A method, server, media, and product for responding to cybersecurity incidents in a campus.
By dividing the park into cybersecurity collaboration zones and setting up security incident response nodes, and using risk propagation models to analyze the probability of risk infection, rapid linkage response and reliable data storage within the park were achieved. This solved the problem of rapid propagation and spread of cybersecurity incidents within the park, and improved overall protection efficiency and data reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2026-03-13
AI Technical Summary
The varying levels of cybersecurity capabilities among companies within the park, coupled with a lack of timely and effective security coordination mechanisms, have led to the rapid spread and proliferation of cybersecurity incidents, making timely responses difficult.
Based on the physical location information and network topology of enterprise nodes, the park is divided into multiple network security collaboration areas. The enterprise node with the highest consensus weight is identified as the security incident response node. The risk propagation model is used to analyze the probability of risk infection, send security protection instructions and store the processing records in the blockchain database to achieve regional security collaborative protection.
It improved the overall security efficiency of the park, reduced the risk of security incidents spreading, ensured the credibility and integrity of data, and encouraged enterprises to improve their security protection level.
Smart Images

Figure CN120825332B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security, and in particular to a method, server, media and product for responding to network security incidents in a campus. Background Technology
[0002] With the rapid development of the Industrial Internet, the level of network interconnection among enterprises within the park is constantly improving, and the business and production systems of each enterprise are showing a high degree of interdependence. Against this backdrop, a cybersecurity incident occurring in one enterprise within the park can spread rapidly through network connections, causing a chain reaction and posing a serious challenge to the overall cybersecurity protection of the park.
[0003] Currently, the park's network security protection primarily employs a network boundary-based security approach. This involves deploying security devices such as firewalls and intrusion detection systems at the park's network boundary to monitor and filter network traffic entering and leaving the park. Simultaneously, each enterprise also deploys its own internal security equipment to provide independent security protection for its own operations.
[0004] However, due to the varying security capabilities of companies within the park and the lack of a timely and effective security coordination mechanism among them, when one company suffers a cyberattack, other companies often find it difficult to obtain threat information and respond in a timely manner. Summary of the Invention
[0005] This application provides a method, server, media, and product for responding to cybersecurity incidents in a campus, which can improve the overall security protection efficiency of the campus and reduce the risk of the spread of security incidents.
[0006] Firstly, this application provides a method for responding to network security incidents in a campus, applied to a server. The method includes: dividing the campus into multiple network security collaboration zones based on the physical location information and network topology of enterprise nodes within the campus; determining the enterprise node with the highest consensus weight within each network security collaboration zone as the security incident response node; each network security collaboration zone includes multiple enterprise nodes, and there is a one-to-one correspondence between the network security collaboration zone and the security incident response node; the consensus weight is determined based on the security protection score and historical reputation score of the enterprise node; after receiving security alarm information sent by the enterprise node that is the source of the security incident, extracting the attack type identifier, asset type identifier, and hazard level identifier from the security alarm information to generate security incident features; the enterprise node that is the source of the security incident is used to represent the enterprise node where the security incident occurred; the security alarm information is used to notify the enterprise node that the security incident has occurred; and the security incident features are used to represent... The system displays the characteristic information of security information; it queries the pre-set risk propagation model library to find risk propagation models that match the characteristics of security events, and calculates the risk infection probability of each network security collaboration area based on the risk propagation model, the physical location information of the security event source enterprise node and the enterprise nodes in the park, and the network topology relationship. The pre-set risk propagation model library is used to represent the propagation rules and impact range of different types of security events; it identifies network security collaboration areas with risk infection probabilities exceeding a pre-set probability threshold as affected areas, and sends security protection instructions to the security event response nodes in the affected areas. The security protection instructions are used to prompt protection against security events; it receives execution status data and processing result data fed back by the security event response nodes, generates security event processing records, and stores the security event processing records in the park's main blockchain database. The security event processing records include processing timestamps, execution status codes, and result evaluation values.
[0007] By adopting the above technical solution, the server divides the park into multiple network security collaboration zones based on the physical location information and network topology of enterprise nodes, and designates the enterprise node with the highest consensus weight as the security incident response node, thus achieving regionalized collaborative security protection. When a security incident occurs, the server can quickly extract the characteristics of the security incident and use a risk propagation model to analyze the risk of infection in each network security collaboration zone, thereby accurately identifying the affected area. The server sends security protection commands to the security incident response nodes in the affected area, enabling rapid coordinated response. Simultaneously, the security incident processing records are stored in the park's main blockchain database, ensuring the trustworthiness and integrity of the data. This regional collaborative response mechanism significantly improves the overall security protection efficiency of the park and reduces the risk of security incident spread.
[0008] In conjunction with some embodiments of the first aspect, in some embodiments, based on the physical location information and network topology of enterprise nodes within the park, the park is divided into multiple network security collaboration zones. Specifically, this includes: determining the physical proximity and network connection density between enterprise nodes based on the physical location information and network topology of each enterprise node within the park, so as to calculate the comprehensive distance value between enterprise nodes; after determining the enterprise node pair with the smallest comprehensive distance value as the initial collaboration zone, the unassigned enterprise nodes are traversed sequentially; when the comprehensive distance value between the unassigned enterprise node and the initial collaboration zone is less than a preset distance threshold, the unassigned enterprise node is assigned to the initial collaboration zone, thus obtaining the network security collaboration zone.
[0009] By adopting the above technical solution, when dividing network security collaboration zones, the server introduces two dimensions: physical proximity and network connectivity density. The initial collaboration zone is determined by calculating the comprehensive distance between enterprise nodes. Then, unassigned enterprise nodes are traversed, and their comprehensive distance to the initial collaboration zone is compared. Enterprise nodes with closer distances are included in the same network security collaboration zone. This division method fully considers the dual correlation between physical and cyberspace, resulting in stronger internal correlation and synergy among the divided network security collaboration zones, which is conducive to improving the collaborative effect of security protection within the zone.
[0010] In conjunction with some embodiments of the first aspect, in some embodiments, based on the risk propagation model, the physical location information and network topology of the enterprise nodes at the source of the security incident and the enterprise nodes within the park, the probability of risk infection in each network security collaboration area is calculated. Specifically, this includes: establishing a two-dimensional coordinate system based on the physical location information of the enterprise nodes at the source of the security incident, and calculating the physical distance between each enterprise node and the enterprise node at the source of the security incident; constructing a network connection graph based on the network topology, and calculating the network hop count between each enterprise node and the enterprise node at the source of the security incident; substituting the physical distance and the network hop count into the distance decay function and network decay function of the risk propagation model, respectively, to obtain the physical risk exposure and network risk exposure of each enterprise node; and determining the probability of risk infection in the network security collaboration area based on the physical risk exposure and network risk exposure of each enterprise node within the network security collaboration area.
[0011] By employing the above technical solution, the server determines the physical distance and network hop count between enterprise nodes based on physical location information and network topology. It then extracts the distance decay function and network decay function from the risk propagation model to obtain the physical and network risk exposure of each enterprise node. Based on these two dimensions of exposure, the server comprehensively calculates the probability of infection in the network security collaboration area. This multi-dimensional risk assessment method can more accurately predict the propagation trend of security incidents, providing a more reliable basis for protection decisions.
[0012] In conjunction with some embodiments of the first aspect, in some embodiments, sending security protection instructions to security event response nodes within the affected area specifically includes: retrieving corresponding security protection strategy combinations from a preset security protection strategy library based on security event characteristics; determining corresponding security protection strategies from the security protection strategy combinations based on the risk infection probability of the affected area; converting the security protection strategies into security protection instructions, and sequentially sending them to security event response nodes within the affected area.
[0013] By adopting the above technical solution, the server employs a layered filtering strategy when issuing security protection commands: First, based on the characteristics of the security event, it retrieves matching combinations of security protection strategies from a pre-set security protection strategy library. Then, it selects the most suitable security protection strategy based on the risk of infection in the affected area. Finally, it converts the security protection strategy into specific security protection commands and issues them to the security event response nodes. This layered filtering mechanism ensures the accuracy and targeting of protection measures, avoiding "one-size-fits-all" protection measures. Simultaneously, the pre-set security protection strategy library allows for the rapid invocation of verified and effective protection schemes, improving response efficiency and reducing the possibility of decision-making errors.
[0014] In conjunction with some embodiments of the first aspect, in some embodiments, after the step of sending security protection instructions to security event response nodes within the affected area, the method further includes: monitoring the execution of security protection instructions by security event response nodes; and when the execution shows an abnormality, resending security protection instructions to security event response nodes.
[0015] By adopting the above technical solution, a monitoring mechanism for the execution of security protection commands is added. This closed-loop monitoring mechanism can promptly identify problems during the execution process and make rapid adjustments, ensuring that the protective measures can play a truly effective role. It also provides important feedback data for subsequent optimization of protection strategies, helping to continuously improve the protection effect.
[0016] In conjunction with some embodiments of the first aspect, in some embodiments, after receiving execution status data and processing result data fed back by the security incident response node, generating a security incident processing record, and storing the security incident processing record in the park's main blockchain database, the method further includes: periodically retrieving security incident processing records from the park's main blockchain database, the security incident processing records including alarm information, response time, and processing results of enterprise nodes; calculating alarm accuracy based on alarm information, timely response rate based on response time, and effective processing rate based on processing results; determining the security contribution of enterprise nodes based on alarm accuracy, timely response rate, and effective processing rate; and weighting the security contribution and historical reputation score to obtain the updated reputation score of enterprise nodes.
[0017] By adopting the above technical solution, a comprehensive enterprise reputation evaluation mechanism has been established. The server periodically analyzes security event handling records in the park's main blockchain database, evaluating the security contribution of enterprise nodes from three dimensions: alarm accuracy, response timeliness, and processing effectiveness. This security contribution is then weighted and calculated with historical reputation scores to obtain the updated reputation score for each enterprise node. This dynamic evaluation mechanism not only objectively reflects the enterprise's security protection capabilities and collaborative performance but also incentivizes enterprises to continuously improve their security protection levels.
[0018] In conjunction with some embodiments of the first aspect, in some embodiments, after the step of weighting the security contribution and historical reputation score to obtain the updated reputation score of the enterprise node, the method further includes: statistically analyzing the frequency of security events, the distribution of security event types, and the propagation path of security events in each network security collaboration area within a preset time window to determine the risk coefficient of each network security collaboration area; calculating the average reputation score of the network security collaboration area based on the reputation score of each enterprise node in the network security collaboration area; determining the area adjustment coefficient based on the risk coefficient and the average reputation score; and triggering the area re-division process if the area adjustment coefficient is greater than a preset adjustment threshold.
[0019] By adopting the above technical solution, a dynamic adjustment mechanism for network security collaboration zones is introduced. The server statistically analyzes security event-related indicators within a preset time window and, combined with the average reputation score of enterprise nodes within the zone, calculates a zone adjustment coefficient. When the zone adjustment coefficient exceeds a preset adjustment threshold, a zone re-division is triggered, ensuring dynamic optimization of the collaboration zone division. This data-driven dynamic adjustment mechanism allows the division of network security collaboration zones to be adjusted promptly as the security situation changes, maintaining optimal collaboration results and improving the adaptability and effectiveness of network security protection throughout the entire campus.
[0020] In a second aspect, embodiments of this application provide a server comprising: one or more processors and a memory; the memory is coupled to the one or more processors and is used to store computer program code, the computer program code including computer instructions, wherein the one or more processors invoke the computer instructions to cause the server to perform the method described in the first aspect and any possible implementation thereof.
[0021] Thirdly, embodiments of this application provide a computer program product containing instructions that, when the computer program product is run on a server, cause the server to perform the method described in the first aspect and any possible implementation thereof.
[0022] Fourthly, an embodiment of the present application provides a computer-readable storage medium, including instructions, which, when running on a server, cause the server to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0023] It can be understood that the server provided in the second aspect, the computer program product provided in the third aspect, and the computer storage medium provided in the fourth aspect are all used to execute the method provided by the embodiments of the present application. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, and will not be elaborated here. <
[0028] Figure 1 This is a flowchart illustrating a campus network security incident response method in an embodiment of this application;
[0029] Figure 2 This is another flowchart illustrating the campus network security incident response method in this application embodiment;
[0030] Figure 3 This is a schematic diagram of the physical device structure of a server in an embodiment of this application. Detailed Implementation
[0031] The terminology used in the following embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. As used in the specification of this application, the singular expressions “a,” “an,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in this application refers to any or all possible combinations including one or more of the listed items.
[0032] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.
[0033] The following describes the process of the method provided in this implementation. Please refer to [link / reference]. Figure 1 This is a flowchart illustrating a campus network security incident response method in an embodiment of this application.
[0034] S101. Based on the physical location information and network topology of enterprise nodes within the park, the park is divided into multiple network security collaboration areas. The enterprise node with the highest consensus weight in the network security collaboration area is determined as the security incident response node. The network security collaboration area includes multiple enterprise nodes, and the network security collaboration area corresponds one-to-one with the security incident response node. The consensus weight is determined based on the security protection score and historical reputation score of the enterprise node.
[0035] Among them, enterprise nodes represent enterprise entities with independent network systems within the park, such as factories, R&D centers, or office buildings; physical location information refers to the geographical coordinates of enterprise nodes within the park, including latitude and longitude or relative coordinates; network topology relationships represent the network connection methods and link relationships between enterprise nodes, including direct connections and indirect connections; network security collaboration areas refer to groups of adjacent enterprise nodes with strong security protection collaboration needs; security incident response nodes represent core nodes responsible for coordinating security protection within the network security collaboration area; consensus weight represents the decision-making influence of enterprise nodes within the network security collaboration area; security protection score refers to the current security protection capability assessment score of enterprise nodes; and historical reputation score refers to the past security protection performance assessment score of enterprise nodes.
[0036] Specifically, the server acquires the physical location information of all enterprise nodes within the park, as well as the network topology relationships between these nodes, and calculates the overall correlation between them. Then, the server groups enterprise nodes that are physically adjacent and have high overall correlation into the same network security collaboration zone, forming multiple relatively independent network security collaboration zones. For each network security collaboration zone, the server acquires the security protection score and historical reputation score of each enterprise node within the zone, and calculates a consensus weight according to preset weights. Finally, the server designates the enterprise node with the highest consensus weight as the security incident response node for that network security collaboration zone, responsible for security coordination within that zone.
[0037] Optionally, under normal circumstances, the division of the park into multiple network security collaboration zones based on the physical location information and network topology of enterprise nodes within the park can be achieved in the following ways, without limitation: Based on the physical location information and network topology of each enterprise node within the park, determine the physical proximity and network connection density between enterprise nodes to calculate the comprehensive distance value between enterprise nodes; after determining the enterprise node pair with the smallest comprehensive distance value as the initial collaboration zone, traverse the unassigned enterprise nodes in turn; when the comprehensive distance value between the unassigned enterprise node and the initial collaboration zone is less than a preset distance threshold, the unassigned enterprise node is assigned to the initial collaboration zone to obtain the network security collaboration zone.
[0038] Suppose a certain industrial park has 6 enterprise nodes, as follows:
[0039] A: Research and Development Center, physical location information is (10, 10);
[0040] B: Manufacturing plant 1, physical location information is (12, 11);
[0041] C: Manufacturing Plant 2, physical location information is (15, 12);
[0042] D: Office Building 1, physical location information is (11, 15);
[0043] E: Office Building 2, physical location information is (14, 16);
[0044] F: Data center, physical location information is (18, 15);
[0045] The network topology of enterprise nodes within the park is as follows:
[0046] A and B are directly connected;
[0047] B and C are directly connected;
[0048] D and E are directly connected;
[0049] C and F are directly connected;
[0050] A and D are indirectly connected;
[0051] E and F are indirectly connected;
[0052] (1) Calculate physical proximity (the closer the distance, the higher the score, full score 100): AB: 85 points (closest);
[0053] BC: 80 points;
[0054] CF: 75 points;
[0055] DE: 82 points;
[0056] AD: 70 points;
[0057] EF: 65 points;
[0058] (2) Calculate the network connectivity density (direct connection 100 points, indirect connection 50 points): AB: 100 points;
[0059] BC: 100 points;
[0060] CF: 100 points;
[0061] DE: 100 points;
[0062] AD: 50 points;
[0063] EF: 50 points;
[0064] (3) Calculate the overall correlation degree (physical proximity × 0.6 + network connection density × 0.4): AB: 91 points;
[0065] BC: 88 points;
[0066] CF: 85 points;
[0067] DE: 89 points;
[0068] AD: 62 points;
[0069] EF: 59 points;
[0070] (4) Divide the network security cooperation area (based on the comprehensive correlation, it can be divided into two network security cooperation areas):
[0071] Network security collaboration area 1: A, B, C;
[0072] Network security collaboration area 2: D, E, F;
[0073] (5) Calculate consensus weights:
[0074] Assume the scores for each enterprise node are as follows (out of 100):
[0075] Table 1. Scoring Table for Enterprise Nodes in Network Security Collaboration Zone 1
[0076] Table 2. Scoring Table for Enterprise Nodes in Network Security Collaboration Zone 2
[0077]
[0078] (6) Identify security incident response nodes:
[0079] The security incident response node in network security collaboration zone 1 is A (with the highest consensus weight of 93.5);
[0080] The security incident response node in network security collaboration zone 2 is E (with the highest consensus weight of 90.6).
[0081] S102. After receiving the security alarm information sent by the enterprise node of the security incident source, extract the attack type identifier, asset type identifier and hazard level identifier from the security alarm information to generate security incident features. The enterprise node of the security incident source is used to represent the enterprise node where the security incident occurred. The security alarm information is used to prompt the enterprise node of the security incident source to have a security incident. The security incident features are used to represent the feature information of the security information.
[0082] Among them, the security incident source enterprise node refers to the enterprise node where the security incident occurred; the security alarm information refers to the structured data describing the specific situation of the security incident; the attack type identifier is used to indicate the attack method classification of the security incident, such as SQL injection, DDoS, etc.; the asset type identifier is used to indicate the type of IT asset affected, such as servers, databases, etc.; the hazard level identifier is used to indicate the severity classification of the security incident; and the security incident characteristics refer to the collection of key characteristic information of the security incident.
[0083] Specifically, the server verifies the legitimacy of the security alert information's source, confirming it was issued by the enterprise node that caused the security incident. Then, the server parses the security alert information's data structure, extracting the attack type identifier field, asset type identifier field, and hazard level identifier field. The server standardizes and combines these identifier fields to generate security event characteristics that facilitate subsequent analysis.
[0084] S103. Query the risk propagation model that matches the characteristics of the security incident in the preset risk propagation model library, and calculate the risk infection probability of each network security collaboration area based on the risk propagation model, the physical location information and network topology relationship of the security incident source enterprise node and the enterprise node in the park. The preset risk propagation model library is used to represent the propagation pattern and impact range of different types of security incidents.
[0085] Among them, the preset risk propagation model library refers to a set of models that store the propagation patterns of various security incidents; the risk propagation model refers to a mathematical model that describes the propagation characteristics of a specific type of security incident in the campus network; the risk infection probability refers to the possibility that a network security collaboration area will be affected by a security incident; the propagation pattern is used to represent the diffusion characteristics of security incidents in space and on the network; and the scope of influence is used to represent the network range that a security incident may affect.
[0086] Specifically, the server uses a feature matching algorithm to find the risk propagation model most similar to the characteristics of the current security incident from a pre-defined risk propagation model library. After acquiring this model, the server uses the physical location of the security incident's source enterprise node as the propagation origin, and combines this with the physical location information of other enterprise nodes within the park to construct a geospatial propagation scenario. Simultaneously, the server constructs a network propagation scenario based on network topology. The server then substitutes these two scenarios into the risk propagation model and calculates the potential risk impact on each network security collaboration area, i.e., the probability of infection. This probability of infection considers multiple influencing factors such as physical distance attenuation and network hop count attenuation.
[0087] Optionally, under normal circumstances, the probability of infection in each network security collaboration area can be calculated based on the risk propagation model, the physical location information of the enterprise nodes at the source of the security incident, and the network topology relationships of enterprise nodes within the park, in the following ways, without limitation: Establish a two-dimensional coordinate system based on the physical location information of the enterprise nodes at the source of the security incident, and calculate the physical distance between each enterprise node and the enterprise node at the source of the security incident; construct a network connection graph based on the network topology relationships, and calculate the network hop count between each enterprise node and the enterprise node at the source of the security incident; substitute the physical distance and network hop count into the distance decay function and network decay function of the risk propagation model, respectively, to obtain the physical risk exposure and network risk exposure of each enterprise node; determine the probability of infection in the network security collaboration area based on the physical risk exposure and network risk exposure of each enterprise node within the network security collaboration area.
[0088] Following the example from step S101, suppose a ransomware security incident occurred in the industrial park, and the source node of the security incident is enterprise node B (manufacturing plant 1). Suppose the characteristics of this ransomware security incident are as follows:
[0089] Method of propagation: Web worm;
[0090] Attack target: Windows system;
[0091] Diffusion rate: rapid;
[0092] Scope of infection: Local network;
[0093] (1) Risk propagation model matching:
[0094] Distance decay function: R_p = e^(-0.2d);
[0095] Network attenuation function: R_n = 0.8^h;
[0096] Comprehensive risk calculation function: R = 1 - (1 - R_p) × (1 - R_n);
[0097] Where d is the physical distance (unit: 10 meters) and h is the number of network hops;
[0098] (2) Calculation of physical risk exposure:
[0099] Calculate the physical distance between B(12, 11) and each enterprise node, with B(12, 11) as the origin:
[0100] Table 3 Physical Distance of Enterprise Nodes
[0101] Enterprise Node physical distance Physical risk exposure A 2.236 0.638 B 0 1.000 C 3.606 0.487 D 4.123 0.435 E 5.831 0.312 F 7.071 0.244
[0102] (3) Calculation of network risk exposure:
[0103] Based on the B enterprise node, calculate the network hop count between the B enterprise node and each other enterprise node:
[0104] Table 4 Enterprise Node Network Hop Count Table
[0105] Enterprise Node Network hop count Network risk exposure A 1 0.800 B 0 1.000 C 1 0.800 D 2 0.640 E 3 0.512 F 2 0.640
[0106] 1. Calculate the overall risk value for each enterprise node:
[0107] Table 5. Comprehensive Risk Values for Enterprise Nodes
[0108]
[0109]
[0110] (5) Calculate the probability of infection in the network security collaboration area:
[0111] The probability of infection in network security collaboration zone 1 is (0.928 + 1.000 + 0.897) / 3 = 0.942 = 94.2%;
[0112] The probability of infection in network security collaboration zone 2 is (0.797 + 0.664 + 0.728) / 3 = 0.730 = 73.0%.
[0113] S104. Identify network security collaboration areas where the probability of risk infection exceeds a preset probability threshold as affected areas, and send security protection instructions to security incident response nodes within the affected areas. The security protection instructions are used to prompt protection against security incidents.
[0114] Among them, the preset probability threshold is a standard value for the risk probability used to determine whether the network security collaboration area is affected; the security protection instruction is used to express specific security protection operation requirements, including specific measures such as traffic restriction and access control; the risk infection probability refers to the assessment value of the possibility that the network security collaboration area will be affected by a security incident.
[0115] Specifically, the server compares the probability of infection in each network security collaboration area with a preset probability threshold (e.g., 70%), and identifies those areas where the probability exceeds the threshold as affected areas. The server automatically identifies security incident response nodes within these affected areas and sends security protection instructions containing specific protection requirements to these nodes, such as increasing security levels, strengthening access control, and enabling deep packet inspection. Upon receiving the security protection instructions, each security incident response node will execute corresponding security protection measures to reduce the scope and severity of the security incident.
[0116] S105. Receive execution status data and processing result data from the security incident response node, generate a security incident processing record, and store the security incident processing record in the park's main blockchain database. The security incident processing record includes a processing timestamp, execution status code, and result evaluation value.
[0117] Among them, execution status data refers to the progress and status information of security protection instructions; processing result data refers to the effect evaluation data after the implementation of security protection measures; security incident processing records are used to represent the complete security incident response process record; the park's main blockchain database is used to represent the distributed database storing security incident processing records; processing timestamps refer to the time markers that record the processing time of each stage; execution status codes refer to the status identifiers of the execution results of security protection instructions, which can be subdivided into multiple status levels, such as execution success, partial success, execution failure, etc.; and result evaluation values refer to the quantitative score of the effectiveness of security protection measures.
[0118] Specifically, the server receives execution status data from each security incident response node via a real-time monitoring interface, including information such as instruction reception confirmation, execution progress, and completion status. Simultaneously, the server collects processing result data, including whether the security threat has been resolved, system recovery status, and residual risk assessment. The server organizes this information according to a unified data format, generating a structured processing record containing a processing timestamp, execution status code, and result evaluation value. Subsequently, the server calls the blockchain interface to submit the security incident processing record to the park's main blockchain database in the form of a transaction, ensuring the record's immutability and traceability.
[0119] By adopting the above technical solution, the server divides the park into multiple network security collaboration zones based on the physical location information and network topology of enterprise nodes, and designates the enterprise node with the highest consensus weight as the security incident response node, thus achieving regionalized collaborative security protection. When a security incident occurs, the server can quickly extract the characteristics of the security incident and use a risk propagation model to analyze the risk of infection in each network security collaboration zone, thereby accurately identifying the affected area. The server sends security protection commands to the security incident response nodes in the affected area, enabling rapid coordinated response. Simultaneously, the security incident processing records are stored in the park's main blockchain database, ensuring the trustworthiness and integrity of the data. This regional collaborative response mechanism significantly improves the overall security protection efficiency of the park and reduces the risk of security incident spread.
[0120] The following provides a more detailed description of the process of the method provided in this implementation. Please refer to [link / reference]. Figure 2 This is another flowchart illustrating the campus network security incident response method in this application embodiment.
[0121] The following steps may or may not be performed after step S103; this is not limited here:
[0122] S201. Identify network security collaboration areas where the probability of infection exceeds a preset probability threshold as affected areas;
[0123] For details, please refer to step S104, which will not be repeated here.
[0124] S202. Based on the characteristics of security events, retrieve the corresponding security protection strategy combination from the preset security protection strategy library; wherein, the preset security protection strategy library refers to a knowledge base that stores various security protection strategies; the security protection strategy combination is used to represent a set of multi-layered protection measures for a specific security event, such as security protection strategies can be further divided into multiple layers such as network layer protection strategies, system layer protection strategies and application layer protection strategies.
[0125] Specifically, the server standardizes the characteristics of security events and extracts key feature vectors. Then, the server accesses a pre-defined security protection strategy library, using the key feature vectors as search criteria and employing a fuzzy matching algorithm to find the strategy template with the highest similarity. For each matching strategy template, the server further analyzes its applicability and protection effectiveness score, ultimately selecting multiple complementary security protection strategies to form a security protection strategy combination. This combination typically includes multiple dimensions such as incident response strategies, continuous protection strategies, and recovery strategies to ensure comprehensive protection.
[0126] S203. Based on the risk of infection probability in the affected area, determine the corresponding security protection strategy from the combination of security protection strategies.
[0127] Among them, security protection strategy refers to specific protection measures and plans. According to different protection levels, security protection strategies can be divided into high-level protection strategies, medium-level protection strategies and basic protection strategies.
[0128] Specifically, the server sets protection level requirements based on the risk of infection in the affected areas. Then, the server analyzes the protection strength and resource overhead of each security protection strategy in the combination of security protection policies, selecting the strategy that meets the protection level requirements while having the optimal resource overhead. For affected areas with a high risk of infection, the server will choose stronger security protection strategies such as stricter access control and more frequent security checks; for affected areas with a lower risk of infection, the server will choose relatively lenient security protection strategies to balance security and business continuity.
[0129] S204. Convert the security protection strategy into security protection instructions and send them sequentially to the security incident response nodes in the affected area;
[0130] Among them, security protection instructions refer to a specific set of operation commands, which can be further divided into various types such as configuration instructions, control instructions, and monitoring instructions.
[0131] Specifically, the server converts the selected security protection policy into a specific sequence of operation instructions (security protection instructions), including specific configuration parameters, execution steps and completion criteria, and then sends them out sequentially to the security event response nodes in the corresponding affected areas.
[0132] S205. Monitor the execution of security protection commands by security incident response nodes;
[0133] Among them, execution status is used to represent information such as the status, progress, and results of security protection command execution; monitoring refers to the real-time tracking and status collection of the execution process. Execution status can be further subdivided into multiple dimensions such as command reception status, command execution progress, execution result status, and resource consumption status. Execution result status can be further divided into specific statuses such as execution success, execution failure, execution timeout, and partial completion.
[0134] Specifically, the server establishes real-time monitoring connections with each security incident response node, ensuring connection reliability through a heartbeat mechanism. The server periodically collects execution status data reported by the security incident response nodes, including command reception confirmation, execution progress percentage, current execution stage, and resource usage. Simultaneously, the server analyzes various performance metrics during execution, such as response latency, throughput, and error rate, to determine whether the execution process meets expectations.
[0135] S206. When the execution status shows an abnormality, resend the security protection command to the security event response node;
[0136] Among them, anomalies refer to unexpected situations that occur during execution; execution status anomalies can be further subdivided into instruction reception anomalies, execution process anomalies, and execution result anomalies; resending can be done in two ways: resending the original instruction or resending the optimized instruction.
[0137] Specifically, the server categorizes and analyzes abnormal execution situations to determine the specific type and possible cause of the anomaly. For instruction reception anomalies, the server checks the communication link status and, if necessary, switches to a backup channel to resend the instruction. For execution process anomalies, the server optimizes and adjusts the original instruction based on the cause of the anomaly, such as adjusting execution parameters, refining execution steps, or reducing resource requirements. For execution result anomalies, the server, considering the current security posture, may choose an alternative protection strategy to generate new instructions. When resending instructions, the server simultaneously initiates a more stringent execution monitoring mechanism, including shortening the status collection interval and lowering the anomaly detection threshold, to ensure timely detection and handling of potential anomalies. If a security event response node experiences multiple anomalies, the server will also consider initiating a node replacement process.
[0138] S207. Receive execution status data and processing result data from the security incident response node, generate a security incident processing record, and store the security incident processing record in the park's main blockchain database. The security incident processing record includes a processing timestamp, execution status code, and result evaluation value.
[0139] For details, please refer to step S105, which will not be repeated here.
[0140] S208. Periodically retrieve security incident handling records from the main blockchain database of the park. The security incident handling records include alarm information, response time and handling results of enterprise nodes.
[0141] The security incident handling record refers to the complete information on the security incident response process; alarm information indicates the security threat information reported by enterprise nodes; response time indicates the time interval from receiving the alarm to completing the handling; and handling result indicates the final resolution of the security incident. Security incident handling records can be indexed and queried according to multiple dimensions such as timestamp, enterprise node, and event type. Periodic retrieval is usually based on a preset statistical period, such as daily, weekly, or monthly.
[0142] Specifically, the server determines the time window range for this statistical analysis and then queries all security event handling records within that time window range via the blockchain interface. The server parses and categorizes the obtained security event handling records, organizing them by enterprise node dimension. It extracts the alarm information (including alarm type, level, description, etc.), response time (including alarm confirmation time, response start time, processing completion time, etc.), and processing results (including threat elimination status, system recovery status, residual risks, etc.) from each security event handling record. The server also verifies the completeness and consistency of the security event handling records to ensure data reliability.
[0143] S209. Calculate the alarm accuracy rate based on the alarm information, the response timeliness rate based on the response duration, and the processing effectiveness rate based on the processing results. Determine the security contribution of the enterprise node based on the alarm accuracy rate, response timeliness rate, and processing effectiveness rate.
[0144] Among them, alarm accuracy rate refers to the degree to which alarms issued by enterprise nodes match the actual threats; response timeliness rate refers to the proportion of responses completed within the specified time; handling effectiveness rate refers to the degree of success in handling security incidents; and security contribution rate refers to the comprehensive performance score of enterprise nodes in security protection.
[0145] Specifically, the server calculates the alert accuracy rate by dividing the number of actual threat alerts by the total number of alerts, taking into account the accuracy of the alert level. Next, the server calculates the response timeliness rate by calculating the proportion of events processed within a preset response time limit, applying different time limit standards for different levels of security events. Then, the server calculates the processing effectiveness rate, evaluating the effectiveness of the handling measures based on the results, including the completeness of threat elimination and the timeliness of system recovery. Finally, the server weights these three indicators according to preset weights to obtain a security contribution score reflecting the overall security protection capability of the enterprise nodes.
[0146] S210. The security contribution score and historical reputation score are weighted and calculated to obtain the updated reputation score for the enterprise node. The security contribution score refers to the score of security protection performance within the current assessment period; the historical reputation score refers to the accumulated reputation score of the enterprise node. The weighted calculation represents the process of combining the old and new scores; the updated reputation score represents the final comprehensive evaluation result of the enterprise node. The weighting coefficients can be dynamically adjusted according to the length of the assessment period and the reliability of historical data.
[0147] Specifically, the server determines the weighting coefficients used in this calculation. Newer security contributions are typically assigned higher weights, while the weight of historical reputation scores decays over time. The server calculates the updated reputation score for each enterprise node using the determined weighting coefficients.
[0148] S211. Statistically analyze the frequency of security events, the distribution of security event types, and the propagation path of security events in each network security collaboration area within a preset time window to determine the risk coefficient of each network security collaboration area.
[0149] Among them, the preset time window is used to represent the time range of statistical analysis; the frequency of security incidents is used to represent the number of times security incidents occur; the distribution of security incident types is used to represent the proportion of different types of security incidents; the security incident propagation path is used to represent the spread trajectory of security incidents within the network security collaboration area; and the risk coefficient is used to represent the overall security risk level of the network security collaboration area.
[0150] Specifically, the server extracts all security event handling records within a preset time window and groups them according to network security collaboration regions. For each network security collaboration region, the server counts the total number of security events and calculates the temporal distribution characteristics of security events. Then, the server classifies and statistically analyzes the security events by type, analyzing the proportion and severity of each type of security event. The server also identifies and records the propagation path patterns of security events by analyzing their spatiotemporal correlation. Finally, the server comprehensively considers factors such as the frequency of security events, the distribution of security event types, and the propagation paths of security events to calculate a risk coefficient reflecting the overall risk level of the network security collaboration region.
[0151] S212. Calculate the average reputation score of the network security collaboration area based on the reputation scores of each enterprise node within the network security collaboration area.
[0152] The average reputation score refers to the overall reputation level of the cybersecurity collaboration area. The score can be calculated using a simple arithmetic average or a weighted average based on node importance.
[0153] Specifically, the server obtains the latest reputation scores of all enterprise nodes within the network security collaboration area. Then, the server determines weighting coefficients based on factors such as the size and business importance of the enterprise nodes, and calculates an average reputation score reflecting the overall reputation level of the network security collaboration area through weighted averaging.
[0154] S213. Determine the regional adjustment coefficient based on the risk coefficient and average credit score;
[0155] Among them, the regional adjustment coefficient is used to represent the necessity of regional adjustment, and can reflect the rationality of the current regional division and the need for optimization.
[0156] Specifically, the server uses a pre-defined calculation model to comprehensively calculate the risk coefficient and average credit score according to a certain weighting relationship. Generally, a higher risk coefficient increases the regional adjustment coefficient, while a higher average credit score decreases the regional adjustment coefficient. The regional adjustment coefficient obtained through this calculation can objectively reflect whether the current regional division status needs optimization and adjustment.
[0157] S214. If the regional adjustment coefficient is greater than the preset adjustment threshold, the regional re-division process will be triggered.
[0158] Among them, the preset adjustment threshold refers to the standard value that triggers the re-division; the area re-division process is used to represent the system process of re-planning network security collaboration areas.
[0159] Specifically, the server compares the calculated region adjustment coefficient with a preset adjustment threshold. When the region adjustment coefficient exceeds the preset threshold, it indicates that the current region division can no longer meet the security protection requirements and needs to be optimized. The server will then initiate a region re-division process, which will consider multiple factors such as the latest network topology, security risk distribution, and node reputation levels, and re-plan a more reasonable collaborative region division scheme through optimization algorithms.
[0160] The server in the embodiments of this invention is described below from the perspective of hardware processing. Please refer to [link / reference]. Figure 3 This is a schematic diagram of the physical device structure of a server in an embodiment of this application.
[0161] It should be noted that, Figure 3 The server structure shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0162] like Figure 3 As shown, the server includes a CPU 301, which can perform various appropriate actions and processes based on a program stored in the read-only memory ROM 302 or a program loaded from the storage section 308 into the random access memory RAM 303, such as performing the methods described in the above embodiments. The RAM 303 also stores various programs and data required for system operation. The CPU 301, ROM 302, and RAM 303 are interconnected via a bus 304. An I / O interface 305 is also connected to the bus 304.
[0163] The following components are connected to I / O interface 305: input section 306 including audio input devices, push-button switches, etc.; output section 307 including a liquid crystal display (LCD) and audio output devices, indicator lights, etc.; storage section 308 including a hard disk, etc.; and communication section 309 including a network interface card such as a LAN (Local Area Network) card, modem, etc. Communication section 309 performs communication processing via a network such as the Internet. Drive 310 is also connected to I / O interface 305 as needed. Removable media 311, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 310 as needed so that computer programs read from them can be installed into storage section 308 as needed.
[0164] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing computer programs for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 309, and / or installed from removable medium 311. When the computer program is executed by CPU 301, it performs the various functions defined in the present invention.
[0165] It should be noted that specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0166] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, program segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those shown in the drawings.
[0167] Specifically, the server in this embodiment includes a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, it implements the campus network security incident response method provided in the above embodiment.
[0168] In another aspect, the present invention also provides a computer-readable storage medium, which may be included in the server described in the above embodiments; or it may exist independently and not assembled into the server. The storage medium carries one or more computer programs that, when executed by a processor of the server, cause the server to implement the campus network security incident response method provided in the above embodiments.
[0169] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
[0170] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".
[0171] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A method for responding to cybersecurity incidents in a campus, characterized in that, Applied to a server, the method includes: Based on the physical location information and network topology of enterprise nodes within the park, the park is divided into multiple network security collaboration zones. The enterprise node with the highest consensus weight in each network security collaboration zone is identified as the security incident response node. Each network security collaboration zone includes multiple enterprise nodes, and each network security collaboration zone corresponds one-to-one with the security incident response node. The consensus weight is determined based on the security protection score and historical reputation score of the enterprise node. After receiving security alarm information sent by the enterprise node that is the source of the security incident, the attack type identifier, asset type identifier, and hazard level identifier are extracted from the security alarm information to generate security incident features. The enterprise node that is the source of the security incident is used to represent the enterprise node where the security incident occurred. The security alarm information is used to notify the enterprise node that the security incident has occurred. The security incident features are used to represent the characteristic information of the security incident. The system queries a risk propagation model that matches the characteristics of the security incident in a preset risk propagation model library. Based on the risk propagation model, the physical location information and network topology of the security incident source enterprise node and enterprise nodes in the park, the system calculates the risk infection probability of each network security collaboration area. The preset risk propagation model library is used to represent the propagation patterns and impact range of different types of security incidents. The network security collaboration area where the probability of infection exceeds a preset probability threshold is identified as the affected area, and a security protection instruction is sent to the security event response node in the affected area. The security protection instruction is used to prompt the security event to be protected. The system receives execution status data and processing result data from security incident response nodes, generates security incident processing records, and stores these records in the park's main blockchain database. The security incident processing records include processing timestamps, execution status codes, and result evaluation values.
2. The method according to claim 1, characterized in that, Based on the physical location information and network topology of enterprise nodes within the park, the park is divided into multiple network security collaboration zones, specifically including: Based on the physical location information and network topology of each enterprise node in the park, the physical proximity and network connection density between enterprise nodes are determined in order to calculate the comprehensive distance value between enterprise nodes. After determining the enterprise node pair with the smallest comprehensive distance value as the initial collaboration area, the unassigned enterprise nodes are traversed sequentially. When the combined distance between the unassigned enterprise node and the initial collaboration area is less than a preset distance threshold, the unassigned enterprise node is assigned to the initial collaboration area, thus obtaining the network security collaboration area.
3. The method according to claim 1, characterized in that, The calculation of the risk infection probability for each network security collaboration area, based on the risk propagation model, the physical location information and network topology of the security incident source enterprise nodes and enterprise nodes within the park, specifically includes: A two-dimensional coordinate system is established based on the physical location information of the enterprise nodes that are the source of the security incident, and the physical distance between each enterprise node and the enterprise node that is the source of the security incident is calculated. Based on the network topology, a network connection graph is constructed, and the network hop count between each enterprise node and the enterprise node that is the source of the security event is calculated. Substituting the physical distance and the network hop count into the distance decay function and network decay function of the risk propagation model, respectively, yields the physical risk exposure and network risk exposure of each enterprise node. The probability of infection in the network security collaboration area is determined based on the physical and network risk exposure of each enterprise node within the network security collaboration area.
4. The method according to claim 1, characterized in that, Sending security protection instructions to security event response nodes within the affected area specifically includes: Based on the characteristics of the security events, the corresponding security protection strategy combinations are retrieved from the preset security protection strategy library; Based on the risk of infection in the affected area, a corresponding security protection strategy is determined from the combination of security protection strategies; The security protection strategy is converted into security protection instructions and sequentially sent to the security event response nodes within the affected area.
5. The method according to claim 4, characterized in that, After the step of sending security protection instructions to security incident response nodes within the affected area, the method further includes: Monitor the execution of the security protection commands by the security event response node; When the execution status shows an anomaly, the security protection command is resent to the security event response node.
6. The method according to claim 1, characterized in that, After the steps of receiving execution status data and processing result data from the security incident response node, generating a security incident processing record, and storing the security incident processing record in the park's main blockchain database, the method further includes: Periodically retrieve security event handling records from the main blockchain database of the park. The security event handling records include alarm information, response time and handling results of enterprise nodes. The alarm accuracy rate is calculated based on the alarm information, the response timeliness rate is calculated based on the response duration, and the processing effectiveness rate is calculated based on the processing results. Based on the alarm accuracy rate, the response timeliness rate, and the processing effectiveness rate, the security contribution of the enterprise node is determined. The security contribution and the historical reputation score are weighted and calculated to obtain the updated reputation score of the enterprise node.
7. The method according to claim 6, characterized in that, After the step of weighting the security contribution and the historical reputation score to obtain the updated reputation score of the enterprise node, the method further includes: The frequency of security incidents, the distribution of security incident types, and the propagation paths of security incidents in each network security collaboration area within a preset time window are statistically analyzed to determine the risk coefficient of each network security collaboration area. The average reputation score of the network security collaboration area is calculated based on the reputation scores of each enterprise node within the network security collaboration area. Based on the risk coefficient and the average credit score, a regional adjustment coefficient is determined; If the region adjustment coefficient is greater than the preset adjustment threshold, the region re-division process is triggered.
8. A server, characterized in that, The server includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code including computer instructions, and the one or more processors call the computer instructions to cause the server to perform the method as described in any one of claims 1-7.
9. A computer-readable storage medium comprising instructions, characterized in that, When the instructions are executed on the server, the server causes the server to perform the method as described in any one of claims 1-7.
10. A computer program product, characterized in that, When the computer program product is run on the server, the server performs the method as described in any one of claims 1-7.
Citation Information
Patent Citations
Security situation awareness response platform and method in credential environment
CN119892516A
Comprehensive service system and method for intelligent safety protection
CN120087774A