed. Receive policy feedback data and update the initial security protection policy based on the policy feedback data to obtain the final security protection policy; The security policy generation model includes a temporal modeling layer, an attention layer, and a policy generation layer; The time-series modeling layer is used to perform time-series modeling processing on the security event time-series feature data to obtain the hidden state vector of the security event time-series feature data. The attention layer is used to perform attention calculations on the hidden state vector to obtain the context vector of the security event time-series feature data; The policy generation layer is used to obtain the initial security protection policy corresponding to the security log data based on the context vector. The timing modeling layer includes multiple GRUs; The policy generation layer uses a DQN network; The time step output by the timing modeling layer t The hidden state vector is: h t =(1- z t )⊙ h t-1 + z t ⊙ h~ t ; In the formula, z t To update the door, z t = σ ( W z ·[ h t-1 , x t ]), W z The first weight matrix is preset. h t-1 For the previous time step t- The hidden state vector of 1, x t The time step in the time sequence feature data of the security event t Feature data, σ ( ) is the Sigmoid activation function; h~ t Let be the candidate hidden state vector. h~ t =tanh( W ·[ r t ⊙ h t-1 , x t ]), W The second weight matrix is preset. r t To reset the door, r t = σ ( W r ·[ h t-1 , x t ]), W r is the preset third weight matrix, ⊙ is the element-wise multiplication operator, and tanh() is the hyperbolic tangent function; The time step output by the attention layer t The context vector is: ; In the formula, α ti The preset attention weights represent the time steps. i Time step t The importance of meeting the conditions T is the time step i The total number; α ti =softmax( v T tanh( W a [ h i ; h t ])), softmax() is the normalization function, v The parameter vector for generating attention scores is preset. W a This is the preset fourth weight matrix; h i For time step i The hidden state vector.
2. The method for automatically generating a security protection strategy according to claim 1, characterized in that, Based on the security log data, the temporal characteristic data of security events is obtained, including: The security log data is preprocessed to obtain security event time-series data; The security event time-series data is processed by feature extraction to obtain security event time-series feature data.
3. The method for automatically generating a security protection strategy according to claim 2, characterized in that, The security log data is preprocessed to obtain security event time-series data, including: The security log data is cleaned, standardized, and security event element extracted to obtain security event time-series data.
4. The method for automatically generating a security protection strategy according to claim 1, characterized in that, After receiving policy feedback data, the method further includes: The policy feedback data is used as correction sample training data to update the security policy generation model, so as to obtain the updated security policy generation model.
5. A security protection strategy automatic generation system, characterized in that, include: The data acquisition module is used to acquire security log data and obtain security event time sequence feature data based on the security log data. An initial policy generation module, which is communicatively connected to the data acquisition module, is used to input the security event time-series feature data into the security policy generation model to obtain the initial security protection policy corresponding to the security log data, and execute the initial security protection policy. The policy update module is communicatively connected to the initial policy generation module. It is used to receive policy feedback data and update the initial security protection policy according to the policy feedback data to obtain the final security protection policy. The security policy generation model includes a temporal modeling layer, an attention layer, and a policy generation layer; The time-series modeling layer is used to perform time-series modeling processing on the security event time-series feature data to obtain the hidden state vector of the security event time-series feature data. The attention layer is used to perform attention calculations on the hidden state vector to obtain the context vector of the security event time-series feature data; The policy generation layer is used to obtain the initial security protection policy corresponding to the security log data based on the context vector. The timing modeling layer includes multiple GRUs; The policy generation layer uses a DQN network; The time step output by the timing modeling layer t The hidden state vector is: h t =(1- z t )⊙ h t-1 + z t ⊙ h~ t ; In the formula, z t To update the door, z t = σ ( W z ·[ h t-1 , x t ]), W z The first weight matrix is preset. h t-1 For the previous time step t- The hidden state vector of 1, x t The time step in the time sequence feature data of the security event t Feature data, σ ( ) is the Sigmoid activation function; h~ t Let be the candidate hidden state vector. h~ t =tanh( W ·[ r t ⊙ h t-1 , x t ]), W The second weight matrix is preset. r t To reset the door, r t = σ ( W r ·[ h t-1 , x t ]), W r is the preset third weight matrix, ⊙ is the element-wise multiplication operator, and tanh() is the hyperbolic tangent function; The time step output by the attention layer t The context vector is: ; In the formula, α ti The preset attention weights represent the time steps. i Time step t The importance of meeting the conditions T is the time step i The total number; α ti =softmax( v T tanh( W a [ h i ; h t ])), softmax() is the normalization function, v The parameter vector for generating attention scores is preset. W a This is the preset fourth weight matrix; h i For time step i The hidden state vector.
6. An electronic device, characterized in that, include: Memory is used to store computer program instructions; as well as, A processor is configured to execute the computer program instructions to perform the operation of the automatic generation method for security protection strategies as described in any one of claims 1 to 4.
7. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or the instructions are executed by the computer, they implement an automatic security protection strategy generation method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Network flow control equipment and security policy configuration method and device thereof
CN104753857A
Security strategy generation method and equipment
CN105844176A
Network security defense system and network security defense method
CN117319000A