Catering compliance attack and defense system

By combining the military strategy library and AI engine, new attack scenarios are dynamically generated and defense evaluation is carried out, the problems of insufficient prediction and inaccurate evaluation of traditional catering compliant offensive and defense systems are solved, and active defense and resource optimization for new attacks are achieved.

CN120498712APending Publication Date: 2025-08-15余沁姝
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510445076.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Traditional catering compliance offensive and defense systems rely on static rule databases and cannot actively predict new attack methods. Manually designed attack scenarios are time-consuming and costly. There are lack of quantitative indicators for the evaluation of defense effect, making it difficult to achieve accurate optimization.

Method used

The military strategy library is combined with the AI engine to dynamically generate new attack scenarios, simulate attacks through the red team engine, the blue team system responds and records logs, analyzes the engine to calculate defense gaps and generates heat maps, and the battle report system provides visual evaluation.

Benefits of technology

It realizes proactive prediction of new attacks, improves defense initiative and forward-lookingness, expands attack scenario coverage, shortens response timeliness, provides quantitative defense effectiveness evaluation, and optimizes resource allocation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498712A_ABST
    Figure CN120498712A_ABST
Patent Text Reader

Abstract

The invention discloses a catering compliance attack and defense system. The system comprises a soldier strategy library, a red team engine, an attack template library, a sand table, a blue team system, an analysis engine and a combat system. The catering compliance attack and defense system provided by the embodiment of the invention has the following three advantages: firstly, by combining a soldier strategy library and an AI generation engine, unknown risks can be actively pre-judged, and the initiative and foresight of defense are improved; secondly, the system constructs a self-adaptive compliance system through attack and defense data reverse optimization, and closed-loop evolution and continuous improvement of the attack and defense capacity are achieved; and finally, through a thermodynamic diagram and other visual tools, the system converts complex risk information into a visual and understandable action guide, and provides support for rapid decision making for a management layer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of compliance attack and defense systems, and in particular relates to a catering compliance attack and defense system. Background Art

[0002] Traditional catering compliance attack and defense systems have numerous shortcomings in practical application. First, they rely on a static rule base, passively responding only to known violations and lacking the ability to predict emerging attack methods such as AI-generated fraudulent orders and supply chain vulnerability exploitation. Second, manually designing attack scenarios is time-consuming, requiring 3-5 days for a single scenario, and is costly, requiring significant investment in manpower and equipment. However, the coverage of risk scenarios is as low as 10%-20%. Third, evaluating defense effectiveness relies on expert experience and lacks quantitative metrics such as defense coverage and response timeliness, making precise optimization difficult. Summary of the Invention

[0003] The purpose of this application is to provide a catering compliance attack and defense system to solve at least one of the above technical problems.

[0004] To achieve the above application objectives, the technical solutions adopted in this application are as follows:

[0005] The present application provides a catering compliance attack and defense system, including a military strategy library, a red team engine, an attack template library, a sandbox, a blue team system, an analysis engine, and a battle report system, for implementing a catering compliance attack and defense method, including:

[0006] S10. The red team engine selects a target strategy from the military strategy library and a target attack template classified under the target strategy from the attack template library. It then dynamically generates new attack scenarios for input into the sandbox based on AI technology.

[0007] S20. The Blue Team system triggers and responds to the corresponding dynamic plan based on the new attack scenario in the sandbox, and records the response process and results as a response log;

[0008] S30, the analysis engine calculates the defense gaps of the blue team system based on new attack scenarios and response logs, and reversely trains the attack model of the red team engine;

[0009] S40, the analysis engine generates heat maps and upgrade recommendations based on response logs and defense gaps;

[0010] S50, the battle report system receives the heat maps and upgrade suggestions generated by the analysis engine, and provides a visual evaluation of defense effectiveness.

[0011] In some embodiments, the method for constructing a military strategy library includes: digitizing the strategies in military strategy books.

[0012] In some embodiments, digitizing military strategy books includes:

[0013] Digitize the strategies in Sun Tzu's Art of War to build a military strategy library that includes strategies such as attacking the enemy when they are unprepared and making a feint to the east and attacking in the west;

[0014] Among them, the digital logic of the strategy of attacking when the enemy is unprepared is: the strategy of attacking during the period of weak defense; the digital logic of the strategy of making a feint to the east and attacking in the west is: feigning an attack on secondary systems to lure out defense resources.

[0015] In some embodiments, step S10 includes:

[0016] The red team engine selects the "attack the enemy by surprise" strategy from the military strategy library and the midday attack template classified under the "attack the enemy by surprise" strategy from the attack template library, and dynamically generates a combined attack based on AI technology.

[0017] In some embodiments, the combined attack includes:

[0018] (1) Chaos Mesh simulates POS machine downtime;

[0019] (2) DeepSeek-R1-671B generates 100 fake negative reviews;

[0020] (3) The crawler automatically publishes to Dianping and Weibo.

[0021] In some embodiments, in step S30, reverse training the attack model of the red team engine includes: strengthening learning to adjust the strategy weights.

[0022] In some embodiments, step S40 includes:

[0023] The analysis engine obtains attack impact, defense coverage, and response timeliness based on response logs and defense gaps.

[0024] The analysis engine generates heat maps and upgrade recommendations based on attack impact, defense coverage, and response timeliness.

[0025] Compared with the prior art, the beneficial effects of the embodiments of the present application are:

[0026] The catering compliance attack and defense system provided in the embodiment of the present application has three major advantages: first, it combines the military strategy library with the AI generation engine to proactively predict unknown risks, thereby improving the initiative and foresight of defense; second, the system uses attack and defense data for reverse optimization to build an adaptive compliance system, achieving closed-loop evolution and continuous improvement of attack and defense capabilities; finally, through visualization tools such as heat maps, the system transforms complex risk information into intuitive and easy-to-understand action guides, providing management with support for rapid decision-making. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0028] Figure 1 A flowchart of a catering compliance attack and defense method provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0029] In order to make the technical problems, technical solutions and beneficial effects to be solved by this application more clearly understood, this application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0030] Traditional catering compliance attack and defense systems have numerous shortcomings in practical application. First, they rely on a static rule base, passively responding only to known violations and lacking the ability to predict emerging attack methods such as AI-generated fraudulent orders and supply chain vulnerability exploitation. Second, manually designing attack scenarios is time-consuming, requiring 3-5 days for a single scenario, and is costly, requiring significant investment in manpower and equipment. However, the coverage of risk scenarios is as low as 10%-20%. Third, evaluating defense effectiveness relies on expert experience and lacks quantitative metrics such as defense coverage and response timeliness, making precise optimization difficult.

[0031] In view of this, the present application provides a catering compliance attack and defense system with the following functions:

[0032] (1) Dynamic risk prediction and countermeasure capabilities: The system can proactively identify and predict new attack methods, including but not limited to complex attack chains such as "equipment failure + public opinion attack", so as to take defensive measures in advance.

[0033] (2) Defense strategy adjustment driven by real-time attack and defense data: The system has the ability to dynamically adjust and evolve defense strategies based on real-time attack and defense data, ensuring that defense measures always keep pace with the current threat environment.

[0034] (3) Comprehensive attack scenario coverage: The system expands the coverage of the attack library to include risks at the business and public opinion levels, ensuring that it can simulate and defend against various possible attack scenarios.

[0035] (4) Data-driven defense effectiveness quantitative model: The system establishes a clear evaluation system and uses a data-driven defense effectiveness quantitative model to accurately evaluate the defense effect and provide a scientific basis for optimizing defense strategies.

[0036] In order to illustrate the technical solution described in this application, specific embodiments are provided below.

[0037] See also Figure 1 As shown, an embodiment of the present application provides a catering compliance attack and defense system, including: a military strategy library, a red team engine, an attack template library, a sandbox, a blue team system, an analysis engine and a battle report system. The catering compliance attack and defense system is used to implement a catering compliance attack and defense method to solve the above-mentioned technical problems.

[0038] The compliance attack method includes the following steps:

[0039] S10. The red team engine selects a target strategy from the military strategy library and a target attack template classified under the target strategy from the attack template library, and dynamically generates a new attack scenario for input into the sandbox based on AI technology.

[0040] Generating new attack scenarios through this step can solve the problem that traditional attack scenarios are single and cannot predict new violation methods.

[0041] As an example, the method for building a military strategy library includes:

[0042] Digitize the strategies in books on military strategy, such as the strategies in "The Art of War", so as to build a military strategy library including strategies such as attacking the enemy when they are unprepared and making a feint to the east and attacking in the west.

[0043] As an example, the digital logic of the attack-where-the-enemy strategy is: a strategy of attacking during periods of weak defense, such as the midday market peak (e.g., 11:00-14:00 noon) and the evening market peak.

[0044] For example, the digital logic behind the "feint to the east, attack to the west" strategy involves feinting an attack on a secondary system to decoy defense resources. For example, a network attack log might be forged to reveal the true target is the financial system.

[0045] As an example, the code sample of the attack-by-defense strategy is as follows:

[0046]

[0047]

[0048] As an example, a plurality of templates are preset in the attack template library, such as a midday attack template and a night market attack template.

[0049] As an example, AI-based dynamic generation of new attack scenarios includes: Dynamic generation of new attack scenarios based on DeepSeek-R1-671B, combined with reinforcement learning to optimize strategy combinations. For example, over 50 attack variants can be generated daily for compliance-enabling attack and defense, such as "AI forging CEO voice commands to bypass approval processes."

[0050] As an example, step S10 includes the following steps:

[0051] S11. The red team engine selects the "attack the enemy when they are unprepared" strategy from the military strategy library and the midday attack template classified under the "attack the enemy when they are unprepared" strategy from the attack template library, and dynamically generates a combination attack based on AI technology (this combination attack is a new attack scenario). For example, the combination attack includes two major attacks: equipment failure and public opinion attack.

[0052] As an example, a sample attack chain for a combined attack is as follows:

[0053] (1) Chaos Mesh simulates POS machine downtime (fault injection);

[0054] (2) DeepSeek-R1-671B generated 100 fake negative reviews (“There was hair in the dish”);

[0055] (3) The crawler automatically publishes to Dianping and Weibo.

[0056] Among them, attack chain (1) is a specific example of equipment failure, and attack chains (2) and (3) are specific examples of public opinion attacks.

[0057] S20. The blue team system triggers and responds to the corresponding dynamic plan based on the new attack scenario in the sandbox, and records the response process and results as a response log.

[0058] As an example, the sandbox serves as a platform for simulating attack scenarios (i.e., new attack scenarios) for the red team engine to generate attack scenarios and the blue team system to perform defensive responses.

[0059] As an example, a dynamic response plan can be implemented based on specific new attack scenarios. For example, a dynamic response plan might include: activating the "Equipment Emergency Plan," automatically switching to a backup POS terminal, and initiating an AI-powered automatic response from the public opinion monitoring platform.

[0060] As an example, the code sample of the response log is as follows:

[0061]

[0062] As an example, the response time can be used to represent the timeliness of the response, and the impact value can be used to represent the impact value of a new attack scenario on the blue team system.

[0063] S30. The analysis engine calculates the defense gaps of the blue team system based on the new attack scenario and the response log, and reversely trains the attack model of the red team engine, such as adjusting the strategy weights through reinforcement learning.

[0064] As an example, strategy weight = historical win rate × attack impact value.

[0065] Example: The weight of the "attack the enemy by surprise" strategy (0.56) = the winning rate of the "attack the enemy by surprise" strategy (such as 80%) × the influence value (such as 0.7 in the response log).

[0066] As an example, defense coverage can be determined by identifying new attack scenarios and defense gaps.

[0067] S40. The analysis engine generates a heat map and upgrade suggestions based on the response log and the defense gap, so as to intuitively display the strength and weakness distribution of defense effectiveness and optimize the defense system.

[0068] Therefore, as an example, the analysis engine can generate heat maps and upgrade recommendations based on attack impact value, defense coverage, and response timeliness to quantitatively evaluate defense effectiveness and guide precise resource investment.

[0069] As an example, the attack impact value can be calculated in real time through Apache Spark (a fast, general-purpose large-scale data processing engine).

[0070] As an example, a heat map can be dynamically generated by Tableau (a data visualization tool).

[0071] Among them, red indicates high risk and green indicates low risk.

[0072] As an example, the upgrade recommendations include short-term recommendations and long-term recommendations.

[0073] For example, short-term recommendations: For the red areas of the heat map (such as POS system defense gaps > 40%), give priority to purchasing high-availability equipment (60% of the budget allocation).

[0074] For example, long-term recommendation: deploy an AI public opinion monitoring system (estimated ROI ≥ 200%).

[0075] S50, the battle report system receives the heat map and upgrade suggestions generated by the analysis engine, and provides a visual defense effectiveness evaluation for reference by management and relevant personnel.

[0076] The catering compliance attack and defense system provided in the embodiments of this application has the following advantages:

[0077] 1. Dynamic risk prediction and defense evolution:

[0078] (1) The coverage of new attack scenarios has been significantly improved from 20% to 80%, and potential unknown risks such as supply chain counterfeiting attacks can be discovered 3-6 months in advance.

[0079] (2) The cost of attack generation has been significantly reduced by 90%, thanks to AI technology replacing manual design and improving efficiency.

[0080] (3) The defense response time was significantly shortened from 30 minutes to 9 minutes, which improved the emergency response speed.

[0081] (4) The speed of repairing defense gaps is accelerated by 50%. The heat map helps to accurately locate and optimize resource investment, accelerating the improvement of the defense system.

[0082] 2. Richness of attack scenarios and standardization of assessment systems:

[0083] (1) The attack library templates have been greatly expanded from 50 to 500, including 20% dynamically generated scenarios, covering multiple dimensions such as technology, business, and public opinion.

[0084] (2) Business-level scenarios such as midday market attacks were incorporated into regular drills, enhancing combat capabilities.

[0085] (3) Quantitative indicators of defense effectiveness, such as defense coverage and response speed, are fully applied, which improves the accuracy and objectivity of the assessment.

[0086] (4) The accuracy of compliance budget allocation has increased by 60%. Data-driven decision-making has replaced previous experience-based decisions, optimizing resource allocation.

[0087] In summary, the embodiment of the present application provides a catering compliance attack and defense system, which combines a military strategy library with an AI engine to proactively predict risks; and utilizes reverse optimization of attack and defense data to achieve continuous improvement in attack and defense capabilities.

Claims

1. A catering compliance attack and defense system, characterized by: It includes a military strategy library, a red team engine, an attack template library, a sandbox, a blue team system, an analysis engine, and a battle report system, and is used to implement catering compliance attack and defense methods, including: S10. The red team engine selects a target strategy from the military strategy library and a target attack template classified as the target strategy from the attack template library, and dynamically generates a new attack scenario for input into the sandbox based on AI technology; S20. The blue team system triggers and responds to the corresponding dynamic plan based on the new attack scenario in the sandbox, and records the response process and results as a response log; S30: The analysis engine calculates the defense gap of the blue team system based on the new attack scenario and the response log, and reversely trains the attack model of the red team engine; S40. The analysis engine generates a heat map and upgrade suggestions based on the response log and the defense gap. S50, the battle report system receives the heat maps and upgrade suggestions generated by the analysis engine, and provides a visual evaluation of defense effectiveness.

2. A catering compliance attack and defense system according to claim 1, characterized in that: The method for constructing the military strategy library includes: digitizing the strategies in military strategy books.

3. A catering compliance attack and defense system according to claim 2, characterized in that: The digitization of military strategy books includes: Digitize the strategies in Sun Tzu's Art of War to build a military strategy library that includes strategies such as attacking the enemy when they are unprepared and making a feint to the east and attacking in the west; Among them, the digital logic of the strategy of attacking when the enemy is unprepared is: the strategy of attacking during the period of weak defense; the digital logic of the strategy of making a feint to the east and attacking in the west is: feigning an attack on secondary systems to lure out defense resources.

4. A catering compliance attack and defense system according to claim 1, characterized in that: Step S10 includes: The red team engine selects the "attack the enemy by surprise" strategy from the military strategy library and the midday attack template classified under the "attack the enemy by surprise" strategy from the attack template library, and dynamically generates a combined attack based on AI technology.

5. A catering compliance attack and defense system according to claim 4, characterized in that: Combination attacks include: (1) Chaos Mesh simulates POS machine downtime; (2) DeepSeek-R1-671B generates 100 fake negative reviews; (3) The crawler automatically publishes to Dianping and Weibo.

6. A catering compliance attack and defense system according to claim 1, characterized in that: In step S30, reverse training of the attack model of the red team engine includes: strengthening learning to adjust the strategy weights.

7. A catering compliance attack and defense system according to claim 1, characterized in that: Step S40 includes: The analysis engine obtains the attack impact value, defense coverage and response timeliness based on the response log and the defense gap; The analysis engine generates heat maps and upgrade recommendations based on attack impact, defense coverage, and response timeliness.