AI-based network security system construction, operation and maintenance method, device and system and medium

CN120639376AInactive Publication Date: 2025-09-12GUIZHOU DAILY
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510754768.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When faced with new types of unknown attacks, massive data processing, and dynamically changing network environments, traditional network security systems have low detection efficiency, high false alarm rates, and lack of adaptability, making it difficult to accurately identify and respond to complex threats.

Method used

By acquiring multi-dimensional data streams and using algorithms to reduce dimensionality, we obtain a low-dimensional feature vector set. We then combine the adaptive clustering algorithm with the preset attack pattern library for dynamic correlation matching to generate a threat situation analysis diagram. We also use the generative adversarial network algorithm to simulate multi-scenario attack paths, optimize defense strategy parameters, and generate a real-time updated threat situation report.

Benefits of technology

It achieves accurate identification of new attack features, improves the accuracy and real-time nature of threat situation awareness, enhances the ability of network security systems to respond to complex threats, and provides intelligent defense strategy optimization suggestions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639376A_ABST
    Figure CN120639376A_ABST
Patent Text Reader

Abstract

The invention relates to an AI-based network security system construction, operation and maintenance method, device and system and a medium. The method comprises the following steps: firstly, acquiring a multi-dimensional data stream, performing feature extraction on the multi-dimensional data stream, and performing dimension reduction by using an algorithm to obtain a low-dimensional feature vector set; fusing an adaptive clustering algorithm according to the vector set to obtain clustering model parameters; extracting novel attack features from the clustering model parameters, and integrating the novel attack features and the clustering model parameters by means of a Bayesian network algorithm to generate a threat situation analysis chart; simulating a multi-scene attack path by utilizing a generative adversarial network algorithm based on the analysis graph, generating a virtual attack data stream and obtaining a defense response result; and finally, aiming at a defense response result, applying a reinforcement learning algorithm to optimize defense strategy parameters, and generating a real-time updated threat situation report after multiple rounds of verification. According to the method, novel attack features can be accurately identified, the accuracy and real-time performance of threat situation awareness are effectively improved, and the ability of a network security system to deal with various complex threats is greatly enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and in particular relates to AI-based network security system construction and operation and maintenance methods, devices, systems and media. Background Art

[0002] With the development of network security technology, AI-based network security system construction and operation and maintenance technologies have emerged. With the rapid development of information technology, networks have become deeply integrated into all areas of society, and various network security threats have also become more diverse, complex, and intelligent. Traditional network security systems rely primarily on protection mechanisms based on rules and feature matching. Faced with new and unknown attacks, massive data processing, and dynamically changing network environments, their shortcomings, such as low detection efficiency, high false alarm rates, and lack of adaptability, have become increasingly apparent. Furthermore, the explosive growth of network traffic, the increasing complexity of system behavior, and the widespread dispersion of external threat intelligence sources have made it increasingly difficult to accurately identify and respond to potential security risks. Summary of the Invention

[0003] Based on this, it is necessary to address the above technical issues and provide an AI-based network security system construction and operation method, device, system and medium that can accurately identify new attack characteristics, effectively improve the accuracy and real-time performance of threat situation perception, and greatly enhance the ability of network security systems to respond to various complex threats.

[0004] First, this application provides an AI-based network security system construction and operation method, including:

[0005] Acquire multidimensional data streams including network traffic logs, system behavior records, and external threat intelligence; perform feature extraction on the multidimensional data streams and use dimensionality reduction algorithms to obtain a low-dimensional feature vector set.

[0006] The clustering model parameters are obtained by dynamically correlating and matching the adaptive clustering algorithm with the preset attack pattern library based on the deep fusion of the low-dimensional feature vector set.

[0007] The clustering model parameters are used to extract new attack features and the real-time monitoring network traffic data is integrated using the Bayesian network algorithm to generate a threat situation analysis diagram.

[0008] Based on the threat situation analysis diagram, the generative adversarial network algorithm is used to simulate multi-scenario attack paths, generate virtual attack data streams and obtain defense response results.

[0009] The defense response results are optimized using a reinforcement learning algorithm to optimize defense strategy parameters, and a real-time updated threat situation report is generated through multiple rounds of verification using a Monte Carlo tree search algorithm.

[0010] In one embodiment, clustering model parameters are obtained by dynamically associating and matching a low-dimensional feature vector set with a deep fusion adaptive clustering algorithm and a preset attack pattern library, including:

[0011] Get the dimensionality reduction distribution result of the low-dimensional feature vector set; the dimensionality reduction distribution result includes weight parameters of multiple feature dimensions.

[0012] The dynamic association threshold of the adaptive clustering algorithm is adjusted according to the weight parameter; the dynamic association threshold is used to control the matching range between the cluster center and the attack pattern library.

[0013] The pattern feature labels in the preset attack pattern library are extracted, and a similarity matrix between the dimensionality reduction distribution results and the pattern feature labels is calculated and constructed; the similarity matrix contains the matching scores of different attack patterns.

[0014] Based on the dynamic correlation threshold, high-correlation data nodes in the similarity matrix are screened to form initial clusters.

[0015] The center vector of the adaptive clustering algorithm is updated according to the initial cluster clusters to generate dynamically optimized clustering model parameters.

[0016] In one embodiment, clustering model parameters are used to extract new attack features and real-time monitoring of network traffic data is integrated using a Bayesian network algorithm to generate a threat situation analysis diagram, including:

[0017] Obtain traffic segments from real-time monitored network traffic data; traffic segments include protocol type and payload length.

[0018] The feature vectors generated according to the traffic segments are input into the dynamic clustering center, and the real-time feature library is updated using the incremental clustering algorithm.

[0019] Abnormal traffic clusters are extracted from the real-time feature library to obtain abnormal traffic cluster data; abnormal traffic cluster data corresponds to traffic segments that do not match historical behavior patterns.

[0020] The abnormal traffic cluster data is input into the Bayesian network node to obtain the threat probability matrix; the Bayesian network node contains the dependency relationship between the attack stage and the vulnerability exploitation; the threat probability matrix contains the joint probability of lateral penetration and data leakage.

[0021] According to the threat probability matrix, the original network topology is superimposed using the thermal map to generate a threat situation analysis diagram.

[0022] Among them, when the regional heat of the threat situation analysis graph exceeds the preset threshold, the feature weight adjustment instruction of the dynamic clustering center is triggered, and the conditional probability table of the Bayesian network node is reconstructed according to the feature weight adjustment instruction and the reconstructed conditional probability table is synchronized to the real-time feature library.

[0023] In one embodiment, the threat probability matrix is ​​calculated using the following formula:

[0024]

[0025]

[0026] Among them, T kl represents the elements of the threat probability matrix, represents the joint probability of lateral penetration and data leakage, (a x ,v y ) represents lateral penetration corresponding to attack stage a x and exploit v y combination, (a z ,v z ) indicates that the data leakage corresponds to attack stage a z and exploit v z k and l represent the row and column indices of the matrix respectively, P(D) represents the probability of abnormal traffic cluster data D appearing, P(a i ,v j ) represents attack phase a i and exploit v j The prior probability of simultaneous occurrence, P(D|a i ,v j ) indicates that in the attack phase a i and exploit v j The probability of abnormal traffic cluster data D occurring at the same time, P(a j ,v j |D) represents attack phase a i and exploit v j The joint probability of simultaneous occurrence, a i represents the i-th attack stage, v j represents the jth vulnerability exploit, and D represents the abnormal traffic cluster data.

[0027] In one embodiment, based on a threat situation analysis graph, a generative adversarial network algorithm is used to simulate multi-scenario attack paths, generate virtual attack data streams, and obtain defense response results, including:

[0028] Obtain attack path topology data from the threat situation analysis diagram.

[0029] The response feature vectors in the attack path topology data are extracted to obtain anomaly detection tags and node connection relationships; the anomaly detection tags are associated with the rule trigger records in the policy execution log.

[0030] A multi-protocol traffic behavior model is constructed based on the node connection relationship to generate a virtual attack data stream carrying dynamic payload.

[0031] The virtual attack data stream is input into the dynamic defense strategy to obtain a feature vector containing the interception rule identifier and the response delay time.

[0032] According to the interception rule identification matching strategy verification matrix, the defense effectiveness parameters are iteratively calculated with the probability of vulnerability exploitation to obtain the iterative calculation results.

[0033] Based on the iterative calculation results, the adversarial sample generator of the generative adversarial network is updated to generate a defense response result.

[0034] In one embodiment, the defense response results are optimized using a reinforcement learning algorithm for defense strategy parameters, and multiple rounds of verification using a Monte Carlo tree search algorithm are performed to generate a real-time updated threat situation report, including:

[0035] Obtain defense failure case data from the defense response results; defense failure case data includes attack path characteristics and strategy parameters.

[0036] The attack path features are extracted based on the defense failure case data to generate an adversarial path tree.

[0037] A strategy parameter space is constructed based on the adversarial path tree, and the strategy parameter space is iteratively optimized using the reinforcement learning algorithm to obtain the optimized defense strategy parameters; the strategy parameter space includes defense node weights and response thresholds.

[0038] The optimized defense strategy parameters are input into the Monte Carlo tree search algorithm to generate multiple rounds of adversarial path simulation results.

[0039] Based on the results of multiple rounds of adversarial path simulation, dynamic evaluation indicators are calculated and the threat situation feature library is updated. The dynamic evaluation indicators include path coverage and response success rate; the threat situation feature library includes attack patterns and defense vulnerabilities.

[0040] Generate a real-time updated threat situation report based on the threat situation signature library; the threat situation report includes risk levels and defense recommendations.

[0041] In one embodiment, a strategy parameter space is constructed based on the adversarial path tree, and the strategy parameter space is iteratively optimized using a reinforcement learning algorithm to obtain optimized defense strategy parameters, including:

[0042] The initial distribution matrix of the strategy parameter space is generated based on the node feature set of the adversarial path tree; the initial distribution matrix is ​​used to map the defense weights of different paths.

[0043] The reinforcement learning algorithm is used to perform gradient updates on the initial distribution matrix to obtain the updated defense parameter vector.

[0044] The generation probability threshold of adversarial samples used to filter high-threat path branches is calculated based on the defense parameter vector.

[0045] The generation probability threshold is input into the policy evaluation model to obtain the policy stability index.

[0046] Among them, if the strategy stability index is lower than the preset threshold, the node feature set of the adversarial path tree is recalculated and the initial distribution matrix is ​​updated.

[0047] The exploration rate of the reinforcement learning algorithm is adjusted based on the strategy stability index to obtain the optimized defense strategy parameters.

[0048] Secondly, this application also provides an AI-based network security system construction and operation and maintenance device, which includes:

[0049] The data processing module is used to obtain multi-dimensional data streams including network traffic logs, system behavior records and external threat intelligence; extract features from the multi-dimensional data streams and use algorithms to reduce the dimension to obtain a low-dimensional feature vector set; and is also used to deeply integrate the adaptive clustering algorithm with the preset attack pattern library based on the low-dimensional feature vector set for dynamic correlation matching to obtain clustering model parameters.

[0050] The threat situation analysis module is used to extract new attack features from clustering model parameters and integrate network traffic data in real time using the Bayesian network algorithm to generate a threat situation analysis diagram.

[0051] The defense strategy optimization module is used to simulate multi-scenario attack paths based on the threat situation analysis diagram using the generative adversarial network algorithm, generate virtual attack data streams and obtain defense response results; it is also used to optimize the defense strategy parameters based on the defense response results using the reinforcement learning algorithm, and generate a real-time updated threat situation report through multiple rounds of verification using the Monte Carlo tree search algorithm.

[0052] In a third aspect, the present application further provides a computer system comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the above method when executing the computer program.

[0053] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which implements the above method when executed by a processor.

[0054] The AI-based network security system construction and operation and maintenance method, device, system, and medium first acquire multidimensional data streams encompassing network traffic logs, system behavior records, and external threat intelligence. Feature extraction and dimensionality reduction algorithms are used to obtain a low-dimensional feature vector set. Based on this vector set, an adaptive clustering algorithm is deeply integrated with a pre-set attack pattern library for dynamic correlation matching, thereby obtaining clustering model parameters. New attack signatures are then extracted from the clustering model parameters while simultaneously monitoring network traffic data in real time. The two are then integrated using a Bayesian network algorithm to generate a threat situation analysis graph. Based on this analysis graph, a generative adversarial network algorithm is then used to simulate multi-scenario attack paths, generate virtual attack data streams, and obtain defense response results. Finally, based on the defense response results, a reinforcement learning algorithm is used to optimize defense strategy parameters. After multiple rounds of verification using a Monte Carlo tree search algorithm, a real-time updated threat situation report is generated. This system can comprehensively and efficiently process complex and diverse network security data, accurately identify new attack signatures, effectively improve the accuracy and real-time nature of threat situation perception, and intelligently optimize defense strategies, significantly enhancing the network security system's ability to respond to various complex threats and providing strong support for network security construction and operation and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0056] Figure 1 A flowchart of the AI-based network security system construction and operation method provided in an embodiment of the present invention;

[0057] Figure 2 A flowchart of an embodiment of the present invention for optimizing defense strategy parameters using a reinforcement learning algorithm based on defense response results, and performing multiple rounds of verification using a Monte Carlo tree search algorithm to generate a real-time updated threat situation report;

[0058] Figure 3 This is a structural block diagram of the AI-based network security system construction and operation and maintenance device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0059] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0060] In one embodiment, Figure 1As shown, this application provides an AI-based network security system construction and operation method, which may include the following steps:

[0061] Step S101: obtain a multidimensional data stream including network traffic logs, system behavior records and external threat intelligence; perform feature extraction on the multidimensional data stream, and use an algorithm to reduce the dimension to obtain a low-dimensional feature vector set.

[0062] Specifically, through traffic collection devices deployed at key network nodes, behavioral monitoring modules within the system, and data docking interfaces with professional security organizations, we extensively and comprehensively acquire multidimensional data streams covering network traffic logs, system behavior records, and external threat intelligence. Subsequently, using professional data mining techniques, we meticulously analyze the various types of data in this multidimensional data stream, extracting key features such as traffic volume, connection frequency, system call sequences, and known threat signatures. To reduce data dimensionality, minimize computational complexity, and avoid the curse of dimensionality, we utilize classic dimensionality reduction algorithms such as principal component analysis (PCA) to convert the high-dimensional feature space into a set of low-dimensional feature vectors.

[0063] Step S102: Dynamically associate and match the low-dimensional feature vector set with the deep fusion adaptive clustering algorithm and the preset attack pattern library to obtain clustering model parameters.

[0064] Relying on the acquired low-dimensional feature vector set, the algorithm deeply integrates an adaptive clustering algorithm with a pre-set attack pattern library. The adaptive clustering algorithm flexibly adjusts clustering strategies based on the dynamic distribution characteristics of the data, while the pre-set attack pattern library contains feature templates for a large number of previously known attack types. During the dynamic association matching process, the algorithm continuously calculates the similarity between the low-dimensional feature vectors and each pattern in the attack pattern library. Through repeated iterative optimization, it determines the optimal matching relationship between the cluster center and each pattern, and then accurately outputs the clustering model parameters.

[0065] Step S103 , extracting new attack features from clustering model parameters and integrating real-time monitoring network traffic data using a Bayesian network algorithm to generate a threat situation analysis diagram.

[0066] Specifically, the established clustering model parameters are deeply mined, and feature extraction algorithms are used to accurately identify characteristics that may represent new attacks. Simultaneously, real-time network traffic monitoring tools are used to continuously collect network traffic data, focusing on key attributes such as protocol type and payload length within traffic segments. These two attributes are then fed into a Bayesian network algorithm framework. This algorithm, based on probabilistic reasoning, fully considers the complex dependencies between attack phases and vulnerability exploitation. Through rigorous mathematical calculations, it integrates and generates an intuitive and detailed threat landscape analysis diagram, clearly presenting the current threat landscape facing the network in a visual manner.

[0067] Step S104: Based on the threat situation analysis diagram, a generative adversarial network algorithm is used to simulate multi-scenario attack paths, generate virtual attack data streams, and obtain defense response results.

[0068] Based on the generated threat situation analysis diagram, a generative adversarial network algorithm is applied. This algorithm consists of a generator and a discriminator. The generator simulates attack paths in various complex scenarios based on information such as the attack path topology data in the analysis diagram, generating virtual attack data streams carrying dynamic payloads. This virtual attack data stream is then fed into the deployed dynamic defense strategy system. By monitoring the defense system's response to the virtual attacks, the defense response results, including key information such as interception rule identification and response delay time, are obtained.

[0069] Step S105 , using a reinforcement learning algorithm to optimize defense strategy parameters based on the defense response results, and performing multiple rounds of verification using a Monte Carlo tree search algorithm to generate a real-time updated threat situation report.

[0070] Based on the defense response results obtained, a reinforcement learning algorithm is used to intelligently optimize the defense strategy parameters. First, attack path features are extracted from the defense failure case data, and an adversarial path tree is constructed. Based on this, a strategy parameter space containing parameters such as defense node weights and response thresholds is constructed. Through continuous trial and error and learning, the reinforcement learning algorithm searches for the optimal solution in this parameter space and optimizes the defense strategy parameters. Then, using the Monte Carlo tree search algorithm, multiple rounds of simulation verification are performed on the optimized defense strategy parameters. Dynamic evaluation indicators such as path coverage and response success rate are calculated, and the threat situation feature library is updated based on the results. Finally, a real-time threat situation report is generated based on the threat situation feature library. The report clearly provides risk levels and targeted defense recommendations, providing strong support for network security operation and maintenance decision-making.

[0071] The AI-based network security system construction and operation method first acquires multidimensional data streams encompassing network traffic logs, system behavior records, and external threat intelligence. Feature extraction and dimensionality reduction algorithms are used to obtain a low-dimensional feature vector set. Based on this vector set, an adaptive clustering algorithm is deeply integrated with a pre-set attack pattern library for dynamic correlation matching to obtain clustering model parameters. New attack signatures are then extracted from the clustering model parameters while simultaneously monitoring network traffic data in real time. The two are then integrated using a Bayesian network algorithm to generate a threat situation analysis diagram. Based on this analysis diagram, a generative adversarial network algorithm is then used to simulate multi-scenario attack paths, generate virtual attack data streams, and obtain defense response results. Finally, based on the defense response results, a reinforcement learning algorithm is used to optimize defense strategy parameters. After multiple rounds of verification using a Monte Carlo tree search algorithm, a real-time threat situation report is generated. This method can comprehensively and efficiently process complex and diverse network security data, accurately identify new attack signatures, effectively improve the accuracy and real-time nature of threat situation perception, and intelligently optimize defense strategies, significantly enhancing the network security system's ability to respond to various complex threats and providing strong support for network security construction and operation.

[0072] In one embodiment, dynamically associating and matching a low-dimensional feature vector set with a deep fusion adaptive clustering algorithm and a preset attack pattern library to obtain clustering model parameters may include the following steps:

[0073] Step S201, obtaining a dimensionality reduction distribution result of a low-dimensional feature vector set; the dimensionality reduction distribution result includes weight parameters of multiple feature dimensions.

[0074] Step S202: Adjust the dynamic association threshold of the adaptive clustering algorithm according to the weight parameter; the dynamic association threshold is used to control the matching range between the cluster center and the attack pattern library.

[0075] Step S203 , extracting pattern feature labels from the preset attack pattern library, and calculating and constructing a similarity matrix between the dimensionality reduction distribution results and the pattern feature labels; the similarity matrix includes matching scores of different attack patterns.

[0076] Step S204: screening highly correlated data nodes in the similarity matrix based on the dynamic correlation threshold to form initial clusters.

[0077] Step S205 : updating the center vector of the adaptive clustering algorithm according to the initial clusters to generate dynamically optimized clustering model parameters.

[0078] Specifically, the algorithm first obtains the dimensionality reduction distribution of a low-dimensional feature vector set, which contains weight parameters for multiple feature dimensions. Based on these weight parameters, the adaptive clustering algorithm's dynamic correlation threshold is adjusted. This dynamic correlation threshold's key role is to precisely control the matching range between cluster centers and the pre-set attack pattern library. Next, the algorithm extracts the pattern feature labels from the pre-set attack pattern library. Through a series of rigorous calculations, a similarity matrix is ​​constructed between the dimensionality reduction distribution results and the pattern feature labels. This matrix clearly displays the matching scores for different attack patterns. Subsequently, the similarity matrix is ​​filtered based on the dynamic correlation threshold to select highly correlated data nodes, thereby forming initial clusters. Finally, the initial clusters are used to update the adaptive clustering algorithm's center vectors, generating dynamically optimized clustering model parameters.

[0079] This embodiment adjusts the dynamic correlation threshold by introducing a weight parameter based on the dimensionality reduction distribution results, significantly improving the accuracy of the matching between the clustering algorithm and the attack pattern library, enabling more efficient identification of potential attack patterns. A similarity matrix is ​​constructed and highly correlated data nodes are filtered based on the dynamic correlation threshold, effectively filtering out interfering information and making the initial clusters more representative. Dynamically updating the clustering algorithm's center vector allows the clustering model to adapt to dynamic changes in data in real time, enhancing its adaptability and analysis capabilities for complex and changing attack patterns.

[0080] In one embodiment, extracting new attack features from clustering model parameters and integrating real-time monitoring network traffic data using a Bayesian network algorithm to generate a threat situation analysis diagram may include the following steps:

[0081] Step S301: Obtain traffic segments from real-time monitored network traffic data; the traffic segments include protocol type and payload length.

[0082] Step S302: Generate a feature vector based on the traffic segment and input it into a dynamic clustering center, and use an incremental clustering algorithm to update and obtain a real-time feature library.

[0083] Step S303: extract abnormal traffic clusters from the real-time feature library to obtain abnormal traffic cluster data; the abnormal traffic cluster data corresponds to traffic segments that do not match the historical behavior pattern.

[0084] In step S304, the abnormal traffic cluster data is input into the Bayesian network node to obtain a threat probability matrix; the Bayesian network node contains the dependency relationship between the attack stage and the vulnerability exploitation; the threat probability matrix contains the joint probability of lateral penetration and data leakage.

[0085] Step S305 , superimposing the original network topology structure using the thermal map according to the threat probability matrix to generate a threat situation analysis map.

[0086] Among them, when the regional heat of the threat situation analysis graph exceeds the preset threshold, the feature weight adjustment instruction of the dynamic clustering center is triggered, and the conditional probability table of the Bayesian network node is reconstructed according to the feature weight adjustment instruction and the reconstructed conditional probability table is synchronized to the real-time feature library.

[0087] Through a real-time monitoring mechanism, traffic segments from network traffic data are captured. These segments contain key information about protocol types and payload lengths. Based on these traffic segments, feature vectors are generated and fed into a dynamic clustering center. The real-time feature library is continuously updated using an incremental clustering algorithm. Subsequently, an anomaly cluster extraction operation is performed on the real-time feature library, filtering out traffic segments corresponding to unmatched historical behavior patterns to generate anomaly traffic cluster data. This anomaly traffic cluster data is then fed into a Bayesian network node that contains attack phases and vulnerability exploitation dependencies. Complex calculations generate a threat probability matrix containing the joint probabilities of lateral movement and data exfiltration. Finally, based on the threat probability matrix, a heatmap is overlaid on the original network topology to intuitively generate a threat landscape analysis map. Specifically, when the heat level of a region in the threat landscape analysis map exceeds a preset threshold, the system automatically triggers a feature weight adjustment command from the dynamic clustering center. This command reconstructs the conditional probability table of the Bayesian network node and promptly synchronizes the reconstructed conditional probability table to the real-time feature library.

[0088] This embodiment obtains traffic segments in real time and updates the feature library, which can timely capture the dynamic changes of network traffic, improve the sensitivity of perception of abnormal traffic, and thus enhance the accuracy of threat detection. The threat probability matrix is ​​generated by using the Bayesian network, and the complex dependency relationship between the attack stage and the exploitation of vulnerabilities is fully considered, making the threat assessment more scientific and reasonable. The generation of a threat situation analysis diagram realizes the visualization of the network security status, which is convenient for operation and maintenance personnel to grasp the overall situation intuitively. The mechanism of automatically adjusting the feature weights, reconstructing the conditional probability table and synchronizing it to the real-time feature library when the heat exceeds the threshold gives the system good adaptability, and can dynamically optimize the analysis model according to the real-time threat situation, continuously improve the ability and efficiency of network security threat situation analysis, and effectively ensure the safe and stable operation of the network system.

[0089] In one embodiment, the threat probability matrix can be calculated using the following formula:

[0090]

[0091] Among them, T kl represents the elements of the threat probability matrix, represents the joint probability of lateral penetration and data leakage, (a x ,v y ) represents lateral penetration corresponding to attack stage a x and exploit v ycombination, (a z ,v z ) indicates that the data leakage corresponds to attack stage a z and exploit v z k and l represent the row and column indices of the matrix respectively, P(D) represents the probability of abnormal traffic cluster data D appearing, P(a i ,v j ) represents attack phase a i and exploit v j The prior probability of simultaneous occurrence, P(D|a i ,v j ) indicates that in the attack phase a i and exploit v j The probability of abnormal traffic cluster data D occurring at the same time, P(a j ,v j |D) represents attack phase a i and exploit v j The joint probability of simultaneous occurrence, a i represents the i-th attack stage, v j represents the jth vulnerability exploit, and D represents the abnormal traffic cluster data.

[0092] From a data processing perspective, real-time acquisition of traffic segments and updating of the feature library can timely capture dynamic changes in network traffic, improve the sensitivity of perception of abnormal traffic, and thus enhance the accuracy of threat detection. At the threat assessment level, the Bayesian network is combined with the above formula to generate a threat probability matrix, fully considering the complex dependency relationship between the attack phase and vulnerability exploitation, and quantifying various factors into the calculation, making the threat assessment more scientific, accurate and comprehensive. Generating a threat situation analysis diagram realizes the visualization of the network security status, making it easier for operation and maintenance personnel to intuitively grasp the overall situation. The mechanism of automatically adjusting feature weights, reconstructing conditional probability tables and synchronizing them to the real-time feature library when the heat exceeds the threshold gives the system good adaptability, and can dynamically optimize the analysis model according to the real-time threat situation, continuously improving the ability and efficiency of network security threat situation analysis, and effectively ensuring the safe and stable operation of the network system.

[0093] In one embodiment, simulating multi-scenario attack paths using a generative adversarial network algorithm based on a threat situation analysis graph, generating virtual attack data streams, and obtaining defense response results may include the following steps:

[0094] Step S401: Acquire attack path topology data in a threat situation analysis graph.

[0095] Step S402: extract the response feature vector in the attack path topology data to obtain anomaly detection tags and node connection relationships; and associate the anomaly detection tags with rule trigger records in the policy execution log.

[0096] Step S403: construct a multi-protocol traffic behavior pattern based on the node connection relationship and generate a virtual attack data flow carrying a dynamic payload.

[0097] Step S404: input the virtual attack data stream into the dynamic defense strategy to obtain a feature vector including the interception rule identifier and the response delay time.

[0098] Step S405 , according to the interception rule identification, the defense effectiveness parameter in the matching strategy verification matrix is ​​subjected to weighted iterative calculation with the vulnerability exploitation probability to obtain an iterative calculation result.

[0099] Step S406: Update the adversarial sample generator of the generative adversarial network based on the iterative calculation result to generate a defense response result.

[0100] Specifically, the attack path topology data is first obtained from the generated threat situation analysis diagram. Next, the response feature vectors in this data are extracted, successfully separating the anomaly detection markers and node connection relationships. The anomaly detection markers are closely associated with the rule trigger records in the policy execution log. Subsequently, based on the node connection relationships, a traffic behavior pattern covering multiple protocols is constructed, and on this basis, a virtual attack data stream carrying a dynamic payload is generated. This virtual attack data stream is input into a pre-set dynamic defense policy system to obtain a feature vector containing key information such as the interception rule identifier and response delay time. Based on the interception rule identifier, the defense effectiveness parameters are precisely matched in the policy verification matrix and weighted iteratively calculated with the vulnerability exploitation probability to obtain the iterative calculation result. Based on this result, the adversarial sample generator of the generative adversarial network is updated to successfully generate a defense response result.

[0101] Building multi-protocol traffic behavior models and generating virtual attack data streams to simulate real-world complex attack scenarios helps comprehensively test the effectiveness of dynamic defense strategies. The iterative process of calculating defense effectiveness parameters and vulnerability exploitation probability weights continuously optimizes defense strategies and improves response capabilities against various threats. Updating the adversarial sample generator for the Generative Adversarial Network enhances the system's adaptability to unknown attacks, continuously optimizing defense response results, comprehensively improving the reliability and stability of the network security defense system, and providing a solid defense against various complex attacks.

[0102] In one embodiment, Figure 2 As shown in the figure, the defense response results are optimized using a reinforcement learning algorithm to optimize the defense strategy parameters, and a real-time updated threat situation report is generated through multiple rounds of verification using a Monte Carlo tree search algorithm. The following steps can be included:

[0103] Step S501: Obtain defense failure case data in the defense response result; the defense failure case data includes attack path characteristics and strategy parameters.

[0104] Step S502: extract attack path features based on defense failure case data and generate a confrontation path tree.

[0105] Step S503: construct a strategy parameter space based on the adversarial path tree, and iteratively optimize the strategy parameter space using a reinforcement learning algorithm to obtain optimized defense strategy parameters; the strategy parameter space includes defense node weights and response thresholds.

[0106] Step S504: Input the optimized defense strategy parameters into the Monte Carlo tree search algorithm to generate multiple rounds of adversarial path simulation results.

[0107] Step S505 , calculating dynamic evaluation indicators based on the results of multiple rounds of confrontation path simulation and updating the threat situation feature library, where the dynamic evaluation indicators include path coverage and response success rate; and the threat situation feature library includes attack patterns and defense vulnerabilities.

[0108] Step S506: Generate a real-time updated threat situation report based on the threat situation feature library; the threat situation report includes risk levels and defense recommendations.

[0109] First, defense failure case data is filtered from the acquired defense response results. This data contains attack path characteristics and corresponding policy parameters. Based on this defense failure case data, attack path characteristics are further extracted and used as a basis to generate an adversarial path tree. Subsequently, a policy parameter space is constructed around the adversarial path tree, including elements such as defense node weights and response thresholds. Within this space, a reinforcement learning algorithm is used to iteratively optimize, resulting in more refined defense policy parameters. The optimized defense policy parameters are then fed into a Monte Carlo tree search algorithm, and adversarial path simulation results are generated through multiple rounds of simulation. Based on these simulation results, dynamic evaluation metrics such as path coverage and response success rate are calculated, and a threat landscape signature library containing information on attack patterns and defense vulnerabilities is updated. Finally, a real-time threat landscape report is generated based on the threat landscape signature library, clearly indicating the risk level and targeted defense recommendations.

[0110] This embodiment generates an adversarial path tree and constructs a strategy parameter space, providing a clear framework and direction for optimizing defense strategies. The use of reinforcement learning algorithms enables defense strategies to be intelligently adjusted based on actual defense situations, effectively improving the adaptability of defense strategies to various attack scenarios. Multiple rounds of simulation using the Monte Carlo tree search algorithm and the calculation of dynamic evaluation indicators ensure the effectiveness and reliability of the optimized defense strategy in practical applications. Updating the threat situation feature library and generating real-time threat situation reports provide network security operations and maintenance personnel with a comprehensive and timely basis for decision-making.

[0111] In one embodiment, constructing a strategy parameter space based on the adversarial path tree and iteratively optimizing the strategy parameter space using a reinforcement learning algorithm to obtain optimized defense strategy parameters may include the following steps:

[0112] Step S601: Generate an initial distribution matrix of the strategy parameter space based on the node feature set of the adversarial path tree; the initial distribution matrix is ​​used to map the defense weights of different paths.

[0113] Step S602: Perform a gradient update on the initial distribution matrix using a reinforcement learning algorithm to obtain an updated defense parameter vector.

[0114] Step S603: Calculate the generation probability threshold of the adversarial sample for screening high-threat path branches based on the defense parameter vector.

[0115] Step S604: input the generation probability threshold into the policy evaluation model to obtain a policy stability index.

[0116] Among them, if the strategy stability index is lower than the preset threshold, the node feature set of the adversarial path tree is recalculated and the initial distribution matrix is ​​updated.

[0117] Step S605: Adjust the exploration rate of the reinforcement learning algorithm based on the strategy stability index to obtain optimized defense strategy parameters.

[0118] During the defense strategy optimization process based on the adversarial path tree, an initial distribution matrix for the strategy parameter space is first generated based on the node feature set of the adversarial path tree. This initial distribution matrix accurately maps the defense weights of different paths. Next, a reinforcement learning algorithm is used to perform a gradient update on the initial distribution matrix. Through continuous learning and adjustment, an updated defense parameter vector is obtained. Based on this defense parameter vector, a generation probability threshold for adversarial examples is calculated to screen high-threat path branches. This generation probability threshold is then input into a carefully constructed strategy evaluation model, and the strategy stability index is derived through model calculation. During this process, if the strategy stability index falls below a pre-set threshold, the system automatically triggers a recalculation of the node feature set of the adversarial path tree and a corresponding update of the initial distribution matrix. Finally, the exploration rate of the reinforcement learning algorithm is appropriately adjusted based on the strategy stability index. After a series of complex and rigorous calculations and optimizations, the optimized defense strategy parameters are obtained.

[0119] This embodiment maps the defense weights of different paths by generating an initial distribution matrix, so that the defense strategy can be deployed differently according to the characteristics of different attack paths, greatly improving the pertinence of the defense. The gradient update of the initial distribution matrix by the reinforcement learning algorithm can enable the defense strategy to continuously evolve according to the actual situation and effectively adapt to complex and changing attack scenarios. Calculating the generation probability threshold and deriving the stability index through the strategy evaluation model provides a quantitative basis for the optimization of the defense strategy, ensuring that the optimized strategy has high reliability in practical applications. When the stability index does not meet the standard, it is automatically recalculated and updated, and the exploration rate is adjusted according to the index, giving the defense strategy the ability to dynamically optimize, so that it can continuously adapt to emerging threats, and comprehensively enhancing the ability of the network security defense system to deal with various potential attacks.

[0120] In one embodiment, Figure 3 As shown, the present application also provides an AI-based network security system construction and operation and maintenance device, which may include:

[0121] Data processing module 701 is used to obtain multidimensional data streams including network traffic logs, system behavior records and external threat intelligence; extract features from the multidimensional data streams and use algorithms to reduce the dimension to obtain a low-dimensional feature vector set; and is also used to deeply integrate the adaptive clustering algorithm with the preset attack pattern library based on the low-dimensional feature vector set for dynamic correlation matching to obtain clustering model parameters.

[0122] The threat situation analysis module 702 is used to extract new attack features from clustering model parameters and integrate the real-time monitoring network traffic data using the Bayesian network algorithm to generate a threat situation analysis diagram.

[0123] The defense strategy optimization module 703 is used to simulate multi-scenario attack paths based on the threat situation analysis diagram using a generative adversarial network algorithm, generate virtual attack data streams, and obtain defense response results. It is also used to optimize defense strategy parameters based on the defense response results using a reinforcement learning algorithm, and generate a real-time updated threat situation report through multiple rounds of verification using a Monte Carlo tree search algorithm.

[0124] The data processing module of the aforementioned AI-based network security system construction and operation and maintenance device collects multidimensional data streams from multiple channels, including network traffic logs, system behavior records, and external threat intelligence. It applies data mining techniques to comprehensively extract features from this data, then performs dimensionality reduction using efficient algorithms to generate a set of low-dimensional feature vectors. This module then deeply integrates an adaptive clustering algorithm with a pre-set attack pattern library, accurately analyzing the matching degree through a dynamic correlation matching mechanism and outputting clustering model parameters. The threat landscape analysis module extracts new attack signatures from the clustering model parameters while simultaneously monitoring network traffic data in real time. This integration utilizes a Bayesian network algorithm, fully accounting for the complex dependencies between attack phases and vulnerability exploitation, to generate an intuitive and detailed threat landscape analysis diagram that clearly visualizes the current threat landscape facing the network. Based on the threat landscape analysis diagram, the defense strategy optimization module applies a generative adversarial network algorithm to simulate attack paths under various scenarios, generate virtual attack data streams, and obtain corresponding defense response results. Next, the defense strategy parameters are intelligently optimized using a reinforcement learning algorithm. Multiple rounds of verification using a Monte Carlo tree search algorithm ultimately produce a real-time threat landscape report. It can comprehensively and efficiently process complex and diverse network security data, accurately identify new attack characteristics, effectively improve the accuracy and real-time nature of threat situation awareness, and intelligently optimize defense strategies, greatly enhancing the network security system's ability to respond to various complex threats and providing strong support for network security construction and operation and maintenance.

[0125] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0126] In one embodiment, a computer system is provided, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the steps of the aforementioned AI-based network security system construction and operation method, device, system, and medium.

[0127] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0128] As for the system embodiment, since it basically corresponds to the method embodiment, the relevant parts can be referred to the partial description of the method embodiment. The system embodiment described above is only illustrative, wherein the components described as separate parts may or may not be physically separated, and the parts displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the disclosed solution. A person of ordinary skill in the art can understand and implement it without paying any creative work.

[0129] The above-described embodiments merely represent several implementation methods of the embodiments of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the concept of the embodiments of the present application, and these modifications and improvements fall within the scope of protection of the embodiments of the present application.

Claims

1. An AI-based network security system construction and operation method, characterized by: The method comprises: Acquire a multidimensional data stream including network traffic logs, system behavior records, and external threat intelligence; perform feature extraction on the multidimensional data stream and use an algorithm to reduce the dimensionality to obtain a low-dimensional feature vector set; Perform dynamic correlation matching based on the deep fusion adaptive clustering algorithm of the low-dimensional feature vector set and the preset attack pattern library to obtain clustering model parameters; Extracting new attack features from the clustering model parameters and integrating the real-time monitoring network traffic data using a Bayesian network algorithm to generate a threat situation analysis diagram; Based on the threat situation analysis diagram, a generative adversarial network algorithm is used to simulate multi-scenario attack paths, generate virtual attack data streams, and obtain defense response results; The defense response results are optimized using a reinforcement learning algorithm for defense strategy parameters, and a real-time updated threat situation report is generated through multiple rounds of verification using a Monte Carlo tree search algorithm.

2. The method according to claim 1, characterized in that The method of dynamically associating and matching the adaptive clustering algorithm with the preset attack pattern library based on the deep fusion of the low-dimensional feature vector set to obtain clustering model parameters includes: Obtaining a dimensionality reduction distribution result of the low-dimensional feature vector set; the dimensionality reduction distribution result includes weight parameters of multiple feature dimensions; Adjusting the dynamic association threshold of the adaptive clustering algorithm according to the weight parameter; the dynamic association threshold is used to control the matching range between the cluster center and the attack pattern library; Extracting pattern feature labels from the preset attack pattern library, and calculating and constructing a similarity matrix between the dimensionality reduction distribution result and the pattern feature labels; the similarity matrix includes matching scores of different attack patterns; Filtering highly correlated data nodes in the similarity matrix based on the dynamic correlation threshold to form an initial cluster; The center vector of the adaptive clustering algorithm is updated according to the initial cluster cluster to generate dynamically optimized clustering model parameters.

3. The method according to claim 1, characterized in that Extract new attack features from the clustering model parameters and integrate the real-time monitoring network traffic data using the Bayesian network algorithm to generate a threat situation analysis diagram, including: Acquire a traffic segment from the network traffic data monitored in real time; the traffic segment includes a protocol type and a payload length; Generating a feature vector according to the traffic segment and inputting it into a dynamic clustering center, and using an incremental clustering algorithm to update and obtain a real-time feature library; Extracting abnormal traffic clusters from the real-time feature library to obtain abnormal traffic cluster data; the abnormal traffic cluster data corresponds to traffic segments that do not match historical behavior patterns; Inputting the abnormal traffic cluster data into a Bayesian network node to obtain a threat probability matrix; the Bayesian network node contains dependency relationships between attack stages and vulnerability exploitation; the threat probability matrix contains the joint probability of lateral penetration and data leakage; According to the threat probability matrix, the original network topology structure is superimposed using a thermal map to generate a threat situation analysis map; Among them, when the regional heat of the threat situation analysis diagram exceeds a preset threshold, the feature weight adjustment instruction of the dynamic clustering center is triggered, and the conditional probability table of the Bayesian network node is reconstructed according to the feature weight adjustment instruction and the reconstructed conditional probability table is synchronized to the real-time feature library.

4. The method according to claim 3, characterized in that The threat probability matrix is ​​calculated using the following formula: Among them, T kl represents the elements of the threat probability matrix, represents the joint probability of lateral penetration and data leakage, (a x ,v y ) represents lateral penetration corresponding to attack stage a x and exploit v y combination, (a z ,v z ) indicates that the data leakage corresponds to attack stage a z and exploit v z k and l represent the row and column indices of the matrix respectively, P(D) represents the probability of abnormal traffic cluster data D appearing, P(a i ,v j ) represents attack phase a i and exploit v j The prior probability of simultaneous occurrence, P(D|a i ,v j ) indicates that in the attack phase a i and exploit v j The probability of abnormal traffic cluster data D occurring at the same time, P(a j ,v j |D) represents attack phase a i and exploit v j The joint probability of simultaneous occurrence, a i represents the i-th attack stage, v j represents the jth vulnerability exploit, and D represents the abnormal traffic cluster data.

5. The method according to claim 1, wherein The method of simulating multi-scenario attack paths based on the threat situation analysis graph using a generative adversarial network algorithm, generating a virtual attack data stream, and obtaining a defense response result includes: Obtaining attack path topology data in the threat situation analysis diagram; Extracting response feature vectors from the attack path topology data to obtain anomaly detection tags and node connection relationships; associating the anomaly detection tags with rule trigger records in the policy execution log; Building a multi-protocol traffic behavior model based on the node connection relationship and generating a virtual attack data flow carrying a dynamic payload; Inputting the virtual attack data stream into a dynamic defense strategy to obtain a feature vector including an interception rule identifier and a response delay time; According to the interception rule identification matching strategy verification matrix, the defense effectiveness parameter is weighted iteratively calculated with the vulnerability exploitation probability to obtain an iterative calculation result; An adversarial sample generator of the generative adversarial network is updated based on the iterative calculation result to generate a defense response result.

6. The method according to claim 1, characterized in that The defense response results are optimized using a reinforcement learning algorithm for defense strategy parameters, and multiple rounds of verification using a Monte Carlo tree search algorithm are used to generate a real-time updated threat situation report, including: Obtaining defense failure case data in the defense response result; the defense failure case data includes attack path characteristics and strategy parameters; Extract attack path features based on the defense failure case data and generate a confrontation path tree; Constructing a strategy parameter space based on the adversarial path tree, and iteratively optimizing the strategy parameter space using a reinforcement learning algorithm to obtain optimized defense strategy parameters; the strategy parameter space includes defense node weights and response thresholds; Inputting the optimized defense strategy parameters into a Monte Carlo tree search algorithm to generate multiple rounds of adversarial path simulation results; Calculate dynamic evaluation indicators based on the results of the multiple rounds of confrontation path simulation and update the threat situation feature library, wherein the dynamic evaluation indicators include path coverage and response success rate; the threat situation feature library includes attack patterns and defense vulnerabilities; A real-time updated threat situation report is generated based on the threat situation feature library; the threat situation report includes risk levels and defense recommendations.

7. The method according to claim 6, characterized in that The strategy parameter space is constructed based on the adversarial path tree, and the strategy parameter space is iteratively optimized using a reinforcement learning algorithm to obtain optimized defense strategy parameters, including: Generate an initial distribution matrix of the strategy parameter space based on the node feature set of the adversarial path tree; the initial distribution matrix is ​​used to map the defense weights of different paths; Performing a gradient update on the initial distribution matrix using a reinforcement learning algorithm to obtain an updated defense parameter vector; Calculating a generation probability threshold of adversarial samples for screening high-threat path branches based on the defense parameter vector; Inputting the generation probability threshold into a strategy evaluation model to obtain a strategy stability index; If the strategy stability index is lower than a preset threshold, the node feature set of the adversarial path tree is recalculated and the initial distribution matrix is ​​updated; The exploration rate of the reinforcement learning algorithm is adjusted based on the strategy stability index to obtain optimized defense strategy parameters.

8. An AI-based network security system construction and operation and maintenance device, characterized in that: The device comprises: A data processing module is used to obtain multidimensional data streams including network traffic logs, system behavior records, and external threat intelligence; perform feature extraction on the multidimensional data streams and use an algorithm to reduce the dimensionality to obtain a low-dimensional feature vector set; and is also used to deeply integrate the adaptive clustering algorithm with the preset attack pattern library based on the low-dimensional feature vector set for dynamic correlation matching to obtain clustering model parameters; A threat situation analysis module is used to extract new attack features from the clustering model parameters and integrate the real-time monitoring network traffic data using a Bayesian network algorithm to generate a threat situation analysis diagram; The defense strategy optimization module is used to simulate multi-scenario attack paths based on the threat situation analysis diagram using a generative adversarial network algorithm, generate virtual attack data streams and obtain defense response results; it is also used to optimize defense strategy parameters based on the defense response results using a reinforcement learning algorithm, and generate a real-time updated threat situation report through multiple rounds of verification using a Monte Carlo tree search algorithm.

9. A computer system comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Switch and gateway collaborative security method and system based on ship scene

    CN121333824A

  • A ship scene-based switch and gateway cooperative security method and system

    CN121333824B

  • Network security situation awareness method and system based on deep learning

    CN121356921A

  • Bird behavior intention prediction and threat evaluation method based on thermal imaging technology

    CN121437982A

  • Bird behavior intention prediction and threat assessment method based on thermal imaging technology

    CN121437982B