Digital risk panoramic detection and intelligent solution providing platform

Through joint modeling of multi-source heterogeneous data, deep neural networks and reinforcement learning algorithms, a digital risk panoramic detection platform is built, which solves the bottleneck problem of risk identification and response in the existing technology, and realizes efficient risk identification and closed-loop response, and adapts to changes in complex environments.

CN120455095AInactive Publication Date: 2025-08-08BEIJING ZHITU YUNAN TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510630689.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-08-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing digital security system is difficult to achieve panoramic identification, dynamic prediction and closed-loop response of digital risks in a multi-source heterogeneous environment, and traditional technologies are difficult to meet the needs of attack surface identification and response under cloud environment and open supply chain architecture.

Method used

The combined modeling and hierarchical preprocessing mechanism of multi-source heterogeneous data is adopted, combined with deep neural networks and reinforcement learning algorithms, and a digital risk panoramic detection and intelligent solution platform is built, including data collection and preprocessing modules, adaptive artificial intelligence risk prediction modules, active solution provision modules and cloud risk exposure discovery modules to realize high-dimensional risk feature extraction, adaptive environment optimization and closed-loop response.

Benefits of technology

It realizes accurate extraction and structured mapping of high-dimensional risk characteristics in digital environments, has stronger data adaptability, adapts to environmental changes, and builds a closed-loop action system for identification-suggestion repair-feedback-re-decision making, which improves response efficiency and comprehensiveness of risk identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455095A_ABST
    Figure CN120455095A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network and information security, and discloses a digital risk panoramic detection and intelligent solution providing platform comprising a data collection and preprocessing module; the adaptive artificial intelligence risk prediction module is in communication connection with the data collection and preprocessing module; the active solution providing module is in communication connection with the risk prediction module; the intelligent decision and response module is in communication connection with the active solution providing module; and the cloud risk exposure discovery module is in communication connection with the data collection module and the intelligent decision module. Through multi-source heterogeneous data joint modeling and a layered preprocessing mechanism, the effects of accurate extraction and structured mapping of high-dimensional risk features in a digital environment are achieved, the problems of data source limitation and insufficient semantic expression are avoided, and particularly under the scene that an abnormal mode is not clear or data is incomplete, the method has the advantages of being high in practicability and easy to popularize. And the method has stronger data adaptation and expression capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network and information security technologies, and specifically provides a platform for panoramic digital risk detection and intelligent solutions. Background Art

[0002] In existing digital security systems, risk identification and response processes primarily rely on rule-based detection models and manually defined remediation strategies. Typical practices include security policy management (including signature matching within firewalls and intrusion detection systems) and aggregated analysis of log behavior within security information and event management systems (SIEMs). These technical approaches are practical within static network architectures and known threat scenarios, providing early warning and response paths for certain attack behaviors or configuration risks. At the same time, some platforms are beginning to experiment with machine learning techniques for feature extraction and risk scoring, enhancing their ability to process unstructured data and improving specific tasks. With the widespread adoption of cloud computing, large-scale distributed architectures, and remote access, security operations platforms have gradually established mechanisms for collecting data from multiple sources, attempting to manage risk status from a unified perspective.

[0003] However, with the increasing dynamism of digital businesses and the diversification of attack techniques, traditional systems are gradually experiencing bottlenecks in policy automation, closed-loop response, and external exposure awareness. First, existing solutions generally lack the ability to deeply integrate and semantically represent multi-source, heterogeneous security data. This results in risk model accuracy being limited by feature granularity, making it difficult to cover evolving attacks. Second, manually configured rules or static machine learning models struggle to continuously adapt to complex environmental changes and lack policy memory and feedback optimization mechanisms. Third, remediation and response processes often lack a complete closed-loop, and response actions cannot be modeled in concert with prior risk behaviors, resulting in unquantifiable remediation results and an inability to dynamically inform decision-making. Furthermore, in cloud environments and open supply chain architectures, the public network exposure of user assets is complex. Third-party service interfaces, dynamic resource allocation, and multi-layer forwarding mechanisms complicate attack surface identification. Traditional technical architectures based on local scanning or reliance on edge devices are no longer able to meet the demands of real-world security operations. Summary of the Invention

[0004] In response to the shortcomings of the existing technology, the present invention provides a digital risk panoramic detection and intelligent solution providing platform, which solves the problem that the existing platform is difficult to achieve digital risk panoramic identification, dynamic prediction and closed-loop response in a multi-source heterogeneous environment.

[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: a digital risk panorama detection and intelligent solution providing platform, comprising: Data collection and preprocessing module, which is used to collect various security data in the customer environment and complete feature extraction; An adaptive artificial intelligence risk prediction module, in communication with the data collection and preprocessing module, for predicting digital risks faced by customers based on deep learning and reinforcement learning algorithms; An active solution providing module, which is in communication with the risk prediction module and is used to automatically provide repair suggestions after predicting a high-risk event, to facilitate operation; An intelligent decision-making and response module, in communication with the active solution providing module, for automatically generating response decisions and executing response measures based on system status and risk level; The cloud-based risk exposure discovery module is in communication with both the data collection module and the intelligent decision-making module, and is used to discover the risk exposure of customers in the digital environment without requiring local deployment by the customers.

[0006] Preferably, the data collection and preprocessing module includes: Data collection unit, which is used to collect network information exposure, system logs, security event records and user behavior information, among which intranet user behavior is realized when intranet deployment is required; Data cleaning unit, which is used to unify the format of collected data, fill in missing values and eliminate anomalies; Feature extraction unit, which is used to convert structured and unstructured data into numerical features that can be used for model training and real-time input, including information type, traffic volume, connection duration, protocol type, and communication frequency.

[0007] Preferably, the adaptive artificial intelligence risk prediction module includes: A deep neural network unit that extracts deep risk representations from input security features and outputs a risk score; The reinforcement learning policy optimization unit is used to update the value function based on the current system state, actions taken, and rewards obtained, and optimize the prediction strategy.

[0008] Preferably, the active solution providing module includes: A risk judgment unit, which is used to judge whether it is necessary to trigger the provision of a solution based on the comparison of the risk prediction value with the set threshold; The remediation policy execution unit is used to automatically provide remediation suggestions and solutions in high-risk situations, including recommendations to update the encryption bit rate, adjust firewall policies, restrict access paths, isolate affected assets, and update security configurations.

[0009] Preferably, the intelligent decision-making and response module includes: Status perception unit, which is used to collect system status data in real time before and after repairs and attacks; A decision generation unit, which is used to output a set of risk response actions based on reinforcement learning and generate the optimal response decision through a strategy that maximizes current rewards and future benefits; The response execution unit is used to automatically execute the response measures output by the decision generation unit, including asset isolation, interface blocking and log collection.

[0010] Preferably, the cloud risk exposure discovery module includes: A digital asset discovery unit, which is used to identify customers' open services, IP segments, domain names, suspicious shadow IT assets, IoT assets, and other digital assets on the internet based on cloud scanning and external intelligence data; A cybersecurity risk identification unit, which assesses the exposure of clients' digital assets, including open ports, default passwords, expired certificates, and non-encrypted communication methods; A data breach matching unit, which is used to locate customer-related account breaches, database file breaches, and identity credential risks based on a global security incident database; The risk compliance analysis unit is used to determine whether the customer and the services they rely on meet industry compliance standards, including compliance with the Level Protection Level in exposure risks, ISO27001 and GDPR requirements.

[0011] Preferably, the network security risk identification unit includes: A third-party risk identification mechanism, which is used to identify IT infrastructure dependencies and exposed assets associated with suppliers that customers directly rely on; A fourth-party dependency chain resolution mechanism, which is used to recursively extract downstream service providers from a client's third-party dependency list and analyze their exposure risks; Supply chain compliance assessment mechanism, which is used to assess the overall risk level of the supply chain based on attack type, industry background and control measure strength and generate a compliance score report.

[0012] Preferably, the reinforcement learning strategy optimization unit is updated by the following formula: ; in, For the time step When the system is in state , take action The action value function when ; For the time step Take action The immediate reward value obtained after is a discount factor used to measure the current value of future rewards; For the next time step When all actions The maximization operation is used to select the optimal strategy; For the system at time step In state , and take action The action-value function when .

[0013] Preferably, the repair strategy execution unit adopts the repair strategy for selection, and the specific rules are as follows: like , execute the repair suggestion push strategy; like , enter the continuous monitoring state; like , the repair suggestion push operation is not performed; in, The risk prediction value output by the system indicates the probability and score of a risk event in the current state; A high-risk threshold is set, exceeding which triggers automatic remediation measures; The low risk threshold is set. Values below this threshold indicate low risk and do not require repair. They can be recorded or ignored.

[0014] Preferably, the decision generation unit generates the optimal response decision in the following calculation method: ; in, For the system in state The optimal action decision function when ; Action to maximize the expression in parentheses ; For the time step Execute action when The value of the immediate reward obtained; is a discount factor used to control the impact of future rewards on current decisions; For all next steps Take the maximum value of the action value function; For the system at time step In state and take action The action-value function when .

[0015] The present invention provides a digital risk panorama detection and intelligent solution platform. It has the following beneficial effects: 1. This invention achieves precise extraction and structured mapping of high-dimensional risk features in digital environments through joint modeling of multi-source heterogeneous data and a hierarchical preprocessing mechanism. Compared to existing methods that rely on single log or static rule collection, this method avoids data source limitations and insufficient semantic expression. It offers enhanced data adaptation and expression capabilities, particularly in scenarios where anomaly patterns are unclear or data is incomplete.

[0016] 2. This invention utilizes a prediction mechanism driven by a deep neural network and reinforcement learning to achieve dynamic perception and continuous self-optimization of system risk scores. Unlike existing static scoring or manual weighting strategies, this solution adapts to environmental changes and training experience, eliminating the issues of complex rule maintenance and delayed model updates.

[0017] 3. This invention utilizes a separate architecture for response path reasoning and execution control to create a closed-loop action system: identification – recommended remediation – feedback – and re-decision. Unlike traditional security platforms that only provide risk alerts, this solution effectively alleviates the challenges of isolated, inefficient, and unconnected responses.

[0018] 4. By designing a cloud-based active attack surface asset scanning and supply chain exposure chain analysis mechanism, this invention enables remote risk identification without the need for local deployment. Compared to existing technologies that rely on edge devices or customer-authorized scanning, this approach avoids a series of practical constraints such as high deployment costs, delayed updates, and exposure blind spots. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 This is a system module architecture diagram of the present invention; Figure 2 Schematic diagram of the data collection and preprocessing module of the present invention; Figure 3 This is a schematic diagram of the adaptive artificial intelligence risk prediction module of the present invention; Figure 4 Provides a module schematic diagram for the active solution of the present invention; Figure 5 Schematic diagram of the intelligent decision-making and response module of the present invention; Figure 6 Schematic diagram of the cloud risk exposure discovery module of the present invention. DETAILED DESCRIPTION

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the present specification. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0021] Please see the attached Figure 1 The embodiment of the present invention provides a digital risk panoramic detection and intelligent solution providing platform, including: Data collection and preprocessing module, which is used to collect various security data in the customer environment and complete feature extraction; An adaptive AI risk prediction module, which communicates with the data collection and preprocessing module and is used to predict digital risks faced by customers based on deep learning and reinforcement learning algorithms; The proactive solution provision module communicates with the risk prediction module and is used to automatically provide repair suggestions after predicting high-risk events, facilitating operation; The intelligent decision-making and response module communicates with the active solution provision module to automatically generate response decisions and execute response measures based on system status and risk level; The cloud-based risk exposure discovery module is connected to both the data collection module and the intelligent decision-making module, and is used to discover the customer's risk exposure in the digital environment without the need for local deployment by the customer.

[0022] Specifically, the platform's data collection and preprocessing module first collects network information exposure, system logs, security event records, and user behavior data from the user environment (including intranet user behavior if required). This data is then cleaned and feature-extracted to form structured numerical feature data. This feature data is then transmitted via a communication interface to the adaptive artificial intelligence risk prediction module, which extracts high-dimensional risk feature representations based on deep neural networks. This module continuously optimizes risk prediction strategies through reinforcement learning, ultimately outputting a score representing the current risk level of the digital environment.

[0023] After obtaining a risk score, the platform uses its proactive solution provisioning module to assess the score. When the score reaches the preset high-risk threshold, it automatically provides remediation recommendations, including actions such as activating the firewall, restricting access paths, isolating affected assets, and updating security configurations. If the score falls within the intermediate range, continuous monitoring is maintained. If the score falls below the low-risk threshold, no additional recommendations are provided. Remediation results and system feedback are then transmitted to the intelligent decision-making and response module, which perceives changes in system status before and after the remediation and before and after the attack. Based on reinforcement learning, it generates optimal solution push and response action sets, including asset isolation, interface blocking, logging, and other countermeasures, forming a closed-loop mechanism for automated policy reasoning and command output.

[0024] The platform also connects to external threat intelligence sources in real time through its cloud-based risk exposure discovery module. This module automatically identifies users' publicly exposed surfaces, including digital assets such as open services, ports, domain names, and APIs, without requiring customer deployment. This analysis then compares and analyzes risks based on data breaches, compliance requirements, and industry standards. Furthermore, the module identifies third parties and their downstream service providers (i.e., fourth parties), recursively modeling and analyzing their potential risks and compliance levels. This helps users gain a comprehensive understanding of their digital environment's risk exposure across the supply chain.

[0025] Each module is interconnected through data communication or API integration, supporting real-time interaction of multiple types of data such as feature data, risk scores, repair signals, and policy instructions, ensuring that the platform has the capabilities of data-driven, intelligent prediction, automatic response, and continuous optimization, ultimately achieving panoramic visualization, intelligent identification, and strategic resolution of customers' digital security risks.

[0026] Please see the attached Figure 2 , the data collection and preprocessing modules include: Data collection unit, which is used to collect network information exposure, system logs, security event records and user behavior information. Intranet user behavior is realized when intranet deployment is required; Data cleaning unit, which is used to unify the format of collected data, fill in missing values and eliminate anomalies; Feature extraction unit, which is used to convert structured and unstructured data into numerical features that can be used for model training and real-time input, including information type, traffic volume, connection duration, protocol type, and communication frequency.

[0027] Specifically, in this embodiment, the data collection and preprocessing module includes multiple functional units. Specifically, it includes a data acquisition unit, a data cleaning unit, and a feature extraction unit. These units are connected sequentially according to the data flow sequence and communicate with the subsequent risk prediction module via a memory interface or remote call, achieving complete transfer and structural mapping of the raw data.

[0028] In general, data collection units are used to collect raw data input from multiple dimensions and time periods within a client's digital environment. Data sources may include, but are not limited to: network exposure data (such as open port scan results, TLS certificate fingerprints, and DNS records, all collected via the cloud), host operation logs, security event alarm logs, operational records, system process lists, user authentication history, API call records, and web access traces. User behavior information is collected only if an intranet deployment is required.

[0029] As an option, in some application scenarios, the unit can further access mirror data from third-party security devices, such as firewall event records, intrusion detection system (IDS) output, behavior tags of terminal security software, VPN channel traffic data, etc.

[0030] Specifically, the data cleaning unit is responsible for removing invalid records, abnormally formatted fields, and noisy data from the original input, and repairing missing fields. This data cleaning process may employ methods such as anomaly detection based on distribution density, format correction based on dictionary rules, or duplicate removal strategies based on sliding time windows. For log data, regular expression matching can also be used to segment and extract fields.

[0031] In one possible implementation, the cleaning unit adopts the following rules: When a format conflict exists in a field, it is corrected by the mode within the approximate time period; Missing values are filled using linear interpolation or methods based on historical sample means; Perform upper and lower limit correction on numeric fields with erroneous data; Standardize timestamp information to a unified time zone.

[0032] The cleaned data is then passed to the feature extraction unit for structured representation. In this unit, the system discretizes, vectorizes, and normalizes the cleaned data based on the input feature space dimensions required by the subsequent model.

[0033] In some embodiments, feature extraction may include but is not limited to the following typical dimensions: Traffic size (unit: bytes); Connection duration (in seconds); Protocol type (e.g., TCP, UDP, ICMP); Communication frequency (number of connections per unit time); The access density between the source and destination IP and port pairs; Frequency of keywords in the log (e.g., "error," "drop," "unauthorized," etc.); Behavior-related features such as the number of authentication failures and the frequency of behavior switching.

[0034] In feature extraction, feature mapping can be further combined with statistical modeling methods to construct new composite features. For example: In some implementations, the system uses the following trait constructor:

[0035] in, For the dimensional composite features; p Indicates the number of packets sent within a unit connection; Indicates the duration of the connection in seconds; Indicates the number of authentication failures that occurred in the context of this session.

[0036] As a technical extension, this module also supports a feature statistics mechanism under a dynamic sliding window, that is, it continuously updates the feature distribution in a real-time traffic environment, constructs a short-time series aggregate statistical vector, and automatically scores the degree of anomaly based on the data behavior in the current window, thereby enhancing the timeliness of the features.

[0037] In order to improve the discriminative ability of input features in high-dimensional space, some embodiments also adopt a feature screening mechanism based on entropy weighting to evaluate the information gain of each dimension of features, thereby retaining the main feature dimensions that have a significant impact on the prediction model.

[0038] In this paper, the feature vectors generated by the data collection and preprocessing module serve as the core input for reinforcement learning and deep learning models. This module not only improves the data reliability of the entire system but also provides a stable and high-quality input foundation for subsequent risk modeling.

[0039] During deployment, the module can run as a standalone container and connect to other modules through local pipelines or remote RPC interfaces. The platform also supports asynchronous data collection and batch preprocessing mechanisms to adapt to the real-time and throughput requirements of large-scale, high-concurrency scenarios.

[0040] Please see the attached Figure 3 , the adaptive artificial intelligence risk prediction module includes: A deep neural network unit that extracts deep risk representations from input security features and outputs a risk score; Reinforcement learning strategy optimization unit, which is used to update the value function based on the current system state, actions taken, and rewards obtained to optimize the prediction strategy; The reinforcement learning strategy optimization unit is updated using the following formula: ; in, For the time step When the system is in state , take action The action value function when ; For the time step Take action The immediate reward value obtained after is a discount factor used to measure the current value of future rewards; For the next time step When all actions The maximization operation is used to select the optimal strategy; For the system at time step In state , and take action The action-value function when .

[0041] Specifically, the adaptive artificial intelligence risk prediction module is the core link for realizing intelligent analysis and risk judgment in the entire platform. Its accuracy directly affects the provision of subsequent repair suggestions and the execution effect of the strategic decision-making of the repair suggestions.

[0042] In this embodiment, the adaptive AI risk prediction module primarily comprises two functional subunits: a deep neural network unit and a reinforcement learning strategy optimization unit. These two subunits are interconnected via an intermediate state variable sharing mechanism and are both directly adapted to the feature input data structure of the previous stage.

[0043] Deep neural network units are primarily used to learn the nonlinear mapping relationship between feature inputs and potential risks. Typically, this unit employs a multi-layer perceptron (MLP) structure or is combined with a convolutional neural network (CNN) to extract local pattern features. In some embodiments, for log data or sequential behavioral data, a long short-term memory network (LSTM) can be incorporated into the model to capture temporal dependencies between behaviors.

[0044] Specifically, in a typical structure, the neural network unit represents the input features as a vector ,in is the input dimension. The system uses a set of weight matrices , bias term , combined with nonlinear activation functions, construct multi-layer hidden layer expressions, and finally output a risk score value ,This score is used to measure the risk level of the current system status.

[0045] As an option, to improve the generalization and online adaptability of the model, some embodiments introduce a Dropout-based regularization mechanism and a BatchNormalization layer to correct the distribution drift caused by different data sources.

[0046] The reinforcement learning strategy optimization unit is used to dynamically adjust the judgment boundary and behavioral strategy of risk scoring. In this invention, the introduction of reinforcement learning is not only used for risk classification itself, but also can further optimize the judgment path under uncertain conditions and enhance the model's strategic reasoning ability.

[0047] In one possible implementation, the unit uses the Q-Learning algorithm framework to update the value function, and its core update formula is as follows: ; in, For the time step When the system is in state , take action The action value function when ; For the time step Take action The immediate reward value obtained after is a discount factor used to measure the current value of future rewards; For the next time step When all actions The maximization operation is used to select the optimal strategy; For the system at time step In state , and take action The action-value function when .

[0048] During the training process, the system stores the historical state transition sequence in the experience replay pool and uses random sampling to avoid short-term sample bias from disturbing the strategy.

[0049] In some embodiments, to prevent the model from falling into local optimum, the system may introduce Greedy strategy, when choosing an action, the probability Randomly explore non-optimal actions with probability Select the current optimal action to improve overall learning efficiency.

[0050] Furthermore, the system supports the risk scoring output by deep neural networks Combined with the state behavior values predicted by the reinforcement learning unit, this strategy is weighted and fused to form a more stable and dynamically adaptive risk identification mechanism. This fusion strategy demonstrates stronger generalization capabilities in scenarios such as complex attack paths and multi-stage intrusion detection, enabling the provision of better and more tailored solutions.

[0051] The risk score output by this module will serve as the input trigger for the next stage's proactive solution provision module. The relevant score can be used to compare whether to trigger the response mechanism and to generate label feedback to feed back model updates.

[0052] In some deployment scenarios, the adaptive AI risk prediction module can be independently deployed on edge nodes or private clouds, receive input feature data by calling standardized API interfaces, and output prediction results in JSON or Tensor format, adapting to different types of security system platforms.

[0053] Please see the attached Figure 4 , the active solution providing modules include: A risk judgment unit, which is used to judge whether it is necessary to trigger the provision of a repair solution based on the comparison of the risk prediction value with a set threshold; A remediation policy execution unit, which is used to automatically provide remediation suggestions and solutions in high-risk situations, including recommendations to update encryption bit rates, adjust firewall policies, restrict access paths, isolate affected assets, and update security configurations; The repair strategy execution unit adopts the repair strategy for selection. The specific rules are as follows: like , execute the repair suggestion push strategy; like , enter the continuous monitoring state; like , the repair suggestion push operation is not performed; in, The risk prediction value output by the system indicates the probability and score of a risk event in the current state; A high-risk threshold is set, exceeding which triggers automatic remediation measures; The low risk threshold is set. Values below this threshold indicate low risk and do not require repair. They can be recorded or ignored.

[0054] Specifically, the active solution providing module plays a central role in response decision-making in the platform of the present invention, and is responsible for automatically triggering a preset set of repair strategies according to different risk levels, and performing feedback recording and archiving analysis on the repair effects.

[0055] In this embodiment, the proactive solution provision module primarily includes a risk scoring unit, a response strategy generation unit, an execution solution recommendation unit, and a result feedback interface. These units are sequentially connected in series to form an automated closed-loop response path, ensuring the system's ability to continuously provide remediation recommendations.

[0056] Generally speaking, the risk score discrimination unit first performs interval mapping on the score value output by the adaptive artificial intelligence risk prediction module. Specifically, the risk score value Divided into multiple level intervals, for example: Low risk range ( ; Medium-risk range ; High-risk range ( ; Among them, the threshold parameter and The thresholds represent the low-risk and high-risk intervals, respectively. As an option, the system can perform adaptive threshold calculation based on historical sample distribution or dynamic risk baseline strategy.

[0057] Within high-risk levels, the response strategy generation unit activates and builds specific remediation recommendations based on contextual features such as the risk source, impacted objects, and event type. For example, if the intrusion originates from an external IP address and the behavior includes multiple authentication failures, the system will generate a solution based on the risk type, ultimately generating a combined remediation strategy based on IP blocking and user lockout and providing it to the client. Furthermore, if a risk event is detected that involves changes to critical system files, operational recommendations for file recovery and process termination will be prioritized.

[0058] Specifically, in some embodiments, the response strategy generation unit performs action combination scoring according to the following formula: ; in, Indicates the The strategy in Overall rating for each event scenario; Indicates the response time score of the strategy; Indicates the degree of system recovery that can be expected after the policy is executed; Indicates the cost of policy implementation (such as the scope of system impact, degree of user interference, etc.); , , are the weighted coefficients of each evaluation index.

[0059] The above scoring values will be used to prioritize policies and automatically select the optimal combination of repair actions.

[0060] As an option, during the strategy generation process, the system can also refer to the context of previous events to model the state-action sequence, giving priority to strategy paths that have been verified to be effective in history, and forming a memorable response behavior.

[0061] The execution plan recommendation unit is responsible for delivering the repair strategy to the corresponding controlled resources or management components. This unit supports multiple execution plans, such as: Provide recommended solutions through the security agent suggestion module, such as: network isolation, port blocking, and IP ban; It is recommended that users terminate suspicious processes and restore system snapshots through the system management interface; Record the synchronization repair proposal to the log server or centralized event platform; A solution for dynamically modifying security policy configuration files (such as firewall rules and intrusion prevention policies).

[0062] In some embodiments, the execution plan suggestion unit adds an identifier to each repair plan suggestion, and archives the identifier, execution timestamp, response target, and expected recovery status as meta-information.

[0063] In specific deployment, the platform supports asynchronous or parallel repair strategy solution provision mechanisms to adapt to the high concurrent response requirements in multi-point triggering scenarios or large-scale attack spread situations.

[0064] In one possible implementation, the system could also incorporate a rollback mechanism, automatically recommending a return to the pre-repair state if the repair fails to meet expectations or produces side effects. For example, by taking a snapshot of the configuration state before execution or recording the service's operating status, this ensures reversibility and fault tolerance during the response process.

[0065] The result feedback interface is used to collect the execution status, system feedback, and external behavior changes of each repair suggestion. This information is not only used for response effect analysis in subsequent modules, but also feeds back into the risk prediction model to update the strategy during the reinforcement learning process.

[0066] In some embodiments, the return interface also supports event synchronization, manual approval, and linkage response with external consoles (such as SOC platforms and security operations platforms), thereby balancing automation efficiency and manual security assurance.

[0067] In summary, the active solution provision module builds a closed-loop security control path through a linkage mechanism of risk identification, strategy generation and execution response, and supports intelligent scheduling and real-time repair solution recommendations in multiple scenarios, thereby improving the platform's emergency response level and continuous defense capabilities in digital risk environments.

[0068] Please see the attached Figure 5 , the intelligent decision-making and response module includes: Status perception unit, which is used to collect system status data in real time before and after repairs and attacks; A decision generation unit, which is used to output a set of risk response actions based on reinforcement learning and generate the optimal response decision through a strategy that maximizes current rewards and future benefits; A response execution unit, which is used to automatically execute the response measures output by the decision generation unit, including asset isolation, interface blocking, and log collection; The calculation method for the decision generation unit to generate the optimal response decision is: ; in, For the system in state The optimal action decision function when ; Action to maximize the expression in parentheses ; For the time step Execute action when The value of the immediate reward obtained; is a discount factor used to control the impact of future rewards on current decisions; For all next steps Take the maximum value of the action value function; For the system at time step In state and take action The action-value function when .

[0069] Specifically, the intelligent decision-making and response module takes the system's current state, historical behavior trajectory, and repair execution results as input to provide recommended solutions. It generates optimized response action suggestions and completes the reasoning and continuous updating of the strategy path, thereby forming an adaptive linkage throughout "identification-decision-feedback".

[0070] In this embodiment, the intelligent decision-making and response module primarily comprises a contextual state perception unit, a policy inference engine, a response action generator, and an enhanced feedback adapter. These functional units collaborate with each other, using state transition modeling as the primary focus, to achieve high-dimensional abstraction and automated control of the security decision-making process.

[0071] Generally, the context state perception unit receives feedback information on the execution of the proposed solution from the active solution provision module, including fields such as the repair action number, affected resource identifier, operation result status code, recovery time, failure reason, etc., and combines it with the real-time collected system operation status to form a unified environmental context representation.

[0072] In some embodiments, to improve the understanding of the integrity of the attack chain, the unit also integrates the attack path map, asset topology, and historical security event sequences, and performs state semantic expansion through a directed graph model, which is represented as a state set: ; in, Indicates that the system is at time A global state snapshot at a given moment, including attributes such as current resource status, external connection relationships, response records, and risk distribution vectors.

[0073] As an option, the state awareness unit also supports modeling of potential risk behaviors, such as abnormal silent connections, irregular behavior transfers, access to inactive assets, and other events, and generates high-dimensional vectors for reasoning input through graph embedding technology.

[0074] The policy inference engine is the core of this module. Its function is to generate a multi-step response policy path based on the state input. In this invention, the engine uses a policy search mechanism based on reinforcement learning and is trained in conjunction with a Markov decision process (MDP) model. The model is defined as follows: State Space Generated by the state perception unit; Action Space Contains a collection of response operations that the platform can perform; State transition function Indicates execution of an action Back-slave state Transfer to probability; Reward Function Indicates that the current action is in state The immediate feedback value brought by the following.

[0075] In some embodiments, the policy inference process is optimized using a policy gradient method, and the policy parameter update formula is as follows: ; in, Indicates that the parameter is Under the strategy of Select Action probability; Representation Strategy The action-value function under Indicates the current policy gradient direction.

[0076] The response action generator generates a structured response task instruction set based on the optimal action sequence output by the policy inference engine and outputs it as a recommended solution. This instruction set includes fields such as action type, execution order, target resource, expected state, dependencies, and rollback flags, and is transmitted to the execution receipt engine or security control platform using a standard protocol.

[0077] In some embodiments, the response actions include but are not limited to: Block a certain network segment and temporarily ban high-risk IPs; Distribute terminal policies (such as updating antivirus rules and strengthening UAC); Adjust cloud resource access policies (such as AWS IAM permission changes); Automatically trigger external audit interfaces (such as SOAR platform linkage); Generate urgent risk alert notifications.

[0078] To improve the dynamic adaptability of the response sequence, this module supports a conditional trigger execution model. That is, when a new state transition or environmental variable change is detected, the proposed solution is dynamically updated, the subsequent action sequence is adjusted, or some operations are terminated, which is highly flexible.

[0079] The reinforcement feedback adapter collects system feedback generated by recommended responses and evaluates the effectiveness of policy execution. This feedback includes action success, system load changes, service recovery time, user response, and attack abort. This module embeds this feedback into the reinforcement learning loop to optimize policy parameters and achieve closed-loop self-learning.

[0080] In one possible implementation, the module also provides a meta-decision analysis interface that can output a confidence score for strategy generation, a visual representation of the strategy generation path, and intermediate state nodes that can be reviewed by human analysts, to support human-machine collaborative decision-making scenarios.

[0081] At the deployment level, the intelligent decision-making and response module can be encapsulated as an independent service process, and efficiently integrated with other modules through message queues or event stream mechanisms. It also supports functions such as policy caching, policy backtracking, and version control to meet enterprise-level traceability, auditability, and controllability requirements.

[0082] Please see the attached Figure 6 , the cloud risk exposure discovery module includes: A digital asset discovery unit, which is used to identify customers' digital assets such as open services, IP segments, domain names, and API endpoints on the Internet based on cloud scanning and external intelligence data; A cybersecurity risk identification unit, which assesses the exposure of clients' digital assets, including open ports, default passwords, expired certificates, and non-encrypted communication methods; A data breach matching unit, which is used to locate customer-related account breaches, database file breaches, and identity credential risks based on a global security incident database; A risk compliance analysis unit, which is used to determine whether the client and the services it relies on meet industry compliance standards, including compliance with the MSP, ISO27001, and GDPR requirements in terms of exposure risks; The cybersecurity risk identification unit includes: A third-party risk identification mechanism, which is used to identify IT infrastructure dependencies and exposed assets associated with suppliers that customers directly rely on; A fourth-party dependency chain resolution mechanism, which is used to recursively extract downstream service providers from a client's third-party dependency list and analyze their exposure risks; Supply chain compliance assessment mechanism, which is used to assess the overall risk level of the supply chain based on attack type, industry background and control measure strength and generate a compliance score report.

[0083] Specifically, the cloud risk exposure discovery module is used to identify, merge and dynamically calibrate externally accessible attack surfaces and supply chain exposure paths, so as to provide better tailored recommended solutions.

[0084] In this embodiment, the cloud-based risk exposure discovery module primarily includes a cloud resource scanning and identification unit, an attack surface feature analysis unit, a risk assessment and attribution unit, and a multi-level dependency tracking unit. These units work collaboratively to discover, classify, fingerprint, and aggregate risk analysis of publicly exposed assets, ultimately providing the platform with a comprehensive view of externally perceived risks. Intranet user behavior is implemented when an intranet deployment is required.

[0085] Generally, the cloud resource scanning and identification unit is used to proactively discover digital asset resources exposed to the public network within the user environment. Scanning methods include active port probing, DNS record reverse lookup, CDN path inference, WHOIS data comparison, SSL certificate aggregation, and API fingerprinting.

[0086] In one possible implementation, the unit takes the user's known IP segment, domain name set, or cloud vendor account binding information as input and constructs a multi-round cascade scanning path. For example: Perform port scans (such as TCP SYN scans) on public IP segments; Combined with IP reverse resolution to obtain the bound domain name list; Use TLS handshake to obtain certificate information for the domain name; Compare the certificate fingerprint with the historical scan sample library.

[0087] The above process can identify all exposed resources including web service interfaces, open database ports, backend management paths, API call entry points, email services, file transfer services, etc., and uniformly represent them as a set of exposed asset vectors: ; in, Indicates the An exposed asset entity, including fields such as its service type, port number, protocol stack, reachable domain name, certificate characteristics, open status and response fingerprint.

[0088] The attack surface feature analysis unit is used to classify the service fingerprints of the above asset sets and match them with the security configurations, thereby outputting the corresponding security configurations as solutions and making reasonable suggestions.

[0089] In some implementations, this module includes a built-in CVE matching engine that automatically searches for high-risk historical vulnerabilities based on asset service type and version number, enabling sequential recommendations. It also supports integration with external threat intelligence sources (such as Shodan, Censys, ZoomEye, and CVE / NVD databases) to cross-validate risk information.

[0090] As an option, the system can also construct a fingerprint hash mapping table to hash and compress common service configurations or page structures and then match them, thereby quickly identifying known high-risk assets in large-scale data streams and facilitating the rapid generation of recommended solutions.

[0091] The Risk Assessment and Attribution Unit quantifies and scores the risks of exposed assets, and determines responsibility based on upstream and downstream access relationships. This risk score utilizes a comprehensive weighted model, taking into account multiple factors, including asset type, default configurations, weak passwords, Common Vulnerabilities and Exposures (CVEs), and regulatory compliance watchlists (e.g., public databases, financial interfaces, etc.).

[0092] In a typical embodiment, the risk score calculation formula is as follows: ; in, Indicates the The overall risk score of each exposed asset; Indicates the vulnerability level it hits (given by CVE score or intelligence rating); Indicates the strength of its exposed configuration (such as whether it is a default password or a weak configuration); Indicates the external exposure level of the asset (e.g., whether it is directly accessible to the public network); Indicates the industry compliance level involved in the asset (such as PCI DSS, GDPR, industrial control, etc.); It is a configurable weight coefficient that can be dynamically adjusted based on industry or user preferences.

[0093] The multi-level dependency tracking unit is used to identify third-party and fourth-party digital entities that have service coupling relationships with user assets. In complex SaaS or API interaction environments, many risks arise not directly from the user's own exposure, but from the external components or supply chain service providers they rely on.

[0094] To this end, the unit constructs a complete exposure path map by tracing call paths, connection fingerprints, and TLS link records, providing a basis for recommended solutions. In some embodiments, multi-level risk backtracking is performed using methods such as deep recursive domain name relationships (such as CNAME chains), DNS resolution points, content hosting paths (such as CDN forwarding), and API chain call sequences.

[0095] Specifically, the path can be modeled as a graph structure: ; in, Represents all asset nodes participating in the exposure chain (including user assets and their directly or indirectly dependent assets); Represents the call or control connection relationship between nodes; the system can perform path weighted shortest-first search (such as Dijkstra algorithm) or risk propagation simulation on the graph to identify possible attack paths or supply chain weaknesses.

[0096] The exposure results output by this module are uniformly encapsulated into a standard format vector and visualized in the platform's front-end interface. They can also be provided as input to the policy response module for coordinated processing. Furthermore, this module supports pushing discovery results to external security platforms (such as CMDB, SOAR, and NOC) via webhooks or APIs, enabling multi-system collaboration.

[0097] In terms of deployment, the cloud-based risk exposure discovery module, as an independently running subsystem, can be deployed in a cloud control center or an area accessible by the Internet. It supports scheduled task scheduling, incremental scanning optimization, and caching mechanisms to ensure high-frequency and efficient dynamic identification of external risks and enhance solution response capabilities.

[0098] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A digital risk panorama detection and intelligent solution providing platform, characterized by: include: Data collection and preprocessing module, which is used to collect various security data in the customer environment and complete feature extraction; An adaptive artificial intelligence risk prediction module, in communication with the data collection and preprocessing module, for predicting digital risks faced by customers based on deep learning and reinforcement learning algorithms; An active solution providing module, which is in communication with the risk prediction module and is used to automatically provide repair suggestions after predicting a high-risk event, to facilitate operation; An intelligent decision-making and response module, in communication with the active solution providing module, for automatically generating response decisions and executing response measures based on system status and risk level; The cloud-based risk exposure discovery module is in communication with both the data collection module and the intelligent decision-making module, and is used to discover the risk exposure of customers in the digital environment without requiring local deployment by the customers.

2. A digital risk panoramic detection and intelligent solution providing platform according to claim 1, characterized in that: The data collection and preprocessing module includes: Data collection unit, which is used to collect network information exposure, system logs, security event records and user behavior information, among which intranet user behavior is realized when intranet deployment is required; Data cleaning unit, which is used to unify the format of collected data, fill in missing values and eliminate anomalies; Feature extraction unit, which is used to convert structured and unstructured data into numerical features that can be used for model training and real-time input, including information type, traffic volume, connection duration, protocol type, and communication frequency.

3. A digital risk panoramic detection and intelligent solution providing platform according to claim 1, characterized in that: The adaptive artificial intelligence risk prediction module includes: A deep neural network unit that extracts deep risk representations from input security features and outputs a risk score; The reinforcement learning policy optimization unit is used to update the value function based on the current system state, actions taken, and rewards obtained, and optimize the prediction strategy.

4. A digital risk panoramic detection and intelligent solution providing platform according to claim 1, characterized in that: The active solution providing module includes: A risk judgment unit, which is used to judge whether it is necessary to trigger the provision of a repair solution based on the comparison of the risk prediction value with a set threshold; The remediation policy execution unit is used to automatically provide remediation suggestions and solutions in high-risk situations, including recommendations to update the encryption bit rate, adjust firewall policies, restrict access paths, isolate affected assets, and update security configurations.

5. A digital risk panoramic detection and intelligent solution providing platform according to claim 1, characterized in that: The intelligent decision-making and response module includes: Status perception unit, which is used to collect system status data in real time before and after repairs and attacks; A decision generation unit, which is used to output a set of risk response actions based on reinforcement learning and generate the optimal response decision through a strategy that maximizes current rewards and future benefits; The response execution unit is used to automatically execute the response measures output by the decision generation unit, including asset isolation, interface blocking and log collection.

6. A digital risk panoramic detection and intelligent solution providing platform according to claim 1, characterized in that: The cloud risk exposure discovery module includes: A digital asset discovery unit, which is used to identify customers' digital assets such as open services, IP segments, domain names, and API endpoints on the Internet based on cloud scanning and external intelligence data; A cybersecurity risk identification unit, which assesses the exposure of clients' digital assets, including open ports, default passwords, expired certificates, and non-encrypted communication methods; A data breach matching unit, which is used to locate customer-related account breaches, database file breaches, and identity credential risks based on a global security incident database; The risk compliance analysis unit is used to determine whether customers and the services they rely on meet industry compliance standards, including compliance with the Level Protection Level (MLP) protection, ISO27001, and GDPR requirements in exposure risks.

7. A digital risk panoramic detection and intelligent solution providing platform according to claim 6, characterized in that: The network security risk identification unit includes: A third-party risk identification mechanism, which is used to identify IT infrastructure dependencies and exposed assets associated with suppliers that customers directly rely on; A fourth-party dependency chain resolution mechanism, which is used to recursively extract downstream service providers from a client's third-party dependency list and analyze their exposure risks; Supply chain compliance assessment mechanism, which is used to assess the overall risk level of the supply chain based on attack type, industry background and control measure strength and generate a compliance score report.

8. The digital risk panoramic detection and intelligent solution providing platform according to claim 3 is characterized by: The reinforcement learning strategy optimization unit is updated by the following formula: ; in, For the time step When the system is in state , take action The action value function when ; For the time step Take action The immediate reward value obtained after is a discount factor used to measure the current value of future rewards; For the next time step When all actions The maximization operation is used to select the optimal strategy; For the system at time step In state , and take action The action-value function when .

9. A digital risk panoramic detection and intelligent solution providing platform according to claim 4, characterized in that: The repair strategy execution unit adopts the repair strategy for selection, and the specific rules are as follows: like , execute the repair suggestion push strategy; like , enter the continuous monitoring state; like , the repair suggestion push operation is not performed; in, The risk prediction value output by the system indicates the probability and score of a risk event in the current state; A high-risk threshold is set, exceeding which triggers automatic remediation measures; The low risk threshold is set. Values below this threshold indicate low risk and do not require repair. They can be recorded or ignored.

10. A digital risk panoramic detection and intelligent solution providing platform according to claim 5, characterized in that: The calculation method of the decision generation unit to generate the optimal response decision is: ; in, For the system in state The optimal action decision function when ; Action to maximize the expression in parentheses ; For the time step Execute action when The value of the immediate reward obtained; is a discount factor used to control the impact of future rewards on current decisions; For all next steps Take the maximum value of the action value function; For the system at time step In state and take action The action-value function when .

Citation Information

Cited By

  • Comprehensive nursing management system based on big data analysis

    CN120748650A

  • Comprehensive nursing management system based on big data analysis

    CN120748650B