A risk guidance-based network security level protection management system and method
The network security level protection management system, which uses multi-channel semantic modeling and risk guidance, solves the problems of single semantic coding and lack of dynamic risk perception in the scoring output of existing technologies, and realizes the systematization, efficiency and accuracy of network security level protection assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-09
- Publication Date
- 2026-04-07
AI Technical Summary
Existing cybersecurity level protection assessment methods suffer from limitations such as simplistic semantic encoding, a lack of structured understanding in the matching process, a lack of dynamic risk perception mechanisms in the scoring output, and a lack of unified model training modules. These issues result in low assessment efficiency, poor accuracy, and difficulty in migrating and generalizing across different industries and systems.
A system is constructed that integrates multi-channel semantic modeling, scoring-based semantic matching, risk-guided level assessment, and training feedback optimization. This system utilizes a network security semantic encoding module for multi-channel semantic encoding, a cross-matching analysis module for constructing semantic interaction matrices and calculating scores, and a feature fusion and level scoring module for fusion of risk factors and coordination of decision rules, thus achieving a systematic modeling and optimization process throughout the entire process.
It has improved the efficiency and accuracy of intelligent assessment of cybersecurity level protection, enhanced the adaptability to different types of evidence texts and the sensitivity of assessment results, and achieved refined and structured assessment and dynamic risk perception.
Smart Images

Figure CN120474830B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security level protection management technology, specifically a risk-guided network security level protection management system and method. Background Technology
[0002] With the deepening implementation of the cybersecurity classification and protection system, network information system classification assessment has become an important component of the information security management system. To meet regulatory compliance requirements, different types of industry entities need to regularly conduct conformity assessments of the technical and management measures of their information systems. Traditional classification assessment methods rely on experts manually comparing classification protection requirements with evidence materials such as system configuration files, equipment lists, and operation logs, which suffers from low efficiency, high subjectivity, and difficulty in standardization. In recent years, with the development of artificial intelligence and natural language processing technologies, researchers have begun to explore introducing semantic matching algorithms into classification protection assessments to improve automation and intelligence. However, this is still in the initial exploratory stage, lacking mature engineering systems and model integration solutions.
[0003] Existing technologies for intelligent assessment of cybersecurity level protection mainly suffer from the following limitations: First, most methods use single-channel semantic coding models (such as BERT or bag-of-words models) to process assessment evidence information and level protection requirements text, failing to fully integrate multiple semantic feature levels, resulting in limited semantic matching accuracy. Second, matching methods are usually based on bidirectional sentence vector similarity or sentence pair classifiers, ignoring the correlation modeling problem between "local control points and overall policy objectives," making it difficult to achieve refined and structured assessment. Third, in the level label output stage, most systems use static scoring rules or directly use classification models, failing to dynamically adjust the scoring results according to different risk dimensions and lacking policy awareness of key control items. In addition, current systems generally lack a unified model training module, failing to establish a closed-loop optimization mechanism from original sample construction, model training to assessment result feedback, limiting the model's transfer and generalization capabilities across different industries and system types. In contrast, this invention, by constructing a complete system encompassing "multi-channel semantic modeling—scoring-based semantic matching—risk-guided level assessment—training feedback optimization," achieves a structured understanding and precise matching between network device evaluation items and grade protection requirements. This significantly improves the efficiency of intelligent evaluation and the accuracy of grade labels, a feat difficult to achieve with existing technologies. Summary of the Invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by this invention is: existing network security level protection assessment methods have problems such as single semantic encoding which makes it difficult to cover different types of evidence text, lack of structured understanding ability in the matching process, lack of dynamic risk perception mechanism in the scoring output, and how to achieve a systematic modeling and optimization closed loop for the entire process of network security level assessment based on semantic intelligent analysis.
[0006] To address the aforementioned technical problems, this invention provides the following technical solution: a risk-guided network security level protection management system, comprising a network security semantic encoding module, used to perform multi-channel semantic encoding on basic requirements information for network security level protection and evidence information for network equipment evaluation items, and output a high-dimensional semantic feature vector in a unified format. The multi-channel semantic encoding includes context modeling, statistical feature extraction, and structural semantic modeling.
[0007] The cross-matching analysis module is used to receive the set of semantic feature vectors, construct a semantic interaction matrix between the level requirements and the assessment evidence, calculate the matching score through a multi-channel scoring function, and aggregate the multi-dimensional scoring results to output a level matching score vector.
[0008] The feature fusion and rating module is used to fuse the matching rating vector with the preset risk weights of the rating requirements. It generates a fused feature vector through a fusion strategy and inputs it into the rating prediction model to output a cybersecurity rating label.
[0009] As a preferred embodiment of the risk-guided network security level protection management system described in this invention, the network security semantic coding module includes a deep semantic coding subunit, a statistical semantic coding subunit, a structural semantic coding subunit, and a channel fusion subunit.
[0010] As a preferred embodiment of the risk-guided network security level protection management system described in this invention, the network security semantic encoding module further includes a deep semantic encoding subunit that performs contextual modeling of the text based on a pre-trained language model and extracts high-dimensional embedding vectors with word order dependencies and syntactic structures.
[0011] The statistical semantic coding subunit calculates keyword importance based on TF-IDF or word frequency model and generates sparse vector representation.
[0012] The structural semantic encoding subunit constructs a syntactic dependency graph, and uses graph neural networks to model the structural relationships and logical dependencies in the text, extracting structural feature vectors.
[0013] The channel fusion subunit fuses the semantic vectors output by the three coding subunits and dynamically adjusts the fusion strategy according to the characteristics of the input data to generate a set of semantic representation vectors in a unified format.
[0014] As a preferred embodiment of the risk-guided network security level protection management system described in this invention, the cross-matching analysis module includes an interaction relationship construction subunit, a scoring function integration subunit, a scoring aggregation subunit, and a scoring vector standardization subunit.
[0015] As a preferred embodiment of the risk-guided network security level protection management system described in this invention, the cross-matching analysis module further includes an interaction relationship construction subunit that combines the level requirement semantic vector and the device evidence semantic vector in pairs to construct interaction pairs and generate an interaction vector matrix.
[0016] The scoring function integration subunit calculates the matching score for each group of interaction vectors through the scoring channel.
[0017] The scoring aggregation subunit aggregates the scores in the scoring matrix by row or column to generate an overall matching scoring vector for each grade protection requirement.
[0018] The scoring vector standardization subunit normalizes and compresses the range of the aggregated matching scoring vectors, outputting a scoring feature vector in a uniform format.
[0019] As a preferred embodiment of the risk-guided network security level protection management system described in this invention, the feature fusion and level scoring module includes a feature fusion subunit, a level prediction subunit, and a decision rule coordination subunit.
[0020] As a preferred embodiment of the risk-guided network security level protection management system described in this invention, the feature fusion and level scoring module further includes a feature fusion subunit that receives the matching scoring vector and, in conjunction with the risk factor vector required by the level protection, performs a weighted fusion or gating mechanism fusion operation.
[0021] The level prediction subunit will integrate features into the classification model and output the corresponding level protection level label, supporting single-label and multi-label output formats.
[0022] The decision rule coordination subunit corrects labels when the model output is inconsistent with the rule system.
[0023] Another objective of this invention is to provide a risk-guided network security level protection management method, which solves the problems of single semantic representation, coarse matching relationship modeling, and lack of risk adjustment capability in current intelligent assessment technologies for network security level protection by introducing multi-channel semantic coding and scoring-based semantic matching paths, integrating level requirement risk factors, and constructing an interactive scoring matrix.
[0024] As a preferred embodiment of the risk-guided network security level protection management method described in this invention, the method includes: when the system receives a network security level protection assessment task, the network security semantic encoding module receives the basic requirements information for level protection and the evidence information of network equipment assessment items, and encodes them sequentially by a deep semantic encoding subunit, a statistical semantic encoding subunit, and a structural semantic encoding subunit; the channel fusion and control subunit fuses the channel vectors to generate a unified format semantic feature vector set. The cross-matching analysis module receives the above semantic feature vectors, the interaction relationship construction subunit generates interaction pairs, the scoring function integration subunit calculates the matching score for the interaction pairs, the scoring aggregation subunit aggregates the scoring results, and the scoring vector standardization subunit generates a unified scoring vector. In the feature fusion and level scoring module, the feature fusion subunit fuses the scoring vector with the level risk weight, the level prediction subunit generates level labels, and the decision rule coordination subunit corrects the results.
[0025] The beneficial effects of this invention are as follows: The risk-guided network security level protection management system provided by this invention employs a multi-channel semantic coding structure to model network security level protection requirements and assessment evidence information in parallel. It integrates deep semantic features, statistical keyword features, and structural grammar features, improving the adaptability and discriminative power of semantic representation to different types of input text. A semantic interaction matrix is constructed, and a multi-channel scoring function and aggregation mechanism are introduced to perform fine-grained modeling of the semantic association between level requirements and assessment evidence, achieving semantic alignment and matching strength quantification at the control point level. A risk factor-guided fusion mechanism and decision rule coordination module are introduced during the level scoring process, enabling the level label output to respond to changes in the weights of key control items, thus enhancing the sensitivity of the assessment results. This invention achieves better results in terms of accuracy and flexibility. Attached Figure Description
[0026] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a framework diagram of a risk-guided network security level protection management system provided for the first embodiment of the present invention.
[0028] Figure 2 This is a framework diagram of a network security semantic encoding module in a risk-guided network security level protection management system, as provided in the first embodiment of the present invention.
[0029] Figure 3This is a framework diagram of a cross-matching analysis module of a risk-guided network security level protection management system provided in the first embodiment of the present invention.
[0030] Figure 4 This is a framework diagram of a feature fusion and level scoring module for a risk-guided network security level protection management system, provided in the first embodiment of the present invention. Detailed Implementation
[0031] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0032] Example 1, referring to Figure 1 As one embodiment of the present invention, a risk-guided network security level protection management system is provided, comprising:
[0033] The network security semantic encoding module 100, as the system's input processing module, receives information on the basic requirements for network security level protection and evidence information on network equipment evaluation items. It performs multi-channel semantic feature encoding on both and outputs a set of semantic vectors in a unified format. This set of semantic vectors serves as the input to the subsequent cross-matching analysis module 200.
[0034] After receiving the set of semantic vectors, the cross-matching analysis module 200 generates an interaction feature matrix through the interaction relationship construction submodule, and calculates the semantic matching score through the scoring function integration submodule. Then, through score aggregation and standardization operations, it outputs the matching score vector.
[0035] The feature fusion and rating module 300 receives the matching rating vector, fuses it with the risk weights of the preset level protection requirements, generates a fusion vector, and outputs the level label through the level prediction submodule. If some values in the matching rating vector are at the level boundary or the key requirement is rated low, the rule coordination submodule in this module will trigger a correction mechanism.
[0036] S1: Network security semantic coding module 100.
[0037] The network security semantic encoding module 100 is used to perform semantic vector encoding processing on the basic requirements information of network security level protection and the evidence information of network equipment evaluation items. This module, through a multi-channel semantic expression structure, transforms the input text into a high-dimensional semantic feature vector in a unified format, providing the input basis for matching calculations in subsequent modules. This module is located in the upstream stage of the system architecture and directly affects the quality of semantic matching and the accuracy of level assessment.
[0038] Furthermore, refer to Figure 2 The network security semantic coding module 100 includes a deep semantic coding subunit 101, a statistical semantic coding subunit 102, a structural semantic coding subunit 103, and a channel fusion subunit 104.
[0039] It should be noted that the network security semantic encoding module 100 also includes a deep semantic encoding subunit 101 that performs context modeling on the text based on a pre-trained language model, extracting high-dimensional embedding vectors with word order dependencies and syntactic structures. This unit uses a language modeler based on the Transformer architecture to embed the complete input text, extracting semantic vectors with context-dependent characteristics. The original text is segmented and positionally encoded. The encoding results are input into a multi-layer Transformer network for multi-head attention calculation. The [CLS] position or the average vector of the entire sentence is extracted from the Transformer output as the semantic representation vector.
[0040] The statistical semantic coding subunit 102 calculates keyword importance based on TF-IDF or term frequency models, generates sparse vector representations, receives input information on basic requirements for network security level protection and evidence information on network equipment evaluation items, and performs deep semantic modeling on them. It also performs shallow semantic modeling on the input text based on a term statistical model. This unit does not consider the contextual order of terms, but instead statistically analyzes metrics such as term frequency and inverse document frequency to construct a sparse vector representation of the input text. Its processing includes word segmentation and stop word filtering. It statistically analyzes the frequency of terms in the current text and document set. It constructs sparse vectors according to rules such as TF-IDF. Finally, it performs vector normalization and dimension alignment.
[0041] The structural semantic encoding subunit 103 constructs a syntactic dependency graph, utilizes a graph neural network to model structural relationships and logical dependencies in the text, and extracts structural feature vectors. The input text is modeled structural information by extracting syntactic dependency relationships, semantic connection relationships, or logical combination patterns, constructing a graph structure representation, and generating corresponding structural embeddings. A syntactic parser identifies structural syntactic relationships between words, such as subject-verb, verb-object, modification, and coordination. Using terms as nodes and dependency relationships as edges, a labeled directed graph structure is formed. The constructed graph structure is then embedded using a graph convolutional network or message passing mechanism to generate structural semantic vector representations.
[0042] The channel fusion subunit 104 fuses the semantic vectors output from the three encoding subunits and dynamically adjusts the fusion strategy based on the characteristics of the input data to generate a set of semantic representation vectors in a unified format. Dynamic fusion weights are set for the deep semantic channel, statistical semantic channel, and structural semantic channel based on attributes such as the length of the input text, syntactic complexity, and keyword ratio. Strategies such as weighted fusion, attention fusion, or splicing-projection fusion are executed to combine the multi-channel semantic vectors into a single unified vector. This operator ensures that the output vector meets the input dimension and format requirements of subsequent modules.
[0043] S2: Cross-matching analysis module 200.
[0044] The cross-matching analysis module 200 is used to perform matching analysis on the semantic vector set of basic requirements for network security level protection and the semantic vector set of evidence for network device evaluation items. Based on a scoring-based matching architecture, this module constructs an interactive feature matrix, generates matching scoring vectors through multiple scoring factor calculation processes, and generates the final semantic matching scoring vector through multi-stage aggregation for use by subsequent scoring modules.
[0045] The core design of this module is to decompose the semantic relationship modeling process of two vector sets into multiple scoring paths and perform vector-level multi-dimensional scoring fusion processing.
[0046] Furthermore, refer to Figure 3 It can be seen that the cross-matching analysis module 200 includes an interaction relationship construction subunit 201, a scoring function integration subunit 202, a scoring aggregation subunit 203, and a scoring vector standardization subunit 204.
[0047] It should be noted that the cross-matching analysis module 200 also includes an interaction relationship construction subunit 201, which combines the semantic vectors of the level requirements with the semantic vectors of the device evidence in pairs to construct interaction pairs and generate an interaction vector matrix, which is the set of semantic encoded vectors of the basic requirements for network security level protection.
[0048] Network device evaluation item evidence semantic encoding vector set
[0049] For sets Each vector in With sets Each vector in Combine them in pairs. This represents the total number of semantic encoding vectors representing the basic requirements for network security level protection. The first in the semantic coding vector set of the basic requirements for network security level protection One index, , This represents the total number of semantic encoding vectors for evidence of network device evaluation items. The first in the set of semantic encoding vectors for evidence of network device evaluation items One index, .
[0050] Each vector pair is fed into the relation function builder, which outputs the interaction vector. , forming an interaction matrix , dimension ,in For the interaction vector dimension.
[0051] Interaction vectors Represents vector pairs The semantic relationship between them is used as input for the subsequent scoring function, and the calculation process is expressed as follows:
[0052]
[0053] in, This is the final interaction feature vector. For semantic coupling coefficients, As the normalized balance factor, It is the hyperbolic tangent function. For the Euclidean norm, is the ReLU function, representing nonlinear compression.
[0054] The scoring function integration subunit 202 calculates a matching score for each set of interaction vectors through a separate scoring channel. The system needs to determine whether network devices meet the graded protection requirements based on multiple semantic dimensions and cannot rely on a single vector similarity. Therefore, this formula nests and fuses three different scoring mechanisms to construct a multi-channel scoring function. The system receives the interaction feature vector output by the interaction relationship construction unit. And construct a parallel computing structure for multiple scoring paths, for each pair Generate fusion matching score The scoring function consists of three parts:
[0055] Path 1: Normalize the squared magnitude of the interaction vector to evaluate its semantic interaction strength.
[0056] Path 2: Input the interaction vector into the neural network model MLP to extract its deep nonlinear expressive power.
[0057] Path 3: Construct a matching decay scoring factor based on the Euclidean distance between the requirement vector and the evidence vector.
[0058] The weighted combination of the outputs from the three paths is then fed into the Sigmoid activation function to obtain the final score.
[0059]
[0060] in, The merged matching score. It is the Sigmoid activation function. The L2 norm of the interaction vectors, As a distance penalty factor, The weighting coefficient for the scoring channels. It is a function of a one-layer feedforward neural network.
[0061] The final result is a scoring matrix representing the matching relationships between all requirements and evidence. .
[0062] The scoring aggregation subunit 203 aggregates the scores in the scoring matrix by row or column to generate an overall matching scoring vector for each level protection requirement. The current level requirement... All corresponding ratings The attention weights are calculated using the Softmax function.
[0063] All ratings A single matching value is generated by weighted summation based on their respective weights. , represented as:
[0064]
[0065] in, This is the attention amplification factor, used to control the weight steepness. For the first The total matching score for each requirement.
[0066] The output is a matching score vector. This will serve as the scoring input for the next stage.
[0067] The scoring vector standardization subunit 204 normalizes and compresses the range of the aggregated matching scoring vector, outputting a scoring feature vector in a unified format. The system then processes the aggregated matching score vector. Normalization is performed to meet the light-entry requirements of the subsequent rating assessment model, and it is expressed as:
[0068]
[0069] in For adjustment coefficients, Set a value for the score center offset.
[0070] Final output For the first Standardized scores for each level requirement.
[0071] S3: Feature Fusion and Rating Module 300.
[0072] Furthermore, refer to Figure 4 It can be seen that the feature fusion and rating module 300 includes a feature fusion subunit 301, a rating prediction subunit 302, and a decision rule coordination subunit 303.
[0073] It should be noted that the feature fusion and rating module 300 also includes a feature fusion subunit 301 that receives the matching rating vector and, in conjunction with the risk factor vector of the grade protection requirements, performs a weighted fusion or gating mechanism fusion operation. The cross-matching analysis module 200 outputs the following content: Semantic enhancement, risk-oriented modeling, and feature dimension compression are performed. Positional encoding or higher-order cross-feature generation is applied to the scoring vector to construct a scoring context. A pre-defined risk weight system for each security requirement within the graded protection system is introduced to construct a risk-guiding vector. The scoring vector and the risk-guiding vector are then fused using a weighted strategy to generate an enhanced graded protection scoring feature vector. .
[0074] The grade prediction subunit 302 integrates features into the classification model and outputs corresponding grade protection level labels. It supports single-label and multi-label output formats, constructs a multi-layer perceptron or lightweight decision tree structure, and performs non-linear mapping on the fused scoring vector. The grade label output boundary is defined as follows:
[0075]
[0076] in, , as well as This is a preset threshold.
[0077] The decision rule coordination subunit 303 corrects labels when the model output is inconsistent with the rule system. If the confidence level of the highest-level label is less than a set threshold, the system marks the result as pending review. When a specific control review score is below 0... Furthermore, when the control point is defined as a mandatory requirement, the system forces the adjustment of the body label.
[0078] Example 2 is the second embodiment of the present invention, which differs from the previous embodiment in that:
[0079] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device, such as a personal computer, server, or network device, to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0080] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device, such as a computer-based system, a processor-based system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device. For the purposes of this specification, "computer-readable medium" can mean any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0081] A more specific, non-exhaustive list of examples of computer-readable media includes the following: electronic devices with electrical connections having one or more wires, portable computer disk drives, magnetic devices, random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM) or flash memory, fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0082] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0083] Example 3, the third embodiment of the present invention, provides a method for a risk-guided network security level protection management system. When the system receives a network security level protection assessment task, the network security semantic encoding module 100 receives basic requirements information for level protection and evidence information for network equipment assessment items. These are then encoded sequentially by a deep semantic encoding subunit 101, a statistical semantic encoding subunit 102, and a structural semantic encoding subunit 103. A channel fusion and control subunit 104 fuses the channel vectors to generate a unified format semantic feature vector set. The cross-matching analysis module 200 receives the aforementioned semantic feature vectors. An interaction relationship construction subunit 201 generates interaction pairs, a scoring function integration subunit 202 calculates matching scores for the interaction pairs, a scoring aggregation subunit 203 aggregates the scoring results, and a scoring vector standardization subunit 204 generates a unified scoring vector. In the feature fusion and level scoring module 300, the feature fusion subunit 301 fuses the scoring vector with level risk weights, the level prediction subunit 302 generates level labels, and the decision rule coordination subunit 303 corrects the results.
[0084] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A risk-guided network security level protection management system, characterized in that, include: The network security semantic coding module (100) is used to perform multi-channel semantic coding on the basic requirements information of network security level protection and the evidence information of network equipment evaluation items, and output a high-dimensional semantic feature vector in a unified format. The multi-channel semantic coding includes context modeling, statistical feature extraction and structural semantic modeling. The cross-matching analysis module (200) is used to receive the set of semantic feature vectors, construct a semantic interaction matrix between the level requirements and the assessment evidence, calculate the matching score through a multi-channel scoring function, aggregate the multi-dimensional scoring results, and output the level matching score vector. The feature fusion and rating module (300) is used to fuse the matching rating vector with the preset risk weight of the rating requirement, generate a fused feature vector through the fusion strategy, and input it into the rating prediction model to output the network security rating label; The network security semantic coding module (100) includes a deep semantic coding subunit (101), a statistical semantic coding subunit (102), a structural semantic coding subunit (103), and a channel fusion subunit (104). The deep semantic coding subunit (101) performs context modeling on the text based on a pre-trained language model and extracts high-dimensional embedding vectors with word order dependence and syntactic structure; the subunit uses a language modeler based on the Transformer architecture to embed the complete input text and extract semantic vectors with context-dependent characteristics. The statistical semantic coding subunit (102) calculates the importance of keywords based on TF-IDF, generates sparse vector representations, receives input information on basic requirements for network security level protection and evidence information on network equipment evaluation items, and performs deep semantic modeling. Perform shallow semantic modeling on the input text based on term statistics model; The structural semantic encoding subunit (103) constructs a syntactic dependency graph, uses a graph neural network to model the structural relationships and logical dependencies in the text, and extracts structural feature vectors; it models the structural information of the input text, and constructs a graph structure representation and generates the corresponding structural embedding by extracting syntactic dependency relationships, semantic connection relationships or logical combination patterns in the text; The channel fusion subunit (104) fuses the semantic vectors output by the three coding subunits and dynamically adjusts the fusion strategy according to the characteristics of the input data to generate a set of semantic representation vectors in a unified format. The cross-matching analysis module (200) includes an interaction relationship construction subunit (201), a scoring function integration subunit (202), a scoring aggregation subunit (203), and a scoring vector standardization subunit (204). The interaction relationship construction subunit (201) combines the level requirement semantic vector and the device evidence semantic vector in pairs to construct interaction pairs and generate an interaction vector matrix, which is the set of semantic encoding vectors for basic requirements of network security level protection. The scoring function integration subunit (202) calculates the matching score through the scoring channel for each group of interaction vectors to construct a multi-channel scoring function. The system receives the interaction feature vector output by the interaction relationship construction subunit and constructs a multi-scoring path parallel computing structure to generate a fusion matching score for each pair of interaction feature vectors. The scoring aggregation subunit (203) aggregates the scores in the scoring matrix by row or column to generate an overall matching scoring vector for each grade protection requirement; The scoring vector standardization subunit (204) normalizes and compresses the range of the aggregated matching scoring vector, and outputs a scoring feature vector in a uniform format. The feature fusion and rating module (300) includes a feature fusion subunit (301), a rating prediction subunit (302), and a decision rule coordination subunit (303). The feature fusion subunit (301) receives the matching score vector and combines it with the risk factor vector required by the grade protection level to perform weighted fusion or gating mechanism fusion operation; The level prediction subunit (302) inputs the fused features into the classification model, outputs the protection level label of the corresponding level, constructs a multi-layer perceptual network, performs nonlinear mapping on the fused scoring vector, and sets the output boundary of the level label; The decision rule coordination subunit (303) corrects the label when the model output is inconsistent with the rule system. If the confidence of the highest level label is less than the set threshold, the system marks the result as pending review. When the control review score is 0 or lower than the first-level label output boundary, and the control point is defined as a mandatory requirement, the system forcibly lowers the overall label.
2. A method for using a risk-guided network security level protection management system as described in claim 1, characterized in that: When the system receives a network security level protection assessment task, the network security semantic coding module (100) receives the basic requirements information of the level protection and the evidence information of the network equipment assessment items, and encodes them in sequence by the deep semantic coding subunit (101), the statistical semantic coding subunit (102) and the structural semantic coding subunit (103). The channel fusion and control subunit (104) fuses the channel vectors to generate a set of semantic feature vectors in a unified format. The cross-matching analysis module (200) receives the semantic feature vectors mentioned above. The interaction relationship construction subunit (201) generates interaction pairs. The scoring function integration subunit (202) calculates the matching score for the interaction pairs. The scoring aggregation subunit (203) aggregates the scoring results. The scoring vector standardization subunit (204) generates a unified scoring vector. In the feature fusion and grade scoring module (300), the feature fusion subunit (301) fuses the scoring vector with the grade risk weight. The grade prediction subunit (302) generates grade labels. The decision rule coordination subunit (303) corrects the results.
Citation Information
Patent Citations
Network security level protection management system and method based on artificial intelligence
CN118709925A