Communication enhancement method and device based on dynamic security
By detecting key information and generating dynamic security policy parameters, the problems of low efficiency and security of inter-process communication in the existing technology are solved, efficient, flexible and reliable security protection is achieved, and the intelligence and security of system communication are improved.
Patent Information
- Application Number
- CN202510607538.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-09-26
AI Technical Summary
Existing inter-process secure communication methods lead to slower system response and low business processing efficiency in scenarios with multiple concurrent processes or tight resources. Traditional detection methods are difficult to ensure system security and have low communication security.
By detecting key information, determining target detection parameters, generating security policy parameters that match the system, and performing communication security enhancement operations based on these parameters, the security policy is dynamically adjusted based on historical data and network environment data.
It improves the intelligence and efficiency of communication, enhances the security and reliability of the system, can effectively prevent external attacks and internal threats, and protect the integrity and confidentiality of system data.
Smart Images

Figure CN120710698A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a communication enhancement method and device based on dynamic security. Background Art
[0002] In modern computer system architectures, secure inter-process communication is a core element for maintaining system stability and ensuring data security. Widely used traditional inter-process secure communication methods, such as the Android system's binder communication mechanism, perform checks on every access. This high-frequency checking consumes significant system resources. In scenarios with multiple concurrent processes or resource constraints, system response speeds are slow, resulting in low business processing efficiency. Furthermore, traditional detection methods rely on fixed, single logic, making it difficult to ensure system security and unable to meet current demands for efficient and intelligent inter-process secure communication detection, resulting in low communication security.
[0003] Therefore, it is particularly important to provide a new communication method to improve the intelligence and efficiency of communication as well as to improve the security and reliability of communication. Summary of the Invention
[0004] The present invention provides a communication enhancement method and device based on dynamic security, which can improve the intelligence and efficiency of communication, and is conducive to improving the security and reliability of communication.
[0005] In order to solve the above technical problems, the first aspect of the present invention discloses a communication enhancement method based on dynamic security, the method comprising:
[0006] Detecting key information and determining target detection parameters based on the key information;
[0007] Based on the target detection parameters, performing a detection operation on the system to be tested to obtain a system detection result, and determining whether the system detection result is used to indicate that a target event has been detected;
[0008] When it is determined that the system detection result indicates that the target event has been detected, generating security policy parameters that match the system to be tested based on the system detection result;
[0009] Based on the security policy parameters, a communication security enhancement operation is performed on the system under test.
[0010] As an optional implementation manner, in the first aspect of the present invention, before performing the communication security enhancement operation on the system under test based on the security policy parameters, the method further includes:
[0011] Acquire historical security data of the system under test, network environment data of the system under test, and application load data of the system under test, and generate comprehensive operation data of the system under test based on the historical security data, the network environment data, and the application load data;
[0012] The security policy parameters are updated according to the comprehensive operation data, and the communication security enhancement operation for the system under test based on the security policy parameters is triggered.
[0013] As an optional implementation manner, in the first aspect of the present invention, before performing a detection operation on the system to be tested based on the target detection parameter and obtaining a system detection result, the method further includes:
[0014] Acquire system key information and user key information of the system to be tested, and generate target key information according to the system key information and the user key information;
[0015] Determining the security level parameters of the system to be tested based on the target key information and a predetermined data prediction model;
[0016] performing an information verification operation on the target key information according to the security level parameter to obtain an information verification result, and determining a dynamic detection strategy for the system to be tested based on the information verification result;
[0017] Based on the dynamic detection strategy, the target detection parameters are updated, and the operation of performing a detection operation on the system to be detected based on the target detection parameters to obtain a system detection result is triggered.
[0018] As an optional implementation manner, in the first aspect of the present invention, determining the target detection parameters based on the key information includes:
[0019] Determine, based on the key information, system target data corresponding to the system under test, wherein the system target data includes one or more of system load data, system activity data, and security event data of the system under test;
[0020] Determining a target factor according to the system target data and a preset target adjustment formula, generating detection interval data of the system to be tested based on the target factor, and determining a target detection parameter based on the detection interval data;
[0021] The target factors include load factor, activity factor, and security event factor.
[0022] As an optional implementation manner, in the first aspect of the present invention, before generating security policy parameters matching the system to be tested based on the system detection result, the method further includes:
[0023] Based on the system detection result, a bidirectional high-speed data channel is constructed, and the acquired system event of the system to be tested is transmitted to a target program based on the bidirectional high-speed data channel, a task processing parameter of the target program is determined, and a detection operation is performed on the system event based on the task processing parameter and the target program to obtain a task detection result;
[0024] The step of generating security policy parameters that match the system to be tested based on the system detection result includes:
[0025] Based on the system detection result and the task detection result, security policy parameters matching the system to be tested are generated.
[0026] As an optional implementation manner, in the first aspect of the present invention, before updating the security policy parameters according to the comprehensive operation data, the method further includes:
[0027] Determining the security configuration information of the system under test based on the comprehensive operation data, and determining the system security level of the system under test according to the security configuration information;
[0028] Generating security profile information of the system to be tested according to the system security level and pre-determined depth detection parameters;
[0029] Wherein, updating the security policy parameters according to the comprehensive operation data includes:
[0030] Update the security policy parameters based on the security portrait information and the comprehensive operation data.
[0031] As an optional implementation manner, in the first aspect of the present invention, generating security profile information of the system to be tested according to the system security level and the predetermined depth detection parameters includes:
[0032] Based on the system security level and the predetermined depth detection parameters, performing a depth detection operation on the system to be tested to obtain a depth detection result;
[0033] Based on the deep detection results, generate security profile information of the system to be tested;
[0034] The deep detection operation includes one or more of a legality verification detection operation, an authority audit detection operation, and a behavior analysis detection operation.
[0035] A second aspect of the present invention discloses a communication enhancement device based on dynamic security, the device comprising:
[0036] Detection module, used to detect key information;
[0037] A determination module, configured to determine target detection parameters based on the key information;
[0038] The detection module is further configured to perform a detection operation on the system to be tested based on the target detection parameters to obtain a system detection result;
[0039] A determination module, configured to determine whether the system detection result indicates that a target event has been detected;
[0040] a generating module configured to generate security policy parameters matching the system to be tested based on the system detection result when the judging module determines that the system detection result indicates that the target event has been detected;
[0041] An execution module is used to perform a communication security enhancement operation on the system to be tested based on the security policy parameters.
[0042] As an optional embodiment, in the second aspect of the present invention, the device further includes:
[0043] an acquisition module, configured to acquire historical security data of the system under test, network environment data of the system under test, and application load data of the system under test before the execution module performs a communication security enhancement operation on the system under test based on the security policy parameters;
[0044] The generating module is further configured to generate comprehensive operating data of the system under test based on the historical security data, the network environment data, and the application load data;
[0045] An updating module is used to update the security policy parameters according to the comprehensive operation data, and trigger the execution module to execute the communication security enhancement operation on the system under test based on the security policy parameters.
[0046] As an optional embodiment, in the second aspect of the present invention, the acquisition module is further configured to obtain key system information and key user information of the system to be tested before the detection module performs a detection operation on the system to be tested based on the target detection parameters and obtains a system detection result;
[0047] The generating module is further configured to generate target key information based on the system key information and the user key information;
[0048] The determination module is further configured to determine the security level parameters of the system to be tested based on the target key information and a predetermined data prediction model;
[0049] The device further comprises:
[0050] A verification module, configured to perform an information verification operation on the target key information according to the security level parameter to obtain an information verification result;
[0051] The determination module is further configured to determine a dynamic detection strategy for the system to be tested based on the information verification result;
[0052] The update module is further configured to update the target detection parameters based on the dynamic detection strategy, and trigger the detection module to execute the detection operation on the system to be detected based on the target detection parameters to obtain the system detection result.
[0053] As an optional implementation manner, in the second aspect of the present invention, the specific manner in which the determination module determines the target detection parameters based on the key information includes:
[0054] Determine, based on the key information, system target data corresponding to the system under test, wherein the system target data includes one or more of system load data, system activity data, and security event data of the system under test;
[0055] Determining a target factor according to the system target data and a preset target adjustment formula, generating detection interval data of the system to be tested based on the target factor, and determining a target detection parameter based on the detection interval data;
[0056] The target factors include load factor, activity factor, and security event factor.
[0057] As an optional embodiment, in the second aspect of the present invention, the device further includes:
[0058] a construction module, configured to construct a bidirectional high-speed data channel based on the system detection result before the generation module generates security policy parameters matching the system to be tested based on the system detection result;
[0059] The determination module is further configured to transmit the acquired system events of the system under test to a target program based on the bidirectional high-speed data channel, and determine task processing parameters of the target program;
[0060] The detection module is further configured to perform a detection operation on the system event based on the task processing parameters and the target program to obtain a task detection result;
[0061] The specific manner in which the generation module generates security policy parameters that match the system to be tested based on the system detection result includes:
[0062] Based on the system detection result and the task detection result, security policy parameters matching the system to be tested are generated.
[0063] As an optional implementation, in the second aspect of the present invention, the determining module is further configured to, before the updating module updates the security policy parameters according to the comprehensive operation data, determine security configuration information of the system under test based on the comprehensive operation data, and determine the system security level of the system under test according to the security configuration information;
[0064] The generating module is further configured to generate security profile information of the system to be tested according to the system security level and the predetermined depth detection parameters;
[0065] The specific manner in which the updating module updates the security policy parameters according to the comprehensive operation data includes:
[0066] Update the security policy parameters based on the security portrait information and the comprehensive operation data.
[0067] As an optional embodiment, in the second aspect of the present invention, the specific manner in which the generation module generates the security profile information of the system to be tested according to the system security level and the predetermined depth detection parameters includes:
[0068] Based on the system security level and the predetermined depth detection parameters, performing a depth detection operation on the system to be tested to obtain a depth detection result;
[0069] Based on the deep detection results, generate security profile information of the system to be tested;
[0070] The deep detection operation includes one or more of a legality verification detection operation, an authority audit detection operation, and a behavior analysis detection operation.
[0071] A third aspect of the present invention discloses another communication enhancement device based on dynamic security, the device comprising:
[0072] a memory storing executable program code;
[0073] a processor coupled to the memory;
[0074] The processor calls the executable program code stored in the memory to execute the communication enhancement method based on dynamic security disclosed in the first aspect of the present invention.
[0075] A fourth aspect of the present invention discloses a computer storage medium storing computer instructions. When the computer instructions are called, they are used to execute the communication enhancement method based on dynamic security disclosed in the first aspect of the present invention.
[0076] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:
[0077] In an embodiment of the present invention, key information is detected, and target detection parameters are determined based on the key information. Based on the target detection parameters, a detection operation is performed on the system under test to obtain a system detection result, and a determination is made as to whether the system detection result indicates the detection of a target event. When the system detection result is determined to indicate the detection of a target event, security policy parameters matching the system under test are generated based on the system detection result. Based on the security policy parameters, a communication security enhancement operation is performed on the system under test. It can be seen that the implementation of the present invention can improve the intelligence and efficiency of communication, as well as the reliability of communication, thereby improving the security of system communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0079] Figure 1 This is a flow chart of a communication enhancement method based on dynamic security disclosed in an embodiment of the present invention;
[0080] Figure 2 This is a flow chart of another communication enhancement method based on dynamic security disclosed in an embodiment of the present invention;
[0081] Figure 3 This is a schematic structural diagram of a communication enhancement device based on dynamic security disclosed in an embodiment of the present invention;
[0082] Figure 4 1 is a schematic structural diagram of another communication enhancement device based on dynamic security disclosed in an embodiment of the present invention;
[0083] Figure 5 This is a structural diagram of another communication enhancement device based on dynamic security disclosed in an embodiment of the present invention. DETAILED DESCRIPTION
[0084] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0085] The terms "first," "second," and so on, in the description and claims of the present invention and the accompanying drawings are used to distinguish between different items, not to describe a specific order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or end comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed therein, or may optionally include other steps or elements inherent to such process, method, product, or end.
[0086] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0087] The present invention discloses a communication enhancement method and device based on dynamic security, which can improve the intelligence and efficiency of communication, as well as the reliability of communication, thereby improving the security of system communication. Detailed descriptions are given below.
[0088] Example 1
[0089] See also Figure 1 , Figure 1 This is a flow chart of a communication enhancement method based on dynamic security disclosed in an embodiment of the present invention. Figure 1 The communication enhancement method based on dynamic security described above can be applied to a communication enhancement device based on dynamic security, wherein the communication enhancement device based on dynamic security can be integrated into a local server or a cloud server, which is not limited in the embodiment of the present invention. Figure 1 As shown, the communication enhancement method based on dynamic security may include the following operations:
[0090] 101. Detect key information and determine target detection parameters based on the key information.
[0091] In an embodiment of the present invention, optionally, the key information may include one or more of process identification information, permission information, behavioral characteristic information, and communication information; wherein the process identification information includes a process identifier (PID), a user identifier (UID), and a process group identifier (GID), wherein the process identifier (PID) is used to uniquely identify the identity of the process, the user identifier (UID) is used to identify the user or permission group to which the process belongs, and the process group identifier (GID) is used to identify the group to which the process belongs; the permission information includes the permission level of the process and the access control list (ACL) of the process, wherein the permission level of the process includes the root permission level or the ordinary user level, and the access control list (ACL) of the process is a mechanism for controlling access to process resources; the behavioral characteristic information includes the start time, path and source of the process, and the historical behavior data of the process, wherein the historical behavior data of the process includes the communication frequency and data volume of the process; the communication information includes the identification information of the communication target process as well as the communication protocol and port information.
[0092] In an embodiment of the present invention, optionally, the target detection parameter may include a detection interval parameter, wherein the detection interval parameter may include the interval duration for detecting the system to be tested. For example, the detection interval parameter may be 3 seconds or 5 seconds, and the embodiment of the present invention does not make specific limitations.
[0093] 102. Based on the target detection parameters, perform a detection operation on the system to be tested, obtain a system detection result, and determine whether the system detection result is used to indicate that the target event is detected.
[0094] In the embodiment of the present invention, optionally, the target detection parameters may further include one or more of a detection mode parameter, a detection time parameter, a detection duration parameter, and a detection interval parameter for the system to be detected.
[0095] In an embodiment of the present invention, optionally, the target event may include process communication-related events, permission change-related events, and system exception-related events; wherein, process communication-related events may include transaction request events; permission change-related events may include user permission change events and process permission information change events; and system exception-related events may include process abnormal termination events.
[0096] 103. When it is determined that the system detection result indicates that the target event has been detected, security policy parameters matching the system to be tested are generated based on the system detection result.
[0097] In the embodiment of the present invention, optionally, generating security policy parameters that match the system to be tested based on the system detection results may include:
[0098] Based on the system detection result, the security level of the system to be tested is determined, and according to the security level of the system to be tested, security policy parameters matching the system to be tested are determined from a predetermined policy parameter set.
[0099] In the embodiment of the present invention, further optionally, when it is determined that the system detection result indicates that the target event is not detected, the process may be terminated.
[0100] 104. Based on the security policy parameters, perform communication security enhancement operations on the system under test.
[0101] In the embodiment of the present invention, optionally, performing the communication security enhancement operation on the system under test based on the security policy parameters may include:
[0102] Based on the security policy parameters, the pre-set policy logic of the target program is called to perform communication security enhancement operations on the process of the system under test;
[0103] Among them, the pre-set target program includes the eBPF program.
[0104] In the embodiment of the present invention, optionally, an eBPF program (Extended Berkeley Packet Filter) is a program that can run efficiently in the kernel and is a core component for implementing process security communication detection.
[0105] It can be seen that implementation Figure 1The communication enhancement method based on dynamic security described can detect key information and determine target detection parameters, perform detection operations on the system to be tested based on the target detection parameters to obtain system detection results and judge whether the system detection results are used to indicate that a target event has been detected, and if so, generate matching security policy parameters based on the system detection results and then perform communication security enhancement operations on the system to be tested, which can accurately locate the parts of the system to be tested that need to be focused on by detecting key information and determining target detection parameters based on this information, thereby improving detection efficiency, and accurately identifying whether a target event has been detected by judging the system detection results, thereby ensuring the reliability of the detection results, and dynamically generating matching security policy parameters for the system to be tested based on the detected target event. The security policy parameters of the system are generated, and the security policy can be adjusted according to the actual operating status and potential threats of the system through dynamic adaptability, which is beneficial to improving the dynamic adaptability and security protection capabilities of the system under test. Communication security enhancement operations are performed on the system based on the generated security policy parameters, which can help improve the reliability and security of system communications, and can effectively prevent external attacks and internal threats, protect the integrity and confidentiality of system data, and improve the overall security protection level of the system. Through precise detection, dynamic policy generation and targeted security enhancement operations, efficient, flexible and reliable security protection is achieved, which can help improve the intelligence and efficiency of communications, as well as improve the reliability of communications, and thus help improve the security of system communications.
[0106] Example 2
[0107] See also Figure 2 , Figure 2 This is a flow chart of another communication enhancement method based on dynamic security disclosed in an embodiment of the present invention. Figure 2 The communication enhancement method based on dynamic security described above can be applied to a communication enhancement device based on dynamic security, wherein the communication enhancement device based on dynamic security can be integrated into a local server or a cloud server, which is not limited in the embodiment of the present invention. Figure 2 As shown, the communication enhancement method based on dynamic security may include the following operations:
[0108] 201. Detect key information and determine target detection parameters based on the key information.
[0109] 202. Based on the target detection parameters, perform a detection operation on the system to be tested, obtain a system detection result, and determine whether the system detection result is used to indicate that the target event is detected.
[0110] 203. When it is determined that the system detection result indicates that the target event has been detected, security policy parameters matching the system to be tested are generated based on the system detection result.
[0111] 204. Obtain historical security data of the system under test, network environment data of the system under test, and application load data of the system under test, and generate comprehensive operation data of the system under test based on the historical security data, network environment data, and application load data.
[0112] In an embodiment of the present invention, optionally, the historical security data of the system to be tested may include security event records, security detection results, and user operation logs of the system to be tested within a preset historical time period; the network environment data of the system to be tested may include network type data, IP reputation data, and connection encryption status data of the system to be tested, wherein the network type data may include whether the system to be tested is a wifi network or a cellular network; the application load data of the system to be tested may include the application currently running on the system to be tested and its resource occupancy data, wherein the resource occupancy data may include CPU occupancy data, memory occupancy data, and network bandwidth data.
[0113] In an embodiment of the present invention, optionally, generating the comprehensive operating data of the system under test based on the historical security data, network environment data, and application load data may include:
[0114] Target operation data are extracted from historical security data, network environment data and application load data respectively, and comprehensive operation data of the system under test is generated based on all the extracted target operation data, wherein the target operation data includes the type and frequency of security events of the system under test, the current network type of the system under test, and the application load data includes the application resource occupancy rate of the system under test; the comprehensive operation data at least includes all target operation data.
[0115] 205. Update security policy parameters based on comprehensive operation data.
[0116] In the embodiment of the present invention, optionally, updating the security policy parameters according to the comprehensive operation data may include:
[0117] Analyze key security events in the comprehensive operation data, as well as the current network type in the comprehensive operation data, and determine security protection parameters based on the key security events and the current network type;
[0118] Update security policy parameters based on security protection parameters.
[0119] In an embodiment of the present invention, optionally, for example, key security events may include security events whose frequency of occurrence is higher than the historical average frequency; security protection parameters may include protection strength parameters, such as the scanning frequency of the intrusion detection system for relevant security event characteristics; further, if the occurrence frequency of key security events is high, the scanning frequency of the intrusion detection system for relevant security event characteristics is increased.
[0120] 206. Based on the security policy parameters, perform communication security enhancement operations on the system under test.
[0121] In the embodiment of the present invention, for detailed descriptions of steps 201 to 203 and step 207, please refer to other descriptions of steps 101 to 104 in the first embodiment, and the embodiment of the present invention will not be repeated.
[0122] It can be seen that implementation Figure 2 The described communication enhancement method based on dynamic security can obtain historical security data, network environment data and application load data of the system under test and generate comprehensive operation data, determine the security configuration information of the system under test based on the comprehensive operation data and then determine the system security level of the system under test, generate security portrait information of the system under test based on the system security level and deep detection parameters and then update the security policy parameters, can generate comprehensive operation data by obtaining historical security data, network environment data and application load data of the system under test, can fully understand the operation status of the system from multiple dimensions, provide a solid data foundation for determining the security configuration information and security level of the system through multi-faceted data synthesis, which is conducive to improving the accuracy and reliability of the security configuration information of the system under test, and It can determine the security configuration information and security level based on the comprehensive operation data, and then generate security portrait information based on the deep detection parameters to update the security policy parameters, so that the security policy can be dynamically adjusted according to the actual situation of the system, and the deep detection frequency and intensity can be adjusted in time, which is conducive to further improving the security and reliability of the detection of the system under test, thereby improving the security and reliability of the operation of the system under test. In addition, through the security portrait information, it can gain a deeper understanding of the potential security issues and vulnerabilities of the system. Based on the information, the security policy parameters can be updated, which can enhance the system's anti-attack capabilities in a targeted manner and reduce the probability of security incidents, thereby improving the intelligence and efficiency of communications, as well as improving the reliability of communications, and thus improving the security of system communications.
[0123] In an optional embodiment, before performing a detection operation on the system to be tested based on the target detection parameters and obtaining a system detection result, the method further includes:
[0124] Obtain system key information and user key information of the system to be tested, and generate target key information based on the system key information and user key information;
[0125] Determine the safety level parameters of the system under test based on the target key information and the pre-determined data prediction model;
[0126] According to the security level parameters, perform information verification operations on the target key information, obtain information verification results, and determine the dynamic detection strategy of the system to be tested based on the information verification results;
[0127] Based on the dynamic detection strategy, the target detection parameters are updated, and the operation of performing detection operations on the system to be tested based on the target detection parameters is triggered to obtain the system detection results.
[0128] In this optional embodiment, optionally, the system key information of the system to be tested includes one or more of the process identification information, permission information, behavioral characteristic data, historical behavioral data, and communication information of the system to be tested, wherein the process identification information includes a process identifier (PID), which is used to uniquely identify the process; a user identifier (UID) and a process group identifier (GID), which clearly identify the user and group to which the process belongs; permission information, including the permission level of the process (such as root, ordinary user) and the access control list (ACL) of the process; behavioral characteristic data including the start time, path and source of the process; the historical behavioral data of the process including the communication frequency and data volume; and communication information including the identification information of the target process (such as the target PID), the communication protocol and port information.
[0129] In this optional embodiment, optionally, the user key information includes the user's identity authentication information, wherein the identity authentication information includes the user name, password hash value, multi-factor authentication information (such as fingerprint, SMS verification code); further, the user key information may also include the user's operation history information, wherein the user's operation history information includes login time, operation behavior (such as file access, process startup), etc.
[0130] In this optional embodiment, the target key information may optionally include a fusion of system key information and user key information. Furthermore, the target key information includes integrated identity information, which associates the process's PID, UID, and GID with the user's identity authentication information to form a complete identity. The fused permission information comprehensively considers the process permissions and user permissions to determine the final permission scope. The combined behavior information combines the process's behavioral characteristics with the user's operation history to comprehensively analyze the behavior pattern. And the summarized communication information summarizes the process communication information and the user's relevant operation information during the communication process to evaluate the communication security.
[0131] In this optional embodiment, optionally, the above-mentioned determination of the security level parameters of the system to be tested based on the target key information and the predetermined data prediction model may include:
[0132] Based on the target key information and the predetermined data prediction model, the process security level of the system under test is predicted, and based on the predefined rules of the predetermined data prediction model, a security scoring operation is performed on the process security level of the system under test to obtain a security scoring result corresponding to the process security level of the system under test;
[0133] Based on the dynamic weighting algorithm predetermined herein and the security scoring result corresponding to the process security level of the system to be tested, the security level parameters of the system to be tested are determined.
[0134] In this optional embodiment, optionally, performing an information verification operation on target key information according to the security level parameter to obtain an information verification result, and determining a dynamic detection strategy for the system to be tested based on the information verification result may include:
[0135] Determining an encryption verification algorithm that matches the security level parameter according to the security level parameter, and performing an information verification operation on the target key information based on the encryption verification algorithm to obtain an information verification result, wherein the encryption verification algorithm includes a chaotic encryption algorithm;
[0136] Based on the information verification result and the security level parameters, a dynamic detection strategy that matches the system to be tested is determined from a predetermined strategy library.
[0137] In this optional embodiment, optionally, the chaotic encryption algorithm is an encryption technology based on chaos theory, the core idea of which is to use the randomness, complexity and sensitivity to initial conditions of the chaotic system to protect the security of data; further, the chaotic encryption algorithm uses the chaotic sequence generated by the chaotic system as a key sequence to encrypt and decrypt data.
[0138] In this optional embodiment, optionally, updating the target detection parameters based on the dynamic detection strategy may include:
[0139] Based on the dynamic strategy parameters and the target detection parameters, a parameter to be adjusted in the target detection parameters that matches the dynamic strategy parameters is determined, and an update operation is performed on the parameter to be adjusted in the target detection parameters based on the dynamic strategy parameters to update the target detection parameters.
[0140] In this optional embodiment, further optionally, the above method may further include:
[0141] Detect whether there are changes in the security level parameters of the system under test;
[0142] When it is determined that the security level parameter of the system under test has changed, an update operation is performed on the dynamic detection strategy of the system under test according to the changed security level parameter of the system under test, so that the updated dynamic detection strategy of the system under test matches the changed security level parameter of the system under test;
[0143] When it is determined that the security level parameters of the system under test do not change, this process can be ended.
[0144] It can be seen that the implementation of this optional embodiment can obtain the system key information and user key information of the system to be tested and generate target key information, determine the security level parameters of the system to be tested in combination with a predetermined data prediction model and perform information verification operations on the target key information, obtain information verification results and determine the dynamic detection strategy of the system to be tested, update the target detection parameters based on the dynamic detection strategy and trigger the execution of the operation of performing detection operations on the system to be tested based on the target detection parameters to obtain system detection results, and comprehensively understand the operating status and security situation of the system from multiple dimensions, and combine the system key information and user key information to improve the comprehensiveness of the generated target key information, and thus to improve the accuracy and reliability of the generated target key information, and determine the security level parameters based on the target key information and the predetermined data prediction model, which is conducive to improving the accuracy and reliability of the generated target key information. It can determine the accuracy and reliability of security level parameters, and perform information verification operations on target key information according to the security level parameters. It can adopt different verification strengths and methods for different security levels, which is beneficial to improving the efficiency and intelligence of testing the system under test. It can also perform information verification operations on target key information according to the security level parameters. It can adopt different verification strengths and methods for different security levels, so that the detection operation is more targeted and efficient. By accurately assessing the security status of the system, realizing dynamic and flexible detection strategies, and improving detection efficiency and resource utilization, it can effectively reduce the security risks of the system, which is beneficial to improving the security and reliability of the system under test, and then it can be beneficial to improve the intelligence and efficiency of communication, as well as improve the reliability of communication, and then it is beneficial to improve the security of system communication.
[0145] In another optional embodiment, determining target detection parameters based on key information includes:
[0146] Determine the system target data corresponding to the system under test based on the key information, wherein the system target data includes one or more of system load data, system activity data, and security event data of the system under test;
[0147] Determine the target factor according to the system target data and the preset target adjustment formula, generate the detection interval data of the system to be tested based on the target factor, and determine the target detection parameter based on the detection interval data;
[0148] Among them, the target factors include load factor, activity factor, and security event factor.
[0149] In this optional embodiment, optionally, the system load data of the system to be tested may include CPU usage data and memory occupancy data of the system to be tested; the system activity data may include communication frequency data and data volume data of the system to be tested; and the security event data may include abnormality detection count data.
[0150] In this optional embodiment, the preset target adjustment formulas may optionally include a load factor adjustment formula, an activity factor adjustment formula, and a security event factor adjustment formula, wherein:
[0151] The load factor adjustment formula includes:
[0152] F_load=1-(α*L_cpu+β*L_mem);
[0153] Among them, L_cpu and L_mem are CPU and memory load rates respectively, α and β are adjustment coefficients, and F_load is the load factor;
[0154] The activity factor adjustment formula includes:
[0155] F_activity = 1 + γ * C;
[0156] Among them, C is the communication frequency, γ is the adjustment coefficient, and F_activity is the activity factor;
[0157] The security event factor adjustment formula includes:
[0158] F_security = 1 + δ * N;
[0159] Where N is the number of anomaly detections, and δ is the adjustment coefficient;
[0160] Furthermore, the load factor is used to adjust the interval according to the CPU and memory load rates, the activity factor is used to adjust the interval according to the process communication frequency, and the security event factor is used to adjust the interval according to the number of anomaly detections.
[0161] In this optional embodiment, optionally, the generating of the detection interval data of the system to be tested based on the target factor may include:
[0162] Determine a detection interval adjustment parameter based on all target factors and a preset interval calculation formula, and generate detection interval data for the system under test based on the detection interval adjustment parameter and a preset basic detection interval;
[0163] The preset interval calculation formulas include:
[0164] T=T_base*F_load*F_activity*F_security;
[0165] Wherein, T is the detection interval adjustment parameter of the system to be tested.
[0166] In this optional embodiment, optionally, for example, if the detection interval adjustment parameter determined based on all target factors is 5 seconds, and the pre-set basic detection interval is 10 seconds, then the detection interval parameter of the system to be tested is 5 seconds, that is, the detection operation is performed on the system to be tested every 5 seconds.
[0167] In this optional embodiment, the target detection parameter optionally matches the detection interval data; that is, the detection interval corresponding to the target detection parameter is the detection interval corresponding to the detection interval data.
[0168] It can be seen that the implementation of this optional embodiment can determine the system target data corresponding to the system under test based on the key information, determine the target factor based on the system target data and the preset target adjustment formula, generate the detection interval data of the system under test, and then determine the target detection parameters. The system target data including system load data, activity data, security event data, etc. can be determined based on the key information, which can comprehensively reflect the real-time operating status of the system under test, which is conducive to improving the accuracy and reliability of the subsequent determination of the target factor and the determination of the target detection parameters. In addition, the target factor is determined based on the system target data and the preset target adjustment formula, and the detection interval data is generated, and the target detection parameters are determined, thereby achieving dynamic optimization of the detection frequency. The target detection parameters can also be reasonably determined, which is conducive to improving resource utilization efficiency and intelligence. The detection parameters are dynamically determined based on the actual system operation data, which can timely detect system anomalies and security risks. When a sudden security incident occurs or the operating state changes in the system, the detection interval is quickly adjusted, and abnormal behavior and potential threats are quickly detected. This is conducive to improving the intelligence and efficiency of the detection of the system under test, thereby improving the intelligence and efficiency of communication, as well as improving the reliability of communication, and thus improving the security of system communication.
[0169] In yet another optional embodiment, before generating security policy parameters matching the system to be tested based on the system detection results, the method further includes:
[0170] Based on the system detection results, a bidirectional high-speed data channel is constructed, and the obtained system events of the system to be tested are transmitted to the target program based on the bidirectional high-speed data channel, task processing parameters of the target program are determined, and based on the task processing parameters and the target program, a detection operation is performed on the system events to obtain the task detection results;
[0171] Based on the system detection results, security policy parameters that match the system under test are generated, including:
[0172] Based on the system detection results and task detection results, generate security policy parameters that match the system to be tested.
[0173] In this optional embodiment, optionally, the above-mentioned construction of a bidirectional high-speed data channel based on the system detection result may include:
[0174] Based on the system detection results, the underlying network communication interface is called, the transmission protocol is selected according to the network environment and system resources, the network port and cache space are allocated for initialization, and the channel parameters are dynamically configured according to the data flow and type in the system detection results to generate a bidirectional high-speed data channel;
[0175] Among them, the bidirectional high-speed data channel architecture includes the user layer to the kernel layer and the kernel layer to the user layer. The user layer to the kernel layer realizes data transmission through the bpf system call and eBPF map, and the kernel layer to the user layer realizes real-time push of events and data through the perf buffer or ring buffer.
[0176] In this optional embodiment, shared data storage and access between the user layer and the kernel layer can be implemented through eBPF maps, and kernel events can be efficiently transmitted to the user layer through perf / ring buffers. This reduces the overhead of copying data between the user layer and the kernel layer through zero-copy technology, and improves transmission efficiency by batching multiple data or events.
[0177] In this optional embodiment, optionally, the above-mentioned transmitting the acquired system events of the system under test to the target program based on the bidirectional high-speed data channel may include:
[0178] Structurally encapsulate the acquired system events of the system under test, and add metadata such as event identifiers, priority tags, and timestamps;
[0179] The encapsulated system events are transmitted to the target program via the established bidirectional high-speed data channel; wherein the encapsulated system events are transmitted to the target program by means of data compression and packet transmission;
[0180] Among them, the target program is the eBPF program.
[0181] In this optional embodiment, optionally, the task processing parameters of the target program may include one or more of the computing resources, algorithm resources and processing priorities corresponding to the target program; wherein the computing resources include the number of CPU cores of the system to be tested and the memory capacity of the system to be tested, the algorithm resources include intrusion detection algorithms and process behavior analysis algorithms, and the processing priority includes the importance corresponding to each task.
[0182] In this optional embodiment, optionally, performing a detection operation on a system event based on the task processing parameters and the target program to obtain a task detection result may include:
[0183] The target program generates task distribution parameters corresponding to each task based on the determined task processing parameters, and performs a detection operation on the system event based on each task distribution parameter and each task to obtain a task detection result.
[0184] In this optional embodiment, optionally, the task distribution parameters corresponding to each task can be distributed in an execution order according to the importance of the tasks, and the task distribution can be dynamically adjusted according to the system load; further, the user layer instructions are passed to the kernel layer eBPF program through the bpf() system call; the kernel layer events are fed back to the user layer through the perf buffer or ringbuffer; the user layer processes the events fed back by the kernel layer through the thread pool or asynchronous I / O, and the kernel layer dynamically allocates detection tasks through the eBPF scheduler.
[0185] In this optional embodiment, optionally, generating security policy parameters matching the system to be tested based on the system detection results and the task detection results may include:
[0186] Correlate and integrate system detection results with task detection results, compare data differences between the two, and explore potential security risks; generate a rule base based on preset security policies, and combine the current system security level, user-defined policy preferences and other conditions to generate security policy parameters including access control policy parameters, process control parameters, and data protection parameters;
[0187] Among them, access control policy parameters may include port opening rules, IP blacklist and whitelist, process control parameters may include process termination conditions, resource limit thresholds, and data protection parameters may include encryption methods and backup frequency.
[0188] In this optional embodiment, optionally, for example, when the system event of the system to be tested is obtained and passed to the eBPF program, the eBPF program distributes detection tasks according to the security level and policy type after receiving the system event, wherein the detection task includes one or more of data verification, behavior analysis and permission check, generates an event queue based on all detection tasks, and dynamically allocates detection tasks based on event type and priority to perform detection operations on system events to obtain task detection results.
[0189] It can be seen that the implementation of this optional embodiment can build a bidirectional high-speed data channel based on the system detection results and transmit the obtained system events of the system to be tested to the target program, determine the task processing parameters of the target program to perform detection operations on the system events to obtain task detection results, and generate security policy parameters matching the system to be tested based on the system detection results and the task detection results. The target program can perform in-depth analysis of the system events of the system to be tested based on the task processing parameters, which is conducive to improving the accuracy and reliability of the detection of the system to be tested, as well as improving the security and reliability of the system to be tested. The security policy parameters are jointly generated based on the system detection results and the task detection results, which can make the generated security policy more in line with the actual security status of the system, achieve precise protection, and help improve the security and reliability of the system to be tested, thereby helping to improve the intelligence and efficiency of communication, as well as help improve the reliability of communication, and thus help improve the security of system communication.
[0190] In yet another optional embodiment, before updating the security policy parameters according to the comprehensive operation data, the method further includes:
[0191] Determining security configuration information of the system under test based on the comprehensive operation data, and determining a system security level of the system under test according to the security configuration information;
[0192] Generating security profile information of the system to be tested according to the system security level and pre-determined depth detection parameters;
[0193] Wherein, updating the security policy parameters according to the comprehensive operation data includes:
[0194] Update the security policy parameters based on the security portrait information and the comprehensive operation data.
[0195] In this optional embodiment, optionally, the above-mentioned determination of the security configuration information of the system to be tested based on the comprehensive operating data may include: determining the calculation weights based on the comprehensive operating data, and determining the security configuration information of the system to be tested based on the calculation weights; wherein the calculation weights include the weights corresponding to the historical security data, the weights corresponding to the network environment data, and the weights corresponding to the application load data. For example, the recommendation level is calculated based on the weights of the historical security data, the network environment, and the application load. For example: the weight of historical high-risk events is 50%, the weight of the network environment is 30%, and the weight of the application load is 20%.
[0196] In this optional embodiment, optionally, the above-mentioned determination of the system security level of the system to be tested based on the security configuration information may include: determining the risk coefficient and the frequency of historical security events of the system to be tested based on the security configuration information, and determining the system security level of the system to be tested based on the risk coefficient and the frequency of historical security events of the system to be tested. For example, the security level is divided into three levels: high, medium, and low, wherein the high level is for a high-risk network environment and frequent historical security events; the medium level is for a medium-risk network environment and fewer historical security events; and the low level is for a low-risk network environment and no historical security events, wherein the risk coefficient corresponding to the high-risk network environment is higher, and the risk coefficient corresponding to the low-risk network environment is lower.
[0197] In this optional embodiment, the predetermined depth detection parameter may optionally include a frequency of performing a depth detection operation on the system to be tested.
[0198] In this optional embodiment, updating the security policy parameters based on the security profile information and the comprehensive operation data includes:
[0199] Extract key feature information from the security profile information, perform feature analysis on the key feature information based on a predetermined target processing model, and obtain feature analysis results;
[0200] Determine the system risk parameters and load prediction parameters of the system under test based on the characteristic analysis results, and determine the target risk parameters of the system under test based on the system risk parameters and load prediction parameters;
[0201] Based on the target risk parameters and comprehensive operation data, key risk data is generated, and risk update parameters matching the key risk data are determined in a predetermined policy parameter library, and an update operation is performed on the security policy parameters based on the risk update parameters.
[0202] In this optional embodiment, optionally, the security portrait information may include process metadata, system resource status information, and security policy configuration information, wherein the process metadata may include process ID, process name, parent process information, permission level, and communication protocol; the system resource status information may include CPU usage, memory occupancy, and network bandwidth; and the security policy configuration information may include the current security level, user-customized parameters, and historical detection results.
[0203] In this optional embodiment, optionally, the key feature information may include extracting key features from metadata, resource status, and policy configuration, and the key feature information may include abnormal process authority data and excessive resource usage data.
[0204] In this optional embodiment, optionally, the predetermined target processing model may include a classification model or a regression model, wherein the classification model may include a random forest model or a support vector machine model, wherein the random forest model is a machine learning algorithm based on ensemble learning (Ensemble Learning), which consists of multiple decision trees and makes the final decision by integrating the prediction results of these decision trees. The support vector machine model (Support Vector Machine, SVM) is a supervised machine learning algorithm that is widely used in classification and regression problems; the regression model may include a linear regression model.
[0205] In this optional embodiment, optionally, performing a feature analysis operation on the key feature information based on the predetermined target processing model to obtain a feature analysis result may include:
[0206] The key feature information is input into a predetermined target processing model to perform feature analysis operations on the key feature information through the target processing model to obtain feature analysis results, wherein the feature analysis results may include the process risk level of the system to be tested and the prediction results of the impact of the system load on the detection strategy.
[0207] In this optional embodiment, the process risk level of the system under test optionally includes a system risk parameter of the system under test, and the prediction result of the impact of the system load on the detection strategy includes a load prediction parameter of the system under test. Furthermore, the target risk parameter includes at least the system risk parameter and the load prediction parameter.
[0208] In this optional embodiment, optionally, the key risk data includes at least target risk parameters and comprehensive operating data.
[0209] In this optional embodiment, optionally, determining risk update parameters that match the key risk data in a predetermined policy parameter library, and performing an update operation on the security policy parameters based on the risk update parameters, can include: determining the detection frequency of the system to be tested based on the key risk data, and determining risk update parameters that match the key risk data in a predetermined policy parameter library based on the detection frequency of the system to be tested. For example, based on the risk level and load prediction results, the optimal detection strategy is selected from the policy library. If the risk level is high, the first mandatory detection and high-frequency random detection are selected; if the risk level is medium, the first mandatory detection and medium-frequency random detection are selected; if the risk level is low, the first mandatory detection and low-frequency random detection are selected.
[0210] In this optional embodiment, optionally, the detection frequency corresponding to the updated security policy parameter is the same as the detection frequency corresponding to the risk update parameter.
[0211] It can be seen that the implementation of this optional embodiment can determine the security configuration information of the system to be tested based on the comprehensive operation data, and determine the system security level of the system to be tested according to the security configuration information, generate security portrait information according to the system security level and deep detection parameters, and update the security policy parameters according to the security portrait information and the comprehensive operation data. It can more accurately identify security threats through deep analysis, make the update of security policy parameters more targeted, and help improve the pertinence, accuracy and reliability of generating security policy parameters, and obtain target risk parameters by determining system risk parameters and load prediction parameters. It fully considers the dynamic changes of system security risks and resource loads, combines load prediction parameters with system risk parameters, and comprehensively determines target risk parameters, which is conducive to improving the accuracy and reliability of determining target risk parameters. It uses a pre-built policy parameter library to quickly match risk update parameters according to target risk parameters, which is conducive to improving the accuracy and reliability of generating risk update parameters, as well as improving the intelligence and efficiency of generating risk update parameters, thereby helping to improve the intelligence and efficiency of communication, as well as helping to improve the reliability of communication, and thus helping to improve the security of system communication.
[0212] In another optional embodiment, generating security profile information of the system to be tested based on the system security level and predetermined depth detection parameters includes:
[0213] Based on the system security level and pre-determined depth detection parameters, a depth detection operation is performed on the system to be tested to obtain a depth detection result;
[0214] Generate security profile information of the system under test based on the deep detection results;
[0215] Among them, the deep detection operation includes one or more of the following: legality verification detection operation, authority audit detection operation, and behavior analysis detection operation.
[0216] In this optional embodiment, further optionally, before generating security profile information of the system to be tested based on the system security level and the predetermined depth detection parameters, the method further includes:
[0217] Obtaining real-time system information of the system to be tested, generating target calculation parameters based on the real-time system information and a pseudo-random number generator, and determining whether the target calculation parameters meet the preset depth detection conditions;
[0218] When it is determined that the target calculation parameters meet the preset deep detection conditions, the operation of generating security profile information of the system to be tested based on the system security level and the pre-determined deep detection parameters is triggered;
[0219] When it is determined that the target calculation parameters do not meet the preset deep detection conditions, it directly triggers the execution of communication security enhancement operations based on the security policy parameters on the system under test;
[0220] Among them, the real-time system information includes the current timestamp and process ID of the system to be tested; the target calculation parameter is a random number generated by a pseudo-random number generator; further, a pseudo-random number generator (PRNG) is an algorithm or device that can generate a digital sequence that appears random but is actually based on a deterministic algorithm and an initial value (seed). The pseudo-random number generator is usually based on a mathematical algorithm and takes an initial seed value as input. This seed value can be a specific number, timestamp or other deterministic information. The algorithm generates a digital sequence based on the seed value through a series of calculations and transformations. Given the same seed, the algorithm will always generate the same digital sequence.
[0221] In this optional embodiment, further optionally, when the operating status of the system to be tested changes, the real-time status of the system to be tested can be obtained based on deep detection, and the security portrait is updated based on the real-time status of the system to be tested.
[0222] In this optional embodiment, the predetermined depth detection parameters may optionally include depth detection frequency parameters that are dynamically adjusted based on the system load and communication frequency, further reducing the detection frequency when the load is high and increasing the detection frequency when the load is low.
[0223] In this optional embodiment, optionally, the legitimacy verification detection operation may include checking the process signature and source credibility, the permission audit detection operation may include verifying whether the permissions of the process match the communication behavior, and the behavior analysis detection operation may include analyzing whether the communication mode of the process is abnormal.
[0224] In this optional embodiment, optionally, the security portrait information of the system to be tested may include one or more of the system security information, vulnerability and threat information, and behavior and risk assessment information of the system to be tested; wherein, the system security information includes key identification information of the system, such as the operating system version, kernel version, main installed software and its version number; vulnerability and threat information includes various types of vulnerabilities existing in the system, including software vulnerabilities, system configuration vulnerabilities, and network protocol vulnerabilities; behavior and risk assessment information includes analyzing the behavior of processes within the system, recording normal behavior patterns and abnormal behavior signs.
[0225] It can be seen that the implementation of this optional embodiment can perform a deep detection operation on the system to be tested based on the system security level and the predetermined deep detection parameters to obtain a deep detection result, and generate security portrait information of the system to be tested based on the deep detection result. It can adopt a variety of deep detection operations such as legitimacy verification detection, authority audit detection and behavior analysis detection, and can review the system from different angles. Through multi-dimensional deep detection, potential security risks in the system can be more accurately discovered, which is conducive to improving the overall security and reliability of the system to be tested. In addition, deep detection is performed according to the system security level to make the detection more targeted. It can also better adapt to the security requirements of different systems through targeted detection methods, ensure that the system security status is accurately assessed, and is conducive to improving the intelligence and efficiency of system detection. The security portrait information generated by the deep detection results can comprehensively and accurately reflect the security situation of the system to be tested, and dynamic security management can be achieved through dynamically updated portraits, which is conducive to further ensuring the security and reliability of the system to be tested, thereby being conducive to improving the intelligence and efficiency of communication, as well as improving the reliability of communication, and thus helping to improve the security of system communication.
[0226] Example 3
[0227] See also Figure 3 , Figure 3 This is a schematic diagram of the structure of a communication enhancement device based on dynamic security disclosed in an embodiment of the present invention. Figure 3 As shown, the communication enhancement device based on dynamic security may include:
[0228] Detection module 301, used to detect key information;
[0229] A determination module 302 is configured to determine target detection parameters based on the key information;
[0230] The detection module 301 is further configured to perform a detection operation on the system to be tested based on the target detection parameters to obtain a system detection result;
[0231] A determination module 303 is used to determine whether the system detection result indicates that a target event has been detected;
[0232] The generating module 304 is configured to generate security policy parameters that match the system to be tested based on the system detection result when the judging module 303 judges that the system detection result indicates that the target event has been detected;
[0233] The execution module 305 is used to perform a communication security enhancement operation on the system under test based on the security policy parameters.
[0234] It can be seen that implementation Figure 3The described device can detect key information and determine target detection parameters, perform detection operations on the system to be tested based on the target detection parameters to obtain system detection results and judge whether the system detection results are used to indicate that a target event has been detected, and if so, generate matching security policy parameters based on the system detection results and then perform communication security enhancement operations on the system to be tested. By detecting key information and determining target detection parameters based on this information, it is possible to accurately locate the parts of the system to be tested that require focus, which is conducive to improving detection efficiency, and by judging the system detection results, it is possible to accurately identify whether a target event has been detected, thereby ensuring the reliability of the detection results, and by dynamically generating security policy parameters that match the system to be tested based on the detected target event. Through dynamic adaptability, the security policy can be adjusted according to the actual operating status and potential threats of the system, which is beneficial to improving the dynamic adaptability and security protection capabilities of the system under test. Based on the generated security policy parameters, the system performs communication security enhancement operations, which can help improve the reliability and security of system communications, and can effectively prevent external attacks and internal threats, protect the integrity and confidentiality of system data, and improve the overall security protection level of the system. Through precise detection, dynamic policy generation and targeted security enhancement operations, efficient, flexible and reliable security protection is achieved, which can help improve the intelligence and efficiency of communications, as well as improve the reliability of communications, and thus help improve the security of system communications.
[0235] In an optional embodiment, if Figure 4 As shown, the device also includes:
[0236] An acquisition module 306 is configured to acquire historical security data of the system under test, network environment data of the system under test, and application load data of the system under test before the execution module 305 performs a communication security enhancement operation on the system under test based on the security policy parameters;
[0237] The generation module 304 is further configured to generate comprehensive operating data of the system under test based on historical security data, network environment data, and application load data;
[0238] The determination module 302 is further configured to determine the security configuration information of the system under test based on the comprehensive operation data, and determine the system security level of the system under test according to the security configuration information;
[0239] The generating module 304 is further configured to generate security profile information of the system to be tested based on the system security level and the predetermined depth detection parameters;
[0240] The updating module 307 is used to update the security policy parameters based on the security profile information, and trigger the execution module 305 to execute the communication security enhancement operation on the system under test based on the security policy parameters.
[0241] It can be seen that implementation Figure 4 The described device can obtain historical security data, network environment data and application load data of the system to be tested and generate comprehensive operation data, determine the security configuration information of the system to be tested based on the comprehensive operation data and then determine the system security level of the system to be tested, generate security portrait information of the system to be tested based on the system security level and deep detection parameters and then update the security policy parameters, can generate comprehensive operation data by obtaining historical security data, network environment data and application load data of the system to be tested, can fully understand the operation status of the system from multiple dimensions, provide a solid data foundation for determining the security configuration information and security level of the system through multi-faceted data synthesis, which is conducive to improving the accuracy and reliability of the security configuration information of the system to be tested, and can be based on comprehensive The operating data determines the security configuration information and security level, and then combines the deep detection parameters to generate security portrait information, thereby updating the security policy parameters so that the security policy can be dynamically adjusted according to the actual situation of the system, and the deep detection frequency and intensity can be adjusted in time, which is conducive to further improving the security and reliability of the detection of the system under test, thereby improving the security and reliability of the operation of the system under test. In addition, through the security portrait information, we can have a deeper understanding of the potential security issues and vulnerabilities of the system. Based on the information, we can update the security policy parameters, enhance the system's anti-attack capabilities in a targeted manner, reduce the probability of security incidents, and thus improve the intelligence and efficiency of communications, as well as improve the reliability of communications, and thus improve the security of system communications.
[0242] In another optional embodiment, as Figure 4 As shown, the acquisition module 306 is further used to obtain key system information and user key information of the system to be tested before the detection module 301 performs a detection operation on the system to be tested based on the target detection parameters and obtains the system detection result;
[0243] The generating module 304 is further configured to generate target key information based on the system key information and the user key information;
[0244] The determination module 302 is further configured to determine the security level parameters of the system to be tested based on the target key information and the predetermined data prediction model;
[0245] The device also includes:
[0246] Verification module 308, used to perform information verification operation on target key information according to security level parameters to obtain information verification results;
[0247] The determination module 302 is further configured to determine a dynamic detection strategy for the system under test based on the information verification result;
[0248] The updating module 307 is further configured to update the target detection parameters based on the dynamic detection strategy, and trigger the detection module 301 to perform a detection operation on the system to be detected based on the target detection parameters to obtain a system detection result.
[0249] It can be seen that implementation Figure 4 The described device can obtain system key information and user key information of the system to be tested and generate target key information, determine the security level parameters of the system to be tested in combination with a predetermined data prediction model and perform information verification operations on the target key information, obtain information verification results and determine the dynamic detection strategy of the system to be tested, update the target detection parameters based on the dynamic detection strategy and trigger the execution of the operation of performing detection operations on the system to be tested based on the target detection parameters to obtain system detection results, and can fully understand the operating status and security situation of the system from multiple dimensions, and combine the system key information and user key information to improve the comprehensiveness of the generated target key information, thereby improving the accuracy and reliability of the generated target key information, and determining the security level parameters based on the target key information and the predetermined data prediction model is conducive to improving the determination of security The accuracy and reliability of the level parameters, as well as the information verification operations performed on the target key information according to the security level parameters, can adopt different verification strengths and methods for different security levels, which is conducive to improving the efficiency and intelligence of the detection of the system to be tested. It can also perform information verification operations on the target key information according to the security level parameters, and can adopt different verification strengths and methods for different security levels, so that the detection operation is more targeted and efficient. By accurately assessing the system security status, implementing dynamic and flexible detection strategies, and improving detection efficiency and resource utilization, it can effectively reduce the security risks of the system, which is conducive to improving the security and reliability of the system to be tested, and then it can be conducive to improving the intelligence and efficiency of communication, as well as improving the reliability of communication, and then it is conducive to improving the security of system communication.
[0250] In another optional embodiment, Figure 4 As shown, the specific manner in which the determination module 302 determines the target detection parameters based on the key information includes:
[0251] Determine the system target data corresponding to the system under test based on the key information, wherein the system target data includes one or more of system load data, system activity data, and security event data of the system under test;
[0252] Determine the target factor according to the system target data and the preset target adjustment formula, generate the detection interval data of the system to be tested based on the target factor, and determine the target detection parameter based on the detection interval data;
[0253] Among them, the target factors include load factor, activity factor, and security event factor.
[0254] It can be seen that implementation Figure 4 The described device can determine system target data corresponding to the system under test based on key information, determine target factors based on the system target data and a preset target adjustment formula, generate detection interval data for the system under test, and then determine target detection parameters. The device can determine system target data, including system load data, activity data, and security event data, based on the key information. This fully reflects the real-time operating status of the system under test, thereby improving the accuracy and reliability of subsequent determination of target factors and target detection parameters. Furthermore, by determining the target factors based on the system target data and a preset target adjustment formula, generating detection interval data, and then determining target detection parameters, the device achieves dynamic optimization of detection frequency and can rationally determine target detection parameters, thereby improving resource utilization efficiency and intelligence. Dynamically determining detection parameters based on actual system operating data enables timely detection of system anomalies and security risks. When a sudden security incident occurs or the system's operating status changes, the detection interval is rapidly adjusted, allowing for rapid detection of abnormal behavior and potential threats. This improves the intelligence and efficiency of detection of the system under test, thereby improving the intelligence and efficiency of communication, as well as the reliability of communication, and thus the security of system communication.
[0255] In another optional embodiment, Figure 4 As shown, the device also includes:
[0256] A construction module 309 is configured to construct a bidirectional high-speed data channel based on the system detection results before the generation module 304 generates security policy parameters that match the system to be tested based on the system detection results;
[0257] The determination module 302 is further configured to transmit the acquired system events of the system under test to the target program based on a bidirectional high-speed data channel, and determine the task processing parameters of the target program;
[0258] The detection module 301 is further configured to perform a detection operation on the system event based on the task processing parameters and the target program to obtain a task detection result;
[0259] The specific manner in which the generation module 304 generates security policy parameters that match the system to be tested based on the system detection results includes:
[0260] Based on the system detection results and task detection results, generate security policy parameters that match the system to be tested.
[0261] It can be seen that implementation Figure 4The described device can build a bidirectional high-speed data channel based on the system detection results and transmit the acquired system events of the system to be tested to the target program, determine the task processing parameters of the target program, perform detection operations on the system events to obtain task detection results, generate security policy parameters matching the system to be tested based on the system detection results and the task detection results, and can perform in-depth analysis of the system events of the system to be tested based on the task processing parameters through the target program, which is conducive to improving the accuracy and reliability of the detection of the system to be tested, as well as improving the security and reliability of the system to be tested, and jointly generating security policy parameters based on the system detection results and the task detection results, which can make the generated security policy more in line with the actual security status of the system, realize accurate protection, and be conducive to improving the security and reliability of the system to be tested, thereby being conducive to improving the intelligence and efficiency of communication, as well as improving the reliability of communication, and further conducive to improving the security of system communication.
[0262] In another optional embodiment, Figure 4 As shown, the determining module 302 is further configured to determine the security configuration information of the system under test based on the comprehensive operation data before the updating module 307 updates the security policy parameters according to the comprehensive operation data, and determine the system security level of the system under test according to the security configuration information;
[0263] The generating module 304 is further configured to generate security profile information of the system to be tested according to the system security level and the predetermined depth detection parameters;
[0264] The specific manner in which the updating module 307 updates the security policy parameters according to the comprehensive operation data includes:
[0265] Update the security policy parameters based on the security portrait information and the comprehensive operation data.
[0266] It can be seen that implementation Figure 4The described device can determine the security configuration information of the system to be tested based on comprehensive operation data, and determine the system security level of the system to be tested based on the security configuration information, generate security portrait information based on the system security level and deep detection parameters, and update security policy parameters based on the security portrait information and comprehensive operation data. It can more accurately identify security threats through deep analysis, making the update of security policy parameters more targeted, which is conducive to improving the targeting, accuracy and reliability of generating security policy parameters, and obtain target risk parameters by determining system risk parameters and load prediction parameters. It fully considers the dynamic changes of system security risks and resource loads, combines load prediction parameters with system risk parameters, and comprehensively determines target risk parameters, which is conducive to improving the accuracy and reliability of determining target risk parameters. It uses a pre-built policy parameter library to quickly match risk update parameters according to target risk parameters, which is conducive to improving the accuracy and reliability of generating risk update parameters, as well as improving the intelligence and efficiency of generating risk update parameters, thereby being conducive to improving the intelligence and efficiency of communication, as well as improving the reliability of communication, and thus helping to improve the security of system communication.
[0267] In another optional embodiment, Figure 4 As shown, the specific manner in which the generation module 304 generates the security profile information of the system to be tested according to the system security level and the pre-determined depth detection parameters includes:
[0268] Based on the system security level and pre-determined depth detection parameters, a depth detection operation is performed on the system to be tested to obtain a depth detection result;
[0269] Generate security profile information of the system under test based on the deep detection results;
[0270] Among them, the deep detection operation includes one or more of the following: legality verification detection operation, authority audit detection operation, and behavior analysis detection operation.
[0271] It can be seen that implementation Figure 4The described device can perform a deep detection operation on the system under test based on the system security level and predetermined deep detection parameters to obtain a deep detection result, and generate security profile information of the system under test based on the deep detection result. It can use multiple deep detection operations such as legality verification detection, authority audit detection and behavior analysis detection to review the system from different angles. Through multi-dimensional deep detection, potential security risks in the system can be more accurately discovered, which is conducive to improving the overall security and reliability of the system under test. In addition, deep detection is performed according to the system security level to make the detection more targeted. It can also better adapt to the security requirements of different systems through targeted detection methods, ensure that the system security status is accurately assessed, and is conducive to improving the intelligence and efficiency of system detection. The security profile information generated by the deep detection results can comprehensively and accurately reflect the security situation of the system under test, and dynamic security management can be achieved through dynamically updated profiles, which is conducive to further ensuring the security and reliability of the system under test, thereby being conducive to improving the intelligence and efficiency of communication, as well as improving the reliability of communication, and further conducive to improving the security of system communication.
[0272] Example 4
[0273] See also Figure 5 , Figure 5 This is a structural diagram of another communication enhancement device based on dynamic security disclosed in an embodiment of the present invention. Figure 5 As shown, the communication enhancement device based on dynamic security may include:
[0274] A memory 401 storing executable program code;
[0275] a processor 402 coupled to the memory 401;
[0276] The processor 402 calls the executable program code stored in the memory 401 to execute the steps of the communication enhancement method based on dynamic security described in the first embodiment of the present invention or the second embodiment of the present invention.
[0277] Example 5
[0278] An embodiment of the present invention discloses a computer storage medium storing computer instructions. When the computer instructions are called, they are used to execute the steps of the communication enhancement device method based on dynamic security described in the first embodiment or the second embodiment of the present invention.
[0279] Example 6
[0280] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps of the communication enhancement method based on dynamic security described in Example 1 or Example 2.
[0281] The device embodiments described above are merely illustrative, wherein the modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, i.e., they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Those skilled in the art can understand and implement the present invention without inventive effort.
[0282] Through the detailed description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus the necessary general hardware platform, or of course, by means of hardware. Based on this understanding, the above technical solution, in essence, or the portion that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, including a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electronically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.
[0283] Finally, it should be noted that the communication enhancement method and device based on dynamic security disclosed in the embodiments of the present invention are only preferred embodiments of the present invention, and are only used to illustrate the technical solutions of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments can still be modified, or some of the technical features therein can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A communication enhancement method based on dynamic security, characterized in that: The method comprises: Detecting key information and determining target detection parameters based on the key information; Based on the target detection parameters, performing a detection operation on the system to be tested to obtain a system detection result, and determining whether the system detection result is used to indicate that a target event has been detected; When it is determined that the system detection result indicates that the target event has been detected, generating security policy parameters that match the system to be tested based on the system detection result; Based on the security policy parameters, a communication security enhancement operation is performed on the system under test.
2. The communication enhancement method based on dynamic security according to claim 1, characterized in that: Before performing the communication security enhancement operation on the system under test based on the security policy parameters, the method further includes: Acquire historical security data of the system under test, network environment data of the system under test, and application load data of the system under test, and generate comprehensive operation data of the system under test based on the historical security data, the network environment data, and the application load data; The security policy parameters are updated according to the comprehensive operation data, and the communication security enhancement operation for the system under test based on the security policy parameters is triggered.
3. The communication enhancement method based on dynamic security according to claim 1, characterized in that: Before performing a detection operation on the system to be tested based on the target detection parameters and obtaining a system detection result, the method further includes: Acquire system key information and user key information of the system to be tested, and generate target key information according to the system key information and the user key information; Determining the security level parameters of the system to be tested based on the target key information and a predetermined data prediction model; performing an information verification operation on the target key information according to the security level parameter to obtain an information verification result, and determining a dynamic detection strategy for the system to be tested based on the information verification result; Based on the dynamic detection strategy, the target detection parameters are updated, and the operation of performing a detection operation on the system to be detected based on the target detection parameters to obtain a system detection result is triggered.
4. The communication enhancement method based on dynamic security according to claim 1, characterized in that: Determining target detection parameters based on the key information includes: Determine, based on the key information, system target data corresponding to the system under test, wherein the system target data includes one or more of system load data, system activity data, and security event data of the system under test; Determining a target factor according to the system target data and a preset target adjustment formula, generating detection interval data of the system to be tested based on the target factor, and determining a target detection parameter based on the detection interval data; The target factors include load factor, activity factor, and security event factor.
5. The communication enhancement method based on dynamic security according to claim 1, characterized in that: Before generating security policy parameters matching the system to be tested based on the system detection result, the method further includes: Based on the system detection result, a bidirectional high-speed data channel is constructed, and the acquired system event of the system to be tested is transmitted to a target program based on the bidirectional high-speed data channel, a task processing parameter of the target program is determined, and a detection operation is performed on the system event based on the task processing parameter and the target program to obtain a task detection result; The step of generating security policy parameters that match the system to be tested based on the system detection result includes: Based on the system detection result and the task detection result, security policy parameters matching the system to be tested are generated.
6. The communication enhancement method based on dynamic security according to claim 2, characterized in that: Before updating the security policy parameters according to the comprehensive operation data, the method further includes: Determining security configuration information of the system under test based on the comprehensive operation data, and determining a system security level of the system under test according to the security configuration information; Generating security profile information of the system to be tested according to the system security level and pre-determined depth detection parameters; Wherein, updating the security policy parameters according to the comprehensive operation data includes: Update the security policy parameters based on the security portrait information and the comprehensive operation data.
7. The communication enhancement method based on dynamic security according to claim 6, characterized in that: Generating security profile information of the system to be tested according to the system security level and predetermined depth detection parameters includes: Based on the system security level and the predetermined depth detection parameters, performing a depth detection operation on the system to be tested to obtain a depth detection result; Based on the deep detection results, generate security profile information of the system to be tested; The deep detection operation includes one or more of a legality verification detection operation, an authority audit detection operation, and a behavior analysis detection operation.
8. A communication enhancement device based on dynamic security, characterized in that: The device comprises: Detection module, used to detect key information; A determination module, configured to determine target detection parameters based on the key information; The detection module is further configured to perform a detection operation on the system to be tested based on the target detection parameters to obtain a system detection result; A determination module, configured to determine whether the system detection result indicates that a target event has been detected; a generating module configured to generate security policy parameters matching the system to be tested based on the system detection result when the judging module determines that the system detection result indicates that the target event has been detected; An execution module is used to perform a communication security enhancement operation on the system to be tested based on the security policy parameters.
9. A communication enhancement device based on dynamic security, characterized in that: The device comprises: a memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the communication enhancement method based on dynamic security as described in any one of claims 1-7.
10. A computer storage medium, characterized in that The computer storage medium stores computer instructions, which, when called, are used to execute the communication enhancement method based on dynamic security as described in any one of claims 1 to 7.
Citation Information
Patent Citations
File descriptor leakage detection method and device
CN112732640A
Method and system for identifying data ransomware based on process behavior
CN119227063A
Memory horse detection method and device, electronic equipment and readable medium
CN119337375A
Application behavioral fingerprints
US11256802B1